MikroTik Certified Network Associate — Free Practice Questions
10 free sample questions from a bank of 123, with the correct answers and explanations. No signup required — start practising right now.
1What does this simple queue do (check the image)?The screenshot shows a Simple Queue named "host_A" with:Target Address: 192.168.1.10Target Upload: CheckedTarget Download: CheckedMax Limit: 1M (upload), unlimited (download)
Queue guarantees upload data rate of one megabit per second for host 192.168.1.10
Queue limits host 192.168.1.10 download data rate to one megabit per second.
Queue limits host 192.168.1.10 upload data rate to one megabit per second.
Queue guarantees download data rate of one megabit per second for host 192.168.1.10
Answer: C
The short version
C — Max Limit is a ceiling on upload. The queue caps host 192.168.1.10 upload at 1 Mbps; download is unlimited, so nothing about download is limited or guaranteed.
Key concepts in this question
Simple Queue Max Limit: a ceiling (caps throughput), not a reservation.
Limit At: the guaranteed floor ( CIR ); absent here, so nothing is guaranteed.
Target Upload / Download direction: the cap applies per direction that is checked.
Why C is correct
Target Upload is checked with Max Limit 1M on upload while download is unlimited, so the only effect is capping the host upload rate at one megabit per second.
Why the others are wrong
A. Guarantees come from Limit At, not Max Limit; this queue reserves nothing.
B. Download is explicitly unlimited, so download is not limited.
D. Same error as A plus the wrong direction: download has no cap at all.
MTCNA exam tip
Max-limit = ceiling, limit-at = guaranteed floor. If the question says guarantee, look for limit-at.
2What is the meaning of letter "R" on an active session in the menu PPP Active Connections?
Radius
Running
Remote
Answer: B
The short version
B — R means the session is Running. It is the standard RouterOS status flag for an active, up PPP session.
Key concepts in this question
PPP Active Connections flags: single-letter status markers (R = running).
RADIUS vs flag letters: RADIUS authentication is a service, not a session flag.
Running state: the session is established and passing traffic.
Why B is correct
In the PPP Active Connections table RouterOS marks an established session with R for Running, exactly as interfaces show R for running.
Why the others are wrong
A. Radius is an authentication backend configured under PPP AAA, not a session status letter.
C. Remote is not a defined flag in this table; the peer side is shown by address/name columns, not by R.
MTCNA exam tip
Read RouterOS flags literally: R = running, D = dynamic, X = disabled. They repeat across menus.
3Which of these are possible solutions to bridge two networks over a wireless link:
Both devices in AP mode and enable WDS mode
One device in AP mode, another one in station-pseudobridge-clone
One device in AP mode, another one in station-pseudobridge
One device in AP mode, another one in station
Answer: A, B, C
The short version
A, B and C — bridging needs WDS or MAC translation. AP-to-AP WDS links bridge, and pseudobridge modes bridge to any vendor AP; a plain station cannot be bridged.
Key concepts in this question
WDS: transparent L2 link between APs (same vendor/WDS support needed).
station-pseudobridge(-clone): MAC address translation that lets a station sit in a bridge facing any standard AP.
Plain station mode: 802.11 three-address frames lose the bridged MAC, so bridging fails.
Why A, B and C are correct
A. Two APs with WDS form a transparent bridge link between the networks.
B. station-pseudobridge-clone translates MACs so the bridged Ethernet works against an AP-mode peer.
C. station-pseudobridge does the same MAC translation against any standard AP.
Why the others are wrong
D. A plain station cannot be a bridge port: without WDS four-address frames or pseudobridge translation, bridged source MACs are lost over the air.
MTCNA exam tip
Bridge worksheet: MikroTik-to-MikroTik AP links use WDS or station-bridge; any-vendor AP plus bridge need means pseudobridge.
4In RouterOS queue configurations the word “total” usually represents:
download
upload + download
download - upload
upload
Answer: B
The short version
B — total counts both directions. In RouterOS queue statistics total is the sum of upload plus download.
Key concepts in this question
Queue counters: per-direction upload/download byte and packet counts.
Total row: aggregate of both directions for quick sizing.
Rate vs counter: total applies to the counted bytes, not a separate shaper.
Why B is correct
RouterOS shows upload and download counters separately and total as their sum, so total represents upload plus download.
Why the others are wrong
A. Download alone is just one component of total.
C. Total is a sum, never a difference of the directions.
D. Upload alone is just one component of total.
MTCNA exam tip
When sizing a queue from graphs, read the total line as up plus down, then split per direction.
5Which statements are true regarding ICMP packets?ICMP guarantees datagram delivery.ICMP can provide hosts with information about network problems.ICMP is encapsulated within IP datagrams.ICMP is encapsulated within UDP datagrams.
1 only
2 and 3
1 and 4
All of the above
Answer: B
The short version
B — statements 2 and 3 are true. ICMP reports network problems and rides inside IP datagrams; it guarantees nothing and never sits inside UDP.
Key concepts in this question
ICMP purpose: error reporting and diagnostics (unreachable, time exceeded, echo).
ICMP encapsulation: IP protocol 1, directly inside an IP datagram.
No delivery guarantees: ICMP is unreliable; reliability comes from TCP at L4.
Why B is correct
Statement 2 is true because hosts learn about network problems via ICMP messages, and statement 3 is true because ICMP is encapsulated within IP datagrams.
Why the others are wrong
A. Statement 1 is false: ICMP guarantees no delivery.
C. Statement 1 is false and statement 4 is false: ICMP is never encapsulated in UDP datagrams.
D. Statements 1 and 4 are false, so not all are true.
MTCNA exam tip
Encapsulation ladder: ICMP lives in IP; port numbers belong to TCP/UDP only.
6Netinstall can be used to
Keep configuration, but reset a lost admin password
Reinstall software without losing licence
Install different software version (upgrade or downgrade)
Install package for different hardware architecture
Answer: B, C
The short version
B and C — Netinstall rewrites RouterOS fresh. It reinstalls the OS (any version) while the hardware-bound license survives; it does not preserve configuration or cross hardware architectures.
Key concepts in this question
Netinstall purpose: bare reinstall and recovery over Ethernet boot.
License binding: the RouterOS license lives with the hardware/flash, so reinstalls keep it.
Config wipe: a Netinstall install starts clean; backups/exports are the preservation path.
Why B and C are correct
B. Reinstalling software does not consume or lose the license, which stays with the device.
C. You can point Netinstall at an older or newer package set to up- or downgrade.
Why the others are wrong
A. Netinstall does not keep the running configuration; resetting a lost password this way loses config (keep config via backup/export instead).
D. Packages are architecture-specific (MIPSBE, ARM, x86, etc.); Netinstall cannot install another architecture package.
MTCNA exam tip
Netinstall = recovery reinstall. Before it, make a backup (binary) and an export (readable script).
7Domain Name System (DNS) requests can use protocol/port:
UDP
TCP port 53
Answer: A, B
The short version
A and B — DNS uses UDP and TCP on port 53. UDP carries normal queries; TCP covers large replies and zone transfers.
Key concepts in this question
DNS over UDP/53: the default transport for standard queries.
DNS over TCP/53: fallback for truncated replies, DNSSEC payloads, and zone transfers.
Firewall consequence: blocking TCP/53 breaks large answers even when browsing seems fine.
Why A and B are correct
A. UDP is the primary DNS transport for queries and replies.
B. TCP port 53 is the documented fallback and transfer transport.
Why the others are wrong
This is a select-all-that-apply item with only two options, and both are true; neither transport can be excluded.
MTCNA exam tip
If DNS works for small names but fails for large records, check that TCP/53 is open too.
8Action=redirect can be used in NAT chain src-nat
true
false
Answer: B
The short version
B — false: redirect belongs to dstnat. The redirect action sends the connection to the router itself, which is a destination-NAT operation.
Key concepts in this question
srcnat chain: sees packets leaving; actions src-nat and masquerade.
dstnat chain: sees packets entering before routing; actions dst-nat and redirect.
redirect meaning: rewrite destination to the router (transparent proxy, hotspot).
Why B is correct
Redirect rewrites the destination address to the local router, so it is only valid in the dstnat chain; placing it in src-nat is invalid.
Why the others are wrong
A. True would mean src-nat accepts redirect, but RouterOS pairs redirect with dstnat only.
MTCNA exam tip
Chain-action pairs: srcnat with src-nat/masquerade, dstnat with dst-nat/redirect. Mismatches never commit.
9Which wireless mode allows you to connect to any standard AP (not only MikroTik) and to beable to bridge this wireless interface to an Ethernet?
station-pseudobridge
station
station-wds
bridge
Answer: A
The short version
A — station-pseudobridge bridges against any AP. Its MAC translation compensates for plain 802.11 frames, unlike modes that need MikroTik-to-MikroTik extensions.
Key concepts in this question
station-pseudobridge: MAC address translation so a station can be a bridge port facing any standard AP.
station: plain client, cannot be bridged (three-address 802.11 limitation).
station-wds / bridge: need WDS support on the AP side or are AP-side modes.
Why A is correct
station-pseudobridge performs the MAC translation locally on the station, so the AP can be any vendor standard AP while the wireless interface still bridges to Ethernet.
Why the others are wrong
B. A plain station cannot sit in a bridge; bridged MACs are lost over three-address frames.
C. station-wds needs the AP to support WDS, which a generic standard AP does not guarantee.
D. bridge is an AP-side mode, not a client mode for connecting to an AP.
MTCNA exam tip
Any-vendor AP plus bridge on your side spells pseudobridge; same-vendor links can use WDS or station-bridge.
10There are two wireless cards (wlan1 and wlan2) which are bridged together. On wlan1 card thereis a setting "Forwarding=no". Choose the correct answer(s):
Stations on wlan2 will be able to communicate with stations on wlan2
Stations on wlan2 will be able to communicate with stations on wlan1
Stations on wlan1 will be able to communicate with stations on wlan1
To prevent communication between wlan1 and wlan2 one cannot use Bridge Filters
Stations on wlan1 will be able to communicate with stations on wlan2
Answer: A, C
The short version
A and C — Forwarding=no isolates the wlan1 leg. Same-interface client traffic still passes locally, but nothing crosses between wlan1 and wlan2; bridge filters remain available.
Key concepts in this question
Forwarding on a wireless leg: controls passing traffic onward from that interface.
Same-interface vs cross-interface: local client-to-client traffic is unaffected by the cross-leg block.
Bridge Filters: the separate tool that can also control inter-port traffic.
Why A and C are correct
A. wlan2 is untouched, so its stations keep reaching each other.
C. wlan1 stations keep reaching each other locally; only forwarding onward is stopped.
Why the others are wrong
B. Cross-leg traffic from wlan2 toward wlan1 is exactly what Forwarding=no on wlan1 stops.
D. Bridge Filters can control traffic between bridge ports, so claiming they cannot is false.
E. Same as B in reverse: wlan1 stations cannot cross to wlan2 with forwarding off.
MTCNA exam tip
Forwarding gates one leg; bridge filter gates the bridge. Check which layer the question names.