300-410 Infrastructure Security Practice Question
A network engineer is implementing Zone-Based Policy Firewall (ZPFW) on a Cisco IOS router. The router has three interfaces: inside, outside, and DMZ. The engineer wants to allow HTTP traffic from the inside zone to the DMZ zone, and block all other traffic from inside to DMZ. Which configuration is required?
⚠ Common exam trap
The trap here is forgetting that ZPFW requires a zone pair to define the direction of traffic; applying a policy-map without a zone pair has no effect.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Define a zone pair from inside to DMZ, apply a policy-map that inspects HTTP and drops all other traffic.
In ZPFW, traffic between zones is controlled by zone pairs. A zone pair from inside to DMZ with a policy-map that inspects HTTP and implicitly drops other traffic will allow only HTTP and block the rest. Other options either do not use ZPFW correctly or apply the policy in the wrong direction.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Configure a class-map that matches HTTP and apply it as an inspect action in the global policy.
Why it's wrong here
A class-map alone does not define the direction or zones. ZPFW requires a zone pair to apply the policy-map to traffic between specific zones. Without the zone pair, the policy would not be applied to the inside-to-DMZ traffic.
- ✓
Define a zone pair from inside to DMZ, apply a policy-map that inspects HTTP and drops all other traffic.
Why this is correct
Zone-Based Policy Firewall uses zone pairs to define traffic flows between zones. To allow HTTP from inside to DMZ and block other traffic, a zone pair must be created from inside to DMZ, and a policy-map applied that permits HTTP and implicitly drops all other traffic. This meets the requirement.
- ✗
Apply an ACL on the inside interface permitting HTTP to the DMZ and denying all other traffic.
Why it's wrong here
While an ACL can filter traffic, ZPFW requires zone pairs and policy-maps to define inter-zone policies. Using only an ACL does not leverage ZPFW and would not provide stateful inspection. The requirement is to implement ZPFW, so an ACL alone is insufficient.
- ✗
Create a zone pair from DMZ to inside and apply a policy-map that permits HTTP return traffic.
Why it's wrong here
The zone pair direction is from inside to DMZ for the initial traffic. The return traffic from DMZ to inside is handled by the stateful inspection of the original flow. Creating a zone pair from DMZ to inside would not allow the initial HTTP request from inside; it would only affect traffic initiated from DMZ.
Go deeper
Related to this question
About these practice questions
One of 1,401 original 300-410 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 300-410 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 300-410 exam.