hardMultiple Select
CCNP Practice Question: Which three statements about extended ACLs on…
Which three statements about extended ACLs on Cisco IOS are true? (Choose three.)
⚠ Common exam trap
350-401 often tests the misconception that extended ACLs can filter on MAC addresses or only source IP, but they operate at Layer 3 and 4, not Layer 2.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Extended ACLs can filter based on source and destination IP addresses.
Option A is correct because extended ACLs match on both source and destination IP addresses, unlike standard ACLs that match only the source. Option B is correct because extended ACLs can specify Layer 4 protocol (TCP/UDP) and port numbers using operators like eq, gt, lt, and range. Option C is correct because ACLs are evaluated top-down, and the first matching statement is applied; once a match occurs, no further entries are checked. Option D is not correct because MAC address filtering requires MAC ACLs (e.g., mac access-list), not extended IP ACLs. Option E is not correct because filtering solely on source IP is the behavior of standard ACLs, not extended ACLs.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Extended ACLs can filter based on source and destination IP addresses.
Why this is correct
Extended ACLs match on Layer 3 and Layer 4 fields, including both source and destination addresses, unlike standard ACLs which filter on source only. This satisfies the stem's requirement by confirming the broader matching capability that distinguishes extended from standard ACLs on Cisco IOS.
- ✓
Extended ACLs can filter based on TCP or UDP port numbers.
Why this is correct
Extended ACLs inspect Layer 4 headers, permitting or denying traffic by TCP or UDP port number, plus ICMP types. This satisfies the stem's requirement by confirming granular protocol and service filtering, a capability standard ACLs lack since they match source addresses only.
- ✓
Extended ACLs are processed in order until a matching permit or deny statement is found.
Why this is correct
Cisco IOS evaluates extended ACL entries sequentially, top to bottom, stopping at the first statement whose criteria match the packet. No later entries are examined once a match occurs, so entry order directly determines filtering behaviour and must be planned carefully.
- ✗
Extended ACLs can filter based on source MAC addresses.
Why it's wrong here
Extended ACLs operate at layers 3 and 4, matching IP addresses, protocols, and ports; they cannot inspect layer 2 MAC addresses. It is tempting because MAC filtering exists on switches, but that requires port security or MAC ACLs, not an extended IP ACL.
- ✗
Extended ACLs only filter traffic based on the source IP address.
Why it's wrong here
Extended ACLs match source and destination addresses, protocol, and port, so restricting them to source IP alone describes a standard ACL. It is tempting because every ACL inspects source addresses, but that limited capability belongs to numbered standard ACLs, not extended ones.
Visual reference
Quick reference
Access Control Model Comparison
| Model | Acronym | Who Controls Access? | Best For |
|---|---|---|---|
| Discretionary Access Control | DAC | Resource owner | Small teams, file shares |
| Mandatory Access Control | MAC | System / security labels | Classified govt / military |
| Role-Based Access Control | RBAC | Administrator (via roles) | Enterprise environments |
| Attribute-Based Access Control | ABAC | Policy engine (user + resource attributes) | Fine-grained, dynamic policies |
| Rule-Based Access Control | RuBAC | System rules / ACLs | Firewall rules, network ACLs |
About these practice questions
This 350-401 question is part of Courseiva's 1,923-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.