ACL questions test your ability to read, write, and place access lists correctly. They appear as configuration tasks, troubleshooting scenarios, and exhibit-based questions showing ACL output. The CCNA covers standard and extended ACLs for both IPv4 and IPv6.
Start Scenario PracticeA company uses Cisco ISE for network access control. They want to authenticate users connecting via VPN using multi-factor authentication. Which solution integrates with ISE to provide MFA for AnyConnect VPN?
Explanation: Cisco Duo integrates with ISE and AnyConnect to provide multi-factor authentication for VPN access.
A Cisco FTD device managed by FMC is processing traffic. An access control rule is configured with the action 'Interactive Block'. What behavior does this action trigger?
Explanation: The Interactive Block action in a Cisco FTD access control rule is designed to give users a chance to override a block decision. When traffic matches the rule, the user's browser is presented with a customizable block page that includes a button allowing them to bypass the block for a configurable time period (default 600 seconds). This is distinct from a hard Block, which silently drops traffic, and from Allow, which permits it outright.
An engineer is troubleshooting a Cisco ASA firewall and notices that traffic from a specific subnet is being dropped. The engineer wants to verify if the drop is due to an access control list (ACL) or an inspection policy. Which command should be used to see the reason for packet drops?
Explanation: The 'show asp drop' command displays packet drop statistics from the Accelerated Security Path (ASP) on a Cisco ASA. It provides a detailed breakdown of why packets are dropped, including drops due to ACLs, inspection policies, or other security checks. This makes it the correct tool to differentiate between ACL and inspection policy drops.
A Cisco FTD is deployed in inline mode and configured with an access control policy. The policy includes rules with actions: Trust, Allow, Block, and Interactive Block. Which two statements about these actions are correct? (Choose two.)
Explanation: Option A is correct because the Trust action in a Cisco FTD access control policy terminates policy evaluation for that connection and bypasses all subsequent inspection, including SSL, IPS, and file/malware inspection, effectively allowing the traffic without further deep inspection. Option B is correct because the Interactive Block action permits the user to proceed after being presented with a customizable block page (a user-response page), unlike the Block action which silently drops the traffic. Option C is incorrect because the default action when no rule matches is Block (or Block with reset), not Allow. Option D is incorrect because the Block action drops the traffic and logs it, it does not allow it to pass. Option E is incorrect because the Allow action permits the traffic and subjects it to all configured inspection modules (IPS, URL filtering, malware, etc.), not URL filtering alone.
A security architect is designing network access control for a campus network. The requirement is to authenticate users before granting network access and to enforce policies based on user identity and device posture. Which solution should be deployed?
Explanation: Cisco ISE is the correct solution because it provides centralized policy-based network access control that authenticates users via 802.1X, MAB, or web authentication, and enforces dynamic VLAN assignment, ACLs, or SGTs based on user identity and device posture (e.g., compliance with antivirus, OS patches). Unlike a generic AAA server, ISE integrates with posture assessment (via AnyConnect or NAC Agent) and supports profiling, guest access, and BYOD onboarding, directly meeting the requirement for identity- and posture-based enforcement.
+10 more scenario questions available
Practice all Access Control List (ACL) ScenariosACL questions test your ability to read, write, and place access lists correctly. They appear as configuration tasks, troubleshooting scenarios, and exhibit-based questions showing ACL output. The CCNA covers standard and extended ACLs for both IPv4 and IPv6. These appear throughout the 350-701 and require you to apply your knowledge, not just recall facts.
Cisco doesn't publish an exact breakdown, but scenario-based questions (especially exhibit and command-output formats) make up a significant portion of the 350-701. Practicing each scenario type ensures you're ready for any format.
Yes. Courseiva provides free 350-701 scenario practice across all official exam domains. The platform includes scenario-based questions, command-output interpretation, topic-based practice, mock exams, and readiness tracking — no account required.
Launch a full Access Control List (ACL) Scenarios session with instant scoring and detailed explanations.
Start Scenario Practice →