Types & Classification Flashcards
7 cards from real ACL practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Types & Classification flashcards as text
Which scenario best justifies using a time-based ACL over a standard ACL?
Answer: Allowing guest Wi-Fi internet access only during 8 AM–6 PM business hours
Time-based ACLs are ideal for enforcing access policies that vary by time of day or day of week, such as business-hours-only internet access.
Which ACL type classification is based on the direction of traffic it evaluates?
Answer: Inbound vs. outbound
ACLs are also classified by application direction — inbound ACLs evaluate packets arriving on an interface, outbound ACLs evaluate packets leaving an interface.
A port ACL (PACL) on a Cisco switch is applied at which level?
Answer: Physical switch port level
Port ACLs (PACLs) are applied directly to physical Layer 2 switch ports and filter traffic entering those ports.
Which ACL classification would an administrator choose to filter traffic based on DSCP markings?
Answer: Extended ACL with DSCP matching
Extended ACLs support matching on IP Differentiated Services Code Point (DSCP) values, enabling QoS-aware filtering.
How does a stateless ACL differ from a stateful firewall ACL?
Answer: Stateless ACLs evaluate each packet independently without tracking session state
Traditional router ACLs are stateless — each packet is evaluated independently with no memory of prior packets in a session.
Which term describes an ACL specifically configured to protect BGP sessions on an internet-facing router?
Answer: Infrastructure ACL (iACL)
Infrastructure ACLs (iACLs) are commonly deployed on internet-facing routers to permit only legitimate BGP peers and block unauthorized access to routing infrastructure.
What is the primary classification difference between a standard ACL numbered 50 and one numbered 1500?
Answer: ACL 50 is standard (1–99 range); ACL 1500 is in the expanded standard range (1300–1999)
Cisco expanded the standard ACL range to 1300–1999 to provide additional numbered ACL identifiers beyond the original 1–99 range.