Courseiva
hardMultiple Select

350-401 Practice Question: Which three statements about IPv4 ACLs on Cisco…

Which three statements about IPv4 ACLs on Cisco IOS are true? (Choose three.)

⚠ Common exam trap

350-401 often tests ACL processing order and direction — candidates assume 'last match wins' or confuse inbound/outbound filtering, but IOS ACLs are first-match, top-down, and inbound filters traffic entering the interface.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Standard ACLs can filter traffic based on source IP address only.

Option A is correct because standard IPv4 ACLs (numbered 1–99 and 1300–1999, or named with the standard keyword) match only on the source IP address, so they can permit or deny traffic solely by source. Option B is correct because extended IPv4 ACLs (numbered 100–199 and 2000–2699, or named with the extended keyword) can match source and destination IP addresses, the IP protocol (ip, tcp, udp, icmp, etc.), and Layer 4 port numbers using operators such as eq, gt, lt, and range. Option C is correct because every Cisco IOS ACL ends with an implicit deny any (deny ip any any for extended, deny any for standard), which drops any packet that does not match an earlier permit statement. Option D is incorrect because ACL entries are processed top-down, and the first match determines the action, not the last match. Option E is incorrect because an inbound ACL filters traffic entering the interface, while an outbound ACL filters traffic leaving the interface.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Standard ACLs can filter traffic based on source IP address only.

    Why this is correct

    Standard ACLs match only on the source IPv4 address, so they cannot distinguish destination, protocol or port. This limited matching capability is the defining constraint that separates standard ACLs from extended ACLs on Cisco IOS.

  • ✓

    Extended ACLs can filter based on source and destination IP addresses, protocol, and port numbers.

    Why this is correct

    Extended ACLs match on source and destination addresses, protocol type, and Layer 4 port numbers, giving granular traffic control. This multi-field matching capability is precisely what distinguishes extended ACLs from standard ACLs, which filter on source address alone.

  • ✓

    An implicit deny any statement is automatically added at the end of every ACL.

    Why this is correct

    Every Cisco IOS ACL carries an invisible implicit deny any at its end. Any packet not explicitly permitted by an earlier statement is dropped, so each ACL must contain at least one permit entry or all traffic is blocked.

  • ✗

    ACL entries are processed from bottom to top, with the last match determining the action.

    Why it's wrong here

    Cisco IOS evaluates ACL entries top to bottom and stops at the first match, so later entries are never consulted. It tempts because ordering matters, and a top-down first-match ACL is correct when you deliberately place specific deny statements above broader permit statements.

  • ✗

    An ACL applied to an inbound interface filters traffic leaving that interface.

    Why it's wrong here

    An inbound ACL filters packets arriving on the interface, not those leaving it; outbound filtering requires the ACL applied in the outbound direction. It tempts because direction is easily confused, and inbound ACLs are the correct choice when filtering traffic entering from an untrusted network.

Visual reference

Source Router + ACL permit 10.0.0.0/8 deny any Server 10.0.0.5 ✓ 192.168.1.1 ✗ dropped ACLs evaluate top-down; first match wins — implicit deny all at end

About these practice questions

One of 1,923 original 350-401 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.