
CCIE Security
Domain 1Objective 10
1.10 Routing Protocols Security on Cisco IOS, Cisco ASA, and Cisco FTD CCIE-SECURITY Practice Questions (Page 11)
Part of the 1.0 Perimeter Security and Intrusion Prevention domain, which accounts for 20% of the CCIE-SECURITY exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~10–16 in this domain), expect 1–1 from this objective — we provide 58 practice questions to prepare you well beyond it. (estimate)
58questions here
12free pages
10concepts
20%of the exam
Questions 51–55
- 51
You administer an OSPF network running on Cisco IOS routers. A security audit requires that OSPF adjacencies only form with trusted neighbors and that OSPF hello packets are not sent to unauthorized segments. What configuration change would you implement?
Select an answer first - 52
Your Cisco ASA is running OSPF inside a VRF for a customer segment. The customer requires that OSPF adjacencies be authenticated and that only specific routes are exchanged with the customer's router. What is the most efficient way to meet both requirements on the ASA?
Select an answer first - 53
You are configuring a Cisco FTD device that runs OSPF with a service provider router. The security policy requires that only the service provider router can form an adjacency and that OSPF packets from other sources are ignored. Which configuration approach should you use on the FTD?
Select an answer first - 54
Your BGP router is experiencing route flapping from a peer, causing instability in your network. You want to suppress unstable routes while still allowing stable routes to be advertised. Which BGP feature should you enable?
Select an answer first - 55
Your EIGRP network includes several remote sites connected via WAN links. You want to ensure that only authorized routers can exchange EIGRP updates and that EIGRP hello packets are not sent to the WAN provider's network. What should you configure on the Cisco IOS routers?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “CCIE-SECURITY” is a trademark of its owner, used for identification only.