When a Cisco IOS Zone-Based Policy Firewall is being configured, which two actions can be applied to a traffic class? (Choose two.)

When a Cisco IOS Zone-Based Policy Firewall is being configured, which two actions can be applied to a traffic class? (Choose two.)

  • log
  • hold
  • drop
  • inspect
  • copy
  • forward
    Answers Explanation & Hints:

    The three actions that can be applied are inspect, drop,and pass.​
    Inspect – This action offers state-based traffic control.
    Drop – This is the default action for all traffic. Similar to the implicit deny any at the end of every ACL, there is an explicit drop applied by the IOS to the end of every policy map.
    Pass – This action allows the router to forward traffic from one zone to another.

Leave a comment