exam questions

Exam HPE6-A73 All Questions

View all questions & answers for the HPE6-A73 exam

Exam HPE6-A73 topic 1 question 38 discussion

Actual exam question from HP's HPE6-A73
Question #: 38
Topic #: 1
[All HPE6-A73 Questions]

Examine the following AOS-CX switch configuration:

Which statement correctly describes what is allowed for traffic entering interface 1/1/3?

  • A. IP traffic from 10.1.11.0/24 is allowed to access 10.1.110.0/24
  • B. IP traffic from 10.0.11.0/24 is allowed to access 10.1.12.0/24
  • C. Traffic from 10.0.12.0/24 will generate a log record when accessing 10.0.11.0/24
  • D. IP traffic from 10.1.12.0/24 is allowed to access 172.0.1.0/23
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
cloud29
Highly Voted 4 years ago
The question is " Which statement correctly describes what is allowed for traffic entering interface 1/1/3?" I think that what is allowed to enter the interface 1/1/3 is everything from: ANY TO -> 10.X.11.X(this is allowed and counted) or 10.X.12.X(this allowed and loged), thats why i think the answer is B Everything with other "destination" should be denny.
upvoted 15 times
...
BFDS
Most Recent 7 months ago
why no one is talking about the incorrect 255.0.255.0 subnet in the ACL
upvoted 2 times
...
SeidorBruno
1 year, 9 months ago
Selected Answer: B
As per ACL definition: Matching seq 20 "permit ip any 10.0.12.0/255.0.255.0 log" So trafic from any source ip address is permitted to 10.x.12.x
upvoted 3 times
...
alex711
2 years, 1 month ago
Selected Answer: B
B is correct
upvoted 1 times
...
Bahadorkh
2 years, 5 months ago
B is correct
upvoted 1 times
...
Jo2241
2 years, 6 months ago
Selected Answer: B
B is correct
upvoted 1 times
...
NetExpert
2 years, 6 months ago
B is correct
upvoted 1 times
...
Jo2241
2 years, 8 months ago
Selected Answer: B
No wildcard mask with Aruba CX. B answer
upvoted 1 times
...
root2022
2 years, 10 months ago
B is correct
upvoted 1 times
...
gondolf
3 years ago
Selected Answer: B
People seem to be confused by inverted mask/wildcard masks. They would be correct for Cisco switches, but AOS-CX does NOT use wildcard masks; "AOX-CX switches do not support wildcard masks - only prefixes or subnet masks - when created ACEs." Cisco: 255.0.255.0 = xx.123.xx.123 AOS-CX: 255.0.255.0 = 123.xx.123.xx My answer is B.
upvoted 2 times
...
jagoanneon
3 years, 2 months ago
Selected Answer: D
I think the answer is D. Here is the simplified access list with X=any (0-255) permit any -> X.0.X.0 count permit any -> X.0.X.0 log They are practically the same ACL with only different the top does count and bottom does log. A. IP traffic from 10.1.11.0/24 is allowed to access 10.1.110.0/24 We dont care with source (10.1.11.0/24). The source can be any. But the destination is 10.1.110.0/24 and it does not match. The second octet must be 0. B. IP traffic from 10.0.11.0/24 is allowed to access 10.1.12.0/24 Same with A. 10.1.12.0 does not match because second octet is 1 C. Traffic from 10.0.12.0/24 will generate a log record when accessing 10.0.11.0/24 This actually match both ACEs but since ACL matches from top to bottom, so it will match the top ACE (count). D. IP traffic from 10.1.12.0/24 is allowed to access 172.0.1.0/23 this would match the ACL. We dont care about source and destination 172.0.1.0 (match X.0.X.0) Samw
upvoted 1 times
...
pabx31
3 years, 6 months ago
My opinion: B Only traffic destined TO the listed subs is allowed This excluded A and D Only traffic TO 10.1.12.0 is logged This excludes C This leaves B .11.0 is part of ANY so it is allowed to access .12.0 This traffic will be logged but that isn't part of the answer.
upvoted 1 times
...
clupato2
3 years, 8 months ago
I think it's C. ACL entries work with wildcard mask. The wildcard mask is 255.0.255.0. This is a wildcard mask and not a subnet mask also because it is not a valid subnet mask. In a wildcard mask made in this way you have to match bits where wildcard is 0. So, it matches packets where the DESTINATION IP ADDRESS is X.0.X.0. In a /24 network, you will never have a destination IP where the last octet is 0. So i think this ACL is not valid, by the way, the only answer that matches the ACL entries is the C BUT it matches the first entry, so it will never generate a log, but a counter increment. This is a bad question with no matching answers. The "best matching" answer is C even if it is wrong.
upvoted 3 times
OICU812
3 years, 7 months ago
In the official HPE study book, it clearly states that AOS-CX switches do not support Wildcard Masks when creating ACEs.
upvoted 5 times
...
watermellonhead
3 years, 7 months ago
Got it backwards. 10.0.12.0/255.0.255.0 will match 10.1.12.0/24 .Therefore B should be correct. Right from the student guide. 1's match 0's ignore. Ch. 5 - Task 2 , or search book for 255.0.255.0 "In this example any destination IP address that has '10' in the first byte, and '12' in the third byte will match the rule.
upvoted 2 times
...
...
maccchinguwo
3 years, 9 months ago
B sound correct but check the ip addresses properly 10.0.11.0/24 and 10.0.12.0/24 where is 10.1.12.0/24 coming from? C is correct then
upvoted 1 times
...
Williams926
3 years, 10 months ago
I think answer is B.
upvoted 2 times
...
El3den
3 years, 10 months ago
but 10.1.12.0 is not matching the wild card mask. i see answer C more accurate, because count will generate syslog message right ?
upvoted 1 times
El3den
3 years, 10 months ago
sorry it is subnet mask no wild card, B is correct
upvoted 2 times
...
...
Simba80
4 years ago
It's possible that B is correct but look at the log and count entries in the commands. I think C is correct. A log entry will be generated for this subnet.
upvoted 2 times
fasty
4 years ago
the log count is only active for destination 10.x.12.x
upvoted 1 times
fasty
4 years ago
Only log*
upvoted 1 times
...
LoneRaccoon
1 year, 6 months ago
AOS-CX does not support Wildcard / Inverted Subnet Masks... Study Guide states: "AOS-CX switches do not support wildcard masks - only prefixes or subnet masks - when creating ACEs". Therefore C is most probably the answer
upvoted 1 times
...
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago