HPE7-A01 · Question #65
A customer wants to provide wired security as close to the source as possible The wired security must meet the following requirements: - allow ping from the IT management VLAN to the user VLAN…
The correct answer is C. Apply an inbound ACL on the user VLAN denying icmp echo traffic toward the IT management. An inbound ACL is applied to traffic entering a port or VLAN. An outbound ACL is applied to traffic leaving a port or VLAN4. To deny ping sourcing from the user VLAN to the IT management VLAN, an inbound ACL on the user VLAN should be used to filter icmp echo traffic toward the…
Question
A customer wants to provide wired security as close to the source as possible The wired security must meet the following requirements:
- allow ping from the IT management VLAN to the user VLAN
- deny ping sourcing from the user VLAN to the IT management VLAN
The customer is using Aruba CX 6300s. What is the correct way to implement these requirements?
Options
- AApply an outbound ACL on the user VLAN allowing temp echo-reply traffic toward the IT
- BApply an inbound ACL on the user VLAN allowing icmp echo-reply traffic toward the IT
- CApply an inbound ACL on the user VLAN denying icmp echo traffic toward the IT management
- DApply an outbound ACL on the user VLAN denying icmp echo traffic toward the IT management
How the community answered
(35 responses)- A3% (1)
- B14% (5)
- C74% (26)
- D9% (3)
Explanation
An inbound ACL is applied to traffic entering a port or VLAN. An outbound ACL is applied to traffic leaving a port or VLAN4. To deny ping sourcing from the user VLAN to the IT management VLAN, an inbound ACL on the user VLAN should be used to filter icmp echo traffic toward the IT management VLAN. Icmp echo-reply traffic is not needed to be allowed because it is already permitted by default.
Topics
Community Discussion
No community discussion yet for this question.