Infrastructure Security, Virtualization, and Automation for CCIE Security Written v5.0 (400-251)

This page covers the Infrastructure Security, Virtualization, and Automation domain of the CCIE Security Written v5.0 (400-251) certification. Master Cybersecurity offers 145 practice questions in this domain, drawn from the same content we use across our timed exam simulations. Below are five sample questions with full answer explanations.

Sample Practice Questions

  1. Question 1

    In an 802.11 WLAN, which option is the Layer 2 identifier of a basic service set, and also is typically the MAC address of the radio of the access point?
    1. A. BSSID
    2. B. SSID
    3. C. VBSSID
    4. D. MBSSID
    Explanation

    The correct answer is: A. BSSID.

    The basic service set identifier is the 48-bit Layer 2 value that names one basic service set, and in an infrastructure network it is normally the MAC address of the radio in the access point serving that cell. Every 802.11 management and data frame carries it in an address field, so clients and analyzers use it to tell apart two cells that share the same network name and to follow a roam from one cell to another. Because it is a MAC address, it is also what a wired-side lookup or a rogue containment action keys on. The service set identifier is something different: a human-readable network name of up to 32 octets, advertised in beacons and probe responses, which can be identical on hundreds of access points and therefore cannot identify a specific cell. Multiple BSSID is the capability that lets one radio host several service sets at once, each mapped to its own VLAN and its own derived BSSID, usually by incrementing the base radio address, so the term names the feature rather than the identifier itself. VBSSID is not a standard 802.11 identifier and appears only informally when describing virtualised access point instances.

  2. Question 2

    What term describes an access point which is detected by your wireless network, but is not a trusted or managed access point?
    1. A. rogue
    2. B. unclassified
    3. C. interferer
    4. D. malicious
    Explanation

    The correct answer is: A. rogue.

    In wireless terminology a rogue access point is any 802.11 device heard by the managed infrastructure that is not part of it and is not authorised: an employee plugging a consumer AP into a wall port, a phone acting as a hotspot, an attacker's honeypot with a matching network name, or simply a neighbour's AP bleeding into the coverage area. Managed access points detect these while off-channel scanning and report the observed identifiers back to the controller, which maintains them as rogue entries. Classification then happens as a second step on top of that state: rules and manual action mark a rogue as friendly when it is known and accepted, malicious when it matches conditions such as advertising a corporate network name or being seen on the wire, or unclassified when no rule has yet matched, which is the default landing state rather than the general term. Containment or wired-side location tracking follows from that classification. An interferer is a different concept entirely, describing a non-802.11 energy source such as a microwave oven, video bridge or Bluetooth device identified by spectrum analysis, which degrades the channel without ever being an access point at all.

  3. Question 3

    A router has four interfaces addressed as 10.1.1.1/24, 10.1.2.1/24, 10.1.3.1/24, and 10.1.4.1/24. What is the smallest summary route that can be advertised covering these four subnets?
    1. A. 10.1.2.0/22
    2. B. 10.1.0.0/22
    3. C. 10.1.0.0/21
    4. D. 10.1.0.0/16
    Explanation

    The correct answer is: C. 10.1.0.0/21.

    Summarization only works on bit boundaries, so the mask has to be short enough that every value in the range falls inside a single block. The four subnets use third-octet values 1, 2, 3 and 4. A /22 groups the third octet into blocks of four that must start on a multiple of four: 0-3, 4-7, 8-11, and so on. That makes 10.1.0.0/22 cover 10.1.0.0 through 10.1.3.255 only, leaving 10.1.4.0/24 unadvertised, which is why it looks close but fails. A /22 starting at 10.1.2.0 is not even a legal block, since 2 is not a multiple of four; the mask would resolve back to the 10.1.0.0 block anyway. Shifting one more bit left produces a /21, whose blocks are eight wide, so 10.1.0.0/21 spans 10.1.0.0 through 10.1.7.255 and contains all four subnets. That is the longest prefix, and therefore the smallest address block, that still covers everything. A /16 also covers them but pulls in 10.1.5.0 through 10.1.255.0 as well, attracting or black-holing traffic for space the router does not own, so it is not the smallest valid summary.

  4. Question 4

    Which authentication mechanism is available to OSPFv3?
    1. A. simple passwords
    2. B. MD5
    3. C. null
    4. D. IKEv2
    5. E. IPsec AH/ESP
    Explanation

    The correct answer is: E. IPsec AH/ESP.

    OSPFv3 relies on IPsec Authentication Header or Encapsulating Security Payload rather than any authentication field of its own. When OSPF was adapted for IPv6, the AuType and Authentication fields present in the OSPFv2 header were removed, so protocol packets carry no credential; RFC 4552 instead specifies that OSPFv3 protection is delivered by IPv6 IPsec applied to protocol number 89, using manually keyed security associations because there is no way to run an IKE negotiation before an adjacency exists. On IOS this appears as ipv6 ospf authentication ipsec spi with a key, or ipv6 ospf encryption ipsec spi for confidentiality as well as integrity. Simple passwords and MD5 keyed digests are the OSPFv2 mechanisms carried in that removed header field, and null authentication is the OSPFv2 AuType 0 meaning no authentication at all. IKEv2 is a key management protocol used to build IPsec SAs for data traffic and is not used to key OSPFv3 adjacencies. Later releases add an OSPFv3 authentication trailer per RFC 7166 as a lighter alternative to full IPsec.

  5. Question 5

    Which two IPv6 tunnel types support only point-to-point communication? (Choose two.)
    1. A. manually configured
    2. B. automatic 6to4
    3. C. ISATAP
    4. D. GRE
    Explanation

    The correct answers are: A. manually configured, D. GRE.

    A manually configured IPv6-in-IPv4 tunnel and a GRE tunnel are both point-to-point by construction. In each case the administrator writes an explicit tunnel source and a single tunnel destination, so the encapsulating header always carries one fixed pair of IPv4 endpoints and the tunnel behaves like a leased line with a routable IPv6 link on top of it. That is what allows a routing protocol such as OSPFv3 or IS-IS to form a normal adjacency across it, and it is also why one tunnel interface is needed per remote site. Automatic 6to4 and ISATAP are the opposite: they are point-to-multipoint, non-broadcast interfaces. A 6to4 tunnel uses the 2002::/16 prefix defined in RFC 3056 and derives the destination IPv4 address at forwarding time from bits 16 to 47 of the destination IPv6 address, so one tunnel interface reaches every 6to4 peer without a configured destination. ISATAP embeds the IPv4 address in the low-order 32 bits of an interface identifier of the form 0000:5efe:a.b.c.d and treats the IPv4 network as a single NBMA link, again with no tunnel destination command.

Other CCIE Security Written v5.0 (400-251) domains

Practice all 145 Infrastructure Security, Virtualization, and Automation questions · Browse CCIE Security Written v5.0 (400-251)