Which two different configuration can you apply to a device to block incoming SSH access?

ccnp-dump
ccnp-route-dump
ccnp-route

#1

Which two different configuration can you apply to a device to block incoming SSH access? (Choose two)

  • A. ipv6 access-list VTY-ACESS-IN
    sequence 10 deny tcp any any eq 22
    sequence 20 permit ipv6 any any
    interface Ethernet0/0
    ip traffic-filter VTY-ACCESS-IN out
  • B. ipv6 access-list VTY-ACESS-IN
    sequence 10 deny tcp any any eq 22
    sequence 20 permit ipv6 any any
    interface Ethernet0/0
    ip traffic-filter VTY-ACCESS-IN in
  • C. ipv6 access-list VTY-ACESS-IN
    sequence 10 deny tcp any any eq 22
    sequence 20 permit ipv6 any any
    line vty 0 15
    ip access-class VTY-ACCESS-IN in
  • D. ipv6 access-list VTY-ACESS-IN
    sequence 10 deny tcp any any eq 22
    sequence 20 permit ipv6 any any
    line vty 0 15
    ip access-list VTY-ACCESS-IN out
  • E. ipv6 access-list VTY-ACESS-IN
    sequence 10 deny tcp any any eq 22
    sequence 20 permit ipv6 any any
    interface Ethernet0/0
    ip traffic-filter VTY-ACCESS-IN out

Correct Answer: BC

Explanation:
If you are denying incoming traffic you would apply the access list in the inbound direction, not outbound.