Cisco CCIE Security Practice Test Exam
1. Which Cisco ISE persona is responsible for processing RADIUS
authentication requests?
A. Administration
B. Policy Service
C. Monitoring
D. pxGrid
Answer: B
Rationale: The Policy Service persona handles RADIUS
authentication, authorization, and accounting requests from
network access devices.
2. In Cisco TrustSec, what is the purpose of the environment
data download?
A. To download SGACL policies
B. To download IP-to-SGT mappings
C. To download PAC files
D. To download encryption keys
Answer: B
,Rationale: Environment data download provides the IP address
to security group tag mapping table to network devices for
classification.
3. Which Cisco Firepower preprocessor handles IP fragment
reassembly?
A. Stream5
B. Frag3
C. HTTP Inspect
D. SMTP
Answer: B
Rationale: Frag3 preprocessor performs IP fragment reassembly
and detects fragmentation-based evasion techniques.
4. What is the maximum number of SGTs supported in Cisco
TrustSec?
A. 1024
B. 4096
C. 65536
D. 16777216
,Answer: C
Rationale: Cisco TrustSec uses a 16-bit field allowing up to
65536 security group tags.
5. Which protocol does Cisco ISE use for integration with third-
party security products?
A. RADIUS
B. TACACS+
C. pxGrid
D. SNMP
Answer: C
Rationale: pxGrid is the platform used for integration and
contextual information sharing between Cisco ISE and third-
party products.
6. Which Cisco ISE feature verifies endpoint compliance before
granting network access?
A. Profiling
B. Posture
C. Guest
, D. BYOD
Answer: B
Rationale: Posture assesses endpoints for compliance with
security policies such as antivirus updates and patch levels.
7. In Cisco Firepower, which policy defines how traffic is
inspected by preprocessors?
A. Access control policy
B. Network analysis policy
C. SSL policy
D. Correlation policy
Answer: B
Rationale: Network analysis policies define how preprocessors
inspect traffic for anomalies and evasion techniques.
8. Which EAP method requires certificates on both client and
server?
A. PEAP
B. EAP-FAST
C. EAP-TLS
1. Which Cisco ISE persona is responsible for processing RADIUS
authentication requests?
A. Administration
B. Policy Service
C. Monitoring
D. pxGrid
Answer: B
Rationale: The Policy Service persona handles RADIUS
authentication, authorization, and accounting requests from
network access devices.
2. In Cisco TrustSec, what is the purpose of the environment
data download?
A. To download SGACL policies
B. To download IP-to-SGT mappings
C. To download PAC files
D. To download encryption keys
Answer: B
,Rationale: Environment data download provides the IP address
to security group tag mapping table to network devices for
classification.
3. Which Cisco Firepower preprocessor handles IP fragment
reassembly?
A. Stream5
B. Frag3
C. HTTP Inspect
D. SMTP
Answer: B
Rationale: Frag3 preprocessor performs IP fragment reassembly
and detects fragmentation-based evasion techniques.
4. What is the maximum number of SGTs supported in Cisco
TrustSec?
A. 1024
B. 4096
C. 65536
D. 16777216
,Answer: C
Rationale: Cisco TrustSec uses a 16-bit field allowing up to
65536 security group tags.
5. Which protocol does Cisco ISE use for integration with third-
party security products?
A. RADIUS
B. TACACS+
C. pxGrid
D. SNMP
Answer: C
Rationale: pxGrid is the platform used for integration and
contextual information sharing between Cisco ISE and third-
party products.
6. Which Cisco ISE feature verifies endpoint compliance before
granting network access?
A. Profiling
B. Posture
C. Guest
, D. BYOD
Answer: B
Rationale: Posture assesses endpoints for compliance with
security policies such as antivirus updates and patch levels.
7. In Cisco Firepower, which policy defines how traffic is
inspected by preprocessors?
A. Access control policy
B. Network analysis policy
C. SSL policy
D. Correlation policy
Answer: B
Rationale: Network analysis policies define how preprocessors
inspect traffic for anomalies and evasion techniques.
8. Which EAP method requires certificates on both client and
server?
A. PEAP
B. EAP-FAST
C. EAP-TLS