Cisco CCNA 200-301 Exam — Questions and Answers
Question 1: An administrator applies the command 'ip access-group 101 in' on an interface. What does this mean?
- ACL 101 is a named ACL
- ACL 101 is applied to all interfaces
- ACL 101 filters traffic entering the interface (Correct answer)
- ACL 101 filters traffic leaving the interface
Correct answer: ACL 101 filters traffic entering the interface
The 'in' keyword applies the ACL to inbound traffic arriving on that interface.
Question 2: What is the function of a YANG model in network automation?
- It is a scripting language for routers
- It provides GUI-based network management
- It defines the data structure and constraints for network configuration (Correct answer)
- It encrypts NETCONF sessions
Correct answer: It defines the data structure and constraints for network configuration
YANG (Yet Another Next Generation) is a data modeling language that defines the structure, syntax, and semantics of network configuration data.
Question 3: Which private IPv4 address range is defined in RFC 1918 for Class B networks?
- 169.254.0.0 – 169.254.255.255
- 10.0.0.0 – 10.255.255.255
- 172.16.0.0 – 172.31.255.255 (Correct answer)
- 192.168.0.0 – 192.168.255.255
Correct answer: 172.16.0.0 – 172.31.255.255
RFC 1918 designates 172.16.0.0 through 172.31.255.255 (172.16.0.0/12) as private Class B space.
Question 4: Which feature prevents RIP routing loops by immediately marking a route as unreachable when its interface goes down, before the update timer expires?
- Route poisoning (Correct answer)
- Hold-down timers
- Triggered updates
- Split horizon
Correct answer: Route poisoning
Route poisoning immediately advertises a failed route with a metric of 16 (infinity) to notify neighbors quickly rather than waiting for a timeout.
Question 5: A PC with the IP address 192.168.50.5 sends a packet to a public web server at 203.0.113.10. The packet traverses a router performing PAT. The router translates the source IP to 209.165.201.30. In this scenario, what does the address 203.0.113.10 represent?
- Outside Global (Correct answer)
- Outside Local
- Inside Local
- Inside Global
Correct answer: Outside Global
The address 203.0.113.10 is the IP address of the destination device located on the external, public network. In NAT terminology, this is known as the 'outside global' address. It is the real, globally routable address of the external host.
Question 6: In an Ansible playbook, what is the purpose of the 'vars' section?
- It lists the target hosts for the playbook
- It defines variable values used throughout the playbook (Correct answer)
- It specifies which Ansible modules to install
- It sets the execution order of tasks
Correct answer: It defines variable values used throughout the playbook
The 'vars' section in a playbook defines variables that can be referenced in tasks using {{ variable_name }} syntax.
Question 7: What does the 'I' stand for in the CRUD acronym used with REST APIs?
- Integrate
- Index
- Insert
- CRUD does not contain an 'I' (Correct answer)
Correct answer: CRUD does not contain an 'I'
CRUD stands for Create, Read, Update, Delete — there is no 'I' in the acronym.
Question 8: On a switch, what does the term 'asymmetric switching' refer to?
- Forwarding frames using different methods per port
- A switch that operates at both Layer 2 and Layer 3
- Using multiple MAC address tables for different VLANs
- Switching between ports that have different bandwidth speeds (Correct answer)
Correct answer: Switching between ports that have different bandwidth speeds
Asymmetric switching provides switched connections between ports of unequal bandwidth, such as between 100 Mbps and 1 Gbps ports.
Question 9: Which ACL feature locks a switch port to a specific user's MAC address after successful authentication?
- Reflexive ACL
- Dynamic ACL (Lock-and-Key) (Correct answer)
- Port ACL (PACL)
- VLAN ACL (VACL)
Correct answer: Dynamic ACL (Lock-and-Key)
Dynamic ACLs (Lock-and-Key) require Telnet authentication before temporarily opening access for a specific host.
Question 10: Which Python data type is most analogous to a JSON object?
- set
- dictionary (Correct answer)
- list
- tuple
Correct answer: dictionary
A JSON object (key-value pairs in curly braces) maps directly to a Python dictionary.
Question 11: A network administrator wants to prevent a switch from learning MAC addresses on a specific port dynamically. Which feature should be used?
- VLAN pruning
- Spanning Tree PortFast
- DHCP snooping
- Port security with sticky MAC (Correct answer)
Correct answer: Port security with sticky MAC
Port security with sticky MAC learning locks down dynamically learned addresses and converts them to secure sticky entries.
Question 12: What is the purpose of the CAPWAP data tunnel between an AP and a WLC?
- To carry management and control messages only
- To synchronize firmware updates across all APs
- To provide redundant paths between APs
- To encapsulate and forward client data traffic to the WLC (Correct answer)
Correct answer: To encapsulate and forward client data traffic to the WLC
The CAPWAP data tunnel encapsulates 802.11 client frames and forwards them to the WLC for centralized processing and routing.
Question 13: When configuring route redistribution from OSPF into EIGRP on a Cisco router, what is required that is not needed when redistributing static routes into EIGRP?
- Redistribution from OSPF into EIGRP is not supported
- The OSPF process ID must match the EIGRP AS number
- A route map must always be used
- A seed metric must be specified since OSPF metrics are incompatible with EIGRP's composite metric (Correct answer)
Correct answer: A seed metric must be specified since OSPF metrics are incompatible with EIGRP's composite metric
EIGRP requires a seed metric when redistributing from protocols that use incompatible metrics, unlike static routes which inherit a default metric.
Question 14: Which of the following technologies is Fast Ethernet?
- 1000BASE-F
- 100BASE-TX (Correct answer)
- 100BASE2
- 100BASE-FX (Correct answer)
- 100BASE-5
Correct answer: 100BASE-TX
Fast Ethernet refers to Ethernet standards that support a data rate of 100 Mbps. 100BASE-TX uses two pairs of unshielded twisted-pair (UTP) cable, while 100BASE-FX uses fiber optic cable. Both are common implementations of Fast Ethernet, providing a significant speed upgrade from the original 10 Mbps Ethernet standards.
Question 15: Which STP enhancement prevents a port from becoming a designated port if it stops receiving BPDUs, protecting against unidirectional link failures?
- PortFast
- Loop Guard (Correct answer)
- BPDU Guard
- Root Guard
Correct answer: Loop Guard
Loop Guard places a port in a loop-inconsistent blocking state if BPDUs stop arriving, preventing it from incorrectly transitioning to Forwarding.
Question 16: What is the purpose of the SNMP 'trap' message type compared to an SNMP 'inform'?
- Traps require acknowledgment; informs are unacknowledged
- Both are identical in function
- Informs are only used in SNMPv1
- Traps are unacknowledged; informs require acknowledgment from the manager (Correct answer)
Correct answer: Traps are unacknowledged; informs require acknowledgment from the manager
SNMP traps are sent once with no acknowledgment, while informs are retransmitted until the manager acknowledges receipt.
Question 17: How does a switch build its MAC address table?
- By querying a DHCP server for MAC-to-IP mappings
- By reading the destination MAC of outgoing frames
- By reading the source MAC address of incoming frames (Correct answer)
- By sending ARP requests to all devices
Correct answer: By reading the source MAC address of incoming frames
A switch learns MAC addresses by examining the source MAC address field of frames received on each port and recording the port association.
Question 18: What is the minimum RSA key size recommended when generating SSH keys on a Cisco IOS device for SSHv2?
- 2048 bits (Correct answer)
- 1024 bits
- 512 bits
- 768 bits
Correct answer: 2048 bits
SSHv2 requires a minimum RSA key modulus of 768 bits, but Cisco and industry best practices recommend at least 2048 bits for current deployments.
Question 19: Which Cisco IOS command displays port security status including the number of secure MAC addresses on an interface?
- show port-security interface (Correct answer)
- show switchport security
- show mac address-table secure
- show interface port-security
Correct answer: show port-security interface
'show port-security interface <interface>' displays the port security configuration, violation count, and learned secure MAC addresses.
Question 20: A Layer 3 EtherChannel differs from a Layer 2 EtherChannel in that it:
- Requires VTP to be disabled before configuration
- Supports only two physical links instead of eight
- Has an IP address assigned directly to the port-channel interface (Correct answer)
- Uses PAgP instead of LACP for negotiation
Correct answer: Has an IP address assigned directly to the port-channel interface
A Layer 3 EtherChannel is created with 'no switchport' on member interfaces; the port-channel interface itself receives an IP address and acts as a routed interface.
Question 21: Which type of VLAN attack allows a rogue device to send frames on a VLAN other than the one it is assigned to?
- STP manipulation
- ARP poisoning
- MAC spoofing
- VLAN hopping (Correct answer)
Correct answer: VLAN hopping
VLAN hopping exploits trunk negotiation (DTP) or double-tagging to inject frames into a target VLAN without authorization.
Question 22: Which of these is the Cisco-developed Neighbour Discovery Protocol?
- IGMP
- CGMP
- CDP (Correct answer)
- ICMP
Correct answer: CDP
CDP (Cisco Discovery Protocol) is a Cisco proprietary Layer 2 protocol used to discover information about directly connected Cisco devices. It allows devices to share details such as device type, IOS version, capabilities, and connected interface. This protocol is invaluable for network documentation, troubleshooting, and managing Cisco-centric network environments.
Question 23: Which protocol encrypts the entire management session between an administrator and a Cisco device?
- SNMP v2c
- TFTP
- SSH (Correct answer)
- Telnet
Correct answer: SSH
SSH (Secure Shell) encrypts all traffic between the client and the network device, while Telnet transmits data in plaintext.
Question 24: During the data encapsulation process, which layer of the OSI model is responsible for adding a header that contains source and destination MAC addresses?
- Data Link Layer (Correct answer)
- Transport Layer
- Network Layer
- Physical Layer
Correct answer: Data Link Layer
The Data Link Layer (Layer 2) is responsible for creating frames. During encapsulation, it adds a header containing the source and destination MAC (physical) addresses to the packet received from the Network Layer. This framing is essential for delivery on the local network segment.
Question 25: What is a characteristic of a full-mesh WAN topology?
- Every site has a direct connection to every other site (Correct answer)
- Only two sites are directly connected
- Sites connect in a ring pattern
- Each site connects only to a central hub
Correct answer: Every site has a direct connection to every other site
In a full-mesh topology, every site has a direct point-to-point connection to every other site, providing maximum redundancy.
Question 26: A switch has a bridge priority of 32768 and a MAC address of 00:1A:2B:3C:4D:5E. What is its Bridge ID?
- 00:1A:2B:3C:4D:5E:32768
- 32768:00:1A:2B:3C:4D:5E (Correct answer)
- The MAC address only
- 32768 only
Correct answer: 32768:00:1A:2B:3C:4D:5E
The Bridge ID is a combination of the bridge priority (2 bytes) followed by the MAC address (6 bytes).
Question 27: What is the well-known UDP port number used by SNMP agents to receive requests from an SNMP manager?
- 161 (Correct answer)
- 514
- 162
- 123
Correct answer: 161
SNMP agents listen on UDP port 161 for polling requests sent by the SNMP manager.
Question 28: Which command hardens a Cisco IOS device by encrypting all plaintext passwords currently in the running configuration?
- service password-encryption (Correct answer)
- enable secret level 5
- password encrypt all
- crypto password enable
Correct answer: service password-encryption
'service password-encryption' applies a weak reversible Type 7 encryption to plaintext passwords in the configuration.
Question 29: What is the primary purpose of EtherChannel on a Cisco switch?
- To bundle multiple physical links into a single logical link for increased bandwidth and redundancy (Correct answer)
- To encrypt traffic between switches
- To separate broadcast domains across trunk links
- To provide dynamic IP address assignment to connected devices
Correct answer: To bundle multiple physical links into a single logical link for increased bandwidth and redundancy
EtherChannel aggregates multiple physical Ethernet links into one logical link, multiplying bandwidth and providing redundancy without Spanning Tree blocking ports.
Question 30: Which automation approach is described as 'push-based' where a central controller sends configuration to devices?
- Ansible (Correct answer)
- Puppet
- Chef
- Both Puppet and Chef
Correct answer: Ansible
Ansible uses a push model where the control node actively pushes configuration to managed devices over SSH.
Question 31: Which command verifies the trunking status and allowed VLANs on interface Gi0/1?
- show interfaces Gi0/1 trunk (Correct answer)
- show trunk Gi0/1
- show vlan brief
- show interfaces Gi0/1 switchport
Correct answer: show interfaces Gi0/1 trunk
`show interfaces Gi0/1 trunk` displays trunking mode, encapsulation, and the allowed VLAN list.
Question 32: Which command on a Cisco switch assigns a physical interface to EtherChannel group 1 using LACP active mode?
- etherchannel 1 lacp active
- lacp group 1 active
- channel-group 1 mode active (Correct answer)
- port-channel 1 active
Correct answer: channel-group 1 mode active
The 'channel-group 1 mode active' interface command assigns the port to port-channel 1 and enables LACP active negotiation.
Question 33: A network administrator uses 'ip ospf 1 area 0' on an interface instead of the 'network' command. What is the result?
- The command is invalid and will be rejected
- The router becomes an OSPF DR for area 0
- Only that specific interface is enabled for OSPF area 0 (Correct answer)
- All interfaces on the router join area 0
Correct answer: Only that specific interface is enabled for OSPF area 0
The interface-level 'ip ospf process-id area area-id' command enables OSPF directly on that specific interface.
Question 34: To prevent double-tagging VLAN hopping attacks, which best practice should be applied?
- Disable 802.1Q on all ports
- Set all ports to dynamic auto
- Enable VTP transparent mode
- Change the native VLAN to an unused VLAN ID (Correct answer)
Correct answer: Change the native VLAN to an unused VLAN ID
Using an unused, non-default native VLAN prevents double-tagging attacks because the attacker cannot predict or match the native VLAN.
Question 35: A switch port is stuck in the STP Blocking state and does not transition even after the network stabilizes. Which feature is most likely responsible?
- The forward delay timer is set too high
- The switch has too many VLANs configured
- PortFast was not enabled on the port
- Root Guard placed the port in root-inconsistent blocking state (Correct answer)
Correct answer: Root Guard placed the port in root-inconsistent blocking state
Root Guard places a port in root-inconsistent (blocking) state when a superior BPDU is received; the port stays blocked until no more superior BPDUs arrive.
Question 36: In Python, which library is commonly used to make HTTP REST API calls to network devices?
- requests (Correct answer)
- netmiko
- scapy
- paramiko
Correct answer: requests
The 'requests' library is the standard Python library for making HTTP/REST API calls.
Question 37: What are the REST's primary characteristics?
- All of them (Correct answer)
- Scalable
- Flexible
- Lightweight
- Platform-agnostic
Correct answer: All of them
REST (Representational State Transfer) is an architectural style for designing networked applications, particularly web services. Its primary characteristics include being lightweight due to its use of standard HTTP methods, flexible in handling various data formats, platform-agnostic as it can be implemented across different technologies, and scalable because of its stateless nature. These attributes make REST a popular choice for modern API design.
Question 38: What is the effect of the implicit deny at the end of every ACL?
- It permits all unmatched traffic
- It logs all unmatched traffic
- It sends unmatched traffic to a default route
- It drops all traffic that does not match any ACL entry (Correct answer)
Correct answer: It drops all traffic that does not match any ACL entry
Every ACL ends with an implicit 'deny any' that silently drops any traffic not matched by a previous entry.
Question 39: What is the maximum number of hops allowed in an MST (Multiple Spanning Tree) region before a BPDU is discarded?
- 20 (Correct answer)
- 7
- 15
- 32
Correct answer: 20
MST uses a max hops field (default 20) instead of the traditional max age timer to limit BPDU propagation within a region.
Question 40: What is a primary characteristic of an autonomous WLAN architecture?
- It relies on a cloud-based dashboard for all configuration and firmware updates.
- Each access point is individually configured and manages its own settings, security, and client associations. (Correct answer)
- All client traffic is tunneled back to a central appliance using the CAPWAP protocol.
- It requires a dedicated Wireless LAN Controller (WLC) on the local network.
Correct answer: Each access point is individually configured and manages its own settings, security, and client associations.
An autonomous AP is a self-contained, standalone device. Each AP is configured and managed individually, typically via a CLI or web GUI. It handles all functions locally, including user authentication, security policies, and RF management, without the need for a WLC. [1, 2, 5] This architecture is simple for small deployments but becomes difficult to manage at scale. [2, 15]
Question 41: When comparing JSON and XML for API data exchange, which statement is accurate?
- JSON is generally more human-readable and less verbose than XML (Correct answer)
- JSON uses tags like <key> and </key> to structure data
- XML is the only format supported by REST APIs
- XML is lighter weight and easier to parse than JSON
Correct answer: JSON is generally more human-readable and less verbose than XML
JSON uses key-value pairs with less syntactic overhead than XML's opening/closing tags, making it more concise and readable.
Question 42: What happens when the MAC address table of a switch becomes full?
- The switch floods all new unknown frames like a hub (Correct answer)
- New frames are dropped
- The switch deletes the oldest VLAN entries first
- The switch reboots automatically
Correct answer: The switch floods all new unknown frames like a hub
When the CAM table is full, the switch cannot learn new MAC addresses and floods unknown frames out all ports, effectively behaving like a hub.
Question 43: Which DNS record type provides reverse lookup, mapping an IPv4 address back to a hostname?
- SOA record
- PTR record (Correct answer)
- MX record
- A record
Correct answer: PTR record
PTR (Pointer) records enable reverse DNS lookups by mapping an IP address to a corresponding fully qualified domain name.
Question 44: To identify traffic bottlenecks between two sites, which router command is used?
- SSH
- Trace (Correct answer)
- Telnet
- Ping
Correct answer: Trace
The `traceroute` (or `trace` on Cisco devices, `tracert` on Windows) command is used to display the path and measure transit delays of packets across an IP network. By showing each router (hop) a packet traverses and the round-trip time to each hop, it helps identify where delays or bottlenecks might be occurring between two sites. This makes it ideal for diagnosing connectivity and performance issues.
Question 45: Which of the following is a primary benefit of using VLANs in a network?
- To increase the size of a collision domain.
- To create a single, large broadcast domain.
- To eliminate the need for routers.
- To segment the network into multiple broadcast domains. (Correct answer)
Correct answer: To segment the network into multiple broadcast domains.
Virtual LANs (VLANs) are used to logically segment a Layer 2 network. Each VLAN is a separate broadcast domain. This means that broadcast frames sent by a device in one VLAN are only forwarded to other devices within that same VLAN, not to the entire physical network. This improves security, reduces unnecessary traffic, and enhances network performance.
Question 46: An administrator adds VLAN 50 to two switches that are connected by a trunk link. Devices in VLAN 50 on the first switch cannot communicate with devices in VLAN 50 on the second switch. The administrator has confirmed that VLAN 50 exists on both switches. Which of the following is the most likely reason for the problem?
- Spanning Tree Protocol has blocked the trunk link for VLAN 50.
- VLAN 50 has not been added to the allowed list on the trunk ports. (Correct answer)
- The switches are operating in different VTP modes.
- A native VLAN mismatch exists on the trunk.
Correct answer: VLAN 50 has not been added to the allowed list on the trunk ports.
By default, a trunk port allows all VLANs to pass. However, if a trunk port has been configured with an allowed VLAN list using the `switchport trunk allowed vlan` command, any new VLAN must be explicitly added to that list. If VLAN 50 is not on the allowed list, its traffic will be blocked from crossing the trunk.
Question 47: An EIGRP router's topology table shows a destination with a Feasible Distance of 28160 and a Reported Distance of 25600. The router has one successor. What correctly describes this entry?
- The router will immediately query neighbors because no feasible successor exists
- This entry is invalid because RD cannot be less than FD
- The route is active because the RD exceeds the FD
- The route is in passive state and the FD is the metric to reach the destination via the successor (Correct answer)
Correct answer: The route is in passive state and the FD is the metric to reach the destination via the successor
In passive state, the FD represents the best metric to the destination via the successor, and a lower RD than FD is normal and expected.
Question 48: Which command prevents the 'enable' password from being stored in plaintext in the Cisco IOS configuration?
- enable secret <password> (Correct answer)
- enable password <password>
- enable md5 <password>
- service password-encryption
Correct answer: enable secret <password>
'enable secret' stores the enable password as an MD5 (or stronger) hash, unlike 'enable password' which stores it in plaintext or weak Type 7.
Question 49: A company needs 10 subnets from 192.168.1.0/24 with at least 10 hosts each. Which prefix length meets both requirements?
- /28
- /25
- /26
- /27 (Correct answer)
Correct answer: /27
A /27 provides 32 subnets (2^5) from a /24 and 30 usable hosts each (2^3 – 2), satisfying both requirements.
Question 50: Which 802.11 band characteristic makes 5 GHz preferable to 2.4 GHz in dense environments?
- 5 GHz has greater range and penetrates walls better
- 5 GHz requires less transmit power for the same coverage area
- 5 GHz has more non-overlapping channels and typically less interference (Correct answer)
- 5 GHz is backward compatible with all 802.11b devices
Correct answer: 5 GHz has more non-overlapping channels and typically less interference
The 5 GHz band offers up to 24 non-overlapping channels (in the US) compared to only 3 in 2.4 GHz, reducing co-channel interference in dense deployments.
Question 51: Which NTP stratum number indicates that a device is directly connected to a reference clock (e.g., GPS)?
- Stratum 2
- Stratum 0
- Stratum 1 (Correct answer)
- Stratum 15
Correct answer: Stratum 1
Stratum 1 NTP servers are directly connected to a stratum 0 reference clock source such as GPS or atomic clocks.
Question 52: A Cisco router learns about the destination network 172.16.10.0/24 from two different routing sources: internal EIGRP and OSPF. Assuming default settings, which route will be installed in the routing table?
- The OSPF route, because it is an open standard.
- The router will install both routes and load balance the traffic.
- The EIGRP route, because it has a lower default administrative distance. (Correct answer)
- The OSPF route, because it has a lower metric.
Correct answer: The EIGRP route, because it has a lower default administrative distance.
When a router learns about the exact same prefix from multiple routing protocols, it uses the Administrative Distance (AD) to determine which route is more trustworthy. On Cisco routers, internal EIGRP has a default AD of 90, while OSPF has a default AD of 110. The router prefers the route with the lower AD, so the EIGRP route will be installed in the routing table.
Question 53: How does OSPFv2 handle equal-cost paths to the same destination by default on Cisco routers?
- The most recently learned path is preferred
- Only the path with the lowest router ID is used
- Traffic is load-balanced across up to 4 equal-cost paths (Correct answer)
- Only one path is installed; the other is held as a backup
Correct answer: Traffic is load-balanced across up to 4 equal-cost paths
Cisco routers perform equal-cost load balancing (ECMP) across up to 4 paths by default when OSPF finds multiple equal-cost routes.
Question 54: Which statement about the 802.11ax (Wi-Fi 6) standard is correct?
- It replaces MIMO with beamforming as the only spatial multiplexing method
- It operates only in the 6 GHz band
- It introduces OFDMA to improve efficiency in dense, multi-client environments (Correct answer)
- It reduces maximum channel width to 80 MHz for better range
Correct answer: It introduces OFDMA to improve efficiency in dense, multi-client environments
802.11ax (Wi-Fi 6) introduces OFDMA (Orthogonal Frequency Division Multiple Access) allowing simultaneous transmission to multiple clients, greatly improving efficiency in dense deployments.
Question 55: How does Spanning Tree Protocol (STP) treat an EtherChannel bundle?
- STP runs separately on each physical link in the bundle
- STP blocks all but one physical link in the bundle
- STP is disabled automatically when EtherChannel is configured
- STP treats the entire EtherChannel as a single logical link (Correct answer)
Correct answer: STP treats the entire EtherChannel as a single logical link
STP sees the entire EtherChannel port-channel as a single logical interface, so it does not block individual member links, allowing all bundled links to carry traffic.
Question 56: The ____ protocol is used to manage network devices.
- SNMP (Correct answer)
- OSPF
- RSTP
- SMTP
Correct answer: SNMP
SNMP (Simple Network Management Protocol) is a widely used application-layer protocol for managing and monitoring network devices. It allows network administrators to collect information, modify configurations, and receive alerts about the status of routers, switches, servers, and other network equipment. SNMP is crucial for network operations, performance monitoring, and troubleshooting.
Question 57: Which OSI layer is responsible for establishing, maintaining, and terminating sessions between applications?
- Presentation (Layer 6)
- Transport (Layer 4)
- Session (Layer 5) (Correct answer)
- Application (Layer 7)
Correct answer: Session (Layer 5)
The Session layer (Layer 5) controls the establishment, management, and termination of communication sessions between applications.
Question 58: A switch receives a tagged frame with VLAN 10 on a port configured as an access port for VLAN 20. What does the switch do?
- Forwards the frame to VLAN 10
- Strips the tag and forwards on VLAN 20
- Adds a second tag and floods the frame
- Drops the frame (Correct answer)
Correct answer: Drops the frame
Cisco switches drop tagged frames received on access ports because access ports expect untagged traffic.
Question 59: A company wants external internet users to reach an internal web server at 10.0.0.5 via the public IP 198.51.100.10. Which NAT type should be used?
- PAT (NAT Overload)
- Double NAT
- Dynamic NAT
- Static NAT (Correct answer)
Correct answer: Static NAT
Static NAT creates a permanent one-to-one mapping between a private IP and a public IP, allowing inbound connections to reach internal servers predictably.
Question 60: What is the primary advantage of using NETCONF over SNMP for network management?
- NETCONF uses UDP for faster delivery
- NETCONF supports transactional configuration with rollback (Correct answer)
- NETCONF is only used for monitoring, not configuration
- NETCONF requires no authentication
Correct answer: NETCONF supports transactional configuration with rollback
NETCONF provides transactional configuration operations including commit and rollback capabilities, which SNMP lacks.
Question 61: Which command configures an interface as a VLAN trunk using IEEE 802.1Q encapsulation?
- switchport mode trunk
- switchport access vlan trunk
- switchport trunk encapsulation dot1q (Correct answer)
- trunk mode dot1q enable
Correct answer: switchport trunk encapsulation dot1q
The 'switchport trunk encapsulation dot1q' command must be issued before setting the port to trunk mode on some Cisco platforms.
Question 62: An administrator wants to log packets that match an ACL deny entry. Which keyword is added to the ACL entry?
- log (Correct answer)
- record
- trace
- monitor
Correct answer: log
Adding the 'log' keyword at the end of an ACL entry causes matching packets to generate a syslog message.
Question 63: A router interface is configured with 'ipv6 address 2001:DB8:A:1::/64 eui-64'. What does the eui-64 keyword cause the router to do?
- Derive the interface ID from the interface's MAC address using EUI-64 (Correct answer)
- Use a randomly generated interface ID
- Use DHCPv6 to obtain the full address
- Configure only the prefix without an interface ID
Correct answer: Derive the interface ID from the interface's MAC address using EUI-64
The eui-64 keyword instructs the router to generate the 64-bit interface ID automatically from the interface's MAC address using the EUI-64 method.
Question 64: A client roams from AP1 to AP2, both managed by the same WLC. Which type of roaming occurs?
- Layer 3 roaming requiring a new IP address assignment
- Inter-controller roaming requiring full re-authentication
- Mesh roaming using wireless backhaul negotiation
- Intra-controller roaming where the WLC updates client mapping internally (Correct answer)
Correct answer: Intra-controller roaming where the WLC updates client mapping internally
When both APs are on the same WLC, intra-controller roaming occurs and the WLC simply updates its internal client-to-AP mapping without requiring full re-authentication.
Question 65: A host has the IP address 10.4.8.77/21. What is the network address of this subnet?
- 10.4.8.64
- 10.4.0.0 (Correct answer)
- 10.4.8.0
- 10.0.0.0
Correct answer: 10.4.0.0
A /21 mask covers the first 21 bits; the third octet's top 5 bits identify the subnet — 8 (00001000) ANDed with the mask gives 10.4.0.0.
Question 66: What happens when you configure one side of a link with EtherChannel mode 'On' and the other side with mode 'Active' (LACP)?
- The switch automatically detects the mismatch and switches to passive mode
- The EtherChannel forms using PAgP as a fallback
- The EtherChannel forms successfully using LACP
- The EtherChannel fails to form because 'On' mode does not send or respond to negotiation packets (Correct answer)
Correct answer: The EtherChannel fails to form because 'On' mode does not send or respond to negotiation packets
'On' mode forces EtherChannel without any negotiation protocol; it will not respond to LACP or PAgP packets, so the channel will not form with a negotiating peer.
Question 67: What distinguishes WPA3-Personal from WPA2-Personal in terms of key exchange?
- WPA3 requires a RADIUS server for authentication
- WPA3 replaces AES with ChaCha20 encryption
- WPA3 uses Simultaneous Authentication of Equals (SAE) instead of PSK (Correct answer)
- WPA3 uses a 4-way handshake with a pre-shared key
Correct answer: WPA3 uses Simultaneous Authentication of Equals (SAE) instead of PSK
WPA3-Personal uses SAE (Simultaneous Authentication of Equals), also known as Dragonfly, which provides forward secrecy and resistance to offline dictionary attacks.
Question 68: A network engineer configures a Cisco router for single-area OSPFv2. The router has three active interfaces: Loopback0 (10.0.0.1/32), GigabitEthernet0/0 (192.168.1.1/24), and GigabitEthernet0/1 (172.16.1.1/24). The OSPF process is started, but the `router-id` command is NOT used. Which IP address will OSPF select as the router ID?
- 172.16.1.1
- The OSPF process will fail to start without a manual router-id.
- 10.0.0.1 (Correct answer)
- 192.168.1.1
Correct answer: 10.0.0.1
The OSPF router ID selection process on Cisco IOS follows a specific order of precedence: 1) The address manually configured with the `router-id` command. 2) The highest IP address on any configured loopback interfaces. 3) The highest IP address on any active non-loopback (physical) interfaces. Since the `router-id` command was not used, OSPF will select the highest loopback IP address, which is 10.0.0.1.
Question 69: Which TCP/IP model layer is responsible for logical addressing and routing between networks?
- Network Access
- Internet (Correct answer)
- Transport
- Application
Correct answer: Internet
The Internet layer of the TCP/IP model handles IP addressing and routing, equivalent to the OSI Network layer.
Question 70: What is the purpose of configuring an 'exec-timeout' on Cisco VTY lines?
- Automatically disconnects idle management sessions after a specified time (Correct answer)
- Sets the maximum session login time
- Limits the number of concurrent VTY sessions
- Applies an inactivity ACL to VTY lines
Correct answer: Automatically disconnects idle management sessions after a specified time
'exec-timeout <minutes> <seconds>' closes inactive VTY sessions automatically, reducing the risk of unauthorized access to unattended sessions.
Question 71: Which protocol operates over TCP port 830 and is used for network device configuration?
- SNMP
- NETCONF (Correct answer)
- gRPC
- RESTCONF
Correct answer: NETCONF
NETCONF uses SSH (TCP port 830) as its transport protocol for secure device configuration.
Question 72: A company has a web server with the private IP address 10.1.1.100. The network administrator needs to make this server permanently accessible from the internet via the public IP address 209.165.200.225. Which type of NAT should be configured to achieve this one-to-one mapping?
- Static NAT (Correct answer)
- Policy-Based NAT
- Dynamic NAT
- PAT (NAT Overload)
Correct answer: Static NAT
Static NAT creates a persistent, one-to-one mapping between a private (local) IP address and a public (global) IP address. This is ideal for making internal resources like web servers consistently reachable from the outside network.
Question 73: Which ACL entry correctly blocks all traffic from the 10.0.0.0/8 network to a web server at 172.16.1.10?
- access-list 100 deny ip 10.0.0.0 0.0.0.255 host 172.16.1.10
- access-list 1 deny 10.0.0.0 0.255.255.255
- access-list 100 deny tcp 10.0.0.0 0.255.255.255 host 172.16.1.10 eq 80 (Correct answer)
- access-list 100 deny tcp 10.0.0.0 255.0.0.0 host 172.16.1.10 eq 80
Correct answer: access-list 100 deny tcp 10.0.0.0 0.255.255.255 host 172.16.1.10 eq 80
The /8 network requires wildcard 0.255.255.255; HTTP uses TCP port 80; 'host' keyword matches the single destination IP.
Question 74: Which WLAN deployment mode should be used when an AP needs to detect rogue devices and monitor RF activity without serving any clients?
- FlexConnect mode
- Sniffer mode
- Local mode
- Monitor mode (Correct answer)
Correct answer: Monitor mode
In monitor mode, the AP dedicates all its resources to scanning channels for rogues, interference, and security threats without providing client access.
Question 75: When port security detects a violation in 'protect' mode, what happens?
- An SNMP trap is sent and the port stays up
- The switch sends a syslog message and drops one frame
- Frames from violating MACs are dropped but no notification is sent (Correct answer)
- The port shuts down (err-disabled)
Correct answer: Frames from violating MACs are dropped but no notification is sent
In protect mode, frames from unauthorized MAC addresses are silently dropped without generating any log messages or SNMP traps.
Question 76: Rapid Spanning Tree Protocol (RSTP, 802.1w) improves convergence over the original 802.1D standard by modifying port states. Which three 802.1D port states are consolidated into the single 'Discarding' state in RSTP?
- Disabled, Blocking, and Listening (Correct answer)
- Listening, Learning, and Forwarding
- Blocking, Learning, and Forwarding
- Disabled, Listening, and Learning
Correct answer: Disabled, Blocking, and Listening
RSTP streamlines the port state machine for faster convergence. The 802.1D states of Disabled, Blocking, and Listening are functionally combined into a single state in RSTP called Discarding. In this state, the port does not forward user frames or learn MAC addresses.
Question 77: A router has the following routes in its routing table: S 192.168.32.0/26 [1/0] via 10.1.1.2 O 192.168.32.0/24 [110/2] via 10.1.1.6 R 192.168.0.0/16 [120/4] via 10.1.1.10 How will the router forward a packet destined for the IP address 192.168.32.63?
- It will use the OSPF route because it is a dynamic protocol.
- It will load balance across the static and OSPF routes.
- It will use the static route because it has the longest prefix match. (Correct answer)
- It will use the RIP route because it covers the largest address range.
Correct answer: It will use the static route because it has the longest prefix match.
The router's first criterion for selecting a path is the longest prefix match. The destination IP 192.168.32.63 falls within the range of all three routes. However, the /26 static route is the most specific (longest match) for this destination. Therefore, it will be chosen over the /24 and /16 routes, regardless of administrative distance or metric.
Question 78: Which command verifies the STP role and state of all ports on a Cisco switch for VLAN 10?
- show vlan brief
- show spanning-tree detail
- show spanning-tree vlan 10 (Correct answer)
- show interface trunk
Correct answer: show spanning-tree vlan 10
The 'show spanning-tree vlan 10' command displays the root bridge, bridge priority, port roles, port states, and costs for VLAN 10.
Question 79: A network engineer configures a WLC to use local mode for APs in the headquarters building. What is a key characteristic of local mode?
- Client traffic bypasses the WLC and goes directly to the router
- All client data is tunneled through CAPWAP to the WLC for centralized switching (Correct answer)
- APs operate autonomously without any WLC dependency
- Client traffic is switched locally at the AP without reaching the WLC
Correct answer: All client data is tunneled through CAPWAP to the WLC for centralized switching
In local mode, all client data frames are encapsulated in CAPWAP tunnels and sent to the WLC, which then forwards them to the appropriate network.
Question 80: Which command configures a Cisco router as a DHCP server and excludes the first 10 addresses of the 192.168.1.0/24 pool?
- ip dhcp excluded-address 192.168.1.1 192.168.1.10 (Correct answer)
- ip dhcp no-assign 192.168.1.1 192.168.1.10
- no ip dhcp address 192.168.1.1 192.168.1.10
- ip dhcp pool exclude 192.168.1.1 192.168.1.10
Correct answer: ip dhcp excluded-address 192.168.1.1 192.168.1.10
The 'ip dhcp excluded-address' command prevents specified IP addresses from being assigned by the DHCP server.
Question 81: Which command verifies the current NTP synchronization status and stratum on a Cisco IOS device?
- show ntp status (Correct answer)
- show ntp associations
- debug ntp events
- show clock detail
Correct answer: show ntp status
'show ntp status' displays whether the clock is synchronized, the reference server, stratum level, and clock offset.
Question 82: A Cisco switch port is configured with 'spanning-tree portfast'. What is the effect?
- The port is excluded from STP entirely and loops can form
- The port immediately transitions to Forwarding state, bypassing Listening and Learning (Correct answer)
- The port blocks all multicast traffic
- The port speed is increased to forward faster
Correct answer: The port immediately transitions to Forwarding state, bypassing Listening and Learning
PortFast causes a port to skip the STP Listening and Learning states and immediately enter Forwarding, reducing connection time for end devices.
Question 83: An access port is assigned to a VLAN that does not exist in the switch's VLAN database. What is the result?
- The port floods traffic to all VLANs
- The port is placed in an inactive state (Correct answer)
- The port operates in VLAN 1 instead
- The switch automatically creates the VLAN
Correct answer: The port is placed in an inactive state
If a port is assigned to a non-existent VLAN, it becomes inactive and does not pass traffic until the VLAN is created.
Question 84: What are the two main types of site-to-site VPNs?
- Intranet Based VPN (Correct answer)
- Excluded Based VPN
- Extranet Based VPN (Correct answer)
- Internet Based VPN
- Included Based VPN
Correct answer: Intranet Based VPN
Site-to-site VPNs connect entire networks, rather than individual hosts, over a public network. Intranet-based VPNs connect different sites belonging to the *same* organization, allowing secure access to internal resources. Extranet-based VPNs connect different sites of *different* organizations, such as business partners or suppliers, enabling secure collaboration between them.
Question 85: Which wildcard mask matches the entire subnet 172.16.0.0/16?
- 255.255.0.0
- 0.0.255.255 (Correct answer)
- 0.0.0.255
- 255.0.0.0
Correct answer: 0.0.255.255
A /16 prefix means 16 bits are fixed, so the wildcard mask is 0.0.255.255, allowing the last 16 bits to vary.
Question 86: Which command enables OSPF on a router with process ID 1?
- ip ospf 1
- enable ospf process 1
- router ospf 1 (Correct answer)
- router ospf enable 1
Correct answer: router ospf 1
The 'router ospf 1' command enters OSPF router configuration mode with process ID 1.
Question 87: Which protocol does a DHCP client use to initially discover a DHCP server on the network?
- DHCP Discover (broadcast) (Correct answer)
- DHCP Inform (multicast)
- DHCP Offer (unicast)
- DHCP Request (unicast)
Correct answer: DHCP Discover (broadcast)
A DHCP client sends a DHCP Discover message as a broadcast to find available DHCP servers on the local network.
Question 88: Which Ansible component describes the desired state of managed devices?
- Inventory
- Playbook (Correct answer)
- Module
- Role
Correct answer: Playbook
An Ansible playbook is a YAML file that defines the desired configuration state for managed hosts.
Question 89: Which command clears all dynamic NAT translations from the translation table?
- flush ip nat translations
- clear ip nat statistics
- clear ip nat translation * (Correct answer)
- no ip nat translation
Correct answer: clear ip nat translation *
'clear ip nat translation *' removes all dynamic NAT entries; static translations must be removed by deleting their configuration.
Question 90: What does the 'ip helper-address' command accomplish on a Cisco router interface?
- Assigns a static IP address to a DHCP client
- Enables DHCP snooping on the interface
- Forwards UDP broadcasts (including DHCP) to a specified server IP (Correct answer)
- Creates a DHCP pool on the router
Correct answer: Forwards UDP broadcasts (including DHCP) to a specified server IP
The 'ip helper-address' command relays UDP broadcast packets (including DHCP) from clients to a unicast server address on another subnet.
Question 91: Which STP port state learns MAC addresses but does NOT forward data frames?
- Blocking
- Forwarding
- Listening
- Learning (Correct answer)
Correct answer: Learning
The Learning state populates the MAC address table but does not forward user data frames, reducing flooding when the port transitions to Forwarding.
Question 92: A network administrator wants to restrict Telnet and SSH access to a router's virtual terminal (VTY) lines, allowing access only from the management workstation with the IP address 10.0.0.99. Which set of commands correctly accomplishes this?
- router(config)# access-list 1 permit any router(config)# line vty 0 15 router(config-line)# access-class 10.0.0.99 in
- router(config)# access-list 101 permit ip host 10.0.0.99 any router(config)# line vty 0 15 router(config-line)# ip access-group 101 in
- router(config)# access-list 1 permit host 10.0.0.99 router(config)# interface vty 0 15 router(config-if)# ip access-group 1 in
- router(config)# access-list 1 permit host 10.0.0.99 router(config)# line vty 0 15 router(config-line)# access-class 1 in (Correct answer)
Correct answer: router(config)# access-list 1 permit host 10.0.0.99 router(config)# line vty 0 15 router(config-line)# access-class 1 in
To apply an access control list to VTY lines to filter management access (like Telnet or SSH), the `access-class` command must be used under `line vty` configuration mode. The `ip access-group` command is used for applying ACLs to physical or logical Layer 3 interfaces, not VTY lines.
Question 93: Which OSPF timer must match between two routers for them to become neighbors?
- SPF delay timer
- LSA refresh timer
- Dead interval (Correct answer)
- LSA retransmit interval
Correct answer: Dead interval
Both the Hello interval and Dead interval must match between OSPF neighbors; mismatched Dead intervals prevent adjacency formation.
Question 94: Which IP SLA probe type can measure round-trip time (RTT) to a remote Cisco device using ICMP echo?
- udp-jitter
- http
- tcp-connect
- icmp-echo (Correct answer)
Correct answer: icmp-echo
IP SLA icmp-echo probes send ICMP echo requests to a target IP and measure round-trip time for availability monitoring.
Question 95: Which attack does DHCP snooping protect against on a switched network?
- MAC flooding attacks
- VLAN hopping attacks
- Rogue DHCP server attacks (Correct answer)
- ARP spoofing attacks
Correct answer: Rogue DHCP server attacks
DHCP snooping prevents rogue DHCP servers by only forwarding DHCP offers from trusted (uplink) ports, blocking unauthorized IP assignments.
Question 96: Which EIGRP packet type is used to acknowledge EIGRP updates and ensure reliable delivery?
- Reply
- Query
- Acknowledgment (Correct answer)
- Hello
Correct answer: Acknowledgment
EIGRP uses explicit Acknowledgment packets to confirm receipt of reliable packets like Updates, Queries, and Replies.
Question 97: Which of the following correctly maps OSI layers to their corresponding TCP/IP model layers?
- OSI Transport = TCP/IP Internet
- OSI Application = TCP/IP Transport
- OSI Network = TCP/IP Transport
- OSI Data Link + Physical = TCP/IP Network Access (Correct answer)
Correct answer: OSI Data Link + Physical = TCP/IP Network Access
The TCP/IP Network Access layer combines both the OSI Physical (Layer 1) and Data Link (Layer 2) layers into a single layer.
Question 98: Which command on a Cisco switch sends Syslog messages to a remote server at 10.1.1.100?
- logging host 10.1.1.100 (Correct answer)
- logging 10.1.1.100 remote
- ip syslog 10.1.1.100
- syslog server 10.1.1.100
Correct answer: logging host 10.1.1.100
The global configuration command 'logging host <ip>' directs Syslog output to the specified remote Syslog server.
Question 99: A router receives packets for destination 192.168.100.50. The routing table has entries for 192.168.100.0/24, 192.168.0.0/16, and 0.0.0.0/0. Which route is selected?
- 192.168.0.0/16 because it is the second most specific match
- The router load-balances across all three matching routes
- 0.0.0.0/0 because it matches all destinations
- 192.168.100.0/24 because longest prefix match is used (Correct answer)
Correct answer: 192.168.100.0/24 because longest prefix match is used
Cisco routers use longest prefix match, so 192.168.100.0/24 with a /24 prefix is more specific than /16 or /0 and is selected.
Question 100: What type of address does the OSI Network layer use to deliver packets between networks?
- Port number
- MAC address
- Physical address
- Logical (IP) address (Correct answer)
Correct answer: Logical (IP) address
The Network layer (Layer 3) uses logical IP addresses to identify source and destination hosts across different networks.
Cisco CCNA 200-301 Exam
The Cisco Certified Network Associate (CCNA 200-301) exam validates the ability to install, configure, operate, and troubleshoot medium-sized routed and switched networks, covering network fundamentals, access, IP connectivity, services, security, and automation.
Exam Rules
- You can skip questions and return to them later
- Flag questions for review before submitting
- No feedback shown until you submit the entire exam
- Unanswered questions count as wrong — answer everything
- 10 pretest questions are mixed in and don't affect your score
- Timer auto-submits when time runs out
- Your progress is auto-saved every 30 seconds