Courseiva
mediumMultiple Select

300-410 Practice Question: Which TWO configuration steps are required to…

Which TWO configuration steps are required to implement IPv6 traffic filtering using a named ACL on a Cisco router? (Choose TWO.)

⚠ Common exam trap

Cisco often tests the distinction between IPv4 and IPv6 ACL commands, and the trap here is that candidates mistakenly apply the IPv4 `ip access-group` command or the non-existent `ipv6 access-group` command instead of the correct `ipv6 traffic-filter` command.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Create the ACL using the ipv6 access-list command.

The `ipv6 access-list` command is the standard Cisco IOS command used to create a named IPv6 ACL, which supports filtering based on IPv6 headers, extension headers, and upper-layer protocols. Option B is correct because the `ipv6 traffic-filter` command is the interface-level command that applies the named IPv6 ACL to filter inbound or outbound IPv6 traffic, analogous to `ip access-group` for IPv4.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Create the ACL using the ipv6 access-list command.

    Why this is correct

    Named IPv6 ACLs are created with the ipv6 access-list command, which enters ACL configuration mode and defines the permit or deny entries. Without this, no filter exists to apply, so it is the mandatory first step for implementing IPv6 traffic filtering on the router.

  • ✓

    Apply the ACL to the interface using the ipv6 traffic-filter command.

    Why this is correct

    Creating an IPv6 ACL does nothing until it is bound to an interface. The ipv6 traffic-filter command attaches the named ACL inbound or outbound on the interface, which is the step that actually enforces filtering on transit traffic.

  • ✗

    Create the ACL using the access-list command.

    Why it's wrong here

    The access-list command creates IPv4 ACLs; IPv6 named ACLs require the ipv6 access-list command instead. It is tempting because access-list is the familiar syntax for named ACLs in IPv4, and would be correct when filtering IPv4 traffic with a named access list on the same router.

  • ✗

    Apply the ACL to the interface using the ip access-group command.

    Why it's wrong here

    The ip access-group command applies IPv4 ACLs only; IPv6 filtering requires ipv6 traffic-filter on the interface. It is tempting because it is the standard interface-binding command for IPv4 named ACLs, and would be correct when applying an IPv4 access list inbound or outbound.

  • ✗

    Apply the ACL to the interface using the ipv6 access-group command.

    Why it's wrong here

    The ipv6 access-group command is not valid Cisco IOS syntax; IPv6 ACLs are bound with ipv6 traffic-filter. It is tempting because the name mirrors the IPv4 ip access-group construct, which is the correct command for applying an IPv4 ACL to an interface.

Visual reference

Source Router + ACL permit 10.0.0.0/8 deny any Server 10.0.0.5 ✓ 192.168.1.1 ✗ dropped ACLs evaluate top-down; first match wins — implicit deny all at end

About these practice questions

One of 1,401 original 300-410 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 300-410 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 300-410 exam.