CCNA Network Services and Security Practice Question
Why is an extended ACL usually placed close to the source of the traffic being filtered?
⚠ Common exam trap
Remember that ACLs are processed by network devices, not end devices, and their placement affects traffic flow, not the ACL's complexity or dynamic capabilities.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
To stop unwanted traffic earlier and conserve bandwidth
Extended ACLs can filter by source, destination, and protocol. Placing them near the source drops unwanted traffic before it crosses more of the network.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Because standard ACLs cannot be applied near the destination
Why it's wrong here
The misconception is that standard ACLs are unusable near the destination. In fact, standard ACLs are often placed near the destination because they lack destination and protocol information, making them too coarse for early filtering. Extended ACLs go near the source because they can precisely identify unwanted traffic, not because standard ACLs cannot be applied near the destination.
When this WOULD be correct
In a different question asking about the limitations of standard ACLs, one might state that they cannot be applied effectively near the destination for complex filtering scenarios, thus making this option correct. For example, a question could ask why standard ACLs are not suitable for certain destination-based filtering tasks.
- ✓
To stop unwanted traffic earlier and conserve bandwidth
Why this is correct
Extended ACLs filter based on source, destination, protocol, and port, so placing them close to the source prevents unwanted packets from traversing the network. This conserves bandwidth on intermediate links and reduces CPU load on downstream routers. Filtering earlier is the core reason for this design guidance, as traffic is dropped before it costs resources.
- ✗
To make NAT translation easier on inside interfaces
Why it's wrong here
ACL placement for filtering is independent of NAT. NAT uses ACLs to match traffic for translation on inside interfaces, but that does not dictate where an extended ACL should be placed in the path. The near-source placement rule exists to limit traffic before it consumes network resources, not to simplify NAT configuration.
When this WOULD be correct
In a scenario where the exam question asks about optimizing NAT configurations in a network, a candidate might be asked why certain ACLs should be placed on NAT devices. In this context, the option could be correct if the question implies that specific ACL placements can facilitate NAT operations.
- ✗
Because extended ACLs only work inbound on access interfaces
Why it's wrong here
Extended ACLs are not limited to inbound access interfaces; they can be applied inbound or outbound on any interface, including distribution and core switches. The recommendation to place them close to the source is a best practice for early traffic filtering, not a technical limitation of the ACL feature itself. This option confuses a design guideline with a hardware or protocol restriction.
When this WOULD be correct
In a question asking about the limitations of extended ACLs, such as 'What is a restriction of extended ACLs on access interfaces?', option D would be correct, as it highlights that extended ACLs are indeed applied inbound on access interfaces.
Option-by-option analysis
Why each answer is right or wrong
Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The 200-301 exam frequently reuses these exact scenarios with slightly different constraints.
✓To stop unwanted traffic earlier and conserve bandwidthCorrect answer▾
Why this is correct
Extended ACLs filter based on source, destination, protocol, and port, so placing them close to the source prevents unwanted packets from traversing the network. This conserves bandwidth on intermediate links and reduces CPU load on downstream routers. Filtering earlier is the core reason for this design guidance, as traffic is dropped before it costs resources.
✗Because standard ACLs cannot be applied near the destinationWrong answer — click to see why▾
Why this is wrong here
Standard ACLs can be applied near the destination or source, but the placement guidance for extended ACLs is based on their ability to filter on source and destination IP addresses and ports, not on limitations of standard ACLs. The reason for placing extended ACLs near the source is to filter traffic early, not because standard ACLs cannot be applied near the destination.
★ When this WOULD be the correct answer
In a different question asking about the limitations of standard ACLs, one might state that they cannot be applied effectively near the destination for complex filtering scenarios, thus making this option correct. For example, a question could ask why standard ACLs are not suitable for certain destination-based filtering tasks.
Why candidates choose this
Students may confuse the placement rules for standard and extended ACLs, thinking that extended ACLs are placed near the source because standard ACLs are limited to destination-based filtering. However, standard ACLs are typically placed near the destination, but that is not the reason for extended ACL placement.
✗To make NAT translation easier on inside interfacesWrong answer — click to see why▾
Why this is wrong here
NAT translation is typically performed on routers or firewalls at network boundaries, and ACL placement for filtering is independent of NAT configuration. Placing an extended ACL near the source does not directly affect NAT translation; NAT uses its own rules and is not a factor in ACL placement decisions.
★ When this WOULD be the correct answer
In a scenario where the exam question asks about optimizing NAT configurations in a network, a candidate might be asked why certain ACLs should be placed on NAT devices. In this context, the option could be correct if the question implies that specific ACL placements can facilitate NAT operations.
Why candidates choose this
Students might associate ACLs with NAT because both are often configured on border devices, leading to the misconception that ACL placement is related to NAT. However, the primary reason for placing extended ACLs near the source is to filter traffic early, not to assist NAT.
✗Because extended ACLs only work inbound on access interfacesWrong answer — click to see why▾
Why this is wrong here
Extended ACLs can be applied inbound or outbound on any interface, not just inbound on access interfaces. The statement is factually incorrect; extended ACLs are versatile and can be placed in various locations depending on the filtering requirements.
★ When this WOULD be the correct answer
In a question asking about the limitations of extended ACLs, such as 'What is a restriction of extended ACLs on access interfaces?', option D would be correct, as it highlights that extended ACLs are indeed applied inbound on access interfaces.
Why candidates choose this
Students may think that extended ACLs are only effective when applied inbound because they filter traffic before it enters the router, but this is a misunderstanding. Extended ACLs can filter traffic in both directions, and placement near the source is a design choice, not a technical limitation.
Analysis generated from the official 200-301blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”
Visual reference
Go deeper
Related to this question
Learn chapter
RA Guard — IPv6 First-Hop Security
Key term
Extended ACL
An extended access control list (ACL) is a set of rules that filters network traffic based on source and destination IP addresses, protocol type, and port numbers, providing more granular control than a standard ACL.
Key term
CAN
A CAN (Controller Area Network) is a robust vehicle bus standard designed to allow microcontrollers and devices to communicate with each other without a host computer.
About these practice questions
This 200-301 question is part of Courseiva's 1,389-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 200-301 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-301 exam.