H12-725_V4.0 · Question #174
Which of the following conditions can be matched by policy routing? (Multiple choice)
The correct answer is A. Source safe zone C. Source IP address D. Application. Policy routing matches traffic based on Layer 3 and above criteria, plus zone-level constructs on security-aware devices. Source safe zone (A) is valid because firewalls and security gateways (such as Huawei USG devices) use security zones as a fundamental traffic…
Question
Which of the following conditions can be matched by policy routing? (Multiple choice)
Options
- ASource safe zone
- BSource MAC address
- CSource IP address
- DApplication
How the community answered
(29 responses)- A76% (22)
- B24% (7)
Explanation
Policy routing matches traffic based on Layer 3 and above criteria, plus zone-level constructs on security-aware devices. Source safe zone (A) is valid because firewalls and security gateways (such as Huawei USG devices) use security zones as a fundamental traffic classification unit, and policy routing can use the ingress zone as a match condition. Source IP address (C) is the classic policy-based routing (PBR) match condition - routing decisions are made per-source rather than per-destination. Application (D) is valid in modern application-aware or intelligent routing systems that use deep packet inspection (DPI) to identify traffic and apply routing policies accordingly.
Source MAC address (B) is wrong because MAC addresses are a Layer 2 construct - they are rewritten at each hop and are not visible or meaningful at the Layer 3 routing decision point where policy routing operates.
Memory tip: Think "Layer 3 and above, plus zone" - policy routing lives at the IP layer and higher, so anything below IP (like MAC addresses at Layer 2) is off the table. If you remember that modern policy routing is zone-aware and application-aware in addition to IP-aware, the three correct answers fall naturally into place.
Topics
Community Discussion
No community discussion yet for this question.