Q62Infrastructure Security
Refer to the exhibit. An engineer is attempting to block the route to `192.168.2.2` from the routing table by using the shown configuration. The route still appears in the routing table as an OSPF route. Which action blocks the route?
← → navigate · a answer
Community votes
Discussion · 18
17
Agree with B
B 14
Selected Answer: B
B is correct.
I dont know how to explain it well, but here it goes.
With the ACL you permit the network or host you want.
With Route-map it will process the match clause and do what you configured the route-map to do, either permit or deny the route.
In the question the route map is permitting the network 192.168.2.2 as it is permited to by the permit statement in the ACL.
If we change the route-map to deny, it will deny network 192.168.2.2 because again its permitted by the ACL to process it and do what the route-map is configured to do, which will deny it from showing in the routing table.
ACLs are configured with permit to have the networks or hosts be processed by the route-map.
config
ip access-list standard 1
permit host 192.168.2.2
(implicit deny any is added at the end of the ACL by default)
route-map RM-OSPF-DL deny 10
match ip address 1
This will process 192.168.2.2 due to the (ACL permit) statement and deny it (through the route-map deny) statement while all other traffic is allowed by the (ACL) implicit deny statement
hope that makes sense
B 7
Selected Answer: B
Tested in lab.
Answer A: permit in ACL and permit in route-map - 192.168.2.2 remain in the routing table.
Answer B: deny in ACL and permit in route-map will remove 192.168.2.2 from the routing table.
Answer C: permit in prefix-list and permit in route-map - 192.168.2.2 remain in the routing table.
Answer D: the sequence 10 already let the 192.168.2.2 remain in the routing table.
C 3
Selected Answer: C
C is the answer because Prefix-list goes with distribution-list not with access-list.
B 3
Selected Answer: B
I choose B
B 3
Selected Answer: B
B is it
B 3
Selected Answer: B
It is sure, B.
2
We use a prefix list as its name implies, to match a list of subnets. In this case we only want to deny just one subnet. Now also in the question it does not specify whether all other networks need to be denied. I go for B
B 2
Selected Answer: B
Confirmed now in PNET Lab.
Correct (B)
B 2
Selected Answer: B
I'm sure it's B
B 2
Selected Answer: B
answer is B
2
agree with B
B 2
Selected Answer: B
I agree with B
1
B is the correct answer
1
I labbed it and B is the correct one.
1
B is correct
1
Distribution-list matches a route-map, not an ACL...
B 1
Selected Answer: B
B is correct