mediumMultiple Choice
CAS-004 Practice Question: Refer to the exhibit
Exhibit
access-list 100 deny ip any any access-list 100 permit tcp any host 10.0.0.10 eq 80
Refer to the exhibit. A security analyst notices that traffic from external clients to the web server at 10.0.0.10 port 80 is being blocked. Which of the following is the MOST likely cause?
⚠ Common exam trap
The trap here is that candidates focus on the ACL content (deny vs permit) rather than the order of entries, assuming that a permit statement anywhere in the ACL will allow traffic, when in fact the first matching rule determines the action.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The ACL is misordered (deny before permit)
The ACL is misordered because Cisco ACLs process rules sequentially from top to bottom, and a 'deny any' statement placed before a 'permit' statement will block all traffic, including the desired web traffic to 10.0.0.10 port 80. Since the exhibit shows a deny statement preceding the permit, the permit is never evaluated, causing the block.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The ACL lacks a log statement
Why it's wrong here
A missing log statement only affects whether denied packets are recorded; it does not itself drop traffic, so it cannot cause the block. It is tempting because absent logs make diagnosis harder, and adding logging would be the right action when you need visibility into which ACL entry is denying the traffic.
- ✓
The ACL is misordered (deny before permit)
Why this is correct
ACLs process rules sequentially, so a deny statement placed above the matching permit blocks port 80 traffic before the permit is ever evaluated. The exhibit's external-to-10.0.0.10:80 flow satisfies the deny entry first, producing the observed block despite a valid permit existing lower in the list.
- ✗
The web server is using port 443
Why it's wrong here
Port 443 carries HTTPS, so a server listening there would not block inbound port 80 traffic; the two are independent listeners. It is tempting because web servers commonly redirect HTTP to HTTPS, and this would be correct if the requirement were secure browsing rather than explaining why port 80 is denied.
- ✗
The destination IP is incorrect
Why it's wrong here
The stem already states the web server is at 10.0.0.10, so the destination address in the traffic matches the server and cannot explain the block. It is tempting because a mistyped address is a common cause of failed connections, and this would be correct if the exhibit showed clients targeting an address other than the server's.
Visual reference
About these practice questions
One of 973 original CAS-005 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.