exam questions

Exam 350-401 All Questions

View all questions & answers for the 350-401 exam

Exam 350-401 topic 1 question 272 discussion

Actual exam question from Cisco's 350-401
Question #: 272
Topic #: 1
[All 350-401 Questions]


Refer to the exhibit. PC-1 must access the web server on port 8080. To allow this traffic, which statement must be added to an access control list that is applied on
SW2 port G0/0 in the inbound direction?

  • A. permit tcp host 172.16.0.2 host 192.168.0.5 eq 8080
  • B. permit tcp host 192.168.0.5 host 172.16.0.2 eq 8080
  • C. permit tcp host 192.168.0.5 eq 8080 host 172.16.0.2
  • D. permit tcp host 192.168.0.5 lt 8080 host 172.16.0.2
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Jclemente
Highly Voted 4 years, 1 month ago
The correct answer is C...
upvoted 27 times
...
netpeer
Highly Voted 4 years ago
Just noticed the G0/0 is towards the web server NOT the PC...Then is permit host 192.168.0.5 eq 8080 host 172.16.0.2
upvoted 16 times
Jh0nh
2 years, 6 months ago
Same here, looks like the G0/0 is the interface facing the PC but no, it is facing the SERVER, so the answer is C :)
upvoted 2 times
CCNPWILL
1 year, 6 months ago
Agreed. Its the traffic coming back from the initial connection. C is correct.
upvoted 1 times
...
...
...
AbdullahMohammad251
Most Recent 8 months, 1 week ago
Selected Answer: C
Option A would have been correct if we were filtering the outbound traffic exiting port G 0/0. Option B is incorrect because the web server is using port 8080, not PC1. PC1 will randomly choose a source port from the ephemeral range: 49152 and 65535. Option D is incorrect because we need to filter traffic coming from the web server on port 8080 ("lt 8080" will allow TCP connections coming from the server with a source port less than 8080).
upvoted 1 times
...
Zendahr
10 months, 2 weeks ago
Selected Answer: C
The correct answer is C...
upvoted 1 times
...
[Removed]
11 months, 2 weeks ago
Selected Answer: C
C is correct the question states "Inbound direction" which means that if the PC tried to connect to the server, the server should have the ability to reply. so in reality you should have 2 access-lists one for traffic from PC1 to the server and another one for traffic from the server to PC1. the question is asking you in a tricky way about the traffic from the server to the PC1 just by stating "Inbound"
upvoted 1 times
...
146b675
1 year, 3 months ago
They could have placed the port label on the right side. I thought it was for the cable facing the PC...
upvoted 1 times
...
Claudiu1
1 year, 5 months ago
Selected Answer: C
Be aware that G0/0 port is the one connected to the server. The catch here is that the ACE doesn't filter any ingress traffic from PC-1. It filters the inbound traffic from the webserver. So naturally, you need to permit the ingress traffic sourced at the web server.
upvoted 2 times
...
Chuckzero
1 year, 8 months ago
The correct answer is C. Since the rule is to be applied Inbound to SW2 Gi0/0, we need to invoke the rule guiding Source Port and Destination Port. <protocol> <source IP/source network> <source port> <destination IP/destination network> <destination port> Therefore, permit tcp host 192.168.0.5 eq 8080 host 172.16.0.2
upvoted 2 times
...
ihateciscoreally
1 year, 8 months ago
i hope whoever made this exhibit no longer works in cisco.
upvoted 11 times
Njavwa
1 year, 8 months ago
lol, its a bit tricky first thing i noticed was where int is facing
upvoted 1 times
...
...
Capt_23
1 year, 10 months ago
Answer is C. The ACL is put on the interface facing the web server that receives a request on port 8080 ---> the answer has source port 8080 and is the web-server as the direction of the ACL is input (from outside to the router).
upvoted 1 times
...
wr4net
1 year, 11 months ago
the obvious quick answer choice for most commonly seen deployments would be answer A. but since that is the only one with 172 as the source, there must be some trick going on! So after looking again, C it is, but this is not a typical ACL found almost anywhere and on a switch for that matter. dumb question for real life. also remember that ports can be applied to both source and dest, which means the port will follow each one. this rules out B as syntactically incorrect.
upvoted 1 times
...
Chiaretta
2 years ago
Selected Answer: C
This question would be correct if the equipment would be a router not a switch. In that case C is correct.
upvoted 2 times
...
dragonwise
2 years, 1 month ago
Selected Answer: A
Question says "PC-1 must access the web server on port 8080" So I'd go for A where PC-1 is the source and server is the destination
upvoted 1 times
mhizha
2 years ago
If your ACL is in an outbound direction on the G0/0 A would be fine, but in this case the ACL is in a inbound direction meaning that it will be looking at traffic from the server to the PC
upvoted 2 times
...
...
Dataset
2 years, 2 months ago
Selected Answer: C
Hi It is confuse the interfece name placement C is correct Regards!
upvoted 2 times
...
Sammy3637
2 years, 2 months ago
Selected Answer: C
Gig0/0 is facing the server
upvoted 2 times
...
rafaelinho88
2 years, 3 months ago
Selected Answer: C
The inbound direction of G0/0 of SW2 only filter traffic from Web Server to PC-1 so the source IP address and port is of the Web Server.
upvoted 2 times
...
StefanOT2
2 years, 3 months ago
Selected Answer: A
C will not prevent the PC from accessing port 8080 on the webserver. Only the answer is not allowed, AFTER the access did already happen. Terrible question, terrible graph, everything terrible. I go for A
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago