300-415 · Question #281
What are the components of zone configuration in an application-aware firewall?
The correct answer is D. source zone, destination zone, and zone pair. The fundamental components of zone configuration in an application-aware firewall are source zones, destination zones, and zone pairs.
Question
Options
- Adestination zone, interface zone, source zone, and zone pair
- Bsource zone, interface zone, and zone pair
- Cdestination zone, interface zone, and zone pair
- Dsource zone, destination zone, and zone pair
How the community answered
(29 responses)- A3% (1)
- B7% (2)
- D90% (26)
Why each option
The fundamental components of zone configuration in an application-aware firewall are source zones, destination zones, and zone pairs.
"interface zone" is not a standard, distinct component of zone configuration in the same way source, destination, and zone pairs are; interfaces are assigned to zones, but "interface zone" itself is not a primary component.
This option omits the "destination zone," which is a critical part of defining a traffic flow in a zone pair.
This option omits the "source zone," which is a critical part of defining a traffic flow in a zone pair.
In a zone-based firewall, security policies are applied to traffic as it moves between defined security zones. The core components are source zones (where traffic originates), destination zones (where traffic is intended to go), and zone pairs (which define the directional flow between a source and destination zone, to which policies are then attached).
Concept tested: Zone-based firewall components
Source: https://www.cisco.com/c/en/us/td/docs/routers/sdwan/configuration/sdwan-xe-gs-cr-book/security-overview.html
Topics
Community Discussion
No community discussion yet for this question.