Courseiva
mediumMultiple ChoiceObjective-mapped

300-410 Practice Question: Runs the following command to troubleshoot an…

A network engineer runs the following command to troubleshoot an IPv6 traffic filtering issue:

R1# show ipv6 access-list FILTER

IPv6 access list FILTER

permit ipv6 2001:DB8:1::/48 any sequence 10
    deny ipv6 2001:DB8:2::/48 any sequence

20

permit ipv6 any any sequence 30

What does this output indicate?

⚠ Common exam trap

Cisco often tests the interaction between explicit permit entries and the implicit deny, where candidates mistakenly assume the implicit deny applies even when a later explicit permit any any exists.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

The access list will permit traffic from 2001:DB8:1::/48 and deny traffic from 2001:DB8:2::/48, but permit all other IPv6 traffic.

The output shows an IPv6 access list with three explicit entries. Sequence 10 permits traffic from source 2001:DB8:1::/48 to any destination, sequence 20 denies traffic from 2001:DB8:2::/48 to any destination, and sequence 30 permits all other IPv6 traffic. Because sequence 30 explicitly permits any any, traffic not matching the first two entries is permitted, overriding the default implicit deny at the end of the list.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • The access list will permit traffic from 2001:DB8:1::/48 and deny traffic from 2001:DB8:2::/48, but permit all other IPv6 traffic.

    Why this is correct

    Correct. Sequence 10 permits the first prefix, sequence 20 denies the second, and sequence 30 permits everything else.

  • The access list will permit traffic from 2001:DB8:1::/48 and deny traffic from 2001:DB8:2::/48, and implicitly deny all other IPv6 traffic.

    Why it's wrong here

    Incorrect. There is an explicit permit any any at sequence 30, so other traffic is permitted.

  • The access list will deny all traffic because of the deny statement.

    Why it's wrong here

    Incorrect. The deny only applies to the specified prefix; other traffic is permitted by sequence 30.

  • The access list is invalid because IPv6 access lists require implicit deny at the end.

    Why it's wrong here

    Incorrect. IPv6 access lists do have an implicit deny, but the explicit permit any any overrides it.

Visual reference

Source Router + ACL permit 10.0.0.0/8 deny any Server 10.0.0.5 ✓ 192.168.1.1 ✗ dropped ACLs evaluate top-down; first match wins — implicit deny all at end

About these practice questions

This 300-410 question is part of Courseiva's 1,966-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 300-410 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 300-410 exam.