Access Control Lists (ACLs) Flashcards
7 cards from real Cisco CCNA practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Access Control Lists (ACLs) flashcards as text
An ACL entry reads: 'permit ip 192.168.1.0 0.0.0.255 any'. What traffic does this permit?
Answer: All IP traffic from the 192.168.1.0/24 subnet to any destination
The source is 192.168.1.0/24 (wildcard 0.0.0.255) and the destination is 'any', permitting all IP traffic from that subnet.
Which command removes a single entry from a named ACL?
Answer: no inside the named ACL config mode
In named ACL configuration mode, typing 'no ' removes that specific entry.
What is the default sequence number increment when adding ACL entries without specifying a sequence number?
Answer: 10
Cisco IOS automatically assigns sequence numbers in increments of 10 (10, 20, 30…) for ACL entries.
Which ACL type uses the 'evaluate' command to permit return traffic?
Answer: Reflexive ACL
Reflexive ACLs use 'ip reflexive-list timeout' and the 'evaluate' command to match dynamic return-traffic entries.
A time-based ACL uses which command to reference a defined time range?
Answer: time-range
The 'time-range ' command defines a time window, which is then referenced in an ACL entry with 'time-range '.
Which ACL feature locks a switch port to a specific user's MAC address after successful authentication?
Answer: Dynamic ACL (Lock-and-Key)
Dynamic ACLs (Lock-and-Key) require Telnet authentication before temporarily opening access for a specific host.
What command displays the hit count for each ACL entry?
Answer: show ip access-lists
'show ip access-lists' shows each ACL entry along with how many packets have matched it.