mediumMultiple Choice
CCNP Practice Question: Consider the following configuration: ip…
Consider the following configuration:
ip access-list extended BLOCK_TELNET deny tcp any any eq 23 permit ip any any
!
interface GigabitEthernet0/2 ip access-group BLOCK_TELNET out
Which statement is true?
⚠ Common exam trap
Cisco often tests the distinction between inbound and outbound ACL application; the trap here is that candidates may assume the ACL blocks Telnet traffic in both directions or misread the 'out' keyword as applying to traffic entering the interface, leading them to select Option A.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Telnet traffic leaving GigabitEthernet0/2 is blocked.
The ACL BLOCK_TELNET is applied to interface GigabitEthernet0/2 in the outbound direction using the 'ip access-group BLOCK_TELNET out' command. The ACL denies TCP traffic destined for port 23 (Telnet) and permits all other IP traffic. Since it is applied outbound, it filters traffic leaving the interface, meaning Telnet sessions initiated from the device or passing through the interface outbound will be blocked. Option B correctly states that Telnet traffic leaving GigabitEthernet0/2 is blocked.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Telnet traffic entering GigabitEthernet0/2 is blocked.
Why it's wrong here
The ACL is configured with the outbound keyword on GigabitEthernet0/2, so it only inspects traffic that has already been routed and is exiting the interface. Incoming Telnet traffic destined for the router or behind it is evaluated by an inbound ACL if one exists; without one, it is not dropped. Therefore, Telnet entering this interface is not blocked by this ACL.
- ✓
Telnet traffic leaving GigabitEthernet0/2 is blocked.
Why this is correct
Because the ACL is applied outbound and contains a deny statement for TCP port 23, any Telnet packet that is about to leave GigabitEthernet0/2 is dropped. The order matters: the deny telnet line is evaluated first, so the permitted implicit/explicit permit at the end does not rescue Telnet. This precisely blocks Telnet egress while permitting all other outbound traffic.
- ✗
All outbound traffic is blocked.
Why it's wrong here
The ACL is not a blanket deny-all; it only denies Telnet and then explicitly permits all other IP traffic with 'permit ip any any'. In Cisco ACLs, processing stops at the first match, so outbound packets that are not Telnet match the permit and are forwarded. Therefore, claiming all outbound traffic is blocked misreads the final permit statement.
- ✗
The ACL is incorrectly applied; only named ACLs can be applied outbound.
Why it's wrong here
Cisco IOS allows both numbered and named ACLs to be applied either inbound or outbound on an interface; there is no restriction limiting outbound application to named ACLs only. The configuration shown is syntactically valid, and the direction is a valid choice. The misconception likely arises from confusion with other platforms, but in Cisco IOS this is perfectly legal.
Visual reference
About these practice questions
This 350-401 question is part of Courseiva's 1,923-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.