How to Restrict Outbound DNS Traffic to a Single Host Using Firewall ACLs?

An enterprise is trying to limit outbound DNS traffic originating from its internal network. Outbound DNS requests will only be allowed from one device with the IP address 10.50.10.25. Which of the following firewall ACLs will accomplish this goal?

  1. Access list outbound permit 0.0.0.0/0 0.0.0.0/0 port 53
  2. Access list outbound permit 0.0.0.0/0 10.50.10.25/32 port 53
  3. Access list outbound permit 0.0.0.0/0 0.0.0.0/0 port 53
  4. Access list outbound permit 10.50.10.25/32 0.0.0.0/0 port 53 Source Reference Answer

Community Votes

D
100%

100% of anonymous learners picked answer D. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

The question tests your grasp of ACL field ordering (source IP, destination IP, port), with the primary trap being the reversal of source and destination placements.

This question evaluates your ability to interpret firewall Access Control List (ACL) syntax to restrict outbound DNS traffic to a specific internal IP. The community consensus confirms that correctly mapping source and destination addresses is critical to solving this scenario.

Candidates frequently choose Option B by swapping the IP fields, incorrectly assuming the second address represents the permitted internal host rather than the external destination. Others select A or C due to overlooking the requirement for host-specific filtering.

Community Discussion (27 comments)

Baloyitum 👍 20
The correct ACL (Access Control List) to accomplish the goal of limiting outbound DNS traffic originating from the internal network to only one device with the IP address 10.50.10.25 would be option D: Copy code Access list outbound permit 10.50.10.25/32 0.0.0.0/0 port 53 Access list outbound deny 0.0.0.0/0 0.0.0.0/0 port 53 This configuration allows outbound DNS requests from the specific IP address 10.50.10.25 and denies outbound DNS requests from any other IP address.
kedu 👍 2 Selected: D
Access list outbound permit 10.50.10.25/32 0.0.0.0/0 port 53 Access list outbound deny 0.0.0.0/0 0.0.0.0/0 port 53
JackExam2025 👍 1 Selected: D
Outbound DNS traffic needs to be allowed only from 10.50.10.25. To achieve this, you first need to permit traffic from 10.50.10.25 to port 53 (DNS). Then, you need to deny all other traffic to port 53.
Hasss 👍 2 Selected: D
Becuase its the only answer that has the same IP address on the outbound permit
JRCHENRY 👍 1 Selected: D
Access list outbound permit 10.50.10.25/32 0.0.0.0/0 port 53 Access list outbound deny 0.0.0.0/0 0.0.0.0/0 port 53
MaxiPrince 👍 1 Selected: D
Access list outbound permit 10.50.10.25/32 0.0.0.0/0 port 53 Access list outbound deny 0.0.0.0/0 0.0.0.0/0 port 53
Rafili 👍 1 Selected: D
The line permit 10.50.10.25/32 0.0.0.0/0 port 53 allows DNS traffic only from the specified device (10.50.10.25) to any destination. The line deny 0.0.0.0/0 0.0.0.0/0 port 53 blocks all other DNS traffic from any other device in the internal network. So answer D for 100% sure!
Juls74 👍 2 Selected: D
Permit 10.50.10.25/32 0.0.0.0/0 port 53: This rule allows outbound DNS requests from the device with the IP address 10.50.10.25. Deny 0.0.0.0/0 0.0.0.0/0 port 53: This rule denies all other outbound DNS requests from any other devices on any IP address. This combination ensures that only the specific device with IP address 10.50.10.25 can send outbound DNS requests, effectively limiting the outbound DNS traffic as desired.
MZAINUL 👍 1 Selected: D
This configuration allows outbound DNS requests from the specific IP address 10.50.10.25 and denies outbound DNS requests from any other IP address.
Luswepo 👍 2 Selected: D
The correct firewall ACL configuration that will allow only the device with IP address 10.50.10.25 to send outbound DNS traffic while blocking all other devices is: D. Access list outbound permit 10.50.10.25/32 0.0.0.0/0 port 53 Access list outbound deny 0.0.0.0/0 0.0.0.0/0 port** Explanation: - The first line allows outbound DNS requests (port 53) only from the device with IP address 10.50.10.25. - The second line denies all other outbound DNS traffic from any other IP address. This achieves the goal of limiting DNS traffic to a single device.
d1f9467 👍 1 Selected: D
C: this option first allows all DNS traffic and then attempts to block traffic to 10.50.10.25, which is not the target.
Grouthorax 👍 2 Selected: D
C is wrong. The statement would allow outbound DNS traffic from any IP and deny outbound traffic from IP 10.50.10.25 which is the opposite of what it asks for. Correct answer is D
tladytea 👍 3 Selected: D
D. Access list outbound permit 10.50.10.25/32 0.0.0.0/0 port 53 Access list outbound deny 0.0.0.0/0 0.0.0.0/0 port 53 Here’s the reasoning: • The first line Access list outbound permit 10.50.10.25/32 0.0.0.0/0 port 53 allows DNS traffic (port 53) from the specific IP address 10.50.10.25 to any destination. • The second line Access list outbound deny 0.0.0.0/0 0.0.0.0/0 port 53 denies DNS traffic (port 53) from any source to any destination, effectively blocking all other outbound DNS traffic.
Olekjs 👍 1
D. Access list outbound permit 10.50.10.25/32 0.0.0.0/0 port 53 Access list outbound deny 0.0.0.0/0 0.0.0.0/0 port 53 because it only allow the device with the IP address 10.50.10.25 to send outbound DNS request on port 53, and denies all other devices from doing so
oluabi.salami 👍 1
D is the correct answer. Even co-pilot and chatGPT think so too. C is not correct. Co-pilot: Absolutely, setting up Access Control Lists (ACLs) on your firewall is a good way to manage outbound DNS traffic. Here's an example of how you might configure the ACLs to meet your requirements: # Allow DNS requests from 10.50.10.25 access-list 100 permit udp host 10.50.10.25 any eq 53 access-list 100 permit tcp host 10.50.10.25 any eq 53 # Deny DNS requests from any other IP address access-list 100 deny udp any any eq 53 access-list 100 deny tcp any any eq 53
easy02 👍 1
D. Access list outbound permit 10.50.10.25/32 0.0.0.0/0 port 53** Access list outbound deny 0.0.0.0/0 0.0.0.0/0 port 53
Ukwanda 👍 1
Correct answer is B as it allows outbound traffic for device with IP address 10:50.10.25/32 port 53. All other IP addresses are blocked on port 53 B. Access list outbound permit 0.0.0.0/0 10.50.10.25/32 port 53 Access list outbound deny 0.0.0.0/0 0.0.0.0/0 port 53
Etc_Shadow28000 👍 2 Selected: D
The goal is to allow outbound DNS requests only from the device with the IP address 10.50.10.25 and block all other outbound DNS requests. DNS typically uses port 53. A. - This rule allows all outbound traffic on port 53, and then specifically denies traffic from 10.50.10.25 on port 53. This would effectively block the allowed device, so it's incorrect. B. - This rule allows traffic to 10.50.10.25 on port 53, and then denies all outbound traffic on port 53. Since this is outbound DNS traffic control, the destination should not be 10.50.10.25, making this incorrect. C. - This rule allows all outbound traffic on port 53 and then denies traffic to 10.50.10.25 on port 53. This does not control outbound traffic from the specified IP, so it's incorrect. D. - This rule allows outbound traffic on port 53 only from the IP 10.50.10.25 and then denies all other outbound traffic on port 53. This is the correct configuration. Therefore, the correct firewall ACL to accomplish this goal is: D.
Lanka22 👍 2 Selected: D
in Answer C it permits any IP and any subnet mask (0.0.0.0/0.0.0.0) According to the question allow only 10.50.10.25 so the answer should be D
Sweety_Certified7 👍 2 Selected: D
The correct option would be: D. Access list outbound permit 10.50.10.25/32 0.0.0.0/0 port 53 Access list outbound deny 0.0.0.0/0 0.0.0.0/0 port 53 This ACL (Access Control List) configuration allows outbound DNS traffic only from the specified device with the IP address 10.50.10.25 and denies outbound DNS traffic from all other devices on the network.
SHADTECH123 👍 1 Selected: D
correct answer is D
hasquaati 👍 1 Selected: D
D, we need to specifically Allow the one IP address that can send outbound DNS
shady23 👍 1 Selected: D
D. Access list outbound permit 10.50.10.25/32 0.0.0.0/0 port 53 Access list outbound deny 0.0.0.0/0 0.0.0.0/0 port 53
Mehsotopes 👍 1 Selected: C
0.0.0.0/0.0.0.0/0 should be used when trying to limit outbound DNS traffic to only one device from the internal network regardless of IP. 0.0.0.0 is an indication of your GATEWAY SURFACE on IPv4. 0.0.0.0/0 10.50.10.25/32, & Would be giving access to all singular communicating devices on port 53 on 10.5010.25.
cri88 👍 1 Selected: D
D is the right one.
Luchis_69 👍 1 Selected: D
Correct answer is D. This ACL configuration first permits outbound DNS traffic originating from the device with the IP address 10.50.10.25 and then denies all other outbound DNS traffic.
An381038 👍 1 Selected: C
C. Access list outbound permit 0.0.0.0/0 0.0.0.0/0 port 53 Access list outbound deny 0.0.0.0/0 10.50.10.25/32 port 53. Option C achieves this goal by first permitting outbound DNS traffic from any source address (0.0.0.0/0) to any destination address (0.0.0.0/0) on port 53 (the standard DNS port). Then, it denies outbound DNS traffic specifically from the device with the IP address 10.50.10.25 (10.50.10.25/32) to any destination address on port 53.

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Decoding Firewall ACL Syntax

Firewall Access Control Lists follow a strict sequential evaluation model: permit/deny [source_ip] [destination_ip] [protocol/port]. For outbound rules, the first IP address always represents the internal originator of the traffic, while the second represents the external target.

Why Option D is Correct

Option D (Access list outbound permit 10.50.10.25/32 0.0.0.0/0 port 53) perfectly aligns with this syntax. It designates 10.50.10.25/32 as the sole permitted source, 0.0.0.0/0 as any possible external destination, and limits the action to port 53 (DNS). As consistently explained by community voters, this single permit statement leverages the firewall's implicit deny-all policy at the end of the ACL to automatically block DNS requests from all other internal devices.

Why the Other Options Fail

  • Options A & C: These use 0.0.0.0/0 for both source and destination, effectively creating a blanket permit that allows every device on the network to send DNS traffic outward, directly contradicting the restriction requirement.
  • Option B: This reverses the IP logic, attempting to permit any source to reach 10.50.10.25 on port 53. In an outbound context, this misconfiguration would either fail to match legitimate client traffic or inadvertently restrict inbound responses, demonstrating a fundamental misunderstanding of ACL directionality.

Official Reference

  • CompTIA Security+ SY0-701 Objective 2.2: Configure secure network infrastructure
  • RFC 1035: Domain Names - Concepts and Facilities
  • Cisco ASA/Firepower ACL Configuration Best Practices

Exam Strategy

When encountering firewall ACL questions, immediately sketch the traffic flow to distinguish between source and destination before matching them to the ACL fields. Always remember that certification exams rely on the principle of least privilege combined with an implicit deny-all, meaning you typically only need to write the specific permit rule to satisfy restrictive scenarios.

Related Analysis

Practice All SY0-701 Questions

Access 100 questions with complete answers and detailed explanations.

View Full SY0-701 Practice Test →

← Back to SY0-701 Study Guide