CCNA: Cisco Certified Network Associate — Question 667

A network engineer must configure an access list on a new Cisco IOS router. The access list must deny HTTP traffic to network 10.125.128.32/27 from the 192.168.240.0/20 network, but it must allow the 192.168.240.0/20 network to reach the rest of the 10.0.0.0/8 network. Which configuration must the engineer apply?

Answer options

Correct answer: B

Explanation

The correct answer is B because it specifically denies HTTP traffic (port 80) from the 192.168.240.0/20 network to the 10.125.128.32/27 network while allowing access to the rest of the 10.0.0.0/8 network. Options A, C, and D either incorrectly allow HTTP traffic or do not properly permit access to the broader 10.0.0.0/8 network.