
CCIE Security
Domain 3Objective 7
3.7 Security Features to Comply with Organizational Security Policies, Procedures, and Standards BCP 38 CCIE-SECURITY Practice Questions (Page 7)
Part of the 3.0 Security Infrastructure domain, which accounts for 15% of the CCIE-SECURITY exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~8–12 in this domain), expect 1–1 from this objective — we provide 34 practice questions to prepare you well beyond it. (estimate)
34questions here
7free pages
9concepts
15%of the exam
Questions 31–34
- 31
A government agency is implementing ISO 27001 and needs to ensure that its network infrastructure supports the ISMS. The agency has multiple departments with different security requirements. Which approach best aligns the network infrastructure with ISO 27001 requirements?
Select an answer first - 32
A university is implementing BCP 38 ingress filtering on its border routers to prevent students from spoofing IP addresses. The university has multiple public IP ranges assigned to different departments. Which ACL design best implements ingress filtering while minimizing operational impact?
Select an answer first - 33
A small e-commerce business is working toward PCI-DSS compliance. The business uses a single server for both the web application and the database that stores cardholder data. The assessor recommends segmentation to reduce scope. Which action is most effective in reducing PCI-DSS scope?
Select an answer first - 34
A cloud service provider is implementing BCP 38 egress filtering on its virtual network edge to prevent customers from sending spoofed traffic. The provider assigns each customer a unique public IP range. Which egress filtering policy should be applied to each customer's virtual router?
Select an answer first
Finished these 4 questions?
Review the revealed explanations, or continue through the curriculum.
No more pagesBack to CCIE-SECURITY
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “CCIE-SECURITY” is a trademark of its owner, used for identification only.