mediumMultiple Select
300-410 Practice Question: Which TWO commands verify the application and…
Which TWO commands verify the application and content of an IPv4 access control list on a Cisco IOS router? (Choose TWO.)
⚠ Common exam trap
Cisco often tests the distinction between commands that verify ACL application (show ip interface) versus content (show access-lists), and candidates mistakenly choose 'show running-config | include access-list' thinking it shows both, but it only shows the configuration lines without interface binding or hit counts.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
show ip interface
The 'show ip interface' command displays the access lists applied to an interface, including the direction (inbound/outbound) and the specific ACL name or number. The 'show access-lists' command shows the detailed content of all ACLs, including the exact permit/deny statements, sequence numbers, and hit counts, verifying both the application and the rules.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
show ip interface
Why this is correct
`show ip interface` displays the ACL name and direction (inbound or outbound) applied per interface, confirming the ACL is bound and filtering traffic as intended. This directly satisfies the stem's requirement to verify ACL application, complementing `show ip access-lists`, which confirms content.
- ✓
show access-lists
Why this is correct
Displays the configured entries of every ACL, including sequence numbers, permit/deny actions and match counters, so the actual content of the IPv4 list is confirmed. It does not show where the list is applied, which the companion interface command covers.
- ✗
show running-config | include access-list
Why it's wrong here
Filtering the running configuration with include access-list displays only the ACL statements themselves, not the interface or line where each ACL is applied, so application cannot be verified. It is tempting because it is a quick way to read ACL content, which suits auditing defined entries, but the question also requires confirming application.
- ✗
show ip route
Why it's wrong here
show ip route displays the routing table and next hops; it contains no ACL entries and no interface ACL bindings, so it verifies neither content nor application. It is tempting because ACLs can influence which routes are installed, which suits troubleshooting routing reachability, but it cannot confirm ACL configuration.
- ✗
debug ip packet
Why it's wrong here
debug ip packet shows per-packet forwarding and drop events, not the configured ACL entries or where an ACL is applied to an interface. It is tempting because it can reveal whether traffic is being dropped, which suits troubleshooting suspected filtering, but it cannot confirm ACL content or application.
Visual reference
Go deeper
Related to this question
About these practice questions
Courseiva writes every 300-410 question from scratch — 1,401 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 300-410 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 300-410 exam.