mediumMultiple Choice
CCNP Practice Question: Consider the following IPv6 access-list on a…
Consider the following IPv6 access-list on a Cisco IOS-XE router: ``` ipv6 access-list PERMIT_ICMP
permit icmp any any echo-request permit icmp any any echo-reply deny ipv6 any any
!
interface GigabitEthernet0/0
ipv6 traffic-filter PERMIT_ICMP in ``` What is the effect of this configuration?
⚠ Common exam trap
Cisco often tests the distinction between ICMPv6 and ICMPv4, and the trap here is that candidates assume 'icmp' in an IPv6 ACL permits all ICMPv6 types, when in fact only the explicitly listed types (echo-request, echo-reply) are allowed.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Only IPv6 ping (echo-request and echo-reply) is allowed inbound on Gi0/0; all other IPv6 traffic is dropped.
The ACL explicitly permits only ICMPv6 echo-request and echo-reply messages, which are the packets used by IPv6 ping. The final 'deny ipv6 any any' statement drops all other IPv6 traffic. Since the ACL is applied inbound on GigabitEthernet0/0 via the 'ipv6 traffic-filter' command, only IPv6 ping is allowed in; all other IPv6 packets are denied.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Only IPv6 ping (echo-request and echo-reply) is allowed inbound on Gi0/0; all other IPv6 traffic is dropped.
Why this is correct
The ACL on Gi0/0 contains two permit statements matching ICMPv6 echo-request (type 128) and echo-reply (type 129), followed by an explicit deny statement for all other IPv6 traffic. Because the ACL is applied inbound with the 'in' keyword, only packets entering the interface that match these two permit statements are forwarded; any other IPv6 packet is dropped. This is a common security practice to allow ping while blocking other ICMPv6 control messages.
- ✗
All ICMPv6 traffic is permitted inbound on Gi0/0.
Why it's wrong here
ICMPv6 encompasses many message types beyond echo-request and echo-reply, such as neighbor solicitation (type 135), neighbor advertisement (type 136), router solicitation (type 133), and router advertisement (type 134). The ACL in question explicitly permits only types 128 and 129, so claiming all ICMPv6 is allowed is false. Unspecified ICMPv6 types would not match the permit statements and would be caught by the final deny, resulting in dropping.
- ✗
The ACL is applied outbound, so it filters traffic leaving Gi0/0.
Why it's wrong here
The 'in' keyword in the ACL ipv6 access-group command indicates the filter is applied to traffic entering the interface, not leaving it. If the ACL were applied outbound, it would inspect packets exiting Gi0/0, but the question's configuration specifies inbound processing. Misreading the direction would lead to incorrect placement, as applying it outbound would not achieve the desired filtering of incoming ping traffic.
- ✗
The ACL permits all IPv6 traffic because the deny statement is at the end.
Why it's wrong here
ACL packet matching is sequential; a packet is evaluated against each line until a match occurs. Permitting all IPv6 traffic would require a permit ipv6 any any statement, but the ACL instead ends with an explicit deny ipv6 any any. The deny statement at the end does not 'permit' anything; it is the default drop for unmatched packets, ensuring that only the explicitly permitted echo-request and echo-reply traffic is forwarded.
Visual reference
About these practice questions
One of 1,923 original 350-401 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.