300-415 · Question #310
Which component is used for stateful inspection of TCP, UDP, and ICMP flows in Cisco SD-WAN firewall policies?
The correct answer is D. zones. In Cisco SD-WAN firewall policies, zones are the component used for stateful inspection of TCP, UDP, and ICMP flows, defining security boundaries for policy application.
Question
Exhibit
Options
- Asubnets
- Bsites
- Cinterfaces
- Dzones
How the community answered
(15 responses)- B7% (1)
- C7% (1)
- D87% (13)
Why each option
In Cisco SD-WAN firewall policies, zones are the component used for stateful inspection of TCP, UDP, and ICMP flows, defining security boundaries for policy application.
Subnets define IP address ranges, which can be part of a zone, but they are not the component that performs stateful inspection itself.
Sites represent physical locations; while firewall policies apply across sites, sites are not the granular component for stateful inspection of individual traffic flows.
Interfaces are endpoints where traffic enters or leaves a device and are assigned to zones, but the stateful inspection logic and policy enforcement are applied at the zone level.
Cisco SD-WAN firewall policies employ security zones to logically group interfaces or subnets, allowing stateful inspection rules to be applied between these zones to control and monitor TCP, UDP, and ICMP traffic flows based on their session state.
Concept tested: Cisco SD-WAN firewall zones
Source: https://www.cisco.com/c/en/us/td/docs/routers/sdwan/configuration/security/sdwan-security-book/sdwan-firewall.html
Topics
Community Discussion
No community discussion yet for this question.
