mediumMultiple Choice
ACL Inbound Show Access-List Interpretation
A network engineer runs the following command on Router R1:
R1# show ip interface GigabitEthernet0/1 | include access list
Inbound access list is not set Outbound access list is 140
R1# show access-lists 140
Extended IP access list 140
10 permit tcp 192.168.1.0 0.0.0.255 any eq 443 (25 matches)
20 deny tcp any any eq 443 (10 matches)
30 permit ip any any (50 matches)Based on this output, what can be concluded?
⚠ Common exam trap
Cisco often tests the distinction between inbound and outbound ACL application, and the trap here is that candidates see 'permit ip any any' and mistakenly think all traffic is allowed, ignoring the order-specific deny of HTTPS from other sources.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
HTTPS traffic from sources outside 192.168.1.0/24 is denied when exiting the interface.
The ACL 140 is applied outbound on GigabitEthernet0/1. It permits TCP port 443 (HTTPS) traffic only from source 192.168.1.0/24, then denies all other HTTPS traffic, and finally permits all other IP traffic. Since the deny statement (line 20) blocks HTTPS from any source not matching the permit (line 10), traffic from outside 192.168.1.0/24 is denied when exiting the interface, making option A correct.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
HTTPS traffic from sources outside 192.168.1.0/24 is denied when exiting the interface.
Why this is correct
Because ACL 140 is applied to outbound traffic on this interface, it evaluates packets as they are leaving the interface. Entry 10 permits HTTPS only from the 192.168.1.0/24 source network, while entry 20 explicitly denies HTTPS from any source that does not match that permit. Therefore, HTTPS sessions initiated from addresses outside that subnet will be denied when they attempt to exit the interface.
- ✗
All HTTPS traffic is permitted outbound.
Why it's wrong here
This statement is false because the ACL does not permit all HTTPS traffic; it only allows HTTPS from 192.168.1.0/24. Traffic from any other source network is explicitly denied by entry 20, and even if that entry were removed, the implicit deny at the end of every IP access list would still block it. Outbound HTTPS from other subnets is therefore dropped.
- ✗
The ACL is applied inbound on the interface.
Why it's wrong here
The output explicitly indicates 'Outbound access list is 140,' meaning the ACL is configured for the outbound direction on this interface, not inbound. An inbound ACL filters packets arriving on the interface, whereas an outbound ACL filters packets leaving it. Since the output states 'outbound,' any claim that it is applied inbound misreads the direction shown in the interface configuration.
- ✗
The ACL permits all traffic from 192.168.1.0/24.
Why it's wrong here
The ACL only permits TCP port 443 (HTTPS) from the 192.168.1.0/24 network; it does not permit all traffic from that source. Any other protocol, such as HTTP, SSH, or ICMP, from that subnet will be dropped by the implicit deny statement at the end of the ACL. Thus, the permit scope is limited to a single service, not all traffic.
Visual reference
Go deeper
Related to this question
About these practice questions
Courseiva writes every 350-401 question from scratch — 1,923 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.