Sign In
Home/MikroTik/MikroTik Certified Network Associate/Free questions

MikroTik Certified Network Associate — Free Practice Questions

10 free sample questions from a bank of 123, with the correct answers and explanations. No signup required — start practising right now.

1What does this simple queue do (check the image)?The screenshot shows a Simple Queue named "host_A" with:Target Address: 192.168.1.10Target Upload: CheckedTarget Download: CheckedMax Limit: 1M (upload), unlimited (download)
  • Queue guarantees upload data rate of one megabit per second for host 192.168.1.10
  • Queue limits host 192.168.1.10 download data rate to one megabit per second.
  • Queue limits host 192.168.1.10 upload data rate to one megabit per second.
  • Queue guarantees download data rate of one megabit per second for host 192.168.1.10
Answer: C

The short version

C — Max Limit is a ceiling on upload. The queue caps host 192.168.1.10 upload at 1 Mbps; download is unlimited, so nothing about download is limited or guaranteed.

Key concepts in this question

  • Simple Queue Max Limit: a ceiling (caps throughput), not a reservation.
  • Limit At: the guaranteed floor ( CIR ); absent here, so nothing is guaranteed.
  • Target Upload / Download direction: the cap applies per direction that is checked.

Why C is correct

Target Upload is checked with Max Limit 1M on upload while download is unlimited, so the only effect is capping the host upload rate at one megabit per second.

Why the others are wrong

  • A. Guarantees come from Limit At, not Max Limit; this queue reserves nothing.
  • B. Download is explicitly unlimited, so download is not limited.
  • D. Same error as A plus the wrong direction: download has no cap at all.

MTCNA exam tip

Max-limit = ceiling, limit-at = guaranteed floor. If the question says guarantee, look for limit-at.

2What is the meaning of letter "R" on an active session in the menu PPP Active Connections?
  • Radius
  • Running
  • Remote
Answer: B

The short version

B — R means the session is Running. It is the standard RouterOS status flag for an active, up PPP session.

Key concepts in this question

  • PPP Active Connections flags: single-letter status markers (R = running).
  • RADIUS vs flag letters: RADIUS authentication is a service, not a session flag.
  • Running state: the session is established and passing traffic.

Why B is correct

In the PPP Active Connections table RouterOS marks an established session with R for Running, exactly as interfaces show R for running.

Why the others are wrong

  • A. Radius is an authentication backend configured under PPP AAA, not a session status letter.
  • C. Remote is not a defined flag in this table; the peer side is shown by address/name columns, not by R.

MTCNA exam tip

Read RouterOS flags literally: R = running, D = dynamic, X = disabled. They repeat across menus.

3Which of these are possible solutions to bridge two networks over a wireless link:
  • Both devices in AP mode and enable WDS mode
  • One device in AP mode, another one in station-pseudobridge-clone
  • One device in AP mode, another one in station-pseudobridge
  • One device in AP mode, another one in station
Answer: A, B, C

The short version

A, B and C — bridging needs WDS or MAC translation. AP-to-AP WDS links bridge, and pseudobridge modes bridge to any vendor AP; a plain station cannot be bridged.

Key concepts in this question

  • WDS: transparent L2 link between APs (same vendor/WDS support needed).
  • station-pseudobridge(-clone): MAC address translation that lets a station sit in a bridge facing any standard AP.
  • Plain station mode: 802.11 three-address frames lose the bridged MAC, so bridging fails.

Why A, B and C are correct

  • A. Two APs with WDS form a transparent bridge link between the networks.
  • B. station-pseudobridge-clone translates MACs so the bridged Ethernet works against an AP-mode peer.
  • C. station-pseudobridge does the same MAC translation against any standard AP.

Why the others are wrong

  • D. A plain station cannot be a bridge port: without WDS four-address frames or pseudobridge translation, bridged source MACs are lost over the air.

MTCNA exam tip

Bridge worksheet: MikroTik-to-MikroTik AP links use WDS or station-bridge; any-vendor AP plus bridge need means pseudobridge.

4In RouterOS queue configurations the word “total” usually represents:
  • download
  • upload + download
  • download - upload
  • upload
Answer: B

The short version

B — total counts both directions. In RouterOS queue statistics total is the sum of upload plus download.

Key concepts in this question

  • Queue counters: per-direction upload/download byte and packet counts.
  • Total row: aggregate of both directions for quick sizing.
  • Rate vs counter: total applies to the counted bytes, not a separate shaper.

Why B is correct

RouterOS shows upload and download counters separately and total as their sum, so total represents upload plus download.

Why the others are wrong

  • A. Download alone is just one component of total.
  • C. Total is a sum, never a difference of the directions.
  • D. Upload alone is just one component of total.

MTCNA exam tip

When sizing a queue from graphs, read the total line as up plus down, then split per direction.

5Which statements are true regarding ICMP packets?ICMP guarantees datagram delivery.ICMP can provide hosts with information about network problems.ICMP is encapsulated within IP datagrams.ICMP is encapsulated within UDP datagrams.
  • 1 only
  • 2 and 3
  • 1 and 4
  • All of the above
Answer: B

The short version

B — statements 2 and 3 are true. ICMP reports network problems and rides inside IP datagrams; it guarantees nothing and never sits inside UDP.

Key concepts in this question

  • ICMP purpose: error reporting and diagnostics (unreachable, time exceeded, echo).
  • ICMP encapsulation: IP protocol 1, directly inside an IP datagram.
  • No delivery guarantees: ICMP is unreliable; reliability comes from TCP at L4.

Why B is correct

Statement 2 is true because hosts learn about network problems via ICMP messages, and statement 3 is true because ICMP is encapsulated within IP datagrams.

Why the others are wrong

  • A. Statement 1 is false: ICMP guarantees no delivery.
  • C. Statement 1 is false and statement 4 is false: ICMP is never encapsulated in UDP datagrams.
  • D. Statements 1 and 4 are false, so not all are true.

MTCNA exam tip

Encapsulation ladder: ICMP lives in IP; port numbers belong to TCP/UDP only.

6Netinstall can be used to
  • Keep configuration, but reset a lost admin password
  • Reinstall software without losing licence
  • Install different software version (upgrade or downgrade)
  • Install package for different hardware architecture
Answer: B, C

The short version

B and C — Netinstall rewrites RouterOS fresh. It reinstalls the OS (any version) while the hardware-bound license survives; it does not preserve configuration or cross hardware architectures.

Key concepts in this question

  • Netinstall purpose: bare reinstall and recovery over Ethernet boot.
  • License binding: the RouterOS license lives with the hardware/flash, so reinstalls keep it.
  • Config wipe: a Netinstall install starts clean; backups/exports are the preservation path.

Why B and C are correct

  • B. Reinstalling software does not consume or lose the license, which stays with the device.
  • C. You can point Netinstall at an older or newer package set to up- or downgrade.

Why the others are wrong

  • A. Netinstall does not keep the running configuration; resetting a lost password this way loses config (keep config via backup/export instead).
  • D. Packages are architecture-specific (MIPSBE, ARM, x86, etc.); Netinstall cannot install another architecture package.

MTCNA exam tip

Netinstall = recovery reinstall. Before it, make a backup (binary) and an export (readable script).

7Domain Name System (DNS) requests can use protocol/port:
  • UDP
  • TCP port 53
Answer: A, B

The short version

A and B — DNS uses UDP and TCP on port 53. UDP carries normal queries; TCP covers large replies and zone transfers.

Key concepts in this question

  • DNS over UDP/53: the default transport for standard queries.
  • DNS over TCP/53: fallback for truncated replies, DNSSEC payloads, and zone transfers.
  • Firewall consequence: blocking TCP/53 breaks large answers even when browsing seems fine.

Why A and B are correct

  • A. UDP is the primary DNS transport for queries and replies.
  • B. TCP port 53 is the documented fallback and transfer transport.

Why the others are wrong

This is a select-all-that-apply item with only two options, and both are true; neither transport can be excluded.

MTCNA exam tip

If DNS works for small names but fails for large records, check that TCP/53 is open too.

8Action=redirect can be used in NAT chain src-nat
  • true
  • false
Answer: B

The short version

B — false: redirect belongs to dstnat. The redirect action sends the connection to the router itself, which is a destination-NAT operation.

Key concepts in this question

  • srcnat chain: sees packets leaving; actions src-nat and masquerade.
  • dstnat chain: sees packets entering before routing; actions dst-nat and redirect.
  • redirect meaning: rewrite destination to the router (transparent proxy, hotspot).

Why B is correct

Redirect rewrites the destination address to the local router, so it is only valid in the dstnat chain; placing it in src-nat is invalid.

Why the others are wrong

  • A. True would mean src-nat accepts redirect, but RouterOS pairs redirect with dstnat only.

MTCNA exam tip

Chain-action pairs: srcnat with src-nat/masquerade, dstnat with dst-nat/redirect. Mismatches never commit.

9Which wireless mode allows you to connect to any standard AP (not only MikroTik) and to beable to bridge this wireless interface to an Ethernet?
  • station-pseudobridge
  • station
  • station-wds
  • bridge
Answer: A

The short version

A — station-pseudobridge bridges against any AP. Its MAC translation compensates for plain 802.11 frames, unlike modes that need MikroTik-to-MikroTik extensions.

Key concepts in this question

  • station-pseudobridge: MAC address translation so a station can be a bridge port facing any standard AP.
  • station: plain client, cannot be bridged (three-address 802.11 limitation).
  • station-wds / bridge: need WDS support on the AP side or are AP-side modes.

Why A is correct

station-pseudobridge performs the MAC translation locally on the station, so the AP can be any vendor standard AP while the wireless interface still bridges to Ethernet.

Why the others are wrong

  • B. A plain station cannot sit in a bridge; bridged MACs are lost over three-address frames.
  • C. station-wds needs the AP to support WDS, which a generic standard AP does not guarantee.
  • D. bridge is an AP-side mode, not a client mode for connecting to an AP.

MTCNA exam tip

Any-vendor AP plus bridge on your side spells pseudobridge; same-vendor links can use WDS or station-bridge.

10There are two wireless cards (wlan1 and wlan2) which are bridged together. On wlan1 card thereis a setting "Forwarding=no". Choose the correct answer(s):
  • Stations on wlan2 will be able to communicate with stations on wlan2
  • Stations on wlan2 will be able to communicate with stations on wlan1
  • Stations on wlan1 will be able to communicate with stations on wlan1
  • To prevent communication between wlan1 and wlan2 one cannot use Bridge Filters
  • Stations on wlan1 will be able to communicate with stations on wlan2
Answer: A, C

The short version

A and C — Forwarding=no isolates the wlan1 leg. Same-interface client traffic still passes locally, but nothing crosses between wlan1 and wlan2; bridge filters remain available.

Key concepts in this question

  • Forwarding on a wireless leg: controls passing traffic onward from that interface.
  • Same-interface vs cross-interface: local client-to-client traffic is unaffected by the cross-leg block.
  • Bridge Filters: the separate tool that can also control inter-port traffic.

Why A and C are correct

  • A. wlan2 is untouched, so its stations keep reaching each other.
  • C. wlan1 stations keep reaching each other locally; only forwarding onward is stopped.

Why the others are wrong

  • B. Cross-leg traffic from wlan2 toward wlan1 is exactly what Forwarding=no on wlan1 stops.
  • D. Bridge Filters can control traffic between bridge ports, so claiming they cannot is false.
  • E. Same as B in reverse: wlan1 stations cannot cross to wlan2 with forwarding off.

MTCNA exam tip

Forwarding gates one leg; bridge filter gates the bridge. Check which layer the question names.

Want the full bank of 123 questions for MikroTik Certified Network Associate? See all practice exams.