mediumMultiple Choice
350-401 Practice Question: Consider the following configuration on a Cisco…
Consider the following configuration on a Cisco IOS-XE router: ```
ip access-list extended BLOCK_SSH deny tcp any any eq 22 permit ip any any
!
line vty 0 4
access-class BLOCK_SSH in ``` Which statement is true about this configuration?
⚠ Common exam trap
Cisco often tests the distinction between `access-class` (filters traffic to the router) and `access-group` (filters traffic through the router), causing candidates to mistakenly think the ACL applies to transit traffic.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The ACL blocks all SSH traffic to the router, but permits other IP traffic.
The `access-class` command applied to the VTY lines filters inbound Telnet/SSH traffic destined to the router itself. The ACL `BLOCK_SSH` explicitly denies TCP traffic to port 22 (SSH) and permits all other IP traffic. Therefore, SSH connections to the router are blocked, while other IP traffic (e.g., HTTP, SNMP) is allowed. Option A correctly describes this behavior.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
The ACL blocks all SSH traffic to the router, but permits other IP traffic.
Why this is correct
The IPv4 access-class applied inbound on all VTY lines evaluates management-plane traffic destined to the router's virtual terminal ports. Since the first ACE is a TCP deny for destination port 22, every SSH handshake packet is matched and discarded before a session can be established. The later permit ip any any then allows all other IP traffic, such as ICMP, NTP, or HTTPS, to reach the router or its interfaces, so the effect is narrowly scoped to blocking SSH only.
- ✗
The ACL blocks all traffic to the router because the deny statement is first.
Why it's wrong here
This is incorrect because the deny statement is not a blanket deny; it specifically matches TCP packets with a destination port of 22, i.e., SSH traffic. ACLs process statements in order, but after the SSH deny is processed, the subsequent permit ip any any explicitly permits all remaining IP traffic, so non-SSH packets are not blocked. The claim also overlooks that the access-class is only applied to VTY lines, meaning it filters only management access to the router, not traffic destined to other services or transit traffic.
- ✗
The ACL only filters traffic going through the router, not destined to it.
Why it's wrong here
This misstates the function of an access-class. An access-class applied to VTY lines is used precisely to filter inbound Telnet/SSH sessions destined to the router's virtual terminal ports—it is a control-plane filter, not a transit filter. Traffic going through the router (transit traffic) is filtered by ACLs applied on interfaces in the data plane, not by VTY access-class. Therefore, the ACL does filter traffic destined to the router, but only that which targets the VTY service, and it does not apply to routed or forwarded traffic.
- ✗
The ACL permits SSH traffic because the permit statement overrides the deny.
Why it's wrong here
No, permit does not override deny. Cisco IOS ACLs are evaluated in top-down order, and the first matching rule is applied; once a packet matches the deny tcp any any eq 22 rule, the action is deny and evaluation stops for that packet. The permit ip any any is only reached when an earlier statement does not match, so it applies to non-SSH traffic. Thus SSH is blocked, and the permit cannot resurrect a packet that has already been denied.
Visual reference
Go deeper
Related to this question
About these practice questions
One of 1,923 original 350-401 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.