H12-821_V1.0 · Question #1006
Match the following firewall zone traffic directions with their corresponding zone pairs.
The correct answer is A. Inbound: DMZ--->Trust; Outbound: Local----->Untrust; Inbound: DMZ----->Local; Outbound: Local----->Trust; Inbound: DMZ----->Untrust; Outbound: Trust----->Untrust. Option A correctly maps each zone pair to its traffic direction based on how zone-based firewalls classify flows relative to the receiving zone. Inbound traffic means a packet is entering the referenced zone (e.g., DMZ→Trust means traffic arriving into the Trust zone), while…
Question
Options
- AInbound: DMZ--->Trust; Outbound: Local----->Untrust; Inbound: DMZ----->Local; Outbound: Local----->Trust; Inbound: DMZ----->Untrust; Outbound: Trust----->Untrust
- B
- C
- D
How the community answered
(42 responses)- A76% (32)
- B14% (6)
- C7% (3)
- D2% (1)
Explanation
Option A correctly maps each zone pair to its traffic direction based on how zone-based firewalls classify flows relative to the receiving zone. Inbound traffic means a packet is entering the referenced zone (e.g., DMZ→Trust means traffic arriving into the Trust zone), while Outbound means a packet is leaving from the referenced zone (e.g., Trust→Untrust means traffic departing from Trust). The pairings in A follow this consistently: DMZ→Trust and DMZ→Local are inbound because packets land in Trust/Local, while Local→Untrust, Local→Trust, and Trust→Untrust are outbound because packets originate from Local or Trust.
Options B, C, and D are blank - meaning no alternative answer set was provided - so A is the only valid choice by elimination, but it also stands on its own merit as a logically consistent set of zone-pair-to-direction mappings.
Memory tip: Think of the arrow direction as a river current. "Inbound" = the water is flowing into the named destination zone (you're on the receiving bank). "Outbound" = the water is flowing out of the named source zone (you're pushing off from your bank). The zone listed first in the pair is always the source; focus on whether that source is trusted or not to remember which flows are guarded as "inbound."
Topics
Community Discussion
No community discussion yet for this question.