nerdexam
Cisco

350-701 · Question #760

What is a difference between a zone-based firewall and a Cisco Adaptive Security Appliance firewall?

The correct answer is C. Zone-based firewalls have a default allow-all policy between interfaces in the same zone, and. The key difference between a Zone-Based Firewall (ZBF) and a Cisco Adaptive Security Appliance (ASA) firewall lies in their default traffic policies: Zone-Based Firewalls (ZBF): Used on Cisco routers to segment traffic into zones. Traffic between interfaces within the same zone…

Submitted by amina.ke· Mar 30, 2026Firewall Technologies

Question

What is a difference between a zone-based firewall and a Cisco Adaptive Security Appliance firewall?

Options

  • AZone-based firewalls provide static routing based on interfaces, and Cisco Adaptive Security
  • BZone-based firewalls support virtual tunnel interfaces across different locations, and Cisco
  • CZone-based firewalls have a default allow-all policy between interfaces in the same zone, and
  • DZone-based firewalls are used in large deployments with multiple areas, and Cisco Adaptive

How the community answered

(25 responses)
  • B
    4% (1)
  • C
    92% (23)
  • D
    4% (1)

Explanation

The key difference between a Zone-Based Firewall (ZBF) and a Cisco Adaptive Security Appliance (ASA) firewall lies in their default traffic policies: Zone-Based Firewalls (ZBF): Used on Cisco routers to segment traffic into zones. Traffic between interfaces within the same zone is allowed by default unless explicitly denied. Cisco Adaptive Security Appliance (ASA): A dedicated firewall appliance that applies more granular security policies. ASA enforces a default deny-all policy for traffic unless explicitly permitted by access control

Topics

#Zone-based firewall#Cisco ASA#Firewall concepts#Firewall comparison

Community Discussion

No community discussion yet for this question.

Full 350-701 Practice