mediumMultiple ChoiceObjective-mapped
300-410 Practice Question: When using an extended ACL to filter traffic,…
When using an extended ACL to filter traffic, which fields can be matched? (Choose the most complete answer.)
⚠ Common exam trap
Cisco often tests the distinction between standard and extended ACLs, trapping candidates who forget that extended ACLs can match protocol and port numbers in addition to source and destination IP addresses, leading them to choose an incomplete option like C or A.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Source and destination IP addresses, protocol, and port numbers.
Extended ACLs (access control lists) operate at Layer 3 and Layer 4 of the OSI model, allowing matching on source and destination IP addresses, protocol (e.g., TCP, UDP, ICMP), and port numbers. This granularity enables precise traffic filtering beyond the source-only limitation of standard ACLs. Option B correctly lists all these matchable fields, making it the most complete answer.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Only source IP address.
Why it's wrong here
Incorrect. That is the capability of a standard ACL.
- ✓
Source and destination IP addresses, protocol, and port numbers.
Why this is correct
Correct. Extended ACLs can match these fields for fine-grained filtering.
- ✗
Source IP address and destination port number only.
Why it's wrong here
Incorrect. Extended ACLs can match more fields, including protocol and source port.
- ✗
MAC address and IP address.
Why it's wrong here
Incorrect. MAC addresses are not matched by IP ACLs; they are used in MAC ACLs.
Visual reference
Quick reference
OSI Model Reference
| Layer | Name | PDU | Key Protocols / Devices |
|---|---|---|---|
| 7 | Application | Data | HTTP, HTTPS, DNS, SMTP, FTP, SSH |
| 6 | Presentation | Data | TLS / SSL, JPEG, ASCII encoding |
| 5 | Session | Data | NetBIOS, RPC, SIP |
| 4 | Transport | Segment / Datagram | TCP, UDP |
| 3 | Network | Packet | IP, ICMP, OSPF — Routers |
| 2 | Data Link | Frame | Ethernet, Wi-Fi, PPP — Switches, Bridges |
| 1 | Physical | Bits | Cables, NICs, Hubs, Repeaters |
Go deeper
Related to this question
About these practice questions
Courseiva writes every 300-410 question from scratch — 1,966 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 300-410 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 300-410 exam.