Cisco CCNA (200-301)Security FundamentalsMedium

An administrator is deploying a standard numbered ACL to block traffic from a specific host, 192.168.5.10, from reaching only one file server (172.16.30.100) on a different subnet, while allowing the host to reach every other destination normally. Where should this ACL be applied for best results?

  1. AInbound on the interface closest to the source host
  2. BInbound on the host's default gateway interface facing the LAN
  3. COutbound on every router along the path
  4. DInbound on the interface closest to the destination server
Show answer & explanation

Correct answer: D. Inbound on the interface closest to the destination server

Standard ACLs filter based only on source IP address, with no visibility into the destination. If applied near the source, all traffic from that host to any destination would be blocked. Placing it as close to the destination as possible ensures only traffic to that specific server is affected.

Why the other options are wrong

  • A. This would block the host from reaching all destinations, not just the one server.
  • B. This is effectively the same as placing it near the source, which over-blocks traffic.
  • C. Unnecessary and inefficient; standard ACLs should be placed close to the destination, not everywhere.

Standard ACL Placement

Standard ACLs filter only by source address, so they should be placed as close to the destination as possible to avoid unintentionally blocking traffic to other destinations.

  • Standard ACLs use only source IP for matching
  • Placing near destination limits collateral blocking
  • Extended ACLs, which match source and destination, are placed close to the source

Memory trick: Standard = near destination (Same target); Extended = near source (Everything specific).

More Security Fundamentals questions