โ† All ACL Flashcard Decks

Vulnerability Assessment & Penetration Testing Flashcards

7 cards from real ACL practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Vulnerability Assessment & Penetration Testing flashcards as text
  1. When conducting a vulnerability assessment, which tool is most commonly used to automatically audit Cisco ACL configurations for weaknesses?

    Answer: Nipper or CIS-CAT for network device configuration analysis

    Nipper and CIS-CAT are specialized tools designed to audit router and switch configurations, including ACL rules, against security best practices and known vulnerabilities.

  2. A tester discovers an ACL that permits 'established' keyword for TCP return traffic. What vulnerability does improper use of this keyword introduce?

    Answer: Attackers can craft packets with the ACK bit set to bypass the ACL and probe internal hosts

    The 'established' keyword only checks for the ACK or RST bit in stateless ACLs, allowing attackers to send crafted packets with ACK set to bypass filtering without a prior legitimate connection.

  3. During an ACL penetration test, a tester finds that management interfaces (SSH, SNMP) are not restricted by source IP in the ACL. What is the highest-priority remediation?

    Answer: Add ACL entries restricting management protocol access to specific trusted management subnets only

    Management interfaces should only be reachable from designated management networks; source IP restrictions in ACLs prevent attackers on untrusted networks from reaching these high-value targets.

  4. A penetration tester uses fragmented IP packets to attempt to bypass an ACL. Which ACL feature is specifically designed to counter this technique?

    Answer: IP Fragment handling with the 'fragments' keyword or stateful inspection

    Cisco ACLs support a 'fragments' keyword that controls how non-initial IP fragments are handled, preventing attackers from hiding malicious traffic in packet fragments that skip layer-4 inspection.

  5. Which OWASP testing technique most directly applies when assessing whether web application ACLs properly enforce authorization?

    Answer: Horizontal and vertical privilege escalation testing to verify access control enforcement

    Horizontal privilege escalation (accessing other users' resources) and vertical privilege escalation (accessing higher-privilege functions) directly test whether ACL-enforced authorization controls are correctly implemented.

  6. A vulnerability assessment finds that a DMZ firewall ACL allows all traffic from DMZ servers to the internal network. Why is this a critical finding?

    Answer: A compromised DMZ server can directly attack internal hosts without restriction

    The DMZ is designed as a semi-trusted zone; unrestricted access from DMZ to internal networks means a single compromised DMZ server gives attackers a pivot point to attack the entire internal network.

  7. During ACL testing, a penetration tester performs a 'time-based ACL evasion' attack. What does this exploit?

    Answer: Time-based ACL rules that only restrict traffic during certain hours, leaving gaps attackers can exploit outside restricted windows

    Time-based ACLs restrict certain traffic only during configured time windows; if not carefully designed, attackers can access restricted resources simply by initiating connections outside the restricted time period.