Cisco CCNA (200-301) — All Questions

← Back to practiceRead the Cisco CCNA (200-301) study guide →

The figures these questions turn on, pooled by value and printable, with a side to write them from memory: the cram packet, $6.99 →

67 questions

Security Fundamentals

A standard IPv4 ACL is applied to filter traffic. On which criterion can a standard ACL match?

  • a.Source and destination IP plus port
  • b.Destination MAC address
  • c.Source IP address only✓
  • d.Application-layer payload

Standard IPv4 ACLs (numbered 1-99 and 1300-1999) filter based only on the source IP address. Extended ACLs are required to match source and destination addresses, protocols, and port numbers. Because standard ACLs are less granular, they are typically placed close to the destination to avoid blocking too much traffic.

Security Fundamentals

DHCP snooping classifies switch ports as trusted or untrusted. What happens to a DHCP server reply (DHCPOFFER) received on an untrusted port?

  • a.It is dropped✓
  • b.It is tagged and logged only
  • c.It is rate-limited but allowed
  • d.It is forwarded normally

DHCP snooping treats ports facing hosts as untrusted and drops server-sourced messages like DHCPOFFER and DHCPACK arriving on them, preventing rogue DHCP servers. Only trusted ports, typically uplinks toward legitimate DHCP servers, may forward these replies. The feature also builds a binding table that Dynamic ARP Inspection uses.

Security Fundamentals

A switch port is configured with port security in the default violation mode. When an unauthorized MAC address exceeds the maximum, what is the result?

  • a.The port reboots the switch
  • b.The port is err-disabled and shut down (shutdown mode)✓
  • c.The port allows the traffic but sends a Syslog
  • d.The port drops only the offending frames but stays up

The default port-security violation mode is shutdown, which places the port in the err-disabled state and requires administrative recovery (or errdisable recovery) when a violation occurs. The 'protect' mode silently drops unknown traffic, while 'restrict' drops it and increments counters plus sends notifications. This limits which MAC addresses can use a port.

Security Fundamentals

Which wireless security standard introduces Simultaneous Authentication of Equals (SAE) to replace the pre-shared key handshake and protect against offline dictionary attacks?

  • a.WEP
  • b.WPA2
  • c.WPA
  • d.WPA3✓

WPA3 replaces the WPA2 four-way handshake with SAE (Simultaneous Authentication of Equals), a dragonfly key exchange that resists offline dictionary attacks even with weak passwords. It also adds forward secrecy. WEP and WPA are legacy and cryptographically broken, while WPA2 relies on AES-CCMP but remains vulnerable to some offline attacks.

Security Fundamentals

To conserve bandwidth and drop unwanted traffic early, where should an extended ACL generally be placed?

  • a.As close to the destination as possible
  • b.Only on the Internet-facing WAN link
  • c.Only on a loopback interface
  • d.As close to the source of the traffic as possible✓

Extended ACLs match on source, destination, protocol, and port, so they can be placed near the source to discard unwanted traffic before it crosses the network, saving bandwidth. Standard ACLs, which match only source, are placed near the destination to avoid unintentionally blocking legitimate traffic. Placement is a common exam distinction.

Security Fundamentals

In an ACL wildcard mask, what does a bit value of 0 indicate?

  • a.It reverses the subnet mask automatically
  • b.Deny any packet with this bit set
  • c.The corresponding address bit must match exactly✓
  • d.Ignore this bit; it can be anything

A wildcard mask is the inverse of a subnet mask: a 0 bit means the corresponding address bit must match exactly, while a 1 bit means ignore it. For example, 0.0.0.255 matches a full /24, checking the first three octets and ignoring the last. This lets ACLs match ranges of addresses precisely.

Security Fundamentals

What behavior is applied to traffic that does not match any explicit statement in an ACL?

  • a.An implicit permit any allows it
  • b.An implicit deny any drops it✓
  • c.It is logged then permitted
  • d.It is queued for review

Every ACL ends with an invisible implicit deny any, so any packet not explicitly permitted is dropped. This means an ACL with only deny statements and no permit will block everything. Administrators must include at least one permit statement for the traffic they want to allow through.

Security Fundamentals

Which statement correctly contrasts TACACS+ with RADIUS?

  • a.RADIUS encrypts the entire packet payload
  • b.TACACS+ uses UDP for transport
  • c.RADIUS separates authentication, authorization, and accounting into distinct functions
  • d.TACACS+ separates authentication, authorization, and accounting and uses TCP✓

TACACS+ is Cisco-developed, uses TCP port 49, encrypts the entire payload, and separates the three AAA functions, making it well suited to granular device administration (command authorization). RADIUS uses UDP, encrypts only the password, and combines authentication and authorization, and is common for network access (802.1X). Both centralize AAA.

Security Fundamentals

Why is SSH preferred over Telnet for remote device management?

  • a.Telnet consumes more bandwidth than SSH
  • b.SSH encrypts the session, while Telnet sends credentials and data in clear text✓
  • c.SSH transfers data faster than Telnet
  • d.SSH requires no authentication

SSH encrypts the entire management session, protecting usernames, passwords, and commands from eavesdropping, whereas Telnet transmits everything in clear text and is trivially captured. Best practice is to disable Telnet, generate RSA keys, and allow only SSH (version 2) on the VTY lines. Both provide CLI access, but only SSH is secure.

Security Fundamentals

Dynamic ARP Inspection (DAI) validates ARP packets against which data source?

  • a.The router's routing table
  • b.The switch MAC address table only
  • c.The DHCP snooping binding table✓
  • d.The spanning-tree topology

DAI checks each ARP packet on untrusted ports against the DHCP snooping binding table, which maps legitimate IP-to-MAC-to-port bindings. ARP replies that do not match a valid binding are dropped, defeating ARP spoofing/man-in-the-middle attacks. Because DAI depends on that table, DHCP snooping must be enabled first.

Want these explained in order? Cisco CCNA 200-301 — Complete Study Guide (2026) — PDF + EPUB, $14.99 · 14-day refund →

Security Fundamentals

Which encryption method is used by WPA2 to secure wireless traffic?

  • a.AES with CCMP✓
  • b.RC4 with TKIP only
  • c.DES
  • d.WEP static keys

WPA2 mandates AES encryption with CCMP, providing strong confidentiality and integrity that replaced the weaker RC4/TKIP used by the original WPA. WEP is obsolete and broken. WPA3 further improves security with SAE for the handshake, but WPA2-AES remains widely deployed and is a solid baseline for enterprise and home use.

Security Fundamentals

What is the key difference between the 'enable secret' and 'enable password' commands?

  • a.enable password is encrypted with AES
  • b.enable secret is stored as a strong hash, while enable password can be clear text or weakly encoded✓
  • c.They are functionally identical
  • d.enable secret is stored in clear text

The 'enable secret' stores the privileged-mode password as a strong one-way hash (MD5 or better on modern IOS), whereas 'enable password' is either clear text or protected only by the weak, reversible Type 7 encoding. When both are set, the enable secret takes precedence. Best practice is to use enable secret and avoid enable password.

Security Fundamentals

Which three goals make up the CIA triad that underpins information security?

  • a.Cryptography, Identity, and Access management
  • b.Compliance, Inspection, and Auditing of systems
  • c.Control, Isolation, and Authorization of network resources
  • d.Confidentiality, Integrity, and Availability✓

The CIA triad stands for Confidentiality (preventing unauthorized disclosure), Integrity (preventing unauthorized modification), and Availability (ensuring authorized access when needed). Nearly every security control maps to protecting one or more of these three properties. Understanding the triad frames how threats and countermeasures are evaluated.

Security Fundamentals

What distinguishes a threat from a vulnerability in security terminology?

  • a.A threat is always internal, while a vulnerability is always external
  • b.They are identical terms describing any network attack
  • c.A threat is a patch, while a vulnerability is the software that needs it Both words describe the same measurable event once a control has already been bypassed by it.
  • d.A vulnerability is a weakness, while a threat is the potential danger that could exploit it✓

A vulnerability is a weakness or flaw in a system, and a threat is a potential event or actor that could exploit that weakness to cause harm. The likelihood and impact of a threat exploiting a vulnerability define the risk. Mitigations reduce risk by removing vulnerabilities or blocking threats.

Security Fundamentals

On which single criterion can a standard IPv4 ACL filter traffic?

  • a.Both the source and destination IP addresses plus port numbers
  • b.The source IP address only✓
  • c.The application-layer content of the packet
  • d.The destination MAC address of each frame

Standard IPv4 ACLs (1-99 and 1300-1999) match only on the source IP address, making them coarse filters. To match on destination address, protocol, or port, an extended ACL is required. Because standard ACLs are so broad, they are generally placed close to the destination to avoid blocking unintended traffic.

Security Fundamentals

Which wildcard mask should an ACL use to match exactly the single host 192.168.10.7?

  • a.255.255.255.255, which would match every possible address
  • b.255.255.255.0, the standard class C subnet mask
  • c.0.0.0.255, which would match the entire 192.168.10.0 subnet
  • d.0.0.0.0✓

A wildcard mask of 0.0.0.0 requires every bit of the address to match, so it selects exactly one host, 192.168.10.7. Equivalently, IOS accepts the 'host 192.168.10.7' keyword. A wildcard of 0.0.0.255 would match the whole /24, and 255.255.255.255 (the 'any' keyword) matches everything.

Security Fundamentals

Which wildcard mask correctly matches the entire 172.16.0.0/16 network in an ACL statement?

  • a.255.255.0.0, which is the subnet mask, not the wildcard
  • b.0.0.15.255, which would match only a /20
  • c.0.0.0.255, matching only the final octet range
  • d.0.0.255.255✓

A /16 has 16 host bits, so the wildcard mask is the inverse of 255.255.0.0, which is 0.0.255.255. The two zero octets force the first 16 bits (172.16) to match while the last two octets are ignored. Remember that ACL wildcard masks are the bitwise inverse of subnet masks.

Security Fundamentals

An ACL entry reads 'permit 10.1.4.0 0.0.1.255'. Which range of addresses does it match?

  • a.Only the single subnet 10.1.4.0 through 10.1.4.255
  • b.10.1.4.0 through 10.1.5.255 (a /23 block)✓
  • c.The entire 10.1.0.0/16 network
  • d.10.1.4.0 through 10.1.4.255 and 10.1.6.0 through 10.1.6.255 only

The wildcard 0.0.1.255 leaves the last nine bits free, covering a block of 512 addresses, which is a /23. Starting at 10.1.4.0, that spans 10.1.4.0 through 10.1.5.255. This is why wildcard masks are powerful: a single line can match two contiguous /24s at once.

Security Fundamentals

Which wildcard mask matches all addresses in the 192.168.16.0/20 network?

  • a.0.0.0.15, which covers only sixteen host addresses
  • b.0.0.7.255, which corresponds to a /21
  • c.0.0.15.255✓
  • d.0.0.255.255, which would match a /16 instead

A /20 has 12 host bits, so its wildcard mask is the inverse of 255.255.240.0, which is 0.0.15.255. The third octet's low four bits and the entire fourth octet are wildcarded. Starting at 192.168.16.0, this matches through 192.168.31.255, a block of 4096 addresses.

Security Fundamentals

What behavior applies to traffic that matches no explicit entry in a Cisco ACL?

  • a.It is logged and then forwarded for administrative review
  • b.It is denied, because every ACL ends with an implicit 'deny any'✓
  • c.It is queued until a matching permit statement is added
  • d.It is permitted, because ACLs allow anything not explicitly denied

Every Cisco ACL concludes with an invisible implicit 'deny any', so any packet not matched by a permit statement is dropped. This means an ACL containing only deny statements, or one with no matching permit, blocks all remaining traffic. Administrators must include an explicit permit for the traffic they intend to allow.

Security Fundamentals

Where should a standard ACL generally be placed, and why?

  • a.On the WAN link only, regardless of traffic direction
  • b.Close to the destination, because it matches only source addresses and could otherwise block too much✓
  • c.On a loopback interface, to centralize all filtering decisions
  • d.Close to the source, so unwanted traffic is dropped before it travels On that link the direction keyword is ignored because the filter applies symmetrically anyway.

Because a standard ACL matches only the source address, placing it near the source risks blocking that source's legitimate traffic to other destinations too. Positioning it close to the destination limits its impact to just the intended flow. Extended ACLs, being more specific, are instead placed near the source to conserve bandwidth.

Security Fundamentals

Which command applies the ACL numbered 101 to inbound traffic on interface GigabitEthernet0/1?

  • a.ip access-list 101 apply inbound on Gi0/1
  • b.access-class 101 in, under the interface configuration
  • c.access-list 101 in directly in global configuration
  • d.ip access-group 101 in✓

Under the interface, 'ip access-group 101 in' applies ACL 101 to traffic entering that interface. The 'in' or 'out' keyword sets the direction relative to the interface. The 'access-class' command is used instead to apply an ACL to VTY lines for remote-access control, which is a different context.

Security Fundamentals

Which type of ACL is required to permit HTTP traffic to a specific server while denying all other traffic to it?

  • a.A MAC address ACL applied at Layer 2 only
  • b.An extended ACL, which can match destination address and TCP port 80✓
  • c.A reflexive ACL, which is the only type able to match ports
  • d.A standard ACL, which matches destination ports directly

Permitting a specific application (HTTP) to a specific destination requires matching destination IP and TCP port 80, which only an extended ACL can do. Standard ACLs match source address alone and cannot filter by port. Extended ACLs are numbered 100-199 (and 2000-2699) or named.

Security Fundamentals

In an extended ACL statement 'permit tcp any host 10.0.0.5 eq 443', what does 'eq 443' specify?

  • a.The maximum number of connections permitted to the host
  • b.The source port that the client must use for the connection
  • c.The administrative distance applied to matching packets
  • d.The destination port (HTTPS) that the traffic must be headed to✓

The 'eq 443' keyword matches traffic whose destination port equals 443, the well-known port for HTTPS, allowing secure web traffic to the server at 10.0.0.5. Extended ACLs can match source and destination ports using operators like eq, gt, lt, and range. This granularity is why extended ACLs are used for application-level filtering.

Security Fundamentals

What is a primary security purpose of port security on a switch access port?

  • a.To limit which and how many MAC addresses can use the port, blocking unauthorized devices✓
  • b.To encrypt all frames leaving the port toward the connected device
  • c.To prioritize voice traffic over data traffic on the same port
  • d.To automatically assign the port to the correct VLAN based on traffic It achieves this by tagging each authorized frame with a higher class-of-service value first.

Port security restricts a switch port to a maximum number of learned MAC addresses and can bind specific addresses, so an attacker who plugs in an unauthorized device or a hub triggers a violation. This defends against MAC flooding and rogue connections. Violations can protect, restrict, or shut down the port depending on the configured mode.

Security Fundamentals

Under port security, which violation mode drops offending frames and increments the violation counter but does NOT shut the port down?

  • a.Recover, which re-enables the port automatically
  • b.Shutdown, the default mode
  • c.Restrict✓
  • d.Protect, which drops silently without any counter

In 'restrict' mode, frames from unauthorized MAC addresses are dropped, the violation counter increases, and an SNMP/Syslog notification is generated, but the port stays up. 'Protect' also drops the frames but silently, with no counter or alert. 'Shutdown', the default, err-disables the port entirely.

Security Fundamentals

What does the port-security 'sticky' option accomplish?

  • a.It encrypts the MAC address table so it cannot be read by 'show' commands This shutdown is triggered before the switch has learned even a single legitimate MAC address.
  • b.It permanently blocks any MAC address that has ever caused a violation
  • c.It forces the port into shutdown mode on the first frame received
  • d.It dynamically learns connected MAC addresses and adds them to the running configuration as secure addresses✓

With 'switchport port-security mac-address sticky', the switch learns the currently connected MAC addresses and writes them into the running configuration as secure addresses, avoiding manual entry. Saving the config makes them persist across reloads. New, unlearned addresses beyond the maximum then trigger the configured violation action.

Security Fundamentals

A port-security-enabled interface is in the err-disabled state after a violation. How can it be returned to service?

  • a.Wait five minutes for it to clear itself with no intervention
  • b.Delete and recreate the VLAN the port belongs to
  • c.Issue 'shutdown' then 'no shutdown' on the interface (or configure errdisable recovery)✓
  • d.Reload the entire switch, as no other method works

An err-disabled port must be manually recovered by shutting and re-enabling it with 'shutdown' followed by 'no shutdown', after removing the offending device. Alternatively, 'errdisable recovery cause psecure-violation' with a timer can auto-recover it. Simply waiting does nothing unless auto-recovery is configured.

Security Fundamentals

DHCP snooping designates ports as trusted or untrusted. Which type of port should face a legitimate DHCP server?

  • a.A port with PortFast disabled to slow down the handshake
  • b.A trusted port, so the server's DHCPOFFER and DHCPACK replies are permitted✓
  • c.An untrusted port, so the server's replies are inspected and dropped
  • d.Any access port, since DHCP snooping does not distinguish ports

Ports connecting to legitimate DHCP servers (typically uplinks) are configured as trusted so server-sourced messages like DHCPOFFER and DHCPACK are allowed through. Ports facing end hosts stay untrusted, and server messages arriving there are dropped as rogue. This prevents attackers from running unauthorized DHCP servers.

Security Fundamentals

Which attack does DHCP snooping primarily defend against?

  • a.ARP cache poisoning between two hosts on the same VLAN
  • b.MAC address table overflow caused by flooding random source MACs
  • c.Spanning-tree manipulation using forged superior BPDUs
  • d.A rogue DHCP server handing out bogus addresses and gateway information✓

DHCP snooping stops a rogue DHCP server from responding to clients by dropping server messages on untrusted ports, preventing attackers from assigning malicious default gateways or DNS servers. It also builds a binding table used by Dynamic ARP Inspection and IP Source Guard. ARP poisoning and STP attacks are addressed by other features.

Security Fundamentals

Dynamic ARP Inspection relies on which data structure to validate ARP packets on untrusted ports?

  • a.The DHCP snooping binding table✓
  • b.The switch's spanning-tree topology database
  • c.The CDP neighbor table maintained per interface
  • d.The router's OSPF link-state database

DAI checks each ARP packet on untrusted ports against the DHCP snooping binding table, which records valid IP-to-MAC-to-port bindings learned during DHCP. ARP messages that do not match a legitimate binding are dropped, defeating ARP spoofing and man-in-the-middle attacks. Because of this dependency, DHCP snooping must be enabled for DAI to function.

Security Fundamentals

Which Layer 2 attack involves an attacker sending gratuitous ARP replies to associate their MAC with the default gateway's IP?

  • a.CAM table overflow through MAC flooding
  • b.DHCP starvation by exhausting the address pool
  • c.ARP spoofing (ARP poisoning)✓
  • d.VLAN hopping using double-tagged 802.1Q frames

In ARP spoofing, the attacker sends forged ARP replies claiming the gateway's IP maps to the attacker's MAC, so victims send their traffic to the attacker, enabling interception. Dynamic ARP Inspection, backed by DHCP snooping, blocks these forged replies. VLAN hopping, CAM overflow, and DHCP starvation are distinct Layer 2 attacks.

Security Fundamentals

How does a MAC address (CAM) table overflow attack degrade switch behavior?

  • a.It reprograms the switch to route packets at Layer 3 incorrectly
  • b.It floods the switch with bogus source MACs until the table fills, causing the switch to flood frames out all ports✓
  • c.It forces the switch to elect the attacker as the spanning-tree root The attacker then advertises a superior bridge ID so every port transitions to the blocking state, letting the traffic be quietly captured.
  • d.It disables the switch's management interface via repeated logins

By flooding the switch with countless frames using random source MAC addresses, an attacker fills the finite CAM table so legitimate entries cannot be learned. The switch then floods unknown-unicast frames out all ports, letting the attacker capture traffic. Port security, which limits MACs per port, is the standard defense.

Security Fundamentals

Which feature protects against VLAN hopping via the double-tagging technique?

  • a.Applying an extended ACL to the native VLAN interface
  • b.Enabling DHCP snooping on all access ports
  • c.Turning on BPDU Guard for every trunk link
  • d.Changing the native VLAN to an unused VLAN and not using VLAN 1✓

Double-tagging VLAN hopping abuses the native VLAN, which is sent untagged, so setting the native VLAN to a dedicated unused VLAN (and explicitly tagging it) removes the opening. Disabling dynamic trunking (DTP) on access ports and pruning unused VLANs from trunks further hardens against hopping. VLAN 1 should be avoided for user or native use.

Security Fundamentals

What are the three core services provided by AAA?

  • a.Authentication, Authorization, and Accounting✓
  • b.Authorization, Auditing, and Acknowledgment
  • c.Access, Auditing, and Alerting
  • d.Authentication, Availability, and Assurance

AAA stands for Authentication (verifying identity), Authorization (determining what an authenticated user may do), and Accounting (recording what the user did). Centralizing these on a server improves security and auditing across many devices. Cisco supports AAA using RADIUS or TACACS+ back-end servers.

Security Fundamentals

Which AAA protocol is Cisco-proprietary, uses TCP port 49, and encrypts the entire packet payload?

  • a.RADIUS, an open standard using UDP
  • b.LDAP, which queries a directory over TCP 389
  • c.TACACS+✓
  • d.Kerberos, which issues time-limited tickets

TACACS+ is Cisco-developed, runs over TCP port 49, and encrypts the whole payload, and it separates authentication, authorization, and accounting into independent functions, which suits granular device-administration control. RADIUS is an open standard over UDP that encrypts only the password and combines authentication with authorization. Both centralize AAA but serve different emphases.

Security Fundamentals

Which statement about RADIUS is correct?

  • a.It is an open standard, uses UDP, and encrypts only the password portion of the packet✓
  • b.It uses TCP and encrypts the entire packet including the username
  • c.It is Cisco-proprietary and separates all three AAA functions
  • d.It operates exclusively on port 49 and cannot perform accounting

RADIUS is an IETF open standard that runs over UDP and encrypts only the user's password, leaving other attributes in clear text. It combines authentication and authorization into one exchange, which is well suited to network access scenarios like 802.1X. TACACS+, by contrast, is Cisco's TCP-based protocol that encrypts the full payload.

Security Fundamentals

For which use case is TACACS+ typically preferred over RADIUS?

  • a.Authenticating thousands of wireless clients joining via 802.1X
  • b.Granular device administration, where per-command authorization is valuable✓
  • c.Providing a lightweight UDP-based option for high-speed access ports
  • d.Handing out IP addresses to hosts as they connect to the network

TACACS+ separates authorization from authentication and can authorize individual CLI commands, making it ideal for controlling what administrators may do on network devices. RADIUS, combining authentication and authorization, is more common for network access (802.1X, VPN). The choice depends on whether fine-grained command control or high-volume access authentication is the priority.

Security Fundamentals

Why is 'enable secret' preferred over 'enable password' for protecting privileged EXEC mode?

  • a.'enable secret' disables the console port entirely for extra safety
  • b.'enable password' uses AES encryption, which is slower and less secure Because the two commands compute the identical hash internally, administrators may freely use either one interchangeably in production.
  • c.'enable secret' stores the password as a strong one-way hash, while 'enable password' may be clear text or weakly reversible✓
  • d.They are identical, so the choice is purely a matter of preference

'enable secret' hashes the privileged-mode password with a strong one-way algorithm, so it cannot be trivially reversed, whereas 'enable password' is either clear text or protected only by the weak, reversible Type 7 encoding. When both are configured, the secret takes precedence. Best practice is to use enable secret and omit enable password.

Security Fundamentals

What does the global command 'service password-encryption' do?

  • a.It hashes all passwords with a strong irreversible algorithm equivalent to enable secret
  • b.It forces every user to change their password at next login
  • c.It encrypts the entire running configuration file stored in NVRAM
  • d.It applies weak, reversible Type 7 encryption to clear-text passwords in the configuration✓

'service password-encryption' obscures clear-text passwords (such as line and enable passwords) using the weak, reversible Type 7 algorithm, which merely prevents shoulder-surfing, not determined attackers. It is not equivalent to the strong hashing of 'enable secret'. It should be seen as a minor hardening step, not real cryptographic protection.

Showing 40 of 67

Report