Sign In
Home/Cisco/Cisco Certified Network Associate (CCNA 200-301)/Free questions

Cisco Certified Network Associate (CCNA 200-301) — Free Practice Questions

10 free sample questions from a bank of 2323, with the correct answers and explanations. No signup required — start practising right now.

1Refer to the exhibit. Which type of route does R1 use to reach host 10.10.13.10/32?
Cisco Certified Network Associate (CCNA 200-301) question 1
  • default route
  • network route
  • host route
  • floating static route
Answer: B

The short version

B — R1 matches a /25 network route, not a host or default route. The routing table lists 10.10.13.0/25 via 10.10.10.1, and host 10.10.13.10 falls inside that prefix, so longest-prefix match selects it.

Key concepts in this question

  • Longest-prefix match: the router forwards using the most specific covering prefix.
  • Network vs host vs default route: a /25 is a network route; a host route is /32; 0.0.0.0/0 is the default.
  • Floating static route: a backup static route with a higher administrative distance.

Why B is correct

R1's table shows 10.10.13.0/25 [110/6576] via 10.10.10.1, an OSPF-learned network route covering .0 through .127. Address 10.10.13.10 lies in that range, so it is reached through this entry rather than the gateway of last resort. It is a network route because the prefix length (/25) covers a whole subnet, not a single host.

Why the others are wrong

  • A. The default (B* 0.0.0.0/0 via .18) is used only when no more specific entry matches; here one does.
  • C. A host route is a /32 for one exact address; no /32 for 10.10.13.10 appears in the table.
  • D. A floating static route is a manually configured backup with elevated distance; this entry is OSPF (code O, distance 110), not floating.

200-301 exam tip

Remember: most-specific match wins — a covering /25 beats the 0.0.0.0/0 default every time.

2Which command automatically generates an IPv6 address from a specified IPv6 prefix and MAC address of an interface?
  • ipv6 address dhcp
  • ipv6 address 2001:DB8:5:112::/64 eui-64
  • ipv6 address autoconfig
  • ipv6 address 2001:DB8:5:112::2/64 link-local
Answer: B

The short version

B — The eui-64 keyword builds the interface ID from the MAC address. Giving a prefix plus eui-64 lets IOS derive the 64-bit host portion from the interface MAC (modified EUI-64) automatically.

Key concepts in this question

  • Modified EUI-64: interface ID derived from the 48-bit MAC with FFFE inserted and the U/L bit flipped.
  • Static vs autoconfig vs DHCP: manual assignment, SLAAC from router advertisements, and stateful DHCPv6 are distinct mechanisms.
  • IOS syntax: the address plus prefix plus eui-64 is the standard static-with-derived-ID form.

Why B is correct

ipv6 address 2001:DB8:5:112::/64 eui-64 supplies the first 64 bits and instructs the router to compute the remaining 64 bits from the interface's burned-in MAC address. That is exactly the described behavior: one command combining an operator prefix with a MAC-derived host portion, producing a full /128 assignment on the interface.

Why the others are wrong

  • A. ipv6 address dhcp obtains the address from a stateful DHCPv6 server, not from the local MAC.
  • C. ipv6 address autoconfig uses SLAAC with the prefix learned from router advertisements, not a specified prefix.
  • D. This appends link-local to a global unicast address, which is invalid syntax and does not derive anything from the MAC.

200-301 exam tip

See eui-64 next to a /64 prefix and think: prefix from you, interface ID from the MAC.

3What is an appropriate use for private IPv4 addressing?
  • to allow hosts inside to communicate in both directions with hosts outside the organization
  • on internal hosts that stream data solely to external resources
  • on the public-facing interface of a firewall
  • on hosts that communicate only with other internal hosts
Answer: D

The short version

D — Private IPv4 space is for hosts that only need to talk internally. RFC 1918 addresses are not routable on the public internet, so their natural use is communication confined to the organization.

Key concepts in this question

  • RFC 1918 private ranges: 10.0.0.0/8, 172.16.0.0/12, 192.168.0.0/16, never routed globally.
  • NAT boundary: reaching the internet from private space requires translation to a public address.
  • Public-facing interfaces: need globally unique public addresses.

Why D is correct

Hosts that communicate only with other internal hosts never need global reachability, so unregistered private addresses serve them perfectly with no public-address consumption. No NAT or internet routing is involved, which is precisely what private space was reserved for.

Why the others are wrong

  • A. Two-way communication with outside hosts requires a public address (or NAT through one); private addresses alone cannot do it.
  • B. Hosts streaming solely to external resources need internet reachability, so they depend on public/NATed addresses, not pure private use.
  • C. A firewall's public-facing interface must carry a globally routable public address to peer with the internet.

200-301 exam tip

Private = internal-only; the moment traffic must cross the internet, think public address or NAT.

4To improve corporate security, an organization is planning to implement badge authentication to limit access to the data center. Which element of a security program is being deployed?
  • user awareness
  • user training
  • physical access control
  • vulnerability verification
Answer: C

The short version

C — Badge authentication is physical access control. It restricts who can physically enter the data center, which is a physical safeguard rather than training or assessment.

Key concepts in this question

  • Physical access control: badges, locks, guards, and cameras protecting facilities.
  • User awareness/training: administrative controls that change behavior, not doors.
  • Vulnerability verification: confirming a weakness exists, unrelated to entry control.

Why C is correct

Requiring a badge to enter the data center enforces a physical barrier: only authorized people can be present near the equipment. That is the textbook definition of a physical access control, one pillar of a security program alongside administrative and technical controls.

Why the others are wrong

  • A. User awareness covers campaigns and reminders about threats like phishing, not door entry.
  • B. User training means instruction and exercises for staff; issuing badges is enforcement, not education.
  • D. Vulnerability verification is re-checking or validating a finding from a scan or test, not gating a room.

200-301 exam tip

Badge, lock, guard, camera: if it gates a room, it is physical access control.

5What is the purpose of a southbound API in a controller-based networking architecture?
  • facilitates communication between the controller and the applications
  • allows application developers to interact with the network
  • integrates a controller with other automation and orchestration tools
  • facilitates communication between the controller and the networking hardware
Answer: D

The short version

D — Southbound APIs connect the controller to the networking hardware. That is their whole purpose.

Key concepts in this question

  • Southbound API: controller-to-device interface driving the data plane (OpenFlow, OpFlex, NETCONF/RESTCONF to devices).
  • Northbound contrast: controller-to-application interfaces for developers and orchestration.

Why D is correct

In controller-based networking the southbound API is the channel by which the controller programs and collects state from switches, routers and access points — the networking hardware. Every other option describes the northbound side.

Why the others are wrong

  • A. Controller-to-application communication is the definition of northbound.
  • B. Developer interaction with the network happens through northbound REST APIs.
  • C. Integration with automation/orchestration tooling consumes northbound interfaces.

200-301 exam tip

South sinks to hardware, north rises to apps.

6Which benefit does Cisco DNA Center provide over traditional campus management?
  • Cisco DNA Center automates HTTPS for secure web access, and traditional campus management uses HTTP.
  • Cisco DNA Center leverages SNMPv3 for encrypted management, and traditional campus management uses SNMPv2.
  • Cisco DNA Center leverages APIs, and traditional campus management requires manual data gathering.
  • Cisco DNA Center automates SSH access for encrypted entry, and SSH is absent from traditional campus management.
Answer: C

The short version

C — DNA Center's edge over legacy management is API-driven automation. A controller with programmatic APIs replaces the box-by-box manual gathering of traditional campus operations.

Key concepts in this question

  • Controller-based management: centralized policy and data collection through software APIs.
  • Traditional campus management: per-device CLI/SNMP polling with manual correlation.
  • APIs vs protocols: HTTPS, SNMPv3, and SSH exist in both worlds; programmability is the differentiator.

Why C is correct

Cisco DNA Center exposes the network through REST APIs and built-in automation workflows, so provisioning, inventory, and telemetry are gathered and pushed programmatically. Traditional management instead logs into devices individually and assembles data by hand, which is slower and error-prone at scale. That contrast is the real benefit.

Why the others are wrong

  • A. Both modern and legacy tools can use HTTPS; automating HTTPS is not DNA Center's defining advantage.
  • B. SNMPv3 encryption is available on traditional gear too; the management model, not the SNMP version, is the point.
  • D. SSH access exists in traditional management as well, so claiming it is absent there is false.

200-301 exam tip

DNA Center question? Look for the answer with APIs and automation, not a single protocol version.

7How does Chef configuration management enforce a required device configuration?
  • The Chef Infra Server uses its configured cookbook to push the required configuration to the remote device requesting updates.
  • The installed agent on the device connects to the Chef Infra Server and pulls its required configuration from the cookbook.
  • The Chef Infra Server uses its configured cookbook to alert each remote device when it is time for the device to pull a new configuration.
  • The installed agent on the device queries the Chef Infra Server and the server responds by pushing the configuration from the cookbook.
Answer: B

The short version

B — Chef uses a pull model: the node's agent fetches its cookbook from the server. The Chef Infra Client on each device periodically connects and converges toward the desired state.

Key concepts in this question

  • Pull vs push: Chef nodes pull policy; tools like classic Ansible push over SSH.
  • Cookbook: the versioned bundle of recipes and attributes defining desired state.
  • Chef Infra Server vs Client: the server stores policy; the agent enforces it locally.

Why B is correct

Each managed device runs a Chef agent that registers with the Infra Server, downloads its assigned cookbook, and applies it locally on its own schedule. Enforcement therefore originates from the node pulling configuration, which scales without the server opening connections to every device.

Why the others are wrong

  • A. The server does not push configs to requesting devices; the pull direction is the opposite.
  • C. The server does not merely send alerts telling devices to pull; the agent's scheduled run handles that.
  • D. The server responds with policy for the agent to apply; it does not push configuration onto the node itself.

200-301 exam tip

Chef = pull: the client calls home and cooks from the book it downloads.

8What is the PUT method within HTTP?
  • It replaces data at the destination.
  • It is a nonidempotent operation.
  • It is a read-only operation.
  • It displays a web site.
Answer: A

The short version

A — PUT writes (replaces) the resource at the target URI. It carries a full representation that the server stores at the destination, creating or overwriting it.

Key concepts in this question

  • PUT semantics: idempotent full replacement of the addressed resource.
  • Idempotency: repeating a PUT yields the same state, unlike POST.
  • GET vs PUT: GET reads and renders; PUT writes.

Why A is correct

Issuing PUT to a URI tells the server to store the enclosed entity exactly there, so the destination ends up holding the sent data whether or not anything existed before. Repeating the same PUT converges on the same result, which is why REST designs use it for updates and full replacements.

Why the others are wrong

  • B. PUT is the classic idempotent write; the nonidempotent creation operation is POST.
  • C. Read-only retrieval is GET (or HEAD), which never carries a replacement body.
  • D. Displaying a site in a browser is a GET fetch and render, not a PUT write.

200-301 exam tip

PUT = put it there: full replacement at the URI, safe to repeat.

9Which advantage does the network assurance capability of Cisco DNA Center provide over traditional campus management?
  • Cisco DNA Center leverages YANG and NETCONF to assess the status of fabric and nonfabric devices, and traditional campus management uses CLI exclusively.
  • Cisco DNA Center handles management tasks at the controller to reduce the load on infrastructure devices, and traditional campus management uses the data backbone.
  • Cisco DNA Center automatically compares security postures among network devices, and traditional campus management needs manual comparisons.
  • Cisco DNA Center correlates information from different management protocols to obtain insights, and traditional campus management requires manual analysis.
Answer: D

The short version

D — Assurance's advantage is correlating multi-source telemetry into insights. DNA Center fuses data from many protocols and analytics so operators get conclusions instead of raw logs to sift manually.

Key concepts in this question

  • Network assurance: continuous health, onboarding, and anomaly analysis from telemetry.
  • Correlation vs collection: gathering via one protocol is old; combining sources into insight is new.
  • Manual analysis: the legacy burden of stitching CLI/SNMP/syslog output by hand.

Why D is correct

DNA Center ingests SNMP, syslog, NetFlow, controller, and device-health feeds together and applies analytics to surface issues like onboarding failures or path problems. Traditional campus management leaves that stitching to the engineer with spreadsheets and per-tool views. Automated correlation producing actionable insight is therefore the stated advantage.

Why the others are wrong

  • A. Legacy tools also use more than CLI, and assurance is not defined as YANG/NETCONF-only fabric checks.
  • B. Management load distribution over a backbone misdescribes assurance; correlation, not offload, is the benefit.
  • C. Comparing security postures is a compliance activity, not the core assurance-vs-manual-analysis distinction.

200-301 exam tip

Hear assurance, think correlation: many feeds in, one insight out.

10Refer to the exhibit. In which structure does the word “warning” directly reside?
Cisco Certified Network Associate (CCNA 200-301) question 10
  • array
  • object
  • Boolean
  • string
Answer: A

The short version

A — The string "warning" sits inside the wheels array. In the exhibit it is one element of the bracketed list under myCar, making an array its direct container.

Key concepts in this question

  • JSON array: an ordered list in square brackets holding the values directly.
  • JSON object: a brace-enclosed set of key/value pairs; it is the grandparent here, not the parent.
  • Strings vs Booleans: quoted text and true/false literals are leaf values, not containers.

Why A is correct

The exhibit shows "wheels": ["good", "good", "pressureLow", "warning"], so "warning" is enclosed by [ ] as a list member. Its immediate structure is therefore the array; myCar and the outer document are objects one or more levels up.

Why the others are wrong

  • B. The object holds keys like name and wheels, but warning is nested one level deeper inside the list.
  • C. The Booleans here are gasLight: false/true; warning is quoted text, not a Boolean, and resides elsewhere.
  • D. "warning" is itself a string value, but the question asks which structure contains it, and that container is the array.

200-301 exam tip

Brackets hold it, braces own the key: value in [ ] means array.

Want the full bank of 2323 questions for Cisco Certified Network Associate (CCNA 200-301)? See all practice exams.