Courseiva

CCNA Network Services and Security Practice Question

A network engineer is configuring a Cisco IOS router that connects a small branch office to the Internet. The router's outside interface is GigabitEthernet0/0 with IP address 203.0.113.5/30, and the inside interface is GigabitEthernet0/1 with IP address 192.168.10.1/24. The branch has 50 internal hosts that need simultaneous outbound Internet access, but the ISP assigned only the single public address 203.0.113.5. The engineer wants to conserve public addresses and ensure that internal addresses are hidden. Which configuration should be applied on the router?

⚠ Common exam trap

The trap here is assuming any NAT pool configuration automatically supports many hosts, when a one-address pool without overload still permits only one simultaneous translation.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

ip nat inside source list 1 interface GigabitEthernet0/0 overload, with an access list permitting 192.168.10.0/24

The router must translate many inside private addresses to the single public address provided by the ISP. NAT overload, also called PAT, allows this by tracking source port numbers to distinguish sessions. Configuring ip nat inside source list with the outside interface and the overload keyword, plus an access list matching 192.168.10.0/24, meets the requirement and hides internal addressing.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    ip nat outside source list 1 interface GigabitEthernet0/1 overload, translating outside sources to the inside interface address

    Why it's wrong here

    This command translates outside source addresses to the inside interface, which is the reverse of what is needed for outbound Internet access. It also references the wrong interface for the inside global address. The correct direction is inside source translation to the outside interface.

  • ✗

    ip nat inside source list 1 pool PUBLIC_POOL, with a pool containing 203.0.113.5 and a matching access list

    Why it's wrong here

    A NAT pool with only one address still requires the overload keyword to allow multiple hosts to share it. Without overload, only one inside host at a time can use the single pool address, so the other 49 hosts would be denied translation. This does not satisfy the requirement for 50 simultaneous outbound connections.

  • ✓

    ip nat inside source list 1 interface GigabitEthernet0/0 overload, with an access list permitting 192.168.10.0/24

    Why this is correct

    This uses Port Address Translation (PAT), also called NAT overload, which maps many inside private addresses to the single public address on the outside interface by multiplexing source ports. It is the standard solution when the ISP provides only one public IP and many internal hosts need simultaneous Internet access. The referenced access list identifies the inside source addresses that should be translated.

  • ✗

    ip nat inside source static 192.168.10.1 203.0.113.5, mapping the inside interface to the public address

    Why it's wrong here

    Static NAT creates a permanent one-to-one mapping between a single inside local address and the inside global address. It cannot support multiple inside hosts sharing one public address, and it is typically used for inbound access to a specific server. This would waste the only public address on a single host.

Visual reference

Inside (Private) PC-A 10.0.0.1 PC-B 10.0.0.2 NAT Router Outside (Public) 203.0.113.1 Inside Global Server PAT: many private IPs share one public IP via unique port numbers

About these practice questions

Courseiva writes every 200-301 question from scratch — 1,450 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 200-301 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-301 exam.