exam questions

Exam 300-415 All Questions

View all questions & answers for the 300-415 exam

Exam 300-415 topic 1 question 106 discussion

Actual exam question from Cisco's 300-415
Question #: 106
Topic #: 1
[All 300-415 Questions]

DRAG DROP -
Drag and drop the definitions from the left to the configuration on the right.
Select and Place:

Show Suggested Answer Hide Answer
Suggested Answer:
Reference:
https://www.cisco.com/c/en/us/td/docs/routers/sdwan/configuration/security/vedge/security-book/ent-firewall-app-aware.html#:~:text=Source%20zone
%E2%80%94A%20grouping%20of,part%20of%20only%20one%20zone.&text=A%20VPN%20can%20be%20part%20of%20only%20one%20zone.,-Firewall%
20policy%E2%80%94A

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
timbo2000
1 year ago
given answer is correct as cisco docs- Firewall policy—A security policy, similar to a localized security policy, that defines the conditions that the data traffic flow from the source zone must match to allow the flow to continue to the destination zone. Firewall policies can match IP prefixes, IP ports, the protocols TCP, UDP, ICMP, and applications. Matching flows for prefixes, ports, and protocols can be accepted or dropped, and the packet headers can be logged. Nonmatching flows are dropped by default. Matching applications are denied. Zone pair—A container that associates a source zone with a destination zone and that applies a firewall policy to the traffic that flows between the two zones.
upvoted 3 times
...
bsk
1 year ago
I will go with the given answer, as per the link Zone configuration consists of the following components: Source zone—A grouping of VPNs where the data traffic flows originate. A VPN can be part of only one zone. Destination zone—A grouping of VPNs where the data traffic flows terminate. A VPN can be part of only one zone. Firewall policy—A security policy, similar to a localized security policy, that defines the conditions that the data traffic flow from the source zone must match to allow the flow to continue to the destination zone. Firewall policies can match IP prefixes, IP ports, the protocols TCP, UDP, and ICMP. Matching flows for prefixes, ports, and protocols can be accepted or dropped, and the packet headers can be logged. Nonmatching flows are dropped by default. Zone pair—A container that associates a source zone with a destination zone and that applies a firewall policy to the traffic that flows between the two zones.
upvoted 1 times
...
heavncong
1 year, 1 month ago
Given answer mixed up firewall policy and zone pair I will go for B -> A -> D -> C as well
upvoted 1 times
...
Erik_N
1 year, 2 months ago
Given answer is correct
upvoted 1 times
...
Roger95
1 year, 3 months ago
https://www.cisco.com/c/dam/en/us/td/docs/routers/sdwan/configuration/config-18-2.pdf#page=474
upvoted 1 times
...
Roger95
1 year, 3 months ago
should be B -> A -> D -> C
upvoted 3 times
Tan_Singh
1 year, 1 month ago
yes agree
upvoted 2 times
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...