Topic 17 Practice Test 1 covers IPsec VPNs and ACLs for Cisco Certified Network Associate 200-301 CCNA and maps to objectives 5.5–5.6. For broader exam preparation, review the Cisco CCNA 200-301 Exam Dumps. Every option includes focused technical reasoning explaining both the networking concept and its fit to the scenario.
Question 1
At Woodgrove, a salesperson working from a hotel must securely reach internal applications from a laptop. Which option best provides a secure tunnel for one remote user endpoint into the enterprise? Choose ONE.
- Remote-access VPN
- IPsec confidentiality through encryption
- IKE negotiation
- Crypto ACL / interesting traffic selector
Correct Answer: A
Correct Answer
Answer A is correct because Remote-access VPN is the right selection because A remote-access VPN connects an individual user device to an organization network across an untrusted transport. For Remote-access VPN, the scenario key outcome is a secure tunnel for one remote user endpoint into the enterprise.
Incorrect Answers
Answer B is incorrect because IPsec can encrypt protected IP traffic so observers on the transit network cannot read the payload IPsec confidentiality through misses the Remote-access VPN decision in this configuration scenario. Operationally, Remote-access VPN needs another behavior than IPsec confidentiality through provides in this configuration case.
Answer C is incorrect because Internet Key Exchange negotiates security associations, algorithms, keying material, and peer authentication before protected IPsec data flows For Remote-access VPN, the configuration evidence requires another function than IKE negotiation. For IKE negotiation, separation from Remote-access VPN remains material in this configuration scenario.
Answer D is incorrect because A crypto ACL identifies the traffic that should be protected by a policy-based IPsec VPN The configuration evidence favors Remote-access VPN; Crypto ACL / operates at another control point. Using Crypto ACL / here would leave the Remote-access VPN requirement unresolved during this configuration task.
Question 2
At Adventure Works, two branch LANs need persistent encrypted connectivity across the public internet. Which option best provides a protected gateway-to-gateway tunnel between two networks? Choose ONE.
- IPsec integrity and peer/data authentication
- Site-to-site VPN
- IPsec ESP
- Remote-access VPN
Correct Answer: B
Correct Answer
Answer B is correct because Site-to-site VPN is the right selection because A site-to-site VPN protects traffic between networks through VPN gateways, making the tunnel transparent to individual hosts. For Site-to-site VPN, the scenario key outcome is a protected gateway-to-gateway tunnel between two networks.
Incorrect Answers
Answer A is incorrect because IPsec protection can detect unauthorized modification and authenticate protected traffic so tampering is not silently accepted For Site-to-site VPN, the configuration evidence requires another function than IPsec integrity and. For IPsec integrity and, separation from Site-to-site VPN remains material in this configuration scenario.
Answer C is incorrect because Encapsulating Security Payload is the IPsec protocol commonly used to provide encryption and integrity for protected data traffic The configuration evidence favors Site-to-site VPN; IPsec ESP operates at another control point.
Answer D is incorrect because A remote-access VPN connects an individual user device to an organization network across an untrusted transport The required Site-to-site VPN outcome differs from the Remote-access VPN purpose in this configuration case.
Question 3
At Litware, packet captures on the internet must not reveal the application payload exchanged between sites. Which option best provides encryption of data carried through the VPN tunnel? Choose ONE.
- IKE negotiation
- Crypto ACL / interesting traffic selector
- IPsec confidentiality through encryption
- Site-to-site VPN
Correct Answer: C
Correct Answer
Answer C is correct because IPsec confidentiality through encryption is the right selection because IPsec can encrypt protected IP traffic so observers on the transit network cannot read the payload. For IPsec confidentiality through, the scenario key outcome is encryption of data carried through the VPN tunnel.
Incorrect Answers
Answer A is incorrect because IKE negotiation is used when Use IKE for establishing and managing the cryptographic parameters of an IPsec VPN. The required IPsec confidentiality through outcome differs from the IKE negotiation purpose in this configuration case.
Answer B is incorrect because Crypto ACL / is used when Use mirrored source and destination definitions on peers so the intended protected flows match consistently. Using Crypto ACL / would not produce the IPsec confidentiality through behavior shown by this configuration evidence.
Answer D is incorrect because A site-to-site VPN protects traffic between networks through VPN gateways, making the tunnel transparent to individual hosts Using Site-to-site VPN would not produce the IPsec confidentiality through behavior shown by this configuration evidence.
Question 4
At Proseware, security requires the receiver to detect if VPN-protected traffic is changed between the two gateways. Which option best provides cryptographic detection of in-transit modification of protected packets? Choose ONE.
- IPsec ESP
- Remote-access VPN
- IPsec confidentiality through encryption
- IPsec integrity and peer/data authentication
Correct Answer: D
Correct Answer
Answer D is correct because IPsec integrity and peer/data authentication is the right selection because IPsec protection can detect unauthorized modification and authenticate protected traffic so tampering is not silently accepted. For IPsec integrity and, the scenario key outcome is cryptographic detection of in-transit modification of protected packets.
Incorrect Answers
Answer A is incorrect because IPsec ESP is used when Use ESP when VPN payloads require confidentiality in addition to integrity services. Using IPsec ESP would not produce the IPsec integrity and behavior shown by this configuration evidence.
Answer B is incorrect because Remote-access VPN is used when Use it for teleworkers or roaming users who need protected access to internal resources. In the configuration case, IPsec integrity and differs from Remote-access VPN behavior.
Answer C is incorrect because IPsec confidentiality through is used when Use confidentiality when sensitive traffic crosses an untrusted network. IPsec confidentiality through misses the IPsec integrity and decision in this configuration scenario. Operationally, IPsec integrity and needs another behavior than IPsec confidentiality through provides in this configuration case.
Question 5
At Alpine, two VPN gateways must agree on cryptographic parameters and authenticate each other before the tunnel passes traffic. Which option best provides negotiation of peers and security associations before encrypted user data is carried? Choose ONE.
- IKE negotiation
- Crypto ACL / interesting traffic selector
- Site-to-site VPN
- IPsec integrity and peer/data authentication
Correct Answer: A
Correct Answer
Answer A is correct because IKE negotiation is the right selection because Internet Key Exchange negotiates security associations, algorithms, keying material, and peer authentication before protected IPsec data flows. For IKE negotiation, the scenario key outcome is negotiation of peers and security associations before encrypted user data is carried.
Incorrect Answers
Answer B is incorrect because The purpose of Crypto ACL / is selection of which IP flows should enter a policy-based IPsec tunnel. Crypto ACL / misses the IKE negotiation decision in this configuration scenario. Operationally, IKE negotiation needs another behavior than Crypto ACL / provides in this configuration case.
Answer C is incorrect because Site-to-site VPN is used when connect branches, data centers, or other fixed networks over an untrusted WAN. Site-to-site VPN misses the IKE negotiation decision in this configuration scenario. Operationally, IKE negotiation needs another behavior than Site-to-site VPN provides in this configuration case.
Answer D is incorrect because IPsec integrity and is used when Use integrity protection where altered packets must be detected. For IKE negotiation, the configuration evidence requires another function than IPsec integrity and. For IPsec integrity and, separation from IKE negotiation remains material in this configuration scenario.
Question 6
At Blue Yonder, a design specifically requires encrypted IPsec user traffic rather than authentication-only protection. Which option best provides the IPsec data-protection protocol that can encrypt packet payloads? Choose ONE.
- Remote-access VPN
- IPsec ESP
- IPsec confidentiality through encryption
- IKE negotiation
Correct Answer: B
Correct Answer
Answer B is correct because IPsec ESP is the right selection because Encapsulating Security Payload is the IPsec protocol commonly used to provide encryption and integrity for protected data traffic. For IPsec ESP, the scenario key outcome is the IPsec data-protection protocol that can encrypt packet payloads.
Incorrect Answers
Answer A is incorrect because The purpose of Remote-access VPN is a secure tunnel for one remote user endpoint into the enterprise. For IPsec ESP, the configuration evidence requires another function than Remote-access VPN. For Remote-access VPN, separation from IPsec ESP remains material in this configuration scenario.
Answer C is incorrect because The purpose of IPsec confidentiality through is encryption of data carried through the VPN tunnel. The configuration evidence favors IPsec ESP; IPsec confidentiality through operates at another control point. Using IPsec confidentiality through here would leave the IPsec ESP requirement unresolved during this configuration task.
Answer D is incorrect because The purpose of IKE negotiation is negotiation of peers and security associations before encrypted user data is carried. The required IPsec ESP outcome differs from the IKE negotiation purpose in this configuration case.
Question 7
At Fourth Coffee, only traffic between the 10.10.10.0/24 and 10.20.20.0/24 LANs should be encrypted between gateways. Which option best provides selection of which IP flows should enter a policy-based IPsec tunnel? Choose ONE.
- Site-to-site VPN
- IPsec integrity and peer/data authentication
- Crypto ACL / interesting traffic selector
- IPsec ESP
Correct Answer: C
Correct Answer
Answer C is correct because Crypto ACL / interesting traffic selector is the right selection because A crypto ACL identifies the traffic that should be protected by a policy-based IPsec VPN. For Crypto ACL /, the scenario key outcome is selection of which IP flows should enter a policy-based IPsec tunnel.
Incorrect Answers
Answer A is incorrect because The purpose of Site-to-site VPN is a protected gateway-to-gateway tunnel between two networks. The configuration evidence favors Crypto ACL /; Site-to-site VPN operates at another control point. Using Site-to-site VPN here would leave the Crypto ACL / requirement unresolved during this configuration task.
Answer B is incorrect because The purpose of IPsec integrity and is cryptographic detection of in-transit modification of protected packets. The required Crypto ACL / outcome differs from the IPsec integrity and purpose in this configuration case.
Answer D is incorrect because The purpose of IPsec ESP is the IPsec data-protection protocol that can encrypt packet payloads. Using IPsec ESP would not produce the Crypto ACL / behavior shown by this configuration evidence.
Question 8
At Wingtip, management wants to block one source subnet from reaching any service on a protected destination network. Which option best provides filtering based only on the source IPv4 address? Choose ONE.
- Implicit deny at the end of an ACL
- Named ACL
- Outbound interface ACL
- Standard IPv4 ACL
Correct Answer: D
Correct Answer
Answer D is correct because Standard IPv4 ACL is the right selection because A standard IPv4 ACL matches primarily on source IPv4 address and is appropriate when source identity alone determines the filtering decision. For Standard IPv4 ACL, the scenario key outcome is filtering based only on the source IPv4 address.
Incorrect Answers
Answer A is incorrect because Cisco ACL processing ends with an implicit deny, so packets that match no explicit permit statement are discarded For Standard IPv4 ACL, the configuration evidence requires another function than Implicit deny at.
Answer B is incorrect because A named ACL uses a meaningful identifier and supports editing individual entries in ACL configuration mode The configuration evidence favors Standard IPv4 ACL; Named ACL operates at another control point. Using Named ACL here would leave the Standard IPv4 ACL requirement unresolved during this configuration task.
Answer C is incorrect because An outbound ACL filters packets after routing has selected the egress interface and before the packets leave that interface The required Standard IPv4 ACL outcome differs from the Outbound interface ACL purpose in this configuration case.
Question 9
At Northwind, only HTTPS from one client subnet to a particular server should be permitted while other traffic is denied. Which option best provides filtering that considers source, destination, protocol, and service port? Choose ONE.
- Extended IPv4 ACL
- ACL wildcard mask
- Inbound interface ACL
- Place an extended ACL near the source
Correct Answer: A
Correct Answer
Answer A is correct because Extended IPv4 ACL is the right selection because An extended IPv4 ACL can match source, destination, protocol, and TCP or UDP port information. For Extended IPv4 ACL, the scenario key outcome is filtering that considers source, destination, protocol, and service port.
Incorrect Answers
Answer B is incorrect because An IPv4 ACL wildcard mask uses zero bits to require a match and one bits to ignore corresponding address bits The configuration evidence favors Extended IPv4 ACL; ACL wildcard mask operates at another control point.
Answer C is incorrect because An inbound ACL filters packets as they enter an interface before the router makes the normal outbound forwarding decision The required Extended IPv4 ACL outcome differs from the Inbound interface ACL purpose in this configuration case.
Answer D is incorrect because Extended ACLs are commonly placed close to the traffic source so unwanted application traffic is discarded before consuming downstream bandwidth Using Place an extended would not produce the Extended IPv4 ACL behavior shown by this configuration evidence.
Question 10
At Contoso, an ACL permits one application but all unrelated traffic unexpectedly stops even though no explicit deny line is shown. Which option best provides the default final deny applied to unmatched traffic? Choose ONE.
- Named ACL
- Implicit deny at the end of an ACL
- Outbound interface ACL
- Place a standard ACL near the destination
Correct Answer: B
Correct Answer
Answer B is correct because Implicit deny at the end of an ACL is the right selection because Cisco ACL processing ends with an implicit deny, so packets that match no explicit permit statement are discarded. For Implicit deny at, the scenario key outcome is the default final deny applied to unmatched traffic.
Incorrect Answers
Answer A is incorrect because Named ACL is used when operational clarity and maintainability are more important than a numeric ACL identifier. Using Named ACL would not produce the Implicit deny at behavior shown by this configuration evidence.
Answer C is incorrect because Outbound interface ACL is used when policy should be enforced on traffic exiting a particular interface. In the configuration case, Implicit deny at differs from Outbound interface ACL behavior. The Outbound interface ACL function therefore differs materially from the Implicit deny at outcome required here.
Answer D is incorrect because Standard ACLs are commonly placed close to the destination because they match only source and could otherwise block that source from unintended destinations In the configuration case, Implicit deny at differs from Place a standard behavior.
Question 11
At Fabrikam, an engineer must match the 192.168.10.0/24 network in an IOS access-list statement. Which option best provides the inverse-style mask used to describe an IPv4 address range in an ACL? Choose ONE.
- Inbound interface ACL
- Place an extended ACL near the source
- ACL wildcard mask
- ip access-group on an interface
Correct Answer: C
Correct Answer
Answer C is correct because ACL wildcard mask is the right selection because An IPv4 ACL wildcard mask uses zero bits to require a match and one bits to ignore corresponding address bits. For ACL wildcard mask, the scenario key outcome is the inverse-style mask used to describe an IPv4 address range in an ACL.
Incorrect Answers
Answer A is incorrect because Inbound interface ACL is used when traffic should be evaluated immediately on arrival at that interface. In the configuration case, ACL wildcard mask differs from Inbound interface ACL behavior. The Inbound interface ACL function therefore differs materially from the ACL wildcard mask outcome required here.
Answer B is incorrect because Place an extended is used when Use this guideline when topology and operational constraints do not require a different placement. Place an extended misses the ACL wildcard mask decision in this configuration scenario.
Answer D is incorrect because The ip access-group command applies an IPv4 ACL to an interface in the inbound or outbound direction ip access-group on misses the ACL wildcard mask decision in this configuration scenario. Operationally, ACL wildcard mask needs another behavior than ip access-group on provides in this configuration case.
Question 12
At Tailspin, the team wants the filter called WEB-IN and expects to add or remove specific entries later. Which option best provides an access list identified by a descriptive name and managed in ACL submode? Choose ONE.
- Outbound interface ACL
- Place a standard ACL near the destination
- show access-lists verification
- Named ACL
Correct Answer: D
Correct Answer
Answer D is correct because Named ACL is the right selection because A named ACL uses a meaningful identifier and supports editing individual entries in ACL configuration mode. For Named ACL, the scenario key outcome is an access list identified by a descriptive name and managed in ACL submode.
Incorrect Answers
Answer A is incorrect because The purpose of Outbound interface ACL is filtering applied to packets leaving the selected egress interface. For Named ACL, the configuration evidence requires another function than Outbound interface ACL. For Outbound interface ACL, separation from Named ACL remains material in this configuration scenario.
Answer B is incorrect because Place a standard is used when limit collateral filtering when only source addresses can be matched. For Named ACL, the configuration evidence requires another function than Place a standard. For Place a standard, separation from Named ACL remains material in this configuration scenario.
Answer C is incorrect because The show access-lists command displays ACL entries and can show match counters that help verify which statements are processing packets For Named ACL, the configuration evidence requires another function than show access-lists verification.
Question 13
At Woodgrove, traffic arriving from a user LAN must be filtered before it is forwarded toward internal networks. Which option best provides filtering applied to packets entering a router interface? Choose ONE.
- Inbound interface ACL
- Place an extended ACL near the source
- ip access-group on an interface
- ACL sequence numbers
Correct Answer: A
Correct Answer
Answer A is correct because Inbound interface ACL is the right selection because An inbound ACL filters packets as they enter an interface before the router makes the normal outbound forwarding decision. For Inbound interface ACL, the scenario key outcome is filtering applied to packets entering a router interface.
Incorrect Answers
Answer B is incorrect because The purpose of Place an extended is early filtering of specific traffic near where it originates. The configuration evidence favors Inbound interface ACL; Place an extended operates at another control point.
Answer C is incorrect because ip access-group on is used when Use it after defining the ACL when packet filtering must actually take effect on routed interface traffic. The configuration evidence favors Inbound interface ACL; ip access-group on operates at another control point.
Answer D is incorrect because Sequence numbers order entries in a named ACL and allow a new statement to be inserted between existing entries without rebuilding the entire list The configuration evidence favors Inbound interface ACL; ACL sequence numbers operates at another control point.
Question 14
At Adventure Works, multiple sources converge on one WAN interface and the policy is intentionally enforced as traffic exits that link. Which option best provides filtering applied to packets leaving the selected egress interface? Choose ONE.
- Place a standard ACL near the destination
- Outbound interface ACL
- show access-lists verification
- VTY access-class
Correct Answer: B
Correct Answer
Answer B is correct because Outbound interface ACL is the right selection because An outbound ACL filters packets after routing has selected the egress interface and before the packets leave that interface. For Outbound interface ACL, the scenario key outcome is filtering applied to packets leaving the selected egress interface.
Incorrect Answers
Answer A is incorrect because The purpose of Place a standard is source-only filtering near the intended destination network. The required Outbound interface ACL outcome differs from the Place a standard purpose in this configuration case.
Answer C is incorrect because show access-lists verification is used when confirm ACL contents and observe whether expected entries are matching traffic. The required Outbound interface ACL outcome differs from the show access-lists verification purpose in this configuration case.
Answer D is incorrect because The access-class command filters which source addresses may establish management sessions to VTY lines using an ACL The required Outbound interface ACL outcome differs from the VTY access-class purpose in this configuration case.
Question 15
At Litware, a branch should drop prohibited application traffic before it crosses the constrained WAN. Which option best provides early filtering of specific traffic near where it originates? Choose ONE.
- ip access-group on an interface
- ACL sequence numbers
- Place an extended ACL near the source
- Standard IPv4 ACL
Correct Answer: C
Correct Answer
Answer C is correct because Place an extended ACL near the source is the right selection because Extended ACLs are commonly placed close to the traffic source so unwanted application traffic is discarded before consuming downstream bandwidth. For Place an extended, the scenario key outcome is early filtering of specific traffic near where it originates.
Incorrect Answers
Answer A is incorrect because The purpose of ip access-group on is attachment of a defined IPv4 ACL to an interface direction. Using ip access-group on would not produce the Place an extended behavior shown by this configuration evidence.
Answer B is incorrect because ACL sequence numbers is used when the policy needs a new ACE at a specific evaluation point. Using ACL sequence numbers would not produce the Place an extended behavior shown by this configuration evidence.
Answer D is incorrect because A standard IPv4 ACL matches primarily on source IPv4 address and is appropriate when source identity alone determines the filtering decision Using Standard IPv4 ACL would not produce the Place an extended behavior shown by this configuration evidence.
Question 16
At Proseware, one source subnet must be blocked from a server LAN but should still reach other networks. Which option best provides source-only filtering near the intended destination network? Choose ONE.
- show access-lists verification
- VTY access-class
- Extended IPv4 ACL
- Place a standard ACL near the destination
Correct Answer: D
Correct Answer
Answer D is correct because Place a standard ACL near the destination is the right selection because Standard ACLs are commonly placed close to the destination because they match only source and could otherwise block that source from unintended destinations. For Place a standard, the scenario key outcome is source-only filtering near the intended destination network.
Incorrect Answers
Answer A is incorrect because The purpose of show access-lists verification is verification of ACL entries and their packet matches. In the configuration case, Place a standard differs from show access-lists verification behavior. The show access-lists verification function therefore differs materially from the Place a standard outcome required here.
Answer B is incorrect because VTY access-class is used when restrict remote management access to approved administrator source networks. In the configuration case, Place a standard differs from VTY access-class behavior. The VTY access-class function therefore differs materially from the Place a standard outcome required here.
Answer C is incorrect because An extended IPv4 ACL can match source, destination, protocol, and TCP or UDP port information In the configuration case, Place a standard differs from Extended IPv4 ACL behavior. The Extended IPv4 ACL function therefore differs materially from the Place a standard outcome required here.
Question 17
At Alpine, the access list exists in the configuration but packets are not being filtered on GigabitEthernet0/1. Which option best provides attachment of a defined IPv4 ACL to an interface direction? Choose ONE.
- ip access-group on an interface
- ACL sequence numbers
- Standard IPv4 ACL
- Implicit deny at the end of an ACL
Correct Answer: A
Correct Answer
Answer A is correct because ip access-group on an interface is the right selection because The ip access-group command applies an IPv4 ACL to an interface in the inbound or outbound direction. For ip access-group on, the scenario key outcome is attachment of a defined IPv4 ACL to an interface direction.
Incorrect Answers
Answer B is incorrect because The purpose of ACL sequence numbers is ordered insertion and editing of individual ACL entries. ACL sequence numbers misses the ip access-group on decision in this configuration scenario. Operationally, ip access-group on needs another behavior than ACL sequence numbers provides in this configuration case.
Answer C is incorrect because Standard IPv4 ACL is used when protocol, destination, and transport port do not need to be distinguished. Standard IPv4 ACL misses the ip access-group on decision in this configuration scenario. Operationally, ip access-group on needs another behavior than Standard IPv4 ACL provides in this configuration case.
Answer D is incorrect because Implicit deny at is used when building an allow-list so required traffic is not unintentionally blocked. For ip access-group on, the configuration evidence requires another function than Implicit deny at. For Implicit deny at, separation from ip access-group on remains material in this configuration scenario.
Question 18
At Blue Yonder, after a filter change, the engineer wants to confirm the statements and see which entries are receiving hits. Which option best provides verification of ACL entries and their packet matches? Choose ONE.
- VTY access-class
- show access-lists verification
- Extended IPv4 ACL
- ACL wildcard mask
Correct Answer: B
Correct Answer
Answer B is correct because show access-lists verification is the right selection because The show access-lists command displays ACL entries and can show match counters that help verify which statements are processing packets. For show access-lists verification, the scenario key outcome is verification of ACL entries and their packet matches.
Incorrect Answers
Answer A is incorrect because The purpose of VTY access-class is ACL-based restriction of incoming VTY management sessions. For show access-lists verification, the configuration evidence requires another function than VTY access-class. For VTY access-class, separation from show access-lists verification remains material in this configuration scenario.
Answer C is incorrect because Extended IPv4 ACL is used when the policy must distinguish specific applications or destination networks. For show access-lists verification, the configuration evidence requires another function than Extended IPv4 ACL. For Extended IPv4 ACL, separation from show access-lists verification remains material in this configuration scenario.
Answer D is incorrect because ACL wildcard mask is used when express the source or destination address range in IOS ACL entries. The configuration evidence favors show access-lists verification; ACL wildcard mask operates at another control point.
Question 19
At Fourth Coffee, a new deny must be inserted between two existing named-ACL statements without deleting the whole ACL. Which option best provides ordered insertion and editing of individual ACL entries? Choose ONE.
- Standard IPv4 ACL
- Implicit deny at the end of an ACL
- ACL sequence numbers
- Named ACL
Correct Answer: C
Correct Answer
Answer C is correct because ACL sequence numbers is the right selection because Sequence numbers order entries in a named ACL and allow a new statement to be inserted between existing entries without rebuilding the entire list. For ACL sequence numbers, the scenario key outcome is ordered insertion and editing of individual ACL entries.
Incorrect Answers
Answer A is incorrect because The purpose of Standard IPv4 ACL is filtering based only on the source IPv4 address. The configuration evidence favors ACL sequence numbers; Standard IPv4 ACL operates at another control point. Using Standard IPv4 ACL here would leave the ACL sequence numbers requirement unresolved during this configuration task.
Answer B is incorrect because The purpose of Implicit deny at is the default final deny applied to unmatched traffic. The required ACL sequence numbers outcome differs from the Implicit deny at purpose in this configuration case.
Answer D is incorrect because The purpose of Named ACL is an access list identified by a descriptive name and managed in ACL submode. Using Named ACL would not produce the ACL sequence numbers behavior shown by this configuration evidence.
Question 20
At Wingtip, SSH should remain enabled, but only hosts from the network-management subnet may open VTY sessions. Which option best provides ACL-based restriction of incoming VTY management sessions? Choose ONE.
- Extended IPv4 ACL
- ACL wildcard mask
- Inbound interface ACL
- VTY access-class
Correct Answer: D
Correct Answer
Answer D is correct because VTY access-class is the right selection because The access-class command filters which source addresses may establish management sessions to VTY lines using an ACL. For VTY access-class, the scenario key outcome is ACL-based restriction of incoming VTY management sessions.
Incorrect Answers
Answer A is incorrect because The purpose of Extended IPv4 ACL is filtering that considers source, destination, protocol, and service port. The required VTY access-class outcome differs from the Extended IPv4 ACL purpose in this configuration case.
Answer B is incorrect because The purpose of ACL wildcard mask is the inverse-style mask used to describe an IPv4 address range in an ACL. Using ACL wildcard mask would not produce the VTY access-class behavior shown by this configuration evidence.
Answer C is incorrect because The purpose of Inbound interface ACL is filtering applied to packets entering a router interface. In the configuration case, VTY access-class differs from Inbound interface ACL behavior. The Inbound interface ACL function therefore differs materially from the VTY access-class outcome required here.