← All ACL Flashcard Decks

Incident Response & Recovery Flashcards

7 cards from real ACL practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 Incident Response & Recovery flashcards as text
  1. Which NIST incident response phase involves analyzing ACL logs to determine the scope and impact of a network security breach?

    Answer: Detection and Analysis

    The Detection and Analysis phase involves collecting and examining logs—including ACL logs—to characterize the incident's scope, source, and impact.

  2. An attacker used IP spoofing to bypass an ACL that permits traffic from 10.0.0.0/8. Which ACL technique mitigates this attack vector?

    Answer: Implementing ingress filtering (anti-spoofing ACLs) that deny RFC 1918 addresses arriving on external interfaces

    Anti-spoofing ACLs on external interfaces deny private IP addresses that should never arrive from the internet, blocking IP spoofing attempts.

  3. During incident recovery, a team must restore ACL configurations across 200 routers quickly. Which approach is most efficient and least error-prone?

    Answer: Use a network automation tool (e.g., Ansible or NAPALM) to push verified ACL templates to all devices

    Automation tools push pre-tested ACL configurations consistently to all devices simultaneously, eliminating human typing errors and drastically reducing recovery time.

  4. A named ACL called BLOCK_MALWARE is missing entries after an incident. Which command verifies the current contents on a Cisco device?

    Answer: show ip access-lists BLOCK_MALWARE

    The 'show ip access-lists ' command displays all ACEs in the named ACL along with hit counts, confirming current content.

  5. Which lesson-learned action best improves ACL resilience after repeated incidents caused by human configuration errors?

    Answer: Implement ACL syntax validation and peer review in a change management pipeline before deployment

    Pre-deployment syntax validation and peer review catch errors before they reach production, directly addressing the root cause of configuration-related incidents.

  6. After an incident where ACL logging consumed all available disk space, which configuration change prevents recurrence while maintaining visibility?

    Answer: Configure log rate-limiting and send logs to a remote syslog server with adequate storage

    Rate-limiting prevents log storms from exhausting local storage, while a remote syslog server provides scalable, persistent log retention.

  7. During the post-incident activity phase, which documentation output is most valuable for improving future ACL-related incident response?

    Answer: An updated incident response playbook with specific ACL remediation steps and rollback procedures

    An updated playbook with ACL-specific remediation and rollback steps codifies lessons learned into actionable procedures for faster future response.