Access Control Lists (ACLs) Flashcards
7 cards from real ACSP practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Access Control Lists (ACLs) flashcards as text
On an Aruba switch, which ACL type can match traffic based on both source and destination MAC addresses?
Answer: Extended MAC ACL
Extended MAC ACLs on Aruba switches allow matching on both source and destination MAC addresses, EtherType, and VLAN.
When applying an ACL to a VLAN interface on an Aruba switch, what does the 'in' direction filter?
Answer: Traffic entering the switch from hosts in that VLAN
Applying an ACL 'in' on a VLAN interface filters traffic as it ingresses from hosts in that VLAN toward the switch.
An administrator wants to permit SSH (port 22) from a management subnet 10.0.0.0/24 only. Which ACL entry accomplishes this?
Answer: permit tcp 10.0.0.0/24 any eq 22
SSH uses TCP port 22; permitting tcp from the source subnet to any destination on port 22 correctly scopes the rule.
In Aruba AOS-Switch ACL processing, what happens to a packet that does not match any explicit ACE?
Answer: It is dropped by the implicit deny all
All Aruba switch ACLs end with an implicit 'deny any' that drops packets not matching any configured ACE.
Which command on an Aruba AOS-Switch shows how many packets have matched each ACE in an ACL named 'BLOCK_WEB'?
Answer: show access-list BLOCK_WEB statistics
The 'show access-list statistics' command displays per-ACE hit counters for traffic matching that ACL.
A named ACL on an Aruba switch is applied to port 1/1 inbound. The ACL permits ICMP but has no other permit statements. What happens to TCP traffic arriving on port 1/1?
Answer: TCP traffic is dropped by the implicit deny
Only ICMP is explicitly permitted; all other protocols including TCP are dropped by the implicit deny all at the end of the ACL.
When configuring a mirror (SPAN) ACL on an Aruba switch, what is the primary purpose of the 'mirror' action keyword?
Answer: Copy matching traffic to a designated mirror port without dropping the original
The 'mirror' action copies matched packets to a configured mirror port while allowing the original traffic to continue forwarding.