nerdexam
Cisco

200-301 · Question #712

Which two statements about firewalls are true ?

The correct answer is A. They can be used with an intrusion prevention system B. They can limit unauthorized user access to protect data. Firewalls serve to control network traffic based on predefined rules, limiting unauthorized access and protecting data by blocking malicious or unwanted connections. They are often deployed in conjunction with other security solutions, such as intrusion prevention systems, for co

Submitted by yuriko_h· Mar 5, 2026

Question

Which two statements about firewalls are true ?

Options

  • AThey can be used with an intrusion prevention system
  • BThey can limit unauthorized user access to protect data
  • CEach wireless access point requires its own firewall
  • DThey must be placed only at locations where the private network connects to the internet
  • EThey can prevent attacks from the internet only

How the community answered

(31 responses)
  • A
    94% (29)
  • C
    3% (1)
  • D
    3% (1)

Why each option

Firewalls serve to control network traffic based on predefined rules, limiting unauthorized access and protecting data by blocking malicious or unwanted connections. They are often deployed in conjunction with other security solutions, such as intrusion prevention systems, for comprehensive defense.

AThey can be used with an intrusion prevention systemCorrect

Firewalls often complement intrusion prevention systems (IPS) by providing initial packet filtering, while an IPS delves deeper into packet content to detect and prevent sophisticated attacks. This layered security approach enhances overall network protection.

BThey can limit unauthorized user access to protect dataCorrect

Firewalls achieve their primary function by enforcing access control policies, inspecting traffic, and blocking connections that do not meet specified security rules, thereby protecting internal network resources and data from unauthorized access.

CEach wireless access point requires its own firewall

Not every wireless access point requires its own dedicated firewall; network firewalls typically protect the entire network segment or perimeter where WAPs reside.

DThey must be placed only at locations where the private network connects to the internet

Firewalls can be placed at various points within a network, including internal network segments (internal firewalls) and between different zones (e.g., DMZ), not just at the internet perimeter.

EThey can prevent attacks from the internet only

Firewalls can prevent attacks originating from internal networks, between different internal segments, or from external sources like the internet, not exclusively from the internet.

Concept tested: Firewall functions and deployment

Source: https://www.cisco.com/c/en/us/products/security/firewalls/what-is-a-firewall.html

Topics

#firewalls#network security#IPS integration

Community Discussion

No community discussion yet for this question.

Full 200-301 Practice