Network Security & Traffic Filtering Flashcards
7 cards from real ACL practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Network Security & Traffic Filtering flashcards as text
Which ACL type can filter traffic based on both source and destination IP addresses as well as port numbers?
Answer: Extended ACL
Extended ACLs filter on source/destination IP, protocol, and port numbers, offering much more granular control than standard ACLs.
An ACL is applied with 'ip access-group 110 in' on an interface. What does 'in' specify?
Answer: Traffic entering the router interface from the network
The 'in' keyword means the ACL filters traffic as it enters the router interface from the connected network segment.
What is the effect of the implicit 'deny all' at the end of every ACL?
Answer: It drops any traffic not explicitly permitted by earlier ACE statements
Every ACL ends with an implicit deny all entry that drops any packet not matched by a preceding permit or deny statement.
A network administrator wants to block Telnet traffic from host 10.1.1.5 to any destination. Which ACL command is correct?
Answer: access-list 100 deny tcp host 10.1.1.5 any eq 23
Telnet uses TCP port 23, so the correct command uses 'tcp' protocol and 'eq 23' to match Telnet traffic from the specific host.
Where should an extended ACL be placed for optimal performance?
Answer: As close to the source as possible
Extended ACLs should be placed close to the source so unwanted traffic is dropped early, reducing unnecessary bandwidth consumption.
Which wildcard mask would match only the host 192.168.10.25?
Answer: 0.0.0.0
A wildcard mask of 0.0.0.0 means all bits must match exactly, which is equivalent to specifying a single host.
What does the ACE 'permit ip any any' accomplish when placed at the end of an ACL?
Answer: It permits all traffic not previously matched by earlier ACEs
Placing 'permit ip any any' at the end of an ACL allows all traffic that was not denied by previous ACEs to pass through.