Access Control Lists (ACLs) Flashcards
7 cards from real Cisco CCNA practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Access Control Lists (ACLs) flashcards as text
What is the effect of the implicit deny at the end of every ACL?
Answer: It drops all traffic that does not match any ACL entry
Every ACL ends with an implicit 'deny any' that silently drops any traffic not matched by a previous entry.
Which ACL type can filter traffic based on both source AND destination IP address?
Answer: Extended ACL
Extended ACLs can match on source IP, destination IP, protocol, and port numbers.
Which command verifies which ACLs are applied to a specific interface and their direction?
Answer: show ip interface
'show ip interface' displays the inbound and outbound ACLs applied to each interface.
A network administrator needs to block only Telnet traffic from host 10.1.1.1 to any destination. Which ACL entry achieves this?
Answer: access-list 100 deny tcp host 10.1.1.1 any eq 23
Telnet uses TCP port 23; the source is the host and destination is 'any'.
Which wildcard mask matches the entire subnet 172.16.0.0/16?
Answer: 0.0.255.255
A /16 prefix means 16 bits are fixed, so the wildcard mask is 0.0.255.255, allowing the last 16 bits to vary.
How many ACLs can be applied per interface per direction?
Answer: One
Cisco IOS allows only one ACL per interface per direction (one inbound and one outbound).
What is a reflexive ACL primarily used for?
Answer: Allowing return traffic for sessions initiated from inside the network
Reflexive ACLs dynamically permit return traffic for outbound sessions, providing stateful-like filtering.