nerdexam
Cisco

200-150 · Question #227

Refer to the exhibit. You want to restrict access from Host B. Where do you apply the ACL?

The correct answer is D. to the inbound and the outbound interfaces of the router. To fully restrict all traffic to and from Host B, ACLs must be applied on both the inbound and outbound interfaces so that traffic is filtered in both directions.

Cisco Data Center Networking Technologies

Question

Refer to the exhibit. You want to restrict access from Host B. Where do you apply the ACL?

Exhibit

200-150 question #227 exhibit

Options

  • Ato a VTY by using a named ACL
  • Bto the outbound interface of the router
  • Cto the inbound interface of the router
  • Dto the inbound and the outbound interfaces of the router

How the community answered

(35 responses)
  • A
    14% (5)
  • B
    9% (3)
  • C
    3% (1)
  • D
    74% (26)

Why each option

To fully restrict all traffic to and from Host B, ACLs must be applied on both the inbound and outbound interfaces so that traffic is filtered in both directions.

Ato a VTY by using a named ACL

A VTY ACL restricts remote management sessions (SSH or Telnet) to the router itself and has no effect on data plane traffic forwarded through the router.

Bto the outbound interface of the router

Applying the ACL only outbound blocks traffic leaving the router toward other networks but does not prevent Host B's packets from entering and being processed by the router.

Cto the inbound interface of the router

Applying the ACL only inbound blocks Host B's outgoing traffic from entering the router but does not restrict traffic flowing back toward Host B's network segment.

Dto the inbound and the outbound interfaces of the routerCorrect

Applying the ACL on the inbound interface blocks Host B's packets as they enter the router, while applying it on the outbound interface blocks return or other traffic destined back toward Host B's network segment. Using only one direction leaves a gap, allowing either Host B's outgoing traffic or traffic flowing toward Host B to pass unchecked.

Concept tested: ACL placement for bidirectional host traffic restriction

Source: https://www.cisco.com/c/en/us/support/docs/security/ios-firewall/23602-confaccesslists.html

Topics

#ACL#access control#packet filtering#router interface

Community Discussion

No community discussion yet for this question.

Full 200-150 Practice