mediumMultiple Choice
350-401 Practice Question: Given the following configuration: ip access-list…
Given the following configuration:
ip access-list extended FILTER permit tcp any host 10.1.1.1 eq 22 permit icmp any any echo-reply
!
interface GigabitEthernet0/4 ip access-group FILTER in
What traffic is permitted?
⚠ Common exam trap
Cisco often tests the distinction between 'permit icmp any any echo-reply' (only replies) versus 'permit icmp any any' (all ICMP), leading candidates to overgeneralize the ICMP permit.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
SSH to 10.1.1.1 and ICMP Echo Reply are permitted.
The access list FILTER permits TCP traffic to destination host 10.1.1.1 on port 22 (SSH) and ICMP packets of type Echo Reply. Since the list is applied inbound on GigabitEthernet0/4, only these two types of traffic are allowed into the interface. Option B correctly identifies both permitted traffic types.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Only SSH traffic to 10.1.1.1 is permitted.
Why it's wrong here
This is incomplete because the ACL contains two explicit permit statements: one for TCP port 22 to host 10.1.1.1 and one for ICMP echo-reply. The ICMP echo-reply entry is a separate, valid ACE that matches only the specific ICMP type used in responses to ping. Therefore the claim that only SSH traffic is permitted overlooks the second ACE, making the 'only' statement incorrect.
- ✓
SSH to 10.1.1.1 and ICMP Echo Reply are permitted.
Why this is correct
The ACL permits exactly two types of traffic: SSH to destination host 10.1.1.1, matching the ubiquitous TCP/22 ACE, and ICMP echo-reply (type 0), which is the response packet generated when the device answers a ping. The first ACE uses 'host 10.1.1.1' as the destination, and the second ACE explicitly matches that ICMP type. Together, those two permit statements validate this answer as the only fully accurate description of the ACL's effect.
- ✗
All ICMP traffic is permitted.
Why it's wrong here
The second ACE in the ACL is narrowly scoped to ICMP echo-reply, which is ICMP type 0. Other ICMP message types such as echo-request (type 8), destination unreachable (type 3), or time exceeded (type 11) are not matched by this entry and, because the ACL ends with an implicit deny, they would be dropped. Therefore 'all ICMP' is far too broad and is not what the configuration actually permits.
- ✗
Only traffic from host 10.1.1.1 is permitted.
Why it's wrong here
The permit statements define destinations, not sources: the TCP ACE's 'host 10.1.1.1' appears in the destination field, meaning SSH traffic is allowed when it is destined to 10.1.1.1, not when it originates from that host. Similarly, the ICMP echo-reply ACE matches a reply sent from a remote address to this router, not a packet sourced from 10.1.1.1. This misreading reverses the directionality of the ACL, so the statement is incorrect.
Visual reference
Go deeper
Related to this question
About these practice questions
One of 1,923 original 350-401 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.