Question 1
In an ACL, what does a final rule 'Permit all other traffic' accomplish?
Correct Answer:
It allows all traffic not explicitly denied by earlier rules
Explanation:
ACLs are checked from top to bottom, and once a packet matches a rule, that rule’s action is taken and processing stops. If nothing matches, the packet would be dropped by the default behavior (implicit deny). When the final rule explicitly says “permit all other traffic,” it provides a catch-all that allows any traffic not matched by earlier rules. This makes the rest of the ACL effectively permissive for everything not previously denied, which is why this final rule best describes its effect. The other ideas don’t fit how ACLs operate: nothing in an ACL inherently denies all unmatched traffic unless you’ve configured that explicit deny, ACLs are applied on the interface you bind them to (inbound or outbound), and they do affect traffic on that interface rather than forwarding without applying.
Question 2
What is a defining characteristic of a global unicast IPv6 address?
Correct Answer:
It is globally routable
Explanation:
Global unicast IPv6 addresses are designed to be reachable anywhere on the Internet. They are globally routable, assigned in blocks by regional registries, and intended for hosts that need public reachability across networks. This makes packets with these addresses forwardable across the global routing system. In contrast, an address used only on the local link isn’t routable beyond that single network segment, multicast addresses target multiple destinations, and private (ULA) addresses aren’t meant for global Internet reachability. So the defining trait is that it is globally routable.
Question 3
What is the effect of enabling port security on a switch port?
Correct Answer:
It restricts access by MAC address and can shut down the port on violations.
Explanation:
Port security controls which devices can use a switch port by binding specific MAC addresses to that port, limiting how many unique addresses can send frames. If a frame from a MAC address that isn’t allowed appears, or if the number of allowed addresses is exceeded, the switch can take a violation action, most commonly shutting the port down to prevent access. This helps protect the network from unauthorized devices and MAC spoofing. It does not encrypt traffic, does not allow every MAC address to connect, and does not dynamically change the VLAN on the port.
Question 4
Migrating your on-premise email capability to a cloud-hosted email service offering is an example of what as a service model?
Correct Answer:
SaaS
Explanation:
Software as a Service is being demonstrated. Migrating on-premises email to a cloud-hosted email service means you’re using a ready-made email application that runs on the provider’s infrastructure and is accessed over the internet. You don’t manage or install the software, the servers, the storage, or the operating system; the provider handles maintenance, updates, and security. You simply use the email service, paying for and configuring it at a user level. This differs from Platform as a Service, where you’re given a platform to develop or deploy your own applications, and from Infrastructure as a Service, where you rent virtual machines and recreate the stack yourself. DaaS would not fit this scenario, since the focus is on using a software application (email) rather than delivering a desktop or data service.
Question 5
Which IP/mask combination would configure a router interface to create a connected route for the entire classful network 172.16.0.0/16?
Correct Answer:
172.16.1.1/16
Explanation:
The main idea is that a router builds a directly connected network from the IP address and the subnet mask configured on the interface. For a classful Class B network, 172.16.0.0 uses the default /16 mask (255.255.0.0). When you configure an interface with an address that falls inside 172.16.0.0/16 and use a /16 mask, the router computes the network as 172.16.0.0/16, creating a connected route for the entire classful network. Configuring 172.16.1.1 with a /16 mask does exactly this: the network becomes 172.16.0.0/16, so the router has a connected route to the whole 172.16.0.0/16 block. In contrast, a /24 mask would split into smaller networks (like 172.16.1.0/24 or 172.16.0.0/24), not the entire 172.16.0.0/16 block, and a /32 mask would only reference a single host. So the address that best creates a connected route for the entire 172.16.0.0/16 is the one with the /16 mask.
Question 1
Exam overview

About this Exam

Prepare with the Cisco Certified Entry Networking Technician (CCENT) Practice Exam practice quiz. This question bank includes 10 questions covering mask, ipv6, address, port, and email. Use it to review important concepts, identify knowledge gaps, and build confidence for the related exam, course, or assessment.

More details

Additional Information

Cisco Certified Entry Networking Technician (CCENT) Practice Exam

This practice set contains 10 questions from the matching question bank and focuses on mask, ipv6, address, port, and email. Work through each question carefully, review the provided solutions, and revisit topics that need more study before your next attempt.

This is an independent study resource intended for practice and review; it is not an official examination or an endorsement by any organization named in the title.

Quiz information

Frequently Asked Questions

The complete question count is available after full access is unlocked.
No fixed duration is currently configured for this quiz.
Question explanations are included where they are available in the quiz content, helping you review the reasoning after answering.
Yes. You can retake the practice test again as you continue studying during your available access period.
After your access is confirmed, you can continue into the complete practice exam from this quiz flow.
Unless explicitly stated otherwise, this page provides independent practice material for study and exam preparation and is not the official examination itself.
Keep studying

Related Questions