Courseiva
mediumMultiple Choice

300-410 Practice Question: Consider the following configuration: ipv6…

Consider the following configuration:

ipv6 access-list BLOCK-ICMP

deny icmp any any echo-request
 deny icmp any any echo-reply
 permit ipv6 any any

interface GigabitEthernet0/2

ipv6 traffic-filter BLOCK-ICMP in

Which statement is true?

⚠ Common exam trap

Cisco often tests the misconception that an ACL applied inbound cannot block echo-reply because it is a response, but in IPv6, echo-reply is a separate ICMP type that can be filtered inbound on the interface where it arrives.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The ACL blocks ICMP echo-request and echo-reply, but permits all other IPv6 traffic inbound.

The IPv6 ACL explicitly denies ICMPv6 echo-request and echo-reply messages (types 128 and 129) while the final permit ipv6 any any statement allows all other IPv6 traffic. The ipv6 traffic-filter command applied inbound on GigabitEthernet0/2 filters traffic as it enters the interface, so only the specified ICMP types are blocked, and all other IPv6 traffic is permitted.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    The ACL blocks ICMP echo-request and echo-reply, but permits all other IPv6 traffic inbound.

    Why this is correct

    The ACL denies only ICMP echo-request and echo-reply, then the permit ipv6 any any statement matches every remaining IPv6 packet, including other ICMP types. Applied inbound with ipv6 traffic-filter, it therefore blocks those two message types while allowing all other inbound IPv6 traffic.

  • ✗

    The ACL blocks all ICMPv6 traffic because the deny statements are too broad.

    Why it's wrong here

    The ACL denies only echo-request and echo-reply, then permits all remaining IPv6 traffic, so other ICMPv6 types such as neighbour solicitation still pass. It is tempting because deny entries precede the permit, and the statement would be true if no permit ipv6 any any line existed.

  • ✗

    The ACL must be applied outbound to filter echo-request.

    Why it's wrong here

    Inbound filtering on Gi0/2 already matches echo-request arriving at that interface, so denying it there works; applying the ACL outbound would only catch traffic leaving, missing the incoming echo-request. Outbound ACLs suit filtering traffic the router itself originates or forwards toward a specific destination.

  • ✗

    The ACL is missing the 'log' keyword to be effective.

    Why it's wrong here

    The 'log' keyword only generates syslog messages for matched entries; it does not alter whether the deny statements take effect. The ACL already drops echo-request and echo-reply because deny entries are processed before the permit ipv6 any any. Logging would be chosen when audit trails of dropped ICMP packets are required.

Visual reference

Source Router + ACL permit 10.0.0.0/8 deny any Server 10.0.0.5 ✓ 192.168.1.1 ✗ dropped ACLs evaluate top-down; first match wins — implicit deny all at end

About these practice questions

One of 1,401 original 300-410 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 300-410 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 300-410 exam.