Cisco CCIE Security Practice Test Exam
1. Which Cisco ISE node type is responsible for handling
authentication requests in a distributed deployment?
A. Administration Node
B. Policy Service Node
C. Monitoring Node
D. pxGrid Node
Answer: B
Rationale: The Policy Service Node handles authentication,
authorization, and accounting requests from network access
devices.
2. What is the maximum number of security group tags
supported in Cisco TrustSec?
A. 1024
B. 4096
C. 65536
D. 16777216
Answer: C
,Rationale: Cisco TrustSec supports up to 65536 security group
tags using a 16-bit field.
3. Which protocol does Cisco ISE use for integration with threat
defense systems?
A. RADIUS
B. TACACS+
C. pxGrid
D. SNMP
Answer: C
Rationale: pxGrid is used for integration and information
sharing between Cisco ISE and threat defense systems.
4. In Cisco Firepower, which preprocessor is responsible for TCP
stream reassembly?
A. Stream5
B. Frag3
C. HTTP Inspect
D. SMTP Preprocessor
Answer: A
,Rationale: Stream5 preprocessor handles TCP stream
reassembly and state tracking in Snort.
5. Which Cisco ISE deployment model supports high availability
across geographically dispersed locations?
A. Standalone
B. Distributed
C. Hybrid
D. Cloud
Answer: B
Rationale: A distributed deployment model supports high
availability and scalability across multiple locations.
6. What is the purpose of Cisco TrustSec environment data
download?
A. Download security group tags
B. Download IP address mappings
C. Download encryption keys
D. Download routing tables
Answer: B
, Rationale: Environment data download provides IP address to
security group tag mappings to network devices.
7. Which Cisco Firepower feature allows inspection of
encrypted traffic without decryption?
A. SSL policy
B. Encrypted Traffic Analytics
C. Access control policy
D. NAT policy
Answer: B
Rationale: Encrypted Traffic Analytics uses machine learning to
detect threats in encrypted traffic without decryption.
8. Which Cisco ISE feature allows dynamic VLAN assignment?
A. Authorization policy
B. Posture policy
C. Profiling policy
D. Guest policy
Answer: A
1. Which Cisco ISE node type is responsible for handling
authentication requests in a distributed deployment?
A. Administration Node
B. Policy Service Node
C. Monitoring Node
D. pxGrid Node
Answer: B
Rationale: The Policy Service Node handles authentication,
authorization, and accounting requests from network access
devices.
2. What is the maximum number of security group tags
supported in Cisco TrustSec?
A. 1024
B. 4096
C. 65536
D. 16777216
Answer: C
,Rationale: Cisco TrustSec supports up to 65536 security group
tags using a 16-bit field.
3. Which protocol does Cisco ISE use for integration with threat
defense systems?
A. RADIUS
B. TACACS+
C. pxGrid
D. SNMP
Answer: C
Rationale: pxGrid is used for integration and information
sharing between Cisco ISE and threat defense systems.
4. In Cisco Firepower, which preprocessor is responsible for TCP
stream reassembly?
A. Stream5
B. Frag3
C. HTTP Inspect
D. SMTP Preprocessor
Answer: A
,Rationale: Stream5 preprocessor handles TCP stream
reassembly and state tracking in Snort.
5. Which Cisco ISE deployment model supports high availability
across geographically dispersed locations?
A. Standalone
B. Distributed
C. Hybrid
D. Cloud
Answer: B
Rationale: A distributed deployment model supports high
availability and scalability across multiple locations.
6. What is the purpose of Cisco TrustSec environment data
download?
A. Download security group tags
B. Download IP address mappings
C. Download encryption keys
D. Download routing tables
Answer: B
, Rationale: Environment data download provides IP address to
security group tag mappings to network devices.
7. Which Cisco Firepower feature allows inspection of
encrypted traffic without decryption?
A. SSL policy
B. Encrypted Traffic Analytics
C. Access control policy
D. NAT policy
Answer: B
Rationale: Encrypted Traffic Analytics uses machine learning to
detect threats in encrypted traffic without decryption.
8. Which Cisco ISE feature allows dynamic VLAN assignment?
A. Authorization policy
B. Posture policy
C. Profiling policy
D. Guest policy
Answer: A