CCNP Security Practice Question
A company has deployed a Cisco ASA firewall in transparent mode. The internal network uses VLAN 10 and the external network uses VLAN 20. The ASA is configured with two bridge groups: BVI 10 for inside and BVI 20 for outside. The security policy must allow HTTPS traffic from inside to outside. Which access-list entry is correct?
⚠ Common exam trap
Cisco often tests the misconception that transparent mode uses interface-based ACLs like routed mode, when in fact transparent mode requires global ACLs applied to the BVI, and the 'GLOBAL' keyword is mandatory for Layer 2 traffic filtering.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
access-list GLOBAL extended permit tcp 192.168.1.0 255.255.255.0 any eq 443
In transparent mode, the ASA acts as a Layer 2 bridge, so traffic must be permitted by a global access list applied to the bridge group virtual interface (BVI). Option D correctly uses the GLOBAL access list to permit TCP traffic from the inside subnet (192.168.1.0/24) to any destination on port 443 (HTTPS), which satisfies the security policy.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
access-list INSIDE extended permit tcp 192.168.1.0 255.255.255.0 any eq 443 access-group INSIDE in interface inside
Why it's wrong here
This command fails because transparent (Layer 2) firewall mode does not support interface-specific access-groups. The ASA bridges traffic, not routes it, so an ACL applied with 'access-group ... in interface inside' is not evaluated for bridged traffic. Instead, only the global access-list, configured as 'access-list GLOBAL' and applied with 'access-group GLOBAL in global', is used to filter all traffic traversing the bridge, regardless of ingress or egress interface.
- ✗
access-list GLOBAL extended permit ip 192.168.1.0 255.255.255.0 any
Why it's wrong here
This global access-list is too broad because it permits all IP protocols (TCP, UDP, ICMP, IPsec, etc.) from the 192.168.1.0/24 subnet to any destination, not just HTTPS. The stated requirement is to allow only outbound HTTPS (TCP 443) traffic, so this rule would over-permit by allowing every IP service from the inside network. In transparent mode, the global ACL applies to all bridged traffic, making this rule even more dangerous as it would open the entire internal network to any destination.
- ✗
access-list GLOBAL extended permit tcp any any eq 443
Why it's wrong here
This global access-list incorrectly specifies 'any' as the source, which would permit HTTPS traffic from any IP address, including untrusted outside networks and other internal segments. Although it restricts the service to TCP 443, it fails to limit the source to the inside subnet 192.168.1.0/24 as required. Since transparent-mode global ACLs apply to all bridged traffic regardless of interface, this rule would allow external hosts to reach any destination on port 443, violating the explicit source restriction in the security policy.
- ✓
access-list GLOBAL extended permit tcp 192.168.1.0 255.255.255.0 any eq 443
Why this is correct
This is the correct configuration for transparent mode. The global access-list is the only ACL applied to a transparent ASA, and it evaluates all traffic crossing the Layer 2 bridge. The rule precisely matches the requirement: source is the inside subnet 192.168.1.0/24, destination is any, and service is TCP 443 (HTTPS), thus permitting only outbound HTTPS from the inside network while implicitly denying everything else. This adheres to least-privilege access control and is applied globally so that traffic from any interface, including the inside, is filtered consistently.
Visual reference
About these practice questions
This 350-401 question is part of Courseiva's 1,923-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.