PCNSE · Question #369
An administrator wants to enable zone protection. Before doing so, what must the administrator consider?
The correct answer is D. The zone protection profile will apply to all interfaces within that zone. A zone protection profile is applied at the zone level, not the interface level. This means every interface assigned to that zone will be subject to the same zone protection settings (flood protection, reconnaissance protection, packet-based attack protection, etc.). Before…
Question
An administrator wants to enable zone protection. Before doing so, what must the administrator consider?
Options
- AActivate a zone protection subscription.
- BTo increase bandwidth no more than one firewall interface should be connected to a zone
- CSecurity policy rules do not prevent lateral movement of traffic between zones
- DThe zone protection profile will apply to all interfaces within that zone
How the community answered
(41 responses)- B5% (2)
- C2% (1)
- D93% (38)
Explanation
A zone protection profile is applied at the zone level, not the interface level. This means every interface assigned to that zone will be subject to the same zone protection settings (flood protection, reconnaissance protection, packet-based attack protection, etc.). Before enabling zone protection, the administrator must confirm the profile settings are appropriate for all interfaces in the zone. (A) Zone protection is a built-in feature requiring no additional subscription. (B) Multiple interfaces can and commonly do belong to a single zone. (C) Is incorrect as stated - Security policy rules absolutely do govern traffic flow between zones; inter-zone traffic is denied by default unless explicitly allowed.
Topics
Community Discussion
No community discussion yet for this question.