Courseiva

350-401 · topic practice

Acls And Copp practice questions

Practise 350-401 ACL questions covering standard vs extended ACLs, top-down processing, implicit deny, inbound vs outbound placement, and troubleshooting traffic that is unexpectedly blocked or permitted.

Courseiva uses original exam-style practice questions designed for learning and revision. The goal is to understand the concepts, recognise exam patterns, and improve through explanations — not memorise copied exam dumps.

Editorial oversight:Johnson Ajibi· MSc IT Security, IEEE Senior Member
20 questionsDomain: Acls And Copp

What the exam tests

What to know about Acls And Copp

ACL questions usually test top-down rule processing, source and destination matching, protocol or port logic, and where the ACL should be applied.

Standard versus extended ACL behaviour.

Top-down processing and the implicit deny rule.

Source, destination, protocol and port matching.

Inbound versus outbound ACL placement.

Why learners struggle

Why Acls And Copp questions are commonly missed

ACL questions are missed when learners apply the wrong direction, overlook the implicit deny, or confuse standard ACL source-only matching with extended ACL protocol and destination matching. A single out-of-order rule or wrong interface direction makes an otherwise correct ACL fail.

  • ·Top-down first-match processing — rule order matters; the first match ends evaluation
  • ·Implicit deny — all traffic not explicitly permitted is denied at the end of every ACL
  • ·Standard ACLs match source address only — destination, protocol, and port are not considered
  • ·Extended ACLs match source, destination, protocol, and port — giving finer control
  • ·Inbound vs outbound — applying the ACL in the wrong direction blocks the wrong traffic
  • ·Standard ACLs placed near the destination to avoid blocking other traffic unnecessarily

Watch out for

Common Acls And Copp exam traps

  • ▸ACLs are processed from top to bottom; the first match wins.
  • ▸There is an implicit deny at the end of most ACLs.
  • ▸Standard ACLs match source only, while extended ACLs can match protocol, source, destination and ports.
  • ▸Applying an ACL in the wrong direction can make a correct ACL look broken.

Practice set

Acls And Copp questions

20 questions · select your answer, then reveal the explanation

Question 1mediumdrag order
Study the full ACL explanation →

Drag and drop the steps of deploying a CoPP policy on a Cisco IOS-XE router into the correct order, from first to last.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5
Question 2mediumdrag order
Study the full ACL explanation →

Drag and drop the steps of named ACL modification using sequence numbers into the correct order, from first to last.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5
Question 3mediumdrag order
Study the full ACL explanation →

Drag and drop the steps of CoPP policy evaluation order into the correct order, from first to last.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5
Question 4hardmultiple choice
Study the full ACL explanation →

A network engineer is using Ansible to push ACL changes to a group of Cisco IOS routers. The playbook uses the ios_acl_interfaces module to bind ACLs to interfaces. After running the playbook, the engineer notices that some routers have the ACL applied inbound instead of outbound as intended. The playbook specifies 'direction: outbound'. What is the most likely cause of this issue?

Question 5hardmultiple choice
Study the full ACL explanation →

An enterprise is migrating from a traditional three-tier campus design to a software-defined access (SD-Access) fabric. The engineer needs to ensure that the existing wireless infrastructure integrates seamlessly. Which component of SD-Access is responsible for integrating wireless and wired policies?

Question 6hardmultiple choice
Study the full ACL explanation →

A company is deploying an SD-Access fabric with a centralized policy model. The design must ensure that all traffic between virtual networks (VNs) is inspected by a firewall. Which fabric role should be used to enforce this inter-VN policy?

Question 7hardmultiple choice
Study the full ACL explanation →

An enterprise is implementing Cisco TrustSec (CTS) to enforce role-based access control. The network engineer configures the switch with 'cts role-based enforcement' and 'cts manual' on an interface connecting to a trusted Cisco switch. The engineer also configures Security Group Tags (SGTs) on the RADIUS server. However, traffic between two hosts in different SGTs is not being filtered as expected. The engineer checks 'show cts role-based counters' and sees no drops. What is the most likely reason for the lack of enforcement?

Question 8mediummultiple choice
Open the full VLAN trunking answer →

A network engineer is configuring dynamic ARP inspection (DAI) on a Cisco switch to prevent ARP spoofing. The switch has DHCP snooping enabled and the DHCP server is trusted. The engineer enables DAI on VLAN 10 and configures 'ip arp inspection trust' on the port connected to the DHCP server. After enabling DAI, some legitimate ARP replies from hosts are being dropped. The engineer checks the DAI statistics and sees 'ARP ACL drops' incrementing. What is the most likely reason?

Question 9mediummulti select
Study the full ACL explanation →

Which three statements about VRF path isolation in a service provider network are true? (Choose three.)

Question 10mediumdrag order
Study the full ACL explanation →

Drag and drop the steps of Control Plane Policing (CoPP) rate-limit evaluation into the correct order, from first to last.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5
Question 11mediummatching
Study the full ACL explanation →

Drag and drop each Control plane protection feature on the left to its matching threat on the right.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

CPU overload from excessive control plane traffic

IP spoofing attacks

Rogue DHCP server

ARP cache poisoning

IP spoofing on access ports

Question 12hardmultiple choice
Study the full ACL explanation →

A network architect is designing a Cisco SD-Access fabric. The requirement is to provide secure segmentation for different departments without deploying separate physical networks or traditional VRFs on every switch. Which Cisco SD-Access component provides this segmentation by using a group-based policy model?

Question 13hardmulti select
Study the full ACL explanation →

A network architect is evaluating Cisco SD-Access for a large campus. The architect must ensure the fabric supports policy enforcement based on user identity and group membership, and that the fabric can scale to thousands of endpoints without flooding the underlay. Which two statements are correct about how SD-Access achieves these goals? (Choose two.)

Question 14mediumdrag order
Study the full ACL explanation →

Drag and drop the steps of SNMP community-based access control setup into the correct order, from first to last.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5
Question 15mediummultiple choice
Study the full ACL explanation →

A network architect is designing a Cisco SD-Access fabric for a hospital campus. The hospital requires that guest wireless users be allowed access only to the internet, while clinical staff devices must reach internal EHR servers. The fabric uses Cisco DNA Center and Cisco Identity Services Engine for policy. Which fabric component enforces the group-based policy between these user groups?

Question 16mediummultiple choice
Open the full BGP breakdown →

A network engineer is configuring Control Plane Policing (CoPP) on a Cisco IOS XE router that runs BGP, SSH management, and SNMP polling. A class-map named CLASS-MGMT matches SNMP and SSH traffic, and a policy-map named COPP-POLICY applies a police rate of 8000 bps with a conform-action transmit and exceed-action drop for that class. After the policy is attached to the control plane, SNMP polling intermittently fails while BGP remains stable. Which action should the engineer take to resolve the SNMP failures while still protecting the route processor?

Question 17hardmultiple choice
Open the full BGP breakdown →

A network engineer is configuring control plane policing (CoPP) on a Cisco IOS XE router that peers BGP with two service providers and is managed over SSH from a jump host. After applying a new policy-map, the engineer notices that BGP sessions remain up but SSH logins intermittently time out during traffic spikes. Which action should the engineer take to resolve the SSH timeouts while preserving the CoPP protection model?

Question 18mediummultiple choice
Review the full OSPF breakdown →

A network administrator is deploying Control Plane Policing (CoPP) on a Cisco IOS XE router that runs BGP, OSPF, and SSH management. The administrator wants to protect the route processor from excessive control-plane traffic while still allowing legitimate routing protocol and management traffic. The administrator creates a class map that matches BGP, OSPF, and SSH traffic and applies a police action with a committed information rate. Which additional configuration element is required to complete the CoPP implementation?

Question 19mediumdrag order
Study the full ACL explanation →

Drag and drop the steps of CoPP class-map match criteria and rate-limit application into the correct order, from first to last.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5
Question 20hardmultiple choice
Review the full OSPF breakdown →

A network engineer is implementing Control Plane Policing (CoPP) on a Cisco IOS XE router to protect against control plane overload. The router has management traffic (SSH, SNMP) and routing protocol traffic (OSPF, BGP). After applying the CoPP policy, the engineer notices that OSPF adjacencies are flapping. Which action should the engineer take to resolve this issue while maintaining control plane protection?

Free account

Track your progress over time

Create a free account to save your results and see which topics improve across sessions.

Focused Acls And Copp sessions

Start a Acls And Copp only practice session

Every question in these sessions is drawn from the Acls And Copp domain — nothing else.

Related practice questions

Related 350-401 topic practice pages

Move into related areas when this topic feels solid.

Frequently asked questions

What does the 350-401 exam test about Acls And Copp?
ACL questions usually test top-down rule processing, source and destination matching, protocol or port logic, and where the ACL should be applied.
How should I use these practice questions?
Select your answer before revealing the explanation. Then read why each option is right or wrong — this active recall approach builds retention far faster than re-reading notes.
Can I practise just Acls And Copp questions in a focused session?
Yes — the session launcher on this page draws every question from the Acls And Copp domain. Use a 10-question session first to gauge your baseline, then move to 20 or 30 once the weak spots are clear.
Where can I practise other 350-401 topics?
Use the topic links above to move to related areas, or go back to the 350-401 question bank to see all topics.
Are these real exam questions or dumps?
These are original practice questions written to test the same concepts the 350-401 exam covers. They are not copied from any real exam or dump site.