QuestionQ40

Security Operations

An enterprise wants to restrict outbound DNS traffic from its internal network. Outbound DNS requests must be permitted only from the device with IP address 10.50.10.25. Which firewall ACL accomplishes this objective?

Explanation

An outbound DNS ACL must match the authorized device as the source (10.50.10.25/32) and DNS as destination port 53, permitting that traffic before denying DNS traffic from every other source. ACL entries are evaluated in sequence, so the specific permit must precede the general deny.

Community Discussion

No comments yet. Be the first to start the discussion!