Courseiva
← Back to ENCOR 350-401 questions

Scenario-based practice

Access Control List (ACL) Scenarios

Practise 350-401 ACL questions covering standard vs extended ACLs, top-down processing, implicit deny, inbound vs outbound placement, and troubleshooting traffic that is unexpectedly blocked or permitted.

15
scenario questions
350-401
exam code
Cisco
vendor

Scenario guide

How to approach access control list (acl) scenarios

ACL questions test your ability to read, write, and place access lists correctly. They appear as configuration tasks, troubleshooting scenarios, and exhibit-based questions showing ACL output. The CCNA covers standard and extended ACLs for both IPv4 and IPv6.

Quick answer

ACL questions usually test top-down rule processing, source and destination matching, protocol or port logic, and where the ACL should be applied.

Standard versus extended ACL behaviour.

Top-down processing and the implicit deny rule.

Source, destination, protocol and port matching.

Inbound versus outbound ACL placement.

Related practice questions

Related 350-401 topic practice pages

Scenario questions usually connect to one or more exam topics. Use these links to review the underlying concepts behind the scenario.

Practice set

Practice scenarios

Question 1mediumdrag order
Study the full ACL explanation →

Drag and drop the steps of named ACL modification using sequence numbers into the correct order, from first to last.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5
Question 2mediummultiple choice
Full question →

A network administrator is deploying Cisco Application Centric Infrastructure (ACI) and needs to allow two endpoint groups (EPGs) in different bridge domains to communicate while applying a contract that permits only TCP port 443. Which ACI construct provides the policy enforcement point where the contract is applied?

Question 3hardmultiple choice
Study the full ACL explanation →

A network engineer is using Ansible to push ACL changes to a group of Cisco IOS routers. The playbook uses the ios_acl_interfaces module to bind ACLs to interfaces. After running the playbook, the engineer notices that some routers have the ACL applied inbound instead of outbound as intended. The playbook specifies 'direction: outbound'. What is the most likely cause of this issue?

Question 4mediummultiple choice
Open the full BGP breakdown →

Consider the following BGP configuration:

router bgp 65000

bgp router-id 1.1.1.1

neighbor 10.1.1.2 remote-as 65001
 neighbor 10.1.1.2 route-map SET_MED out

! route-map SET_MED permit 10 set metric 50

What is the effect of this configuration?

Question 5hardmultiple choice
Review the full routing breakdown →

A network engineer runs the following command on Router R1:

R1# show ip access-lists

Extended IP access list 150

10 permit tcp 10.0.0.0 0.255.255.255 any eq 23 (2 matches)
    
20 deny tcp any any eq 23 (8 matches)
    
30 permit tcp 172.16.0.0 0.0.255.255 any eq 22 (4 matches)
    
40 deny tcp any any eq 22 (1 match)
    
50 permit ip any any (15 matches)

Based on this output, what can be concluded?

Question 6mediummultiple choice
Full question →

Given the following configuration:

interface GigabitEthernet0/0
 ip address 10.0.0.1 255.255.255.0
 ip access-group 101 in

!

access-list 101 permit tcp 192.168.1.0 0.0.0.255 any eq 80
access-list 
101 deny ip any any

What is the effect of this configuration?

Question 7hardmultiple choice
Study the full AAA explanation →

An enterprise is implementing Cisco TrustSec (CTS) to enforce role-based access control. The network engineer configures the switch with 'cts role-based enforcement' and 'cts manual' on an interface connecting to a trusted Cisco switch. The engineer also configures Security Group Tags (SGTs) on the RADIUS server. However, traffic between two hosts in different SGTs is not being filtered as expected. The engineer checks 'show cts role-based counters' and sees no drops. What is the most likely reason for the lack of enforcement?

Question 8mediummultiple choice
Study the full ACL explanation →

A network engineer is configuring 802.1X on a Cisco switch for a guest network. The engineer wants to allow guests to access the internet after authentication but restrict access to internal resources. The engineer configures the switch with 'authentication port-control auto' and a downloadable ACL (dACL) from the RADIUS server. After a guest authenticates, the engineer tests connectivity and finds that the guest can access internal servers. What is the most likely cause?

Question 9mediummultiple choice
Read the full NAT/PAT explanation →

A network engineer is configuring a Cisco router to provide internet access to a small office using a single public IP address assigned by the ISP. The engineer wants to allow internal hosts to initiate connections to the internet, but also needs to make a web server on the internal network reachable from the internet. The engineer configures a standard access list for NAT and an ip nat inside source list command. However, external users cannot reach the internal web server. What is the most likely cause?

Question 10mediummultiple choice
Open the full VLAN trunking answer →

A network engineer is configuring dynamic ARP inspection (DAI) on a Cisco switch to prevent ARP spoofing. The switch has DHCP snooping enabled and the DHCP server is trusted. The engineer enables DAI on VLAN 10 and configures 'ip arp inspection trust' on the port connected to the DHCP server. After enabling DAI, some legitimate ARP replies from hosts are being dropped. The engineer checks the DAI statistics and sees 'ARP ACL drops' incrementing. What is the most likely reason?

Question 11mediummultiple choice
Open the full BGP breakdown →

Examine the following BGP configuration:

router bgp 65001

bgp log-neighbor-changes

neighbor 10.1.1.1 remote-as 65002
 neighbor 10.1.1.1 route-map SET_MED out

! route-map SET_MED permit 10 set metric 50

What is the purpose of this configuration?

Question 12mediummultiple choice
Study the full IPv6 explanation →

Consider the following IPv6 access-list on a Cisco IOS-XE router: ``` ipv6 access-list PERMIT_ICMP

permit icmp any any echo-request
 permit icmp any any echo-reply
 deny ipv6 any any

!

interface GigabitEthernet0/0

ipv6 traffic-filter PERMIT_ICMP in ``` What is the effect of this configuration?

Question 13mediummultiple choice
Open the full BGP breakdown →

Examine the following BGP configuration on a Cisco IOS-XE router: ```

router bgp 65000

bgp default local-preference 150

neighbor 10.1.1.1 remote-as 65001
 neighbor 10.1.1.1 password cisco123
 neighbor 10.1.1.1 route-map SET-MED out

! route-map SET-MED permit 10 set metric 50 ``` What is the effect of the route-map on outbound updates to 10.1.1.1?

Question 14mediummatching
Study the full ACL explanation →

Drag and drop each ACL action on the left to its matching result on the right.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Packet is allowed to pass through the ACL

Packet is discarded and not forwarded

Adds a descriptive comment to the ACL entry

Generates a syslog message when a packet matches the entry

Assigns a numeric identifier to the ACL line for insertion/deletion

Question 15mediummultiple choice
Full question →

Given the following configuration:

ip access-list extended FILTER
 permit tcp any host 10.1.1.1 eq 22
 permit icmp any any echo-reply

!

interface GigabitEthernet0/4
 ip access-group FILTER in

What traffic is permitted?

These 350-401 practice questions are part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style 350-401 questions with detailed explanations, topic-based practice, mock exams, readiness tracking, and study analytics.