← All ACSP Flashcard Decks

Access Control Lists (ACLs) Flashcards

7 cards from real ACSP practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 Access Control Lists (ACLs) flashcards as text
  1. Which Aruba AOS-CX ACL feature allows an ACE to redirect matching traffic to a specified next-hop IP address instead of normal routing?

    Answer: ACE redirect action with a nexthop parameter

    AOS-CX ACEs support a 'redirect' action that policy-routes matching packets to a specified next-hop, bypassing the normal routing table.

  2. On an Aruba switch, what is the primary purpose of a 'remark' entry in an ACL configuration?

    Answer: To add a human-readable comment to the ACL without affecting traffic

    A 'remark' is a comment line in an ACL that is visible in the configuration for documentation purposes but has no effect on packet processing.

  3. An ACL contains these sequential ACEs: (1) permit tcp any any eq 443, (2) deny ip 10.0.0.0/8 any, (3) permit ip any any. What happens to HTTPS traffic from 10.5.5.5?

    Answer: It is permitted by ACE 1 before reaching ACE 2

    ACL processing is top-down and stops at the first match; TCP port 443 from any source matches ACE 1 and is permitted before ACE 2 is evaluated.

  4. In Aruba AOS-CX, which ACL type uses 'ipv6 access-list' to filter IPv6 traffic on an interface?

    Answer: IPv6 ACL

    AOS-CX uses 'ipv6 access-list ' to create dedicated IPv6 ACLs that match on IPv6 source/destination addresses and upper-layer protocols.

  5. What is the recommended best practice for ACL sequence numbers on Aruba switches to allow future ACE insertions?

    Answer: Number ACEs in increments of 10 (10, 20, 30…) to leave gaps for insertion

    Numbering ACEs in increments of 10 leaves room to insert new entries between existing ones without resequencing the entire ACL.

  6. On an Aruba switch, which ACL application scenario would require a VLAN ACL (VACL) rather than an interface ACL?

    Answer: Filtering traffic between two hosts within the same VLAN

    VACLs filter traffic within a VLAN (intra-VLAN), including host-to-host traffic that never leaves the VLAN and would not traverse a routed interface.

  7. After configuring an ACL on an Aruba AOS-Switch, the administrator notices traffic that should be blocked is still passing. Which of the following is the most likely cause?

    Answer: The ACL was not applied to the correct interface or direction

    A common misconfiguration is creating an ACL correctly but forgetting to apply it to the specific interface and direction where the traffic should be filtered.