ETExamTower
Q23Management and Operations

Drag and drop the definitions on the left to the corresponding configuration on the right. <DragDrop items={["destination zone","source zone","firewall policy","zone pair"]} slots={[{"answer":"source zone","id":"slot1","label":"grouping of VPNs where the data traffic flows originate"},{"answer":"destination zone","id":"slot2","label":"grouping of VPNs where the data traffic flows terminate"},{"answer":"firewall policy","id":"slot3","label":"matching condition that allows traffic flow between two zones"},{"answer":"zone pair","id":"slot4","label":"container that associates forwarding and blocking decisions"}]} explanation={"A source zone identifies where traffic enters or originates, and a destination zone identifies where it ends. Firewall policies match traffic and allow it between zones. Zone pairs group the forwarding and blocking behavior for traffic between zones.\n\n**Learn more:** [Cisco SD-WAN Zone-Based Firewall (ZBFW)](https://www.cisco.com/c/en/us/support/docs/routers/sd-wan/217758-cisco-sd-wan-zone-based-firewall-zbfw.html) · [Enterprise Firewall with Application Awareness](https://www.cisco.com/c/en/us/td/docs/routers/sdwan/configuration/security/ios-xe-17/security-book-xe/m-firewall-17.html)"} reuse={false} />

← → navigate · a answer
Discussion · 8
3
should be B -> A -> D -> C
3
given answer is correct per cisco docs- Firewall policy—A security policy, similar to a localized security policy, that defines the conditions that the data traffic flow from the source zone must match to allow the flow to continue to the destination zone. Firewall policies can match IP prefixes, IP ports, the protocols TCP, UDP, ICMP, and applications. Matching flows for prefixes, ports, and protocols can be accepted or dropped, and the packet headers can be logged. Nonmatching flows are dropped by default. Matching applications are denied. Zone pair—A container that associates a source zone with a destination zone and applies a firewall policy to the traffic that flows between the two zones.
2
yes, agree
2
Answer is incorrect. Correct order is BADC Zone Pair: This is the specific directional relationship between two zones (e.g., Source_Zone to Destination_Zone). It functions as the "matching condition" because the firewall only inspects traffic that matches a defined pair. • Firewall Policy: This is the actual "container" where you define your inspect, pass, or drop actions. It is applied to a zone pair to control the forwarding and blocking decisions for that specific traffic path.
1
https://www.cisco.com/c/dam/en/us/td/docs/routers/sdwan/configuration/config-18-2.pdf#page=474
1
Given answer is correct
1
Given answer mixes up firewall policy and zone pair I will go for B -> A -> D -> C too
1
I will go with the given answer, as per the link Zone configuration consists of the following components: Source zone—A grouping of VPNs where the data traffic flows originate. A VPN can be part of only one zone. Destination zone—A grouping of VPNs where the data traffic flows terminate. A VPN can be part of only one zone. Firewall policy—A security policy, similar to a localized security policy, that defines the conditions that the data traffic flow from the source zone must match to allow the flow to continue to the destination zone. Firewall policies can match IP prefixes, IP ports, the protocols TCP, UDP, and ICMP. Matching flows for prefixes, ports, and protocols can be accepted or dropped, and the packet headers can be logged. Nonmatching flows are dropped by default. Zone pair—A container that links a source zone with a destination zone and applies a firewall policy to the traffic that flows between the two zones.