Cisco CCNA 200-301 IPsec VPNs and ACLs Practice Test 2

 

Topic 17 Practice Test 2 covers IPsec VPNs and ACLs for Cisco Certified Network Associate 200-301 CCNA and maps to objectives 5.5–5.6. For broader exam preparation, review the Cisco CCNA 200-301 Exam Dumps. Every option includes focused technical reasoning explaining both the networking concept and its fit to the scenario.

Question 1

A contractor needs encrypted access from a single managed laptop into private applications while traveling; no branch gateway exists at the remote location. Which option should the engineer use or identify? Choose ONE.

  1. IPsec integrity and peer/data authentication
  2. Remote-access VPN
  3. Crypto ACL / interesting traffic selector
  4. IPsec confidentiality through encryption

Correct Answer: B

Correct Answer

 

 

Answer B is correct because Remote-access VPN provides a secure tunnel for one remote user endpoint into the enterprise. In a Remote-access VPN use case, it is appropriate when Use it for teleworkers or roaming users who need protected access to internal resources. The observed behavior aligns with that role.

Incorrect Answers

 

Answer A is incorrect because IPsec integrity and concerns this behavior: IPsec protection can detect unauthorized modification and. The operations evidence favors Remote-access VPN; IPsec integrity and operates at another control point. The Remote-access VPN result depends on another mechanism, not the IPsec integrity and behavior described above.

Answer C is incorrect because Crypto ACL / concerns this behavior: A crypto ACL identifies the traffic that. The required Remote-access VPN outcome differs from the Crypto ACL / purpose in this operations case. For Remote-access VPN, choosing Crypto ACL / would change the control point in this operations case.

Answer D is incorrect because IPsec confidentiality through concerns this behavior: IPsec can encrypt protected IP traffic so. Using IPsec confidentiality through would not produce the Remote-access VPN behavior shown by this operations evidence. The IPsec confidentiality through function therefore differs materially from the Remote-access VPN outcome required here.

 

Question 2

Two offices each have an edge gateway and require continuous protected connectivity between their internal subnets across the public internet. Which option should the engineer use or identify? Choose ONE.

  1. IKE negotiation
  2. Remote-access VPN
  3. Site-to-site VPN
  4. IPsec integrity and peer/data authentication

Correct Answer: C

Correct Answer

 

 

Answer C is correct because Site-to-site VPN provides a protected gateway-to-gateway tunnel between two networks. In a Site-to-site VPN use case, it is appropriate when connect branches, data centers, or other fixed networks over an untrusted WAN. The observed behavior aligns with that role.

Incorrect Answers

 

Answer A is incorrect because IKE negotiation concerns this behavior: Internet Key Exchange negotiates security associations, algorithms. The required Site-to-site VPN outcome differs from the IKE negotiation purpose in this operations case. For Site-to-site VPN, choosing IKE negotiation would change the control point in this operations case.

Answer B is incorrect because Remote-access VPN concerns this behavior: A remote-access VPN connects an individual user. Using Remote-access VPN would not produce the Site-to-site VPN behavior shown by this operations evidence. The Remote-access VPN function therefore differs materially from the Site-to-site VPN outcome required here.

Answer D is incorrect because IPsec protection can detect unauthorized modification and authenticate protected traffic so tampering is not silently accepted IPsec integrity and misses the Site-to-site VPN decision in this operations scenario. For IPsec integrity and, separation from Site-to-site VPN remains material in this operations scenario.

 

Question 3

A VPN design must prevent an intermediary on the internet from reading the contents of packets traversing the protected tunnel. Which option should the engineer use or identify? Choose ONE.

  1. IPsec ESP
  2. Site-to-site VPN
  3. IKE negotiation
  4. IPsec confidentiality through encryption

Correct Answer: D

Correct Answer

 

 

Answer D is correct because IPsec confidentiality through encryption provides encryption of data carried through the VPN tunnel. In a IPsec confidentiality through use case, it is appropriate when Use confidentiality when sensitive traffic crosses an untrusted network. The observed behavior aligns with that role.

Incorrect Answers

 

Answer A is incorrect because IPsec ESP concerns this behavior: Encapsulating Security Payload is the IPsec protocol. Using IPsec ESP would not produce the IPsec confidentiality through behavior shown by this operations evidence. The IPsec ESP function therefore differs materially from the IPsec confidentiality through outcome required here.

Answer B is incorrect because Site-to-site VPN concerns this behavior: A site-to-site VPN protects traffic between networks. In the operations case, IPsec confidentiality through differs from Site-to-site VPN behavior. Operationally, IPsec confidentiality through needs another behavior than Site-to-site VPN provides in this operations case.

Answer C is incorrect because Internet Key Exchange negotiates security associations, algorithms, keying material, and peer authentication before protected IPsec data flows For IPsec confidentiality through, the operations evidence requires another function than IKE negotiation. Using IKE negotiation here would leave the IPsec confidentiality through requirement unresolved during this operations task.

 

Question 4

The VPN receiver must detect if protected traffic has been modified in transit and reject tampered packets. Which option should the engineer use or identify? Choose ONE.

  1. IPsec integrity and peer/data authentication
  2. Crypto ACL / interesting traffic selector
  3. IPsec confidentiality through encryption
  4. IPsec ESP

Correct Answer: A

Correct Answer

 

 

Answer A is correct because IPsec integrity and peer/data authentication provides cryptographic detection of in-transit modification of protected packets. In a IPsec integrity and use case, it is appropriate when Use integrity protection where altered packets must be detected. The observed behavior aligns with that role.

Incorrect Answers

 

Answer B is incorrect because A crypto ACL identifies the traffic that should be protected by a policy-based IPsec VPN Crypto ACL / misses the IPsec integrity and decision in this operations scenario. For Crypto ACL /, separation from IPsec integrity and remains material in this operations scenario.

Answer C is incorrect because IPsec can encrypt protected IP traffic so observers on the transit network cannot read the payload For IPsec integrity and, the operations evidence requires another function than IPsec confidentiality through. Using IPsec confidentiality through here would leave the IPsec integrity and requirement unresolved during this operations task.

Answer D is incorrect because Encapsulating Security Payload is the IPsec protocol commonly used to provide encryption and integrity for protected data traffic The operations evidence favors IPsec integrity and; IPsec ESP operates at another control point.

 

Question 5

Before user traffic is protected, two VPN peers need a protocol to authenticate/establish security associations and negotiate cryptographic parameters. Which option should the engineer use or identify? Choose ONE.

  1. Remote-access VPN
  2. IKE negotiation
  3. IPsec integrity and peer/data authentication
  4. Crypto ACL / interesting traffic selector

Correct Answer: B

Correct Answer

 

 

Answer B is correct because IKE negotiation provides negotiation of peers and security associations before encrypted user data is carried. In a IKE negotiation use case, it is appropriate when Use IKE for establishing and managing the cryptographic parameters of an IPsec VPN. The observed behavior aligns with that role.

Incorrect Answers

 

Answer A is incorrect because A remote-access VPN connects an individual user device to an organization network across an untrusted transport For IKE negotiation, the operations evidence requires another function than Remote-access VPN. Using Remote-access VPN here would leave the IKE negotiation requirement unresolved during this operations task.

Answer C is incorrect because IPsec integrity and is used when Use integrity protection where altered packets must be detected. The required IKE negotiation outcome differs from the IPsec integrity and purpose in this operations case.

Answer D is incorrect because Crypto ACL / is used when Use mirrored source and destination definitions on peers so the intended protected flows match consistently. Using Crypto ACL / would not produce the IKE negotiation behavior shown by this operations evidence.

 

Question 6

The engineer needs the IPsec protocol that carries protected user data and can provide payload encryption for the tunnel. Which option should the engineer use or identify? Choose ONE.

  1. Site-to-site VPN
  2. IKE negotiation
  3. IPsec ESP
  4. Remote-access VPN

Correct Answer: C

Correct Answer

 

 

Answer C is correct because IPsec ESP provides the IPsec data-protection protocol that can encrypt packet payloads. In a IPsec ESP use case, it is appropriate when Use ESP when VPN payloads require confidentiality in addition to integrity services. The observed behavior aligns with that role.

Incorrect Answers

 

Answer A is incorrect because A site-to-site VPN protects traffic between networks through VPN gateways, making the tunnel transparent to individual hosts The operations evidence favors IPsec ESP; Site-to-site VPN operates at another control point. The IPsec ESP result depends on another mechanism, not the Site-to-site VPN behavior described above.

Answer B is incorrect because IKE negotiation is used when Use IKE for establishing and managing the cryptographic parameters of an IPsec VPN. Using IKE negotiation would not produce the IPsec ESP behavior shown by this operations evidence.

Answer D is incorrect because Remote-access VPN is used when Use it for teleworkers or roaming users who need protected access to internal resources. In the operations case, IPsec ESP differs from Remote-access VPN behavior. Operationally, IPsec ESP needs another behavior than Remote-access VPN provides in this operations case.

 

Question 7

Only traffic between two specified private subnets should enter a policy-based IPsec tunnel; ordinary internet traffic must remain outside it. Which option should the engineer use or identify? Choose ONE.

  1. IPsec confidentiality through encryption
  2. IPsec ESP
  3. Site-to-site VPN
  4. Crypto ACL / interesting traffic selector

Correct Answer: D

Correct Answer

 

 

Answer D is correct because Crypto ACL / interesting traffic selector provides selection of which IP flows should enter a policy-based IPsec tunnel. In a Crypto ACL / use case, it is appropriate when Use mirrored source and destination definitions on peers so the intended protected flows match consistently. The observed behavior aligns with that role.

Incorrect Answers

 

Answer A is incorrect because IPsec confidentiality through is used when Use confidentiality when sensitive traffic crosses an untrusted network. Using IPsec confidentiality through would not produce the Crypto ACL / behavior shown by this operations evidence.

Answer B is incorrect because IPsec ESP is used when Use ESP when VPN payloads require confidentiality in addition to integrity services. In the operations case, Crypto ACL / differs from IPsec ESP behavior. Operationally, Crypto ACL / needs another behavior than IPsec ESP provides in this operations case.

Answer C is incorrect because Site-to-site VPN is used when connect branches, data centers, or other fixed networks over an untrusted WAN. Site-to-site VPN misses the Crypto ACL / decision in this operations scenario. For Site-to-site VPN, separation from Crypto ACL / remains material in this operations scenario.

 

Question 8

A filtering decision depends only on the packet source IPv4 subnet; destination, protocol, and port do not need to be distinguished. Which option should the engineer use or identify? Choose ONE.

  1. Standard IPv4 ACL
  2. ACL wildcard mask
  3. Outbound interface ACL
  4. ip access-group on an interface

Correct Answer: A

Correct Answer

 

 

Answer A is correct because Standard IPv4 ACL provides filtering based only on the source IPv4 address. In a Standard IPv4 ACL use case, it is appropriate when protocol, destination, and transport port do not need to be distinguished. The observed behavior aligns with that role.

Incorrect Answers

 

Answer B is incorrect because ACL wildcard mask concerns this behavior: An IPv4 ACL wildcard mask uses zero. The required Standard IPv4 ACL outcome differs from the ACL wildcard mask purpose in this operations case. For Standard IPv4 ACL, choosing ACL wildcard mask would change the control point in this operations case.

Answer C is incorrect because Outbound interface ACL concerns this behavior: An outbound ACL filters packets after routing. Using Outbound interface ACL would not produce the Standard IPv4 ACL behavior shown by this operations evidence. The Outbound interface ACL function therefore differs materially from the Standard IPv4 ACL outcome required here.

Answer D is incorrect because ip access-group on concerns this behavior: The ip access-group command applies an IPv4. In the operations case, Standard IPv4 ACL differs from ip access-group on behavior. Operationally, Standard IPv4 ACL needs another behavior than ip access-group on provides in this operations case.

 

Question 9

A policy must permit HTTPS from one client subnet to one server subnet while denying a different transport service between the same networks. Which option should the engineer use or identify? Choose ONE.

  1. Named ACL
  2. Extended IPv4 ACL
  3. Place an extended ACL near the source
  4. show access-lists verification

Correct Answer: B

Correct Answer

 

 

Answer B is correct because Extended IPv4 ACL provides filtering that considers source, destination, protocol, and service port. In a Extended IPv4 ACL use case, it is appropriate when the policy must distinguish specific applications or destination networks. The observed behavior aligns with that role.

Incorrect Answers

 

Answer A is incorrect because Named ACL concerns this behavior: A named ACL uses a meaningful identifier. Using Named ACL would not produce the Extended IPv4 ACL behavior shown by this operations evidence. The Named ACL function therefore differs materially from the Extended IPv4 ACL outcome required here.

Answer C is incorrect because Place an extended concerns this behavior: Extended ACLs are commonly placed close to. In the operations case, Extended IPv4 ACL differs from Place an extended behavior. Operationally, Extended IPv4 ACL needs another behavior than Place an extended provides in this operations case.

Answer D is incorrect because show access-lists verification concerns this behavior: The show access-lists command displays ACL entries. show access-lists verification misses the Extended IPv4 ACL decision in this operations scenario. For show access-lists verification, separation from Extended IPv4 ACL remains material in this operations scenario.

 

Question 10

An ACL contains several permit entries but traffic that matches none of them is still discarded even though no final deny statement is displayed. Which option should the engineer use or identify? Choose ONE.

  1. Inbound interface ACL
  2. Place a standard ACL near the destination
  3. Implicit deny at the end of an ACL
  4. ACL sequence numbers

Correct Answer: C

Correct Answer

 

 

Answer C is correct because Implicit deny at the end of an ACL provides the default final deny applied to unmatched traffic. In a Implicit deny at use case, it is appropriate when building an allow-list so required traffic is not unintentionally blocked. The observed behavior aligns with that role.

Incorrect Answers

 

Answer A is incorrect because Inbound interface ACL concerns this behavior: An inbound ACL filters packets as they. In the operations case, Implicit deny at differs from Inbound interface ACL behavior. Operationally, Implicit deny at needs another behavior than Inbound interface ACL provides in this operations case.

Answer B is incorrect because Place a standard concerns this behavior: Standard ACLs are commonly placed close to. Place a standard misses the Implicit deny at decision in this operations scenario. For Place a standard, separation from Implicit deny at remains material in this operations scenario.

Answer D is incorrect because ACL sequence numbers concerns this behavior: Sequence numbers order entries in a named. For Implicit deny at, the operations evidence requires another function than ACL sequence numbers. Using ACL sequence numbers here would leave the Implicit deny at requirement unresolved during this operations task.

 

Question 11

A Cisco ACL statement must match a range of IPv4 addresses using the inverse-style bits that specify which address positions may vary. Which option should the engineer use or identify? Choose ONE.

  1. Outbound interface ACL
  2. ip access-group on an interface
  3. VTY access-class
  4. ACL wildcard mask

Correct Answer: D

Correct Answer

 

 

Answer D is correct because ACL wildcard mask provides the inverse-style mask used to describe an IPv4 address range in an ACL. In a ACL wildcard mask use case, it is appropriate when express the source or destination address range in IOS ACL entries. The observed behavior aligns with that role.

Incorrect Answers

 

Answer A is incorrect because An outbound ACL filters packets after routing has selected the egress interface and before the packets leave that interface For ACL wildcard mask, the operations evidence requires another function than Outbound interface ACL.

Answer B is incorrect because The ip access-group command applies an IPv4 ACL to an interface in the inbound or outbound direction The operations evidence favors ACL wildcard mask; ip access-group on operates at another control point.

Answer C is incorrect because VTY access-class concerns this behavior: The access-class command filters which source addresses. The operations evidence favors ACL wildcard mask; VTY access-class operates at another control point. The ACL wildcard mask result depends on another mechanism, not the VTY access-class behavior described above.

 

Question 12

Operations wants an ACL identified by a descriptive text name and edited in ACL configuration submode instead of referenced only by a number. Which option should the engineer use or identify? Choose ONE.

  1. Named ACL
  2. Place an extended ACL near the source
  3. show access-lists verification
  4. Standard IPv4 ACL

Correct Answer: A

Correct Answer

 

 

Answer A is correct because Named ACL provides an access list identified by a descriptive name and managed in ACL submode. In a Named ACL use case, it is appropriate when operational clarity and maintainability are more important than a numeric ACL identifier. The observed behavior aligns with that role.

Incorrect Answers

 

Answer B is incorrect because Extended ACLs are commonly placed close to the traffic source so unwanted application traffic is discarded before consuming downstream bandwidth The operations evidence favors Named ACL; Place an extended operates at another control point.

Answer C is incorrect because The show access-lists command displays ACL entries and can show match counters that help verify which statements are processing packets The required Named ACL outcome differs from the show access-lists verification purpose in this operations case.

Answer D is incorrect because Standard IPv4 ACL concerns this behavior: A standard IPv4 ACL matches primarily on. The required Named ACL outcome differs from the Standard IPv4 ACL purpose in this operations case. For Named ACL, choosing Standard IPv4 ACL would change the control point in this operations case.

 

Question 13

A policy must discard unwanted traffic immediately as packets arrive on a particular router interface, before the routing decision sends them onward. Which option should the engineer use or identify? Choose ONE.

  1. Place a standard ACL near the destination
  2. Inbound interface ACL
  3. ACL sequence numbers
  4. Extended IPv4 ACL

Correct Answer: B

Correct Answer

 

 

Answer B is correct because Inbound interface ACL provides filtering applied to packets entering a router interface. In a Inbound interface ACL use case, it is appropriate when traffic should be evaluated immediately on arrival at that interface. The observed behavior aligns with that role.

Incorrect Answers

 

Answer A is incorrect because Standard ACLs are commonly placed close to the destination because they match only source and could otherwise block that source from unintended destinations The required Inbound interface ACL outcome differs from the Place a standard purpose in this operations case.

Answer C is incorrect because Sequence numbers order entries in a named ACL and allow a new statement to be inserted between existing entries without rebuilding the entire list Using ACL sequence numbers would not produce the Inbound interface ACL behavior shown by this operations evidence.

Answer D is incorrect because Extended IPv4 ACL concerns this behavior: An extended IPv4 ACL can match source. Using Extended IPv4 ACL would not produce the Inbound interface ACL behavior shown by this operations evidence. The Extended IPv4 ACL function therefore differs materially from the Inbound interface ACL outcome required here.

 

Question 14

A policy should evaluate packets only after routing has selected a particular egress interface and just before the packets leave that interface. Which option should the engineer use or identify? Choose ONE.

  1. ip access-group on an interface
  2. VTY access-class
  3. Outbound interface ACL
  4. Implicit deny at the end of an ACL

Correct Answer: C

Correct Answer

 

 

Answer C is correct because Outbound interface ACL provides filtering applied to packets leaving the selected egress interface. In a Outbound interface ACL use case, it is appropriate when policy should be enforced on traffic exiting a particular interface. The observed behavior aligns with that role.

Incorrect Answers

 

Answer A is incorrect because ip access-group on is used when Use it after defining the ACL when packet filtering must actually take effect on routed interface traffic. In the operations case, Outbound interface ACL differs from ip access-group on behavior.

Answer B is incorrect because The access-class command filters which source addresses may establish management sessions to VTY lines using an ACL In the operations case, Outbound interface ACL differs from VTY access-class behavior. Operationally, Outbound interface ACL needs another behavior than VTY access-class provides in this operations case.

Answer D is incorrect because Implicit deny at concerns this behavior: Cisco ACL processing ends with an implicit. In the operations case, Outbound interface ACL differs from Implicit deny at behavior. Operationally, Outbound interface ACL needs another behavior than Implicit deny at provides in this operations case.

 

Question 15

A very specific application flow should be blocked before it consumes bandwidth across the network, while other traffic from the same source remains allowed. Which option should the engineer use or identify? Choose ONE.

  1. show access-lists verification
  2. Standard IPv4 ACL
  3. ACL wildcard mask
  4. Place an extended ACL near the source

Correct Answer: D

Correct Answer

 

 

Answer D is correct because Place an extended ACL near the source provides early filtering of specific traffic near where it originates. In a Place an extended use case, it is appropriate when Use this guideline when topology and operational constraints do not require a different placement. The observed behavior aligns with that role.

Incorrect Answers

 

Answer A is incorrect because show access-lists verification is used when confirm ACL contents and observe whether expected entries are matching traffic. show access-lists verification misses the Place an extended decision in this operations scenario. For show access-lists verification, separation from Place an extended remains material in this operations scenario.

Answer B is incorrect because A standard IPv4 ACL matches primarily on source IPv4 address and is appropriate when source identity alone determines the filtering decision Standard IPv4 ACL misses the Place an extended decision in this operations scenario.

Answer C is incorrect because An IPv4 ACL wildcard mask uses zero bits to require a match and one bits to ignore corresponding address bits For Place an extended, the operations evidence requires another function than ACL wildcard mask.

 

Question 16

A source-only filter must block one subnet from one destination LAN without accidentally preventing that source from reaching unrelated destinations. Which option should the engineer use or identify? Choose ONE.

  1. Place a standard ACL near the destination
  2. ACL sequence numbers
  3. Extended IPv4 ACL
  4. Named ACL

Correct Answer: A

Correct Answer

 

 

Answer A is correct because Place a standard ACL near the destination provides source-only filtering near the intended destination network. In a Place a standard use case, it is appropriate when limit collateral filtering when only source addresses can be matched. The observed behavior aligns with that role.

Incorrect Answers

 

Answer B is incorrect because ACL sequence numbers is used when the policy needs a new ACE at a specific evaluation point. For Place a standard, the operations evidence requires another function than ACL sequence numbers.

Answer C is incorrect because An extended IPv4 ACL can match source, destination, protocol, and TCP or UDP port information For Place a standard, the operations evidence requires another function than Extended IPv4 ACL. Using Extended IPv4 ACL here would leave the Place a standard requirement unresolved during this operations task.

Answer D is incorrect because A named ACL uses a meaningful identifier and supports editing individual entries in ACL configuration mode The operations evidence favors Place a standard; Named ACL operates at another control point. The Place a standard result depends on another mechanism, not the Named ACL behavior described above.

 

Question 17

An ACL has been created correctly, but it has no effect because it has not yet been bound to an interface and direction. Which option should the engineer use or identify? Choose ONE.

  1. VTY access-class
  2. ip access-group on an interface
  3. Implicit deny at the end of an ACL
  4. Inbound interface ACL

Correct Answer: B

Correct Answer

 

 

Answer B is correct because ip access-group on an interface provides attachment of a defined IPv4 ACL to an interface direction. In a ip access-group on use case, it is appropriate when Use it after defining the ACL when packet filtering must actually take effect on routed interface traffic. The observed behavior aligns with that role.

Incorrect Answers

 

Answer A is incorrect because VTY access-class is used when restrict remote management access to approved administrator source networks. The operations evidence favors ip access-group on; VTY access-class operates at another control point. The ip access-group on result depends on another mechanism, not the VTY access-class behavior described above.

Answer C is incorrect because Cisco ACL processing ends with an implicit deny, so packets that match no explicit permit statement are discarded The operations evidence favors ip access-group on; Implicit deny at operates at another control point.

Answer D is incorrect because An inbound ACL filters packets as they enter an interface before the router makes the normal outbound forwarding decision The required ip access-group on outcome differs from the Inbound interface ACL purpose in this operations case.

 

Question 18

After deploying an ACL, the engineer needs to view its entries and check match counters to verify which statements are processing traffic. Which option should the engineer use or identify? Choose ONE.

  1. Standard IPv4 ACL
  2. ACL wildcard mask
  3. show access-lists verification
  4. Outbound interface ACL

Correct Answer: C

Correct Answer

 

 

Answer C is correct because show access-lists verification provides verification of ACL entries and their packet matches. In a show access-lists verification use case, it is appropriate when confirm ACL contents and observe whether expected entries are matching traffic. The observed behavior aligns with that role.

Incorrect Answers

 

Answer A is incorrect because Standard IPv4 ACL is used when protocol, destination, and transport port do not need to be distinguished. The required show access-lists verification outcome differs from the Standard IPv4 ACL purpose in this operations case.

Answer B is incorrect because ACL wildcard mask is used when express the source or destination address range in IOS ACL entries. Using ACL wildcard mask would not produce the show access-lists verification behavior shown by this operations evidence.

Answer D is incorrect because Outbound interface ACL is used when policy should be enforced on traffic exiting a particular interface. In the operations case, show access-lists verification differs from Outbound interface ACL behavior. Operationally, show access-lists verification needs another behavior than Outbound interface ACL provides in this operations case.

 

Question 19

A named ACL needs a new deny inserted between two existing entries while preserving the rest of the list and its evaluation order. Which option should the engineer use or identify? Choose ONE.

  1. Extended IPv4 ACL
  2. Named ACL
  3. Place an extended ACL near the source
  4. ACL sequence numbers

Correct Answer: D

Correct Answer

 

 

Answer D is correct because ACL sequence numbers provides ordered insertion and editing of individual ACL entries. In a ACL sequence numbers use case, it is appropriate when the policy needs a new ACE at a specific evaluation point. The observed behavior aligns with that role.

Incorrect Answers

 

Answer A is incorrect because Extended IPv4 ACL is used when the policy must distinguish specific applications or destination networks. Using Extended IPv4 ACL would not produce the ACL sequence numbers behavior shown by this operations evidence.

Answer B is incorrect because Named ACL is used when operational clarity and maintainability are more important than a numeric ACL identifier. In the operations case, ACL sequence numbers differs from Named ACL behavior. Operationally, ACL sequence numbers needs another behavior than Named ACL provides in this operations case.

Answer C is incorrect because Place an extended is used when Use this guideline when topology and operational constraints do not require a different placement. Place an extended misses the ACL sequence numbers decision in this operations scenario.

 

Question 20

SSH service should remain enabled, but only hosts from the management subnet may initiate remote VTY sessions to the router. Which option should the engineer use or identify? Choose ONE.

  1. VTY access-class
  2. Implicit deny at the end of an ACL
  3. Inbound interface ACL
  4. Place a standard ACL near the destination

Correct Answer: A

Correct Answer

 

 

Answer A is correct because VTY access-class provides ACL-based restriction of incoming VTY management sessions. In a VTY access-class use case, it is appropriate when restrict remote management access to approved administrator source networks. The observed behavior aligns with that role.

Incorrect Answers

 

Answer B is incorrect because Implicit deny at is used when building an allow-list so required traffic is not unintentionally blocked. In the operations case, VTY access-class differs from Implicit deny at behavior. Operationally, VTY access-class needs another behavior than Implicit deny at provides in this operations case.

Answer C is incorrect because Inbound interface ACL is used when traffic should be evaluated immediately on arrival at that interface. Inbound interface ACL misses the VTY access-class decision in this operations scenario. For Inbound interface ACL, separation from VTY access-class remains material in this operations scenario.

Answer D is incorrect because Place a standard is used when limit collateral filtering when only source addresses can be matched. For VTY access-class, the operations evidence requires another function than Place a standard. Using Place a standard here would leave the VTY access-class requirement unresolved during this operations task.

Leave a Reply

How It Works

img
Step 1. Choose Exam
on ExamLabs
Download IT Exams Questions & Answers
img
Step 2. Open Exam with
Avanset Exam Simulator
Press here to download VCE Exam Simulator that simulates real exam environment
img
Step 3. Study
& Pass
IT Exams Anywhere, Anytime!