โ† All ACL Flashcard Decks

Vulnerability Assessment & Penetration Testing Flashcards

7 cards from real ACL practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Vulnerability Assessment & Penetration Testing flashcards as text
  1. During a penetration test, a tester discovers that a router ACL permits inbound Telnet (port 23) from any source. What is the primary security risk?

    Answer: Telnet transmits credentials in plaintext, enabling credential interception

    Telnet sends all data, including usernames and passwords, in cleartext, making it trivial for an attacker to capture credentials via packet sniffing.

  2. A penetration tester uses 'nmap -sA' against a target network. What does a 'filtered' result on a port typically indicate?

    Answer: A firewall or ACL is blocking probe packets to that port

    A 'filtered' nmap result means a firewall, ACL, or other network device is dropping or rejecting packets before they reach the target port.

  3. Which ACL misconfiguration most commonly allows an attacker to perform IP spoofing attacks into a network?

    Answer: Absence of ingress filtering that blocks private IP ranges from external interfaces

    Without ingress ACL filtering that blocks RFC 1918 private addresses and other bogon ranges on external interfaces, attackers can spoof internal IP addresses to bypass security controls.

  4. A vulnerability scan reveals that ACL entries allow ICMP unreachable messages outbound. Why might a penetration tester consider this a finding?

    Answer: These messages can reveal internal network topology and ACL rule structures to an attacker

    ICMP unreachable messages returned to external hosts can reveal which ports/protocols are filtered versus closed, helping attackers map the network's ACL ruleset.

  5. During ACL review, a tester finds the rule 'permit ip any any' at the end of an extended ACL. What is the security implication?

    Answer: The rule overrides all previous deny statements, allowing all traffic through

    A 'permit ip any any' at the end of an ACL negates the implicit deny-all, allowing any traffic not matched by earlier rules to pass through unchecked.

  6. What technique do penetration testers use to bypass ACLs that block standard scanning ports by sending packets with specific TCP flags?

    Answer: ACK scanning or FIN scanning to probe through stateless ACLs

    ACK and FIN scans exploit stateless ACLs that only filter SYN packets, since these ACLs may permit non-SYN packets that appear to belong to established connections.

  7. A penetration tester discovers that a network ACL permits outbound traffic to TCP port 4444. What common threat does this suggest?

    Answer: A potential Metasploit reverse shell channel or malware command-and-control

    TCP port 4444 is the default listener port for Metasploit's Meterpreter reverse shells, and its presence in egress ACLs may indicate malware or unauthorized remote access.