A router interface applies this ACL inbound:
10 deny tcp any any eq 80 20 permit ip any any
A user reports that web browsing to a server by IP address fails, but ping works. Which statement best explains the behavior?
200-301 · topic practice
Use this page to practise 200-301 ACL practice questions. The goal is not to memorise dumps, but to understand the concept, review the explanation and improve your exam readiness.
What the exam tests
ACL questions usually test top-down rule processing, source and destination matching, protocol or port logic, and where the ACL should be applied.
Standard versus extended ACL behaviour.
Top-down processing and the implicit deny rule.
Source, destination, protocol and port matching.
Inbound versus outbound ACL placement.
Practice set
20 questions · select your answer, then reveal the explanation
A router interface applies this ACL inbound:
10 deny tcp any any eq 80 20 permit ip any any
A user reports that web browsing to a server by IP address fails, but ping works. Which statement best explains the behavior?
A switch displays the following output:
Switch# show interfaces trunk
Port Mode Encapsulation Status Native vlan Gi1/0/24 on 802.1q trunking 99
Port Vlans allowed on trunk Gi1/0/24 10,20,30
Port Vlans active in management domain Gi1/0/24 10,20,30,40
Users in VLAN 40 cannot reach resources across this trunk.
What is the most likely reason?
A switch has DHCP snooping enabled and Dynamic ARP Inspection enabled on VLAN 30. A printer with a static IP on VLAN 30 cannot communicate because its ARP packets are being dropped.
What is the best fix?
Watch out for
Free account
Create a free account to save your results and see which topics improve across sessions.
Focused ACL sessions
Every question in these sessions is drawn from the ACL domain — nothing else.
Related practice questions
Move into related areas when this topic feels solid.
Practise IPv4 subnetting, CIDR, masks, host ranges and subnet selection.
Practise OSPF neighbours, router IDs, metrics, areas and routing-table interpretation.
Practise VLANs, access ports, trunks, allowed VLANs and switching scenarios.
Practise spanning tree, root bridge election, port roles and STP troubleshooting.
Practise LACP, PAgP, port-channel behaviour and bundle requirements.
Practise standard and extended ACLs, permit/deny logic and traffic filtering.
Practise static NAT, dynamic NAT, PAT and inside/outside address translation.
Practise DHCP scopes, relay, leases and troubleshooting.
Practise routing-table output, longest-prefix match, AD and route selection.
Practise trunk verification and VLAN forwarding across switches.
Practise WLAN security, authentication and wireless architecture concepts.
Practise IPv6 addressing, routes, neighbour discovery and common IPv6 exam traps.
A free account saves results across sessions and highlights which topics need work.
Sign up free