Implementing Cisco IOS Zone-Based Firewalls Flashcards

1
Q

Which zone is implied by default and does not need to be manually created?

A

Self

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

If interface number 1 is in zone A, and interface number 2 is in zone B, and there are no policy or service commands applied yet to the configuration, what is the status of transit traffic that is being routed between these two interfaces?

A

Denied

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

When creating a specific zone pair and applying a policy to it, the policy is being implemented on initial traffic in how many directions?

A

1

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What is the default policy between an administratively created zone and the self zone?

A

Permit

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What is one of the added configuration elements that the Advanced security setting has in the ZBF Wizard that is not included in the Low security setting?

A

Filtering on peer-to-peer networking applications

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Why is it that the return traffic, from previously inspected sessions, is allowed back to the user, in spite of not having a zone pair explicitly configured that matches on the return traffic?

A

Stateful entries (from the initial flow) are matched, which dynamically allows return traffic

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What does the keyword OVERLOAD imply in a NAT configuration?

A

PAT is being used

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What command shows the current NAT translations on the router?

A

show ip nat translations

How well did you know this?
1
Not at all
2
3
4
5
Perfectly