300-410 Infrastructure Security Practice Question
A network engineer is configuring Zone-Based Policy Firewall on a Cisco IOS XE router. The company requires that all traffic from the internal LAN zone to the untrusted Internet zone be inspected, but traffic from the Internet to the internal LAN must be blocked unless it is return traffic. The engineer has already defined zone pairs with 'zone-pair security IN-TO-OUT source LAN destination INTERNET' and applied an inspect policy-map. What must the engineer do to complete the configuration?
⚠ Common exam trap
The trap here is assuming that applying a policy-map to a zone pair is sufficient, when interfaces must first be assigned to zones for the policy to take effect.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Assign the interfaces to the LAN and INTERNET zones using the 'zone-member security' command.
Zone-Based Policy Firewall operates by grouping interfaces into security zones and defining policies between zone pairs. The inspect policy-map applied to the LAN-to-INTERNET zone pair only functions when the involved interfaces are assigned to their respective zones with 'zone-member security'. Until interfaces are bound to zones, the zone-pair policy remains inactive, so no stateful inspection or implicit return traffic handling occurs.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Configure a class-map matching all traffic and apply it to the zone pair with the 'inspect' action.
Why it's wrong here
A class-map is used to classify traffic within a policy-map; it cannot be applied directly to a zone pair. The engineer already has an inspect policy-map applied to the zone pair. The missing step is interface zone membership, not additional classification. Creating another class-map does not activate the zone pair.
- ✓
Assign the interfaces to the LAN and INTERNET zones using the 'zone-member security' command.
Why this is correct
Zone-Based Policy Firewall requires interfaces to be assigned to zones before any zone-pair policy takes effect. The 'zone-member security' interface command binds each interface to its zone, enabling the inspect policy-map to be applied to traffic traversing the LAN-to-INTERNET zone pair. Without this binding, the zone-pair policy is dormant and no inspection occurs.
- ✗
Enable 'ip inspect' globally on the router to activate stateful inspection for all zones.
Why it's wrong here
The legacy 'ip inspect' command belongs to Context-Based Access Control (CBAC), not Zone-Based Policy Firewall. ZBPF does not use global inspection activation; it relies on zone membership and zone-pair policies. Enabling 'ip inspect' would not satisfy the zone-based inspection requirement and may conflict with ZBPF configuration.
- ✗
Apply the inspect policy-map directly to the inside interface using the 'service-policy type inspect' command.
Why it's wrong here
In Zone-Based Policy Firewall, policy-maps are applied to zone pairs, not directly to interfaces as with classic CBAC or IOS Firewall. Applying 'service-policy type inspect' to an interface is not the correct configuration model for ZBPF and would not create the required zone-pair inspection relationship. The interface must be a zone member instead.
Go deeper
Related to this question
About these practice questions
Courseiva writes every 300-410 question from scratch — 1,401 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 300-410 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 300-410 exam.