Which component performs stateful inspection of TCP, UDP, and ICMP flows in Cisco SD-WAN firewall policies?
Choose an answer
Tap an option to check your answer.
Correct answer: zones.
Why this is the answer
In Cisco SD-WAN, firewall policies perform stateful inspection based on security zones. Zones are logical groupings of interfaces or subnets that share a common security posture. By defining traffic flows between these zones, the firewall can apply stateful inspection to TCP, UDP, and ICMP sessions, tracking their state and ensuring only legitimate return traffic is allowed. Incorrect options: Subnets are network segments, but firewall policies operate at a higher logical level using zones to group these segments for security. Sites refer to physical locations where SD-WAN devices are deployed; while relevant for routing, they don't directly perform stateful inspection in firewall policies. Interfaces are physical or logical ports on a device. While interfaces are assigned to zones, the zone itself is the construct that enables stateful inspection within the firewall policy.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed