Courseiva
Network Fundamentals →hardMultiple Choice

200-901 Network Fundamentals Practice Question

A network engineer is troubleshooting an issue where a client cannot reach a web server at 203.0.113.10. The engineer runs a traceroute from the client and sees that the path stops at a router with IP 198.51.100.1, which is the last hop before the destination. The engineer suspects that the router is dropping packets due to an ACL. Which command should the engineer use on the router to verify if an ACL is blocking traffic to the web server?

⚠ Common exam trap

The trap here is assuming that show ip interface will reveal ACL contents, when it only shows that an ACL is applied, not its rules or match statistics.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

show ip access-lists

To verify if an ACL is blocking traffic, the engineer should examine the ACL configuration and match counters. The show ip access-lists command provides this information, allowing the engineer to see if a deny entry is matching the traffic in question. Other commands like show ip route or show ip interface do not show ACL contents, and debug ip packet is too disruptive for routine troubleshooting.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    show ip interface

    Why it's wrong here

    The show ip interface command displays IP interface status and may show which ACLs are applied to interfaces, but it does not show the contents of the ACLs or whether they are matching traffic. It can indicate that an ACL is applied, but to verify if it is blocking specific traffic, the engineer must examine the ACL entries and potentially use debug or logging. This command alone is insufficient for the task.

  • ✗

    show ip route 203.0.113.10

    Why it's wrong here

    The show ip route command displays the routing table entry for the destination, which can confirm if a route exists. However, it does not show ACL configurations or whether traffic is being filtered. While useful for verifying reachability at Layer 3, it does not address the suspicion of an ACL blocking traffic. The engineer needs to inspect ACLs, not just routing.

  • ✓

    show ip access-lists

    Why this is correct

    The show ip access-lists command displays the configured ACLs and their entries, including match counters if the ACL has been applied and is counting matches. By examining the ACL entries, the engineer can see if there is a deny statement that would block traffic from the client to the web server. The match counters can also indicate if packets are hitting a particular entry, which helps confirm if the ACL is the cause of the problem.

  • ✗

    debug ip packet

    Why it's wrong here

    The debug ip packet command can show IP packets as they are processed, but it is very resource-intensive and can severely impact router performance, especially in production. It may not directly show ACL matches and is not the recommended first step for verifying ACL blocks. While it can provide detailed information, it is generally used with caution and often with an ACL filter to limit output. It is not the best choice for this scenario.

Visual reference

Source Router + ACL permit 10.0.0.0/8 deny any Server 10.0.0.5 ✓ 192.168.1.1 ✗ dropped ACLs evaluate top-down; first match wins — implicit deny all at end

About these practice questions

This 200-901 question is part of Courseiva's 975-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 200-901 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-901 exam.