Courseiva
mediumMultiple Choice

300-410 Practice Question: Runs the following command on Router R1: R1# show…

A network engineer runs the following command on Router R1:

R1# show ip access-lists

Extended IP access list 170

10 permit icmp any any echo (100 matches)
    
20 permit icmp any any echo-reply (80 matches)
    
30 deny ip any any (10 matches)

Based on this output, which statement is correct?

⚠ Common exam trap

Cisco often tests the misconception that an ACL with only two permit statements for specific ICMP types permits all ICMP traffic, but the explicit or implicit deny ip any any at the end blocks all other ICMP types and non-ICMP IP traffic.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Only ICMP echo and echo-reply are permitted; all other IP traffic is denied.

The ACL 170 explicitly permits only ICMP echo (type 8) and echo-reply (type 0) traffic, as shown by the match counters. The final deny ip any any statement blocks all other IP traffic, including other ICMP types and non-ICMP IP protocols. Therefore, only ICMP echo and echo-reply are permitted; all other IP traffic is denied, making option B correct.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    All ICMP traffic is permitted.

    Why it's wrong here

    Only ICMP echo and echo-reply are permitted; other ICMP types, such as unreachable or redirect, hit the deny and are dropped. It tempts because ICMP appears twice in the list, but the type and code fields restrict each entry to one specific message pair.

  • ✓

    Only ICMP echo and echo-reply are permitted; all other IP traffic is denied.

    Why this is correct

    The access list permits ICMP echo and echo-reply, then explicitly denies all remaining IP traffic via the final deny ip any any entry. Only those two ICMP message types pass; every other protocol is dropped.

  • ✗

    The ACL permits all IP traffic.

    Why it's wrong here

    Line 30 denies all remaining IP traffic, so the list permits only ICMP echo and echo-reply, not all IP. It tempts because the two permit entries are visible at the top, yet a trailing deny ip any any is exactly what makes this an effective, complete ACL.

  • ✗

    The ACL is not applied.

    Why it's wrong here

    Match counters of 100, 80 and 10 prove the ACL is actively filtering traffic on an interface; an unapplied list shows no matches. It tempts because show ip access-lists alone does not name the interface, so verifying application requires show ip interfaces or running-config.

Visual reference

Source Router + ACL permit 10.0.0.0/8 deny any Server 10.0.0.5 ✓ 192.168.1.1 ✗ dropped ACLs evaluate top-down; first match wins — implicit deny all at end

About these practice questions

Courseiva writes every 300-410 question from scratch — 1,401 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 300-410 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 300-410 exam.