Cisco CCNA (200-301) — All Questions

← Back to practiceRead the Cisco CCNA (200-301) study guide →

The figures these questions turn on, pooled by value and printable, with a side to write them from memory: the cram packet, $6.99 →

68 questions

IP Services

A network uses Port Address Translation (PAT). How does the router distinguish return traffic for multiple internal hosts sharing one public IP address?

  • a.By using unique source port numbers✓
  • b.By using different MAC addresses
  • c.By assigning each host a separate public IP
  • d.By using VLAN tags

PAT (NAT overload) maps many private addresses to a single public IP by translating and tracking unique source port numbers for each session. The router records these port-to-host mappings in its translation table so return traffic is delivered to the correct inside host. This conserves scarce public IPv4 addresses.

IP Services

Which protocol synchronizes the clocks of network devices so that log timestamps and certificates remain consistent?

  • a.Syslog
  • b.NTP✓
  • c.SNMP
  • d.DNS

NTP (Network Time Protocol) synchronizes device clocks to a reliable time source, typically over UDP port 123. Accurate time is essential for correlating Syslog messages, validating certificates, and troubleshooting. Devices reference a stratum hierarchy where lower stratum numbers are closer to the authoritative time source.

IP Services

What is the correct order of messages in the DHCP address-assignment process?

  • a.Offer, Discover, Acknowledge, Request
  • b.Discover, Offer, Request, Acknowledge✓
  • c.Discover, Request, Offer, Acknowledge
  • d.Request, Offer, Discover, Acknowledge

DHCP follows the DORA sequence: the client broadcasts a Discover, servers respond with an Offer, the client broadcasts a Request for one offer, and the server replies with an Acknowledgment finalizing the lease. Understanding DORA helps troubleshoot issues such as a missing relay when the server is on another subnet.

IP Services

What does the interface command 'ip helper-address' accomplish?

  • a.It assigns a static IP to the interface
  • b.It forwards DHCP and select UDP broadcasts to a server on another subnet✓
  • c.It enables Port Address Translation
  • d.It blocks all broadcast traffic

Because routers do not forward broadcasts, 'ip helper-address' converts a client's broadcast DHCP Discover into a unicast (or directed) packet aimed at a DHCP server on a different subnet, acting as a DHCP relay. It also relays a handful of other UDP services by default. This lets one central DHCP server serve many subnets.

IP Services

Which NAT type creates a permanent one-to-one mapping between a single inside local address and a single inside global address?

  • a.Port forwarding pool
  • b.Dynamic NAT
  • c.Static NAT✓
  • d.PAT (overload)

Static NAT fixes a one-to-one mapping so a specific internal host always translates to the same public address, which is useful for servers that must be reachable from outside. Dynamic NAT draws from a pool without fixed mappings, and PAT overloads many hosts onto one address using port numbers. Static NAT provides predictable inbound access.

IP Services

On the Syslog severity scale, which level represents the most severe condition?

  • a.7 (debugging)
  • b.3 (error)
  • c.0 (emergency)✓
  • d.5 (notification)

Syslog severities run from 0 (emergency, system unusable) up to 7 (debugging, most verbose), so 0 is the most severe. Lower numbers indicate more critical events. Setting a logging level of, say, 4 captures messages of that severity and all more-severe levels below it, letting operators filter noise.

IP Services

In SNMP, what is a trap?

  • a.An access control list entry
  • b.A polling request sent by the manager to a device
  • c.An unsolicited notification sent by the agent to the manager when an event occurs✓
  • d.A configuration backup file

An SNMP trap is an asynchronous, agent-initiated message that alerts the management station of an event (like an interface going down) without waiting to be polled. This is more efficient than the manager continuously polling for changes. Traps typically use UDP port 162, while polling/get requests use UDP 161.

IP Services

Which QoS marking is typically applied to real-time voice traffic so it receives priority (low-latency) queuing?

  • a.AF11 (DSCP 10)
  • b.Expedited Forwarding (EF / DSCP 46)✓
  • c.Best effort (DSCP 0)
  • d.CS1 (DSCP 8)

Voice is commonly marked Expedited Forwarding (EF, DSCP 46) so it is placed in a low-latency priority queue during congestion, minimizing delay and jitter. CS1 and AF11 are lower-priority classes, and DSCP 0 is best effort with no guarantees. Consistent marking and trust boundaries make end-to-end QoS effective.

IP Services

In Cisco NAT terminology, what is an 'inside local' address?

  • a.The public address a remote Internet host uses to reach an internal server
  • b.The public address assigned to the outside destination on the Internet
  • c.The translated address that appears in packets after they leave the router
  • d.The private address of an inside host as seen within the internal network✓

The inside local address is the private (RFC 1918) address assigned to a host on the internal network before translation. After NAT, that host is represented on the outside by its inside global address. The 'inside/outside' words indicate whose host it is, and 'local/global' indicate whether it is the pre- or post-translation view.

IP Services

What is the 'inside global' address in a NAT translation?

  • a.The link-local address the router uses on its internal interface
  • b.The private address of a server located on the outside network
  • c.The private address of the internal host before any translation occurs
  • d.The public address that represents an inside host to the outside world✓

The inside global address is the public, routable address that represents an internal host to devices on the outside network after translation. It is what external hosts see as the source of the traffic. With PAT, many inside local addresses share one inside global address distinguished by port numbers.

Want these explained in order? Cisco CCNA 200-301 — Complete Study Guide (2026) — PDF + EPUB, $14.99 · 14-day refund →

IP Services

Which command configures a router interface as the NAT inside interface?

  • a.ip nat pool inside referencing the interface name
  • b.nat inside enable on the interface configuration line
  • c.switchport nat inside for Layer 3 switch ports
  • d.ip nat inside✓

On the internal-facing interface you enter 'ip nat inside', and on the external-facing interface 'ip nat outside', so the router knows which direction to translate. These designations are required before any NAT rule will function. Omitting them is a common reason NAT appears configured but does not translate.

IP Services

Which command configures PAT (NAT overload) so that hosts matched by ACL 1 are translated to the address of interface GigabitEthernet0/0?

  • a.ip nat outside source static 1 GigabitEthernet0/0 overload
  • b.ip nat inside source list 1 interface GigabitEthernet0/0 overload✓
  • c.ip nat pool 1 GigabitEthernet0/0 netmask 255.255.255.0 type rotary
  • d.ip nat inside destination list 1 pool GigabitEthernet0/0

The command 'ip nat inside source list 1 interface Gi0/0 overload' translates addresses permitted by ACL 1 to the IP of Gi0/0, and the 'overload' keyword enables PAT so many hosts share that one address via unique ports. This is the standard configuration for an Internet edge router. Without 'overload', it would attempt one-to-one dynamic NAT.

IP Services

Which command displays the current active NAT translations, including protocol and port information?

  • a.show ip nat translations✓
  • b.show ip nat inside, which is not a valid IOS command
  • c.show ip nat pool, which lists only the configured address pools
  • d.show running-config | section nat, which shows configuration not live entries

'show ip nat translations' lists the active translation table entries, showing inside local, inside global, outside local, and outside global addresses along with protocol and port numbers for PAT. It is the primary tool for verifying that NAT is working. 'show ip nat statistics' complements it with hit counts and totals.

IP Services

A single public IPv4 address serves 300 internal hosts through PAT. How is this possible?

  • a.Each session is tracked by a unique source port number mapped to the shared public IP✓
  • b.The router assigns each host a unique VLAN so their addresses never collide
  • c.PAT temporarily borrows additional public addresses from a shared ISP pool
  • d.The internal hosts take turns, with only one host online at any given moment

PAT multiplexes many internal hosts onto one public IP by assigning each outbound session a unique source port and recording the port-to-host mapping. Return traffic is matched to the correct host using that port. Because the port field is 16 bits, a single address can support thousands of simultaneous sessions.

IP Services

Why does NAT complicate protocols that embed IP address information in their payload, such as some VoIP signaling?

  • a.NAT increases latency so much that embedded timers expire before delivery
  • b.NAT rewrites the header addresses but not addresses buried inside the payload unless an ALG assists✓
  • c.NAT strips the Layer 4 header, removing the port needed to reassemble the call The affected endpoints then renegotiate the call using a lower-bandwidth codec automatically.
  • d.NAT encrypts the payload, hiding the embedded addresses from the endpoints

NAT translates addresses in the IP header, but protocols that carry IP addresses inside their application payload can break because those embedded addresses are not automatically rewritten. An Application Layer Gateway (ALG) is needed to inspect and fix the payload addresses. This is a well-known challenge for protocols like SIP, FTP, and some VoIP signaling.

IP Services

Which transport protocol and port does NTP use to synchronize device clocks?

  • a.TCP port 123, using a reliable connection for each time sample
  • b.UDP port 161, the same port used by SNMP polling
  • c.UDP port 123✓
  • d.TCP port 37, inherited from the legacy TIME protocol

NTP operates over UDP port 123, exchanging timestamps to synchronize clocks across the network. UDP's low overhead suits the small, frequent time messages. Accurate time is essential for correlating logs, validating certificates, and time-based access controls, which is why NTP is configured on nearly all managed devices.

IP Services

In NTP, what does a lower stratum number indicate about a time source?

  • a.The device polls for time less frequently to conserve bandwidth
  • b.The device is closer to the authoritative reference clock and more accurate✓
  • c.The device is farther from the authoritative clock and less trustworthy Such a device also declines to answer any polling request that arrives from a lower stratum.
  • d.The device is a client only and cannot serve time to others

NTP uses a stratum hierarchy where stratum 0 is a reference clock (like GPS or an atomic clock), stratum 1 servers attach directly to it, and each additional hop increments the number. A lower stratum therefore means the source is closer to the authoritative clock and generally more accurate. Devices prefer synchronizing to the lowest available stratum.

IP Services

Which command configures a Cisco router to synchronize its clock with an NTP server at 192.0.2.10?

  • a.ntp master 192.0.2.10 to designate the upstream reference
  • b.ntp server 192.0.2.10✓
  • c.ip ntp source 192.0.2.10 on the outbound interface
  • d.clock set ntp 192.0.2.10 in global configuration mode

'ntp server 192.0.2.10' tells the device to poll that address as an NTP time source and adjust its clock accordingly. 'ntp master' instead makes the local device an authoritative source for others. 'clock set' manually sets time but does not synchronize with a server, so it drifts over time.

IP Services

A DHCP client and server are on different subnets separated by a router. What must be configured so the client can obtain an address?

  • a.NAT overload on the router to translate the DHCP broadcast into a unicast
  • b.A static route on the client pointing to the DHCP server's subnet
  • c.An 'ip helper-address' on the router interface facing the client, pointing to the server✓
  • d.Spanning-tree PortFast on the client's switch port to speed the lease

Because routers do not forward broadcasts, the DHCP Discover would never reach a server on another subnet. Configuring 'ip helper-address <server-ip>' on the client-facing interface makes the router relay the request as a unicast to the DHCP server. The router acts as a DHCP relay agent for the clients on that segment.

IP Services

Which pair of messages completes the DHCP DORA exchange after Discover and Offer?

  • a.Acknowledgment, then Request
  • b.Inform, then Release
  • c.Request, then Acknowledgment✓
  • d.Decline, then Renew

DHCP follows Discover, Offer, Request, Acknowledgment (DORA). After the server offers an address, the client broadcasts a Request for that specific offer, and the server responds with an Acknowledgment finalizing the lease. Release and Decline are separate messages used to give up or reject an address, not part of the core DORA flow.

IP Services

Which command excludes the addresses 10.1.1.1 through 10.1.1.10 from being handed out by a Cisco IOS DHCP pool?

  • a.ip dhcp excluded-address 10.1.1.1 10.1.1.10✓
  • b.ip dhcp pool 10.1.1.1 deny range 10.1.1.10
  • c.ip dhcp pool exclude 10.1.1.1 10.1.1.10 inside the pool configuration
  • d.dhcp reserve 10.1.1.1 to 10.1.1.10 for static assignment

'ip dhcp excluded-address 10.1.1.1 10.1.1.10' is a global command that reserves that range so the DHCP server never leases those addresses to clients. Administrators typically exclude the addresses used by routers, servers, and printers. The exclusion is configured outside the pool, unlike the network and default-router statements.

IP Services

Within a Cisco IOS DHCP pool, which command specifies the default gateway that clients will receive?

  • a.default-router✓
  • b.dns-server, which also doubles as the gateway assignment
  • c.ip helper-address, pointing clients to the router
  • d.gateway-address, the modern replacement command

Inside a DHCP pool, 'default-router <address>' sets the gateway that leased clients will use for off-subnet traffic. Other pool options include 'network', 'dns-server', 'domain-name', and 'lease'. Without a default-router, clients receive an address but cannot reach other subnets.

IP Services

What is the primary function of DNS in a network?

  • a.To synchronize the clocks of servers so their records stay consistent
  • b.To resolve human-readable domain names into IP addresses✓
  • c.To assign IP addresses dynamically to hosts as they join the network
  • d.To encrypt web traffic between a browser and a secure server

DNS translates human-friendly domain names (like example.com) into the IP addresses that devices actually use to communicate. It operates primarily over UDP port 53, falling back to TCP for large responses and zone transfers. Without DNS, users would need to remember numeric IP addresses for every service.

IP Services

Which command enables a Cisco device to use DNS name resolution and points it to a DNS server at 8.8.8.8?

  • a.ip name-server 8.8.8.8 (with 'ip domain-lookup' enabled)✓
  • b.name-resolution server 8.8.8.8 primary
  • c.dns-server 8.8.8.8 in global configuration mode
  • d.ip host resolve 8.8.8.8 for all lookups

'ip name-server 8.8.8.8' specifies the DNS server the device queries, and 'ip domain-lookup' (on by default) enables the resolver. With these set, you can reference hostnames instead of IP addresses in commands like ping. 'dns-server' is used inside a DHCP pool to hand a resolver to clients, which is a different context.

IP Services

A user complains that pinging a website by name fails but pinging its IP address succeeds. What is the most likely cause?

  • a.The default gateway is misconfigured on the local router interface
  • b.Spanning Tree has blocked the port the user is connected to
  • c.A DNS resolution problem, such as a missing or unreachable DNS server✓
  • d.The router's NAT translation table has overflowed and dropped the session

If the IP address is reachable but the name is not, connectivity is fine and the failure lies in name resolution, pointing to a DNS issue such as a wrong, missing, or unreachable DNS server. Verifying the configured name server and testing 'nslookup' isolates the problem. Routing and gateway problems would break the IP ping too.

IP Services

Which SNMP version first introduced strong authentication and encryption for management traffic?

  • a.SNMPv1, the original specification with community strings
  • b.SNMPv2c, which added bulk retrieval operations
  • c.SNMPv4, which replaced community strings with certificates
  • d.SNMPv3✓

SNMPv3 introduced security features including message integrity, authentication, and encryption (privacy), addressing the plaintext community-string weakness of SNMPv1 and SNMPv2c. It uses a user-based security model with configurable authentication and privacy protocols. For any environment where SNMP traffic could be intercepted, SNMPv3 is strongly recommended.

IP Services

On which UDP ports do SNMP polling (get/set) and SNMP traps operate, respectively?

  • a.Port 67 for polling and port 68 for traps
  • b.Port 514 for polling and port 520 for traps
  • c.Port 161 for both polling and traps
  • d.Port 161 for polling and port 162 for traps✓

SNMP managers poll agents using get and set requests on UDP port 161, while agents send unsolicited trap notifications to the manager on UDP port 162. Keeping the ports distinct lets a device act as both an agent and a trap receiver. Port 514 is Syslog and 67/68 are DHCP, which are unrelated services.

IP Services

What is an SNMP MIB?

  • a.A backup copy of the device configuration stored on a TFTP server
  • b.The community string used to authenticate SNMPv2c polling requests
  • c.A hierarchical database of managed objects, each identified by an object identifier (OID)✓
  • d.A message that an agent sends to the manager when a threshold is exceeded This copy is refreshed automatically each time an administrator saves the running configuration.

A Management Information Base (MIB) is the structured, hierarchical collection of managed objects on a device, each addressed by a unique object identifier (OID). SNMP managers read and set these objects to monitor and configure the device. Traps and community strings are separate SNMP concepts, not the MIB itself.

IP Services

On the Syslog severity scale, which numeric level corresponds to informational messages?

  • a.Level 3, used for error conditions
  • b.Level 7, reserved for verbose debugging output
  • c.Level 0, the most critical emergency level
  • d.Level 6✓

Syslog severity level 6 is 'informational', sitting between notifications (5) and debugging (7). The scale runs from 0 (emergency) to 7 (debugging), with lower numbers indicating more severe events. Setting a logging level captures that severity and all more-critical ones, so configuring level 6 logs everything except level-7 debug messages.

IP Services

Which command directs a Cisco device to send its Syslog messages to a server at 192.0.2.50?

  • a.service timestamps log datetime 192.0.2.50
  • b.syslog-server 192.0.2.50 severity informational
  • c.logging host 192.0.2.50✓
  • d.snmp-server host 192.0.2.50 traps for centralized logging

'logging host 192.0.2.50' (or the older 'logging 192.0.2.50') configures the device to forward Syslog messages to that server over UDP port 514 by default. Centralized logging aids correlation and long-term retention. The 'snmp-server host' command is for SNMP traps, a different notification mechanism.

IP Services

In a Cisco log message such as '%LINK-3-UPDOWN', what does the number 3 represent?

  • a.The severity level of the message✓
  • b.The process ID of the logging subsystem
  • c.The count of times the event has occurred since boot
  • d.The interface number that generated the event

In the '%FACILITY-SEVERITY-MNEMONIC' format, the middle number is the Syslog severity level, so a 3 indicates an error-level condition. LINK is the facility and UPDOWN is the mnemonic describing the event. Recognizing the severity helps operators quickly gauge how urgent a logged event is.

IP Services

Why is enabling 'service timestamps log datetime msec' recommended, especially alongside NTP?

  • a.It stamps each log entry with an accurate date and time so events can be correlated✓
  • b.It compresses log messages to reduce the storage they consume on the device Those forwarded traps are then correlated by the manager using each device's stratum number.
  • c.It automatically forwards logs to an SNMP manager as traps
  • d.It encrypts Syslog traffic between the device and the logging server

Timestamping log entries with the date and time (to the millisecond) lets engineers correlate events across multiple devices during troubleshooting. Combined with NTP-synchronized clocks, timestamps from different devices line up accurately. Without synchronized, timestamped logs, reconstructing an incident timeline is error-prone.

IP Services

Which QoS mechanism drops or delays traffic that exceeds a configured rate, smoothing bursts by buffering excess packets?

  • a.Fragmentation, which splits large packets into smaller pieces
  • b.Traffic shaping✓
  • c.Classification, which only identifies and marks traffic types
  • d.Marking, which sets DSCP or CoS values on packets

Traffic shaping buffers packets that exceed a defined rate and releases them later, smoothing bursts to conform to a target rate, which is useful on links to a provider. Policing, by contrast, drops or remarks excess traffic immediately without buffering. Classification and marking identify and tag traffic but do not enforce rates.

IP Services

In QoS, what is the difference between traffic policing and traffic shaping?

  • a.Both drop excess traffic identically; the terms are interchangeable
  • b.Policing drops or remarks excess traffic immediately, while shaping buffers and delays it to smooth bursts✓
  • c.Shaping applies only to inbound traffic while policing applies only to voice In practice the two behave identically once the interface reaches its configured rate ceiling.
  • d.Policing buffers excess traffic while shaping drops it immediately

Policing enforces a rate by dropping or remarking packets that exceed it right away, without buffering, so it can be applied inbound or outbound. Shaping instead queues excess traffic and releases it later, smoothing bursts but adding delay, and is applied outbound. Choosing between them depends on whether buffering or immediate enforcement is desired.

IP Services

Which QoS field in the IPv4 header carries the 6-bit DSCP value used to classify traffic?

  • a.The Fragment Offset field
  • b.The Protocol field identifying the upper-layer protocol This field is also incremented at every hop to guarantee the packet cannot loop indefinitely.
  • c.The Differentiated Services (DS) field, formerly the Type of Service byte✓
  • d.The Time-To-Live (TTL) field

The 8-bit Differentiated Services field in the IPv4 header (originally the Type of Service byte) contains the 6-bit DSCP value plus 2 bits for explicit congestion notification. DSCP markings let devices apply per-hop behaviors such as priority queuing. The TTL and Protocol fields serve unrelated forwarding functions.

IP Services

Why is queuing a critical QoS tool during periods of link congestion?

  • a.It encrypts high-priority traffic so it is delivered before other flows Those applications are automatically re-enabled the moment the link utilization drops again.
  • b.It lets a device schedule which packets are sent first, prioritizing latency-sensitive traffic like voice✓
  • c.It disables all low-priority applications until congestion clears
  • d.It permanently increases the physical bandwidth of the congested link

When a link is congested, packets wait in queues, and QoS queuing strategies (such as low-latency queuing) decide the order in which they are dequeued, letting delay-sensitive voice and video go first. This protects real-time applications from jitter and drops. Queuing only matters during congestion; an uncongested link forwards packets immediately.

IP Services

Which characteristic makes voice traffic especially sensitive and a prime candidate for QoS priority treatment?

  • a.Voice consumes more bandwidth than any other application on a typical network
  • b.Voice always uses TCP, so it retransmits any lost packets automatically
  • c.Voice tolerates high latency but requires guaranteed lossless delivery like a file transfer
  • d.Voice is highly sensitive to delay, jitter, and loss because it is real-time and interactive✓

Interactive voice must arrive with minimal delay and consistent spacing, so latency, jitter, and packet loss quickly degrade call quality. It actually uses relatively little bandwidth but cannot wait behind bulk traffic. QoS marks voice (often EF/DSCP 46) and places it in a priority queue to meet these strict requirements.

IP Services

Before enabling SSH on a Cisco device, which two prerequisites must be met?

  • a.Configure a hostname and domain name, then generate RSA crypto keys✓
  • b.Configure NAT overload and assign a public IP to the VTY lines
  • c.Enable Telnet first, then disable it once SSH negotiates a session
  • d.Set the reference bandwidth and enable NTP synchronization

SSH requires a hostname and an IP domain name because those values are used to name the RSA key pair, which you then generate with 'crypto key generate rsa'. Without a key pair, the device cannot perform the SSH encryption handshake. You also enable SSH on the VTY lines with 'transport input ssh'.

IP Services

Which command restricts the VTY lines so that only SSH (not Telnet) is permitted for remote access?

  • a.service password-encryption combined with login local
  • b.no transport telnet on the VTY lines
  • c.transport input ssh✓
  • d.ip ssh version 2 only in global configuration mode

Under line vty configuration, 'transport input ssh' allows only SSH connections and implicitly denies Telnet, protecting management traffic. Pairing it with local or AAA authentication and 'ip ssh version 2' hardens access further. Leaving the default 'transport input all' or including telnet would expose plaintext logins.

IP Services

What is a key security advantage of SCP over TFTP for transferring configuration files?

  • a.SCP runs over SSH and encrypts both the data and the authentication credentials✓
  • b.SCP requires no username or password, simplifying automated backups
  • c.SCP compresses files, which prevents anyone from reading their contents
  • d.SCP uses UDP, making transfers faster and inherently more secure than TFTP

SCP (Secure Copy) operates over the encrypted SSH channel, protecting both the file contents and the login credentials from eavesdropping. TFTP, by contrast, uses UDP port 69 with no authentication or encryption, sending everything in clear text. For sensitive configuration transfers, SCP is the more secure choice.

Showing 40 of 68

Report