โ† All ACL Flashcard Decks

Incident Response & Recovery Flashcards

7 cards from real ACL practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Incident Response & Recovery flashcards as text
  1. After discovering a security breach caused by a misconfigured ACL, what is the FIRST remediation step an administrator should take?

    Answer: Identify and isolate affected network segments

    Isolating affected segments prevents further lateral movement while preserving evidence for forensic analysis.

  2. Which ACL log entry pattern most strongly indicates an ongoing port scan attack against a protected network?

    Answer: Multiple denied TCP SYN packets to sequential ports from one source IP

    Sequential port probing via SYN packets from a single source is the hallmark of an automated port scan.

  3. When recovering from an ACL-related incident where traffic was incorrectly permitted, which recovery action verifies the fix is effective?

    Answer: Running a penetration test against the fixed ACL

    A targeted penetration test confirms that previously exploited traffic paths are now correctly blocked by the corrected ACL.

  4. An ACL permits traffic from 10.0.0.0/24 but logs show 10.0.0.50 exfiltrating data. Which incident response action addresses the root cause?

    Answer: Block 10.0.0.50 specifically with a deny ACE before the permit statement

    Adding a specific deny ACE for the compromised host before the broad permit statement blocks that host while preserving access for legitimate users.

  5. During incident response, an analyst needs to determine which ACL rule permitted unauthorized SSH access. What is the most efficient method?

    Answer: Review ACL hit counters and logs filtered for port 22 traffic

    ACL hit counters combined with syslog entries filtered for destination port 22 pinpoint the permissive rule without disrupting the network.

  6. A company's ACL was modified by an attacker to allow inbound traffic on port 3389. What post-incident change control practice prevents recurrence?

    Answer: Require multi-person authorization and audit logging for ACL changes

    Dual-authorization and immutable audit logs for ACL changes create accountability and detect unauthorized modifications early.

  7. Which forensic artifact is most valuable when reconstructing the timeline of an ACL-bypass incident?

    Answer: Syslog timestamps of ACL deny/permit events correlated with NetFlow data

    Syslog ACL events with timestamps correlated against NetFlow provide a precise traffic timeline to reconstruct the attack sequence.