Q11Security
A client with IP address `209.165.201.25` must reach a web server at `209.165.200.225` on port `80`. To permit this traffic, an engineer must add a statement to an access control list applied inbound on the port connected to the web server. Which statement permits this traffic?
← → navigate · a answer
Community votes
Discussion · 21
71
Inbound direction - C
32
Correct Option is B.
9
The correct answer here is C:
Remember that the the interface with the ACL applied is the server interface.
so the flow at first will be client ==> server
Here there is not any acl applied inbound and outbound.
Then the traffic flow must come back like this:
server ==> client
In the server port the acl is applied, so in this case because it is return traffic the source ip address and tcp port will be of the server and the destination will be the client.
So the statement of the ACL is:
permit tcp host 209.165.200.225 eq 80 host 209.165.201.25
(permit the traffic sourced by the server to reach the destination)
So the answer is for sure C
4
"on the port connecting to the web server"
-> C
C 3
Selected Answer: C
NOTE: applied in the inbound direction on the port that connects to the web server.
C 3
Selected Answer: C
Its C, inbound direction on the port connecting the host
regards
C 3
Selected Answer: C
the inbound traffic coming from the port connected to the server will include the server's IP address therefore the ACL statement has to use the source IP as the server's IP. The client will reach the server using TCP 80 as the destination so the return traffic sourced by the server will have port 80 as the source TCP. Which in this case I'd go with C.
3
I don't care what interface or direction you try to apply the ACL for answer D, it isn't going to work.
Why? Because port 80 can only be associated with the webserver host IP.
Answer D assumes that port 80 would be associated with the client IP, which would never be the case.
Not in the real world anyway.
C 2
Selected Answer: C
Inbound on the server side >> C
2
C. permit tcp host 209.165.200.225 eq 80 host 209.165.201.25 Most Voted
permit tcp host ---- THE SOURCE - THE PORT --- THE DESTINATION.
The exact same question - answer is available at question 272
2
Transport Control Protocol (TCP)
access-list access-list-number [dynamic dynamic-name [timeout minutes]]
{deny | permit} tcp source source-wildcard [operator [port]] destination destination-wildcard [operator [port]]
[established] [precedence precedence] [tos tos] [log | log-input]
[time-range time-range-name][fragments]
C 2
Selected Answer: C
C is the correct answer. Because it's traffic INcoming on the port FROM the Webserver, the ACL would be configured with that same source/destination orientation, as follows:
permit tcp host <FROM_WEBSERVER_IP> eq 80 host <TO_CLIENT_IP>
we put the "eq 80" with the webserver since that's the port it listens on, and that's the port it will use to send the data back to the client.
Admins, please fix the correct answer, it should be C but is showing as D.
2
So, in this scenario:
The destination port has to be equal to 80 in the initial request from the client to the server.
The source port has to be equal to 80 in the response from the server to the client.
Here's a summary:
Client (host) -> Server (HTTP):
Source port (random): >1024
Destination port: 80
Server (HTTP) -> Client (host):
Source port: 80
Destination port (matches client's source port): >1024.
Therefore, answer C is correct, not D.
D is wrong because source TCP port must be 80 in the server's response, not destination port.
B 1
Selected Answer: B
i asked chatgpt and it gave this answer.
permit tcp host 209.165.201.25 host 209.165.200.225 eq 80
so, according to chatgpt, it is B
1
no, this will only work if the ACL is applied inbound for the port facing the client.
the question is "inbound port facing web server"
1
it says "inbound".
1
Correct answer is B.
Option C is the wrong syntax for an extended access-list, which is based on the source and destination IPs.
1
My bad. it is actually source and destination port that we are looking at here, so C has the right syntax for source and destination port.
1
D the ACL has to be applied in the inbound direction of the R
C 1
Selected Answer: C
CISCO keeps amusing me. english is a very powerful language, but when it is used by someone who doesn't know it, it can get very confusing. there is a simple way to say this, yet someone picked this obscure wording and confused people who understand this problem very well but still can give an incorrect answer , let me ask you a simple question, when there is a connection , we have two ports ( otherwise there wouldn't be a connection, right ? ) , each one receives traffic in the inbound direction , server port when it receives a request, client port when it receives a response , which port is the port connecting to the web server ?
B 1
Selected Answer: B
B is the correct answer.
Even Chat GPT confirms it.