mediumMultiple Choice
300-410 Practice Question: Which IPv6 access-list entry will deny traffic…
Which IPv6 access-list entry will deny traffic from any source to the destination prefix 2001:db8:1::/48?
⚠ Common exam trap
Cisco often tests the order of source and destination in ACL entries, where candidates mistakenly reverse them (as in Option B) or use a host keyword instead of a prefix (as in Option C), thinking it matches a range.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
deny ipv6 any 2001:db8:1::/48
The IPv6 access-list entry 'deny ipv6 any 2001:db8:1::/48' uses the correct syntax: the source is 'any' (all traffic), and the destination is the prefix 2001:db8:1::/48, which matches all addresses within that /48 range. This entry denies traffic from any source to the entire destination prefix, as required by the question.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
deny ipv6 any 2001:db8:1::/48
Why this is correct
The entry deny ipv6 any 2001:db8:1::/48 uses any as the source and the /48 prefix as destination, matching all traffic destined to that prefix regardless of origin. This precisely satisfies the requirement to deny any source to that destination.
- ✗
deny ipv6 2001:db8:1::/48 any
Why it's wrong here
This entry places 2001:db8:1::/48 in the source position, so it denies traffic originating from that prefix rather than traffic destined to it. The stem requires any source and that destination. It would be correct if the requirement were to block all traffic sourced from that prefix.
- ✗
deny ipv6 any host 2001:db8:1::1
Why it's wrong here
This entry matches a single host address, 2001:db8:1::1, not the whole 2001:db8:1::/48 prefix, so traffic to other addresses in the prefix is permitted. The stem requires the entire /48. It would be correct if only that one destination host needed denying.
- ✗
deny ipv6 2001:db8:1::/48 2001:db8:1::/48
Why it's wrong here
Both source and destination are set to the same prefix, so only traffic from 2001:db8:1::/48 to 2001:db8:1::/48 is denied, not traffic from any source. The stem needs the source wildcard. It would be correct for denying intra-prefix traffic within that /48.
Go deeper
Related to this question
About these practice questions
One of 1,401 original 300-410 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 300-410 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 300-410 exam.