Courseiva
Network SecuritymediumMultiple SelectObjective-mapped

350-701 Network Security Practice Question

A security administrator is deploying a Cisco ASA in a DMZ architecture. The inside interface is security 100, outside interface is security 0, and DMZ interface is security 50. Which TWO statements about traffic flow are correct?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Traffic from inside to DMZ is allowed by default.

Traffic from higher to lower security levels is allowed by default; lower to higher requires ACLs. Also, traffic from inside to DMZ is allowed, but return traffic is allowed due to stateful inspection.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Traffic from DMZ to outside is denied by default.

    Why it's wrong here

    DMZ security 50 > outside 0, so allowed by default.

  • Traffic from inside to DMZ is allowed by default.

    Why this is correct

    Inside security 100 > DMZ security 50.

  • Traffic from outside to inside is allowed by default without ACL.

    Why it's wrong here

    Lower to higher requires an ACL.

  • Traffic from inside to outside is allowed by default.

    Why this is correct

    Higher to lower security is permitted.

  • Traffic from DMZ to inside is allowed by default.

    Why it's wrong here

    DMZ security 50 < inside 100, so not allowed by default.

About these practice questions

Courseiva writes every 350-701 question from scratch — 978 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 350-701 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-701 exam.