mediumMultiple Choice
300-410 Practice Question: Runs the following command on Router R6: R6# show…
A network engineer runs the following command on Router R6:
R6# show logging | include %SEC-6-IPACCESSLOGP *Mar 1 00:01:15.123: %SEC-6-IPACCESSLOGP: list ACL_INBOUND denied tcp 10.0.0.100(12345) -> 192.168.1.1(80), 1 packet *Mar 1 00:01:20.456: %SEC-6-IPACCESSLOGP: list ACL_INBOUND denied tcp 10.0.0.100(12346) -> 192.168.1.1(80), 1 packet *Mar 1 00:01:25.789: %SEC-6-IPACCESSLOGP: list ACL_INBOUND denied tcp 10.0.0.100(12347) -> 192.168.1.1(80), 1 packet *Mar 1 00:01:30.012: %SEC-6-IPACCESSLOGP: list ACL_INBOUND denied tcp 10.0.0.100(12348) -> 192.168.1.1(80), 1 packet
Based on this output, what is the most likely problem?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
A host at 10.0.0.100 is attempting to access a web server at 192.168.1.1 and is being blocked by the ACL.
The output shows repeated denied packets from source 10.0.0.100 to destination 192.168.1.1 on port 80 (HTTP). This indicates that a host at 10.0.0.100 is trying to access a web server at 192.168.1.1 but is being blocked by ACL ACL_INBOUND. The pattern suggests a possible scan or attack, or a legitimate access that is being denied due to misconfiguration.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The ACL ACL_INBOUND is permitting traffic from 10.0.0.100 to 192.168.1.1 on port 80.
Why it's wrong here
Each entry states the packets were denied, so the ACL is blocking rather than permitting that flow; the log keyword itself records drops. Permitting is what an ACL does when its statements match with permit, which would be the expected output had the engineer intended to allow this traffic.
- ✓
A host at 10.0.0.100 is attempting to access a web server at 192.168.1.1 and is being blocked by the ACL.
Why this is correct
The ACL_INBOUND list is denying TCP traffic from 10.0.0.100 to 192.168.1.1 on port 80, with incrementing source ports indicating repeated connection attempts. This confirms the host is blocked from reaching the web server by the inbound ACL.
- ✗
The router is experiencing a DoS attack from 192.168.1.1.
Why it's wrong here
The denied packets originate from 10.0.0.100 toward 192.168.1.1, so the source is the client, not the destination server; nothing indicates attack volume or spoofing. DoS analysis would be the right approach if the log showed high-rate traffic from many sources targeting one host.
- ✗
The ACL ACL_INBOUND is not configured on any interface.
Why it's wrong here
The log entries prove ACL_INBOUND is applied and actively matching traffic, since denied packets are logged against that list name. Engineers sometimes assume logging implies a missing binding, but ACL logging is commonly configured for auditing on live interfaces, where it would be the correct diagnostic output.
Visual reference
Go deeper
Related to this question
About these practice questions
One of 1,401 original 300-410 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 300-410 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 300-410 exam.