Courseiva
mediumMultiple Choice

350-401 Practice Question: Review the ACL configuration: ip access-list…

Review the ACL configuration:

ip access-list extended TEST
 permit tcp 192.168.1.0 0.0.0.255 any eq 80
 permit tcp 192.168.1.0 0.0.0.255 any eq

443

deny ip any any

!

interface GigabitEthernet0/3
 ip access-group TEST in

What is missing or incorrect?

⚠ Common exam trap

Cisco often tests the concept of the implicit deny to see if candidates recognize that an explicit deny at the end of an ACL is redundant and does not alter functionality.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The deny ip any any is redundant because ACLs have an implicit deny at the end.

The `deny ip any any` line is redundant. Cisco ACLs have an implicit deny all at the end of every ACL, so adding an explicit deny is unnecessary and does not change the behavior. The configuration is otherwise valid for filtering inbound traffic on GigabitEthernet0/3.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The ACL should use a wildcard mask of 255.255.255.0 instead of 0.0.0.255.

    Why it's wrong here

    The wildcard mask in an ACL is the inverse of the subnet mask: 0 means 'must match' and 255 means 'ignore.' For a /24 network like 192.168.1.0/24, the correct wildcard is 0.0.0.255, which forces exact matching on the first three octets and ignores the host octet. A wildcard of 255.255.255.0 would ignore the network portion and only match hosts ending in .0, which is not the intended traffic and would break the ACL's filtering.

  • ✓

    The deny ip any any is redundant because ACLs have an implicit deny at the end.

    Why this is correct

    Cisco IOS ACLs automatically append an implicit 'deny ip any any' at the end of every access list, so any traffic not explicitly permitted is discarded without further configuration. The explicit 'deny ip any any' is therefore redundant—it does not change the outcome but can still be included for clarity, to generate logging via the 'log' keyword, or to make the default behavior visible to someone reading the config. Removing it would not alter the security posture.

  • ✗

    The ACL must be applied outbound to filter incoming traffic.

    Why it's wrong here

    The direction keyword in an interface ACL is relative to the interface: 'in' filters packets that are entering the interface (i.e., arriving from the network), while 'out' filters packets leaving the interface after routing. Since the goal is to filter incoming traffic, 'in' is correct—applying the ACL outbound would not affect incoming packets, it would instead filter traffic destined out that interface, which is a completely different traffic flow.

  • ✗

    The ACL should use the keyword 'established' to allow return traffic.

    Why it's wrong here

    The 'established' keyword applies only to TCP and matches packets where the ACK or RST bit is set, indicating an ongoing connection—it does not permit the initial SYN packet. If a host on the permitted source initiates HTTP/HTTPS, the reply traffic would likely have ACK set, but that traffic is destined back to the source and would be handled by a separate permit statement or by stateful inspection if configured. Adding 'established' to this outbound permit would actually block the initial request, and it is not needed for the basic HTTP/HTTPS access described.

Visual reference

Source Router + ACL permit 10.0.0.0/8 deny any Server 10.0.0.5 ✓ 192.168.1.1 ✗ dropped ACLs evaluate top-down; first match wins — implicit deny all at end

About these practice questions

This 350-401 question is part of Courseiva's 1,923-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.