โ† All ACL Flashcard Decks

Vulnerability Assessment & Penetration Testing Flashcards

7 cards from real ACL practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Vulnerability Assessment & Penetration Testing flashcards as text
  1. A penetration tester discovers a reflexive ACL is in use. What type of attack does this control BEST defend against compared to a standard extended ACL?

    Answer: Session hijacking by tracking TCP session state and only permitting return traffic for established sessions

    Reflexive ACLs dynamically create temporary permit entries only for return traffic matching outbound sessions, preventing attackers from injecting unsolicited inbound packets that stateless ACLs might pass.

  2. When testing ACLs protecting a Voice over IP (VoIP) network, which UDP port range should a tester specifically verify is properly restricted to trusted sources only?

    Answer: UDP 16384-32767 (RTP media streams) and UDP 5060 (SIP signaling)

    RTP uses UDP ports 16384-32767 for media and SIP uses UDP 5060 for signaling; unrestricted access to these ports allows toll fraud, eavesdropping, and denial of service attacks against VoIP infrastructure.

  3. A vulnerability assessment reveals 'implicit permit' ACL behavior on a legacy switch. What does this mean and why is it dangerous?

    Answer: Traffic not matched by any ACL rule is permitted rather than denied, allowing unfiltered traffic through

    Implicit permit behavior (permit any as a default action) means traffic not explicitly denied passes through, which is the opposite of the secure 'default deny' stance and allows unanticipated traffic flows.

  4. During a penetration test, a tester successfully uses DNS port 53 UDP tunneling to exfiltrate data despite strict ACLs. Which ACL control would have prevented this?

    Answer: Restricting outbound DNS to only authorized internal DNS servers, blocking direct external DNS from workstations

    DNS tunneling exploits allowed outbound DNS traffic; restricting DNS to flow only through internal resolvers (which can be monitored) prevents direct DNS tunneling from endpoints to external servers.

  5. What is the purpose of testing ACLs using the 'ACL tester' or 'packet-tracer' feature on Cisco ASA during a vulnerability assessment?

    Answer: To simulate packet flows and verify whether specific traffic is permitted or denied without sending real packets

    The packet-tracer tool allows security testers to simulate a packet traversing the firewall and see exactly which ACL rules match it, confirming whether the security policy is enforced as intended.

  6. A penetration tester finds that a network allows ICMP type 3 code 3 (port unreachable) messages outbound from internal servers to the internet. How can this aid an attacker's reconnaissance?

    Answer: Responses confirm which UDP ports are closed on internal hosts, helping external attackers map internal services via negative space

    ICMP port unreachable (type 3, code 3) responses from internal hosts confirm that a UDP port is closed, enabling external attackers to perform UDP service discovery by identifying which ports don't respond.

  7. Which penetration testing methodology phase specifically involves reviewing ACL configurations for misconfigurations before active exploitation attempts?

    Answer: Vulnerability analysis / security assessment phase

    The vulnerability analysis phase includes reviewing network device configurations including ACLs to identify misconfigurations, which informs the subsequent exploitation phase without requiring active attacks.