300-410 Infrastructure Security Practice Question
A network engineer configures a Cisco IOS router with the following commands:
ip access-list extended BLOCK_TELNET deny tcp any any eq 23 permit ip any any
!
interface GigabitEthernet0/0 ip access-group BLOCK_TELNET in
After applying the configuration, the engineer notices that Telnet traffic from the local router to a remote device is still successful. What is the cause of this issue?
⚠ Common exam trap
The trap here is assuming that an interface ACL applied inbound will also filter traffic generated by the router itself.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The access list is applied in the inbound direction, which only filters traffic entering the interface, not traffic originated by the router.
Access lists applied to an interface with the ip access-group command filter only traffic that passes through that interface in the specified direction. They do not filter traffic originated by the router itself. To control Telnet access to or from the router, an access-class must be applied under the VTY lines. Since the ACL is applied inbound on an interface, it does not affect locally generated Telnet packets, so the Telnet session succeeds.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
The access list is applied in the inbound direction, which only filters traffic entering the interface, not traffic originated by the router.
Why this is correct
The access list is applied inbound on GigabitEthernet0/0, so it filters only packets entering that interface. Locally generated Telnet traffic from the router does not pass through the inbound access-group; it is subject to outbound filtering on the egress interface or to a VTY access-class. Therefore, the Telnet session succeeds despite the deny statement.
- ✗
The implicit deny at the end of the access list is blocking the Telnet traffic, but the 'permit ip any any' statement overrides it.
Why it's wrong here
The implicit deny at the end of an ACL blocks traffic not explicitly permitted, but the 'permit ip any any' statement explicitly permits all other IP traffic, so the implicit deny is not the cause. Moreover, the Telnet traffic is denied by the first statement, not by the implicit deny. The real issue is ACL direction and placement.
- ✗
The access list must be applied with the 'ip access-group BLOCK_TELNET out' command on the same interface to filter locally generated traffic.
Why it's wrong here
Applying the ACL outbound on the same interface would filter traffic leaving that interface, but it would not affect locally generated traffic unless that interface is the egress for the Telnet session. The issue is that the ACL is applied in the wrong direction and location for the traffic in question. Outbound application on the ingress interface does not solve the problem.
- ✗
The 'deny tcp any any eq 23' statement is incorrect because Telnet uses TCP port 22, not port 23.
Why it's wrong here
Telnet uses TCP port 23, not port 22. Port 22 is used by SSH. The deny statement correctly matches Telnet traffic. Therefore, the ACL statement itself is not the cause of the problem; the issue is the application point of the ACL relative to the traffic flow.
Visual reference
Go deeper
Related to this question
About these practice questions
This 300-410 question is part of Courseiva's 1,401-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 300-410 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 300-410 exam.