easyMultiple ChoiceObjective-mapped
350-701 Practice Question: Is configuring a Cisco ASA to block traffic from…
A security engineer is configuring a Cisco ASA to block traffic from a specific IP address. Which access control entry (ACE) should be applied to the inbound direction of the outside interface?
⚠ Common exam trap
Cisco often tests the source-destination order in ACL syntax, and the trap here is that candidates mistakenly reverse the order (putting the target IP as the destination instead of the source) or unnecessarily restrict the protocol, thinking that blocking TCP alone is sufficient.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
access-list outside_in extended deny ip host 10.1.1.1 any
The ACE uses the 'ip' protocol to block all traffic from the specific source host 10.1.1.1 to any destination, which is the most comprehensive way to block all IP traffic from that address. In Cisco ASA ACLs, the order of source and destination is 'source destination', so 'deny ip host 10.1.1.1 any' correctly matches packets with source IP 10.1.1.1 and any destination, applied inbound on the outside interface to block traffic entering the network.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
access-list outside_in extended deny ip any host 10.1.1.1
Why it's wrong here
Blocks all IP traffic to the host, not from it.
- ✓
access-list outside_in extended deny ip host 10.1.1.1 any
Why this is correct
Correctly blocks all IP traffic from the specified host.
- ✗
access-list outside_in extended deny tcp any host 10.1.1.1
Why it's wrong here
Blocks TCP traffic to the host, not from it.
- ✗
access-list outside_in extended deny tcp host 10.1.1.1 any eq 80
Why it's wrong here
Only blocks HTTP traffic from the host, not all traffic.
Go deeper
Related to this question
About these practice questions
Courseiva writes every 350-701 question from scratch — 978 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 350-701 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-701 exam.