easyMultiple Choice
CCNP Practice Question: Runs the following command on Router R1: R1# show…
A network engineer runs the following command on Router R1:
R1# show ip access-lists 101
Extended IP access list 101
10 permit tcp 192.168.1.0 0.0.0.255 any eq 80 (100 matches)
20 deny tcp any any eq 23 (50 matches)
30 permit ip any any (200 matches)Based on this output, what can be concluded?
⚠ Common exam trap
Cisco often tests the sequential evaluation of ACLs, where candidates mistakenly think a later 'permit any any' overrides earlier denies, but the trap is that once a packet matches a deny rule, processing stops and the packet is dropped.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Telnet traffic from any source is denied.
The ACL explicitly denies TCP traffic to port 23 (Telnet) from any source, as shown by the 'deny tcp any any eq 23' statement with 50 matches. This rule is processed before the final permit any any, so Telnet traffic is denied regardless of the source IP.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Telnet traffic from 192.168.1.0/24 is permitted.
Why it's wrong here
The first access control entry permits only TCP port 80 (HTTP) from the 192.168.1.0/24 source network. Entry 20 then explicitly denies TCP port 23 (Telnet) from any source to any destination. Because ACLs are evaluated top-down, Telnet traffic from 192.168.1.0/24 is matched by the deny entry before any later permit rule could be considered. Therefore, Telnet from that subnet is blocked, not permitted.
- ✓
Telnet traffic from any source is denied.
Why this is correct
This is correct because the ACL contains an explicit deny statement for TCP port 23 (Telnet) with source any and destination any. When a packet matches this entry, the router immediately drops it and does not evaluate any subsequent ACEs. Even though a later entry permits all IP traffic, the sequential and first-match nature of Cisco ACLs ensures the Telnet deny takes precedence. Thus, Telnet from any source, including 192.168.1.0/24, is denied.
- ✗
HTTP traffic from any source is permitted.
Why it's wrong here
The first entry in the ACL permits HTTP (TCP port 80) only when the source address falls within 192.168.1.0/24. Traffic from any other source network does not match that ACE and therefore cannot be permitted by it. Consequently, HTTP traffic from outside 192.168.1.0/24 is either denied by later explicit rules or by the implicit deny at the end of the ACL. So HTTP is not permitted from any source; it is restricted to the specified subnet.
- ✗
All traffic is permitted because of the last entry.
Why it's wrong here
The final entry is a broad 'permit ip any any' rule, but ACL processing is sequential and stops at the first match. Telnet traffic is explicitly denied by entry 20, so it never reaches the final permit-all entry. This means the last entry does not override earlier denies; it simply permits all other unmatched traffic. Therefore, saying 'all traffic is permitted' is false because Telnet remains blocked despite the permissive final ACE.
Visual reference
About these practice questions
This 350-401 question is part of Courseiva's 1,923-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.