Which two rules about interfaces are valid when implementing a Zone-Based Policy Firewall? (Choose two.)
- If one interface is a zone member, but the other is not, all traffic will be passed.
- If neither interface is a zone member, then the action is to pass traffic.
- If both interfaces are members of the same zone, all traffic will be passed.
- If one interface is a zone member and a zone-pair exists, all traffic will be passed.
- If both interfaces belong to the same zone-pair and a policy exists, all traffic will be passed.
Explanation: The rules for traffic transiting through the router are as follows:
If neither interface is a zone member, then the resulting action is to pass the traffic.
If both interfaces are members of the same zone, then the resulting action is to pass the traffic.
If one interface is a zone member, but the other is not, then the resulting action is to drop the traffic regardless of whether a zone-pair exists.
If both interfaces belong to the same zone-pair and a policy exists, then the resulting action is inspect, allow, or drop as defined by the policy.
Exam with this question: CCNA Security Chapter 4 Exam Answers
Exam with this question: Network Security ( Version 1) - Network Security 1.0 Modules 8-10: ACLs and Firewalls Group Exam Answers
Please login or Register to submit your answer