Practice Exam 1
5 of this form’s 60 questions, drawn from across its domains, free. The explanation on every one of them is free too, at every tier, and always will be.
Question 1 of 5
ipsec-architecture-sasSecurity ConceptsAn engineer builds an IPsec SA between a host and a security gateway that forwards traffic for a protected network. Which mode does the architecture require?
Question 2 of 5
asa-access-rulesNetwork SecurityAn engineer permits outbound TCP through an ASA and asks whether a matching rule is needed for the replies. What does the ASA require?
Question 3 of 5
aws-iam-policy-typesSecuring the CloudA team creates a VPC endpoint and attaches no endpoint policy to it. What access does the endpoint allow?
Question 4 of 5
defender-next-generation-protectionEndpoint Protection and DetectionAn analyst finds Defender blocking an application that no signature identifies as malware. Which capability accounts for that?
Question 5 of 5
ise-external-admin-accessSecure Network Access, Visibility, and EnforcementAn engineer picks RADIUS Token as the password-based identity source for the ISE admin portal. What becomes unavailable?
0 of 60 completed
The other 55 questions are the rest of this form: same 120 minute clock, same 750 cut score, and the same explanation on every question, which is never behind the wall. Practice Exam 1 of 2 on CCNP Security.
What this exam covers
- Security Concepts15 questions / 25% of the exam
- Network Security12 questions / 20% of the exam
- Securing the Cloud9 questions / 15% of the exam
- Content Security6 questions / 10% of the exam
- Endpoint Protection and Detection9 questions / 15% of the exam
- Secure Network Access, Visibility, and Enforcement9 questions / 15% of the exam
Checking what you already have access to.
Every question is original, written from the published objectives. We never reproduce, paraphrase, or imitate real exam content, and neither should anything else you study from.