PracticeLabs
Week 7Section quizRequired8 questions~10 min

ACLs & Device Hardening

Covers Lesson 1 and Lesson 2

Checks that you can choose, write, and place an ACL correctly, and that you can secure the device's own management plane rather than only the traffic passing through it.

Topics covered

  • Standard versus extended, and placement
  • Wildcard masks and the host/any shorthands
  • First match wins and the implicit deny
  • The SSH prerequisite chain
  • Password hardening and AAA fallback

Every question here is answerable from the first-party notes of the lessons above. You commit to an answer before you see whether it was right.

This quiz is a Week 7 milestone in its own right. Passing it does not change the completion state of any individual lesson, and you do not need it to finish the lessons it covers.

Section quiz

ACLs & Device Hardening

8 questions covering Lesson 1 and Lesson 2. Answer each one before you see whether you were right.

Question 1 of 8

1. You must stop one subnet reaching one specific server, leaving all its other traffic untouched. Which ACL type, and placed where?
2. Why is a standard ACL placed near the destination rather than near the source?
3. Which single address-and-wildcard pair matches every address in 172.16.8.0/22?
4. An ACL has permit 10.10.10.0 0.0.0.255 as line 10 and deny host 10.10.10.10 as line 20. What happens to traffic from 10.10.10.10?
5. An ACL contains only permit statements and is applied to an interface. What happens to traffic matching none of them?
6. You set transport input ssh and a VTY line password, then try to SSH in and are refused. What is missing?
7. What does service password-encryption actually provide?
8. Your login method is group tacacs+ only, and the TACACS+ server becomes unreachable. What happens, and what prevents it?