Access Control Lists (ACLs) Flashcards
7 cards from real ACSP practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Access Control Lists (ACLs) flashcards as text
Which Aruba switch ACL feature allows you to assign a QoS priority to packets matching a specific ACE?
Answer: ACL remarking with DSCP set action
Aruba AOS-Switch ACEs support a 'set dscp' or priority action that remarks the DSCP value of matching packets for QoS treatment.
On an Aruba switch, what is the maximum number of ACLs that can be simultaneously applied to a single port?
Answer: One per direction per traffic type (e.g., one IPv4 in, one IPv4 out)
Aruba switches allow one ACL per direction per type (IPv4, IPv6, MAC) on a port, so multiple ACLs can coexist if they are different types or directions.
An extended ACL entry reads: 'deny tcp 192.168.10.0/24 172.16.0.0/16 eq 80'. Which traffic does this block?
Answer: TCP port 80 from 192.168.10.0/24 to 172.16.0.0/16
The ACE matches TCP traffic sourced from 192.168.10.0/24 destined for port 80 on any host in 172.16.0.0/16.
What does the 'established' keyword do when used in an Aruba extended IP ACL entry for TCP?
Answer: Matches only TCP segments with ACK or RST flags set
The 'established' keyword matches TCP packets with the ACK or RST bit set, indicating they belong to an existing connection rather than initiating a new one.
An Aruba switch ACL is applied outbound on a routed VLAN interface. Which traffic does it inspect?
Answer: Traffic being routed out of that VLAN toward other networks
An outbound ACL on a routed VLAN interface inspects traffic that has been routed and is exiting through that interface toward its destination.
Which of the following is a valid reason to place an extended ACL close to the traffic source on an Aruba switch?
Answer: To drop unwanted traffic early and reduce unnecessary transit
Placing extended ACLs near the source drops unwanted traffic before it traverses the network, reducing bandwidth consumption on transit links.
On an Aruba switch, what happens if you attempt to apply an ACL that references a non-existent ACL name to an interface?
Answer: The switch rejects the command with an error
Aruba AOS-Switch returns an error if you try to apply an ACL name that has not been defined, preventing misconfiguration.