Courseiva

CCNA Network Services and Security Practice Question

A network administrator at a small branch office needs to allow a wireless guest user to reach an internal web server at 10.5.5.20 using a browser, while preventing that guest from reaching any other internal subnet. The guest is connected to VLAN 50 and the web server is in VLAN 10. Which type of ACL should be applied on the router between VLANs to meet this requirement?

⚠ Common exam trap

The trap here is assuming that a standard ACL applied close to the source is sufficient, when destination-based filtering requires an extended ACL.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Extended numbered ACL 100 applied inbound on the VLAN 50 interface

An extended ACL is required because the requirement involves matching both source and destination addresses, and the protocol/port for HTTP. Applying it inbound on the guest VLAN interface filters traffic as it enters the router, before it can reach other internal subnets. A standard ACL cannot match destination addresses, and the other placements either use the wrong ACL type or the wrong direction.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Extended numbered ACL 100 applied inbound on the VLAN 50 interface

    Why this is correct

    An extended ACL can match source IP, destination IP, protocol, and port. Applied inbound on VLAN 50, it can permit TCP traffic from the guest subnet to 10.5.5.20 port 80 while denying all other traffic, exactly meeting the requirement to allow only the web server and block other internal subnets.

  • ✗

    Standard numbered ACL 10 applied inbound on the VLAN 50 interface

    Why it's wrong here

    A standard ACL can only match on source IP address, so it cannot specifically permit traffic to 10.5.5.20 while denying other destinations. If applied inbound on VLAN 50, it would either permit all destinations or deny all destinations based on the guest's source address, which does not meet the requirement to allow only the web server.

  • ✗

    Standard named ACL GUEST_IN applied outbound on the VLAN 10 interface

    Why it's wrong here

    A standard ACL matches only source addresses and cannot check the destination address 10.5.5.20. Applying it outbound on VLAN 10 would also affect all traffic leaving that VLAN, not just guest traffic, and would not selectively permit only the web server for the guest while denying other destinations.

  • ✗

    Extended named ACL GUEST_OUT applied outbound on the VLAN 50 interface

    Why it's wrong here

    Applying an extended ACL outbound on VLAN 50 would filter traffic leaving the guest VLAN, but the direction is wrong for traffic going from the guest to the web server. Traffic from the guest enters the router on VLAN 50, so an inbound ACL on VLAN 50 is the correct placement to filter it before routing.

Visual reference

Switch VLAN 10 Sales (192.168.10.0/24) PC-A PC-B VLAN 20 HR (192.168.20.0/24) PC-C PC-D Router VLANs isolate traffic — inter-VLAN routing requires a Layer 3 device

About these practice questions

One of 1,450 original 200-301 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 200-301 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-301 exam.