ETExamTower
Q5Secure Network Access, Visibility, and Enforcement

Refer to the exhibit. What is the outcome of this configuration?

Question exhibit
← → navigate · a answer
Community votes
D
100% (3)
A
0% (0)
B
0% (0)
C
0% (0)
Discussion · 16
14
The answer is definitely D. The ACLs match 192.168.100.0 to 192.168.100.255 and 172.16.0.0 to 172.16.255.255. The DMZ and inside network are within those ranges.
D 7
Selected Answer: D Traffic from both the inside and DMZ networks gets redirected. Inside networks are 192.168.100.0/24 and 172.16.0.0/16 DMZ network is 172.16.10.0/24 The redirect acl is permitting 192.168.100.0/24 and 172.16.0.0/16 (which also includes 172.16.10.0/24 --> traffic from DMZ networks)
6
Forget what was said, the answer is D
4
The access-list also matches the DMZ network 172.16.10.0, so D is correct
4
D is correct. Answer D does not say that every network from inside and DMZ is redirected, only that some traffic is redirected.
3
Answer is D 192.168.100.0 255.255.255.0 is directly connected, inside 172.16.10.0 255.255.255.0 is directly connected, dmz Both ACLs do apply to these networks.
3
10.10.10.0/24 (to DMZ) isn't in the access-list. So the answer is only B.
2
answer is B If you look at the 172.16.10.0/24 for DMZ, it does not match the access list 172.16.0.0/16
2
Yes, it should be D
2
The correct answer would be: traffic from inside networks and traffic from DMZ DIRECTLY CONNECTED network are redirected. Terrible question, since both B and D can be considered correct answers.
2
yes, to this
1
Is it D? I'm not 100% sure. Couldn't it maybe be B?
1
What about the last static route 10.10.10.0/24, part of the dmz? The inside network, along with part of the dmz, falls in those ranges.
1
172.16.10.0 matches 172.16.0.0/16... 172.16.0.0 255.255.0.0 has range of 172.16.0.0 - 172.16.255.255
D 1
Selected Answer: D My answer is D
1
I know this is late, but don't let this throw you off, since the /24 is part of the /16 172.16.10.0/24 is part of 172.16.0.0/16