Courseiva
mediumMultiple Choice

300-410 Practice Question: Runs the following command to troubleshoot an…

A network engineer runs the following command to troubleshoot an IPv4 Access Control Lists issue:

R1# show ip access-lists 130

Extended IP access list 130

10 deny ip host 10.1.1.1 host 10.2.2.2
    
20 permit ip any any

Then the engineer runs:

R1# debug ip packet 130
IP packet debugging is on for access list 130
*Mar  1 00:20:10.123: IP: s=10.1.1.1 (GigabitEthernet0/0), d=10.2.2.2, len 100, proto ICMP, access list 130: matched line 
10 deny ip host 10.1.1.1 host 10.2.2.2

What does this output indicate?

⚠ Common exam trap

Cisco often tests the misconception that a debug message showing a packet matched an ACL line implies the packet was permitted, when in fact the action (deny or permit) is determined by the matched line's action.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

ICMP traffic from 10.1.1.1 to 10.2.2.2 is being denied by ACL 130.

The debug output explicitly shows that the packet with source 10.1.1.1 and destination 10.2.2.2 matched line 10 of ACL 130, which is a deny statement. Since the ACL is evaluated sequentially and the first match is a deny, the ICMP traffic is denied. The debug message confirms the match, so option A is correct.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    ICMP traffic from 10.1.1.1 to 10.2.2.2 is being denied by ACL 130.

    Why this is correct

    The debug output shows the packet matched line 10, which denies IP traffic from host 10.1.1.1 to host 10.2.2.2. Because the protocol is ICMP and the source and destination match the deny statement, that ICMP traffic is being dropped.

  • ✗

    ICMP traffic from 10.1.1.1 to 10.2.2.2 is being permitted by ACL 130.

    Why it's wrong here

    Line 10 denies the flow, and the debug line confirms that deny entry matched, so the packet is dropped rather than permitted. It is tempting because the trailing permit ip any any would allow the traffic if the deny entry were absent or ordered after it.

  • ✗

    ACL 130 is applied outbound on GigabitEthernet0/0.

    Why it's wrong here

    The debug output names GigabitEthernet0/0 as the ingress interface for the source packet, giving no evidence of outbound application. It is tempting because direction determines where an ACL filters traffic, and outbound placement would be correct when filtering packets leaving an interface toward a destination.

  • ✗

    ACL 130 is not matching any packets.

    Why it's wrong here

    The log explicitly records a match on line 10, so the ACL is evaluating and matching traffic. It is tempting because an empty match counter on the ACL entry can indicate a misapplied or unreferenced list, which would be the correct diagnosis when no debug output appears.

Visual reference

Source Router + ACL permit 10.0.0.0/8 deny any Server 10.0.0.5 ✓ 192.168.1.1 ✗ dropped ACLs evaluate top-down; first match wins — implicit deny all at end

About these practice questions

This 300-410 question is part of Courseiva's 1,401-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 300-410 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 300-410 exam.