exam questions

Exam 300-410 All Questions

View all questions & answers for the 300-410 exam

Exam 300-410 topic 1 question 250 discussion

Actual exam question from Cisco's 300-410
Question #: 250
Topic #: 1
[All 300-410 Questions]


Refer to the exhibit. A network administrator must block ping from user 3 to the App Server only. An inbound standard access list is applied to R1 interface G0/0 to block ping. The network administrator was notified that user 3 cannot even ping user 9 anymore. Where must the access list be applied in the outgoing direction to resolve the issue?

  • A. R2 interface G0/0
  • B. SW1 interface G1/10
  • C. R2 interface G1/0
  • D. SW1 interface G2/21
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Patrick1234
Highly Voted 2 years, 3 months ago
It's a standard ACL. Standard ACL's should always be installed as close to the DESTINATION as possible. Read this: Standard ACLs should be located as close to the destination as possible. If a standard ACL were placed at the source of the traffic, the “permit” or “deny” would occur based on the given source address, regardless of the traffic destination. So the only right answer in this question is B: SW1 interface G1/10.
upvoted 13 times
bk989
9 months, 1 week ago
To add to this. If a standard ACL were placed at the source of the traffic, the “permit” or “deny” would occur based on the given source address, regardless of the traffic destination. What this is saying is that we may block more traffic then intended. If we use extended ACL we place it close to the source as we can define ports, and the packet doesn't have to travel through the network.
upvoted 2 times
bk989
8 months, 1 week ago
To add to this: The reason we place standard access lists close to destination is to save resources. Extended ACL's can be more precise; in example ports, match header information, protocols etc, so we can place close to source.
upvoted 2 times
...
...
...
XBfoundX
Most Recent 8 months, 1 week ago
For me is C cause the interface is connected to the server I think that B is not a good answer, if you have an SVI is another story, or for example several switches connected to that port. In this example they are talking about the interface connected to the server, for sure you are not gonna configure an IP to that port but a VLAN, the routed interface is the router interface.
upvoted 1 times
...
Fenix7
8 months, 4 weeks ago
It's definitely B.
upvoted 1 times
...
[Removed]
9 months, 2 weeks ago
Selected Answer: B
B is correct standard ACL = closest to the destination extended ACL = closest to the source
upvoted 3 times
...
Commando1664
1 year ago
Using a standard ACL to block icmp doesn't make sense...it can't be done. Stupid quesiton
upvoted 2 times
...
Chiaretta
1 year, 1 month ago
Selected Answer: C
An ACL can be applied on L3 equipment, switch is a L2 equipment, take the CCNA first.
upvoted 1 times
...
louisvuitton12
1 year, 5 months ago
Selected Answer: B
Closest to the destination
upvoted 3 times
...
jansan55
1 year, 6 months ago
Selected Answer: C
A standard ACL can only deny the IP address of User 3, not only just ping. So the first step to remove that statndard ACL from R1 Gi0/0. We are not sure that SW1 is a an L3 type, so i rule out any SW1 related answers.
upvoted 1 times
...
Muste
1 year, 8 months ago
Selected Answer: B
provided answer is correct standard access-list should be placed as close to the destination as possible
upvoted 3 times
...
inteldarvid
1 year, 9 months ago
Selected Answer: D
Correct 100% "D": team sorry for my earlier reply. The correct answer is "D", it is true, it is the closest to the destination, but it cannot be added (outside or inside) in the swi (g1/10), because the traffic that I want to deny comes from the source and enters the switch through the G2/21, (I tried all the options in my lab) and the correct answer is "D": SW1 interface G2/21
upvoted 1 times
Brand
1 year, 8 months ago
"Where must the access list be applied in the outgoing direction" It says "outgoing direction" how would you block a traffic sourced by the user3 by applying the ACL to the return traffic back from server?
upvoted 2 times
...
...
inteldarvid
1 year, 9 months ago
Selected Answer: B
correct
upvoted 2 times
...
pepgua
1 year, 10 months ago
Selected Answer: B
By applying the access list in the outgoing direction on the interface facing the App Server, you can ensure that ping traffic from user 3 to other destinations, including user 9, is not affected. Only the ping traffic specifically destined for the App Server will be blocked in the outgoing direction on SW1.
upvoted 2 times
...
Typovy
2 years ago
Selected Answer: B
If vlan's are terminated on switch and then routed to router answer is B. If vlans are terminated on router via .q subinterfaces then answer is C. Switch icon indicates that this is L3 switch so most propably vlans are ended there on SVI so answet is propably B :)
upvoted 2 times
...
Jerome_2046
2 years ago
Selected Answer: B
Standard ACL's should always be installed as close to the DESTINATION as possible
upvoted 2 times
...
anaisa_goncalves
2 years, 5 months ago
Hi, Why not answer D. Since, it's a standard ACL that has to be applied in outgoing interface. Because if we apply in R2 G1/0, we will not let that User 3 ping SW1, and the question says that it cannot ping ONLY App Server. And this is assuming that SW1 is a layer 3 switch.
upvoted 1 times
anaisa_goncalves
2 years, 5 months ago
Correction I meant option B SW1 Interface Gi 1/10 as correct answer
upvoted 2 times
...
...
VergilP
2 years, 5 months ago
I am confuse of question is ask about.. so question is ask ..delete R1 G0/0 ACL and place the ACL "somewhere" then make User3 can ping User9 but can not reach app server? Is my understanding correct?
upvoted 1 times
...
Remsync
2 years, 6 months ago
Selected Answer: C
If you're usign an ACL to block ping, that means you're using an extended ACL, and it's recommended to place de ACL closest to the source, so the given answer is correct.
upvoted 1 times
Remsync
2 years, 6 months ago
My bad, it says standard ACL. Given answer is correct.
upvoted 2 times
...
Remsync
2 years, 6 months ago
I mean, C is correct, not the given answer.
upvoted 1 times
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago