Types & Classification Flashcards
7 cards from real ACL practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Types & Classification flashcards as text
Which ACL classification operates at Layer 3 and Layer 4 of the OSI model?
Answer: Extended ACL
Extended ACLs examine Layer 3 fields (IP addresses) and Layer 4 fields (TCP/UDP ports and flags) for filtering decisions.
A VACL (VLAN Access Control List) differs from a router ACL in that it:
Answer: Can filter traffic within the same VLAN on a switch
VACLs (also called VLAN maps) can filter all traffic within a VLAN, including traffic that is switched and never routed.
Which statement correctly distinguishes numbered from named ACLs?
Answer: Named ACLs allow individual entry deletion and descriptive labels; numbered ACLs traditionally require full replacement
Named ACLs allow you to delete individual sequence-numbered entries and use meaningful names, advantages not available in traditional numbered ACLs.
An infrastructure ACL (iACL) is primarily used to:
Answer: Protect the network device's control plane from unauthorized access
Infrastructure ACLs protect router and switch management planes by permitting only legitimate management and routing protocol traffic to the device itself.
Which ACL type would you use to filter Ethernet frames based on MAC address?
Answer: MAC ACL (EtherType ACL)
MAC ACLs (EtherType ACLs) operate at Layer 2 and match traffic based on source or destination MAC addresses.
What distinguishes a 'receive ACL' (rACL) from a standard interface ACL on Cisco platforms?
Answer: rACLs filter traffic destined for the router's own IP addresses specifically
A receive ACL (rACL) filters packets destined for the router's own processor, protecting the control plane from traffic addressed directly to the device.
IPv6 ACLs differ from IPv4 ACLs in that they:
Answer: Automatically include implicit permits for neighbor discovery messages
IPv6 ACLs automatically include implicit permit entries for ICMPv6 Neighbor Discovery messages required for normal IPv6 operation.