NAT Types in CCNA
Which TWO statements accurately describe Network Address Translation (NAT) types?
Quick Answer
The answer is Dynamic NAT and Static NAT. Dynamic NAT is correct because it maps a private IP to a public IP from a pool for the duration of a session without altering Layer 4 port numbers, meaning it performs a one-to-one address translation only. Static NAT is correct because it creates a permanent, fixed mapping between a single inside local address and a single inside global address, commonly used to expose internal servers like a web server to the internet with a consistent public IP. On the CCNA 200-301 v2 exam, this question tests your ability to distinguish NAT types and translation terms, often appearing in a multiple-select format where a common trap is confusing Dynamic NAT with PAT, which does modify port numbers. Remember: if ports change, it’s PAT; if only the IP changes from a pool, it’s Dynamic NAT. For Static NAT, think “one-to-one, always on.”
⚠ Common exam trap
Cisco often tests the misconception that PAT only works with TCP, but in reality PAT supports both TCP and UDP, and the trap here is that candidates confuse PAT's use of port numbers with a protocol limitation.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Static NAT creates a fixed one-to-one mapping between a local and global address and is typically used to allow external connectivity to internal servers.
Option A is correct because static NAT (also called one-to-one NAT) permanently maps a single private (local) address to a single public (global) address, which is exactly the configuration used to publish internal servers such as web or mail hosts to the Internet. Option B is correct because dynamic NAT draws a public address from a configured pool and creates a temporary one-to-one binding for the duration of the session, and since it operates strictly at Layer 3 it does not rewrite TCP/UDP port numbers (that is the job of PAT/overloading). Option C is wrong because PAT translates both TCP and UDP (and ICMP query IDs), since it multiplexes on any Layer 4 identifier, not TCP alone. Option D is wrong because static NAT mappings are manually configured and persist until an administrator removes them; they are not aged out by inactivity timers. Option E is wrong because PAT specifically allows many private hosts to share a single public IP by translating source ports, so exhaustion of a public pool is not the failure mode described.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Static NAT creates a fixed one-to-one mapping between a local and global address and is typically used to allow external connectivity to internal servers.
Why this is correct
Static NAT builds a permanent one-to-one binding between an inside local address and an inside global address, with no port translation. Because the mapping is fixed and predictable, external hosts can reliably initiate connections to internal servers, which is why it suits inbound service publishing.
- ✓
Dynamic NAT assigns a public IP from a pool for the duration of a translation, but it does not modify Layer 4 port numbers.
Why this is correct
Dynamic NAT draws a public address from a configured pool and holds that binding only while the translation is active, releasing it afterwards. Crucially, it maps addresses alone; port numbers remain untouched, unlike PAT, which multiplexes many sessions over one address using Layer 4 identifiers.
- ✗
PAT only translates TCP packets because it uses port numbers, leaving UDP translation unsupported.
Why it's wrong here
PAT translates both TCP and UDP, mapping port numbers (and ICMP query IDs) per flow, so UDP is fully supported. The claim is tempting because port-based multiplexing is genuinely PAT's defining mechanism, but that mechanism applies across both transport protocols, not TCP alone.
- ✗
Static NAT entries are automatically removed after periods of inactivity to free up public addresses.
Why it's wrong here
Static NAT mappings are manually configured and persist until an administrator removes them; they are not aged out by inactivity. The option is tempting because dynamic NAT translations genuinely expire from the translation table after idle timeouts, but that behaviour does not apply to static entries.
- ✗
With PAT, if the public IP address pool is exhausted, new translations fail because PAT requires unique public IPs for each private host.
Why it's wrong here
PAT multiplexes many private hosts onto one public address using unique source ports, so pool exhaustion is not caused by requiring a unique public IP per host. The option is tempting because address-pool exhaustion is a real NAT concern, but the stated mechanism misstates how PAT conserves addresses.
Option-by-option analysis
Why each answer is right or wrong
Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The 200-301 exam frequently reuses these exact scenarios with slightly different constraints.
✓Static NAT creates a fixed one-to-one mapping between a local and global address and is typically used to allow external connectivity to internal servers.Correct answer▾
Why this is correct
Static NAT builds a permanent one-to-one binding between an inside local address and an inside global address, with no port translation. Because the mapping is fixed and predictable, external hosts can reliably initiate connections to internal servers, which is why it suits inbound service publishing.
✗PAT only translates TCP packets because it uses port numbers, leaving UDP translation unsupported.Wrong answer — click to see why▾
Why this is wrong here
PAT works with any transport protocol that has port fields—TCP, UDP, and even ICMP through the identifier field.
✗Static NAT entries are automatically removed after periods of inactivity to free up public addresses.Wrong answer — click to see why▾
Why this is wrong here
Only dynamic translations (from dynamic NAT or PAT) have idle timeouts; static mappings are permanent.
✗With PAT, if the public IP address pool is exhausted, new translations fail because PAT requires unique public IPs for each private host.Wrong answer — click to see why▾
Why this is wrong here
This statement describes dynamic NAT pool exhaustion, not PAT, which uses port multiplexing.
Analysis generated from the official 200-301blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”
Visual reference
Go deeper
Related to this question
Learn chapter
NAT Types — Static, Dynamic, and PAT
Key term
TCP
TCP is a connection-oriented transport layer protocol that ensures reliable, ordered, and error-checked delivery of data between applications over IP networks.
Key term
PAT
PAT (Port Address Translation) is a method of network address translation that maps multiple private IP addresses to a single public IP address by using different port numbers for each connection.
About these practice questions
Courseiva writes every 200-301 question from scratch — 1,450 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on 200-301
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. Match each NAT term to its most accurate description.
medium- ✓ A.Inside Local: The IP address of an internal host as seen from inside the network.
- B.Inside Local: The IP address of an external host as seen from inside the network.
- C.Inside Local: The IP address of an internal host as seen from outside the network.
- D.Inside Local: The IP address of an external host as seen from outside the network.
Why A: NAT terms describe address perspectives: Inside Local is the internal host's IP, Inside Global is its external IP, Outside Local is the external host's IP seen internally, Outside Global is its actual external IP, Static NAT provides permanent mapping, and Dynamic NAT uses a pool.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 200-301 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-301 exam.