Courseiva

CCNA Network Services and Security Practice Question

A small office has an internal server at 192.168.1.50 that must be reachable from the internet on TCP port 443 using the public address 203.0.113.10. The edge router already performs NAT overload for outbound client traffic on its outside interface. Which configuration correctly adds inbound reachability without breaking existing outbound translation?

⚠ Common exam trap

The trap here is assuming that an overload statement or a NAT pool alone can publish an internal server, when only a static inside source mapping creates a predictable inbound translation.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

ip nat inside source static tcp 192.168.1.50 443 203.0.113.10 443

Static NAT with port forwarding binds the inside server's private address and port to a specific public address and port, producing a permanent one-to-one mapping that outside hosts can initiate connections to. Because it is a static entry, it does not conflict with the existing overload configuration used for outbound client traffic, so both behaviors can run on the same router.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    ip nat outside source static tcp 192.168.1.50 443 203.0.113.10 443

    Why it's wrong here

    The outside source keyword translates addresses that arrive from the outside network before they are forwarded inward, which is the opposite direction from what is needed. The internal server address is an inside local address, so it must be referenced with inside source static for inbound reachability.

  • ✓

    ip nat inside source static tcp 192.168.1.50 443 203.0.113.10 443

    Why this is correct

    A static NAT entry maps the inside server's address and port to a fixed public address and port, which creates a permanent translation that inbound clients can reach. Because it is a static mapping rather than an overload entry, it coexists with the existing dynamic PAT configuration and does not disturb outbound client translations.

  • ✗

    ip nat pool WEB 203.0.113.10 203.0.113.10 netmask 255.255.255.0

    Why it's wrong here

    A NAT pool only defines a range of addresses that dynamic translation rules can draw from; it performs no translation by itself and contains no port information. Without an accompanying source list and translation statement, the pool does nothing to make the internal server reachable from the internet.

  • ✗

    ip nat inside source list 1 interface GigabitEthernet0/0 overload

    Why it's wrong here

    This command configures dynamic PAT for traffic matched by access list 1, which is exactly the outbound overload behavior already in use. It does not create any predictable inbound mapping, so external clients have no way to initiate a connection to the internal server on port 443 using the known public address.

Visual reference

Inside (Private) PC-A 10.0.0.1 PC-B 10.0.0.2 NAT Router Outside (Public) 203.0.113.1 Inside Global Server PAT: many private IPs share one public IP via unique port numbers

About these practice questions

One of 1,450 original 200-301 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 200-301 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-301 exam.