Courseiva
mediumMultiple Choice

350-401 Practice Question: Runs the following command on Router R1: R1# show…

A network engineer runs the following command on Router R1:

R1# show ip access-lists

Extended IP access list 120

10 permit tcp 10.0.0.0 0.255.255.255 any eq 22 (5 matches)
    
20 permit tcp 172.16.0.0 0.0.255.255 any eq 22 (3 matches)
    
30 deny tcp any any eq 22 (2 matches)
    
40 permit ip any any (10 matches)

Based on this output, what can be concluded?

⚠ Common exam trap

Cisco often tests the misconception that an implicit deny at the end of an ACL is the only reason traffic is blocked, ignoring that explicit deny entries can also block traffic and that the order of entries matters.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

SSH access from 192.168.1.0/24 would be denied.

The ACL 120 explicitly denies TCP traffic to port 22 (SSH) from any source not matching the earlier permit statements. The source 192.168.1.0/24 is not covered by the permit entries (10.0.0.0/8 or 172.16.0.0/16), so it hits line 30 (deny tcp any any eq 22) and is denied. The 5 matches on line 10 and 3 on line 20 confirm that only traffic from those specific subnets is permitted for SSH.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    SSH access from 192.168.1.0/24 would be denied.

    Why this is correct

    Entry 30 of the ACL is an explicit deny statement for SSH traffic from any source IP address that has not already been permitted by entries 10 or 20. Because the source prefix 192.168.1.0/24 is outside the ranges specified in those earlier permit statements, it matches the wildcard condition of entry 30 and is denied. This occurs before the final permit-any statement (entry 40), which only applies to non-SSH traffic. Thus, SSH access from 192.168.1.0/24 is indeed denied.

  • ✗

    SSH access from 10.0.0.0/8 is denied.

    Why it's wrong here

    This statement is incorrect because entry 10 explicitly permits SSH traffic originating from the 10.0.0.0/8 address space. Typically, an ACL like this uses an extended access list with a source wildcard mask of 0.255.255.255 to match the entire 10/8 range. Since the evaluation is first-match, packets from 10.x.x.x are matched and permitted by entry 10 before any later deny statement could apply. Therefore, SSH access from 10.0.0.0/8 is not denied.

  • ✗

    All SSH traffic is permitted.

    Why it's wrong here

    This statement misreads the ACL's structure: while entry 10 and entry 20 permit SSH from specific sources, entry 30 is a catch-all deny that blocks SSH from every other source. Only unsupported source ranges are denied, but because this ACL is deployed on a control-plane interface, any SSH source outside the named prefixes will be dropped. Consequently, 'all SSH traffic' is not permitted; it is strictly filtered. The existence of a final permit-any only allows non-SSH protocols through, not SSH.

  • ✗

    The ACL has an implicit deny at the end.

    Why it's wrong here

    This statement is false because the ACL ends with an explicit 'permit ip any any' statement (entry 40), which overrides the default implicit deny for any traffic that reaches that point. For non-SSH traffic, the final permit-any ensures it is forwarded, so the implicit deny is never invoked for those packets. For SSH traffic, the deny is an explicit statement in entry 30, not an implicit one. Thus, the ACL does not rely on an implicit deny at the end.

Visual reference

Source Router + ACL permit 10.0.0.0/8 deny any Server 10.0.0.5 ✓ 192.168.1.1 ✗ dropped ACLs evaluate top-down; first match wins — implicit deny all at end

About these practice questions

Courseiva writes every 350-401 question from scratch — 1,923 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.