Module 16 - Zone-based policy firewalls Flashcards

(62 cards)

1
Q

Which firewall model applies policy directly to interfaces using traditional configuration?

A

A classic firewall

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Which firewall model assigns interfaces to security zones and applies policies between zones?

A

ZPF (Zone based policy firewall)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What is the first step in designing a ZPF?

A

Determine the zones

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What is the third step in ZPF design?

A

Design physical infrastructure

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Can Classic Firewall and ZPF be enabled simultaneously on the same router?

A

Yes but on different interfaces

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Which benefit of ZPF supports scalability and easier troubleshooting?

A

Use of C3PL (Cisco Common Classification Policy Language)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What defines a boundary where traffic is restricted based on policies in ZPF?

A

A zone

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What is the default security posture of a ZPF?

A

Block unless explicitly permitted

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What is the second step in the ZPF design process?

A

Establish policies between zones

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

In ZPF, how are policies applied between zones?

A

Unidirectional (From source zone to destination zone)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What is the fourth step in ZPF design?

A

Identify subsets within zones and merge traffic requirements

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

In ZPF, what term describes defined policies from one zone to another?

A

Zone pairs

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Which ZPF action uses Cisco IOS stateful packet inspection?

A

Inspect

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Which ZPF action drops traffic and offers an option to log rejected packets?

A

Drop

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Which ZPF action allows traffic without tracking session state?

A

Pass

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What is required for ZPF to perform actions like inspect or drop between zones?

A

A zone pair with a defined policy

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What happens when traffic enters and exits interfaces that are not zone members?

A

It is passed (no zone= no policy)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What is the result when traffic flows between interfaces in the same zone?

A

It is passed

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

What happens when traffic moves between a zone member interface and a non-zone member interface?

A

It is dropped

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

What happens if both interfaces are in different zones but no zone pair exists?

A

It is dropped

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

What is the default action when a zone pair exists but no policy is configured?

A

It is passed

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

What must exist for the ZPF to inspect traffic between zones?

A

A zone pair and an inspect policy

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

What action occurs when a zone pair and an inspect policy exist?

A

It is inspected

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

What is enforced when one interface is a zone member and the other is not?

A

Traffic is dropped

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
What does ZPF do by default if no zones are applied to interfaces?
Passes traffic
14
What is the result when a private-to-public zone pair exists but no policy is defined?
Traffic is passed
15
What happens when traffic flows from a private to a public zone without a zone pair?
Traffic is dropped
16
Which special ZPF zone includes all IP addresses assigned to router interfaces?
Self zone
16
What is the default action for traffic when the router is the source or destination and no zone-pair exists?
Pass
16
What kind of traffic is considered part of the self zone?
Traffic originating from the router or is addressed to the router itself
17
What happens to traffic from the self zone to another zone when a zone-pair exists but no policy is configured?
Traffic is passed
17
When is traffic to or from the self zone subject to a policy inspection?
If there is a zone pair and a policy
17
18
What is the result when traffic flows from the self zone to another zone and a policy exists?
Traffic is inspected
19
In the absence of any policy or zone-pair, how is traffic between the router and any other zone handled?
It is passed
20
What happens to traffic sent from another zone to the self zone when no zone-pair exists?
It is passed
21
What is my personal rule concerning dropping and passing data in ZPF transit traffic?
For traffic in transit, source and destination need to both not be part of a zone, or both part of a zone with a zone pair for data to be permitted. The rest is denied
22
What command is used to create a security zone in ZPF?
zone security (zone name)
23
What ZPF configuration component identifies traffic based on match criteria for later policy assignment?
A class map
24
25
26
27
28
29
30
31
31
32
32
33
33
34
35
35
35
36
36
36
37
38
38