350-029 · Question #333
Refer to the exhibit. Inbound Infrastructure ACLs are configured to protect the SP network. Which three types of traffic should be filtered in the infrastructure ACLs? (Choose three.)
The correct answer is A. traffic from a source with an IP address that is within 239.255.0.0/16 B. FTP traffic destined for internal routers D. traffic from a source with an IP address that is within 162.238.0.0/16. With the use of the protocols and addresses identified, the infrastructure ACL can be built to permit the protocols and protect the addresses. In addition to direct protection, the ACL also provides a first line of defense against certain types of invalid traffic on the…
Question
Refer to the exhibit. Inbound Infrastructure ACLs are configured to protect the SP network. Which three types of traffic should be filtered in the infrastructure ACLs? (Choose three.)
Exhibit
Options
- Atraffic from a source with an IP address that is within 239.255.0.0/16
- BFTP traffic destined for internal routers
- CIPsec traffic that at an internal router
- Dtraffic from a source with an IP address that is within 162.238.0.0/16
- EEBGP traffic that peers with edge routers
How the community answered
(31 responses)- A74% (23)
- C16% (5)
- E10% (3)
Explanation
With the use of the protocols and addresses identified, the infrastructure ACL can be built to permit the protocols and protect the addresses. In addition to direct protection, the ACL also provides a first line of defense against certain types of invalid traffic on the Internet: - RFC 1918 space must be denied. (RFC1918 describes a set of network ranges set aside for so- called "private" use.) - Packets with a source address that fall under special-use address space, as defined in RFC 3330, must be denied. - Anti-spoof filters must be applied. (Your address space must never be the source of packets from outside your AS.)
Topics
Community Discussion
No community discussion yet for this question.
