restrict anyone from the network. How can the ACL statements be re-arranged so that the
system works as intended?
A. ACDB
B. BADC
C. DBAC
D. CDBA
5. When you are troubleshooting an ACL issue on a router, which command would
you use to verify which interfaces are affected by the ACL?
show ip interface
show access-lists
show interface
show ip access-lists
list ip interface
6. Which of the following access lists use the proper syntax to allow all telnet
traffic to host 192.168.1.3, from network 192.168.10.0, and apply the list inbound
on s0?
router(config):access-list 110 permit ip 192.168.10.0 0.0.0.255 host 192.168.1.3 eq 23
router(config):int e0
router(config-if):ip access-group 110 in
router(config)>access-list 105 permit tcp 192.168.10.0 0.0.0.255 host 192.168.1.3 eq 25
router(config)>int s0
router(config-if)>ip access-group 105 in
router(config)#access-list 101 permit 23 192.168.10.0 0.0.0.255 host 192.168.1.3 eq telnet
router(config)#int s0
router(config-if)#ip access-group 100 in
router(config)#access-list 100 permit tcp 192.168.10.0 0.0.0.255 host 192.168.1.3
eq 23
router(config)#int s0
router(config-if)#ip access-group 100 in
7. Which of the following commands uses the proper syntax to block all traffic into
network 192.168.3.0 except for SSH traffic?
ip access-list 89 permit any tcp 192.168.3.0 0.0.0.255 eq 23
ip access-list 99 permit tcp any 192.168.3.0 0.0.0.255 eq 23
ip access-list 100 permit tcp any 192.168.3.0 0.0.0.255 eq 23 any
ip access-list 101 permit tcp any 192.168.3.0 0.0.0.255 eq 22
8. To represent all hosts from network 172.16.3.0/22, which wildcard mask would
be most appropriate? (Choose One)
0.0.3.255
0.0.15.255
0.0.16.255
0.0.4.255
9. Which of the following would correctly configure an access list, numbered 10,
outbound on a VTY line? (Choose one)
access group 10 out
ip access-group 10 out
ip access-class 10 out
access-list 10 out
Explication: On a VTY, the command is ip access-class.
10. To filter any IP traffic between the network range 10.0.0.0 and 10.32.0.0, what
wildcard mask would best meet your nedds? (Choose one)
255.255.31.0
0.0.64.255
0.64.255.255
0.31.255.255
11. A router interface witch the IP address of 192.168.1.0 has the following access
list, applied inbound
ip access-list 100 permit tcp any any eq 23
What would happen if a host from the network 172.16.0.0, attempted to SSH to the
interface?
SSH traffic would be permitted
SSH traffic would be denied
12. Which of the following sample commands uses the proper syntax to deny telnet
access from IP address 10.1.1.54 into 10.1.1.50?
access-list 90 deny tcp 10.1.1.54 0.0.0.0 10.1.1.50 0.0.0.0 eq 21
access-list 99 deny telnet 10.1.1.54 0.0.0.0 10.1.1.50 0.0.0.0
access-list 101 deny ip 10.1.1.54 0.0.0.0 10.1.1.50 0.0.0.0 telnet
access-list 101 deny tcp 10.1.1.54 0.0.0.0 10.1.1.50 0.0.0.0 eq 23
13. Which of the following could take the place of the wildcard mask 0.0.0.0 in an
access lilst (Choose one)?
Any
Deny
Host
All
Host is the equivalent of the wildcard mask 0.0.0.0
14. At a client location, you issue a show ip interface command and find an access
list numbered 910. What type of access list is this? (Choose one)
IP standard
IP Extended
IPX Standard
IPX Extended
IPX extended access lists are numbered 900-999
15. The task is to create and apply a numberd access-list with no more than
statements that will allow ONLY host C web access to the Finance Web Server. No
other hosts will hace web access to the Finance Web Server.
All other traffic is permitted.
The Core connectios uses an IP address og 198.18.196.65
The computer in the Hosts LAN hace been assigned address of 192.168.33.1 192.168.33.254
Host A 192.168.33.1
Host B 192.168.33.2
Host C 192.168.33.3
Host D 192.168.33.4
The serves in the Server LAN hace been assigned address of 172.22.242.17 172.22.242.30
The Finance Web Server 172.22.242.23
The Public Web Server 172.22.242.17
We learn that interface FastEthernet0/1 is the interface connected to Server LAN network. It
is the interface we will apply our access-list (for outbound direction).
Corp1#configure terminal
Our access-list needs to allow host C 192.168.33.3 to the Finance Web Server
172.22.242.23 via web (port 80)
Some modifications:
Modification 1:
permit host B from accessing finance
server
Modification 2:
Only allow Host C to to access the financial
server
Modification 3:
- Host C should be able to use a
web browser(HTTP)to access the
Finance Web Server
Modification 4:
Host C should be able to use a
web browser to access the
financial web server
* There are some reports about the command of All hosts in the core and on the local LAN
should be able to access the Public web server saying that the correct command should be
access-list 100 permit ip any any, not access-list 100 permit ip any host (IP of Public Web
Server). Although I believe the second command is better but maybe you should use the
first command access-list 100 permit ip any any instead as some reports said they got
100% when using this command (even if the question gives you the IP address of Public Web
Server). It is a bug in this sim.
(Note: Dont forget to apply this access list to the suitable interface or you will lose points
interface fa0/1
ip access-group 100 out
And in the exam, they may slightly change the requirements, for example host A, host B
instead of host C so make sure you read the requirement carefully and use the access-list
correctly)