Cisco CCNA (200-301)Security FundamentalsHard

A switch's running configuration shows the following access list applied inbound on interface GigabitEthernet0/1: access-list 110 deny tcp 192.168.5.0 0.0.0.255 any eq 23 access-list 110 permit ip any any A host at 192.168.5.10 attempts an SSH session (TCP port 22) to a remote server. What is the result?

  1. AThe SSH session is permitted because it does not match the deny statement's port 23 condition
  2. BThe SSH session is denied because the source subnet matches the first line
  3. CThe SSH session is denied because there is no explicit permit for port 22
  4. DThe SSH session is denied due to the implicit deny at the end of the ACL
Show answer & explanation

Correct answer: A. The SSH session is permitted because it does not match the deny statement's port 23 condition

The first line only denies TCP traffic from 192.168.5.0/24 destined to port 23 (Telnet). SSH uses port 22, so it does not match the deny line; it falls through to the second line, 'permit ip any any', which allows it.

Why the other options are wrong

  • B. The deny line only applies to port 23 (Telnet), not port 22 (SSH).
  • C. An explicit permit is not needed for port 22 because 'permit ip any any' covers all remaining traffic.
  • D. The implicit deny never triggers here because the second explicit line permits all remaining IP traffic.

ACL Line-by-Line Evaluation

Cisco ACLs are processed top-down; the first matching line determines the action, and remaining lines (including implicit deny) are only evaluated if no prior match occurs.

  • Match is based on protocol, source/destination, and port together
  • A deny for one specific port does not affect other ports/protocols
  • Explicit 'permit ip any any' catches everything not explicitly denied above it

Memory trick: First Match Wins, then Move On

More Security Fundamentals questions