CCNA Network Services and Security Practice Question
As a general rule, where should an extended ACL be placed?
⚠ Common exam trap
Remember that extended ACLs should be placed near the source, not the destination or core, to effectively manage traffic.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
As close to the source as practical
Extended ACLs are commonly placed near the source to stop unwanted traffic earlier and conserve bandwidth and device resources.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
As close to the source as practical
Why this is correct
Placing an extended ACL as close to the source as practical is the standard rule because extended ACLs can match both source and destination addresses, ports, and protocols. By filtering at the ingress point near the source, you prevent unwanted traffic from consuming bandwidth and processing resources on intermediate routers and links. This early filtering also reduces the risk of the traffic causing harm deeper inside the network, making the policy more efficient and effective.
- ✗
As close to the destination as possible in all cases
Why it's wrong here
The guidance to place an ACL close to the destination is normally reserved for standard ACLs, which can only filter on source addresses. A standard ACL near the source would accidentally block all traffic from that source, regardless of destination; placing it near the destination lets you permit or deny based on the destination's location. For extended ACLs, however, this would let unwanted traffic traverse the network unnecessarily, wasting bandwidth and potentially triggering security issues before being denied at the destination.
When this WOULD be correct
In a scenario where the question specifies that the network is highly segmented and traffic must be controlled at the destination for compliance reasons, placing an extended ACL close to the destination might be the best approach to enforce specific access policies for that segment.
- ✗
Only on the default gateway
Why it's wrong here
Default gateway placement is insufficient because extended ACLs are not restricted to the gateway's interface and the gateway may not see all internal traffic. If two hosts on the same VLAN or same subnet communicate directly, that traffic never reaches the default gateway, so ACLs placed only there would miss those flows. Additionally, the correct placement is determined by the packet's source and the filtering goal, not by a router's role as a default gateway in the topology.
When this WOULD be correct
In a scenario where a question specifies that all traffic must be filtered at the default gateway due to a specific network design or security policy, stating that extended ACLs should only be on the default gateway could be correct. For example, if the question indicates that the network is small and all traffic must pass through the gateway, this option would apply.
- ✗
Only on WAN interfaces
Why it's wrong here
Limiting extended ACL placement to WAN interfaces is too restrictive and ignores the key principle of source proximity. WAN interfaces are commonly used for edge filtering, but extended ACLs can be applied to LAN interfaces, trunk interfaces, or any interface where the traffic enters the network. The real objective is to stop unwanted packets as early as possible, which often means placing the ACL on an interface closer to the source, regardless of whether that interface is a WAN link.
When this WOULD be correct
In a scenario where the exam question specifies that the network design requires strict control over traffic entering and leaving a WAN connection, placing an extended ACL only on WAN interfaces could be the correct answer. This would apply in a situation where all traffic must be filtered at the edge of the network for security compliance.
Option-by-option analysis
Why each answer is right or wrong
Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The 200-301 exam frequently reuses these exact scenarios with slightly different constraints.
✓As close to the source as practicalCorrect answer▾
Why this is correct
Placing an extended ACL as close to the source as practical is the standard rule because extended ACLs can match both source and destination addresses, ports, and protocols. By filtering at the ingress point near the source, you prevent unwanted traffic from consuming bandwidth and processing resources on intermediate routers and links. This early filtering also reduces the risk of the traffic causing harm deeper inside the network, making the policy more efficient and effective.
✗As close to the destination as possible in all casesWrong answer — click to see why▾
Why this is wrong here
Placing an extended ACL as close to the destination can lead to unnecessary traffic being processed by intermediate devices, which is inefficient. Extended ACLs are designed to filter traffic based on source and destination, so positioning them closer to the source enhances performance and security.
★ When this WOULD be the correct answer
In a scenario where the question specifies that the network is highly segmented and traffic must be controlled at the destination for compliance reasons, placing an extended ACL close to the destination might be the best approach to enforce specific access policies for that segment.
Why candidates choose this
Candidates may choose this option because they associate ACLs with controlling access at the endpoint, believing that filtering at the destination is a more secure practice without considering the efficiency of traffic management.
✗Only on the default gatewayWrong answer — click to see why▾
Why this is wrong here
This option is incorrect because placing an extended ACL only on the default gateway limits its effectiveness in controlling traffic originating from various sources across the network. Extended ACLs should be strategically placed closer to the source to filter traffic before it reaches the destination.
★ When this WOULD be the correct answer
In a scenario where a question specifies that all traffic must be filtered at the default gateway due to a specific network design or security policy, stating that extended ACLs should only be on the default gateway could be correct. For example, if the question indicates that the network is small and all traffic must pass through the gateway, this option would apply.
Why candidates choose this
Candidates may choose this option due to a misunderstanding of ACL placement principles, believing that centralizing control at the default gateway simplifies management and security, without considering the broader implications of traffic flow.
✗Only on WAN interfacesWrong answer — click to see why▾
Why this is wrong here
Placing an extended ACL only on WAN interfaces can lead to inefficient traffic filtering, as it may not adequately control traffic originating from internal sources. Extended ACLs should ideally be positioned close to the source to effectively manage traffic before it reaches the destination.
★ When this WOULD be the correct answer
In a scenario where the exam question specifies that the network design requires strict control over traffic entering and leaving a WAN connection, placing an extended ACL only on WAN interfaces could be the correct answer. This would apply in a situation where all traffic must be filtered at the edge of the network for security compliance.
Why candidates choose this
Candidates may find this option tempting because they associate WAN interfaces with external traffic control, leading them to believe that filtering at this point is sufficient for managing network security.
Analysis generated from the official 200-301blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”
Visual reference
Go deeper
Related to this question
Learn chapter
Device File Management with SFTP and SCP
Key term
Access Control List
An Access Control List is a set of rules that decides which traffic is allowed or denied entry to a network or device.
Key term
Extended ACL
An extended access control list (ACL) is a set of rules that filters network traffic based on source and destination IP addresses, protocol type, and port numbers, providing more granular control than a standard ACL.
About these practice questions
Courseiva writes every 200-301 question from scratch — 1,389 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 200-301 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-301 exam.