Courseiva
mediumMultiple Choice

ISC2 CC Practice Question: Based on the exhibit, which statement about the…

Exhibit

Refer to the exhibit.

```
show access-list 101
Standard IP access list 101
    10 permit tcp any any eq 80
    20 deny icmp any any
    30 permit ip any any
```

Based on the exhibit, which statement about the access control list is true?

⚠ Common exam trap

ISC2 often tests the sequential nature of ACLs and the fact that 'permit ip any any' permits all IP protocols except those explicitly denied earlier, leading candidates to mistakenly think ICMP is permitted or that only HTTP is allowed.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

All IP traffic is permitted except ICMP

The exhibit shows an access control list (ACL) that explicitly denies ICMP traffic with the entry 'deny icmp any any' and then permits all other IP traffic with 'permit ip any any'. Since ACLs are processed sequentially and the 'permit ip any any' matches all IP protocols (including HTTP, HTTPS, etc.) except those already denied, the result is that all IP traffic is permitted except ICMP. This makes option A correct.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    All IP traffic is permitted except ICMP

    Why this is correct

    The ACL's implicit deny is overridden by a permit statement covering all IP protocols, so every packet type is forwarded; only ICMP is explicitly denied by a preceding rule. This matches the exhibit's rule order, where the ICMP deny sits above the blanket permit.

  • ✗

    HTTP traffic is denied

    Why it's wrong here

    Denying HTTP would block inbound web requests, yet the exhibit's ACL permits port 80, so this contradicts the rule order shown. It tempts because a deny statement does appear in the list, but that entry targets a different protocol or source, not HTTP itself.

  • ✗

    Only HTTP traffic is permitted

    Why it's wrong here

    The ACL also permits other protocols or ports beyond port 80, so HTTP is not the sole permitted traffic. It tempts because HTTP is explicitly allowed, but the exhibit shows additional permit entries that this statement ignores.

  • ✗

    ICMP echo requests are permitted

    Why it's wrong here

    Permitting ICMP echo requests contradicts the exhibit's deny statement for that traffic, so the claim is false. It is tempting because echo requests are commonly permitted for troubleshooting, which would be correct if the ACL contained an explicit permit icmp any any rule.

Visual reference

Source Router + ACL permit 10.0.0.0/8 deny any Server 10.0.0.5 ✓ 192.168.1.1 ✗ dropped ACLs evaluate top-down; first match wins — implicit deny all at end

About these practice questions

Courseiva writes every CC question from scratch — 989 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.