CompTIA Network+ (N10-009)Network SecurityEasy
A technician configures a new router ACL that permits only HTTP and HTTPS traffic to a web server. After applying the ACL to the interface, all other traffic types are automatically blocked even though no explicit deny statement was written for them. Which concept explains this behavior?
- ASplit horizon
- BPort mirroring
- CImplicit deny
- DSpanning Tree Protocol
Show answer & explanationAnswer & explanation
Correct answer: C. Implicit deny
Every ACL ends with an unwritten, implicit 'deny all' rule, so any traffic not explicitly matched by a permit statement is automatically dropped. This is why administrators must explicitly permit needed traffic before the list ends.
Why the other options are wrong
- A. Split horizon is a routing loop-prevention technique, unrelated to ACLs.
- B. Port mirroring copies traffic for monitoring, not filtering.
- D. STP prevents Layer 2 loops, not packet filtering.
Implicit Deny
The default rule at the end of every ACL that blocks all traffic not explicitly permitted by a preceding rule.
- ACLs are processed top-down, first match wins
- If no rule matches, the implicit deny drops the packet
- Administrators must add explicit permit statements for needed traffic
Memory trick: No match? No pass—the gate stays shut by default.