nerdexam
CiscoCisco

200-301 · Question #291

200-301 Question #291: Real Exam Question with Answer & Explanation

The correct answer is A: firewall. A firewall is a network security device that monitors and filters incoming and outgoing network traffic based on predefined security rules.

Submitted by jakub_pl· Mar 5, 2026Security Fundamentals

Question

Which device permits or denies network traffic based on a set of rules?

Options

  • Afirewall
  • Bswitch
  • Caccess point
  • Dwireless controller

Explanation

A firewall is a network security device that monitors and filters incoming and outgoing network traffic based on predefined security rules.

Common mistakes.

  • B. A switch operates at Layer 2 (data link layer) and forwards traffic based on MAC addresses within a local network segment, without inspecting or filtering based on higher-layer rules.
  • C. An access point connects wireless devices to a wired network and primarily handles wireless connectivity and Layer 2 forwarding, not policy-based traffic filtering.
  • D. A wireless controller centrally manages access points and their configurations, but it does not directly perform packet filtering based on security rules like a firewall.

Concept tested. Firewall function

Reference. https://learn.microsoft.com/en-us/windows/security/threat-protection/windows-firewall/windows-firewall-with-advanced-security-overview

Topics

#firewall#network security#traffic filtering#access control

Community Discussion

No community discussion yet for this question.

Full 200-301 PracticeBrowse All 200-301 Questions