Rule Configuration & Permissions Management Flashcards
7 cards from real ACL practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Rule Configuration & Permissions Management flashcards as text
Which ACL type can filter traffic based on both source and destination IP addresses as well as Layer 4 port numbers?
Answer: Extended ACL
Extended ACLs can match on source/destination IP, protocol, and source/destination port numbers, offering much finer granularity than standard ACLs.
An administrator applies the same ACL to an interface twice — once inbound and once outbound. What happens?
Answer: Cisco IOS replaces the first application with the second for that direction
On Cisco IOS, only one ACL of a given type can be applied per interface per direction; applying a second ACL in the same direction overwrites the first.
What is the purpose of the 'established' keyword in an extended ACL rule for TCP?
Answer: It permits TCP segments that have the ACK or RST flag set, indicating an established session
The 'established' keyword matches TCP packets with ACK or RST flags set, which are characteristic of return traffic in an existing connection.
An ACL is configured with the following rules in order: (1) permit 10.0.0.0/8, (2) deny 10.1.0.0/16. A packet from 10.1.1.5 arrives. What happens?
Answer: The packet is permitted by rule 1
ACLs are processed top-to-bottom; rule 1 matches 10.1.1.5 (which is within 10.0.0.0/8) before rule 2 is even evaluated, so the packet is permitted.
Which command removes a specific sequence-numbered entry (e.g., sequence 30) from a named ACL on Cisco IOS?
Answer: ip access-list extended MYACL / no 30
Entering named ACL config mode with 'ip access-list extended MYACL' and then 'no 30' removes the entry with sequence number 30.
A DACL (Downloadable ACL) is most commonly associated with which technology?
Answer: 802.1X port-based authentication with RADIUS
DACLs are pushed from a RADIUS server to network devices after successful 802.1X authentication, dynamically applying per-user access policies.
What is the maximum number of ACEs (Access Control Entries) typically recommended per ACL on a performance-sensitive router interface?
Answer: Fewer is better; each entry consumes TCAM or CPU cycles during lookup
Each ACE consumes hardware TCAM resources or requires a CPU lookup cycle, so minimizing ACE count improves forwarding performance.