Courseiva
easyMultiple Choice

300-410 Practice Question: Runs the following command to troubleshoot an…

A network engineer runs the following command to troubleshoot an IPv4 Access Control Lists issue:

R1# show ip access-lists 101

Extended IP access list 101

10 permit tcp 192.168.1.0 0.0.0.255 any eq 80 (12 matches)
    
20 deny tcp any any eq 443 (5 matches)
    
30 permit ip any any (100 matches)

What does this output indicate?

⚠ Common exam trap

Cisco often tests the misconception that an explicit deny statement (like line 20) blocks all traffic, when in fact it only blocks the specific protocol and port, and subsequent permit entries can still allow other traffic.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The ACL is permitting TCP traffic from 192.168.1.0/24 to any destination on port 80, denying all TCP traffic to port 443, and permitting all other IP traffic.

The ACL explicitly permits TCP traffic from source 192.168.1.0/24 to any destination on port 80 (line 10), denies TCP traffic from any source to any destination on port 443 (line 20), and then permits all other IP traffic (line 30). The match counts confirm that traffic matching each line has been processed, and the implicit deny at the end is never reached because line 30 permits everything else.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    The ACL is permitting TCP traffic from 192.168.1.0/24 to any destination on port 80, denying all TCP traffic to port 443, and permitting all other IP traffic.

    Why this is correct

    Sequence numbers 10, 20 and 30 are evaluated top-down: line 10 permits TCP port 80 from 192.168.1.0/24, line 20 denies TCP port 443 from any source, and line 30 permits all remaining IP traffic, with match counters confirming each entry's hits.

  • ✗

    The ACL is denying all traffic because line 20 is an explicit deny.

    Why it's wrong here

    Line 20 denies only TCP port 443, and line 30 then permits every other IP packet, so traffic is not wholly denied. Reading an explicit deny as a blanket block is tempting because implicit deny-all sits at the end of every ACL, but that default applies only when no later permit matches.

  • ✗

    The ACL is applied inbound on an interface and is blocking all traffic to port 443.

    Why it's wrong here

    The output shows match counters only; it never states the ACL's binding direction or interface, so inbound application cannot be inferred. Port 443 is denied by line 20, but that rule is not blocking all traffic. The command's purpose is verifying which entries match, not where the list is attached.

  • ✗

    The ACL has no effect because the match counts are too low.

    Why it's wrong here

    Match counters record hits, not ACL effectiveness; low counts simply mean few packets matched those entries. Line 30's 100 matches prove the ACL is actively evaluating traffic. Counters are tempting as a health signal, yet they only evidence that the list is bound to an interface and processing packets.

Visual reference

Source Router + ACL permit 10.0.0.0/8 deny any Server 10.0.0.5 ✓ 192.168.1.1 ✗ dropped ACLs evaluate top-down; first match wins — implicit deny all at end

About these practice questions

Courseiva writes every 300-410 question from scratch — 1,401 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 300-410 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 300-410 exam.