easyMultiple ChoiceObjective-mapped
SSCP Practice Question: Refer to the exhibit
Exhibit
access-list 101 permit tcp any host 192.168.1.100 eq 22 access-list 101 deny tcp any any eq 22
Refer to the exhibit. A network administrator implements this ACL on a border router. What is the effect?
⚠ Common exam trap
ISC2 often tests the implicit deny all at the end of an ACL, leading candidates to mistakenly think that only explicitly denied traffic is blocked, when in fact all traffic not explicitly permitted is denied.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
SSH to 192.168.1.100 is permitted from any source
The ACL explicitly permits TCP traffic sourced from any IP address destined to 192.168.1.100 on port 22, which is the default port for SSH. Since the ACL is applied inbound on the border router's external interface, it allows SSH connections from any external source to reach the internal host 192.168.1.100, while implicitly denying all other traffic.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
SSH to 192.168.1.100 is permitted from any source
Why this is correct
The permit rule applies to any source destined to that host on port 22.
- ✗
SSH is completely blocked
Why it's wrong here
The permit rule allows SSH to the specific host.
- ✗
All traffic to 192.168.1.100 is permitted
Why it's wrong here
Only SSH traffic is permitted; other ports are not allowed.
- ✗
Only SSH from external networks is blocked
Why it's wrong here
SSH to 192.168.1.100 is permitted, so not blocked.
Visual reference
Go deeper
Related to this question
About these practice questions
Courseiva writes every SSCP question from scratch — 920 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.