easyMultiple Select
350-401 Practice Question: Which two statements about the 'ip access-group'…
Which two statements about the 'ip access-group' command are true? (Choose two.)
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The 'ip access-group' command applies an ACL to an interface in a specified direction.
Option A is correct because the 'ip access-group' command binds an existing ACL to an interface and requires a direction keyword (in or out), thereby filtering traffic in that specified direction. Option B is correct because 'ip access-group' can be configured on physical interfaces (e.g., GigabitEthernet0/1) as well as on switched virtual interfaces (SVIs) such as interface Vlan10, since both are Layer 3 interfaces that support ACL application. Option C is incorrect because 'ip access-group' only applies an already-defined ACL; it does not create one, and referencing a nonexistent ACL results in an error or an empty ACL depending on platform. Option D is incorrect because the command supports both the inbound and outbound directions via the 'in' and 'out' keywords. Option E is incorrect because CoPP policies are applied to the control plane using the 'service-policy' command under 'control-plane' configuration, not with 'ip access-group'.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
The 'ip access-group' command applies an ACL to an interface in a specified direction.
Why this is correct
The ip access-group command binds a numbered or named ACL to a specific interface and specifies whether filtering applies inbound or outbound. This satisfies the stem's requirement for an accurate statement about the command's behaviour.
- ✓
The 'ip access-group' command can be applied to both physical interfaces and SVIs.
Why this is correct
The command binds an ACL to an interface's forwarding path, and that binding works on routed ports and switched virtual interfaces alike, since SVIs are logical Layer 3 interfaces. This satisfies the stem's requirement that both interface types are valid application points.
- ✗
The 'ip access-group' command creates a new ACL if the named ACL does not exist.
Why it's wrong here
The ip access-group command references an existing ACL by name or number; it does not create one, and referencing a non-existent ACL produces an error rather than instantiating it. It is tempting because named ACLs are configured with similar syntax, but creation happens under ip access-list, not at the interface.
- ✗
The 'ip access-group' command can only filter traffic in the inbound direction.
Why it's wrong here
The ip access-group command accepts an in or out keyword, applying the ACL to either ingress or egress traffic on the interface. Inbound-only filtering is therefore false. It is tempting because inbound ACLs are commonly deployed for edge filtering, but the command itself supports both directions.
- ✗
The 'ip access-group' command is used to apply a CoPP policy to the control plane.
Why it's wrong here
CoPP is applied globally with the control-plane host command referencing a policy-map, not with ip access-group on an interface. It is tempting because CoPP policies do use ACLs internally to classify control-plane traffic, but ip access-group binds an ACL to interface forwarding traffic, not to the control plane.
Visual reference
Go deeper
Related to this question
About these practice questions
This 350-401 question is part of Courseiva's 1,923-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.