An ACL interview question often starts with “standard or extended?” and ends with a packet that unexpectedly disappears. The useful answer connects match fields, rule order, interface direction and the traffic that was never explicitly permitted.
Short answer: A classic IPv4 interface access control list is an ordered packet filter: the first matching entry decides permit or deny, and packets that match no entry are denied implicitly.[1] A standard IPv4 ACL matches the source address; an extended ACL can also match destination address, protocol and TCP/UDP ports.[1]