When grouping VPNs into destination zones for Zone-Based Firewall, how many zones can a single VPN belong to?
Choose an answer
Tap an option to check your answer.
Correct answer: one.
Why this is the answer
In Cisco SD-WAN Zone-Based Firewall (ZBFW), a single VPN can belong to only one zone. This is a fundamental principle of ZBFW design, ensuring clear and unambiguous security policy enforcement. Each zone represents a security grouping, and traffic flows are controlled by policies defined between these zones. Allowing a VPN to belong to multiple zones would create ambiguity in policy application and complicate security posture. For example, if a VPN were in both an "Internal" and "DMZ" zone, it would be unclear which set of policies should apply to its traffic, undermining the granular control ZBFW aims to provide. Therefore, for consistent and predictable security, a VPN must be assigned to a single, distinct zone.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed