Network Security & Traffic Filtering Flashcards
7 cards from real ACL practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Network Security & Traffic Filtering flashcards as text
An ACL is configured to deny traffic from 10.0.0.0/8 but a host at 10.5.5.5 must be permitted. How should the ACEs be ordered?
Answer: Place the permit host 10.5.5.5 entry first, then the deny 10.0.0.0/8 entry
The more specific permit for host 10.5.5.5 must appear before the broader deny for 10.0.0.0/8, otherwise the host would be denied before reaching the permit statement.
Which ACL feature allows traffic filtering based on the time of day?
Answer: Time-based ACL
Time-based ACLs use a 'time-range' object to activate or deactivate ACEs during specific periods, enabling policies like blocking social media during business hours.
What wildcard mask is equivalent to using the 'host' keyword in an ACL statement?
Answer: 0.0.0.0
The wildcard mask 0.0.0.0 requires all 32 bits to match exactly, which is identical to specifying a single host using the 'host' keyword.
A company needs to allow only HTTPS traffic from the internet to their web server at 172.16.1.10. Which ACL entry achieves this?
Answer: access-list 101 permit tcp any host 172.16.1.10 eq 443
HTTPS uses TCP port 443, so the correct entry permits TCP traffic from any source to the web server specifically on port 443.
What does the keyword 'established' do in an extended ACL?
Answer: Permits TCP packets that have the ACK or RST bit set, indicating an existing session
The 'established' keyword matches TCP packets with the ACK or RST flag set, which indicates the packet is part of an already-established TCP session rather than a new connection.
How many ACLs can be applied per direction per interface on a Cisco router?
Answer: One
Cisco routers allow only one ACL per direction (inbound or outbound) per interface, so a maximum of two ACLs per interface (one in, one out).
Which command removes a specific numbered ACL from the running configuration?
Answer: no access-list 100
The 'no access-list [number]' command removes the entire numbered ACL from the configuration, deleting all its ACEs at once.