Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Cisco logo

CCIE Security

Domain 3Objective 7

3.7 Security Features to Comply with Organizational Security Policies, Procedures, and Standards BCP 38 CCIE-SECURITY Practice Questions (Page 6)

Part of the 3.0 Security Infrastructure domain, which accounts for 15% of the CCIE-SECURITY exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~8–12 in this domain), expect 1–1 from this objective — we provide 34 practice questions to prepare you well beyond it. (estimate)

34questions here
7free pages
9concepts
15%of the exam

Questions 26–30

  1. 26expert · hard

    A network engineer is implementing egress filtering on a corporate firewall. The company has a public IP range 192.0.2.0/24, but also uses a secondary public IP range 198.51.100.0/24 for a specific application. The egress filter must allow both ranges to exit, but block all other source addresses. The engineer is creating an ACL. Which configuration is correct?

    Select an answer first
  2. 27application · medium

    A managed security services provider (MSSP) is hardening its customer edge routers to comply with BCP 38 and PCI-DSS Requirement 1.3.2 (ingress and egress filtering). The customer network uses private RFC 1918 addressing internally. Which egress filtering rule should be applied on the router's WAN interface to prevent spoofed traffic from leaving the network?

    Select an answer first
  3. 28application · medium

    A retail company processes credit card transactions and is preparing for a PCI-DSS assessment. The network includes a cardholder data environment (CDE) segment and a corporate segment. The security team needs to implement network segmentation to reduce the PCI-DSS scope. Which firewall configuration best achieves this while meeting PCI-DSS Requirement 1.1.4 (network diagram) and 1.3 (firewall rules)?

    Select an answer first
  4. 29application · medium

    A hospital's IT department is implementing PCI-DSS controls for its payment processing systems. They need to ensure that all access to cardholder data is logged and monitored. Which set of actions best meets PCI-DSS Requirement 10 (track and monitor all access to network resources and cardholder data) and Requirement 11 (regularly test security systems)?

    Select an answer first
  5. 30application · medium

    A multinational corporation is aligning its network security infrastructure with ISO 27001 Annex A controls. The security team is focusing on Annex A.13.1.1 (network controls) and A.13.1.3 (segregation in networks). Which infrastructure change best demonstrates compliance with these controls?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “CCIE-SECURITY” is a trademark of its owner, used for identification only.