CCNA Network Services and Security Practice Question
A network engineer is configuring a Cisco IOS router that connects a small branch office to the Internet. The router's outside interface is GigabitEthernet0/0 with IP address 203.0.113.5/30, and the inside interface is GigabitEthernet0/1 with IP address 192.168.10.1/24. The branch has 50 internal hosts that need simultaneous outbound Internet access, but the ISP assigned only the single public address 203.0.113.5. The engineer wants to conserve public addresses and ensure that internal addresses are hidden. Which configuration should be applied on the router?
⚠ Common exam trap
The trap here is assuming any NAT pool configuration automatically supports many hosts, when a one-address pool without overload still permits only one simultaneous translation.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
ip nat inside source list 1 interface GigabitEthernet0/0 overload, with an access list permitting 192.168.10.0/24
The router must translate many inside private addresses to the single public address provided by the ISP. NAT overload, also called PAT, allows this by tracking source port numbers to distinguish sessions. Configuring ip nat inside source list with the outside interface and the overload keyword, plus an access list matching 192.168.10.0/24, meets the requirement and hides internal addressing.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
ip nat outside source list 1 interface GigabitEthernet0/1 overload, translating outside sources to the inside interface address
Why it's wrong here
This command translates outside source addresses to the inside interface, which is the reverse of what is needed for outbound Internet access. It also references the wrong interface for the inside global address. The correct direction is inside source translation to the outside interface.
- ✗
ip nat inside source list 1 pool PUBLIC_POOL, with a pool containing 203.0.113.5 and a matching access list
Why it's wrong here
A NAT pool with only one address still requires the overload keyword to allow multiple hosts to share it. Without overload, only one inside host at a time can use the single pool address, so the other 49 hosts would be denied translation. This does not satisfy the requirement for 50 simultaneous outbound connections.
- ✓
ip nat inside source list 1 interface GigabitEthernet0/0 overload, with an access list permitting 192.168.10.0/24
Why this is correct
This uses Port Address Translation (PAT), also called NAT overload, which maps many inside private addresses to the single public address on the outside interface by multiplexing source ports. It is the standard solution when the ISP provides only one public IP and many internal hosts need simultaneous Internet access. The referenced access list identifies the inside source addresses that should be translated.
- ✗
ip nat inside source static 192.168.10.1 203.0.113.5, mapping the inside interface to the public address
Why it's wrong here
Static NAT creates a permanent one-to-one mapping between a single inside local address and the inside global address. It cannot support multiple inside hosts sharing one public address, and it is typically used for inbound access to a specific server. This would waste the only public address on a single host.
Visual reference
Go deeper
Related to this question
Learn chapter
Network Automation Benefits
Key term
PAT
PAT (Port Address Translation) is a method of network address translation that maps multiple private IP addresses to a single public IP address by using different port numbers for each connection.
Key term
IP address
An IP address is a unique numerical label assigned to each device connected to a computer network that uses the Internet Protocol for communication.
About these practice questions
Courseiva writes every 200-301 question from scratch — 1,450 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 200-301 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-301 exam.