400-007 · Question #363
While access lists are generally associated with routers and firewalls, they can also be applied on layer 2 interfaces and to VLANs to provide granular security. Which are two benefits of using…
The correct answer is A. traffic filtering C. containing lateral attacks. Layer 2 ACLs (also called MAC ACLs or VLAN ACLs/VACLs) provide two key segmentation benefits: (A) Traffic filtering - they can permit or deny frames based on MAC addresses, EtherType, or VLAN membership, controlling which traffic flows between segments at the data link layer…
Question
While access lists are generally associated with routers and firewalls, they can also be applied on layer 2 interfaces and to VLANs to provide granular security. Which are two benefits of using layer 2 access lists for segmentation? (Choose two.)
Options
- Atraffic filtering
- Bcontextual filtering
- Ccontaining lateral attacks
- Dreduced load at layer 2
- EVLAN intercept
How the community answered
(34 responses)- A91% (31)
- B6% (2)
- D3% (1)
Explanation
Layer 2 ACLs (also called MAC ACLs or VLAN ACLs/VACLs) provide two key segmentation benefits: (A) Traffic filtering - they can permit or deny frames based on MAC addresses, EtherType, or VLAN membership, controlling which traffic flows between segments at the data link layer. (C) Containing lateral attacks - by restricting east-west traffic between hosts within the same Layer 2 domain, they prevent an attacker who has compromised one host from freely moving laterally to other hosts on the same segment. Contextual filtering (B) is more associated with next-gen firewalls, 'reduced load at layer 2' (D) is not a primary benefit, and VLAN intercept (E) is not a standard networking feature.
Topics
Community Discussion
No community discussion yet for this question.