← All Cisco CCNA Flashcard Decks

Access Control Lists (ACLs) Flashcards

7 cards from real Cisco CCNA practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 Access Control Lists (ACLs) flashcards as text
  1. An ACL entry reads: 'permit ip 192.168.1.0 0.0.0.255 any'. What traffic does this permit?

    Answer: All IP traffic from the 192.168.1.0/24 subnet to any destination

    The source is 192.168.1.0/24 (wildcard 0.0.0.255) and the destination is 'any', permitting all IP traffic from that subnet.

  2. Which command removes a single entry from a named ACL?

    Answer: no inside the named ACL config mode

    In named ACL configuration mode, typing 'no ' removes that specific entry.

  3. What is the default sequence number increment when adding ACL entries without specifying a sequence number?

    Answer: 10

    Cisco IOS automatically assigns sequence numbers in increments of 10 (10, 20, 30…) for ACL entries.

  4. Which ACL type uses the 'evaluate' command to permit return traffic?

    Answer: Reflexive ACL

    Reflexive ACLs use 'ip reflexive-list timeout' and the 'evaluate' command to match dynamic return-traffic entries.

  5. A time-based ACL uses which command to reference a defined time range?

    Answer: time-range

    The 'time-range ' command defines a time window, which is then referenced in an ACL entry with 'time-range '.

  6. Which ACL feature locks a switch port to a specific user's MAC address after successful authentication?

    Answer: Dynamic ACL (Lock-and-Key)

    Dynamic ACLs (Lock-and-Key) require Telnet authentication before temporarily opening access for a specific host.

  7. What command displays the hit count for each ACL entry?

    Answer: show ip access-lists

    'show ip access-lists' shows each ACL entry along with how many packets have matched it.