CCNA Security Chapter 4

Is this your test? Login to manage it. If not, you can build an exam just like it.

This is a non-interactive preview of the quiz content.

1.
1 point
What is one benefit of using a stateful firewall instead of a proxy server?
2.
1 point
What is one limitation of a stateful firewall?
3.
1 point
To facilitate the troubleshooting process, which inbound ICMP message should be permitted on an outside interface?
4.
1 point
If the provided ACEs are in the same ACL, which ACE should be listed first in the ACL according to best practice?
5.
1 point
Which two rules about interfaces are valid when implementing a Zone-Based Policy Firewall? (Choose two.)
6.
1 point
A network administrator is implementing a Classic Firewall and a Zone-Based Firewall concurrently on a router. Which statement best describes this implementation?
7.
1 point
The _______ action in a Cisco IOS Zone-Based Policy Firewall is similar to a permit statement in an ACL.
8.
1 point
A company is deploying a new network design in which the border router has three interfaces. Interface Serial0/0/0 connects to the ISP, GigabitEthernet0/0 connects to the DMZ, and GigabitEthernet/01 connects to the internal private network. Which type of traffic would receive the least amount of inspection (have the most freedom of travel)?
9.
1 point
A router has been configured as a classic firewall and an inbound ACL applied to the external interface. Which action does the router take after inbound-to-outbound traffic is inspected and a new entry is created in the state table?
10.
1 point
When an inbound Internet-traffic ACL is being implemented, what should be included to prevent the spoofing of internal networks?
11.
1 point
Which command will verify a Zone-Based Policy Firewall configuration?
12.
1 point
Which statement describes a typical security policy for a DMZ firewall configuration?
13.
1 point
Which type of packet is unable to be filtered by an outbound ACL?
14.
1 point
Which command is used to activate an IPv6 ACL named ENG_ACL on an interface so that the router filters traffic prior to accessing the routing table?
15.
1 point
Refer to the exhibit. Which statement describes the function of the ACEs?

16.
1 point
Refer to the exhibit. The network “A” contains multiple corporate servers that are accessed by hosts from the Internet for information about the corporation. What term is used to describe the network marked as “A”?
17.
1 point
In addition to the criteria used by extended ACLs, what conditions are used by a classic firewall to filter traffic?
18.
1 point
Refer to the exhibit. If a hacker on the outside network sends an IP packet with source address 172.30.1.50, destination address 10.0.0.3, source port 23, and destination port 2447, what does the Cisco IOS firewall do with the packet?
19.
1 point
Refer to the exhibit. The ACL statement is the only one explicitly configured on the router. Based on this information, which two conclusions can be drawn regarding remote access network connections? (Choose two.)
20.
1 point
When a Cisco IOS Zone-Based Policy Firewall is being configured via CLI, which step must be taken after zones have been created?
21.
1 point
Consider the following

access list.access-list 100 permit ip host 192.168.10.1 any

access-list 100 deny icmp 192.168.10.0 0.0.0.255 any echo

access-list 100 permit ip any any

Which two actions are taken if the access list is placed inbound on a router Gigabit Ethernet port that has the IP address 192.168.10.254 assigned? (Choose two.)
22.
1 point
A _________ firewall monitors the state of connections as network traffic flows into and out of the organization.
23.
1 point
When a Cisco IOS Zone-Based Policy Firewall is being configured, which two actions can be applied to a traffic class? (Choose two.)