Access Control Lists (ACLs) Flashcards
7 cards from real Cisco CCNA practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Access Control Lists (ACLs) flashcards as text
A VLAN ACL (VACL) differs from a routed ACL because it can filter traffic that is:
Answer: Both routed and bridged within the same VLAN
VACLs apply to all traffic within a VLAN, including Layer 2 bridged traffic that never passes through a routed interface.
Which keyword in a standard ACL matches all hosts (equivalent to 0.0.0.0 255.255.255.255)?
Answer: any
The keyword 'any' is shorthand for source address 0.0.0.0 with wildcard 255.255.255.255, matching every IP address.
What is the result of applying an ACL with only a 'deny' statement and no permit entries?
Answer: All traffic is denied due to the implicit deny any at the end
The single deny entry plus the implicit deny any at the end means all traffic is blocked.
Which protocol number would you use in an extended ACL to match ICMP traffic?
Answer: 1
ICMP is protocol number 1; TCP is 6, UDP is 17, and OSPF is 89.
An administrator wants to log packets that match an ACL deny entry. Which keyword is added to the ACL entry?
Answer: log
Adding the 'log' keyword at the end of an ACL entry causes matching packets to generate a syslog message.
Which statement about numbered ACLs versus named ACLs is TRUE?
Answer: Named ACLs allow deletion of individual entries; numbered ACLs require deleting the entire ACL
Named ACLs support per-entry deletion using sequence numbers, while numbered ACLs require removing and re-entering the entire list.
Which ACL entry correctly blocks all traffic from the 10.0.0.0/8 network to a web server at 172.16.1.10?
Answer: access-list 100 deny tcp 10.0.0.0 0.255.255.255 host 172.16.1.10 eq 80
The /8 network requires wildcard 0.255.255.255; HTTP uses TCP port 80; 'host' keyword matches the single destination IP.