350-401 Security Practice Question
A network security administrator is configuring a Cisco IOS Zone-Based Firewall on a branch router. The inside zone and outside zone are defined, and the administrator wants to allow inside hosts to initiate sessions to outside servers while preventing outside hosts from initiating sessions to inside hosts. Which configuration accomplishes this?
⚠ Common exam trap
The trap here is assuming that configuring an inspect action on one zone pair automatically permits sessions in both directions rather than only the direction defined by the zone pair.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
A zone pair from inside to outside with a policy that inspects the relevant traffic, and no zone pair from outside to inside.
Zone-Based Firewall policy is directional and defined by zone pairs. An inside-to-outside zone pair with an inspect action permits inside-initiated sessions and statefully allows return traffic, while the absence of an outside-to-inside zone pair causes traffic initiated from the outside to be dropped by the default inter-zone policy, achieving the required asymmetry.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
A zone pair from inside to outside with a policy that inspects the relevant traffic, and no zone pair from outside to inside.
Why this is correct
Zone-Based Firewall uses zone pairs to define directional policy. Creating a zone pair from inside to outside with an inspect action permits inside-initiated sessions and automatically allows return traffic. Because there is no zone pair from outside to inside, traffic initiated from the outside zone to the inside zone is denied by default, which matches the requirement exactly.
- ✗
A zone pair from outside to inside with an inspect action and no zone pair from inside to outside.
Why it's wrong here
This configuration allows outside hosts to initiate sessions toward the inside zone, violating the requirement that outside hosts must not initiate sessions to inside hosts. With no inside-to-outside zone pair, inside hosts also cannot initiate outbound sessions. The direction of inspection is reversed relative to the intended policy.
- ✗
A single zone pair from inside to outside with a drop action, and a class-map matching return traffic.
Why it's wrong here
A drop action on the inside-to-outside zone pair would block all inside-initiated traffic, which is the opposite of the stated requirement. Class-maps match traffic but do not by themselves permit sessions or handle return traffic. This configuration prevents legitimate outbound access and does not provide the stateful behavior needed.
- ✗
A zone pair from outside to inside with a policy that inspects traffic, plus a zone pair from inside to outside with a pass action.
Why it's wrong here
Placing an inspect policy on the outside-to-inside zone pair would allow outside hosts to initiate sessions into the inside zone, which contradicts the requirement. The inside-to-outside zone pair with a pass action would not create stateful inspection for return traffic. This combination inverts the intended security posture and permits unwanted inbound initiation.
Go deeper
Related to this question
About these practice questions
One of 1,923 original 350-401 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.