CCNA – Access list Questions

April 29th, 2015

Note: If you are not sure about Access list, please read our Access List Tutorial.

Question 1


The standard access lists are ranged from 1 to 99 and from 1300 to 1999 so only access list 50 is a standard access list.

Question 2


We see the difference of the four networks,,, and is at the third octet (146, 147, 148, 149) so we need to convert them into binary numbers (the different bit is underlined):

146 = 10010010
147 = 10010011

We see only the last bit is different so a wildcard mask can be created to cover them with XOR operation:

Wildcard mask = 10010010 XOR 10010011 = 00000001 = 1

Note: The XOR operation here means “if two compared bits are same, write 0; if two compared bits are different, write 1”. Remember, for the wildcard mask, 1 means “I DON’T CARE”, and 0 means “I CARE”

Therefore the full wildcard mask should be The last octet is “255” to cover all hosts in /24 range. And the “access-list 10 permit ip” can cover networks,

Do the same for two remaining networks:

148 = 10010100
149 = 10010101

So the “access-list 10 permit ip” can cover these two networks.


If we want to use only one command in the access-list, we can compare all four networks at the same time:

146 = 10010010
147 = 10010011
148 = 10010100
149 = 10010101

-> Wildcard mask = 00000011 = 3

Therefore we can use one command “access-list 10 permit ip” to cover all four networks.

Question 3

Question 4

Question 5


An access-list will be checked from the first to last statement. If a statement is matched then the check will finish immediately. A rule of thumb when creating an access-list is writing more specific matches first. So for this question we need to:

+ Permit hosts & (first & last IP of subnet
+ Deny other hosts in subnet
+ Permit anyone else

Remember another rule of thumb: the “permit/deny anyone else” statement is always put at the end of the access-list because it will be matched surely and the check will finish immediately (so any statements under this statement cannot be checked -> they are useless). Therefore in this case, the “permit any” statement will surely be at the end of the access-list.

We cannot place statement B: “deny” before statement A: “permit” and statement C: “permit” because any IP that matches statement A & C will surely match statement B and the check will finish immediately -> statements A & C are never been matched. Therefore statements A & C must be placed on top of statement B.

Question 6


We can have only 1 access list per protocol, per direction and per interface. It means:

+ We can not have 2 inbound access lists on an interface
+ We can have 1 inbound and 1 outbound access list on an interface

Question 7


We can use a dynamic access list to authenticate a remote user with a specific username and password. The authentication process is done by the router or a central access server such as a TACACS+ or RADIUS server. The configuration of dynamic ACL can be read here: http://www.cisco.com/en/US/tech/tk583/tk822/technologies_tech_note09186a0080094524.shtml

    Passed my CCNA exam today (18th Mar)… Q2, Q4 and Q7 in exam

    can be a network with a block size of 1 means with /24 prefix…

  14. gidz
    May 2nd, 2015

    I cant understand question 2
    If i try to summarize the networks 146-149, i get the block size of 1, i cant figure out why are you guys trying to summarize network and together and separate them from and…

  15. metacortex
    May 4th, 2015

    @gidz – don’t summarize. Because of the increment when you have a wildcard mask of you’re including 146-147 and 148-149 in the ACL.
    For example: (subnet mask / wildcard mask – first host – last host – broadcast address

  16. gidz
    May 4th, 2015

    but and was stated as a network, ryt?

    passed today. Thanks a lot to 9tut. eigrp trouble shooting lab and both ACL labs came.

    June 4th, 2015

    can anyone help me to solve Q2??

  21. Anonymous
    June 5th, 2015

    @bhabs – Q2 – ACLs use wildcard masks not subnet
    Widcard masks are the inverse of a subnet mask

    The access list could be written as:

    access-list 10 pemit ip
    access-list 10 pemit ip
    access-list 10 pemit ip
    access-list 10 pemit ip


    access-list 10 pemit ip
    access-list 10 pemit ip


    access-list 10 pemit ip

    Only the first summarised options were given so
    thats the answer.

    For anyone thats confused on the network addresses and being included as
    a host in the ACL, it wont make a difference
    because the ACL includes all hosts within those
    networks and being network addresses no host can
    have those network addresses to be worried about.

    The ACL will assume that
    is the network and is the broadcast
    which they would be even if you were to do each ACL
    seperately. Same applies to the ACL

  24. Anonymous
    June 6th, 2015

    @H.K – Q5 – ACLs must be in order.

    ACLs are checked off the list in order from top to bottom. Once a statement is met that refers to the host that ACL is applied and no further checks down the list are done.

    In Q5 above, the first ACL is permit any which would apply to all hosts trying to gain access and to anything they wish to access. Those who are supposed to be denied gain access because the first ACL permits everyone to everything.

    Therfore, the permit any statement should be the last statement so that hosts trying to gain access pass all other ACLs first.

  29. Hussain
    June 22nd, 2015

    Hi everyone,
    Can anyone please explain question no 2

  30. Elena
    June 22nd, 2015

    @ Imran & Hussain, for Q2 , you need to pay attention to the wildcard mask:

    A. access-list 10 permit ip -> the wildcard mask it allows the very next IP add network, meaning, to have the same permission as

    C. access-list 10 permit ip -> same as above, allowing the very next IP add network in the sequence, meaning, to have the same permission as

    the rest of the answers are wrong because either the wildcard mask is wrong , either there is no 2nd command to match the 1st

  31. Questions Today
    June 24th, 2015

    Q3,Q7 was in exam. Praise The Lord and thnx 9tut passed on 24th june 986/1000.
    Some new questions to be observed:
    What will happen if a private IP address is assigned to a public interface connected to an ISP?
    A. Addresses in a private range will be not be routed on the Internet backbone.
    B. Only the ISP router will have the capability to access the public network.
    C. The NAT process will be used to translate this address to a valid IP address.
    D. A conflict of IP addresses happens, because other public routers can use the same range.
    Answer: A
    What are three values that must be the same within a sequence of packets for Netflow to consider
    them a network flow? (Choose three.)
    A. source IP address
    B. source MAC address
    C. egress interface
    D. ingress interface
    E. destination IP address
    F. IP next-hop
    Answer: A,D,E

  39. 9tut
    July 12th, 2015

    @all: We had to move all the questions and answers out of 9tut. We can only keep the explanation. You can download the questions and answers at: https://mega.co.nz/#!wt9kVCjL!vvp79FTtjsqfpCgq0uTOTKlE6_qsLY6C_m163sNGs_s

