Topic 17 Practice Test 3 covers IPsec VPNs and ACLs for Cisco Certified Network Associate 200-301 CCNA and maps to objectives 5.5–5.6. For broader exam preparation, review the Cisco CCNA 200-301 Exam Dumps. Every option includes focused technical reasoning explaining both the networking concept and its fit to the scenario.
Question 1
A support engineer connects from a home broadband network. The solution must terminate an encrypted user session on the enterprise edge without creating a permanent tunnel for the entire home LAN. Which option best matches the required behavior? Choose ONE.
- IKE negotiation
- Site-to-site VPN
- Remote-access VPN
- IPsec ESP
Correct Answer: C
Correct Answer
Answer C is correct because Verification for Remote-access VPN supports this choice. When Use it for teleworkers or roaming users who need protected access to internal resources, Remote-access VPN supplies a secure tunnel for one remote user endpoint into the enterprise.
Incorrect Answers
Answer A is incorrect because The purpose of IKE negotiation is negotiation of peers and security associations before encrypted user data is carried. Using IKE negotiation would not produce the Remote-access VPN behavior shown by this verification evidence.
Answer B is incorrect because The purpose of Site-to-site VPN is a protected gateway-to-gateway tunnel between two networks. In the verification case, Remote-access VPN differs from Site-to-site VPN behavior. For Site-to-site VPN, separation from Remote-access VPN remains material in this verification scenario.
Answer D is incorrect because The purpose of IPsec ESP is the IPsec data-protection protocol that can encrypt packet payloads. IPsec ESP misses the Remote-access VPN decision in this verification scenario. Using IPsec ESP here would leave the Remote-access VPN requirement unresolved during this verification task.
Question 2
A merger connects two fixed corporate networks, each behind a security gateway. Applications on either LAN should communicate through an always-available encrypted gateway-to-gateway path. Which option best matches the required behavior? Choose ONE.
- IPsec ESP
- IPsec confidentiality through encryption
- Crypto ACL / interesting traffic selector
- Site-to-site VPN
Correct Answer: D
Correct Answer
Answer D is correct because Verification for Site-to-site VPN supports this choice. When connect branches, data centers, or other fixed networks over an untrusted WAN, Site-to-site VPN supplies a protected gateway-to-gateway tunnel between two networks. Using Site-to-site VPN here would leave the Site-to-site VPN requirement unresolved during this verification task.
Incorrect Answers
Answer A is incorrect because IPsec ESP concerns this behavior: Encapsulating Security Payload is the IPsec protocol. IPsec ESP misses the Site-to-site VPN decision in this verification scenario. Using IPsec ESP here would leave the Site-to-site VPN requirement unresolved during this verification task.
Answer B is incorrect because The purpose of IPsec confidentiality through is encryption of data carried through the VPN tunnel. IPsec confidentiality through misses the Site-to-site VPN decision in this verification scenario. Using IPsec confidentiality through here would leave the Site-to-site VPN requirement unresolved during this verification task.
Answer C is incorrect because The purpose of Crypto ACL / is selection of which IP flows should enter a policy-based IPsec tunnel. For Site-to-site VPN, the verification evidence requires another function than Crypto ACL /.
Question 3
A compliance test captures encrypted VPN packets on the provider network and verifies that application payloads are unintelligible to the observer. Which option best matches the required behavior? Choose ONE.
- IPsec confidentiality through encryption
- Crypto ACL / interesting traffic selector
- IPsec integrity and peer/data authentication
- Remote-access VPN
Correct Answer: A
Correct Answer
Answer A is correct because Verification for IPsec confidentiality through supports this choice. When Use confidentiality when sensitive traffic crosses an untrusted network, IPsec confidentiality through supplies encryption of data carried through the VPN tunnel. The IPsec confidentiality through result depends on another mechanism, not the IPsec confidentiality through behavior described above.
Incorrect Answers
Answer B is incorrect because Crypto ACL / concerns this behavior: A crypto ACL identifies the traffic that. For IPsec confidentiality through, the verification evidence requires another function than Crypto ACL /. The IPsec confidentiality through result depends on another mechanism, not the Crypto ACL / behavior described above.
Answer C is incorrect because The purpose of IPsec integrity and is cryptographic detection of in-transit modification of protected packets. For IPsec confidentiality through, the verification evidence requires another function than IPsec integrity and. The IPsec confidentiality through result depends on another mechanism, not the IPsec integrity and behavior described above.
Answer D is incorrect because The purpose of Remote-access VPN is a secure tunnel for one remote user endpoint into the enterprise. The verification evidence favors IPsec confidentiality through; Remote-access VPN operates at another control point.
Question 4
A test tool flips bits in protected VPN traffic. The receiving peer must detect the alteration rather than delivering silently modified data. Which option best matches the required behavior? Choose ONE.
- Remote-access VPN
- IPsec integrity and peer/data authentication
- IKE negotiation
- Site-to-site VPN
Correct Answer: B
Correct Answer
Answer B is correct because Verification for IPsec integrity and supports this choice. When Use integrity protection where altered packets must be detected, IPsec integrity and supplies cryptographic detection of in-transit modification of protected packets. For IPsec integrity and, choosing IPsec integrity and would change the control point in this verification case.
Incorrect Answers
Answer A is incorrect because Remote-access VPN concerns this behavior: A remote-access VPN connects an individual user. The verification evidence favors IPsec integrity and; Remote-access VPN operates at another control point. For IPsec integrity and, choosing Remote-access VPN would change the control point in this verification case.
Answer C is incorrect because IKE negotiation concerns this behavior: Internet Key Exchange negotiates security associations, algorithms. The required IPsec integrity and outcome differs from the IKE negotiation purpose in this verification case. The IKE negotiation function therefore differs materially from the IPsec integrity and outcome required here.
Answer D is incorrect because Site-to-site VPN concerns this behavior: A site-to-site VPN protects traffic between networks. Using Site-to-site VPN would not produce the IPsec integrity and behavior shown by this verification evidence. Operationally, IPsec integrity and needs another behavior than Site-to-site VPN provides in this verification case.
Question 5
Two gateways have compatible IPsec policies but no security associations yet. They need to establish peer trust and negotiate the parameters that precede protected data flow. Which option best matches the required behavior? Choose ONE.
- Site-to-site VPN
- IPsec ESP
- IKE negotiation
- IPsec confidentiality through encryption
Correct Answer: C
Correct Answer
Answer C is correct because Verification for IKE negotiation supports this choice. When Use IKE for establishing and managing the cryptographic parameters of an IPsec VPN, IKE negotiation supplies negotiation of peers and security associations before encrypted user data is carried.
Incorrect Answers
Answer A is incorrect because A site-to-site VPN protects traffic between networks through VPN gateways, making the tunnel transparent to individual hosts Using Site-to-site VPN would not produce the IKE negotiation behavior shown by this verification evidence.
Answer B is incorrect because Encapsulating Security Payload is the IPsec protocol commonly used to provide encryption and integrity for protected data traffic In the verification case, IKE negotiation differs from IPsec ESP behavior. For IPsec ESP, separation from IKE negotiation remains material in this verification scenario.
Answer D is incorrect because IPsec confidentiality through concerns this behavior: IPsec can encrypt protected IP traffic so. In the verification case, IKE negotiation differs from IPsec confidentiality through behavior. For IPsec confidentiality through, separation from IKE negotiation remains material in this verification scenario.
Question 6
A packet analysis exercise asks which IPsec component encapsulates protected IP traffic and supplies encryption/integrity services to user data. Which option best matches the required behavior? Choose ONE.
- IPsec confidentiality through encryption
- Crypto ACL / interesting traffic selector
- IPsec integrity and peer/data authentication
- IPsec ESP
Correct Answer: D
Correct Answer
Answer D is correct because Verification for IPsec ESP supports this choice. When Use ESP when VPN payloads require confidentiality in addition to integrity services, IPsec ESP supplies the IPsec data-protection protocol that can encrypt packet payloads.
Incorrect Answers
Answer A is incorrect because IPsec can encrypt protected IP traffic so observers on the transit network cannot read the payload In the verification case, IPsec ESP differs from IPsec confidentiality through behavior. For IPsec confidentiality through, separation from IPsec ESP remains material in this verification scenario.
Answer B is incorrect because A crypto ACL identifies the traffic that should be protected by a policy-based IPsec VPN Crypto ACL / misses the IPsec ESP decision in this verification scenario. Using Crypto ACL / here would leave the IPsec ESP requirement unresolved during this verification task.
Answer C is incorrect because IPsec integrity and concerns this behavior: IPsec protection can detect unauthorized modification and. IPsec integrity and misses the IPsec ESP decision in this verification scenario. Using IPsec integrity and here would leave the IPsec ESP requirement unresolved during this verification task.
Question 7
A policy-based VPN is up, but the wrong subnets are being encrypted. The engineer must inspect the selector that defines which source/destination flows are considered interesting. Which option best matches the required behavior? Choose ONE.
- Crypto ACL / interesting traffic selector
- IPsec integrity and peer/data authentication
- Remote-access VPN
- IKE negotiation
Correct Answer: A
Correct Answer
Answer A is correct because Verification for Crypto ACL / supports this choice. When Use mirrored source and destination definitions on peers so the intended protected flows match consistently, Crypto ACL / supplies selection of which IP flows should enter a policy-based IPsec tunnel.
Incorrect Answers
Answer B is incorrect because IPsec protection can detect unauthorized modification and authenticate protected traffic so tampering is not silently accepted IPsec integrity and misses the Crypto ACL / decision in this verification scenario. Using IPsec integrity and here would leave the Crypto ACL / requirement unresolved during this verification task.
Answer C is incorrect because A remote-access VPN connects an individual user device to an organization network across an untrusted transport For Crypto ACL /, the verification evidence requires another function than Remote-access VPN. The Crypto ACL / result depends on another mechanism, not the Remote-access VPN behavior described above.
Answer D is incorrect because Internet Key Exchange negotiates security associations, algorithms, keying material, and peer authentication before protected IPsec data flows The verification evidence favors Crypto ACL /; IKE negotiation operates at another control point.
Question 8
A router should deny all packets sourced from 10.20.30.0/24 regardless of their destination or Layer 4 protocol. The filter does not need any additional packet fields. Which option best matches the required behavior? Choose ONE.
- Named ACL
- Standard IPv4 ACL
- Place a standard ACL near the destination
- VTY access-class
Correct Answer: B
Correct Answer
Answer B is correct because Verification for Standard IPv4 ACL supports this choice. When protocol, destination, and transport port do not need to be distinguished, Standard IPv4 ACL supplies filtering based only on the source IPv4 address.
Incorrect Answers
Answer A is incorrect because The purpose of Named ACL is an access list identified by a descriptive name and managed in ACL submode. In the verification case, Standard IPv4 ACL differs from Named ACL behavior.
Answer C is incorrect because The purpose of Place a standard is source-only filtering near the intended destination network. Place a standard misses the Standard IPv4 ACL decision in this verification scenario. Using Place a standard here would leave the Standard IPv4 ACL requirement unresolved during this verification task.
Answer D is incorrect because The purpose of VTY access-class is ACL-based restriction of incoming VTY management sessions. For Standard IPv4 ACL, the verification evidence requires another function than VTY access-class. The Standard IPv4 ACL result depends on another mechanism, not the VTY access-class behavior described above.
Question 9
A router must distinguish TCP/443 from ICMP and from other TCP ports while also matching both source and destination networks. Which option best matches the required behavior? Choose ONE.
- Inbound interface ACL
- ip access-group on an interface
- Extended IPv4 ACL
- Standard IPv4 ACL
Correct Answer: C
Correct Answer
Answer C is correct because Verification for Extended IPv4 ACL supports this choice. When the policy must distinguish specific applications or destination networks, Extended IPv4 ACL supplies filtering that considers source, destination, protocol, and service port.
Incorrect Answers
Answer A is incorrect because The purpose of Inbound interface ACL is filtering applied to packets entering a router interface. Inbound interface ACL misses the Extended IPv4 ACL decision in this verification scenario. Using Inbound interface ACL here would leave the Extended IPv4 ACL requirement unresolved during this verification task.
Answer B is incorrect because The purpose of ip access-group on is attachment of a defined IPv4 ACL to an interface direction. For Extended IPv4 ACL, the verification evidence requires another function than ip access-group on.
Answer D is incorrect because The purpose of Standard IPv4 ACL is filtering based only on the source IPv4 address. The verification evidence favors Extended IPv4 ACL; Standard IPv4 ACL operates at another control point. For Extended IPv4 ACL, choosing Standard IPv4 ACL would change the control point in this verification case.
Question 10
A newly added allow-list permits the documented applications, yet an undocumented diagnostic flow stops. The engineer sees no explicit final deny line in the ACL. Which option best matches the required behavior? Choose ONE.
- Outbound interface ACL
- show access-lists verification
- Extended IPv4 ACL
- Implicit deny at the end of an ACL
Correct Answer: D
Correct Answer
Answer D is correct because Verification for Implicit deny at supports this choice. When building an allow-list so required traffic is not unintentionally blocked, Implicit deny at supplies the default final deny applied to unmatched traffic.
Incorrect Answers
Answer A is incorrect because The purpose of Outbound interface ACL is filtering applied to packets leaving the selected egress interface. For Implicit deny at, the verification evidence requires another function than Outbound interface ACL. The Implicit deny at result depends on another mechanism, not the Outbound interface ACL behavior described above.
Answer B is incorrect because The purpose of show access-lists verification is verification of ACL entries and their packet matches. The verification evidence favors Implicit deny at; show access-lists verification operates at another control point. For Implicit deny at, choosing show access-lists verification would change the control point in this verification case.
Answer C is incorrect because The purpose of Extended IPv4 ACL is filtering that considers source, destination, protocol, and service port. The required Implicit deny at outcome differs from the Extended IPv4 ACL purpose in this verification case.
Question 11
To match 192.0.2.0/24 in an IOS ACL, the engineer needs the mask form in which host bits are set to 1 and fixed network bits are set to 0. Which option best matches the required behavior? Choose ONE.
- ACL wildcard mask
- Place an extended ACL near the source
- ACL sequence numbers
- Implicit deny at the end of an ACL
Correct Answer: A
Correct Answer
Answer A is correct because Verification for ACL wildcard mask supports this choice. When express the source or destination address range in IOS ACL entries, ACL wildcard mask supplies the inverse-style mask used to describe an IPv4 address range in an ACL.
Incorrect Answers
Answer B is incorrect because The purpose of Place an extended is early filtering of specific traffic near where it originates. The verification evidence favors ACL wildcard mask; Place an extended operates at another control point.
Answer C is incorrect because The purpose of ACL sequence numbers is ordered insertion and editing of individual ACL entries. The required ACL wildcard mask outcome differs from the ACL sequence numbers purpose in this verification case.
Answer D is incorrect because The purpose of Implicit deny at is the default final deny applied to unmatched traffic. Using Implicit deny at would not produce the ACL wildcard mask behavior shown by this verification evidence.
Question 12
A change-control standard requires operators to refer to the filter as BRANCH-WEB rather than by a numeric identifier and to insert ACEs from ACL submode. Which option best matches the required behavior? Choose ONE.
- Place a standard ACL near the destination
- Named ACL
- VTY access-class
- ACL wildcard mask
Correct Answer: B
Correct Answer
Answer B is correct because Verification for Named ACL supports this choice. When operational clarity and maintainability are more important than a numeric ACL identifier, Named ACL supplies an access list identified by a descriptive name and managed in ACL submode.
Incorrect Answers
Answer A is incorrect because Place a standard concerns this behavior: Standard ACLs are commonly placed close to. Using Place a standard would not produce the Named ACL behavior shown by this verification evidence. Operationally, Named ACL needs another behavior than Place a standard provides in this verification case.
Answer C is incorrect because VTY access-class concerns this behavior: The access-class command filters which source addresses. In the verification case, Named ACL differs from VTY access-class behavior. For VTY access-class, separation from Named ACL remains material in this verification scenario.
Answer D is incorrect because The purpose of ACL wildcard mask is the inverse-style mask used to describe an IPv4 address range in an ACL. In the verification case, Named ACL differs from ACL wildcard mask behavior.
Question 13
An interface receives traffic from an untrusted LAN. The requirement is to filter it as it enters that interface, before the router forwards it. Which option best matches the required behavior? Choose ONE.
- ip access-group on an interface
- Standard IPv4 ACL
- Inbound interface ACL
- Named ACL
Correct Answer: C
Correct Answer
Answer C is correct because Verification for Inbound interface ACL supports this choice. When traffic should be evaluated immediately on arrival at that interface, Inbound interface ACL supplies filtering applied to packets entering a router interface.
Incorrect Answers
Answer A is incorrect because ip access-group on concerns this behavior: The ip access-group command applies an IPv4. In the verification case, Inbound interface ACL differs from ip access-group on behavior. For ip access-group on, separation from Inbound interface ACL remains material in this verification scenario.
Answer B is incorrect because Standard IPv4 ACL concerns this behavior: A standard IPv4 ACL matches primarily on. Standard IPv4 ACL misses the Inbound interface ACL decision in this verification scenario. Using Standard IPv4 ACL here would leave the Inbound interface ACL requirement unresolved during this verification task.
Answer D is incorrect because Named ACL concerns this behavior: A named ACL uses a meaningful identifier. For Inbound interface ACL, the verification evidence requires another function than Named ACL. The Inbound interface ACL result depends on another mechanism, not the Named ACL behavior described above.
Question 14
Traffic from several ingress interfaces may route toward one WAN link. The filter must apply only to packets as they exit that WAN interface. Which option best matches the required behavior? Choose ONE.
- show access-lists verification
- Extended IPv4 ACL
- Inbound interface ACL
- Outbound interface ACL
Correct Answer: D
Correct Answer
Answer D is correct because Verification for Outbound interface ACL supports this choice. When policy should be enforced on traffic exiting a particular interface, Outbound interface ACL supplies filtering applied to packets leaving the selected egress interface.
Incorrect Answers
Answer A is incorrect because show access-lists verification concerns this behavior: The show access-lists command displays ACL entries. show access-lists verification misses the Outbound interface ACL decision in this verification scenario. Using show access-lists verification here would leave the Outbound interface ACL requirement unresolved during this verification task.
Answer B is incorrect because Extended IPv4 ACL concerns this behavior: An extended IPv4 ACL can match source. For Outbound interface ACL, the verification evidence requires another function than Extended IPv4 ACL. The Outbound interface ACL result depends on another mechanism, not the Extended IPv4 ACL behavior described above.
Answer C is incorrect because Inbound interface ACL concerns this behavior: An inbound ACL filters packets as they. The verification evidence favors Outbound interface ACL; Inbound interface ACL operates at another control point. For Outbound interface ACL, choosing Inbound interface ACL would change the control point in this verification case.
Question 15
A branch generates one prohibited application flow toward the data center. The network should discard that specific flow at the branch edge instead of carrying it across the WAN. Which option best matches the required behavior? Choose ONE.
- Place an extended ACL near the source
- ACL sequence numbers
- Implicit deny at the end of an ACL
- Outbound interface ACL
Correct Answer: A
Correct Answer
Answer A is correct because Verification for Place an extended supports this choice. When Use this guideline when topology and operational constraints do not require a different placement, Place an extended supplies early filtering of specific traffic near where it originates.
Incorrect Answers
Answer B is incorrect because ACL sequence numbers concerns this behavior: Sequence numbers order entries in a named. For Place an extended, the verification evidence requires another function than ACL sequence numbers. The Place an extended result depends on another mechanism, not the ACL sequence numbers behavior described above.
Answer C is incorrect because Implicit deny at concerns this behavior: Cisco ACL processing ends with an implicit. The verification evidence favors Place an extended; Implicit deny at operates at another control point. For Place an extended, choosing Implicit deny at would change the control point in this verification case.
Answer D is incorrect because Outbound interface ACL concerns this behavior: An outbound ACL filters packets after routing. The required Place an extended outcome differs from the Outbound interface ACL purpose in this verification case. The Outbound interface ACL function therefore differs materially from the Place an extended outcome required here.
Question 16
A standard ACL matches only source addresses. Engineers want to minimize collateral impact on that source subnet’s access to other networks. Which option best matches the required behavior? Choose ONE.
- VTY access-class
- Place a standard ACL near the destination
- ACL wildcard mask
- Place an extended ACL near the source
Correct Answer: B
Correct Answer
Answer B is correct because Verification for Place a standard supports this choice. When limit collateral filtering when only source addresses can be matched, Place a standard supplies source-only filtering near the intended destination network. For Place a standard, choosing Place a standard would change the control point in this verification case.
Incorrect Answers
Answer A is incorrect because The access-class command filters which source addresses may establish management sessions to VTY lines using an ACL The required Place a standard outcome differs from the VTY access-class purpose in this verification case.
Answer C is incorrect because ACL wildcard mask concerns this behavior: An IPv4 ACL wildcard mask uses zero. The required Place a standard outcome differs from the ACL wildcard mask purpose in this verification case. The ACL wildcard mask function therefore differs materially from the Place a standard outcome required here.
Answer D is incorrect because Place an extended concerns this behavior: Extended ACLs are commonly placed close to. Using Place an extended would not produce the Place a standard behavior shown by this verification evidence. Operationally, Place a standard needs another behavior than Place an extended provides in this verification case.
Question 17
Verification shows the ACL definition is correct and contains matches, but the intended interface configuration lacks any ACL attachment command. Which option best matches the required behavior? Choose ONE.
- Standard IPv4 ACL
- Named ACL
- ip access-group on an interface
- Place a standard ACL near the destination
Correct Answer: C
Correct Answer
Answer C is correct because Verification for ip access-group on supports this choice. When Use it after defining the ACL when packet filtering must actually take effect on routed interface traffic, ip access-group on supplies attachment of a defined IPv4 ACL to an interface direction.
Incorrect Answers
Answer A is incorrect because A standard IPv4 ACL matches primarily on source IPv4 address and is appropriate when source identity alone determines the filtering decision Using Standard IPv4 ACL would not produce the ip access-group on behavior shown by this verification evidence.
Answer B is incorrect because A named ACL uses a meaningful identifier and supports editing individual entries in ACL configuration mode In the verification case, ip access-group on differs from Named ACL behavior. For Named ACL, separation from ip access-group on remains material in this verification scenario.
Answer D is incorrect because Standard ACLs are commonly placed close to the destination because they match only source and could otherwise block that source from unintended destinations Place a standard misses the ip access-group on decision in this verification scenario.
Question 18
A troubleshooting session needs evidence that a particular ACE is receiving hits and a view of the ACL statements currently installed. Which option best matches the required behavior? Choose ONE.
- Extended IPv4 ACL
- Inbound interface ACL
- ip access-group on an interface
- show access-lists verification
Correct Answer: D
Correct Answer
Answer D is correct because Verification for show access-lists verification supports this choice. When confirm ACL contents and observe whether expected entries are matching traffic, show access-lists verification supplies verification of ACL entries and their packet matches.
Incorrect Answers
Answer A is incorrect because An extended IPv4 ACL can match source, destination, protocol, and TCP or UDP port information In the verification case, show access-lists verification differs from Extended IPv4 ACL behavior. For Extended IPv4 ACL, separation from show access-lists verification remains material in this verification scenario.
Answer B is incorrect because An inbound ACL filters packets as they enter an interface before the router makes the normal outbound forwarding decision Inbound interface ACL misses the show access-lists verification decision in this verification scenario.
Answer C is incorrect because The ip access-group command applies an IPv4 ACL to an interface in the inbound or outbound direction For show access-lists verification, the verification evidence requires another function than ip access-group on.
Question 19
A named ACL has entries 10 and 20. The engineer must insert a new statement between them without deleting and recreating the ACL. Which option best matches the required behavior? Choose ONE.
- ACL sequence numbers
- Implicit deny at the end of an ACL
- Outbound interface ACL
- show access-lists verification
Correct Answer: A
Correct Answer
Answer A is correct because Verification for ACL sequence numbers supports this choice. When the policy needs a new ACE at a specific evaluation point, ACL sequence numbers supplies ordered insertion and editing of individual ACL entries.
Incorrect Answers
Answer B is incorrect because Cisco ACL processing ends with an implicit deny, so packets that match no explicit permit statement are discarded Implicit deny at misses the ACL sequence numbers decision in this verification scenario.
Answer C is incorrect because An outbound ACL filters packets after routing has selected the egress interface and before the packets leave that interface For ACL sequence numbers, the verification evidence requires another function than Outbound interface ACL.
Answer D is incorrect because The show access-lists command displays ACL entries and can show match counters that help verify which statements are processing packets The verification evidence favors ACL sequence numbers; show access-lists verification operates at another control point.
Question 20
The router’s data-plane interfaces should not be filtered, but remote administrative logins to VTY lines must be limited by source network. Which option best matches the required behavior? Choose ONE.
- ACL wildcard mask
- VTY access-class
- Place an extended ACL near the source
- ACL sequence numbers
Correct Answer: B
Correct Answer
Answer B is correct because Verification for VTY access-class supports this choice. When restrict remote management access to approved administrator source networks, VTY access-class supplies ACL-based restriction of incoming VTY management sessions. Using VTY access-class here would leave the VTY access-class requirement unresolved during this verification task.
Incorrect Answers
Answer A is incorrect because An IPv4 ACL wildcard mask uses zero bits to require a match and one bits to ignore corresponding address bits For VTY access-class, the verification evidence requires another function than ACL wildcard mask.
Answer C is incorrect because Extended ACLs are commonly placed close to the traffic source so unwanted application traffic is discarded before consuming downstream bandwidth The verification evidence favors VTY access-class; Place an extended operates at another control point.
Answer D is incorrect because Sequence numbers order entries in a named ACL and allow a new statement to be inserted between existing entries without rebuilding the entire list The required VTY access-class outcome differs from the ACL sequence numbers purpose in this verification case.