← All ACL Flashcard Decks

Mixed Deck — All ACL Topics Flashcards

100 cards from real ACL practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 20 Mixed Deck — All ACL Topics flashcards as text
  1. Which of the following best describes confidentiality in Access Control Lists?

    Answer: Protecting sensitive information from unauthorized disclosure

    Confidentiality involves protecting sensitive information and only sharing it with authorized parties who need it.

  2. Under the CIS Benchmarks for network devices, what is the recommended treatment of the ACL 'permit ip any any' rule?

    Answer: It should never appear in a production ACL on external-facing interfaces

    CIS Benchmarks prohibit 'permit ip any any' on external-facing interfaces as it negates all other ACL controls and violates least-privilege.

  3. During an ACL penetration test, a tester finds that management interfaces (SSH, SNMP) are not restricted by source IP in the ACL. What is the highest-priority remediation?

    Answer: Add ACL entries restricting management protocol access to specific trusted management subnets only

    Management interfaces should only be reachable from designated management networks; source IP restrictions in ACLs prevent attackers on untrusted networks from reaching these high-value targets.

  4. An engineer is implementing ACLs on a Cisco router and notices the implicit deny at the end. What action should be taken to meet logging compliance requirements for denied traffic?

    Answer: Add an explicit 'deny any any log' rule before the implicit deny

    The implicit deny does not generate log entries; adding an explicit 'deny any any log' statement captures denied traffic for compliance logging.

  5. A security team reviews ACL logs to meet NIST SP 800-53 AU-2 (Auditable Events) requirements. Which log entries are most critical to capture from ACL devices?

    Answer: Both permitted and denied connection attempts including source IP, destination IP, port, protocol, and timestamp

    AU-2 requires logging both allowed and denied events; capturing complete ACL flow data (source, destination, port, protocol, time) enables auditing and forensic analysis.

  6. Which wildcard mask would match only the host 192.168.10.25?

    Answer: 0.0.0.0

    A wildcard mask of 0.0.0.0 means all bits must match exactly, which is equivalent to specifying a single host.

  7. An organization implements Zero Trust Architecture (ZTA) as guided by NIST SP 800-207. How does this change their approach to ACLs compared to traditional perimeter-based compliance?

    Answer: ZTA requires per-session ACL enforcement based on identity, device posture, and context rather than relying on network location as a trust signal

    NIST SP 800-207 ZTA shifts ACL enforcement from network-perimeter trust to per-session dynamic policies based on identity, device health, and request context regardless of network location.

  8. Which mechanism allows a client to check whether a TLS certificate has been revoked without downloading a full Certificate Revocation List (CRL)?

    Answer: OCSP (Online Certificate Status Protocol)

    OCSP lets a client query the CA's OCSP responder in real time to check a specific certificate's revocation status, avoiding the need to download and process a full CRL.

  9. After an insider threat incident, an administrator audits ACLs and finds overly permissive rules violating least privilege. Which remediation approach is best practice?

    Answer: Replace all ACLs with a single deny-all rule and gradually add permit rules based on verified business need

    Starting with deny-all and adding only verified permit rules implements the principle of least privilege and ensures no unintended access remains.

  10. Which type of threat actor is most likely to conduct slow, low-volume port scans that attempt to evade ACL-based detection?

    Answer: Advanced Persistent Threat (APT) actors

    APT actors deliberately use slow, distributed scanning techniques to avoid triggering rate-based ACL logging thresholds.

  11. An extended ACL uses the keyword 'any' in the source field. What does this represent?

    Answer: 0.0.0.0 with wildcard mask 255.255.255.255

    'any' is shorthand for source address 0.0.0.0 with wildcard mask 255.255.255.255, which matches every possible IP address.

  12. A SOC team wants to detect port scanning activity using ACL logs. Which pattern in the logs would best indicate a port scan from a single source?

    Answer: Many deny hits from one source IP to many different destination ports

    A port scan appears in ACL logs as one source IP generating deny matches across many different destination ports in a short time.

  13. Which ACL feature allows a security team to dynamically permit return traffic for established sessions without writing explicit inbound permit rules?

    Answer: Extended ACL with established keyword for TCP

    The 'established' keyword in an extended ACL permits TCP packets with the ACK or RST bit set, allowing return traffic for sessions initiated outbound without tracking full state.

  14. Which NIST incident response phase involves analyzing ACL logs to determine the scope and impact of a network security breach?

    Answer: Detection and Analysis

    The Detection and Analysis phase involves collecting and examining logs—including ACL logs—to characterize the incident's scope, source, and impact.

  15. Which scenario best justifies using a time-based ACL over a standard ACL?

    Answer: Allowing guest Wi-Fi internet access only during 8 AM–6 PM business hours

    Time-based ACLs are ideal for enforcing access policies that vary by time of day or day of week, such as business-hours-only internet access.

  16. Which factor is most important for effective delegation in Access Control Lists?

    Answer: Matching tasks to team members' skills and development goals

    Effective delegation considers team members' current skills and development goals to ensure tasks are completed well and people grow.

  17. How does collaboration enhance Cloud Security Architecture in Access Control Lists?

    Answer: It brings diverse perspectives and improves outcomes

    Collaboration brings together different viewpoints and expertise, leading to better decision-making and outcomes.

  18. Which IAM concept ensures that no single user has enough privileges to complete a sensitive transaction alone?

    Answer: Separation of duties

    Separation of duties requires that critical tasks be split among multiple users to prevent fraud or error by any one individual.

  19. A network administrator wants to block Telnet traffic from host 10.1.1.5 to any destination. Which ACL command is correct?

    Answer: access-list 100 deny tcp host 10.1.1.5 any eq 23

    Telnet uses TCP port 23, so the correct command uses 'tcp' protocol and 'eq 23' to match Telnet traffic from the specific host.

  20. What distinguishes a 'receive ACL' (rACL) from a standard interface ACL on Cisco platforms?

    Answer: rACLs filter traffic destined for the router's own IP addresses specifically

    A receive ACL (rACL) filters packets destined for the router's own processor, protecting the control plane from traffic addressed directly to the device.