Cisco CCNA (200-301) — All Questions
The figures these questions turn on, pooled by value and printable, with a side to write them from memory: the cram packet, $6.99 →
101 questions
Which layer of the OSI model is responsible for logical addressing and determining the best path to route packets between networks?
- a.Network (Layer 3)✓
- b.Data Link (Layer 2)
- c.Transport (Layer 4)
- d.Session (Layer 5)
The Network layer (Layer 3) handles logical addressing, such as IPv4 and IPv6, and performs routing to select the best path across internetworks. Routers operate at this layer. The Data Link layer uses physical MAC addresses within a single segment, while the Transport layer manages end-to-end delivery.
A host is configured with the IPv4 address 172.16.45.10/20. What is the network address of the subnet it belongs to?
- a.172.16.0.0
- b.172.16.40.0
- c.172.16.45.0
- d.172.16.32.0✓
A /20 mask (255.255.240.0) makes the third octet increment in blocks of 16 (256 - 240 = 16). The subnets in the third octet are 0, 16, 32, 48, so 45 falls in the 32 block, giving a network address of 172.16.32.0. The host portion is zeroed to identify the subnet.
Which IPv6 address type is automatically configured on every IPv6-enabled interface and is only valid within a single link (never routed)?
- a.Unique local (FC00::/7)
- b.Multicast (FF00::/8)
- c.Link-local (FE80::/10)✓
- d.Global unicast (2000::/3)
Link-local addresses in the FE80::/10 range are automatically generated on each IPv6 interface and are used for on-link communication such as neighbor discovery and next-hop routing. Routers never forward packets with link-local source or destination addresses beyond the local link. Global unicast addresses are the routable, Internet-facing addresses.
Which TCP/IP protocol provides connectionless, best-effort delivery with no retransmission or flow control, making it suitable for real-time voice traffic?
- a.ICMP
- b.UDP✓
- c.ARP
- d.TCP
UDP (User Datagram Protocol) is a connectionless Transport layer protocol that adds minimal overhead and does not guarantee delivery, ordering, or provide flow control. This low latency makes it ideal for real-time applications like VoIP and video streaming where speed matters more than retransmission. TCP, by contrast, is connection-oriented and reliable.
How many usable host addresses are available on a subnet with a /26 prefix length?
- a.126
- b.64
- c.30
- d.62✓
A /26 mask leaves 6 host bits (32 - 26 = 6). The total addresses are 2^6 = 64, but the network address and the broadcast address cannot be assigned to hosts, so 64 - 2 = 62 usable addresses remain. This block-of-64 sizing is common for medium LAN segments.
Traditionally, which cable type is required to directly connect two Cisco switches together using copper Ethernet ports?
- a.Single-mode fiber
- b.Rollover (console)
- c.Straight-through (patch)
- d.Crossover✓
Connecting two like devices (switch-to-switch or router-to-router) traditionally requires a crossover cable so the transmit and receive pairs align correctly. A straight-through cable connects unlike devices such as switch-to-PC. Modern switches with Auto-MDIX detect and adjust automatically, but the exam expects knowledge of the classic crossover requirement.
What is the broadcast address of the subnet that contains the host 192.168.1.100/27?
- a.192.168.1.96
- b.192.168.1.95
- c.192.168.1.127✓
- d.192.168.1.128
A /27 mask (255.255.255.224) creates a block size of 32 (256 - 224). The subnets are .0, .32, .64, .96, .128, so 192.168.1.100 falls in the .96 subnet (range .96 to .127). The broadcast address is the last address in that block, 192.168.1.127, where all host bits are set to one.
If you borrow 3 bits from the host portion of a classful network to create subnets, how many subnets can you address?
- a.8✓
- b.6
- c.16
- d.3
Each borrowed bit doubles the number of subnets, so borrowing 3 bits yields 2^3 = 8 subnets. Modern classless routing (and Cisco's default 'ip subnet-zero' behavior) allows using all 8, including the all-zeros and all-ones subnets. The remaining host bits determine how many hosts each subnet supports.
Which is the correctly compressed form of the IPv6 address 2001:0db8:0000:0000:0000:ff00:0042:8329?
- a.2001:db8::ff00:42:8329✓
- b.2001:db8:0:0:ff00:42:8329
- c.2001::db8:ff00:42:8329
- d.2001:0db8::ff00::8329
IPv6 compression removes leading zeros within each hextet and replaces one contiguous run of all-zero hextets with a double colon (::). The three zero hextets become ::, and 0db8 becomes db8, giving 2001:db8::ff00:42:8329. The double colon may be used only once in an address to keep it unambiguous.
Which sequence correctly describes the TCP three-way handshake used to establish a connection?
- a.SYN-ACK, SYN, ACK
- b.SYN, ACK, FIN
- c.SYN, SYN-ACK, ACK✓
- d.ACK, SYN, SYN-ACK
TCP establishes a session with SYN (client requests), SYN-ACK (server acknowledges and requests), and ACK (client acknowledges). This exchange synchronizes sequence numbers so data can be reliably tracked and retransmitted if lost. FIN messages are used later to gracefully close the connection, not to open it.
Want these explained in order? Cisco CCNA 200-301 — Complete Study Guide (2026) — PDF + EPUB, $14.99 · 14-day refund →
Which OSI layer encapsulates packets into frames and uses MAC addresses for delivery within a single link?
- a.Physical (Layer 1)
- b.Network (Layer 3)
- c.Transport (Layer 4)
- d.Data Link (Layer 2)✓
The Data Link layer (Layer 2) frames packets and uses hardware MAC addresses to move data between nodes on the same physical segment. Switches operate here. The Network layer uses logical IP addresses for end-to-end routing, while the Physical layer transmits the raw bits on the medium.
Which application protocol primarily uses UDP port 53 for standard name-resolution queries?
- a.DNS✓
- b.SSH
- c.SMTP
- d.HTTPS
DNS uses UDP port 53 for most name-resolution queries because they are small and benefit from low overhead; it falls back to TCP 53 for large responses and zone transfers. HTTPS uses TCP 443, SMTP uses TCP 25, and SSH uses TCP 22. Knowing well-known ports helps in writing ACLs and troubleshooting.
Which of the following is a private IPv4 address as defined by RFC 1918?
- a.172.32.10.5
- b.192.169.1.1
- c.172.15.0.1
- d.10.221.4.9✓
RFC 1918 reserves 10.0.0.0/8, 172.16.0.0/12 (172.16-172.31), and 192.168.0.0/16 for private use, so 10.221.4.9 qualifies. 172.32.x and 172.15.x fall outside the 172.16-172.31 range, and 192.169.x is outside 192.168.x, making those three public. Private addresses require NAT to reach the Internet.
Which IPv6 prefix range is currently allocated for globally routable unicast addresses?
- a.FF00::/8
- b.FC00::/7
- c.2000::/3✓
- d.FE80::/10
Global unicast addresses, the IPv6 equivalent of public IPv4 addresses, come from the 2000::/3 range and are routable across the Internet. FE80::/10 is link-local, FC00::/7 is unique local (private), and FF00::/8 is reserved for multicast. Recognizing these ranges helps identify an address's scope at a glance.
During encapsulation, what is the protocol data unit (PDU) called at the Transport layer?
- a.Packet
- b.Frame
- c.Segment✓
- d.Bit
At the Transport layer, data is encapsulated into segments (TCP) or datagrams (UDP). The Network layer then wraps a segment into a packet, the Data Link layer into a frame, and the Physical layer transmits bits. Knowing PDU names by layer clarifies where each header is added during encapsulation.
A point-to-point WAN link is addressed with a /30 subnet mask. How many usable host addresses does it provide?
- a.2✓
- b.1
- c.0
- d.4
A /30 mask (255.255.255.252) leaves 2 host bits, giving 2^2 = 4 total addresses minus the network and broadcast addresses, for 2 usable hosts. This is exactly enough for the two endpoints of a point-to-point link, which is why /30 (or /31 in some designs) is standard for such links, conserving address space.
How many usable host addresses does a subnet with a /28 prefix provide?
- a.16
- b.30
- c.A /28 provides all 256 addresses on the segment for hosts
- d.14✓
A /28 leaves 4 host bits, so 2^4 = 16 total addresses. Subtracting the network and broadcast addresses leaves 14 usable host addresses. This block-of-16 size is common for small point-to-multipoint segments.
Which dotted-decimal subnet mask corresponds to a /28 prefix length?
- a.255.255.255.240✓
- b.255.255.255.224
- c.255.255.255.192
- d.255.255.255.248
A /28 sets 28 network bits, leaving 4 host bits, which gives 255.255.255.240 (the last octet 11110000 = 240). Each step in the fourth octet mask (240) creates blocks of 16 addresses. Converting between prefix length and dotted decimal is an essential subnetting skill.
A subnet must support at least 500 hosts. Which subnet mask is the most efficient choice?
- a.255.255.252.0
- b.255.255.254.0✓
- c.255.255.255.192
- d.255.255.255.0
To fit 500 hosts you need 9 host bits because 2^9 - 2 = 510 usable, and 2^8 - 2 = 254 is too few. Nine host bits means a /23, which is 255.255.254.0. A /22 (255.255.252.0) would also fit but wastes addresses, so /23 is the most efficient.
What is the network (subnet) address for the host 192.168.10.75/28?
- a.192.168.10.64✓
- b.192.168.10.80
- c.192.168.10.48
- d.192.168.10.0
A /28 has a block size of 16, so subnets increment .0, .16, .32, .48, .64, .80. The host .75 falls in the .64 subnet (range .64 to .79), making the network address 192.168.10.64. Zeroing the host bits identifies the subnet.
What is the broadcast address of the subnet containing 10.10.10.10/29?
- a.10.10.10.16
- b.10.10.10.15✓
- c.10.10.10.7
- d.10.10.10.8
A /29 (255.255.255.248) creates blocks of 8. The subnets are .0, .8, .16, so .10 falls in the .8 subnet (range .8 to .15). The broadcast is the last address of that block, 10.10.10.15, where all host bits are 1.
What is the valid host address range for the subnet 172.16.8.0/22?
- a.172.16.8.1 to 172.16.11.254✓
- b.172.16.8.1 to 172.16.9.254
- c.172.16.8.1 to 172.16.8.254
- d.172.16.8.1 to 172.16.15.254
A /22 mask (255.255.252.0) makes the third octet increment in blocks of 4, so this subnet spans 172.16.8.0 through 172.16.11.255. The network is 172.16.8.0 and the broadcast is 172.16.11.255, leaving usable hosts 172.16.8.1 to 172.16.11.254.
How many /26 subnets can be created from a single /24 network?
- a.16
- b.8
- c.2
- d.4✓
Going from /24 to /26 borrows 2 bits (26 - 24 = 2), and 2^2 = 4 subnets. Each /26 provides 62 usable hosts. This is a common way to divide one /24 among four departments.
How many usable host addresses are available on a /25 subnet?
- a.254 usable hosts
- b.126 usable hosts✓
- c.128 usable hosts
- d.62 usable hosts
A /25 mask (255.255.255.128) leaves 7 host bits, so 2^7 = 128 total addresses minus 2 for the network and broadcast equals 126 usable hosts. A /25 splits a /24 into two equal halves.
Which of the following is a valid IPv4 subnet mask?
- a.255.255.255.100
- b.255.255.255.5
- c.255.255.255.224✓
- d.255.255.240.255
A valid subnet mask must be a contiguous string of 1 bits followed by 0 bits, so 255.255.255.224 (/27) is valid. Values like 100, 5, or a 0 octet sandwiched before a 255 break the contiguous rule and are invalid masks.
The subnet mask 255.255.240.0 is equivalent to which CIDR prefix length?
- a./21
- b./20✓
- c./19
- d./22
255.255.240.0 has two full octets of 1s (16 bits) plus 240 in the third octet (11110000 = 4 bits), totaling 20 network bits, which is /20. Each 0 bit is a host bit, here 12 of them.
A /24 network must be divided into at least 6 subnets. What is the minimum number of bits to borrow?
- a.3 bits (/27)✓
- b.2 bits (/26)
- c.4 bits (/28)
- d.6 bits, extending each subnet mask all the way to /30
Each borrowed bit doubles the subnet count: 2 bits give 4 subnets (too few) and 3 bits give 2^3 = 8 subnets (enough for 6). Borrowing 3 bits changes /24 to /27, leaving 5 host bits (30 usable hosts each).
Are the hosts 192.168.1.62/26 and 192.168.1.65/26 in the same subnet?
- a.Yes, both are in 192.168.1.0/26
- b.Yes, all 192.168.1.x hosts share one subnet
- c.No, they are in different /26 subnets✓
- d.No, but only because their gateways differ
A /26 has a block size of 64, so the subnets are .0-.63 and .64-.127. Address .62 falls in the first subnet and .65 in the second, so they are in different subnets and cannot communicate without a router.
What is the network address for 10.5.5.130/25?
- a.10.5.5.130
- b.10.5.5.192
- c.10.5.5.128✓
- d.10.5.5.0
A /25 has a block size of 128, giving subnets .0-.127 and .128-.255. Address .130 falls in the second block, so the network address is 10.5.5.128 (host bits zeroed).
On a point-to-point link using a /31 prefix (RFC 3021), how many usable host addresses are available?
- a.0
- b.It cannot be used on point-to-point links at all
- c.1
- d.2✓
RFC 3021 allows /31 on point-to-point links, where both addresses are usable because no network or broadcast address is reserved. This yields exactly 2 usable addresses, one for each endpoint, conserving address space compared with a /30.
What is the default (classful) subnet mask for a Class B IPv4 address?
- a.255.255.255.255
- b.255.0.0.0
- c.255.255.0.0✓
- d.255.255.255.0
Class B addresses (first octet 128-191) use a default mask of 255.255.0.0 (/16), giving 16 host bits. Class A defaults to 255.0.0.0 and Class C to 255.255.255.0. Modern networks subnet these classful defaults with CIDR.
Which of the following is a valid /27 network (subnet) address?
- a.192.168.4.100
- b.192.168.4.96✓
- c.192.168.4.16
- d.192.168.4.80
A /27 has a block size of 32, so valid subnet addresses are multiples of 32: .0, .32, .64, .96, .128. Only 192.168.4.96 is a multiple of 32; .100, .80, and .16 fall inside subnets rather than on a boundary.
Which OSI layer is responsible for data formatting, encryption, and translation between formats?
- a.Session (Layer 5)
- b.Presentation (Layer 6)✓
- c.Application (Layer 7)
- d.Transport (Layer 4)
The Presentation layer (Layer 6) handles data representation, including encryption, compression, and format translation such as ASCII or character encoding. The Session layer manages dialogs, and the Application layer provides network services to programs.
Which OSI layer provides network services directly to end-user applications?
- a.Presentation (Layer 6)
- b.Session (Layer 5)
- c.Application (Layer 7)✓
- d.Network (Layer 3)
The Application layer (Layer 7) is the top layer and interfaces directly with user applications through protocols like HTTP, FTP, and DNS. It is where the user-facing service request originates before data moves down the stack for delivery.
What is the primary function of the Physical layer (Layer 1) of the OSI model?
- a.Routes packets between networks using logical addresses
- b.Transmits raw bits as electrical, optical, or radio signals✓
- c.Provides reliable end-to-end delivery with retransmission
- d.Establishes and manages sessions between applications
The Physical layer moves raw bits across the medium as electrical voltages, light pulses, or radio waves, defining connectors, pinouts, and signaling. It does not interpret the data; higher layers handle addressing, sessions, and reliability.
Which pair of protocols operates at the Transport layer of the TCP/IP model?
- a.ARP and RARP
- b.IP and ICMP
- c.HTTP and DNS
- d.TCP and UDP✓
TCP and UDP are the two Transport layer protocols: TCP is connection-oriented and reliable, while UDP is connectionless and low-overhead. IP and ICMP work at the Internet (Network) layer, and HTTP and DNS are application protocols.
Which TCP header field lets the receiver reorder segments that arrive out of order?
- a.Sequence number✓
- b.Checksum
- c.Window size field advertising available buffer space
- d.Source port
TCP assigns a sequence number to the bytes in each segment, so the receiver can place data back in the correct order and detect gaps for retransmission. The checksum validates integrity and the window field handles flow control, but ordering relies on sequence numbers.
Which TCP mechanism regulates how much data a sender can transmit before receiving an acknowledgment?
- a.Windowing (sliding window)✓
- b.Fragmentation and reassembly performed at the network layer
- c.Broadcasting
- d.Flooding
TCP uses a sliding window to control flow: the receiver advertises how much buffer space it has, and the sender limits unacknowledged data to that window. This prevents overwhelming a slower receiver and adapts dynamically as conditions change.
Which well-known port number is used by HTTPS?
- a.22
- b.25
- c.80
- d.443✓
HTTPS runs over TCP port 443, encrypting web traffic with TLS. Plain HTTP uses port 80, SSH uses 22, and SMTP uses 25. Memorizing well-known ports helps when writing ACLs and troubleshooting application connectivity.
Which TCP port does SSH use for secure remote management?
- a.21
- b.22✓
- c.23
- d.443
SSH listens on TCP port 22 and encrypts the entire management session. Telnet uses port 23 in clear text, and FTP control uses 21. Because SSH protects credentials from eavesdropping, it is the preferred remote CLI method.
Showing 40 of 101