Sitonce
Country: US
Show exams for United States Hong Kong
Sign in

CCNA Practice Questions with Explanations

Updated 8 min read
Key takeaway

These original CCNA practice questions illustrate current v1.1 concepts in addressing, switching, routing, services, ACLs, wireless, and automation.

  • Each answer explains the reasoning and why distractors fail.
  • They are study examples, not copied from Cisco's exam and not evidence of the exact live item count or interface.
On this page10 sections
  1. Question 1: IPv4 subnet and gateway
  2. Question 2: trunk allowed list
  3. Question 3: longest-prefix match
  4. Question 4: OSPF neighbor does not form
  5. Question 5: DHCP address missing
  6. Question 6: ACL rule order
  7. Question 7: secure remote management
  8. Question 8: NTP and logs
  9. Question 9: interpret a simple automation payload
  10. How to learn from each explanation

Work each item before reading its answer. State the constraint, calculate or trace the network behavior, then compare the choices. These original examples align to current Cisco topic areas but are not Cisco exam questions. The current exam page does not publish a fixed question count or confirm a universal live simulation format.

Question 1: IPv4 subnet and gateway

A workstation is configured as 10.24.8.70/26 with gateway 10.24.8.1. The host can communicate with another device in its local segment but cannot reach any remote subnet. Which setting is the most likely problem?

  • A. The gateway is outside the workstation's subnet.
  • B. The workstation uses a private IPv4 address.
  • C. The prefix length must be /16 for all LANs.
  • D. The workstation's address is a network address.

Answer: A. A /26 mask divides the last octet into blocks of 64. Address 10.24.8.70 belongs to the 10.24.8.64/26 subnet, whose usable host range is .65 through .126. Gateway .1 is in the .0/26 subnet and is not locally reachable from this host. A private address can route internally; /16 is not required; .70 is not the network address.

Question 2: trunk allowed list

Two switches have an operational 802.1Q trunk. Hosts in VLAN 20 on the first switch cannot reach hosts in VLAN 20 on the second, while VLAN 10 works. What should you inspect first?

  • A. Whether VLAN 20 exists and is allowed on the trunk at both ends.
  • B. Whether the IP default route points to a public DNS server.
  • C. Whether the router has a NAT overload statement.
  • D. Whether the access port is configured as a trunk on every host.

Answer: A. A trunk can be up while a particular VLAN is absent or excluded. Confirm VLAN 20 exists, the ports are correctly configured, and the trunk's allowed VLAN list carries it in both directions. DNS, NAT, and host-facing trunk configuration are not the first explanation for same-VLAN Layer 2 reachability between switches.

Question 3: longest-prefix match

A router has routes for 10.0.0.0/8, 10.20.0.0/16, and 0.0.0.0/0. A packet is destined for 10.20.4.9. Which route is selected if all three are otherwise usable?

  • A. 0.0.0.0/0
  • B. 10.0.0.0/8
  • C. 10.20.0.0/16
  • D. The route with the oldest configuration date

Answer: C. Longest-prefix match selects the most specific route that contains the destination. /16 contains more network bits than /8 or /0. The default route is used only when no more-specific usable match applies; configuration age is not the selection rule.

Question 4: OSPF neighbor does not form

Two directly connected routers should form an OSPF adjacency in a single area but remain neighbors in a down state. Which check is a sensible early step?

  • A. Verify that the interfaces are up, share the expected subnet and area, and have compatible OSPF settings.
  • B. Configure NAT on both routers.
  • C. Delete all static routes before checking the link.
  • D. Change the LAN's DNS server to the router ID.

Answer: A. OSPF needs working interfaces and compatible neighbor parameters. Confirm link state and addressing, then inspect area, timers, authentication, and relevant network configuration as appropriate. NAT does not establish adjacency, static routes are not automatically the cause, and a router ID is not a DNS server.

Question 5: DHCP address missing

A client receives a self-assigned address instead of the expected subnet address. Other clients in the same VLAN work. Which first investigation is most useful?

  • A. Inspect the client's access VLAN and link, then the DHCP exchange or relay path for that client.
  • B. Add a default route to the public internet on the workstation.
  • C. Disable spanning tree on every switch.
  • D. Replace DNS with an NTP server.

Answer: A. Since peers in the same VLAN work, check whether this port places the client in the correct VLAN, whether the link is active, and whether the DHCP request reaches the server or relay. A default route does not assign a lease. Disabling spanning tree can create a loop, and DNS or NTP does not solve DHCP addressing.

Question 6: ACL rule order

An interface ACL has an early rule denying all traffic from 192.168.40.0/24, followed by a later permit for one host in that subnet. The host is blocked. What is the best explanation?

  • A. The earlier matching deny is evaluated before the later permit.
  • B. ACLs always evaluate permit rules first.
  • C. The host needs a different DNS server.
  • D. ACLs cannot filter by source network.

Answer: A. Ordered ACL processing means the first matching entry controls the packet. A broad deny before a narrower permit prevents the later exception from being reached. Reorder or refine the rules deliberately, preserve any implicit deny behavior, and test both permitted and blocked traffic.

Question 7: secure remote management

An administrator must manage a switch remotely over an untrusted network. Which protocol is the appropriate choice among these options?

  • A. Telnet
  • B. SSH
  • C. TFTP
  • D. HTTP without transport protection

Answer: B. SSH protects the remote management session in transit and is the expected secure alternative to Telnet. TFTP transfers files and does not provide an encrypted interactive management session. Unprotected HTTP and Telnet expose credentials or session content.

Question 8: NTP and logs

A network team receives syslog messages from several routers but cannot correlate event order because device clocks differ significantly. Which service should be configured consistently?

  • A. NTP
  • B. NAT
  • C. DHCP snooping
  • D. LACP

Answer: A. NTP synchronizes clocks so timestamps are more useful for event correlation. NAT translates addresses, DHCP snooping protects DHCP behavior, and LACP negotiates EtherChannel links. Centralized logs are more actionable when devices use a consistent time source.

Question 9: interpret a simple automation payload

An API response contains {"interface":"GigabitEthernet0/1","enabled":false}. What does the value false most directly indicate?

  • A. The interface is enabled but has no IPv4 address.
  • B. The structured data reports the enabled field as false.
  • C. The API request was encrypted with JSON.
  • D. The value represents a subnet mask.

Answer: B. In JSON, false is a Boolean value for the enabled key. It does not by itself say why the interface is disabled, and it is not a mask or encryption method. Read the field name and value, then use the API documentation to determine the object's full semantics.

How to learn from each explanation

For every question, name the fact or calculation that controls the answer. For the subnet item, sketch the /26 block boundary. For the VLAN problem, trace the frame over the trunk. For routing, compare prefix lengths. For ACLs, follow ordered evaluation. This makes knowledge portable to a new diagram instead of tied to an answer letter.

Also explain why the distractors are wrong. Many weak practice resources explain only the correct choice, leaving a candidate unable to recognize a nearly correct but unsafe alternative. For a real review, write one sentence for each excluded option. If the question depends on a command or feature not found in the current outline, verify whether it is in scope before memorizing it.

Do not treat the mock percentage as an official Cisco score. Cisco reports pass or fail and does not publish a fixed passing cutoff. The questions here are original illustrations for study, not a sample of the secure item pool. Build broad skill through fresh examples, configured topologies, and clear explanations.

When reviewing the answer to a subnet question, verify the arithmetic with an independent method. Convert the mask to a block size or count host bits, identify the boundary, and check the next range. For a route question, list all matching prefixes before deciding which wins. For an ACL question, move from the first entry downward. These routines make explanations auditable and help catch a practice answer key error.

When reviewing a subnet answer, verify the arithmetic independently. Convert the mask to a block size or count host bits, identify the boundary, and check the next range. For routing, list all matching prefixes before deciding which wins. For an ACL, move from the first entry down. These routines make explanations auditable and help catch an answer-key error.

Alter one condition and solve the scenario again. Change /26 to /27, remove one VLAN from a trunk, add a more-specific static route, or move an ACL entry earlier. This tests whether you learned the rule or remembered the answer. Keep the scenarios original and avoid any purported live exam wording.

Common questions

Are these real CCNA exam questions?

No. They are original scenarios and do not reproduce protected exam content.

Can these answers predict my pass result?

No. Cisco does not publish a fixed passing cutoff; use them to learn and diagnose concepts.

Should I memorize the answer letters?

No. Explain the networking behavior and practice it in a different example.