nerdexam
Cisco

350-001 · Question #76

Refer to the exhibit. Clients that are connected to Fa0/0 of RTA are only allowed to connect to the Internet and networks, but not the networks on Fa1/0, Fa2/0, Fa3/0 and Fa4/0. To achieve this, you…

The correct answer is D. access-list 101 deny ip any 10.1.0.0 0.0.3.255. Access-lists use a wild card mask which is incorrectly configured in the above example Reference

Security

Question

Refer to the exhibit. Clients that are connected to Fa0/0 of RTA are only allowed to connect to the Internet and networks, but not the networks on Fa1/0, Fa2/0, Fa3/0 and Fa4/0. To achieve this, you have configured an ACL on RTA and applied it on the incoming direction of interface Fa0/0. After you apply this ACL, you learn that some of these networks are still accessible for clients that are connected to the 10.10.10.0/24 network. What is the correct ACL configuration to solve this issue?

Exhibit

350-001 question #76 exhibit

Options

  • Aaccess-list 101 deny ip any 10.1.0.0 0.0.1.255
  • Baccess-list 101 permit ip any 10.1.0.0 0.0.1.255
  • Caccess-list 101 deny ip any 10.1.0.0 0.0.252.255
  • Daccess-list 101 deny ip any 10.1.0.0 0.0.3.255

How the community answered

(51 responses)
  • A
    6% (3)
  • B
    27% (14)
  • C
    12% (6)
  • D
    55% (28)

Explanation

Access-lists use a wild card mask which is incorrectly configured in the above example Reference

Topics

#ACL#wildcard mask#subnet filtering#access control

Community Discussion

No community discussion yet for this question.

Full 350-001 Practice