Drag or tap steps into the slots.
CCNA PAT (Port Address Translation) Practice Question
Drag and drop the following steps into the correct order to configure PAT (overload) on a Cisco router using a single public IP address on the outside interface.
⚠ Common exam trap
Learners often forget to assign the 'ip nat inside' and 'ip nat outside' interface commands, or they configure them in the wrong order relative to the source NAT statement.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
Enter global configuration mode
The correct order is A, B, C, D, E. First, enter global configuration mode. Second, create an access list to match the traffic to be translated. Third, configure the inside interface with 'ip nat inside'. Fourth, configure the outside interface with 'ip nat outside'. Fifth, apply PAT with 'ip nat inside source list <ACL> interface <outside-if> overload'. This final command enables PAT using the outside interface's public IP.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Enter global configuration mode
Why this is correct
Entering global configuration mode is always the first step in any router configuration.
- ✓
Create an access list to match the traffic to be translated
Why this is correct
Creating an access list to identify the traffic that will be translated is necessary before applying NAT rules.
- ✓
Configure the inside interface with 'ip nat inside'
Why this is correct
Configuring the inside interface with `ip nat inside` marks it as the internal side for NAT translation.
- ✓
Configure the outside interface with 'ip nat outside'
Why this is correct
Configuring the outside interface with `ip nat outside` marks it as the external side for NAT translation.
Visual reference
Go deeper
Related to this question
Learn chapter
Cisco IOS Licensing Overview
Key term
IP address
An IP address is a unique numerical label assigned to each device connected to a computer network that uses the Internet Protocol for communication.
Key term
Access Control List
An Access Control List is a set of rules that decides which traffic is allowed or denied entry to a network or device.
About these practice questions
This 200-301 question is part of Courseiva's 1,450-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 200-301 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-301 exam.