Courseiva
Network Security Devices →hardMultiple Choice

GSEC Network Security Devices Practice Question

Exhibit

DENY ip any host 10.0.5.5 eq 80
PERMIT tcp 192.168.1.0 0.0.0.255 host 10.0.5.5 eq 80
PERMIT ip any any

Refer to the exhibit. A network administrator applies this ACL to a router interface. A user from the 192.168.1.0/24 subnet attempts to access the web server at 10.0.5.5 on port 80. What is the result of this traffic flow?

⚠ Common exam trap

Candidates often assume that because a permit rule exists for the subnet, the traffic will be allowed, forgetting that ACLs are processed top-down and the first match wins.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The traffic is denied because the first rule matches and terminates evaluation.

Cisco standard and extended ACLs process rules sequentially from top to bottom. The first rule explicitly denies any IP traffic to the host 10.0.5.5 on port 80. Because this deny rule is matched first, the router immediately drops the packet before evaluating subsequent lines. Even though the second rule would have permitted the traffic, it is unreachable due to the specificity and position of the initial deny statement.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The traffic is permitted because the second rule matches the source subnet.

    Why it's wrong here

    ACLs are processed sequentially. The first line of the configuration is a deny statement that matches all IP traffic directed at the specific host and port. Once a packet matches a deny rule, the router drops the packet immediately, preventing any evaluation of the later permit statement.

  • ✓

    The traffic is denied because the first rule matches and terminates evaluation.

    Why this is correct

    The router processes the ACL in a top-down fashion. The first rule denies all traffic to 10.0.5.5 on port 80. Since the packet matches this criteria, the evaluation stops, and the router silently discards the packet. The permit rule located on the second line is never reached.

  • ✗

    The traffic is permitted because permit rules take precedence over deny rules.

    Why it's wrong here

    ACLs do not prioritize permit rules over deny rules; they prioritize the order of the rules as they appear in the configuration. The router follows the logic provided by the administrator, and because the deny rule is placed first, it overrides any subsequent permit commands for matching packets.

  • ✗

    The router generates an error because the ACL rules are contradictory.

    Why it's wrong here

    The router does not check for logic errors or shadowed rules when applying an ACL. It simply follows the list from top to bottom. While the rules are technically redundant and poorly ordered for the administrator's goal, the router will execute them exactly as configured without throwing errors.

Visual reference

Source Router + ACL permit 10.0.0.0/8 deny any Server 10.0.0.5 ✓ 192.168.1.1 ✗ dropped ACLs evaluate top-down; first match wins — implicit deny all at end

About these practice questions

Courseiva writes every GSEC question from scratch — 351 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GSEC practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GSEC exam.