hardMultiple Choice
350-401 Practice Question: Runs the following command on switch SW6: SW6#…
A network engineer runs the following command on switch SW6:
SW6# show cts role-based counters
Role-based counters:
Source Group Dest Group Packets Sent Bytes Sent Packets Denied Bytes Denied 10 20 1500 120000 0 0 10 30 0 0 500 40000
Based on this output, what can be concluded?
⚠ Common exam trap
The trap here is that candidates often misinterpret the 'Packets Sent' and 'Packets Denied' columns, assuming that non-zero values in one column imply the opposite action for the other, when in fact both columns are independent counters that must be read together to determine the actual policy outcome.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Traffic from SGT 10 to SGT 20 is being permitted, and traffic from SGT 10 to SGT 30 is being denied.
The output shows that for the source group (SGT) 10 to destination group (SGT) 20, packets sent and bytes sent are non-zero (1500 and 120000 respectively), while packets denied and bytes denied are zero. This indicates traffic is being permitted. For SGT 10 to SGT 30, packets sent and bytes sent are zero, but packets denied and bytes denied are non-zero (500 and 40000), indicating traffic is being denied. Therefore, option C is correct.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Traffic from SGT 10 to SGT 20 is being denied.
Why it's wrong here
This is incorrect because the TrustSec SGACL counters for the SGT 10 to SGT 20 flow show zero packets denied. A zero on the deny counter means that no packets in that flow matched any deny ACE, and the hardware would only increment that counter if a deny action were executed. Therefore, the flow is being permitted, not denied.
- ✗
Traffic from SGT 10 to SGT 30 is being permitted.
Why it's wrong here
This is wrong because the counters show 500 packets denied for the SGT 10 to SGT 30 flow. A non-zero deny count is definitive proof that the SGACL deny ACE matched and dropped packets for that flow. If the traffic were being permitted, the deny counter would have remained at zero, so the traffic is unequivocally being denied.
- ✓
Traffic from SGT 10 to SGT 20 is being permitted, and traffic from SGT 10 to SGT 30 is being denied.
Why this is correct
The counters confirm both flow outcomes: for SGT 10 to SGT 20, the deny counter is zero while the permit counter has incremented, so that traffic is being permitted; for SGT 10 to SGT 30, the deny counter has incremented 500 times, proving that traffic is being denied. This is the only interpretation that is consistent with both observed counter values and explains the full policy behavior.
- ✗
No traffic has been sent between any SGTs.
Why it's wrong here
This is false because the counters clearly show that traffic has been sent and processed: the flow from SGT 10 to SGT 20 has a non-zero permit count, and the flow from SGT 10 to SGT 30 has 500 denied packets, both of which indicate packets were transmitted and evaluated by the SGACL. If no traffic had been sent, all counters for these flows would still be at zero, which is not the case.
Go deeper
Related to this question
About these practice questions
One of 1,923 original 350-401 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.