Incident Response & Recovery Flashcards
7 cards from real ACL practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Incident Response & Recovery flashcards as text
A wildcard mask of 0.0.0.255 in an ACL entry on a Cisco router matches which range of addresses when paired with 192.168.1.0?
Answer: 192.168.1.0 through 192.168.1.255
A wildcard mask of 0.0.0.255 ignores the last octet, matching all 256 host addresses in the 192.168.1.0 /24 network.
During recovery from an ACL misconfiguration that caused a network outage, which rollback strategy carries the lowest risk?
Answer: Restoring a known-good ACL from a version-controlled configuration backup
Version-controlled backups provide verified, tested configurations that can be restored quickly and accurately without introducing new errors.
An IDS alert indicates ACL-permitted traffic is being used for command-and-control (C2) over port 443. Which containment action is most targeted?
Answer: Add a deny ACE for the specific C2 destination IP before the permit HTTPS rule
Inserting a deny ACE for the known C2 IP before the broad HTTPS permit rule surgically blocks C2 while preserving legitimate HTTPS traffic.
What does a reflexive ACL (IP session filtering) do that a standard ACL cannot during incident recovery?
Answer: Permits inbound traffic only for established outbound sessions
Reflexive ACLs dynamically create temporary permit entries for return traffic matching established outbound sessions, blocking unsolicited inbound connections.
After an incident where ACL rules were exhausted by a DoS attack flooding the ACE table, which preventive measure is most appropriate?
Answer: Implement upstream rate-limiting and summarize ACL rules to reduce ACE count
Upstream rate-limiting reduces attack volume, while ACL summarization decreases table size, preventing TCAM exhaustion.
Which ACL placement rule is critical during incident recovery to stop an internal host from communicating with a known malicious external IP?
Answer: Place an extended ACL on the internal interface in the outbound direction
An extended ACL on the internal (LAN-facing) interface in the outbound direction blocks traffic as it leaves the internal network toward the malicious IP.
A security team discovers that a time-based ACL was incorrectly configured, allowing unauthorized access during off-hours. Which recovery action directly addresses this?
Answer: Correct the time-range definition and verify NTP synchronization on all devices
Fixing the time-range definition and ensuring NTP accuracy guarantees the time-based ACL enforces the correct schedule.