How to Restrict Outbound DNS Traffic to a Single Host Using Firewall ACLs?
An enterprise is trying to limit outbound DNS traffic originating from its internal network. Outbound DNS requests will only be allowed from one device with the IP address 10.50.10.25. Which of the following firewall ACLs will accomplish this goal?
Community Votes
100% of anonymous learners picked answer D. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
The question tests your grasp of ACL field ordering (source IP, destination IP, port), with the primary trap being the reversal of source and destination placements.
This question evaluates your ability to interpret firewall Access Control List (ACL) syntax to restrict outbound DNS traffic to a specific internal IP. The community consensus confirms that correctly mapping source and destination addresses is critical to solving this scenario.
Candidates frequently choose Option B by swapping the IP fields, incorrectly assuming the second address represents the permitted internal host rather than the external destination. Others select A or C due to overlooking the requirement for host-specific filtering.
Community Discussion (27 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Decoding Firewall ACL Syntax
Firewall Access Control Lists follow a strict sequential evaluation model: permit/deny [source_ip] [destination_ip] [protocol/port]. For outbound rules, the first IP address always represents the internal originator of the traffic, while the second represents the external target.Why Option D is Correct
Option D (Access list outbound permit 10.50.10.25/32 0.0.0.0/0 port 53) perfectly aligns with this syntax. It designates 10.50.10.25/32 as the sole permitted source, 0.0.0.0/0 as any possible external destination, and limits the action to port 53 (DNS). As consistently explained by community voters, this single permit statement leverages the firewall's implicit deny-all policy at the end of the ACL to automatically block DNS requests from all other internal devices.Why the Other Options Fail
- Options A & C: These use 0.0.0.0/0 for both source and destination, effectively creating a blanket permit that allows every device on the network to send DNS traffic outward, directly contradicting the restriction requirement.
- Option B: This reverses the IP logic, attempting to permit any source to reach 10.50.10.25 on port 53. In an outbound context, this misconfiguration would either fail to match legitimate client traffic or inadvertently restrict inbound responses, demonstrating a fundamental misunderstanding of ACL directionality.
Official Reference
- CompTIA Security+ SY0-701 Objective 2.2: Configure secure network infrastructure
- RFC 1035: Domain Names - Concepts and Facilities
- Cisco ASA/Firepower ACL Configuration Best Practices
Exam Strategy
When encountering firewall ACL questions, immediately sketch the traffic flow to distinguish between source and destination before matching them to the ACL fields. Always remember that certification exams rely on the principle of least privilege combined with an implicit deny-all, meaning you typically only need to write the specific permit rule to satisfy restrictive scenarios.
Related Analysis
Practice All SY0-701 Questions
Access 100 questions with complete answers and detailed explanations.
View Full SY0-701 Practice Test →