
CCIE Security
Domain 1Objective 3
1.3 Security Features on Cisco IOS/IOS XE CCIE-SECURITY Practice Questions (Page 6)
Part of the 1.0 Perimeter Security and Intrusion Prevention domain, which accounts for 20% of the CCIE-SECURITY exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~10–16 in this domain), expect 1–1 from this objective — we provide 42 practice questions to prepare you well beyond it. (estimate)
42questions here
9free pages
11concepts
20%of the exam
Questions 26–30
- 26
A security team is deploying a zone-based firewall on a router that connects three segments: inside (trusted), DMZ (public servers), and outside (internet). The requirements are: inside can initiate to DMZ and outside; DMZ can only be reached from outside on ports 80/443; outside cannot initiate to inside. The administrator has created zones and zone pairs. What is the correct policy configuration?
Select an answer first - 27
A network administrator is using NBAR to classify traffic on a WAN link. They have a policy that prioritizes voice traffic, but they notice that some voice calls are being misclassified as generic RTP and not getting priority. The router runs IOS XE. What is the best action to improve classification accuracy?
Select an answer first - 28
A router is configured with NAT and a zone-based firewall. The inside network uses 10.0.0.0/8, and the outside is the internet. The firewall policy allows all outbound traffic. Users can access the internet, but an external partner cannot reach a web server in the DMZ that is behind the router. The web server has a static NAT mapping. What is the most likely cause?
Select an answer first - 29
A security administrator needs to verify that a zone-based firewall is correctly blocking certain traffic and also wants to see real-time logs of dropped packets. Which two actions should they take? (Select all that apply.)
Select an answer first - 30
A company has a single public IP address and needs to host multiple internal servers (web, email, and FTP) that must be reachable from the internet. They also need to allow internal users to access the internet. What is the most efficient NAT strategy?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “CCIE-SECURITY” is a trademark of its owner, used for identification only.