Courseiva
Network Assurance →hardMultiple Choice

CCNP Network Assurance Practice Question

A network engineer is analyzing network traffic using Cisco IOS Embedded Packet Capture (EPC) on a Cisco ISR router. The engineer wants to capture only TCP packets with a source port of 80 and a destination IP address of 10.1.1.1. Which EPC configuration is required to achieve this?

⚠ Common exam trap

A common mix-up: candidates confuse EPC filtering with QoS or NetFlow mechanisms, such as class maps or flow records, which are not applicable to EPC.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Define an access list that permits tcp any eq 80 host 10.1.1.1, then reference it in the capture point with 'access-list'.

EPC uses an access list to filter packets. The access list 'permit tcp any eq 80 host 10.1.1.1' matches the required traffic, and it is applied to the capture point with the 'access-list' keyword. Other options involve features like class maps or flow records that are not used by EPC for filtering. The capture buffer only defines storage, not filtering.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Define a class map that matches tcp source eq 80 and destination host 10.1.1.1, then apply it to the capture point.

    Why it's wrong here

    EPC does not use class maps for filtering. Class maps are used in QoS and NetFlow configurations. While they can match traffic, they are not supported in EPC capture point configuration. EPC specifically uses access lists for filtering. Therefore, this approach would not work and is not a valid EPC configuration.

  • ✓

    Define an access list that permits tcp any eq 80 host 10.1.1.1, then reference it in the capture point with 'access-list'.

    Why this is correct

    EPC uses an access list to filter captured traffic. The access list 'permit tcp any eq 80 host 10.1.1.1' matches TCP packets with source port 80 and destination IP 10.1.1.1. This access list is then applied to the capture point using the 'access-list' keyword. This is the correct method to filter specific traffic in EPC, as it leverages standard ACL syntax to define match criteria.

  • ✗

    Define a flow record with match ipv4 source port 80 and destination address 10.1.1.1, then apply it to the capture point.

    Why it's wrong here

    Flow records are part of Flexible NetFlow, not EPC. EPC does not use flow records for filtering. While Flexible NetFlow can capture similar information, it is a separate feature. The question specifies EPC, so using a flow record is incorrect. EPC requires an access list to filter packets, not a flow record.

  • ✗

    Define a capture buffer with 'filter' option specifying tcp port 80 and host 10.1.1.1.

    Why it's wrong here

    EPC does not have a 'filter' option directly on the capture buffer. The capture buffer defines storage parameters like size and type (linear or circular). Filtering is done via an access list referenced in the capture point. The syntax suggested is not valid for EPC. Therefore, this option is incorrect.

Visual reference

Source Router + ACL permit 10.0.0.0/8 deny any Server 10.0.0.5 ✓ 192.168.1.1 ✗ dropped ACLs evaluate top-down; first match wins — implicit deny all at end

Quick reference

IPv4 Address Class Summary

ClassFirst Octet RangeDefault MaskNetworksHosts per Network
A1–126/8 (255.0.0.0)12616,777,214
B128–191/16 (255.255.0.0)16,38465,534
C192–223/24 (255.255.255.0)2,097,152254
D224–239N/AMulticast groups—
E240–255N/AReserved / experimental—

127.x.x.x is reserved for loopback. Modern networks use CIDR (classless) rather than classful addressing.

About these practice questions

This 350-401 question is part of Courseiva's 1,923-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.