Courseiva
mediumMultiple Choice

300-410 Practice Question: Runs the following command to troubleshoot an…

A network engineer runs the following command to troubleshoot an IPv6 traffic filtering issue:

R1# show ipv6 access-list FILTER

IPv6 access list FILTER

permit ipv6 2001:DB8:1::/48 any sequence 10
    deny ipv6 2001:DB8:2::/48 any sequence

20

permit ipv6 any any sequence 30

What does this output indicate?

⚠ Common exam trap

Cisco often tests the interaction between explicit permit entries and the implicit deny, where candidates mistakenly assume the implicit deny applies even when a later explicit permit any any exists.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The access list will permit traffic from 2001:DB8:1::/48 and deny traffic from 2001:DB8:2::/48, but permit all other IPv6 traffic.

The output shows an IPv6 access list with three explicit entries. Sequence 10 permits traffic from source 2001:DB8:1::/48 to any destination, sequence 20 denies traffic from 2001:DB8:2::/48 to any destination, and sequence 30 permits all other IPv6 traffic. Because sequence 30 explicitly permits any any, traffic not matching the first two entries is permitted, overriding the default implicit deny at the end of the list.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    The access list will permit traffic from 2001:DB8:1::/48 and deny traffic from 2001:DB8:2::/48, but permit all other IPv6 traffic.

    Why this is correct

    Sequential evaluation stops at the first match, so 2001:DB8:1::/48 is permitted by sequence 10, 2001:DB8:2::/48 is denied by sequence 20, and everything else falls through to the sequence 30 permit any any. The implicit deny never applies because that final entry matches all remaining IPv6 traffic.

  • ✗

    The access list will permit traffic from 2001:DB8:1::/48 and deny traffic from 2001:DB8:2::/48, and implicitly deny all other IPv6 traffic.

    Why it's wrong here

    Sequence 30 permits all remaining IPv6 traffic, so the implicit deny never takes effect; only 2001:DB8:2::/48 is blocked. The implicit deny would apply only if no trailing permit any any existed, which is the classic ACL behaviour this option wrongly assumes.

  • ✗

    The access list will deny all traffic because of the deny statement.

    Why it's wrong here

    The deny statement matches only source prefix 2001:DB8:2::/48, and sequence 30 then permits everything else, so traffic is not wholly blocked. A single deny entry blocks only its matched prefix; an all-deny outcome would require no subsequent permit statement.

  • ✗

    The access list is invalid because IPv6 access lists require implicit deny at the end.

    Why it's wrong here

    The list is valid: sequence 30's permit any any makes the implicit deny unreachable for unmatched traffic, but that does not invalidate the ACL. IPv6 ACLs always carry an implicit deny; explicit trailing permits are optional, not mandatory, so syntax remains correct.

Visual reference

Source Router + ACL permit 10.0.0.0/8 deny any Server 10.0.0.5 ✓ 192.168.1.1 ✗ dropped ACLs evaluate top-down; first match wins — implicit deny all at end

About these practice questions

This 300-410 question is part of Courseiva's 1,401-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 300-410 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 300-410 exam.