Cisco CCNA (200-301) — All Questions
The figures these questions turn on, pooled by value and printable, with a side to write them from memory: the cram packet, $6.99 →
522 questions
Which layer of the OSI model is responsible for logical addressing and determining the best path to route packets between networks?
- a.Network (Layer 3)✓
- b.Data Link (Layer 2)
- c.Transport (Layer 4)
- d.Session (Layer 5)
The Network layer (Layer 3) handles logical addressing, such as IPv4 and IPv6, and performs routing to select the best path across internetworks. Routers operate at this layer. The Data Link layer uses physical MAC addresses within a single segment, while the Transport layer manages end-to-end delivery.
A host is configured with the IPv4 address 172.16.45.10/20. What is the network address of the subnet it belongs to?
- a.172.16.0.0
- b.172.16.40.0
- c.172.16.45.0
- d.172.16.32.0✓
A /20 mask (255.255.240.0) makes the third octet increment in blocks of 16 (256 - 240 = 16). The subnets in the third octet are 0, 16, 32, 48, so 45 falls in the 32 block, giving a network address of 172.16.32.0. The host portion is zeroed to identify the subnet.
Which IPv6 address type is automatically configured on every IPv6-enabled interface and is only valid within a single link (never routed)?
- a.Unique local (FC00::/7)
- b.Multicast (FF00::/8)
- c.Link-local (FE80::/10)✓
- d.Global unicast (2000::/3)
Link-local addresses in the FE80::/10 range are automatically generated on each IPv6 interface and are used for on-link communication such as neighbor discovery and next-hop routing. Routers never forward packets with link-local source or destination addresses beyond the local link. Global unicast addresses are the routable, Internet-facing addresses.
Which TCP/IP protocol provides connectionless, best-effort delivery with no retransmission or flow control, making it suitable for real-time voice traffic?
- a.ICMP
- b.UDP✓
- c.ARP
- d.TCP
UDP (User Datagram Protocol) is a connectionless Transport layer protocol that adds minimal overhead and does not guarantee delivery, ordering, or provide flow control. This low latency makes it ideal for real-time applications like VoIP and video streaming where speed matters more than retransmission. TCP, by contrast, is connection-oriented and reliable.
On a Cisco switch trunk link using IEEE 802.1Q, how are frames belonging to the native VLAN handled by default?
- a.They are sent untagged✓
- b.They are tagged with the highest VLAN ID
- c.They are tagged with VLAN ID 1
- d.They are dropped for security
With 802.1Q, frames on the native VLAN traverse the trunk untagged by default, while all other VLANs are tagged with a 4-byte VLAN identifier. The native VLAN must match on both ends of the trunk to avoid a mismatch. For security, administrators often change the native VLAN away from the default VLAN 1.
In a Spanning Tree Protocol topology, which switch becomes the root bridge?
- a.The switch with the most ports
- b.The switch configured last
- c.The switch with the lowest bridge ID✓
- d.The switch with the highest MAC address
STP elects the root bridge as the switch with the lowest bridge ID, which is the combination of bridge priority and MAC address. If priorities are equal (default 32768), the lowest MAC address breaks the tie. Administrators lower the priority on the desired switch to control root placement.
Which EtherChannel negotiation protocol is an IEEE open standard (802.3ad) rather than Cisco-proprietary?
- a.VTP
- b.PAgP
- c.LACP✓
- d.CDP
LACP (Link Aggregation Control Protocol) is the IEEE 802.3ad open standard for dynamically bundling multiple physical links into one logical channel. PAgP is Cisco's proprietary equivalent. Bundling links increases bandwidth and provides redundancy while STP treats the channel as a single logical interface.
In a wireless network, what is the primary role of a Wireless LAN Controller (WLC) in a split-MAC architecture?
- a.It centrally manages configuration and RF for lightweight APs✓
- b.It broadcasts the SSID directly to clients
- c.It acts only as a DHCP server
- d.It replaces all access points
In split-MAC (controller-based) deployments, lightweight access points handle real-time RF functions while the WLC centrally manages configuration, security policies, roaming, and RF resource management via CAPWAP tunnels. This centralizes control of many APs. Autonomous APs, by contrast, operate independently without a controller.
A router has two routes to 10.1.1.0/24: a static route with administrative distance 1 and an OSPF route with AD 110. Which route is installed in the routing table?
- a.The OSPF route, because OSPF is dynamic
- b.The static route, because it has the lower AD✓
- c.Neither, they conflict and both are rejected
- d.Both routes, load-balanced equally
Administrative distance measures the trustworthiness of a routing source, and the route with the lower AD is preferred. A static route (AD 1) is preferred over an OSPF route (AD 110) to the same destination. The less-trusted OSPF route is kept in the OSPF database but not installed while the static route is valid.
Which command correctly configures a default static route that forwards all unknown-destination traffic to next-hop 203.0.113.1?
- a.ip route 0.0.0.0 0.0.0.0 203.0.113.1✓
- b.ip route 203.0.113.1 0.0.0.0 0.0.0.0
- c.ip default-gateway 203.0.113.1
- d.ip route 203.0.113.1 255.255.255.255 0.0.0.0
A default route uses 0.0.0.0 0.0.0.0 to match any destination, followed by the next-hop address, so 'ip route 0.0.0.0 0.0.0.0 203.0.113.1' is correct. It is the gateway of last resort used when no more specific route matches. The 'ip default-gateway' command only applies to a device that is not routing (ip routing disabled).
Want these explained in order? Cisco CCNA 200-301 — Complete Study Guide (2026) — PDF + EPUB, $14.99 · 14-day refund →
In OSPFv2, two routers on the same Ethernet segment fail to form an adjacency. Which mismatch is a common cause?
- a.Different hostnames
- b.Different serial numbers
- c.Different interface descriptions
- d.Different hello/dead timers or mismatched area IDs✓
OSPF neighbors must agree on parameters including hello and dead intervals, area ID, authentication, subnet mask, and MTU to reach the FULL adjacency state. A mismatch in any of these prevents the neighbor relationship from forming. Hostnames and descriptions are cosmetic and do not affect adjacency.
What metric does OSPF use by default to calculate the cost of a link?
- a.Hop count
- b.Delay
- c.Load
- d.Bandwidth (reference bandwidth / interface bandwidth)✓
OSPF calculates cost based on bandwidth, using the formula reference bandwidth (default 100 Mbps) divided by the interface bandwidth. Higher-bandwidth links receive lower costs and are preferred. Because modern links exceed the default reference, engineers often raise the reference bandwidth so faster interfaces are distinguished.
A packet arrives at a router destined for 192.168.5.130. The routing table contains 192.168.5.0/24, 192.168.5.128/25, and 0.0.0.0/0. Which route is used?
- a.192.168.5.0/24
- b.All three simultaneously
- c.0.0.0.0/0
- d.192.168.5.128/25✓
Routers forward using the longest prefix match, meaning the most specific route (the one with the longest matching subnet mask) wins. 192.168.5.130 falls within 192.168.5.128/25 (128-255 range), which is more specific than the /24 or the default route. Longer masks always take precedence regardless of administrative distance across differing prefixes.
Which statement about IPv6 Stateless Address Autoconfiguration (SLAAC) is correct?
- a.Hosts build their own address from the Router Advertisement prefix✓
- b.It uses ARP to learn the gateway
- c.It requires a DHCPv6 server to assign every address
- d.It only works with link-local addresses
With SLAAC, a host listens for Router Advertisement messages, takes the announced /64 prefix, and combines it with a self-generated interface identifier to form a global address without a DHCP server. Neighbor Discovery Protocol (not ARP) provides address resolution and router discovery in IPv6. DHCPv6 is optional and can supplement SLAAC for information like DNS.
A network uses Port Address Translation (PAT). How does the router distinguish return traffic for multiple internal hosts sharing one public IP address?
- a.By using unique source port numbers✓
- b.By using different MAC addresses
- c.By assigning each host a separate public IP
- d.By using VLAN tags
PAT (NAT overload) maps many private addresses to a single public IP by translating and tracking unique source port numbers for each session. The router records these port-to-host mappings in its translation table so return traffic is delivered to the correct inside host. This conserves scarce public IPv4 addresses.
Which protocol synchronizes the clocks of network devices so that log timestamps and certificates remain consistent?
- a.Syslog
- b.NTP✓
- c.SNMP
- d.DNS
NTP (Network Time Protocol) synchronizes device clocks to a reliable time source, typically over UDP port 123. Accurate time is essential for correlating Syslog messages, validating certificates, and troubleshooting. Devices reference a stratum hierarchy where lower stratum numbers are closer to the authoritative time source.
A standard IPv4 ACL is applied to filter traffic. On which criterion can a standard ACL match?
- a.Source and destination IP plus port
- b.Destination MAC address
- c.Source IP address only✓
- d.Application-layer payload
Standard IPv4 ACLs (numbered 1-99 and 1300-1999) filter based only on the source IP address. Extended ACLs are required to match source and destination addresses, protocols, and port numbers. Because standard ACLs are less granular, they are typically placed close to the destination to avoid blocking too much traffic.
DHCP snooping classifies switch ports as trusted or untrusted. What happens to a DHCP server reply (DHCPOFFER) received on an untrusted port?
- a.It is dropped✓
- b.It is tagged and logged only
- c.It is rate-limited but allowed
- d.It is forwarded normally
DHCP snooping treats ports facing hosts as untrusted and drops server-sourced messages like DHCPOFFER and DHCPACK arriving on them, preventing rogue DHCP servers. Only trusted ports, typically uplinks toward legitimate DHCP servers, may forward these replies. The feature also builds a binding table that Dynamic ARP Inspection uses.
A switch port is configured with port security in the default violation mode. When an unauthorized MAC address exceeds the maximum, what is the result?
- a.The port reboots the switch
- b.The port is err-disabled and shut down (shutdown mode)✓
- c.The port allows the traffic but sends a Syslog
- d.The port drops only the offending frames but stays up
The default port-security violation mode is shutdown, which places the port in the err-disabled state and requires administrative recovery (or errdisable recovery) when a violation occurs. The 'protect' mode silently drops unknown traffic, while 'restrict' drops it and increments counters plus sends notifications. This limits which MAC addresses can use a port.
Which wireless security standard introduces Simultaneous Authentication of Equals (SAE) to replace the pre-shared key handshake and protect against offline dictionary attacks?
- a.WEP
- b.WPA2
- c.WPA
- d.WPA3✓
WPA3 replaces the WPA2 four-way handshake with SAE (Simultaneous Authentication of Equals), a dragonfly key exchange that resists offline dictionary attacks even with weak passwords. It also adds forward secrecy. WEP and WPA are legacy and cryptographically broken, while WPA2 relies on AES-CCMP but remains vulnerable to some offline attacks.
In a controller-based (SDN) network architecture, which plane does the centralized controller primarily assume from the individual network devices?
- a.Control plane✓
- b.Physical layer
- c.Management plane only
- d.Data (forwarding) plane
SDN separates the control plane from the data plane, centralizing control-plane decisions such as routing and topology in a controller. The controller programs the devices, which continue to forward traffic in their data plane. A southbound interface (for example, OpenFlow or NETCONF) carries instructions from the controller down to the devices.
A configuration management tool applies a desired state to network devices without requiring an agent installed on each device, connecting over SSH and using YAML playbooks. Which tool is described?
- a.Puppet
- b.SNMP
- c.Chef
- d.Ansible✓
Ansible is agentless, pushing configuration over SSH and defining desired state in human-readable YAML playbooks, which makes it popular for network automation. Puppet and Chef traditionally use an agent-based, pull model with their own domain-specific languages. All three enforce consistent, repeatable configuration across many devices.
How many usable host addresses are available on a subnet with a /26 prefix length?
- a.126
- b.64
- c.30
- d.62✓
A /26 mask leaves 6 host bits (32 - 26 = 6). The total addresses are 2^6 = 64, but the network address and the broadcast address cannot be assigned to hosts, so 64 - 2 = 62 usable addresses remain. This block-of-64 sizing is common for medium LAN segments.
Traditionally, which cable type is required to directly connect two Cisco switches together using copper Ethernet ports?
- a.Single-mode fiber
- b.Rollover (console)
- c.Straight-through (patch)
- d.Crossover✓
Connecting two like devices (switch-to-switch or router-to-router) traditionally requires a crossover cable so the transmit and receive pairs align correctly. A straight-through cable connects unlike devices such as switch-to-PC. Modern switches with Auto-MDIX detect and adjust automatically, but the exam expects knowledge of the classic crossover requirement.
What is the broadcast address of the subnet that contains the host 192.168.1.100/27?
- a.192.168.1.96
- b.192.168.1.95
- c.192.168.1.127✓
- d.192.168.1.128
A /27 mask (255.255.255.224) creates a block size of 32 (256 - 224). The subnets are .0, .32, .64, .96, .128, so 192.168.1.100 falls in the .96 subnet (range .96 to .127). The broadcast address is the last address in that block, 192.168.1.127, where all host bits are set to one.
If you borrow 3 bits from the host portion of a classful network to create subnets, how many subnets can you address?
- a.8✓
- b.6
- c.16
- d.3
Each borrowed bit doubles the number of subnets, so borrowing 3 bits yields 2^3 = 8 subnets. Modern classless routing (and Cisco's default 'ip subnet-zero' behavior) allows using all 8, including the all-zeros and all-ones subnets. The remaining host bits determine how many hosts each subnet supports.
Which is the correctly compressed form of the IPv6 address 2001:0db8:0000:0000:0000:ff00:0042:8329?
- a.2001:db8::ff00:42:8329✓
- b.2001:db8:0:0:ff00:42:8329
- c.2001::db8:ff00:42:8329
- d.2001:0db8::ff00::8329
IPv6 compression removes leading zeros within each hextet and replaces one contiguous run of all-zero hextets with a double colon (::). The three zero hextets become ::, and 0db8 becomes db8, giving 2001:db8::ff00:42:8329. The double colon may be used only once in an address to keep it unambiguous.
Which sequence correctly describes the TCP three-way handshake used to establish a connection?
- a.SYN-ACK, SYN, ACK
- b.SYN, ACK, FIN
- c.SYN, SYN-ACK, ACK✓
- d.ACK, SYN, SYN-ACK
TCP establishes a session with SYN (client requests), SYN-ACK (server acknowledges and requests), and ACK (client acknowledges). This exchange synchronizes sequence numbers so data can be reliably tracked and retransmitted if lost. FIN messages are used later to gracefully close the connection, not to open it.
Which OSI layer encapsulates packets into frames and uses MAC addresses for delivery within a single link?
- a.Physical (Layer 1)
- b.Network (Layer 3)
- c.Transport (Layer 4)
- d.Data Link (Layer 2)✓
The Data Link layer (Layer 2) frames packets and uses hardware MAC addresses to move data between nodes on the same physical segment. Switches operate here. The Network layer uses logical IP addresses for end-to-end routing, while the Physical layer transmits the raw bits on the medium.
Which application protocol primarily uses UDP port 53 for standard name-resolution queries?
- a.DNS✓
- b.SSH
- c.SMTP
- d.HTTPS
DNS uses UDP port 53 for most name-resolution queries because they are small and benefit from low overhead; it falls back to TCP 53 for large responses and zone transfers. HTTPS uses TCP 443, SMTP uses TCP 25, and SSH uses TCP 22. Knowing well-known ports helps in writing ACLs and troubleshooting.
Which of the following is a private IPv4 address as defined by RFC 1918?
- a.172.32.10.5
- b.192.169.1.1
- c.172.15.0.1
- d.10.221.4.9✓
RFC 1918 reserves 10.0.0.0/8, 172.16.0.0/12 (172.16-172.31), and 192.168.0.0/16 for private use, so 10.221.4.9 qualifies. 172.32.x and 172.15.x fall outside the 172.16-172.31 range, and 192.169.x is outside 192.168.x, making those three public. Private addresses require NAT to reach the Internet.
Which IPv6 prefix range is currently allocated for globally routable unicast addresses?
- a.FF00::/8
- b.FC00::/7
- c.2000::/3✓
- d.FE80::/10
Global unicast addresses, the IPv6 equivalent of public IPv4 addresses, come from the 2000::/3 range and are routable across the Internet. FE80::/10 is link-local, FC00::/7 is unique local (private), and FF00::/8 is reserved for multicast. Recognizing these ranges helps identify an address's scope at a glance.
During encapsulation, what is the protocol data unit (PDU) called at the Transport layer?
- a.Packet
- b.Frame
- c.Segment✓
- d.Bit
At the Transport layer, data is encapsulated into segments (TCP) or datagrams (UDP). The Network layer then wraps a segment into a packet, the Data Link layer into a frame, and the Physical layer transmits bits. Knowing PDU names by layer clarifies where each header is added during encapsulation.
A point-to-point WAN link is addressed with a /30 subnet mask. How many usable host addresses does it provide?
- a.2✓
- b.1
- c.0
- d.4
A /30 mask (255.255.255.252) leaves 2 host bits, giving 2^2 = 4 total addresses minus the network and broadcast addresses, for 2 usable hosts. This is exactly enough for the two endpoints of a point-to-point link, which is why /30 (or /31 in some designs) is standard for such links, conserving address space.
Which interface command assigns a switch access port to VLAN 10?
- a.vlan 10 access
- b.switchport trunk vlan 10
- c.switchport access vlan 10✓
- d.switchport mode vlan 10
The command 'switchport access vlan 10' assigns the port to VLAN 10 for untagged end-device traffic. You typically pair it with 'switchport mode access' to force the port into access mode. Trunk commands carry multiple VLANs and are used between switches, not for a single end device.
A switch receives a frame whose destination MAC address is not in its MAC address table. What does the switch do?
- a.Sends it only to the default gateway
- b.Drops the frame immediately
- c.Floods it out all ports in the VLAN except the port it arrived on✓
- d.Forwards it to every VLAN
When the destination MAC is unknown (unknown unicast), the switch floods the frame out all ports in the same VLAN except the ingress port, hoping the destination replies so its MAC can be learned. Flooding stays within the VLAN because a VLAN is a single broadcast domain. Once a reply is seen, the table is updated.
What is a consequence of a native VLAN mismatch on the two ends of an 802.1Q trunk?
- a.Only VLAN 1 will pass traffic
- b.Nothing; it is purely cosmetic
- c.The trunk negotiates a slower speed
- d.Traffic from the two native VLANs is bridged together, risking security and loop issues✓
If the native VLANs differ, untagged frames sent from one side's native VLAN are received into a different VLAN on the other side, effectively merging two VLANs. This can leak traffic between segments and create spanning-tree inconsistencies. CDP often flags the mismatch, and both trunk ends should use the same native VLAN.
In classic Spanning Tree Protocol, which port state populates the MAC address table but does not yet forward user frames?
- a.Learning✓
- b.Listening
- c.Forwarding
- d.Blocking
In the Learning state, the switch begins recording source MAC addresses to build its table but still does not forward user data, preventing loops during convergence. Listening processes BPDUs without learning MACs, Blocking discards data frames, and only Forwarding passes user traffic. RSTP streamlines these transitions for faster convergence.
What is the primary advantage of Rapid PVST+ (RSTP) over the original 802.1D Spanning Tree Protocol?
- a.It doubles the link bandwidth
- b.It removes the need for a root bridge
- c.Much faster convergence after a topology change✓
- d.It permanently disables all redundant links
RSTP (802.1w), used by Rapid PVST+, converges in seconds rather than the 30-50 seconds classic STP can take, by using proposal/agreement handshakes and defined port roles. It still elects a root bridge and blocks loops but reacts to changes far more quickly. This reduces downtime when links fail or recover.
What does the PortFast feature do when enabled on a switch access port?
- a.Blocks all incoming BPDUs
- b.Bundles the port into an EtherChannel
- c.Elects the port as the root port
- d.Transitions the port straight to forwarding, skipping listening and learning✓
PortFast lets an edge/access port that connects to a single host move immediately to the forwarding state, avoiding the usual STP delay so devices get connectivity (and DHCP) quickly. It should be used only on ports facing end devices, not other switches. Pairing it with BPDU Guard protects against accidental loops.
Showing 40 of 522