Courseiva
mediumMultiple Choice

300-410 Practice Question: Review the following configuration: ipv6…

Review the following configuration:

ipv6 access-list FILTER

permit tcp 2001:db8:1::/48 any eq 80
 permit tcp 2001:db8:1::/48 any eq

443

deny ipv6 any any

interface GigabitEthernet0/3

ipv6 traffic-filter FILTER out

What is the effect of this configuration?

⚠ Common exam trap

Cisco often tests the misconception that an ACL without a destination prefix permits all traffic from the source, but in reality, the permit statement still requires the specified protocol and ports to match, and the explicit deny blocks everything else.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Only HTTP and HTTPS traffic from 2001:db8:1::/48 is permitted outbound; all other traffic is denied.

The IPv6 ACL named FILTER explicitly permits TCP traffic from source prefix 2001:db8:1::/48 to any destination on ports 80 (HTTP) and 443 (HTTPS), and then denies all other IPv6 traffic. Applied as an outbound traffic filter on GigabitEthernet0/3, this configuration restricts outbound traffic to only HTTP and HTTPS sessions originating from the specified prefix.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Only HTTP and HTTPS traffic from 2001:db8:1::/48 is permitted outbound; all other traffic is denied.

    Why this is correct

    The outbound IPv6 ACL permits TCP port 80 and 443 sourced from 2001:db8:1::/48, then the implicit-final deny ipv6 any any drops everything else leaving GigabitEthernet0/3. It satisfies the stem by restricting egress to those two web ports from that prefix only.

  • ✗

    All traffic from 2001:db8:1::/48 is permitted because the ACL does not specify destination prefix.

    Why it's wrong here

    'any' in the destination field matches every destination prefix; the permits are still restricted to TCP ports 80 and 443 from 2001:db8:1::/48. The final deny drops all remaining IPv6 traffic, so the claim of blanket permission is false.

  • ✗

    The ACL is misconfigured because 'out' should be 'in' for source-based filtering.

    Why it's wrong here

    An outbound ACL filters packets leaving the interface, and source addresses are still matched normally, so 'out' is valid here. Inbound filtering is chosen when traffic should be screened before routing or when the source sits behind that interface.

  • ✗

    The ACL permits all traffic because the deny statement is implicit.

    Why it's wrong here

    The explicit 'deny ipv6 any any' is present in the ACL, so the implicit deny is not what terminates matching. The implicit deny only matters when no explicit deny exists; here the configured statement drops everything not already permitted.

Visual reference

Source Router + ACL permit 10.0.0.0/8 deny any Server 10.0.0.5 ✓ 192.168.1.1 ✗ dropped ACLs evaluate top-down; first match wins — implicit deny all at end

About these practice questions

This 300-410 question is part of Courseiva's 1,401-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 300-410 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 300-410 exam.