Cisco CCNA (200-301)Security FundamentalsEasy
A router has an access list applied inbound on an interface. The ACL contains only two explicit entries that both deny specific hosts. No other statements are configured. What happens to traffic from a host not matching either deny statement?
- AThe traffic is logged but still forwarded
- BThe traffic is permitted because only deny statements exist
- CThe traffic is dropped due to the implicit deny at the end of the ACL
- DThe router forwards the traffic without evaluating the ACL further
Show answer & explanationAnswer & explanation
Correct answer: C. The traffic is dropped due to the implicit deny at the end of the ACL
Every Cisco ACL ends with an implicit 'deny any' even though it is not visible in the configuration. Because no permit statement exists, all traffic not explicitly matched by the deny entries falls through to the implicit deny and is dropped.
Why the other options are wrong
- A. Logging requires the 'log' keyword and does not change the deny action.
- B. Incorrect: lack of a permit statement means traffic is denied, not permitted.
- D. ACLs always evaluate every packet against each line in order.
Implicit Deny
Every Cisco ACL has an unwritten 'deny any' statement at the end, causing any unmatched traffic to be dropped.
- Not shown in running-config
- Applies to standard and extended ACLs
- At least one permit statement is needed to allow any traffic
Memory trick: No match? No mercy — implicit deny drops it.