exam questions

Exam 200-301 All Questions

View all questions & answers for the 200-301 exam

Exam 200-301 topic 1 question 997 discussion

Actual exam question from Cisco's 200-301
Question #: 997
Topic #: 1
[All 200-301 Questions]



Refer to the exhibit. This ACL is configured to allow client access only to HTTP, HTTPS, and DNS services via UDP. The new administrator wants to add TCP access to the ONS service. Which configuration updates the ACL efficiently?

  • A. no ip access-list extended Services
    ip access-list extended Services
    30 permit tcp 10.0.0.0 0.255.255.255 host 198.51.100.11 eq domain
  • B. ip access-list extended Services
    35 permit tcp 10.0.0.0 0.255.255.255 host 198.51.100.11 eq domain
  • C. ip access-list extended Services
    permit tcp 10.0.0.0 0.255.255.255 host 198.51.100.11 eq domain
  • D. no ip access-list extended Services
    ip access-list extended Services
    permit udp 10.0.0.0 0.255.255.255 any eq 53
    permit tcp 10.0.0.0 0.255.255.255 host 198.51.100.11 eq domain deny ip any any log
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
gewe
Highly Voted 2 years, 2 months ago
its said add so option B would be better
upvoted 10 times
oatmealturkey
2 years, 2 months ago
And is most efficient
upvoted 3 times
...
Brocolee
1 year, 10 months ago
Just curious, It said "by gewe" which mean you are the contributor of this questions right? So who gave the answer above? you or admin? I find it strange since I saw few questions listed that you are the contributor only to find that you give different answer in the comment... I mean, I don't blame you if you change your answer after further research.
upvoted 1 times
[Removed]
1 year, 5 months ago
The "by x" is just the person who started the discussion.
upvoted 1 times
...
...
...
Stichy007
Highly Voted 2 years, 2 months ago
Selected Answer: B
Answer is B. They really did a horrible job with some of these questions.
upvoted 6 times
...
Joshua25
Most Recent 6 months ago
Since when has Cisco been providing ONS service?! No wonder the quality of their questions is going down down all the way down...
upvoted 1 times
...
Rich_rude
1 year ago
It’s b it’s the only one with a line configuration
upvoted 1 times
...
[Removed]
1 year, 1 month ago
Selected Answer: B
it´s B
upvoted 1 times
...
AbdullahMohammad251
1 year, 4 months ago
Selected Answer: B
The question asks us to allow access only to HTTP, HTTPS, and DNS via both TCP and UDP: A is incorrect, it will only permit client access to DNS services via TCP (but we need DNS via UDP, HTTP, and HTTPS services) B is correct (the permit statement must be placed before the "deny ip any any" statement to allow DNS services via TCP C is incorrect (without specifying the sequence number, the entry will be placed last in the access list with a sequence number of 50. This makes it inactive and unreachable because a "deny ip any any" entry in the ACL comes before it in order and will be executed first.) D allows access only to DNS services (without allowing access to HTTP, HTTPS )
upvoted 1 times
...
[Removed]
1 year, 10 months ago
What is the ONS service??
upvoted 2 times
Shri_Fcb10
1 year, 9 months ago
Its DNS, typo error. God knows when they will fix it
upvoted 5 times
...
...
Simon_1103
2 years ago
Selected Answer: B
Option A will delete the ACL completely and create a new one with only one entry, which is not efficient. Option C is missing the line number and will insert the new entry at the beginning of the list, which may affect the order of other rules. Option D allows access to both UDP and TCP DNS services and adds an unnecessary entry at the end that denies all other IP traffic. This option is not efficient and may cause issues. Option B adds a new entry to the existing ACL with the appropriate line number and rule syntax, allowing TCP access to the ONS service while keeping the existing rules for HTTP, HTTPS, and DNS services. This option is the most efficient and effective way to update the ACL.
upvoted 4 times
...
rx78_2
2 years, 1 month ago
Selected Answer: B
B is the correct answer. D would deny HTTP as well as HTTPS connection
upvoted 4 times
...
lucantonelli93
2 years, 2 months ago
Selected Answer: B
For me it's B
upvoted 1 times
...
Rynurr
2 years, 2 months ago
Selected Answer: B
Should be "B"
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago