Courseiva
mediumMultiple Choice

ACL Application Direction and Common Pitfalls

Examine the following configuration snippet:

interface GigabitEthernet0/1
 ip access-group FILTER_IN in

!

ip access-list extended FILTER_IN
 deny   icmp any any echo
 permit ip any any

What is the effect of this configuration?

⚠ Common exam trap

Cisco often tests the distinction between 'all ICMP' and 'specific ICMP types' — the trap here is assuming 'deny icmp any any echo' blocks all ICMP traffic, when it only blocks Echo requests, leaving other ICMP types permitted.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

It blocks inbound ICMP Echo requests on GigabitEthernet0/1.

The access list FILTER_IN explicitly denies ICMP packets with the 'echo' type (ping requests) while permitting all other IP traffic. Applied inbound on GigabitEthernet0/1, this blocks only inbound ICMP Echo requests, not all ICMP traffic (e.g., Echo replies, TTL-exceeded messages are permitted). The 'permit ip any any' at the end ensures all other traffic is allowed.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    It blocks all ICMP traffic inbound on GigabitEthernet0/1.

    Why it's wrong here

    The ACL does not filter all ICMP traffic; it only contains a deny statement that matches ICMP Echo (type 8), which corresponds to ping requests. Other ICMP message types such as Echo Reply (type 0), Destination Unreachable (type 3), and Time Exceeded (type 11) do not match this entry and fall through to the subsequent permit ip any any statement, so they are forwarded normally. Therefore, the claim that it blocks all inbound ICMP is incorrect because only one specific ICMP type is denied.

  • ✓

    It blocks inbound ICMP Echo requests on GigabitEthernet0/1.

    Why this is correct

    This configuration filters ingress traffic on GigabitEthernet0/1 by matching ICMP packets with type 8, which is the Echo request used by ping. Because the access-group is applied in the inbound direction, any ICMP Echo request arriving on the interface is denied and dropped, while every other packet—including other ICMP types and all IP protocols—matches the final permit ip any any and is permitted. The result is precisely that inbound ICMP Echo requests (pings) are blocked, but nothing else is affected.

  • ✗

    It blocks all inbound traffic on GigabitEthernet0/1.

    Why it's wrong here

    The ACL does not block all inbound traffic because the last statement, permit ip any any, is an explicit catch-all that permits anything not previously denied. Only packets that match the earlier deny statement—specifically ICMP Echo requests—are dropped; all other traffic, whether TCP, UDP, or other IP protocols, matches the permit statement and is allowed. Thus the effect is a targeted denial of one packet type rather than a blanket inbound shutdown, making this option incorrect.

  • ✗

    It blocks outbound ICMP Echo requests on GigabitEthernet0/1.

    Why it's wrong here

    This option misstates the direction of the access-group. The ACL is applied with the inbound keyword, meaning it evaluates packets as they enter GigabitEthernet0/1 from the network, not as they exit the interface. Outbound ICMP Echo requests—those sourced from the router or forwarded toward the external network—are not inspected by this ACL at all, so they would not be blocked. Since the deny rule only acts on incoming traffic, the claim about outbound blocking is wrong.

Visual reference

Source Router + ACL permit 10.0.0.0/8 deny any Server 10.0.0.5 ✓ 192.168.1.1 ✗ dropped ACLs evaluate top-down; first match wins — implicit deny all at end

About these practice questions

This 350-401 question is part of Courseiva's 1,923-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

2 more ways this is tested on 350-401

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. Review the ACL configuration: ip access-list extended TEST permit tcp 192.168.1.0 0.0.0.255 any eq 80 permit tcp 192.168.1.0 0.0.0.255 any eq 443 deny ip any any ! interface GigabitEthernet0/3 ip access-group TEST in What is missing or incorrect?

medium
  • A.The ACL should use a wildcard mask of 255.255.255.0 instead of 0.0.0.255.
  • ✓ B.The deny ip any any is redundant because ACLs have an implicit deny at the end.
  • C.The ACL must be applied outbound to filter incoming traffic.
  • D.The ACL should use the keyword 'established' to allow return traffic.

Why B: The `deny ip any any` line is redundant. Cisco ACLs have an implicit deny all at the end of every ACL, so adding an explicit deny is unnecessary and does not change the behavior. The configuration is otherwise valid for filtering inbound traffic on GigabitEthernet0/3.

Variation 2. Given the following configuration: ip access-list extended FILTER permit tcp any host 10.1.1.1 eq 22 permit icmp any any echo-reply ! interface GigabitEthernet0/4 ip access-group FILTER in What traffic is permitted?

medium
  • A.Only SSH traffic to 10.1.1.1 is permitted.
  • ✓ B.SSH to 10.1.1.1 and ICMP Echo Reply are permitted.
  • C.All ICMP traffic is permitted.
  • D.Only traffic from host 10.1.1.1 is permitted.

Why B: The access list FILTER permits TCP traffic to destination host 10.1.1.1 on port 22 (SSH) and ICMP packets of type Echo Reply. Since the list is applied inbound on GigabitEthernet0/4, only these two types of traffic are allowed into the interface. Option B correctly identifies both permitted traffic types.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.