Courseiva
Infrastructure →easyMultiple Choice

350-401 Infrastructure Practice Question

A network administrator is configuring a Cisco Catalyst switch to allow management access only from the subnet 10.10.10.0/24. The administrator wants to apply an ACL to the VTY lines. Which command correctly applies the ACL named MGMT to the VTY lines?

⚠ Common exam trap

Test-takers frequently confuse interface ACL application with VTY ACL application; many candidates mistakenly use ip access-group on VTY lines, but the correct command is access-class.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

access-class MGMT in

To restrict management access to a Cisco device, an ACL is defined globally and then applied to the VTY lines using the access-class command in line configuration mode. The in keyword filters incoming connections. This ensures that only hosts matching the ACL's permit statements can establish remote management sessions, effectively limiting access to the specified subnet.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    ip access-group MGMT in

    Why it's wrong here

    The ip access-group command is used on router interfaces to filter transit traffic, not on VTY lines. Applying it under line configuration mode is invalid. For controlling management access to the device itself, the access-class command must be used instead. This option would not achieve the desired restriction on VTY access.

  • ✓

    access-class MGMT in

    Why this is correct

    The access-class command is used under line configuration mode to restrict incoming VTY connections based on an ACL. The in keyword specifies that the ACL filters traffic entering the VTY lines. This is the correct way to apply an ACL to management access, ensuring only hosts from permitted subnets can establish SSH or Telnet sessions.

  • ✗

    ip access-class MGMT in

    Why it's wrong here

    There is no command called ip access-class. The correct command is simply access-class, without the ip prefix. This option is a common misnomer. Using it would result in a syntax error, and the ACL would not be applied to the VTY lines, leaving management access unrestricted.

  • ✗

    access-list MGMT in

    Why it's wrong here

    The access-list command is used in global configuration mode to define an ACL, not to apply it to an interface or line. It does not filter traffic on VTY lines. To apply an ACL to VTY lines, the access-class command must be used under line configuration mode. This option is syntactically incorrect for the purpose of restricting management access.

Visual reference

Source Router + ACL permit 10.0.0.0/8 deny any Server 10.0.0.5 ✓ 192.168.1.1 ✗ dropped ACLs evaluate top-down; first match wins — implicit deny all at end

About these practice questions

One of 1,923 original 350-401 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.