โ† All ACL Flashcard Decks

Network Security & Traffic Filtering Flashcards

7 cards from real ACL practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Network Security & Traffic Filtering flashcards as text
  1. A Dynamic ACL (lock-and-key ACL) requires users to do what before gaining network access?

    Answer: Authenticate via Telnet or SSH to trigger a temporary permit entry

    Dynamic ACLs require users to authenticate via Telnet or SSH to the router, which then dynamically creates a temporary ACE permitting their traffic.

  2. What is the effect of applying an ACL to a VTY line with 'access-class 10 in'?

    Answer: It restricts which IP addresses can establish a Telnet or SSH management session to the router

    The 'access-class' command applied to VTY lines uses a standard ACL to restrict which source IP addresses are allowed to initiate Telnet or SSH management sessions.

  3. Which of the following is NOT a valid reason to use ACLs?

    Answer: Encrypting traffic between two routers

    ACLs filter and permit/deny traffic but do not provide encryption; encryption is handled by protocols like IPsec, SSL/TLS, or MACsec.

  4. An administrator sees 'access-list 1 permit 0.0.0.0 255.255.255.255' in the config. What traffic does this match?

    Answer: All IP traffic from any source address

    The combination of source address 0.0.0.0 and wildcard 255.255.255.255 matches all 32 bits as 'don't care,' which is equivalent to 'any' and permits all traffic.

  5. What is the significance of ACL sequence numbers in named ACLs on Cisco IOS?

    Answer: They allow specific ACEs to be inserted between existing entries or deleted individually

    Sequence numbers in named ACLs allow administrators to insert new ACEs at a specific position (e.g., sequence 15 between 10 and 20) or delete a specific ACE by its sequence number.

  6. A 'permit ip any any' rule exists in an ACL but traffic is still being blocked. What is the most likely cause?

    Answer: A more specific deny entry appears before the permit statement in the ACL

    Because ACLs process entries top-down and stop at the first match, a deny statement appearing before 'permit ip any any' will catch matching traffic before the permit is ever evaluated.

  7. Which show command displays the hit counts for each ACE in an ACL to verify it is matching traffic?

    Answer: show access-lists

    'show access-lists' displays each ACE along with its match count (number of packets matched), which is essential for verifying that the ACL is functioning as intended.