Implementation & Compliance Best Practices Flashcards
7 cards from real ACL practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Implementation & Compliance Best Practices flashcards as text
An engineer is implementing ACLs on a Cisco router and notices the implicit deny at the end. What action should be taken to meet logging compliance requirements for denied traffic?
Answer: Add an explicit 'deny any any log' rule before the implicit deny
The implicit deny does not generate log entries; adding an explicit 'deny any any log' statement captures denied traffic for compliance logging.
When using ACLs to segment a network for SOX compliance, which systems should be isolated in a separate security zone?
Answer: Systems that process or store financial reporting data
SOX compliance requires controls around systems that directly process or store financial reporting data to ensure data integrity and confidentiality.
Which ACL design principle aligns with the Zero Trust security model?
Answer: Verify every request regardless of network location and apply least-privilege ACLs
Zero Trust requires verifying all requests regardless of origin and enforcing least-privilege access, which means granular ACLs for all traffic flows.
A network team is implementing ACLs across 50 branch routers. Which approach reduces misconfiguration risk while ensuring compliance consistency?
Answer: Deploy templated ACLs via a network automation tool with peer review and version control
Templated ACLs deployed through automation with version control and peer review reduce errors and ensure consistent compliance across all sites.
During an ACL audit, a tester discovers a 'permit ip any any' rule positioned before more restrictive rules. What is the security impact?
Answer: The permissive rule overrides all subsequent restrictive rules for matching traffic
ACLs are processed top-down and stop at the first match, so a broad 'permit ip any any' early in the list allows all traffic before restrictive rules are reached.
Which method is recommended for testing ACL changes in a production environment to minimize risk?
Answer: Test in a staging environment first, then deploy during a maintenance window
Validating ACL changes in a staging environment before deploying during a scheduled maintenance window minimizes disruption and rollback complexity.
An ACL is configured with 'permit tcp 192.168.1.0 0.0.0.255 any eq 443'. Which traffic does this rule explicitly allow?
Answer: HTTPS traffic originating from the 192.168.1.0/24 subnet to any destination
This rule permits TCP traffic sourced from the 192.168.1.0/24 network destined for any IP on port 443 (HTTPS).