Cisco CCNA (200-301)Security FundamentalsEasy

Which extended ACL statement correctly permits only HTTPS traffic from any source to the server at 10.10.20.50?

  1. Aaccess-list 110 permit tcp host 10.10.20.50 any eq 443
  2. Baccess-list 110 permit ip any host 10.10.20.50 eq 443
  3. Caccess-list 110 permit tcp any 10.10.20.50 0.0.0.0 eq 80
  4. Daccess-list 110 permit tcp any host 10.10.20.50 eq 443
Show answer & explanation

Correct answer: D. access-list 110 permit tcp any host 10.10.20.50 eq 443

The correct syntax is 'permit tcp any host 10.10.20.50 eq 443', matching any source, the specific destination host, and TCP port 443 (HTTPS). Option B reverses source and destination, option C uses the 'ip' protocol which doesn't support port filtering, and option D uses port 80 (HTTP) instead of 443.

Why the other options are wrong

  • A. This reverses source and destination, meaning the server is treated as the source.
  • B. The 'ip' keyword does not support port numbers, so 'eq 443' would be invalid/ignored.
  • C. Port 80 is HTTP, not HTTPS, so this does not meet the requirement.

Extended ACL Syntax

Extended ACLs filter based on protocol, source, destination, and port number using the syntax: access-list <100-199> permit/deny protocol source destination [operator port].

  • Port matching requires tcp or udp, not ip
  • 'eq 443' matches HTTPS traffic
  • Source is listed before destination in the syntax

Memory trick: Protocol-Source-Destination-Port, like mailing an envelope in order.

More Security Fundamentals questions