Module 10 Flashcards

1
Q

Step 1 of designing a ZPF

A

Determine the zones

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Step 2 of designing a ZPF

A

Establish policies between zones

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Step 3 of designing a ZPF

A

Design the physical infrastructure

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Step 4 of designing a ZPF

A

Identify subsets within zones and merge traffic requirements

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Are ZPFs dependent on ACLs? (benefit)

A

No

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What is Cisco Common Classification Policy Language (C3PL)? (benefit)

A

A structured method to create traffic policies based on events, conditions, and actions

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What does C3PL provide? (benefit)

A

Scalability

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

How does C3PL provide scalability? (benefit)

A

One policy affects any given traffic, instead of needing multiple ACLs and inspection actions for different types of traffic

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What can be grouped into zones? (benefit)

A

Virtual and physical interfaces

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What are policies applied to? (benefit)

A

Unidirectional traffic between zones

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What does the action ‘inspect’ do?

A

Performs Cisco IOS stateful packet inspection

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

What does the action ‘drop’ do?

A

Similar to deny statement in an ACL. Log option is available to log the rejected packets

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

What does the action ‘pass’ do?

A

Similar to permit statement in an ACL. Pass action does not track the state of connections or sessions within the traffic

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

Neither interface is a zone member. (inspect, drop, pass)

A

Traffic passes

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

Both interfaces are members of the same zone. (inspect, drop, pass)

A

Passes because they are both members

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

One interface is a zone member, but the other is not. (inspect, drop, pass)

A

Drop regardless of whether a zone-pair exists

17
Q

Both interfaces belong to the same zone-pair and a policy exists. (inspect, drop, pass)

A

Inspect, allow, or drop as defined by the policy

18
Q

What is the self zone?

A

The router itself and includes all of the IP addresses assigned to the router interfaces