Rule Configuration & Permissions Management Flashcards
7 cards from real ACL practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Rule Configuration & Permissions Management flashcards as text
Which ACL rule action causes the router to silently discard a packet without sending any notification to the source?
Answer: deny
The 'deny' action silently discards the packet, while 'reject' (used in some implementations) sends an ICMP unreachable message back to the source.
When configuring a named extended ACL on a Cisco router, which command enters the ACL configuration mode?
Answer: ip access-list extended MYACL
'ip access-list extended MYACL' is the correct command to create and enter named extended ACL configuration mode on Cisco IOS.
An administrator needs to permit only HTTPS traffic from a specific subnet. Which port number must be specified in the ACL rule?
Answer: 443
HTTPS uses TCP port 443, so the ACL rule must specify destination port 443 to permit only encrypted web traffic.
What does the wildcard mask 0.0.0.255 represent when used in an ACL?
Answer: Match all addresses in a /24 subnet
A wildcard mask of 0.0.0.255 means the last octet is irrelevant, so all 256 host addresses in a /24 subnet are matched.
An ACL rule reads: 'deny tcp 192.168.1.0 0.0.0.255 any eq 23'. What traffic does this block?
Answer: Telnet traffic originating from the 192.168.1.0/24 subnet
Port 23 is Telnet; this rule denies TCP connections from any host in 192.168.1.0/24 to port 23 on any destination.
Which of the following best describes a 'reflexive ACL'?
Answer: An ACL that automatically creates temporary permit entries for return traffic of established sessions
Reflexive ACLs dynamically create temporary entries to allow return traffic for outbound sessions, providing basic stateful filtering.
When adding a new rule to a numbered standard ACL on a Cisco router that already has entries, where is the new rule inserted by default?
Answer: At the end of the ACL before the implicit deny
New entries added to a numbered ACL are appended at the end of the list; to insert rules in a specific position, a named ACL with sequence numbers must be used.