
CCIE Security
Domain 2Objective 4
2.4 VPN High Availability Methods CCIE-SECURITY Practice Questions (Page 9)
Part of the 2.0 Secure Connectivity and Segmentation domain, which accounts for 20% of the CCIE-SECURITY exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~10–16 in this domain), expect 2–3 from this objective — we provide 54 practice questions to prepare you well beyond it. (estimate)
54questions here
11free pages
7concepts
20%of the exam
Questions 41–45
- 41
An ASA cluster is deployed using the spanned EtherChannel model. The administrator notices that traffic is not using all links in the EtherChannel; only one link is active. What is a possible cause?
Select an answer first - 42
During ASA cluster configuration, the control link is not coming up. The administrator has verified that the interfaces are correctly configured and the cable is connected. What else should they check?
Select an answer first - 43
A dual-hub DMVPN network is designed with two hubs in different geographic locations. The spokes are configured with both hubs as NHRP servers. However, after a hub failure, some spokes take a long time to converge. What can be done to speed up failover?
Select an answer first - 44
In a dual-hub DMVPN, a spoke is configured with NHRP mappings for both hubs. However, the spoke is only establishing a tunnel to one hub. What is a possible reason?
Select an answer first - 45
An ASA cluster is configured for remote-access VPN. The administrator wants to ensure that if a cluster member fails, the VPN sessions are redistributed to other members without any interruption. What is the best way to achieve this?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “CCIE-SECURITY” is a trademark of its owner, used for identification only.