Courseiva
mediumMultiple Choice

350-401 Practice Question: Is configuring a zone-based firewall (ZBF) on a…

A network engineer is configuring a zone-based firewall (ZBF) on a Cisco router to allow traffic from the inside zone to the outside zone while blocking traffic from outside to inside. The engineer creates zones, assigns interfaces, and configures a policy-map with a class-map that matches all traffic from inside to outside. The engineer applies the policy to the zone-pair inside-to-outside. However, traffic from inside to outside is being dropped. What is the most likely reason?

⚠ Common exam trap

Cisco often tests the misconception that simply matching traffic in a class-map and applying it to a zone-pair is enough to permit traffic, when in fact an explicit action (inspect or pass) is required in the policy-map.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The policy-map does not include an 'inspect' or 'pass' action for the matched traffic.

In a zone-based firewall (ZBF), a policy-map applied to a zone-pair defines the actions to be taken on traffic flowing between the two zones. By default, traffic between zones is denied unless explicitly permitted. The class-map matches traffic from inside to outside, but without an 'inspect' or 'pass' action in the policy-map, the matched traffic is implicitly dropped. The 'inspect' action enables stateful inspection and allows return traffic, while 'pass' permits traffic without stateful tracking; omitting either results in a deny.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    The policy-map does not include an 'inspect' or 'pass' action for the matched traffic.

    Why this is correct

    In Zone-Based Firewall, a policy-map that matches traffic but does not specify an explicit action such as 'inspect' or 'pass' causes the router to apply the implicit default action of 'drop'. The class-map correctly identifies the inside-to-outside traffic, but the missing action means no forwarding or stateful inspection is performed, so all matched packets are silently discarded. The fix is to configure an 'inspect' action (or 'pass' for stateless forwarding) under the policy-map for that class.

  • ✗

    The zone-pair should be configured as outside-to-inside instead.

    Why it's wrong here

    The zone-pair 'from inside to outside' is the correct directional pairing for traffic originating on the trusted inside network and heading to the untrusted outside network. Reversing it to 'outside-to-inside' would create a policy for the opposite direction, which would not affect the inside-to-outside traffic that is currently failing. Therefore, the zone-pair direction is not the cause of the problem; the missing action is.

  • ✗

    The class-map must also match return traffic for the firewall to allow the session.

    Why it's wrong here

    With the 'inspect' action, the firewall creates a dynamic stateful session entry that allows the return traffic without a matching class-map. Since the policy-map in question lacks any 'inspect' action entirely, the concept of return traffic is moot—there is no session to which return traffic could be matched. The issue is the absence of the action, not the class-map's scope, and adding return traffic matching would not fix the underlying drop behavior.

  • ✗

    The policy-map is applied to the wrong zone-pair; it should be applied to the inside zone.

    Why it's wrong here

    In IOS Zone-Based Firewall, policy-maps are applied to zone-pairs using the 'service-policy' command under the zone-pair configuration, not directly to zones themselves. The zone-pair 'inside-to-outside' is already correctly defined and is the appropriate attachment point for this traffic flow. Applying the policy-map to the inside zone would be an invalid configuration and would not alter the fact that the existing policy-map has no action configured for the matched traffic.

Visual reference

Source Router + ACL permit 10.0.0.0/8 deny any Server 10.0.0.5 ✓ 192.168.1.1 ✗ dropped ACLs evaluate top-down; first match wins — implicit deny all at end

About these practice questions

One of 1,923 original 350-401 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.