Hi there,
To answer your questions:
1) All ACLs can be prefixed with a sequence number. Typically each ACE in an ACL is sequentially numbered from 10 in increments of 10. This means if you wanted to insert an ACE between line 10 and 20 you would do something like:
!
ip access-list ex FOO
15 permit ip 192.168.11.0 255.255.255.0 any
!
So the ACL would look like
Extended ip access list FOO
10 permit 192.168.10.0 255.255.255.0 any
15 permit 192.168.11.0 255.255.255.0 any
20 permit 192.168.20.0 255.255.255.0 any
2) Yes, the ACL should be added to the interface without interrupting traffic.
3) it is true that all ACLs have an implicitly deny at the end, with one exception that when the ACL is empty an implicit permit any any is present.
cheers,
Seb.