PrepAway - Latest Free Exam Questions & Answers

Which of the following rules is necessary to support this implementation?

A system administrator is implementing a firewall ACL to block specific communication to and from
a predefined list of IP addresses, while allowing all other communication. Which of the following
rules is necessary to support this implementation?

PrepAway - Latest Free Exam Questions & Answers

A.
Implicit allow as the last rule

B.
Implicit allow as the first rule

C.
Implicit deny as the first rule

D.
Implicit deny as the last rule

Explanation:

9 Comments on “Which of the following rules is necessary to support this implementation?

  1. Paul S says:

    What makes this a really stupid question is that implicit deny is never a rule. It is implicit, meaning that it is not written and exists at the end of the existing rule set. For this question, implicit deny does nothing. Implicit deny as the first rule means no communications. Implicit deny as the last rule means that unless you have explicit allow statements, everything is denied. The problem is “while allowing all other communications”. The correct answer would be creating a list of blocked IP at the top of the ACL and then creating an explicit allow at the end.
    Oh–just to add to my irritation, firewalls have rules. Routers have ACLS.




    0



    0
  2. Clindamycin says:

    Implicit deny indicates that unless something (such as traffic on a network) is explicitly allowed, it is denied. It isn’t used to deny all traffic, but instead used to deny all traffic that isn’t explicitly granted or allowed.

    But in this question it’s exactly the opposite
    they want to block some eye IP’s and allow other IPs
    that means this should be allow at the end of the rules after specifying the IP’s that should be blocked

    So its A
    By the way, the rule called Permit All NOT implicit Allow




    0



    0

Leave a Reply