350-701 · Question #675
Which key feature of Cisco ZFW is unique among other Cisco IOS firewall solutions?
The correct answer is D. security zones. Cisco Zone-Based Firewall (ZFW) uniquely employs security zones to group interfaces, controlling traffic flow based on policies between these zones rather than interface-specific access lists or security levels.
Question
Which key feature of Cisco ZFW is unique among other Cisco IOS firewall solutions?
Options
- ASSL inspection
- Bsecurity levels
- Cstateless inspection
- Dsecurity zones
How the community answered
(53 responses)- A2% (1)
- B4% (2)
- C2% (1)
- D92% (49)
Why each option
Cisco Zone-Based Firewall (ZFW) uniquely employs security zones to group interfaces, controlling traffic flow based on policies between these zones rather than interface-specific access lists or security levels.
SSL inspection (or decryption/re-encryption) is a capability found in various modern Cisco security solutions, including other firewalls and security appliances, not unique to ZFW.
The concept of security levels (e.g., higher security levels can access lower security levels by default) is primarily associated with Cisco ASA firewalls, not IOS firewalls, and certainly not unique to ZFW within the IOS firewall family.
Stateless inspection, while a fundamental concept in networking, is generally avoided for robust firewalls, and most modern Cisco IOS firewalls, including ZFW, employ stateful inspection for security.
Cisco Zone-Based Firewall (ZFW) introduced the concept of security zones to Cisco IOS, where interfaces are assigned to zones, and policies are applied to traffic *between* zones. This zone-based approach fundamentally differs from traditional IOS firewalls that rely on interface-based access control lists (ACLs) or stateful inspection on individual interfaces without the zone abstraction.
Concept tested: Cisco Zone-Based Firewall architecture
Source: https://www.cisco.com/c/en/us/support/docs/security/ios-firewall/60211-zone-fwall.html
Topics
Community Discussion
No community discussion yet for this question.