Skip to content

Cisco Certified Network Associate (CCNA) Practice Questions

Prepare for 200-301 with more than an answer.

548 questions in the full set23 sample questionsUpdated Mar 18, 2026

Unlock the full exam and previous versions

  • v1Standard 548 questions Current
  • 200-105Legacy Interconnecting Cisco Networking Devices Part 2 (ICND2) 257 questions Locked
  • 200-125Legacy Cisco Certified Network Associate (CCNA) 70 questions Locked
Exam fee
$300 USD
Level
Associate
Valid for
3 years
Domains covered on the exam 6
  1. Network Fundamentals20%
  2. Network Access20%
  3. IP Connectivity25%
  4. IP Services10%
  5. Security Fundamentals15%
  6. Automation and Programmability10%
  1. 1

    You network team is exploring the use of switch stacking.

    Which of the following statements is NOT true of switch stacking?

    Show answer details

    Correct answer: A

    In Cisco switch stacking, all switches in the stack have full access to the interconnect bandwidth through the stack ring architecture, not just the master switch. The stack operates as a single logical unit with distributed forwarding capabilities across all member switches. Each switch maintains full switching capacity and can process traffic independently while participating in the stack control plane managed by the master switch. The stack ring provides redundant high-speed connectivity between switches, ensuring traffic can flow efficiently between any ports in the stack. Only the master switch manages the stack configuration and provides the management IP address, but all switches share equal access to the stack interconnect bandwidth for optimal performance and load distribution.

  2. 2

    A network security policy requires that switch ports connected to end-user workstations dynamically learn the first MAC address connected and permit only that MAC address. If a different device is connected, the port should be shut down. Which set of commands correctly implements this policy on an interface?

    Show answer details

    Correct answer: C

    This combination of commands meets all policy requirements. maximum 1 limits the port to a single MAC address. mac-address sticky tells the switch to dynamically learn the first MAC address it sees and add it to the running configuration as a secure MAC. violation shutdown is the action taken when an unauthorized MAC address attempts to connect, placing the port in an err-disabled state (shutting it down).

  3. 3

    An organization is using a configuration management tool to automate the deployment of VLANs across hundreds of switches. The tool uses a declarative language to define the desired state of the network and is known for its agentless architecture, communicating with devices over SSH. Which tool is being described?

    Show answer details

    Correct answer: D

    Ansible is a popular configuration management tool that is well-known for its agentless architecture, meaning it does not require any special software to be installed on the managed devices. It communicates with network devices primarily over SSH. Ansible uses YAML for its playbooks, which is a declarative language used to define the desired state. Terraform is also declarative but is more focused on infrastructure provisioning (IaC) rather than configuration management. Python with Netmiko is imperative, not declarative.

  4. 4

    A network engineer is configuring a Cisco Wireless LAN Controller (WLC) for a corporate environment. The security policy requires that users authenticate using their Active Directory credentials before gaining network access. Which security setting should be configured for the WLAN?

    Show answer details

    Correct answer: B

    WPA2 with 802.1X provides enterprise-grade authentication. In this model, the access point (or WLC) acts as an authenticator, the user's device is the supplicant, and an external server (typically a RADIUS server like Cisco ISE or Microsoft NPS) acts as the authentication server. The RADIUS server can integrate with Active Directory to validate user credentials. WPA2 + PSK uses a single shared password for all users and does not support individual user authentication.

  5. 5

    In a Rapid PVST+ environment, a switch port is connected to an end device like a PC. If the port is configured with PortFast, what is its initial STP state when the link comes up?

    Show answer details

    Correct answer: D

    The purpose of PortFast is to bypass the normal STP states of Listening and Learning for access ports. When a link on a PortFast-enabled port comes up, it transitions immediately to the Forwarding state, reducing the time it takes for an end device to gain network connectivity. This avoids delays such as a PC failing to get a DHCP address because the port is still in a non-forwarding STP state.

  6. 6

    A network administrator needs to create a standard numbered access control list that permits all traffic from the 192.168.10.0/24 network. Which command syntax is correct?

    Show answer details

    Correct answer: B

    Standard numbered ACLs use numbers from 1-99. The command syntax requires a wildcard mask, not a subnet mask. A wildcard mask is the inverse of a subnet mask. For a /24 network (subnet mask 255.255.255.0), the corresponding wildcard mask is 0.0.0.255. Therefore, the correct command is access-list 10 permit 192.168.10.0 0.0.0.255.

  7. 7

    You are the network administrator for your company and have configured Cisco Discovery Protocol (CDP) in your network. You recently noticed that when devices send large numbers of CDP neighbor announcements, some devices are crashing. You decide to disable CDP on the router.

    Which command should you use to achieve the objective?

    Show answer details

    Correct answer: A

    The no cdp run command globally disables Cisco Discovery Protocol (CDP) on the entire router, providing complete protection against CDP-based denial-of-service attacks and information disclosure vulnerabilities. CDP operates at Layer 2 and broadcasts detailed device information including IOS version, platform type, and capabilities, which can be exploited by attackers. The other options use invalid commands - set cdp disable is not valid Cisco IOS syntax, no cdp enable attempts to disable a non-existent enable command, and no cdp advertise-v2 only disables CDP version 2 advertisements while leaving the protocol vulnerable. Complete CDP disabling with no cdp run is the recommended security practice in environments where device discovery is not required.

  8. 8

    Which is NOT a valid range for private IP addresses?

    Show answer details

    Correct answer: D

    The range 192.255.255.255-193.0.0.0 represents public Internet addresses, not private addresses as defined by RFC 1918. Private address ranges reserved for internal networks include 10.0.0.0/8 (Class A providing 16.7 million addresses), 172.16.0.0/12 (Class B providing 1 million addresses), and 192.168.0.0/16 (Class C providing 65,536 addresses). The specified range contains public addresses used for Internet routing and cannot be used for private networks without causing routing conflicts. Network Address Translation (NAT) is required to translate private addresses to public addresses for Internet communication, ensuring proper routing and avoiding address conflicts with global Internet addressing.

  9. 9

    Which of the following protocols allow the root switch location to be optimized per VLAN? (Choose all that apply.)

    Show answer details

    Correct answer: A, C

    Per-VLAN Spanning Tree Plus (PVST+) creates a separate spanning tree instance for each VLAN, allowing network administrators to optimize root bridge placement per VLAN for optimal traffic flow and load balancing. This Cisco proprietary enhancement enables different VLANs to use different paths through the network, preventing a single root bridge from becoming a bottleneck for all traffic. Standard STP and RSTP operate as single instances across all VLANs and cannot provide per-VLAN optimization, making them unsuitable for VLAN-specific root bridge placement in modern enterprise networks requiring load distribution and redundancy.

    Per-VLAN Rapid Spanning Tree (PVRST) combines the per-VLAN optimization of PVST+ with the rapid convergence of RSTP, creating separate spanning tree instances for each VLAN while achieving convergence in seconds rather than minutes. This allows root bridge optimization per VLAN for traffic engineering and load balancing while maintaining fast recovery from link failures. PVRST provides the best of both worlds - the flexibility of per-VLAN trees for traffic optimization and the speed of rapid convergence for network stability, making it ideal for modern enterprise networks with multiple VLANs requiring both performance and reliability.

  10. 10

    Which two fields are present in the output of the show ip interface brief command? (Choose two.)

    Show answer details

    Correct answer: C, D

    The show ip interface brief command displays the OK? field which indicates whether the interface configuration is valid and error-free. This field shows YES for properly configured interfaces or NO for interfaces with configuration issues such as invalid IP addresses, subnet mask conflicts, or duplicate address assignments. The OK? field provides immediate visibility into interface configuration health, helping network administrators quickly identify interfaces requiring attention during troubleshooting and network verification procedures.

    The Method field in show ip interface brief output indicates how the IP address was configured on each interface, displaying values like NVRAM (statically configured), DHCP (dynamically assigned), IPCP (PPP negotiated), or unset (not configured). This information helps network administrators understand the source of IP configuration for troubleshooting and documentation purposes. Other fields in the output include Interface (interface name), IP-Address (assigned IP), Status (physical status), and Protocol (data link protocol status), but YES?, Helper address, and Proxy ARP are not displayed in this specific command output.

  11. 11

    Which two modes are Cisco Internetwork Operating System (IOS) operating modes? (Choose two.)

    Show answer details

    Correct answer: B, D

    User EXEC mode is the initial command-line access level after logging into a Cisco router or switch, identified by the > prompt. This mode provides basic monitoring commands like show, ping, and telnet but restricts configuration changes for security. Users can view system status, interface statistics, and routing tables without modifying device configuration. Administrative commands requiring privileged access are blocked in User EXEC mode. The transition to privileged EXEC mode requires the enable command and potentially an enable password, providing role-based access control that prevents unauthorized configuration changes while allowing network monitoring and troubleshooting functions.

    Global configuration mode is accessed from privileged EXEC mode using the configure terminal command and is identified by the (config)# prompt. This mode enables administrators to make system-wide configuration changes affecting the entire device, including hostname, routing protocols, access control lists, and global interface parameters. Commands entered in global configuration mode are immediately active but not saved until the copy running-config startup-config command is executed. Sub-configuration modes like interface configuration, router configuration, and line configuration are accessed from global configuration mode. This hierarchical structure provides organized access to different device configuration aspects while maintaining security through privilege levels.

Create an account to continue.