
CCIE Security
Domain 1Objective 10
1.10 Routing Protocols Security on Cisco IOS, Cisco ASA, and Cisco FTD CCIE-SECURITY Practice Questions (Page 9)
Part of the 1.0 Perimeter Security and Intrusion Prevention domain, which accounts for 20% of the CCIE-SECURITY exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~10–16 in this domain), expect 1–1 from this objective — we provide 58 practice questions to prepare you well beyond it. (estimate)
58questions here
12free pages
10concepts
20%of the exam
Questions 41–45
- 41
Your company's BGP edge router receives full Internet routes from two ISPs. A recent route leak caused traffic to be black-holed for 30 minutes. Management wants to minimize the risk of accepting invalid or malicious prefixes while keeping operational overhead low. Which two actions should you implement on the edge router?
Select an answer first - 42
You are troubleshooting an OSPF adjacency problem on a Cisco IOS router. The neighbor is not coming up, and you suspect that OSPF authentication is failing. Which debug command would provide the most useful information?
Select an answer first - 43
Your BGP edge router receives full Internet routes from two ISPs. You need to prevent the acceptance of your own AS's prefixes (to avoid routing loops) and also protect against BGP session spoofing. You have limited CPU resources. Which two actions are most efficient and effective?
Select an answer first - 44
You are migrating an OSPF network from MD5 authentication to HMAC-SHA256 for stronger security. During the migration, you need to maintain adjacency without downtime. What is the best approach?
Select an answer first - 45
Your BGP network is experiencing route flapping from a peer, causing instability. You want to suppress unstable routes while still allowing stable routes to be advertised. However, you also need to ensure that legitimate new routes are not suppressed immediately. What is the best configuration?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “CCIE-SECURITY” is a trademark of its owner, used for identification only.