Cisco CCNA (200-301) practice questions
254 free questions with answers and explanations.
- 51.An engineer captures traffic on an IPv6-enabled network and observes a packet destined for ff02::1. What is the purpose of this destination address?Network Fundamentals
- 52.A network engineer needs to enable OSPF on a router interface configured with IP address 192.168.20.65/26. Which command correctly includes this interface's subnet in OSPF area 0?IP Connectivity
- 53.A wireless network engineer is planning security for a new SOHO access point. The client wants a solution that resists offline dictionary attacks even if the pre-shared key is weak, without requiring a RADIUS server. Which technology should be enabled?Security Fundamentals
- 54.An engineer creates an Ansible inventory file named 'hosts.ini' with the following content: [switches] sw1 ansible_host=10.1.1.1 sw2 ansible_host=10.1.1.2 [routers] r1 ansible_host=10.1.1.10 What is the purpose of the group names '[switches]' and '[routers]' in this file?Automation and Programmability
- 55.An administrator is deploying a standard numbered ACL to block traffic from a specific host, 192.168.5.10, from reaching only one file server (172.16.30.100) on a different subnet, while allowing the host to reach every other destination normally. Where should this ACL be applied for best results?Security Fundamentals
- 56.A network architect is explaining SDN architecture to a junior engineer. She states that the controller communicates directly with switches and routers to push configuration and collect telemetry, effectively separating this function from application logic. Which plane does this controller-to-device communication represent?Automation and Programmability
- 57.An engineer configures a recursive static route on R1: 'ip route 192.168.10.0 255.255.255.0 172.16.1.1'. R1 also has a route to 172.16.1.0/24 reachable out interface GigabitEthernet0/0. When R1 receives a packet destined for 192.168.10.5, what must it do before forwarding the packet?IP Connectivity
- 58.A switch's running configuration shows the following access list applied inbound on interface GigabitEthernet0/1: access-list 110 deny tcp 192.168.5.0 0.0.0.255 any eq 23 access-list 110 permit ip any any A host at 192.168.5.10 attempts an SSH session (TCP port 22) to a remote server. What is the result?Security Fundamentals
- 59.A network engineer configures the following static route on R1: 'ip route 172.20.5.0 255.255.255.0 GigabitEthernet0/1'. R1's GigabitEthernet0/1 connects to a multi-access Ethernet segment shared with several other devices. What is a potential drawback of using an exit interface instead of a next-hop IP address in this configuration?IP Connectivity
- 60.R1 has two equal-cost OSPF paths to network 10.5.5.0/24, each with a total cost of 20, learned via GigabitEthernet0/0 and GigabitEthernet0/1. Both appear in the routing table with the same [110/20] metric. What is the default behavior of R1 regarding these two routes?IP Connectivity
- 61.A switch is under a DoS attack in which an attacker on an untrusted access port floods the network with DHCP DISCOVER messages, exhausting the DHCP server's lease pool. DHCP snooping is already enabled. Which additional configuration should the administrator apply to mitigate this specific attack while still allowing normal client DHCP requests?Security Fundamentals
- 62.A company wants each wireless employee to authenticate using their individual Active Directory username and password, with authentication centrally validated by a RADIUS server, rather than using one shared passphrase for the whole office. Which wireless security mode should be configured on the access points?Security Fundamentals
- 63.A company configures a remote-access VPN for telecommuters using an ASA. Security policy requires that when a VPN client is connected, all of the employee's internet-bound traffic (including personal web browsing) must be routed through the corporate network and inspected, rather than going directly to the internet from the client's local connection. Which VPN tunneling configuration enforces this requirement?Security Fundamentals
- 64.A switch is configured with 'spanning-tree vlan 20 priority 4096'. Assuming the extended system ID feature is enabled (the default on modern Catalyst switches), what bridge priority value will actually be advertised in this switch's BPDUs for VLAN 20?Network Access
- 65.An automation engineer runs the following Terraform commands in order while deploying cloud network resources: terraform init terraform plan terraform apply What is the purpose of the 'terraform plan' step?Automation and Programmability
- 66.A technician connects two new Catalyst switches with a single copper link and wants an 802.1Q trunk to form automatically using only default Dynamic Trunking Protocol (DTP) behavior, with no manual 'switchport mode trunk' command on either side. Which pair of switchport modes, one on each end, will successfully negotiate a trunk?Network Access
- 67.An engineer runs 'service password-encryption' on a router, then views the running configuration and sees 'password 7 0822455D0A16' under a VTY line. A colleague claims this fully protects the password from disclosure. Why is this claim incorrect?Security Fundamentals
- 68.An engineer is documenting IPv6 addresses used on an internal network that must be routable only within the organization and never forwarded to the internet, similar in purpose to RFC 1918 private addresses. Which address best fits this description?Network Fundamentals
- 69.A technician issues the command 'show ip route' on a branch router and sees the line: S* 0.0.0.0/0 [1/0] via 203.0.113.1. What does this entry represent?IP Connectivity
- 70.Which TCP port number is used by default for unencrypted web (HTTP) traffic?Network Fundamentals
- 71.R1 and R2 run HSRP for VLAN 10, with R1 configured with priority 120 and standby track on interface Serial0/0/0 with a decrement of 30. R2 is configured with priority 100 and no tracking. If R1's Serial0/0/0 interface fails, what is the result?IP Connectivity
- 72.A switch port running port security has entered the err-disabled state due to a security violation. The administrator wants the interface to automatically recover after 5 minutes without manual intervention. Which set of commands accomplishes this?Security Fundamentals
- 73.An engineer examines the IPv6 address 2001:DB8:ACAD:1::10/64 assigned to a server's interface. Which portion of this address represents the interface identifier (host portion)?Network Fundamentals
- 74.An engineer configures the same IPv6 address on multiple servers located in different data centers so that client traffic is automatically delivered to the nearest server based on routing metrics. Which type of IPv6 address is being used?Network Fundamentals
- 75.Which statement best describes the primary function of Dynamic ARP Inspection (DAI) on a switch?Security Fundamentals
- 76.A small business owner wants to upgrade wireless security from WPA2-Personal to WPA3-Personal because employees complain that a shared passphrase is vulnerable to offline dictionary attacks. Which feature of WPA3 directly addresses this concern?Security Fundamentals
- 77.A network engineer enables DHCP snooping on a switch. Clients on access ports stop receiving IP addresses from the legitimate DHCP server connected via the uplink trunk port. What is the most likely cause?Security Fundamentals
- 78.An engineer runs the same Ansible playbook against a switch twice in a row. Both times, the task 'Ensure VLAN 20 exists' produces the exact same end configuration on the device, and the second run reports zero changes made. What property of Ansible does this behavior demonstrate?Automation and Programmability
- 79.A branch office needs an always-on encrypted tunnel connecting its router permanently to headquarters, without requiring end-user client software. Which VPN type best fits this requirement?Security Fundamentals
- 80.A small office has two routers acting as redundant default gateways for the LAN using a First Hop Redundancy Protocol. What is the primary purpose of this configuration?IP Connectivity
- 81.A wireless engineer is designing a campus network using a centralized wireless architecture. A single WLC will manage dozens of lightweight APs across multiple buildings. Which statement correctly describes this architecture?Network Fundamentals
- 82.An administrator configures the following on interface FastEthernet0/3: switchport port-security switchport port-security maximum 3 switchport port-security mac-address sticky The port currently has one manually configured static MAC address and has already dynamically learned two more via sticky learning. A fourth unknown device now sends traffic on this port. Assuming the default violation mode, what occurs?Security Fundamentals
- 83.A company's primary path uses OSPF (AD 110). An administrator wants to configure a backup static default route that is only installed in the routing table if OSPF fails. Which command achieves this?IP Connectivity
- 84.An administrator is enabling Dynamic ARP Inspection on a switch. The uplink port connecting to the distribution switch must be allowed to relay ARP replies for many downstream hosts without inspection. Which command should be applied to that uplink interface?Security Fundamentals
- 85.On SW1, interfaces Gi0/1 and Gi0/2 are configured with 'channel-group 1 mode passive'. On SW2, the matching interfaces Gi0/1 and Gi0/2 are also configured with 'channel-group 1 mode passive'. What is the result?Network Access
- 86.An engineer configures an IPv6 static route on a router with a point-to-point serial interface: 'ipv6 route 2001:db8:200::/64 Serial0/0/1'. No next-hop address is specified. Why is this command valid?IP Connectivity
- 87.An ISP customer is assigned the 10.5.0.0/16 aggregate block and wants to advertise it as a single summarized static route toward the ISP, even though only a few /24 subnets within that range are actually in use. To prevent routing loops for the unused address space, the administrator adds: 'ip route 10.5.0.0 255.255.0.0 Null0'. What is the purpose of this command?IP Connectivity
- 88.A new employee's laptop can successfully ping other devices on its own subnet but cannot reach any hosts on other VLANs or the internet. Which configuration item is the MOST likely cause?Network Fundamentals
- 89.An engineer wants to configure a static IPv6 route to network 2001:db8:100::/64 out of interface GigabitEthernet0/1 using the next-hop link-local address fe80::2. Which command correctly implements this?IP Connectivity
- 90.A network administrator wants a switch to automatically learn MAC addresses on each access port via port security and retain them across a reload without manual re-entry. Which configuration accomplishes this?Security Fundamentals
- 91.A network designer is implementing Cisco SD-Access and explains the architecture to a colleague. She describes a component that carries encapsulated user traffic between edge nodes using VXLAN, logically separate from the physical topology used for basic IP reachability. Which term describes this VXLAN-based traffic-carrying layer?Automation and Programmability
- 92.A router has an access list applied inbound on an interface. The ACL contains only two explicit entries that both deny specific hosts. No other statements are configured. What happens to traffic from a host not matching either deny statement?Security Fundamentals
- 93.A security architect is designing a network segment that will host a public-facing web server. The server must be reachable from the internet but isolated from the internal corporate LAN. Which firewall design concept best fits this requirement?Network Fundamentals
- 94.A DevOps team wants to deploy multiple lightweight, isolated application instances on a single Linux server with minimal overhead and fast startup times, sharing the host's OS kernel. Which virtualization technology BEST fits this requirement?Network Fundamentals
- 95.A technician examines an OSPF-enabled Ethernet segment with four routers and notices that one router is configured with 'ip ospf priority 0' on its interface facing the segment. What effect does this have?IP Connectivity
- 96.A network administrator must assign an address block to a LAN segment that needs to support 50 hosts, using the smallest subnet possible. Which subnet mask should be used?Network Fundamentals
- 97.Two OSPF routers, R1 and R2, are connected via a serial link and remain stuck in the INIT state. R1 is configured with 'hello-interval 10' and 'dead-interval 40' (defaults), while R2 has been changed to 'hello-interval 5' and 'dead-interval 20'. What is the most likely cause of the adjacency failure?IP Connectivity
- 98.An administrator is assigning internal IP addresses to hosts in a private office network that will never be routed directly on the public internet. Which of the following address ranges is reserved by RFC 1918 for this purpose?Network Fundamentals
- 99.A company wants remote administrators authenticated against a central AAA server, but once authenticated, wants the AAA server to also determine which specific IOS commands each administrator is permitted to run. Which AAA function accomplishes the command-level restriction?Security Fundamentals
- 100.A switch has 24 hosts connected to 24 separate access ports, all assigned to the same VLAN. How many collision domains and broadcast domains exist on this switch?Network Fundamentals