Types & Classification Flashcards
7 cards from real ACL practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Types & Classification flashcards as text
Which ACL type is most suitable for implementing per-user security policies after 802.1X authentication?
Answer: Downloadable ACL (dACL)
Downloadable ACLs (dACLs) are pushed from a RADIUS/ISE server to a switch after 802.1X authentication to enforce per-user access policies.
In Cisco terminology, which ACL type uses the 'ip access-list extended' command instead of the 'access-list' global command?
Answer: Named ACL
Named ACLs are created with the 'ip access-list standard|extended ' command, which enters ACL configuration mode.
Which statement about Cisco ACL types and their numbered ranges is CORRECT?
Answer: Standard IP ACLs use 1–99; extended use 100–199
Cisco standard IP ACLs use numbers 1–99 (expanded: 1300–1999), while extended IP ACLs use 100–199 (expanded: 2000–2699).
A 'turbo ACL' in Cisco IOS is a classification referring to:
Answer: Compiled ACLs that use a lookup table for faster hardware matching
Turbo ACLs compile ACL entries into indexed lookup tables, significantly improving packet matching speed on large ACLs.
Which type of ACL is evaluated BEFORE routing decisions are made on a Cisco router?
Answer: Inbound interface ACL
Inbound ACLs are processed as packets arrive on an interface, before the router makes a routing table lookup decision.
Which ACL classification is used in Cisco ASA firewalls that differs from IOS router ACLs?
Answer: ASA ACLs are applied inbound on both interfaces and use stateful inspection by default
Cisco ASA ACLs are paired with stateful inspection — only inbound ACLs are typically needed because return traffic is tracked by the state table.
Which term describes ACLs that are automatically generated by Cisco IOS to support features like NAT or GRE tunnels?
Answer: Implicit system-generated ACLs
IOS automatically creates implicit system-generated ACL entries to support internal features such as NAT translations and tunnel encapsulation.