mediumMultiple Choice
300-410 Practice Question: Consider the following configuration: ipv6…
Consider the following configuration:
ipv6 access-list BLOCK-ICMP
deny icmp any any echo-request deny icmp any any echo-reply permit ipv6 any any interface GigabitEthernet0/2
ipv6 traffic-filter BLOCK-ICMP in
Which statement is true?
⚠ Common exam trap
Cisco often tests the misconception that an ACL applied inbound cannot block echo-reply because it is a response, but in IPv6, echo-reply is a separate ICMP type that can be filtered inbound on the interface where it arrives.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The ACL blocks ICMP echo-request and echo-reply, but permits all other IPv6 traffic inbound.
The IPv6 ACL explicitly denies ICMPv6 echo-request and echo-reply messages (types 128 and 129) while the final permit ipv6 any any statement allows all other IPv6 traffic. The ipv6 traffic-filter command applied inbound on GigabitEthernet0/2 filters traffic as it enters the interface, so only the specified ICMP types are blocked, and all other IPv6 traffic is permitted.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
The ACL blocks ICMP echo-request and echo-reply, but permits all other IPv6 traffic inbound.
Why this is correct
The ACL denies only ICMP echo-request and echo-reply, then the permit ipv6 any any statement matches every remaining IPv6 packet, including other ICMP types. Applied inbound with ipv6 traffic-filter, it therefore blocks those two message types while allowing all other inbound IPv6 traffic.
- ✗
The ACL blocks all ICMPv6 traffic because the deny statements are too broad.
Why it's wrong here
The ACL denies only echo-request and echo-reply, then permits all remaining IPv6 traffic, so other ICMPv6 types such as neighbour solicitation still pass. It is tempting because deny entries precede the permit, and the statement would be true if no permit ipv6 any any line existed.
- ✗
The ACL must be applied outbound to filter echo-request.
Why it's wrong here
Inbound filtering on Gi0/2 already matches echo-request arriving at that interface, so denying it there works; applying the ACL outbound would only catch traffic leaving, missing the incoming echo-request. Outbound ACLs suit filtering traffic the router itself originates or forwards toward a specific destination.
- ✗
The ACL is missing the 'log' keyword to be effective.
Why it's wrong here
The 'log' keyword only generates syslog messages for matched entries; it does not alter whether the deny statements take effect. The ACL already drops echo-request and echo-reply because deny entries are processed before the permit ipv6 any any. Logging would be chosen when audit trails of dropped ICMP packets are required.
Visual reference
Go deeper
Related to this question
About these practice questions
One of 1,401 original 300-410 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 300-410 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 300-410 exam.