CCNP Security Practice Question
A network administrator is configuring a Cisco IOS zone-based firewall (ZBFW) on a router that connects a LAN zone to an Internet zone. The administrator wants to allow outbound HTTP and HTTPS from the LAN to the Internet while blocking all other outbound traffic, and to allow return traffic for established sessions. Which two configuration elements are required to accomplish this? (Choose two.)
⚠ Common exam trap
The trap here is assuming that an interface ACL or NAT is part of the zone-based firewall configuration, when ZBFW specifically uses class maps, policy maps, and zone pairs with service-policy.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
A class map that matches HTTP and HTTPS traffic and a policy map that applies an inspect action.
Zone-based firewall on Cisco IOS requires class maps to identify traffic and policy maps to apply actions like inspect. The policy map must be applied to a zone pair that defines the direction of traffic, in this case LAN to Internet. The inspect action allows return traffic for established sessions, and any traffic not explicitly permitted is implicitly denied by the zone pair policy.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
A NAT configuration that translates LAN addresses to the Internet-facing interface address.
Why it's wrong here
NAT is often deployed alongside ZBFW, but it is not a required element to allow HTTP and HTTPS from LAN to Internet or to permit return traffic for established sessions. The scenario asks for the ZBFW configuration elements, and NAT is a separate function that does not enforce zone-based policy.
- ✗
A parameter map that defines inspection parameters for HTTP and HTTPS.
Why it's wrong here
Parameter maps are optional and are used to fine-tune inspection behavior, such as timeouts or session limits, for specific protocols. They are not required to simply allow HTTP and HTTPS with the inspect action. The essential elements are the class map, policy map, and zone pair with service-policy.
- ✓
A class map that matches HTTP and HTTPS traffic and a policy map that applies an inspect action.
Why this is correct
Zone-based firewall uses class maps to identify traffic and policy maps to apply actions such as inspect. To allow HTTP and HTTPS from LAN to Internet, a class map matching those protocols is required, and the policy map must apply the inspect action so that return traffic is permitted for established sessions.
- ✓
Zone pairs that define the LAN-to-Internet direction and apply the policy map with the service-policy command.
Why this is correct
ZBFW requires zone pairs to define the direction of traffic flow between zones. Applying the policy map to the LAN-to-Internet zone pair with the service-policy command enforces the inspect action for HTTP and HTTPS while implicitly denying all other traffic not explicitly permitted.
- ✗
An extended ACL applied inbound on the LAN interface to permit HTTP and HTTPS.
Why it's wrong here
An ACL applied inbound on the LAN interface is a classic IOS firewall technique, not a zone-based firewall configuration. ZBFW uses class maps and policy maps applied to zone pairs, not interface ACLs. Adding an ACL would not satisfy the ZBFW requirement and could conflict with zone-based policy enforcement.
About these practice questions
One of 1,923 original 350-401 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.