Cisco Certified Network Associate (CCNA 200-301) — Free Practice Questions
10 free sample questions from a bank of 2323, with the correct answers and explanations. No signup required — start practising right now.
1Refer to the exhibit. Which type of route does R1 use to reach host 10.10.13.10/32?
default route
network route
host route
floating static route
Answer: B
The short version
B — R1 matches a /25 network route, not a host or default route. The routing table lists 10.10.13.0/25 via 10.10.10.1, and host 10.10.13.10 falls inside that prefix, so longest-prefix match selects it.
Key concepts in this question
Longest-prefix match: the router forwards using the most specific covering prefix.
Network vs host vs default route: a /25 is a network route; a host route is /32; 0.0.0.0/0 is the default.
Floating static route: a backup static route with a higher administrative distance.
Why B is correct
R1's table shows 10.10.13.0/25 [110/6576] via 10.10.10.1, an OSPF-learned network route covering .0 through .127. Address 10.10.13.10 lies in that range, so it is reached through this entry rather than the gateway of last resort. It is a network route because the prefix length (/25) covers a whole subnet, not a single host.
Why the others are wrong
A. The default (B* 0.0.0.0/0 via .18) is used only when no more specific entry matches; here one does.
C. A host route is a /32 for one exact address; no /32 for 10.10.13.10 appears in the table.
D. A floating static route is a manually configured backup with elevated distance; this entry is OSPF (code O, distance 110), not floating.
200-301 exam tip
Remember: most-specific match wins — a covering /25 beats the 0.0.0.0/0 default every time.
2Which command automatically generates an IPv6 address from a specified IPv6 prefix and MAC address of an interface?
ipv6 address dhcp
ipv6 address 2001:DB8:5:112::/64 eui-64
ipv6 address autoconfig
ipv6 address 2001:DB8:5:112::2/64 link-local
Answer: B
The short version
B — The eui-64 keyword builds the interface ID from the MAC address. Giving a prefix plus eui-64 lets IOS derive the 64-bit host portion from the interface MAC (modified EUI-64) automatically.
Key concepts in this question
Modified EUI-64: interface ID derived from the 48-bit MAC with FFFE inserted and the U/L bit flipped.
Static vs autoconfig vs DHCP: manual assignment, SLAAC from router advertisements, and stateful DHCPv6 are distinct mechanisms.
IOS syntax: the address plus prefix plus eui-64 is the standard static-with-derived-ID form.
Why B is correct
ipv6 address 2001:DB8:5:112::/64 eui-64 supplies the first 64 bits and instructs the router to compute the remaining 64 bits from the interface's burned-in MAC address. That is exactly the described behavior: one command combining an operator prefix with a MAC-derived host portion, producing a full /128 assignment on the interface.
Why the others are wrong
A.ipv6 address dhcp obtains the address from a stateful DHCPv6 server, not from the local MAC.
C.ipv6 address autoconfig uses SLAAC with the prefix learned from router advertisements, not a specified prefix.
D. This appends link-local to a global unicast address, which is invalid syntax and does not derive anything from the MAC.
200-301 exam tip
See eui-64 next to a /64 prefix and think: prefix from you, interface ID from the MAC.
3What is an appropriate use for private IPv4 addressing?
to allow hosts inside to communicate in both directions with hosts outside the organization
on internal hosts that stream data solely to external resources
on the public-facing interface of a firewall
on hosts that communicate only with other internal hosts
Answer: D
The short version
D — Private IPv4 space is for hosts that only need to talk internally. RFC 1918 addresses are not routable on the public internet, so their natural use is communication confined to the organization.
Key concepts in this question
RFC 1918 private ranges: 10.0.0.0/8, 172.16.0.0/12, 192.168.0.0/16, never routed globally.
NAT boundary: reaching the internet from private space requires translation to a public address.
Public-facing interfaces: need globally unique public addresses.
Why D is correct
Hosts that communicate only with other internal hosts never need global reachability, so unregistered private addresses serve them perfectly with no public-address consumption. No NAT or internet routing is involved, which is precisely what private space was reserved for.
Why the others are wrong
A. Two-way communication with outside hosts requires a public address (or NAT through one); private addresses alone cannot do it.
B. Hosts streaming solely to external resources need internet reachability, so they depend on public/NATed addresses, not pure private use.
C. A firewall's public-facing interface must carry a globally routable public address to peer with the internet.
200-301 exam tip
Private = internal-only; the moment traffic must cross the internet, think public address or NAT.
4To improve corporate security, an organization is planning to implement badge authentication to limit access to the data center. Which element of a security program is being deployed?
user awareness
user training
physical access control
vulnerability verification
Answer: C
The short version
C — Badge authentication is physical access control. It restricts who can physically enter the data center, which is a physical safeguard rather than training or assessment.
Key concepts in this question
Physical access control: badges, locks, guards, and cameras protecting facilities.
User awareness/training: administrative controls that change behavior, not doors.
Vulnerability verification: confirming a weakness exists, unrelated to entry control.
Why C is correct
Requiring a badge to enter the data center enforces a physical barrier: only authorized people can be present near the equipment. That is the textbook definition of a physical access control, one pillar of a security program alongside administrative and technical controls.
Why the others are wrong
A. User awareness covers campaigns and reminders about threats like phishing, not door entry.
B. User training means instruction and exercises for staff; issuing badges is enforcement, not education.
D. Vulnerability verification is re-checking or validating a finding from a scan or test, not gating a room.
200-301 exam tip
Badge, lock, guard, camera: if it gates a room, it is physical access control.
5What is the purpose of a southbound API in a controller-based networking architecture?
facilitates communication between the controller and the applications
allows application developers to interact with the network
integrates a controller with other automation and orchestration tools
facilitates communication between the controller and the networking hardware
Answer: D
The short version
D — Southbound APIs connect the controller to the networking hardware. That is their whole purpose.
Key concepts in this question
Southbound API: controller-to-device interface driving the data plane (OpenFlow, OpFlex, NETCONF/RESTCONF to devices).
Northbound contrast: controller-to-application interfaces for developers and orchestration.
Why D is correct
In controller-based networking the southbound API is the channel by which the controller programs and collects state from switches, routers and access points — the networking hardware. Every other option describes the northbound side.
Why the others are wrong
A. Controller-to-application communication is the definition of northbound.
B. Developer interaction with the network happens through northbound REST APIs.
C. Integration with automation/orchestration tooling consumes northbound interfaces.
200-301 exam tip
South sinks to hardware, north rises to apps.
6Which benefit does Cisco DNA Center provide over traditional campus management?
Cisco DNA Center automates HTTPS for secure web access, and traditional campus management uses HTTP.
Cisco DNA Center leverages SNMPv3 for encrypted management, and traditional campus management uses SNMPv2.
Cisco DNA Center leverages APIs, and traditional campus management requires manual data gathering.
Cisco DNA Center automates SSH access for encrypted entry, and SSH is absent from traditional campus management.
Answer: C
The short version
C — DNA Center's edge over legacy management is API-driven automation. A controller with programmatic APIs replaces the box-by-box manual gathering of traditional campus operations.
Key concepts in this question
Controller-based management: centralized policy and data collection through software APIs.
Traditional campus management: per-device CLI/SNMP polling with manual correlation.
APIs vs protocols: HTTPS, SNMPv3, and SSH exist in both worlds; programmability is the differentiator.
Why C is correct
Cisco DNA Center exposes the network through REST APIs and built-in automation workflows, so provisioning, inventory, and telemetry are gathered and pushed programmatically. Traditional management instead logs into devices individually and assembles data by hand, which is slower and error-prone at scale. That contrast is the real benefit.
Why the others are wrong
A. Both modern and legacy tools can use HTTPS; automating HTTPS is not DNA Center's defining advantage.
B. SNMPv3 encryption is available on traditional gear too; the management model, not the SNMP version, is the point.
D. SSH access exists in traditional management as well, so claiming it is absent there is false.
200-301 exam tip
DNA Center question? Look for the answer with APIs and automation, not a single protocol version.
7How does Chef configuration management enforce a required device configuration?
The Chef Infra Server uses its configured cookbook to push the required configuration to the remote device requesting updates.
The installed agent on the device connects to the Chef Infra Server and pulls its required configuration from the cookbook.
The Chef Infra Server uses its configured cookbook to alert each remote device when it is time for the device to pull a new configuration.
The installed agent on the device queries the Chef Infra Server and the server responds by pushing the configuration from the cookbook.
Answer: B
The short version
B — Chef uses a pull model: the node's agent fetches its cookbook from the server. The Chef Infra Client on each device periodically connects and converges toward the desired state.
Key concepts in this question
Pull vs push: Chef nodes pull policy; tools like classic Ansible push over SSH.
Cookbook: the versioned bundle of recipes and attributes defining desired state.
Chef Infra Server vs Client: the server stores policy; the agent enforces it locally.
Why B is correct
Each managed device runs a Chef agent that registers with the Infra Server, downloads its assigned cookbook, and applies it locally on its own schedule. Enforcement therefore originates from the node pulling configuration, which scales without the server opening connections to every device.
Why the others are wrong
A. The server does not push configs to requesting devices; the pull direction is the opposite.
C. The server does not merely send alerts telling devices to pull; the agent's scheduled run handles that.
D. The server responds with policy for the agent to apply; it does not push configuration onto the node itself.
200-301 exam tip
Chef = pull: the client calls home and cooks from the book it downloads.
8What is the PUT method within HTTP?
It replaces data at the destination.
It is a nonidempotent operation.
It is a read-only operation.
It displays a web site.
Answer: A
The short version
A — PUT writes (replaces) the resource at the target URI. It carries a full representation that the server stores at the destination, creating or overwriting it.
Key concepts in this question
PUT semantics: idempotent full replacement of the addressed resource.
Idempotency: repeating a PUT yields the same state, unlike POST.
GET vs PUT: GET reads and renders; PUT writes.
Why A is correct
Issuing PUT to a URI tells the server to store the enclosed entity exactly there, so the destination ends up holding the sent data whether or not anything existed before. Repeating the same PUT converges on the same result, which is why REST designs use it for updates and full replacements.
Why the others are wrong
B. PUT is the classic idempotent write; the nonidempotent creation operation is POST.
C. Read-only retrieval is GET (or HEAD), which never carries a replacement body.
D. Displaying a site in a browser is a GET fetch and render, not a PUT write.
200-301 exam tip
PUT = put it there: full replacement at the URI, safe to repeat.
9Which advantage does the network assurance capability of Cisco DNA Center provide over traditional campus management?
Cisco DNA Center leverages YANG and NETCONF to assess the status of fabric and nonfabric devices, and traditional campus management uses CLI exclusively.
Cisco DNA Center handles management tasks at the controller to reduce the load on infrastructure devices, and traditional campus management uses the data backbone.
Cisco DNA Center automatically compares security postures among network devices, and traditional campus management needs manual comparisons.
Cisco DNA Center correlates information from different management protocols to obtain insights, and traditional campus management requires manual analysis.
Answer: D
The short version
D — Assurance's advantage is correlating multi-source telemetry into insights. DNA Center fuses data from many protocols and analytics so operators get conclusions instead of raw logs to sift manually.
Key concepts in this question
Network assurance: continuous health, onboarding, and anomaly analysis from telemetry.
Correlation vs collection: gathering via one protocol is old; combining sources into insight is new.
Manual analysis: the legacy burden of stitching CLI/SNMP/syslog output by hand.
Why D is correct
DNA Center ingests SNMP, syslog, NetFlow, controller, and device-health feeds together and applies analytics to surface issues like onboarding failures or path problems. Traditional campus management leaves that stitching to the engineer with spreadsheets and per-tool views. Automated correlation producing actionable insight is therefore the stated advantage.
Why the others are wrong
A. Legacy tools also use more than CLI, and assurance is not defined as YANG/NETCONF-only fabric checks.
B. Management load distribution over a backbone misdescribes assurance; correlation, not offload, is the benefit.
C. Comparing security postures is a compliance activity, not the core assurance-vs-manual-analysis distinction.
200-301 exam tip
Hear assurance, think correlation: many feeds in, one insight out.
10Refer to the exhibit. In which structure does the word “warning” directly reside?
array
object
Boolean
string
Answer: A
The short version
A — The string "warning" sits inside the wheels array. In the exhibit it is one element of the bracketed list under myCar, making an array its direct container.
Key concepts in this question
JSON array: an ordered list in square brackets holding the values directly.
JSON object: a brace-enclosed set of key/value pairs; it is the grandparent here, not the parent.
Strings vs Booleans: quoted text and true/false literals are leaf values, not containers.
Why A is correct
The exhibit shows "wheels": ["good", "good", "pressureLow", "warning"], so "warning" is enclosed by [ ] as a list member. Its immediate structure is therefore the array; myCar and the outer document are objects one or more levels up.
Why the others are wrong
B. The object holds keys like name and wheels, but warning is nested one level deeper inside the list.
C. The Booleans here are gasLight: false/true; warning is quoted text, not a Boolean, and resides elsewhere.
D."warning" is itself a string value, but the question asks which structure contains it, and that container is the array.
200-301 exam tip
Brackets hold it, braces own the key: value in [ ] means array.