
CCIE Security
Domain 1Objective 10
1.10 Routing Protocols Security on Cisco IOS, Cisco ASA, and Cisco FTD CCIE-SECURITY Practice Questions (Page 6)
Part of the 1.0 Perimeter Security and Intrusion Prevention domain, which accounts for 20% of the CCIE-SECURITY exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~10–16 in this domain), expect 1–1 from this objective — we provide 58 practice questions to prepare you well beyond it. (estimate)
58questions here
12free pages
10concepts
20%of the exam
Questions 26–30
- 26
A network engineer is configuring BGP on a Cisco ASA firewall that connects to a service provider. The engineer wants to authenticate the BGP session and also ensure that only the provider's routes are accepted. Which configuration is correct on the ASA?
Select an answer first - 27
A security engineer is configuring BGP on a Cisco FTD device and needs to implement BGP TTL security to protect against spoofed packets. However, the FTD management interface does not expose this option. What should the engineer do?
Select an answer first - 28
A service provider is implementing MPLS L3VPN and wants to secure the routing protocol between PE and CE routers. The provider uses EIGRP as the PE-CE protocol and wants to authenticate EIGRP updates within a VRF. Which configuration is required on the Cisco IOS PE router?
Select an answer first - 29
A network engineer is troubleshooting an OSPF adjacency problem on a Cisco IOS router. The engineer has verified that OSPF authentication is configured correctly on both sides, but the adjacency is still not forming. Which command should be used to see if OSPF packets are being dropped due to authentication mismatch?
Select an answer first - 30
A network architect is designing BGP security for a multi-homed enterprise. The architect wants to protect against route injection, spoofing, and route flapping. Which of the following measures should be implemented? (Select all that apply.)
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “CCIE-SECURITY” is a trademark of its owner, used for identification only.