350-401 Security Practice Question
A network engineer is implementing a Zone-Based Firewall (ZBFW) on a Cisco IOS XE router. The router has three interfaces: inside (GigabitEthernet0/0), outside (GigabitEthernet0/1), and DMZ (GigabitEthernet0/2). The security policy requires that traffic from the inside zone to the outside zone be inspected, traffic from the outside zone to the DMZ be allowed only for HTTP and HTTPS, and all other traffic between zones be denied by default. Which configuration step is essential to achieve this policy?
⚠ Common exam trap
The trap here is thinking that an ACL or a single zone pair can satisfy all requirements, but ZBFW requires explicit zone pairs for each direction and default deny between zones.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Assign interfaces to zones and create zone pairs with inspect policies for inside-to-outside and outside-to-DMZ.
Zone-Based Firewall requires interfaces to be assigned to zones, and traffic between zones is controlled by zone pairs. Each zone pair has a policy that defines actions like inspect, pass, or drop. By default, inter-zone traffic is dropped, so explicit policies are needed for allowed traffic. The correct configuration involves creating zones, assigning interfaces, and defining zone pairs with appropriate inspect policies for inside-to-outside and outside-to-DMZ, ensuring the default deny posture.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Configure a single zone pair from inside to outside with an inspect policy and rely on implicit permit for other traffic.
Why it's wrong here
ZBFW does not have an implicit permit for inter-zone traffic; the default is to drop all traffic between zones unless explicitly allowed. Relying on implicit permit would not meet the requirement to deny all other traffic. Additionally, this approach does not address the outside-to-DMZ traffic, which requires its own zone pair and policy. So this configuration is incomplete and incorrect.
- ✗
Create a class map that matches HTTP and HTTPS traffic and apply it as a policy to the outside interface.
Why it's wrong here
Class maps are used within policy maps in ZBFW, but they must be applied to zone pairs, not directly to interfaces. Applying a policy directly to an interface is not how ZBFW works; ZBFW policies are applied to zone pairs. This option misapplies the configuration construct and does not fulfill the requirement for zone-based inspection and default deny between zones.
- ✗
Apply an ACL to the outside interface to permit HTTP and HTTPS to the DMZ and deny all other traffic.
Why it's wrong here
While ACLs can filter traffic, ZBFW uses zone pairs and policies for stateful inspection. Using only an ACL does not provide the stateful inspection required for inside-to-outside traffic. Also, the requirement specifies ZBFW, which provides more granular control and inspection. ACLs alone would not meet the stateful inspection requirement and would require additional configuration for the inside-to-outside inspection.
- ✓
Assign interfaces to zones and create zone pairs with inspect policies for inside-to-outside and outside-to-DMZ.
Why this is correct
This is the fundamental ZBFW configuration. Interfaces must be assigned to zones, and zone pairs define the direction of traffic flow. For traffic to be allowed, a zone pair must exist with a policy that inspects or passes traffic. The default action for inter-zone traffic is drop, so explicit policies are needed. This step is essential to meet the requirements of inspecting inside-to-outside and allowing only HTTP/HTTPS from outside to DMZ.
Go deeper
Related to this question
About these practice questions
This 350-401 question is part of Courseiva's 1,923-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.