โ† All Cisco CCNA Flashcard Decks

Access Control Lists (ACLs) Flashcards

7 cards from real Cisco CCNA practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Access Control Lists (ACLs) flashcards as text
  1. Which wildcard mask would match only the host 192.168.10.5?

    Answer: 0.0.0.0

    A wildcard mask of 0.0.0.0 means all bits must match, which specifies a single host.

  2. Which ACL number range is used for extended IP ACLs?

    Answer: 100-199

    Extended IP ACLs use the number range 100-199 (and 2000-2699 for expanded range).

  3. Where should an extended ACL be placed for optimal performance?

    Answer: As close to the source as possible

    Extended ACLs should be placed close to the source to stop unwanted traffic early and reduce unnecessary network load.

  4. What does the 'established' keyword do in an extended ACL?

    Answer: Permits TCP packets with ACK or RST bits set

    The 'established' keyword matches TCP segments that have the ACK or RST bit set, indicating an existing session.

  5. An administrator applies the command 'ip access-group 101 in' on an interface. What does this mean?

    Answer: ACL 101 filters traffic entering the interface

    The 'in' keyword applies the ACL to inbound traffic arriving on that interface.

  6. Which command correctly creates a named extended ACL called BLOCK-WEB?

    Answer: ip access-list extended BLOCK-WEB

    The correct syntax to create a named extended ACL is 'ip access-list extended '.

  7. What happens when a packet matches a permit statement in an ACL?

    Answer: The packet is forwarded and no further ACL entries are checked

    Once a packet matches any ACL statement (permit or deny), processing stops and the action is taken immediately.

Access Control Lists (ACLs) Flashcards โ€” Cisco CCNA Study Cards with Answers