
CCIE Security
Domain 5Objective 5
5.5 Web Filtering, User Identification, and Application Visibility and Control (AVC) on Cisco FTD and Cisco WSA CCIE-SECURITY Practice Questions (Page 4)
Part of the 5.0 Advanced Threat Protection and Content Security domain, which accounts for 20% of the CCIE-SECURITY exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~10–16 in this domain), expect 1–2 from this objective — we provide 36 practice questions to prepare you well beyond it. (estimate)
36questions here
8free pages
8concepts
20%of the exam
Questions 16–20
- 16
Which user identification method on Cisco WSA automatically identifies users without requiring them to log in?
Select an answer first - 17
A company is deploying Cisco FTD as their internet gateway. They want to block access to gambling sites for all users, but allow access to social media during lunch hours only. They also need to ensure that users are identified by their Active Directory username for logging. Which configuration approach on FTD will meet these requirements with the least administrative overhead?
Select an answer first - 18
A university uses Cisco WSA. They want to allow social media for students but block it for faculty during working hours. They also want to monitor and control the use of peer-to-peer (P2P) file sharing applications. The university has a large number of users and wants to minimize authentication overhead. Which WSA configuration is most appropriate?
Select an answer first - 19
A multinational company has Cisco FTD at each branch office and a centralized Cisco WSA in the data center. They want to enforce consistent web filtering policies across all branches, but they also want to allow local branches to have some flexibility. They are concerned about WAN bandwidth if all web traffic is tunneled to the data center. Which deployment strategy is most effective?
Select an answer first - 20
A security architect is choosing between Cisco FTD and Cisco WSA for a new deployment. The organization needs deep application-level control (e.g., blocking specific features within applications), granular user-based web policies, and detailed reporting on web usage. They also have a limited budget and prefer a single appliance. Which solution should they choose?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “CCIE-SECURITY” is a trademark of its owner, used for identification only.