Courseiva
mediumMultiple Choice

CCNP Practice Question: Runs the following command on Router R1: R1# show…

A network engineer runs the following command on Router R1:

R1# show access-lists 130

Extended IP access list 130

10 permit icmp host 10.1.1.1 any echo (8 matches)
    
20 permit icmp host 10.1.1.1 any echo-reply (5 matches)
    
30 deny icmp any any (3 matches)
    
40 permit ip any any (12 matches)

Based on this output, what can be concluded?

⚠ Common exam trap

Cisco often tests the misconception that a 'permit ip any any' at the end of an ACL permits all traffic, including ICMP, but candidates must remember that earlier explicit deny statements for a specific protocol take precedence and are not overridden by a later permit of all IP.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

ICMP packets from sources other than 10.1.1.1 are denied.

The ACL explicitly denies all ICMP traffic (line 30) except for echo and echo-reply from host 10.1.1.1 (lines 10 and 20). The 'deny icmp any any' statement matches ICMP packets from any source other than 10.1.1.1, and the 'permit ip any any' at line 40 only permits non-ICMP traffic. Therefore, ICMP packets from sources other than 10.1.1.1 are denied.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    ICMP packets from sources other than 10.1.1.1 are denied.

    Why this is correct

    This is correct because the ACL's logic is explicit: entries 10 and 20 only match ICMP echo requests and echo replies sourced from 10.1.1.1. A final explicit deny entry (entry 30) then catches every other ICMP packet, regardless of its type or destination, and drops it. Thus, any ICMP packet with a source address different from 10.1.1.1 is denied, which makes the statement accurate.

  • ✗

    All ICMP traffic is permitted.

    Why it's wrong here

    The claim is false because the ACL is restrictive rather than permissive: it permits only two ICMP types (echo and echo-reply) from a single host. All other ICMP message types—such as destination unreachable, time-exceeded, or parameter problem—are not matched by the permit entries and are therefore dropped by the final deny. So 'all ICMP traffic is permitted' is the opposite of the configured behavior.

  • ✗

    The ACL permits all traffic from 10.1.1.1.

    Why it's wrong here

    This is incorrect because the permit entries are protocol- and type-specific: they match only ICMP with type 8 (echo) and type 0 (echo-reply) from host 10.1.1.1. Traffic from that same host using other protocols—TCP (e.g., SSH, HTTP) or UDP (e.g., DNS)—does not match any permit statement and hits the deny-all at the end. Thus, the ACL does not permit 'all' traffic even from the specified source.

  • ✗

    The ACL is applied inbound on an interface.

    Why it's wrong here

    The displayed ACL output, which likely comes from 'show access-lists' or a running configuration snippet, contains only ordered ACEs with sequence numbers and hit counters; it shows neither an interface binding nor a direction such as 'in'. An ACL can be applied either inbound or outbound, but that information must be found in the interface configuration, such as 'ip access-group ACLNAME in'. Without that context, stating the ACL is applied inbound is unsupported.

Visual reference

Source Router + ACL permit 10.0.0.0/8 deny any Server 10.0.0.5 ✓ 192.168.1.1 ✗ dropped ACLs evaluate top-down; first match wins — implicit deny all at end

About these practice questions

One of 1,923 original 350-401 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.