
CCIE Security
Domain 1Objective 10
1.10 Routing Protocols Security on Cisco IOS, Cisco ASA, and Cisco FTD CCIE-SECURITY Practice Questions (Page 8)
Part of the 1.0 Perimeter Security and Intrusion Prevention domain, which accounts for 20% of the CCIE-SECURITY exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~10–16 in this domain), expect 1–1 from this objective — we provide 58 practice questions to prepare you well beyond it. (estimate)
58questions here
12free pages
10concepts
20%of the exam
Questions 36–40
- 36
A network engineer is securing BGP on a router that peers with multiple ISPs. The engineer is concerned about spoofed BGP packets and wants to ensure that only packets from directly connected peers are accepted. Which feature should be enabled?
Select an answer first - 37
A service provider is experiencing route flapping from a customer edge router. The provider wants to suppress unstable routes while still allowing the customer to recover quickly after the flapping stops. Which BGP feature should be configured on the provider's router?
Select an answer first - 38
A network administrator is configuring OSPF on a Cisco IOS router and wants to prevent OSPF hello packets from being sent on an interface that connects to a LAN with no other OSPF routers. The administrator also wants to ensure that OSPF updates on other interfaces are authenticated. Which configuration should be applied?
Select an answer first - 39
A network engineer is configuring EIGRP on a Cisco IOS router and wants to authenticate EIGRP updates to prevent route injection. The engineer also wants to ensure that EIGRP hello packets are not sent on an interface that connects to a stub network. Which configuration should be used?
Select an answer first - 40
A service provider uses MPLS VPNs and wants to secure routing protocols within each VRF. The provider is using OSPF as the PE-CE routing protocol and wants to authenticate OSPF updates between the PE and CE routers. Which configuration is required on the Cisco IOS PE router?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “CCIE-SECURITY” is a trademark of its owner, used for identification only.