Courseiva
mediumMultiple Choice

300-410 Practice Question: In an extended IPv4 ACL, what is the default…

In an extended IPv4 ACL, what is the default action if only a source and destination are specified without a protocol?

⚠ Common exam trap

Cisco often tests the mandatory nature of the protocol field in extended ACLs, trapping candidates who assume a default protocol (like IP, TCP, or UDP) is applied when none is specified.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The command is rejected by the IOS parser.

In an extended IPv4 ACL, the protocol keyword is mandatory. If you omit it, the IOS parser rejects the command because it cannot determine which protocol to filter. The correct syntax requires a protocol (e.g., ip, tcp, udp) after the permit or deny keyword; without it, the parser returns an error.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The ACL matches all IP traffic.

    Why it's wrong here

    An extended ACL entry requires a protocol keyword; without one the entry is invalid, and the implicit deny at the end drops unmatched traffic rather than matching all IP. It is tempting because standard ACLs match on source alone, where omitting further criteria does permit all traffic.

  • ✗

    The ACL matches only TCP traffic.

    Why it's wrong here

    Omitting the protocol keyword in an extended ACL defaults to ip, matching all protocols, not TCP alone. Specifying tcp is tempting because most filtered traffic is TCP, and it would be correct when you explicitly need to match only TCP segments.

  • ✓

    The command is rejected by the IOS parser.

    Why this is correct

    The IOS parser requires a protocol keyword before source and destination in an extended ACL. Omitting it means the syntax is incomplete, so the command is rejected outright rather than defaulting to 'ip' or any other protocol.

  • ✗

    The ACL matches only UDP traffic.

    Why it's wrong here

    Without a protocol keyword, the extended ACL entry defaults to ip, matching every protocol rather than UDP only. Naming udp is tempting for DNS, DHCP or voice traffic, and would be correct when the requirement is to filter UDP datagrams specifically.

Visual reference

Source Router + ACL permit 10.0.0.0/8 deny any Server 10.0.0.5 ✓ 192.168.1.1 ✗ dropped ACLs evaluate top-down; first match wins — implicit deny all at end

About these practice questions

One of 1,401 original 300-410 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 300-410 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 300-410 exam.