Courseiva
Network Services and SecurityhardMultiple ChoiceObjective-mapped

CCNA Network Services and Security Practice Question

Why is an extended ACL usually placed close to the source of the traffic being filtered?

⚠ Common exam trap

Remember that ACLs are processed by network devices, not end devices, and their placement affects traffic flow, not the ACL's complexity or dynamic capabilities.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

To stop unwanted traffic earlier and conserve bandwidth

Extended ACLs can filter by source, destination, and protocol. Placing them near the source drops unwanted traffic before it crosses more of the network.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Because standard ACLs cannot be applied near the destination

    Why it's wrong here

    The misconception is that standard ACLs are unusable near the destination. In fact, standard ACLs are often placed near the destination because they lack destination and protocol information, making them too coarse for early filtering. Extended ACLs go near the source because they can precisely identify unwanted traffic, not because standard ACLs cannot be applied near the destination.

    When this WOULD be correct

    In a different question asking about the limitations of standard ACLs, one might state that they cannot be applied effectively near the destination for complex filtering scenarios, thus making this option correct. For example, a question could ask why standard ACLs are not suitable for certain destination-based filtering tasks.

  • To stop unwanted traffic earlier and conserve bandwidth

    Why this is correct

    Extended ACLs filter based on source, destination, protocol, and port, so placing them close to the source prevents unwanted packets from traversing the network. This conserves bandwidth on intermediate links and reduces CPU load on downstream routers. Filtering earlier is the core reason for this design guidance, as traffic is dropped before it costs resources.

  • To make NAT translation easier on inside interfaces

    Why it's wrong here

    ACL placement for filtering is independent of NAT. NAT uses ACLs to match traffic for translation on inside interfaces, but that does not dictate where an extended ACL should be placed in the path. The near-source placement rule exists to limit traffic before it consumes network resources, not to simplify NAT configuration.

    When this WOULD be correct

    In a scenario where the exam question asks about optimizing NAT configurations in a network, a candidate might be asked why certain ACLs should be placed on NAT devices. In this context, the option could be correct if the question implies that specific ACL placements can facilitate NAT operations.

  • Because extended ACLs only work inbound on access interfaces

    Why it's wrong here

    Extended ACLs are not limited to inbound access interfaces; they can be applied inbound or outbound on any interface, including distribution and core switches. The recommendation to place them close to the source is a best practice for early traffic filtering, not a technical limitation of the ACL feature itself. This option confuses a design guideline with a hardware or protocol restriction.

    When this WOULD be correct

    In a question asking about the limitations of extended ACLs, such as 'What is a restriction of extended ACLs on access interfaces?', option D would be correct, as it highlights that extended ACLs are indeed applied inbound on access interfaces.

Option-by-option analysis

Why each answer is right or wrong

Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The 200-301 exam frequently reuses these exact scenarios with slightly different constraints.

To stop unwanted traffic earlier and conserve bandwidthCorrect answer

Why this is correct

Extended ACLs filter based on source, destination, protocol, and port, so placing them close to the source prevents unwanted packets from traversing the network. This conserves bandwidth on intermediate links and reduces CPU load on downstream routers. Filtering earlier is the core reason for this design guidance, as traffic is dropped before it costs resources.

Because standard ACLs cannot be applied near the destinationWrong answer — click to see why

Why this is wrong here

Standard ACLs can be applied near the destination or source, but the placement guidance for extended ACLs is based on their ability to filter on source and destination IP addresses and ports, not on limitations of standard ACLs. The reason for placing extended ACLs near the source is to filter traffic early, not because standard ACLs cannot be applied near the destination.

★ When this WOULD be the correct answer

In a different question asking about the limitations of standard ACLs, one might state that they cannot be applied effectively near the destination for complex filtering scenarios, thus making this option correct. For example, a question could ask why standard ACLs are not suitable for certain destination-based filtering tasks.

Why candidates choose this

Students may confuse the placement rules for standard and extended ACLs, thinking that extended ACLs are placed near the source because standard ACLs are limited to destination-based filtering. However, standard ACLs are typically placed near the destination, but that is not the reason for extended ACL placement.

To make NAT translation easier on inside interfacesWrong answer — click to see why

Why this is wrong here

NAT translation is typically performed on routers or firewalls at network boundaries, and ACL placement for filtering is independent of NAT configuration. Placing an extended ACL near the source does not directly affect NAT translation; NAT uses its own rules and is not a factor in ACL placement decisions.

★ When this WOULD be the correct answer

In a scenario where the exam question asks about optimizing NAT configurations in a network, a candidate might be asked why certain ACLs should be placed on NAT devices. In this context, the option could be correct if the question implies that specific ACL placements can facilitate NAT operations.

Why candidates choose this

Students might associate ACLs with NAT because both are often configured on border devices, leading to the misconception that ACL placement is related to NAT. However, the primary reason for placing extended ACLs near the source is to filter traffic early, not to assist NAT.

Because extended ACLs only work inbound on access interfacesWrong answer — click to see why

Why this is wrong here

Extended ACLs can be applied inbound or outbound on any interface, not just inbound on access interfaces. The statement is factually incorrect; extended ACLs are versatile and can be placed in various locations depending on the filtering requirements.

★ When this WOULD be the correct answer

In a question asking about the limitations of extended ACLs, such as 'What is a restriction of extended ACLs on access interfaces?', option D would be correct, as it highlights that extended ACLs are indeed applied inbound on access interfaces.

Why candidates choose this

Students may think that extended ACLs are only effective when applied inbound because they filter traffic before it enters the router, but this is a misunderstanding. Extended ACLs can filter traffic in both directions, and placement near the source is a design choice, not a technical limitation.

Analysis generated from the official 200-301blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”

Visual reference

Source Router + ACL permit 10.0.0.0/8 deny any Server 10.0.0.5 ✓ 192.168.1.1 ✗ dropped ACLs evaluate top-down; first match wins — implicit deny all at end

About these practice questions

This 200-301 question is part of Courseiva's 1,389-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 200-301 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-301 exam.