โ† All ACL Flashcard Decks

Incident Response & Recovery Flashcards

7 cards from real ACL practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Incident Response & Recovery flashcards as text
  1. During a post-incident review, analysts find that an ACL had an implicit 'permit ip any any' instead of the expected 'deny ip any any'. What risk does this represent?

    Answer: All unmatched traffic was allowed, potentially permitting attacker traffic through the device

    A missing or incorrect implicit deny means all traffic not explicitly matched by earlier ACEs passes through unchecked, nullifying the ACL's security purpose.

  2. An organization detects lateral movement between VLANs despite inter-VLAN ACLs being in place. Which explanation is most likely?

    Answer: An ACL is applied in the wrong direction on the Layer 3 SVI

    ACLs applied in the wrong direction on an SVI (e.g., inbound instead of outbound or vice versa) fail to inspect the traffic in the intended flow path.

  3. What is the purpose of the 'established' keyword in an extended ACL during incident recovery for TCP traffic?

    Answer: It allows inbound TCP packets that have the ACK or RST bit set, indicating an existing session

    The 'established' keyword permits inbound TCP replies (ACK/RST set) while blocking unsolicited inbound SYN packets that initiate new connections.

  4. Which incident scenario requires an object-group ACL rather than a traditional ACL for efficient management?

    Answer: Permitting access from 50 different source IPs to 20 different destination services

    Object-group ACLs consolidate many IPs and services into named groups, drastically reducing the number of ACEs needed compared to individual entries for each combination.

  5. After an insider threat incident, an administrator audits ACLs and finds overly permissive rules violating least privilege. Which remediation approach is best practice?

    Answer: Replace all ACLs with a single deny-all rule and gradually add permit rules based on verified business need

    Starting with deny-all and adding only verified permit rules implements the principle of least privilege and ensures no unintended access remains.

  6. A router's ACL log shows thousands of entries for 'deny ip any any' in a short window. What does this most likely indicate?

    Answer: A network scan or DoS attack generating traffic that fails all ACL permit rules

    A surge in implicit deny hits indicates large volumes of traffic matching no permit rules, consistent with a scan or DoS attack probing the network.

  7. When re-applying a corrected ACL after an incident, which step prevents an accidental outage?

    Answer: Remove the existing ACL from the interface, verify the replacement, then apply the corrected version during a maintenance window

    Removing the old ACL, verifying the new one in a test environment, and applying during a maintenance window minimizes disruption risk.

Incident Response & Recovery Flashcards โ€” ACL Study Cards with Answers