Courseiva
Security →easyMultiple Choice

350-401 Security Practice Question

A network administrator is configuring a zone-based firewall on a Cisco IOS XE router. The requirement is to allow HTTP traffic from the INSIDE zone to the OUTSIDE zone while blocking all other traffic initiated from INSIDE. Which action must be taken to define the traffic that is permitted?

⚠ Common exam trap

The trap here is assuming interface ACLs or route-maps control inter-zone traffic, when zone-based firewall requires class-maps and policy-maps on a zone pair.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Create a class-map that matches HTTP, then reference it in a policy-map and apply the policy-map to the zone pair.

Zone-based firewall policy is built with class-maps for traffic identification and policy-maps for action. The policy-map is attached to a zone pair, and traffic not explicitly permitted is dropped by default, which matches the requirement to allow only HTTP from INSIDE to OUTSIDE.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Configure a route-map that matches HTTP and apply it to the zone pair.

    Why it's wrong here

    Route-maps are used for routing policy, such as redistribution or PBR, not for zone-based firewall traffic classification. They cannot define permit or inspect actions between zones, so this approach would not achieve the required HTTP-only permission.

  • ✓

    Create a class-map that matches HTTP, then reference it in a policy-map and apply the policy-map to the zone pair.

    Why this is correct

    Zone-based firewall uses class-maps to identify traffic and policy-maps to define actions. The policy-map is applied to a zone pair (INSIDE to OUTSIDE) with the service-policy command, so only HTTP is permitted while other traffic is dropped by default.

  • ✗

    Apply an ACL directly to the INSIDE zone interface with the ip access-group command.

    Why it's wrong here

    Zone-based firewall does not use interface ACLs to define inter-zone policy. Applying an ACL to the interface bypasses the zone framework and does not create the required inspect or pass actions between zones, so the policy would not function as intended.

  • ✗

    Enable NAT with an overload statement matching HTTP on the OUTSIDE interface.

    Why it's wrong here

    NAT translates addresses and does not enforce security policy between zones. While NAT may be used alongside zone-based firewall, it does not permit or deny traffic based on application, so it cannot satisfy the requirement to allow only HTTP from INSIDE to OUTSIDE.

About these practice questions

One of 1,923 original 350-401 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.