Courseiva
hardMultiple Select

CCNP Practice Question: Which three statements about extended ACLs on…

Which three statements about extended ACLs on Cisco IOS are true? (Choose three.)

⚠ Common exam trap

350-401 often tests the misconception that extended ACLs can filter on MAC addresses or only source IP, but they operate at Layer 3 and 4, not Layer 2.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Extended ACLs can filter based on source and destination IP addresses.

Option A is correct because extended ACLs match on both source and destination IP addresses, unlike standard ACLs that match only the source. Option B is correct because extended ACLs can specify Layer 4 protocol (TCP/UDP) and port numbers using operators like eq, gt, lt, and range. Option C is correct because ACLs are evaluated top-down, and the first matching statement is applied; once a match occurs, no further entries are checked. Option D is not correct because MAC address filtering requires MAC ACLs (e.g., mac access-list), not extended IP ACLs. Option E is not correct because filtering solely on source IP is the behavior of standard ACLs, not extended ACLs.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Extended ACLs can filter based on source and destination IP addresses.

    Why this is correct

    Extended ACLs match on Layer 3 and Layer 4 fields, including both source and destination addresses, unlike standard ACLs which filter on source only. This satisfies the stem's requirement by confirming the broader matching capability that distinguishes extended from standard ACLs on Cisco IOS.

  • ✓

    Extended ACLs can filter based on TCP or UDP port numbers.

    Why this is correct

    Extended ACLs inspect Layer 4 headers, permitting or denying traffic by TCP or UDP port number, plus ICMP types. This satisfies the stem's requirement by confirming granular protocol and service filtering, a capability standard ACLs lack since they match source addresses only.

  • ✓

    Extended ACLs are processed in order until a matching permit or deny statement is found.

    Why this is correct

    Cisco IOS evaluates extended ACL entries sequentially, top to bottom, stopping at the first statement whose criteria match the packet. No later entries are examined once a match occurs, so entry order directly determines filtering behaviour and must be planned carefully.

  • ✗

    Extended ACLs can filter based on source MAC addresses.

    Why it's wrong here

    Extended ACLs operate at layers 3 and 4, matching IP addresses, protocols, and ports; they cannot inspect layer 2 MAC addresses. It is tempting because MAC filtering exists on switches, but that requires port security or MAC ACLs, not an extended IP ACL.

  • ✗

    Extended ACLs only filter traffic based on the source IP address.

    Why it's wrong here

    Extended ACLs match source and destination addresses, protocol, and port, so restricting them to source IP alone describes a standard ACL. It is tempting because every ACL inspects source addresses, but that limited capability belongs to numbered standard ACLs, not extended ones.

Visual reference

Source Router + ACL permit 10.0.0.0/8 deny any Server 10.0.0.5 ✓ 192.168.1.1 ✗ dropped ACLs evaluate top-down; first match wins — implicit deny all at end

Quick reference

Access Control Model Comparison

ModelAcronymWho Controls Access?Best For
Discretionary Access ControlDACResource ownerSmall teams, file shares
Mandatory Access ControlMACSystem / security labelsClassified govt / military
Role-Based Access ControlRBACAdministrator (via roles)Enterprise environments
Attribute-Based Access ControlABACPolicy engine (user + resource attributes)Fine-grained, dynamic policies
Rule-Based Access ControlRuBACSystem rules / ACLsFirewall rules, network ACLs

About these practice questions

This 350-401 question is part of Courseiva's 1,923-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.