โ† All Cisco CCNA Flashcard Decks

Access Control Lists (ACLs) Flashcards

7 cards from real Cisco CCNA practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Access Control Lists (ACLs) flashcards as text
  1. What is the effect of the implicit deny at the end of every ACL?

    Answer: It drops all traffic that does not match any ACL entry

    Every ACL ends with an implicit 'deny any' that silently drops any traffic not matched by a previous entry.

  2. Which ACL type can filter traffic based on both source AND destination IP address?

    Answer: Extended ACL

    Extended ACLs can match on source IP, destination IP, protocol, and port numbers.

  3. Which command verifies which ACLs are applied to a specific interface and their direction?

    Answer: show ip interface

    'show ip interface' displays the inbound and outbound ACLs applied to each interface.

  4. A network administrator needs to block only Telnet traffic from host 10.1.1.1 to any destination. Which ACL entry achieves this?

    Answer: access-list 100 deny tcp host 10.1.1.1 any eq 23

    Telnet uses TCP port 23; the source is the host and destination is 'any'.

  5. Which wildcard mask matches the entire subnet 172.16.0.0/16?

    Answer: 0.0.255.255

    A /16 prefix means 16 bits are fixed, so the wildcard mask is 0.0.255.255, allowing the last 16 bits to vary.

  6. How many ACLs can be applied per interface per direction?

    Answer: One

    Cisco IOS allows only one ACL per interface per direction (one inbound and one outbound).

  7. What is a reflexive ACL primarily used for?

    Answer: Allowing return traffic for sessions initiated from inside the network

    Reflexive ACLs dynamically permit return traffic for outbound sessions, providing stateful-like filtering.