nerdexam
Huawei

H12-821_V1.0 · Question #827

The firewall at the Diff-Serv domain usually only needs to perform simple traffic classification.

The correct answer is A. TRUE. Option A is correct because Diff-Serv (Differentiated Services) is architecturally designed to push complex, per-flow traffic classification to the ingress edge nodes of the domain. By the time packets traverse the domain firewall, they already carry DSCP (Differentiated…

QoS

Question

The firewall at the Diff-Serv domain usually only needs to perform simple traffic classification.

Options

  • ATRUE
  • BFALSE

How the community answered

(33 responses)
  • A
    82% (27)
  • B
    18% (6)

Explanation

Option A is correct because Diff-Serv (Differentiated Services) is architecturally designed to push complex, per-flow traffic classification to the ingress edge nodes of the domain. By the time packets traverse the domain firewall, they already carry DSCP (Differentiated Services Code Point) markings in their IP headers, so the firewall only needs to read that pre-set field - a simple operation - rather than inspect multiple packet fields to determine traffic class.

Option B is wrong because it contradicts the core design principle of Diff-Serv: complexity is front-loaded at the boundary/ingress, enabling interior nodes (including domain firewalls) to use lightweight, scalable per-hop behaviors (PHBs) instead of expensive stateful or deep-packet inspection.

Memory tip: Think of Diff-Serv as a "stamp-once, read-easily" postal system - the sorting (classification) happens at the post office entrance, so everyone inside just reads the pre-printed label. The firewall is "inside," so it only reads labels.

Topics

#Diff-Serv Architecture#Traffic Classification#QoS#DSCP Marking

Community Discussion

No community discussion yet for this question.

Full H12-821_V1.0 Practice