Lesson 5 Flashcards

(18 cards)

1
Q

If there are no ACLs installed, outbound traffic is [permitted | denied] by default?

A

Permitted

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

If there are no ACLs installed, inbound traffic is [permitted | denied] by default?

A

Denied

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Security Appliances use Subnet Masks or Wildcard Masks?

A

Subnet Masks

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Cisco ISRs use Subnet Masks or Wildcard Masks?

A

Wildcard Masks

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

True or False: ACLs on Security Appliances apply to traffic destined TO the device?

A

No. Only through it. Unlike an ISR which goes through and to.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

After an initial connection is established, what happens with the return packets?

A

They aren’t described.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What is the first step in ACL processing?

A

The device checks to see if the packet is a part of an initial connection

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What is the second step in ACL processing?

A

If address translation is enabled, both addresses are compared against the ACL

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What is the third step in ACL processing?

A

The packet filter occurs at this stage.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What is the fourth step in ACL processing?

A

Routing

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What is the fifth step in ACL processing?

A

If address translation, outbound translation occurs

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

On ASAs, standard ACLs match packets based off of what?

A

Destination IP address

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

True or False: Standard ACLs can be applied to an internet for filtering traffic

A

False

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

What five things to Extended ACLs use to match traffic?

A
  • Source & Destination addresses
  • Layer 3 protocols
  • Source & Destination TCP/UDP ports
  • ICMP type for ICMP packets
  • User Identity for AD group membership
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

True or False: ACLs are processed before or after NAT translation

A

Before

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

In ASA version 8.3+ you must specify the __________ IP address.

17
Q

What hidden ACE do ACLs have at the end of every list?

A

Implicit deny

18
Q

How do you disable (not delete) an ACE?

A

Append “inactive” to the end of the line