Courseiva

CCNA Access Control List (ACL) Practice Question

Exhibit

Source subnet: 10.20.30.0/24
Requirement: block Telnet, allow HTTP and HTTPS

Users in 10.20.30.0/24 should be allowed to browse the web but should not be able to open Telnet sessions to any remote device. Which access list entry best meets the requirement?

⚠ Common exam trap

A common trap is selecting an ACL that denies UDP port 23 or denies traffic based on source port 23. Telnet always uses TCP destination port 23, so only a deny statement with 'tcp' and 'eq 23' blocks it effectively. Another trap is confusing inbound and outbound ACLs: blocking Telnet to the subnet does not prevent users from initiating outbound Telnet sessions.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

deny tcp 10.20.30.0 0.0.0.255 any eq 23

Option A is correct because Telnet uses TCP port 23, and the entry `deny tcp 10.20.30.0 0.0.0.255 any eq 23` blocks outbound Telnet from the 10.20.30.0/24 subnet to any remote destination while leaving other traffic (such as web browsing) unaffected. The wildcard mask 0.0.0.255 correctly matches the /24 source subnet, and placing the source before `any` reflects traffic originating from those users. Option B is wrong because Telnet is TCP-based, not UDP, so denying UDP port 23 would not stop Telnet sessions. Option C reverses the source and destination, blocking Telnet destined to the users rather than originated by them. Option D is a permit for TCP port 80 (HTTP) and does not deny Telnet at all.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    deny tcp 10.20.30.0 0.0.0.255 any eq 23

    Why this is correct

    Telnet uses TCP port 23, so this entry blocks Telnet while permitting all other traffic, including web browsing, from the subnet. The wildcard mask 0.0.0.255 correctly matches 10.20.30.0/24, satisfying the requirement to deny Telnet to any remote device.

  • ✗

    deny udp 10.20.30.0 0.0.0.255 any eq 23

    Why it's wrong here

    Telnet uses TCP port 23, so denying UDP 23 blocks no Telnet traffic at all; the protocol mismatch means the ACL never matches. It is tempting because port 23 is the correct Telnet port, and a UDP deny would be right for blocking a UDP-based service such as TFTP or SNMP.

    When this WOULD be correct

    In a scenario where the question specifies that UDP traffic on port 23 should be blocked due to a specific application requirement or security policy, option B would be the correct answer. For example, if the question stated that UDP-based services on port 23 were being exploited and needed to be restricted, this option would apply.

  • ✗

    deny tcp any 10.20.30.0 0.0.0.255 eq 23

    Why it's wrong here

    That blocks inbound Telnet to the subnet, not outbound sessions from the users.

    When this WOULD be correct

    In a different scenario where the question specifies that any device trying to initiate a Telnet session to the 10.20.30.0/24 subnet should be denied, option C would be correct as it would effectively block all Telnet attempts from any source to that subnet.

  • ✗

    permit tcp 10.20.30.0 0.0.0.255 any eq 80

    Why it's wrong here

    This entry permits only outbound HTTP to any destination; it never denies Telnet, so Telnet traffic falls through to the implicit deny only if no later permit exists, and it also blocks HTTPS and other browsing. A web-only permit is appropriate when the requirement is restricting traffic to specific ports.

    When this WOULD be correct

    In a different scenario where the question asks for an access list entry to allow web browsing while explicitly permitting HTTP traffic from the 10.20.30.0/24 subnet, option D would be correct. For example, if the question required allowing users to access web services while not mentioning any restrictions on Telnet, this option would fit.

Option-by-option analysis

Why each answer is right or wrong

Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The 200-301 exam frequently reuses these exact scenarios with slightly different constraints.

✓deny tcp 10.20.30.0 0.0.0.255 any eq 23Correct answer▾

Why this is correct

Telnet uses TCP port 23, so this entry blocks Telnet while permitting all other traffic, including web browsing, from the subnet. The wildcard mask 0.0.0.255 correctly matches 10.20.30.0/24, satisfying the requirement to deny Telnet to any remote device.

✗deny udp 10.20.30.0 0.0.0.255 any eq 23Wrong answer — click to see why▾

Why this is wrong here

Telnet uses TCP as its transport protocol, not UDP. Denying UDP port 23 would have no effect on Telnet traffic, as Telnet does not use UDP.

★ When this WOULD be the correct answer

In a scenario where the question specifies that UDP traffic on port 23 should be blocked due to a specific application requirement or security policy, option B would be the correct answer. For example, if the question stated that UDP-based services on port 23 were being exploited and needed to be restricted, this option would apply.

Why candidates choose this

Students may confuse Telnet with other protocols that use UDP, or mistakenly think that port 23 can be used with either TCP or UDP.

✗deny tcp any 10.20.30.0 0.0.0.255 eq 23Wrong answer — click to see why▾

Why this is wrong here

This entry denies inbound Telnet sessions to the subnet (from any source to 10.20.30.0/24), but the requirement is to block outbound Telnet sessions initiated by users in that subnet.

★ When this WOULD be the correct answer

In a different scenario where the question specifies that any device trying to initiate a Telnet session to the 10.20.30.0/24 subnet should be denied, option C would be correct as it would effectively block all Telnet attempts from any source to that subnet.

Why candidates choose this

Students may misinterpret the direction of traffic, confusing 'from the subnet' with 'to the subnet', or think that blocking inbound Telnet also blocks outbound.

✗permit tcp 10.20.30.0 0.0.0.255 any eq 80Wrong answer — click to see why▾

Why this is wrong here

This entry permits HTTP traffic (TCP port 80) but does not deny Telnet. Without a deny statement for Telnet, Telnet sessions would still be allowed by default (if no other deny exists).

★ When this WOULD be the correct answer

In a different scenario where the question asks for an access list entry to allow web browsing while explicitly permitting HTTP traffic from the 10.20.30.0/24 subnet, option D would be correct. For example, if the question required allowing users to access web services while not mentioning any restrictions on Telnet, this option would fit.

Why candidates choose this

Students might think that permitting web traffic implicitly blocks other traffic, but ACLs require explicit deny statements to block unwanted traffic.

Analysis generated from the official 200-301blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”

Visual reference

Source Router + ACL permit 10.0.0.0/8 deny any Server 10.0.0.5 ✓ 192.168.1.1 ✗ dropped ACLs evaluate top-down; first match wins — implicit deny all at end

About these practice questions

Courseiva writes every 200-301 question from scratch — 1,450 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 200-301 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-301 exam.