Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Cisco logo

CCIE Security

Domain 3Objective 7

3.7 Security Features to Comply with Organizational Security Policies, Procedures, and Standards BCP 38 CCIE-SECURITY Practice Questions (Page 5)

Part of the 3.0 Security Infrastructure domain, which accounts for 15% of the CCIE-SECURITY exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~8–12 in this domain), expect 1–1 from this objective — we provide 34 practice questions to prepare you well beyond it. (estimate)

34questions here
7free pages
9concepts
15%of the exam

Questions 21–25

  1. 21expert · hard

    A large enterprise has multiple internet connections from different ISPs for redundancy. The network uses BGP to advertise its public prefixes. The security team is implementing BCP 38 ingress filtering on all edge routers. The network also uses a public IP range that is not yet fully utilized, and some internal servers use RFC 1918 addresses with NAT. The team must ensure that ingress filtering does not break legitimate traffic. Which approach best balances BCP 38 compliance with operational continuity?

    Select an answer first
  2. 22expert · hard

    A financial institution is undergoing a PCI-DSS assessment. The network includes a legacy application that transmits cardholder data in clear text over the internal network. The application cannot be modified to use TLS. The assessor has flagged this as a finding. The security team must implement a compensating control to meet PCI-DSS Requirement 4.1 (encrypt transmission of cardholder data across open, public networks). Which compensating control is most appropriate?

    Select an answer first
  3. 23expert · hard

    A multinational company is implementing ISO 27001 and has a distributed network with regional offices connected via MPLS. The company wants to implement network segregation between the corporate network and the guest Wi-Fi network. The guest network is used by visitors and is considered untrusted. Which approach best meets ISO 27001 Annex A.13.1.3 while maintaining usability for guests?

    Select an answer first
  4. 24expert · hard

    A network administrator is troubleshooting a BCP 38 ingress filtering issue. The edge router has an inbound ACL that permits only the internal public IP range 198.51.100.0/24. However, users are reporting that they cannot access external websites. The administrator discovers that the internal network uses NAT, and the NAT pool is 203.0.113.10-203.0.113.20. What is the most likely cause of the issue?

    Select an answer first
  5. 25expert · hard

    A payment processor is preparing for a PCI-DSS audit. The network includes a wireless network used by employees to access the cardholder data environment (CDE). The wireless network uses WPA2-PSK with a shared passphrase. The assessor has identified this as a finding. Which change is most aligned with PCI-DSS Requirement 4.1.1 (use strong cryptography for wireless transmissions) and Requirement 8.2.1 (unique user IDs)?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “CCIE-SECURITY” is a trademark of its owner, used for identification only.