Network Security & Traffic Filtering Flashcards
7 cards from real ACL practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Network Security & Traffic Filtering flashcards as text
A named ACL uses 'ip access-list extended BLOCK_HTTP'. What advantage does the name provide?
Answer: It allows insertion or deletion of specific ACEs without rewriting the entire ACL
Named ACLs allow administrators to add, remove, or reorder individual ACEs using sequence numbers without deleting and recreating the entire ACL.
Which protocol number is used in an ACL to match ICMP traffic?
Answer: 1
ICMP is assigned IP protocol number 1, which can be used in extended ACLs with 'permit icmp' or 'permit 1'.
An administrator configures 'access-list 50 permit 192.168.0.0 0.0.255.255'. Which traffic is permitted?
Answer: All hosts in the 192.168.0.0/16 network
The wildcard mask 0.0.255.255 allows the last two octets to vary freely, matching all 65,536 hosts in the 192.168.0.0/16 address space.
What is a 'reflexive ACL' used for in network security?
Answer: Automatically permitting return traffic for sessions initiated from inside the network
Reflexive ACLs dynamically create temporary entries that permit return traffic for sessions initiated from the trusted inside network, providing stateful-like behavior.
Which command verifies which ACLs are applied to a specific router interface?
Answer: show ip interface
'show ip interface' displays the inbound and outbound ACLs applied to each interface along with other IP interface statistics.
A packet arrives at a router with an ACL containing 15 ACEs. The packet matches ACE #7 which denies it. What happens to ACEs 8–15?
Answer: They are skipped because processing stops at the first match
ACL processing is top-down and stops at the first matching ACE; once a packet matches ACE #7, the remaining ACEs are not evaluated.
What is the purpose of the 'log' keyword appended to an ACL ACE?
Answer: It generates a syslog message each time a packet matches that ACE
The 'log' keyword causes the router to generate a syslog message with match statistics each time a packet matches that specific ACE.