exam questions

Exam 210-260 All Questions

View all questions & answers for the 210-260 exam

Exam 210-260 topic 1 question 10 discussion

Actual exam question from Cisco's 210-260
Question #: 10
Topic #: 1
[All 210-260 Questions]

Which two statements about stateless firewalls are true? (Choose two.)

  • A. They compare the 5-tuple of each incoming packet against configurable rules.
  • B. They cannot track connections.
  • C. They are designed to work most efficiently with stateless protocols such as HTTP or HTTPS.
  • D. Cisco IOS cannot implement them because the platform is stateful by nature.
  • E. The Cisco ASA is implicitly stateless because it blocks all traffic by default.
Show Suggested Answer Hide Answer
Suggested Answer: AB 🗳️
However, since iptables and Netfilter were introduced and connection tracking in particular, this option was gotten rid of. The reason for this is that connection tracking can not work properly without defragmenting packets, and hence defragmenting has been incorporated into conntrack and is carried out automatically. It can not be turned off, except by turning off connection tracking. Defragmentation is always carried out if connection tracking is turned on.
Reference:
http://www.iptables.info/en/connection-state.html

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
VILASCO
2 years, 5 months ago
A ET B
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago