CCNP Security Practice Question
A network security team is hardening a Cisco IOS XE router that terminates IPsec tunnels to remote branch offices. The team wants to use zone-based firewall (ZBFW) to inspect traffic between the inside, outside, and VPN zones. Which two statements correctly describe zone-based firewall behavior on this platform? (Choose two.)
⚠ Common exam trap
The trap here is assuming a single zone pair inspects traffic in both directions, when zone pairs are unidirectional and return traffic is handled by the stateful inspect action.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Traffic between two interfaces assigned to the same zone is implicitly permitted and not inspected by the zone policy.
ZBFW permits intra-zone traffic without inspection and denies inter-zone traffic by default unless a zone pair with a policy exists. Zone pairs are unidirectional, inspection handles return traffic for established sessions, and unassigned interfaces use classic ACL behavior rather than joining the self zone. These behaviors drive how the branch router's inside, outside, and VPN zones must be paired and inspected.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Applying an inspect action to a zone pair automatically creates a reverse zone pair for return traffic.
Why it's wrong here
The inspect action enables stateful tracking of sessions so return traffic for established flows is permitted, but it does not create a reverse zone pair. A reverse zone pair is a separate configuration object that must be defined explicitly if traffic initiation from the opposite direction is required. Confusing stateful return-traffic handling with automatic reverse zone pair creation is a common design error that leads to asymmetric policy gaps.
- ✓
Traffic between two interfaces assigned to the same zone is implicitly permitted and not inspected by the zone policy.
Why this is correct
ZBFW treats all interfaces in the same zone as a single trust domain, so intra-zone traffic is not inspected and is permitted by default. This design simplifies policy by letting administrators define inspection only for inter-zone flows. In this scenario, if two branch-facing interfaces were both in the VPN zone, traffic between them would bypass inspection, which is a key behavior to understand when designing zone membership.
- ✗
Interfaces not assigned to any zone are treated as members of the self zone and inspected.
Why it's wrong here
The self zone represents the router itself, not unassigned interfaces. Interfaces that are not assigned to any zone continue to use classic interface-based ACL behavior and are not inspected by ZBFW. Assuming unassigned interfaces join the self zone would leave traffic uninspected while the administrator believes it is protected, creating an unintended security gap in the branch router deployment.
- ✓
Traffic between two zones with no configured zone pair is implicitly denied by default.
Why this is correct
ZBFW follows a default-deny model for inter-zone traffic: if no zone pair and policy exist between two zones, traffic is dropped. This is a security improvement over classic CBAC, which permitted traffic unless explicitly denied. In this scenario, the team must create explicit zone pairs (for example, inside-to-outside and VPN-to-inside) with inspect actions, or the corresponding traffic will be silently dropped.
- ✗
A zone pair must be configured bidirectionally; a single zone pair covers traffic in both directions automatically.
Why it's wrong here
Zone pairs are unidirectional: a zone pair from inside to outside only matches traffic flowing in that direction. Return traffic is handled by the stateful inspection engine when an inspect action is applied, not by the reverse zone pair. Administrators who assume a single zone pair covers both directions will find that traffic initiated from the other zone is dropped unless a separate zone pair and policy are configured.
Visual reference
Quick reference
VPN Protocol Comparison
| Protocol | Port | Encryption | Authentication | Use Case |
|---|---|---|---|---|
| IKEv2 / IPsec | UDP 500 / 4500 | AES-256 | Certificates / PSK | Site-to-site & remote access |
| SSL / TLS VPN | TCP 443 | TLS 1.3 | Certificates / MFA | Clientless remote access |
| L2TP / IPsec | UDP 1701 | AES (IPsec) | PSK / Certificates | Legacy remote access |
| WireGuard | UDP 51820 | ChaCha20 | Public keys | Modern high-performance VPN |
| PPTP | TCP 1723 | MPPE (weak) | MS-CHAPv2 | Legacy — avoid in production |
PPTP is considered insecure. IKEv2/IPsec and SSL VPN are the current recommended options.
About these practice questions
This 350-401 question is part of Courseiva's 1,923-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.