mediumMultiple Choice
300-410 Practice Question: Runs the following command to troubleshoot an…
A network engineer runs the following command to troubleshoot an IPv4 Access Control Lists issue:
R1# show ip access-lists 130
Extended IP access list 130
10 deny ip host 10.1.1.1 host 10.2.2.2
20 permit ip any anyThen the engineer runs:
R1# debug ip packet 130 IP packet debugging is on for access list 130 *Mar 1 00:20:10.123: IP: s=10.1.1.1 (GigabitEthernet0/0), d=10.2.2.2, len 100, proto ICMP, access list 130: matched line 10 deny ip host 10.1.1.1 host 10.2.2.2
What does this output indicate?
⚠ Common exam trap
Cisco often tests the misconception that a debug message showing a packet matched an ACL line implies the packet was permitted, when in fact the action (deny or permit) is determined by the matched line's action.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
ICMP traffic from 10.1.1.1 to 10.2.2.2 is being denied by ACL 130.
The debug output explicitly shows that the packet with source 10.1.1.1 and destination 10.2.2.2 matched line 10 of ACL 130, which is a deny statement. Since the ACL is evaluated sequentially and the first match is a deny, the ICMP traffic is denied. The debug message confirms the match, so option A is correct.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
ICMP traffic from 10.1.1.1 to 10.2.2.2 is being denied by ACL 130.
Why this is correct
The debug output shows the packet matched line 10, which denies IP traffic from host 10.1.1.1 to host 10.2.2.2. Because the protocol is ICMP and the source and destination match the deny statement, that ICMP traffic is being dropped.
- ✗
ICMP traffic from 10.1.1.1 to 10.2.2.2 is being permitted by ACL 130.
Why it's wrong here
Line 10 denies the flow, and the debug line confirms that deny entry matched, so the packet is dropped rather than permitted. It is tempting because the trailing permit ip any any would allow the traffic if the deny entry were absent or ordered after it.
- ✗
ACL 130 is applied outbound on GigabitEthernet0/0.
Why it's wrong here
The debug output names GigabitEthernet0/0 as the ingress interface for the source packet, giving no evidence of outbound application. It is tempting because direction determines where an ACL filters traffic, and outbound placement would be correct when filtering packets leaving an interface toward a destination.
- ✗
ACL 130 is not matching any packets.
Why it's wrong here
The log explicitly records a match on line 10, so the ACL is evaluating and matching traffic. It is tempting because an empty match counter on the ACL entry can indicate a misapplied or unreferenced list, which would be the correct diagnosis when no debug output appears.
Visual reference
Go deeper
Related to this question
About these practice questions
This 300-410 question is part of Courseiva's 1,401-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 300-410 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 300-410 exam.