Refer to the exhibit. Employees on 192.168.11.0/24 work on critically sensitive information and are not allowed access off their network. What is the best ACL type and placement to use in this situation?

IT Exam Items RepositoryCategory: CCNARefer to the exhibit. Employees on 192.168.11.0/24 work on critically sensitive information and are not allowed access off their network. What is the best ACL type and placement to use in this situation?

Refer to the exhibit. Employees on 192.168.11.0/24 work on critically sensitive information and are not allowed access off their network. What is the best ACL type and placement to use in this situation?

  • standard ACL inbound on R1 vty lines
  • extended ACL inbound on R1 G0/0
  • standard ACL inbound on R1 G0/1
  • extended ACL inbound on R3 S0/0/1

Explanation: A standard ACL is the best choice here because the security policy requires filtering traffic based solely on the source IP address (the 192.168.11.0/24 network). Placing the ACL inbound on the R1 G0/1 interface is most efficient because it discards unauthorized packets immediately upon entering the router. This "close to the source" placement prevents unwanted traffic from consuming any routing resources or bandwidth on the rest of the network.

Related exam: CCNA 3 Final Exam Answers

Related exam: Modules 3 – 5: Network Security Exam