Practice Exam 2
5 of this form’s 60 questions, drawn from across its domains, free. The explanation on every one of them is free too, at every tier, and always will be.
Question 1 of 5
ipsec-and-isakmp-on-asaSecurity ConceptsAn engineer configures one IKEv2 policy on an ASA with several encryption and integrity algorithms. In what order does the ASA negotiate them with the peer?
Question 2 of 5
asa-access-rulesNetwork SecurityOn an ASA, when does same-security-level checking happen relative to access rules?
Question 3 of 5
aws-iam-policy-typesSecuring the CloudAn engineer gives a role an identity-based policy allowing S3 writes and a permissions boundary that omits S3. What can the role do?
Question 4 of 5
defender-next-generation-protectionEndpoint Protection and DetectionAn organization needs blocking of a threat first seen minutes ago elsewhere in the world. Which capability delivers that?
Question 5 of 5
ise-external-admin-accessSecure Network Access, Visibility, and EnforcementA team sets up ISE administrator authentication against RSA SecurID with internal authorization. What must exist in both places?
0 of 60 completed
The other 55 questions are the rest of this form: same 120 minute clock, same 750 cut score, and the same explanation on every question, which is never behind the wall. Practice Exam 2 of 2 on CCNP Security.
What this exam covers
- Security Concepts15 questions / 25% of the exam
- Network Security12 questions / 20% of the exam
- Securing the Cloud9 questions / 15% of the exam
- Content Security6 questions / 10% of the exam
- Endpoint Protection and Detection9 questions / 15% of the exam
- Secure Network Access, Visibility, and Enforcement9 questions / 15% of the exam
Checking what you already have access to.
Every question is original, written from the published objectives. We never reproduce, paraphrase, or imitate real exam content, and neither should anything else you study from.