CCNA Network Services and Security Practice Question
A network administrator at a small branch office needs to allow a wireless guest user to reach an internal web server at 10.5.5.20 using a browser, while preventing that guest from reaching any other internal subnet. The guest is connected to VLAN 50 and the web server is in VLAN 10. Which type of ACL should be applied on the router between VLANs to meet this requirement?
⚠ Common exam trap
The trap here is assuming that a standard ACL applied close to the source is sufficient, when destination-based filtering requires an extended ACL.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Extended numbered ACL 100 applied inbound on the VLAN 50 interface
An extended ACL is required because the requirement involves matching both source and destination addresses, and the protocol/port for HTTP. Applying it inbound on the guest VLAN interface filters traffic as it enters the router, before it can reach other internal subnets. A standard ACL cannot match destination addresses, and the other placements either use the wrong ACL type or the wrong direction.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Extended numbered ACL 100 applied inbound on the VLAN 50 interface
Why this is correct
An extended ACL can match source IP, destination IP, protocol, and port. Applied inbound on VLAN 50, it can permit TCP traffic from the guest subnet to 10.5.5.20 port 80 while denying all other traffic, exactly meeting the requirement to allow only the web server and block other internal subnets.
- ✗
Standard numbered ACL 10 applied inbound on the VLAN 50 interface
Why it's wrong here
A standard ACL can only match on source IP address, so it cannot specifically permit traffic to 10.5.5.20 while denying other destinations. If applied inbound on VLAN 50, it would either permit all destinations or deny all destinations based on the guest's source address, which does not meet the requirement to allow only the web server.
- ✗
Standard named ACL GUEST_IN applied outbound on the VLAN 10 interface
Why it's wrong here
A standard ACL matches only source addresses and cannot check the destination address 10.5.5.20. Applying it outbound on VLAN 10 would also affect all traffic leaving that VLAN, not just guest traffic, and would not selectively permit only the web server for the guest while denying other destinations.
- ✗
Extended named ACL GUEST_OUT applied outbound on the VLAN 50 interface
Why it's wrong here
Applying an extended ACL outbound on VLAN 50 would filter traffic leaving the guest VLAN, but the direction is wrong for traffic going from the guest to the web server. Traffic from the guest enters the router on VLAN 50, so an inbound ACL on VLAN 50 is the correct placement to filter it before routing.
Visual reference
Go deeper
Related to this question
Learn chapter
Troubleshoot: Port Security Violation
Key term
VLAN
A VLAN logically segments a physical network into isolated broadcast domains without requiring separate physical switches.
Key term
Subnet
A subnet is a logical subdivision of an IP network, created by partitioning a larger network address space using subnet masks.
About these practice questions
One of 1,450 original 200-301 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 200-301 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-301 exam.