ACL questions test your ability to read, write, and place access lists correctly. They appear as configuration tasks, troubleshooting scenarios, and exhibit-based questions showing ACL output. The CCNA covers standard and extended ACLs for both IPv4 and IPv6.
Start Scenario PracticeDrag and drop the steps of named ACL modification using sequence numbers into the correct order, from first to last.
Explanation: Sequence numbers allow editing named ACLs without re-entering all entries. The correct order is: view current entries, insert a new entry at a specific sequence, then verify the updated ACL.
A network administrator is deploying Cisco Application Centric Infrastructure (ACI) and needs to allow two endpoint groups (EPGs) in different bridge domains to communicate while applying a contract that permits only TCP port 443. Which ACI construct provides the policy enforcement point where the contract is applied?
Explanation: ACI applies contracts at the leaf switch, which acts as the policy enforcement point for the attached EPGs. The APIC distributes the compiled policy, but the leaf hardware renders and enforces the permit for TCP port 443 between the two EPGs in their respective bridge domains.
A network engineer is using Ansible to push ACL changes to a group of Cisco IOS routers. The playbook uses the ios_acl_interfaces module to bind ACLs to interfaces. After running the playbook, the engineer notices that some routers have the ACL applied inbound instead of outbound as intended. The playbook specifies 'direction: outbound'. What is the most likely cause of this issue?
Explanation: The ios_acl_interfaces module in Ansible expects the direction parameter to be specified as 'in' or 'out', not 'outbound'. When 'direction: outbound' is used, the module either ignores the value or defaults to 'in', causing the ACL to be applied inbound instead of outbound. This is a common parameter naming mismatch between the Ansible module and the engineer's expectation.
Consider the following BGP configuration: router bgp 65000 bgp router-id 1.1.1.1 neighbor 10.1.1.2 remote-as 65001 neighbor 10.1.1.2 route-map SET_MED out ! route-map SET_MED permit 10 set metric 50 What is the effect of this configuration?
Explanation: The route-map SET_MED is applied to outbound updates to neighbor 10.1.1.2, setting the MED (Multi-Exit Discriminator) attribute to 50. MED is a metric that influences inbound path selection in the neighboring AS (AS 65001), telling its routers which path to prefer when multiple entry points exist into AS 65000. Therefore, option A correctly describes the effect.
A network engineer runs the following command on Router R1: R1# show ip access-lists Extended IP access list 150 10 permit tcp 10.0.0.0 0.255.255.255 any eq 23 (2 matches) 20 deny tcp any any eq 23 (8 matches) 30 permit tcp 172.16.0.0 0.0.255.255 any eq 22 (4 matches) 40 deny tcp any any eq 22 (1 match) 50 permit ip any any (15 matches) Based on this output, what can be concluded?
Explanation: The ACL 150 processes entries sequentially. Telnet (TCP port 23) from 192.168.1.0/24 is not explicitly permitted by the first permit statement (which only allows source 10.0.0.0/8) and is denied by the subsequent deny statement (line 20). SSH (TCP port 22) from 10.0.0.0/8 is permitted by line 10 only for Telnet, not SSH; line 30 permits SSH only from 172.16.0.0/16, so SSH from 10.0.0.0/8 hits line 40 (deny) and is denied. The implicit deny at the end would also block unmatched traffic, but here explicit denies apply.
+10 more scenario questions available
Practice all Access Control List (ACL) ScenariosACL questions test your ability to read, write, and place access lists correctly. They appear as configuration tasks, troubleshooting scenarios, and exhibit-based questions showing ACL output. The CCNA covers standard and extended ACLs for both IPv4 and IPv6. These appear throughout the 350-401 and require you to apply your knowledge, not just recall facts.
Cisco doesn't publish an exact breakdown, but scenario-based questions (especially exhibit and command-output formats) make up a significant portion of the 350-401. Practicing each scenario type ensures you're ready for any format.
Yes. Courseiva provides free 350-401 scenario practice across all official exam domains. The platform includes scenario-based questions, command-output interpretation, topic-based practice, mock exams, and readiness tracking — no account required.
Launch a full Access Control List (ACL) Scenarios session with instant scoring and detailed explanations.
Start Scenario Practice →