Perimeter Security and Intrusion Prevention for CCIE Security Written v5.0 (400-251)
This page covers the Perimeter Security and Intrusion Prevention domain of the CCIE Security Written v5.0 (400-251) certification. Master Cybersecurity offers 54 practice questions in this domain, drawn from the same content we use across our timed exam simulations. Below are five sample questions with full answer explanations.
Sample Practice Questions
Question 1
Which two address translation types can map a group of private addresses to a smaller group of public addresses? (Choose two.)- A. static NAT
- B. dynamic NAT
- C. dynamic NAT with overloading
- D. PAT
- E. VAT
Explanation
The correct answers are: C. dynamic NAT with overloading, D. PAT.
Mapping many private hosts onto fewer public addresses requires port multiplexing, and that is what overloading and Port Address Translation do; on IOS the feature is enabled by appending the overload keyword to ip nat inside source list, while the same mechanism is called PAT on the ASA. Each entry in the translation table is keyed on the inside local address and port together with the inside global address and port, so one public address can carry thousands of simultaneous sessions by handing out distinct source ports from the high range, and the device rewrites that port on the way out and reverses the rewrite on the way back. Static NAT is a permanent one-to-one binding created per host, so it consumes exactly as many public addresses as it serves and offers no compression at all. Dynamic NAT without overloading draws one-to-one bindings from a pool for the life of a session, which means the pool must be at least as large as the number of hosts needing simultaneous access, and once it is exhausted further hosts simply fail. There is no translation type called VAT.
Question 2
When configuring a Cisco IPS custom signature, what type of signature engine must you use to block podcast clients from accessing the network?- A. service HTTP
- B. service TCP
- C. string TCP
- D. fixed TCP
- E. service GENERIC
Explanation
The correct answer is: A. service HTTP.
Blocking a podcast client means identifying it by the HTTP User-Agent string it sends, and only the Service HTTP engine gives a custom signature named regular expression fields for the individual pieces of an HTTP transaction. That engine parses a request into URI, argument, header and body regex fields, applies de-obfuscation so percent-encoded and otherwise disguised characters are normalised before matching, and lets you bound the search with maximum field lengths, which is what makes a header match on an application name both possible and dependable. Service TCP is a generic engine for TCP protocols the specialised engines do not cover and has no notion of HTTP fields. String TCP can run a regular expression across a reassembled TCP stream, but with no HTTP normalisation or field awareness it is easy to evade with encoding tricks and it burns cycles scanning the whole flow. There is no fixed TCP engine in the sensor. Service Generic exists for hand-crafted decoding of protocols that have no dedicated engine and is intended for signatures Cisco authors itself rather than for routine custom work.
Question 3
Which multicast capability is not supported by the Cisco ASA appliance?- A. ASA configured as a rendezvous point
- B. Sending multicast traffic across a VPN tunnel
- C. NAT of multicast traffic
- D. IGMP forwarding (stub) mode
Explanation
The correct answer is: B. Sending multicast traffic across a VPN tunnel.
The ASA implements a useful subset of multicast: it can act as a PIM sparse mode router with a statically configured rendezvous point, it supports the simpler IGMP stub forwarding mode in which it proxies host membership reports toward the multicast router instead of running PIM, and it can translate multicast traffic with NAT. What it cannot do is carry multicast traffic natively inside a site to site IPsec VPN tunnel. IPsec tunnel mode as used by the ASA encrypts unicast IP between the two peer addresses, and there is no multicast security association or group key mechanism on the platform, so a multicast packet handed to the crypto engine has no matching tunnel. The standard workaround is to build a GRE tunnel between routers behind the firewalls and encrypt the resulting unicast GRE stream, or to use a router based design such as GETVPN or multicast enabled DMVPN where the group and tunnel semantics are handled properly. Rendezvous point operation, NAT of multicast, and IGMP stub mode are all documented ASA capabilities, so each of those is a supported feature rather than the exception the question asks for.
Question 4
Refer to the exhibit. What type of attack is being mitigated on the Cisco ASA appliance?- A. HTTPS certificate man-in-the-middle attack
- B. HTTP distributed denial of service attack
- C. HTTP Shockwave Flash exploit
- D. HTTP SQL injection attack
Explanation
The correct answer is: D. HTTP SQL injection attack.
The exhibit defines regular expressions that look for the strings UNION SELECT and SELECT followed by FROM, and applies them through HTTP inspection to the body of requests crossing the ASA. Those patterns are SQL fragments, not web content, so their presence in a request parameter means a client is trying to append its own database query to one the application intended to run; UNION SELECT in particular is the standard technique for grafting an attacker chosen result set onto a legitimate query in order to read arbitrary tables. Matching them in the request body and dropping or resetting the connection is therefore mitigation of an HTTP SQL injection attack. The other choices point at different mechanisms entirely. Certificate based interception concerns TLS trust and cannot be seen by a regex on cleartext body content. A distributed denial of service is a volumetric or connection rate problem, addressed with embryonic connection limits or TCP intercept rather than payload patterns. A Shockwave Flash exploit would be identified by content type or file signature, since its indicators live in the object being downloaded, not in a SQL keyword pair.
Question 5
Which method of output queuing is supported on the Cisco ASA appliance?- A. CBWFQ
- B. priority queuing
- C. MDRR
- D. WFQ
- E. custom queuing
Explanation
The correct answer is: B. priority queuing.
The appliance implements low latency queuing, which means each interface has just two transmit queues: a strict priority queue serviced first and a best-effort queue for everything else. It is enabled per interface with priority-queue outside, tuned with queue-limit and tx-ring-limit, and traffic is steered into it by a Modular Policy Framework class carrying the priority action, which is how latency-sensitive flows such as voice and the control traffic of a tunnel group are protected. Alongside that the appliance offers policing and, in later releases, traffic shaping, but it deliberately keeps the scheduler simple. Class-based weighted fair queuing and weighted fair queuing are IOS software disciplines that build a queue per configured class or per flow with bandwidth guarantees, and they are not implemented on the firewall. Modified deficit round robin belongs to high-end platforms such as the 12000 series and CRS, where it schedules across hardware queues. Custom queuing is a legacy IOS mechanism that serves a fixed byte count from each of up to sixteen queues in rotation.
Other CCIE Security Written v5.0 (400-251) domains
- Advanced Threat Protection and Content Security (10 questions)
- Identity Management, Information Exchange, and Access Control (33 questions)
- Infrastructure Security, Virtualization, and Automation (145 questions)
- Secure Connectivity and Segmentation (87 questions)