01. Engineers at a regional bank enabled reachability monitoring on the branch firewall's primary static route, expecting the pair to hand traffic to the peer whenever the upstream path failed. During a genuine upstream outage the branch's traffic did move onto the secondary path and service was restored.
The runbook step telling the engineers to confirm that the peer had taken over never applied, because the members kept their roles throughout.
What does this outcome tell the engineers?
a) The peer would have taken over only if the monitored destination had also been unreachable from the passive member itself.
b) The mechanism edits the routing table of this device only; which member is active is a separate decision entirely.
c) The pair keeps its roles while any monitored route remains installed, and the secondary path therefore suppressed the handover.
d) The monitoring did not act at all, since the members would have exchanged roles first if it had.
02. A hospital branch firewall is centrally managed. A local administrator adds a rule permitting a clinical application between two zones and confirms that it sits at the top of the list they administer.
The application is still refused. The denial is logged against a rule the administrator did not write and cannot edit, and that rule sits above their entire list.
What accounts for the behaviour?
a) The clinical traffic arrives in a zone the administrator's rule does not name, so that rule is never a candidate.
b) The administrator's rule was never committed on the device, so the list being read is not the one being enforced.
c) Part of the centrally delivered policy is evaluated ahead of the whole local list, so the administrator's ordering could not change the outcome.
d) Local rules are evaluated only after every centrally delivered rule, including the ones meant as a final catch-all or backstop.
03. Two video editors at a media company hold identical roles and identical group membership, and both connect from home through the nearest available tunnel endpoint. One reaches the internal build server; the other is refused, and her session appears in the firewall's records against a named rule that denies it.
Both authenticated without error and both hold an established tunnel.
What best explains the difference between them?
a) The refused editor authenticated against a different identity source, so her group membership was never applied.
b) The refused editor's client kept the build server out of the tunnel, and the firewall never saw it.
c) The component that distributes the client configuration is unreachable, so the settings she holds are incomplete.
d) Each editor's traffic is enforced where the tunnel terminated, on endpoints that carry different rules.
04. A managed service provider hosts three customers on one firewall, giving each its own virtual system, and has told all three they are effectively on their own firewall.
One customer now asks for a maintenance window that no other customer shares, and a second asks what becomes of its traffic if the chassis suffers a hardware fault.
Which two statements describe the limits of the separation the provider has sold?
(Choose two.)
a) One platform fault takes every virtual system with it, because the three customers share a single failure domain.
b) Zones defined in one virtual system are visible to the others, so identically named zones collide at every attempted commit.
c) An administrator scoped to one virtual system can, on a shared chassis, read and change any other customer's policy at will.
d) Traffic in one virtual system reaches another automatically, because a shared chassis implies a shared forwarding path.
e) The chassis runs a single software image, so all three tenants upgrade together and none holds an independent window.
05. A university's remote-access deployment keeps a published range of addresses belonging to a hosted collaboration suite out of the tunnel. The suite's provider has begun returning different addresses to clients depending on which resolver the client uses, and some of those addresses lie outside the published range.
Staff report the same application behaving inconsistently: quick from some homes, and noticeably slower and evidently passing through headquarters from others. The exclusion definitions are identical for every user and have not been edited.
What accounts for the inconsistency?
a) The client applies the exclusion to the address it resolved, so one name can land inside or outside the tunnel.
b) Each tunnel endpoint holds its own exclusion definitions, so staff are excluded differently, depending on where their tunnel happened to land.
c) The gateway selects a different internal path for each user, which changes how quickly the suite responds to them.
d) Affected staff connect to the endpoint nearer headquarters, so their sessions travel the longer internal path home.
06. Three times in one month, a broadcaster's firewall pair has changed roles at moments when nothing inside the data centre changed. Each time, the provider later reported a fault in a network several hops beyond its own edge.
The pair monitors reachability to a well-known public destination on the internet, and every role change interrupted live production traffic.
What is wrong with this monitoring design?
a) The monitored destination lies beyond anything the members are responsible for, so its own outages became the reason they changed roles.
b) Watching reachability through the network adds nothing that the state of the local interfaces does not already reveal.
c) The members should watch their own interfaces alone, since a change of interface state is the only condition worth acting on at all.
d) The pair, reacting to brief interruptions too readily, should wait longer and require repeated failures before acting.
07. A media company's firewalls send their records to the cloud logging service. After a weekend change to the way each device's own service traffic is routed, nothing has appeared in the cloud from any firewall.
Traffic through the firewalls is passing and being enforced exactly as before, and every device still shows current local entries for its rules.
What does this pattern indicate?
a) The firewalls now deny or discard the traffic they used to permit, so nothing at all is left to record.
b) Logging on the rules was switched off by the weekend change, which is why the cloud, since then, has received nothing.
c) The service refuses records from any firewall whose configuration has changed since the firewall was first registered with it.
d) The devices lost the path they use to reach the logging destination, so only visibility has stopped.
08. A regional logistics operator is replacing the single firewall at its distribution hub with a pair of identical devices. Traffic reaches the hub through one upstream router and leaves through one downstream switch stack, so every flow has exactly one logical path through the pair.
The two engineers who run the site troubleshoot by tracing an individual session end to end, and they size the hub on the assumption that one device carries the whole load.
Which arrangement fits these requirements, and why?
a) Active/passive, because the single path needs only one forwarding member and leaves exactly one device to examine per flow.
b) Active/passive, because that is the only arrangement in which both members are guaranteed to hold matching enforcement configuration at all times.
c) Active/active, because both members would be forwarding and the hub could then be sized on the two devices' combined capacity.
d) Active/active, because a single upstream router, sitting in front of the pair, is exactly the topology the mode serves best.
09. A university inserted a firewall as a virtual wire between the research building's distribution switch and the campus core, chosen because no addressing or topology change was permitted during the teaching term.
A funded project now requires that same firewall to terminate an encrypted site-to-site link to a partner institute and to exchange routes with the campus core so the partner's networks are learned automatically. The engineer has spent two days searching the paired interfaces for the settings that would enable this.
Which assessment of the new requirement is accurate?
a) The campus core can name the pair as its next hop for the partner networks, which supplies the routing role that the new requirement asks for.
b) The pair can terminate the partner link, because every session crossing that path is already inspected and passed by the firewall.
c) A transparent pair keeps inspecting this traffic, yet it neither routes nor terminates tunnels, so the insertion choice is what must change.
d) Once the paired interfaces sit in two different zones, the firewall has the standing to exchange routes with the campus core.
10. A distributor runs the same scheduled traffic report for each of its regions. One region's report has come back empty for the last month.
That region's firewalls are visibly passing traffic, its users report no problems, and the report definition is identical to the ones that work.
What should be checked first?
a) Whether the report definition should be rebuilt, since an identical definition can behave differently in each region.
b) Whether the log data the report draws on was generated or retained for that region at all.
c) Whether that region's rules are permitting the traffic, since a report shows what policy allowed.
d) Whether the report should cover a longer period, since a month is too short for a regional summary.