PrepAway - Latest Free Exam Questions & Answers

Which statement is true?

Refer to the exhibit and partial configuration.

Which statement is true?

PrepAway - Latest Free Exam Questions & Answers

A.
All traffic destined for network 172.16.150.0 will be denied due to the implicit deny all.

B.
All traffic from network 10.0.0.0 will be permitted.

C.
Access-list 101 will prevent address spoofing from interface E0.

D.
This is a misconfigured ACL resulting in traffic not being allowed into the router in interface S0.

E.
This ACL will prevent any host on the Internet from spoofing the inside network address as the
source address for packets coming into the router from the Internet.

Explanation:
http://www.cisco.com/en/US/tech/tk648/tk361/technologies_white_paper09186a00801afc76.shtml
Transit ACL Sections
In general, a transit ACL is composed of four sections.
Special-use address and anti-spoofing entries that deny illegitimate sources and packets with
source addresses that belong within your network from entering the network from an external
source NotE. RFC 1918 leavingcisco.com defines reserved address space that is not a valid
source address on the Internet. RFC 3330 leavingcisco.com defines special-use addresses that
might require filtering. RFC 2827 leavingcisco.com provides anti-spoofing guidelines.
Explicitly permitted return traffic for internal connections to the Internet
Explicitly permitted externally sourced traffic destined to protected internal addresses
Explicit deny statement NotE. Although all ACLs contain an implicit deny statement, Cisco
recommends use of an explicit deny statemen, for example, deny ip any any. On most platforms,
such statements maintain a count of the number of denied packets that can be displayed using the
show access-list command.


Leave a Reply