CCNA Security Practice Test Results

Question 1
48% answer correctly
Which option is true of intrusion prevention systems?
They have no potential impact on the data segment being monitored.
They are more vulnerable to evasion techniques than IDS.
They operate in promiscuous mode.
They operate in inline mode.
Question 2
40% answer correctly
Which statement is true when configuring access control lists (ACLs) on a Cisco router?
Only one ACL per protocol, per direction, and per interface is allowed.
An "implicit deny" is applied to the start of the ACL entry by default.
Apply the ACL to the interface prior to configuring access control entries to ensure that controls are applied immediately upon configuration.
ACLs filter all traffic through and sourced from the router.
Question 3
55% answer correctly
Which statement is true when using zone-based firewalls on a Cisco router?
Interface ACLs are applied before zone-based policy firewalls when they are applied outbound.
When configured with the "PASS" action, stateful inspection is applied to all traffic passing between the configured zones.
The firewalls can be configured simultaneously on the same interface as classic CBAC using the ip inspect CLI command.
Policies are applied to traffic moving between zones, not between interfaces.