Courseiva
mediumMultiple Choice

350-401 Practice Question: Given the following configuration: ip access-list…

Given the following configuration:

ip access-list extended FILTER
 permit tcp any host 10.1.1.1 eq 22
 permit icmp any any echo-reply

!

interface GigabitEthernet0/4
 ip access-group FILTER in

What traffic is permitted?

⚠ Common exam trap

Cisco often tests the distinction between 'permit icmp any any echo-reply' (only replies) versus 'permit icmp any any' (all ICMP), leading candidates to overgeneralize the ICMP permit.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

SSH to 10.1.1.1 and ICMP Echo Reply are permitted.

The access list FILTER permits TCP traffic to destination host 10.1.1.1 on port 22 (SSH) and ICMP packets of type Echo Reply. Since the list is applied inbound on GigabitEthernet0/4, only these two types of traffic are allowed into the interface. Option B correctly identifies both permitted traffic types.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Only SSH traffic to 10.1.1.1 is permitted.

    Why it's wrong here

    This is incomplete because the ACL contains two explicit permit statements: one for TCP port 22 to host 10.1.1.1 and one for ICMP echo-reply. The ICMP echo-reply entry is a separate, valid ACE that matches only the specific ICMP type used in responses to ping. Therefore the claim that only SSH traffic is permitted overlooks the second ACE, making the 'only' statement incorrect.

  • ✓

    SSH to 10.1.1.1 and ICMP Echo Reply are permitted.

    Why this is correct

    The ACL permits exactly two types of traffic: SSH to destination host 10.1.1.1, matching the ubiquitous TCP/22 ACE, and ICMP echo-reply (type 0), which is the response packet generated when the device answers a ping. The first ACE uses 'host 10.1.1.1' as the destination, and the second ACE explicitly matches that ICMP type. Together, those two permit statements validate this answer as the only fully accurate description of the ACL's effect.

  • ✗

    All ICMP traffic is permitted.

    Why it's wrong here

    The second ACE in the ACL is narrowly scoped to ICMP echo-reply, which is ICMP type 0. Other ICMP message types such as echo-request (type 8), destination unreachable (type 3), or time exceeded (type 11) are not matched by this entry and, because the ACL ends with an implicit deny, they would be dropped. Therefore 'all ICMP' is far too broad and is not what the configuration actually permits.

  • ✗

    Only traffic from host 10.1.1.1 is permitted.

    Why it's wrong here

    The permit statements define destinations, not sources: the TCP ACE's 'host 10.1.1.1' appears in the destination field, meaning SSH traffic is allowed when it is destined to 10.1.1.1, not when it originates from that host. Similarly, the ICMP echo-reply ACE matches a reply sent from a remote address to this router, not a packet sourced from 10.1.1.1. This misreading reverses the directionality of the ACL, so the statement is incorrect.

Visual reference

Source Router + ACL permit 10.0.0.0/8 deny any Server 10.0.0.5 ✓ 192.168.1.1 ✗ dropped ACLs evaluate top-down; first match wins — implicit deny all at end

About these practice questions

One of 1,923 original 350-401 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.