Courseiva
mediumMultiple Choice

CCNP Practice Question: Consider the following IPv6 access-list on a…

Consider the following IPv6 access-list on a Cisco IOS-XE router: ``` ipv6 access-list PERMIT_ICMP

permit icmp any any echo-request
 permit icmp any any echo-reply
 deny ipv6 any any

!

interface GigabitEthernet0/0

ipv6 traffic-filter PERMIT_ICMP in ``` What is the effect of this configuration?

⚠ Common exam trap

Cisco often tests the distinction between ICMPv6 and ICMPv4, and the trap here is that candidates assume 'icmp' in an IPv6 ACL permits all ICMPv6 types, when in fact only the explicitly listed types (echo-request, echo-reply) are allowed.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Only IPv6 ping (echo-request and echo-reply) is allowed inbound on Gi0/0; all other IPv6 traffic is dropped.

The ACL explicitly permits only ICMPv6 echo-request and echo-reply messages, which are the packets used by IPv6 ping. The final 'deny ipv6 any any' statement drops all other IPv6 traffic. Since the ACL is applied inbound on GigabitEthernet0/0 via the 'ipv6 traffic-filter' command, only IPv6 ping is allowed in; all other IPv6 packets are denied.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Only IPv6 ping (echo-request and echo-reply) is allowed inbound on Gi0/0; all other IPv6 traffic is dropped.

    Why this is correct

    The ACL on Gi0/0 contains two permit statements matching ICMPv6 echo-request (type 128) and echo-reply (type 129), followed by an explicit deny statement for all other IPv6 traffic. Because the ACL is applied inbound with the 'in' keyword, only packets entering the interface that match these two permit statements are forwarded; any other IPv6 packet is dropped. This is a common security practice to allow ping while blocking other ICMPv6 control messages.

  • ✗

    All ICMPv6 traffic is permitted inbound on Gi0/0.

    Why it's wrong here

    ICMPv6 encompasses many message types beyond echo-request and echo-reply, such as neighbor solicitation (type 135), neighbor advertisement (type 136), router solicitation (type 133), and router advertisement (type 134). The ACL in question explicitly permits only types 128 and 129, so claiming all ICMPv6 is allowed is false. Unspecified ICMPv6 types would not match the permit statements and would be caught by the final deny, resulting in dropping.

  • ✗

    The ACL is applied outbound, so it filters traffic leaving Gi0/0.

    Why it's wrong here

    The 'in' keyword in the ACL ipv6 access-group command indicates the filter is applied to traffic entering the interface, not leaving it. If the ACL were applied outbound, it would inspect packets exiting Gi0/0, but the question's configuration specifies inbound processing. Misreading the direction would lead to incorrect placement, as applying it outbound would not achieve the desired filtering of incoming ping traffic.

  • ✗

    The ACL permits all IPv6 traffic because the deny statement is at the end.

    Why it's wrong here

    ACL packet matching is sequential; a packet is evaluated against each line until a match occurs. Permitting all IPv6 traffic would require a permit ipv6 any any statement, but the ACL instead ends with an explicit deny ipv6 any any. The deny statement at the end does not 'permit' anything; it is the default drop for unmatched packets, ensuring that only the explicitly permitted echo-request and echo-reply traffic is forwarded.

Visual reference

Source Router + ACL permit 10.0.0.0/8 deny any Server 10.0.0.5 ✓ 192.168.1.1 ✗ dropped ACLs evaluate top-down; first match wins — implicit deny all at end

About these practice questions

One of 1,923 original 350-401 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.