Access Control Lists (ACLs) Flashcards
7 cards from real ACSP practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Access Control Lists (ACLs) flashcards as text
In Aruba AOS-CX, which command correctly creates a named IPv4 ACL called 'RESTRICT_GUEST'?
Answer: ip access-list RESTRICT_GUEST
On Aruba AOS-CX, 'ip access-list ' enters ACL configuration mode to define an IPv4 named ACL.
On an Aruba AOS-CX switch, how is an ACL applied to a VLAN interface in the inbound direction?
Answer: Under the VLAN interface: 'ip access-group in'
On AOS-CX, you navigate to the VLAN interface and use 'ip access-group in' to apply an IPv4 ACL inbound.
What is the effect of adding the 'log' action to an ACE on an Aruba switch?
Answer: Matching packets are forwarded with a syslog entry generated
The 'log' keyword generates a syslog message for each matching packet but does not change the permit or deny action of the ACE.
Which Aruba ACL type is specifically designed to filter traffic based on EtherType values such as ARP or IPv6?
Answer: MAC ACL with EtherType matching
MAC ACLs on Aruba switches support EtherType matching, enabling filtering of specific Layer 2 protocols like ARP (0x0806) or IPv6 (0x86DD).
On an Aruba switch, an ACL applied to a LAG (Link Aggregation Group) is enforced on which ports?
Answer: All member ports of the LAG simultaneously
An ACL applied to a LAG interface is enforced on all member ports simultaneously, ensuring consistent filtering across the aggregated link.
A security engineer wants to block ICMP echo requests (ping) from host 10.1.1.5 to the server farm 172.31.0.0/16. Which ACE is correct?
Answer: deny icmp host 10.1.1.5 172.31.0.0/16 echo
ICMP type 'echo' (ping request) is correctly denied from the specific source host to the destination subnet using the icmp protocol keyword.
When troubleshooting an ACL on an Aruba AOS-Switch, which command clears the ACE hit counters so you can observe fresh traffic patterns?
Answer: clear access-list statistics
'clear access-list statistics' resets all hit counters for the specified ACL, allowing fresh observation of traffic matching each ACE.