Courseiva
← Back to Cisco CCNP ENARSI 300-410 questions

Scenario-based practice

Access Control List (ACL) Scenarios

Practise 300-410 ACL questions covering standard vs extended ACLs, top-down processing, implicit deny, inbound vs outbound placement, and troubleshooting traffic that is unexpectedly blocked or permitted.

15
scenario questions
300-410
exam code
Cisco
vendor

Scenario guide

How to approach access control list (acl) scenarios

ACL questions test your ability to read, write, and place access lists correctly. They appear as configuration tasks, troubleshooting scenarios, and exhibit-based questions showing ACL output. The CCNA covers standard and extended ACLs for both IPv4 and IPv6.

Quick answer

ACL questions usually test top-down rule processing, source and destination matching, protocol or port logic, and where the ACL should be applied.

Standard versus extended ACL behaviour.

Top-down processing and the implicit deny rule.

Source, destination, protocol and port matching.

Inbound versus outbound ACL placement.

Related practice questions

Related 300-410 topic practice pages

Scenario questions usually connect to one or more exam topics. Use these links to review the underlying concepts behind the scenario.

Practice set

Practice scenarios

Question 1easymultiple choice
Study the full IPv6 explanation →

A network engineer runs the following command on Router R1:

R1# show ipv6 access-list DENY-REMOTE

IPv6 access list DENY-REMOTE

deny ipv6 2001:DB8:2::/48 any sequence 10
    permit ipv6 any any sequence 20

Based on this output, what is the effect of this access list when applied to an interface?

Question 2mediummultiple choice
Study the full ACL explanation →

A network engineer is configuring policy-based routing (PBR) on a Cisco IOS XE router. The router has two interfaces: GigabitEthernet0/0 (LAN) and GigabitEthernet0/1 (WAN). The engineer wants all HTTP traffic from the 10.1.1.0/24 subnet to be routed via next-hop 192.168.2.2 instead of the default route. The engineer creates a route map named PBR with sequence 10, matches an ACL that permits TCP port 80 from 10.1.1.0/24, and sets the next-hop to 192.168.2.2. The route map is applied to interface GigabitEthernet0/0 with the command `ip policy route-map PBR`. However, traffic still follows the default route. Which action will fix the problem?

Question 3hardmultiple choice
Study the full ACL explanation →

A network engineer runs the following command on Router R1:

R1# show policy-map control-plane

Control Plane

Service-policy input: CoPP-IN

Class-map: CoPP-SNMP (match-all) 0 packets, 0 bytes 5 minute offered rate 0000 bps, drop rate 0000 bps Match: access-group 130 police: cir 32000 bps, bc 6000 bytes, be 6000 bytes conformed 0 packets, 0 bytes; actions: transmit exceeded 0 packets, 0 bytes; actions: drop violated 0 packets, 0 bytes; actions: drop

R1# show access-lists 130

Extended IP access list 130

10 permit udp any any eq snmp
    
20 permit udp any any eq snmptrap

Based on this output, what is the most likely reason that no packets are matching the CoPP-SNMP class?

Question 4mediummultiple choice
Study the full IPv6 explanation →

Consider the following configuration:

ipv6 access-list BLOCK-ICMP

deny icmp any any echo-request
 deny icmp any any echo-reply
 permit ipv6 any any

interface GigabitEthernet0/2

ipv6 traffic-filter BLOCK-ICMP in

Which statement is true?

A network engineer runs the following command to troubleshoot SNMP access lists:

R1# show snmp access
Access-list: 10

Community: public View: v1default

Access-list: 20

Community: private View: v1default

What does this output indicate?

Question 6mediummultiple choice
Open the full BGP breakdown →

Examine the following configuration on a PE router:

ip vrf CUSTOMER-E

rd 400:1 route-target export 400:1 route-target import 400:2 !

interface GigabitEthernet0/5
 ip vrf forwarding CUSTOMER-E
 ip address 10.4.4.1 255.255.255.252

!

router bgp 65000
 neighbor 10.0.0.1 remote-as 65000
 neighbor 10.0.0.1 update-source Loopback0

! address-family vpnv4

neighbor 10.0.0.1 activate
  neighbor 10.0.0.1 send-community extended

exit-address-family ! address-family ipv4 vrf CUSTOMER-E

neighbor 10.4.4.2 remote-as 65003
  neighbor 10.4.4.2 activate
  neighbor 10.4.4.2 route-map SET-COMMUNITY in

exit-address-family ! route-map SET-COMMUNITY permit 10 set community 100:100

What is the effect of the route-map on the incoming routes from the CE?

Question 7easymultiple choice
Study the full ACL explanation →

What is the default behavior of an IPv4 access control list (ACL) when no explicit permit or deny statement matches a packet?

Question 8mediummultiple choice
Read the full VPN explanation →

A network engineer runs the following command on Router R1:

R1# show crypto ipsec sa peer 10.1.1.2
interface: Tunnel0
    Crypto map tag: VPN-MAP, local addr 10.1.1.1

protected vrf: (none) local ident (addr/mask/prot/port): (10.1.1.0/255.255.255.0/0/0) remote ident (addr/mask/prot/port): (192.168.1.0/255.255.255.0/0/0) current_peer 10.1.1.2 port 500 PERMIT, flags={origin_is_acl,} #pkts encaps: 100, #pkts encrypt: 100, #pkts digest: 100 #pkts decaps: 0, #pkts decrypt: 0, #pkts verify: 0 #send errors 0, #recv errors 0

Based on this output, what is the problem?

Question 9hardmultiple choice
Review the full OSPF breakdown →

A router has CoPP configured with a class-map that matches OSPF traffic and polices it to 2000 pps. The router is also configured with an OSPF distribute-list in to filter routes. After applying CoPP, OSPF neighbors form, but routes from a specific neighbor are missing. The distribute-list permits all routes. Which is the most likely explanation?

Question 10harddrag order
Study the full ACL explanation →

Drag and drop the steps to troubleshoot IPv4 ACL adjacency or connectivity failures into the correct order, from first to last.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5
Question 11hardmultiple choice
Study the full ACL explanation →

An engineer configures Control Plane Policing (CoPP) on a router to protect the control plane. After applying the policy, the router becomes unreachable via SSH and SNMP. The engineer checks the policy and confirms that the class-map for SSH and SNMP traffic is set to 'permit'. What is the most likely explanation?

Question 12mediummultiple choice
Study the full ACL explanation →

A network engineer runs the following command to troubleshoot an IPv4 Access Control Lists issue:

R1# show ip access-lists 130

Extended IP access list 130

10 deny ip host 10.1.1.1 host 10.2.2.2
    
20 permit ip any any

Then the engineer runs:

R1# debug ip packet 130
IP packet debugging is on for access list 130
*Mar  1 00:20:10.123: IP: s=10.1.1.1 (GigabitEthernet0/0), d=10.2.2.2, len 100, proto ICMP, access list 130: matched line 
10 deny ip host 10.1.1.1 host 10.2.2.2

What does this output indicate?

Question 13mediummultiple choice
Open the full BGP breakdown →
Router R4 has the following configuration:

!--- R4 configuration route-map SETTAG permit 10 match tag 100 set tag 200 ! route-map SETTAG permit 20 !

router bgp 65100
 neighbor 10.0.0.1 route-map SETTAG in

!

What is the effect of this configuration?

Question 14hardmultiple choice
Open the full VLAN trunking answer →

An engineer applies an IPv6 ACL to filter traffic between two VLANs on a switch using a router-on-a-stick configuration. The ACL is applied inbound on the subinterface. Traffic from VLAN 10 to VLAN 20 is permitted, but return traffic from VLAN 20 to VLAN 10 is dropped. Which is the most likely explanation?

Question 15easymultiple choice
Review the full routing breakdown →

A network engineer runs the following command on Router R1:

R1# show ip interface GigabitEthernet0/1

GigabitEthernet0/1 is up, line protocol is up Internet address is 10.1.1.1/24 Broadcast address is 255.255.255.255 Address determined by non-volatile memory MTU is 1500 bytes Helper address is not set Directed broadcast forwarding is disabled Outgoing access list is 101 Inbound access list is not set

Based on this output, which statement is correct?

These 300-410 practice questions are part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style 300-410 questions with detailed explanations, topic-based practice, mock exams, readiness tracking, and study analytics.