CCNA IP Routing Practice Question
Exhibit
R1# show standby
Vlan10 - Group 1
State is Active
2 state changes, last state change 00:03:45
Virtual IP address is 192.168.10.1
Active virtual MAC address is 0000.0c07.ac01
Local virtual MAC address is 0000.0c07.ac01 (v1 default)
Hello time 3 sec, hold time 10 sec
Next hello sent in 1.920 secs
Preemption disabled
Active router is local
Standby router is 192.168.10.3, priority 100 (expires in 8.928 sec)
Priority 110 (configured 110)
Group name is "hsrp-Vlan10-1" (v1)
R2# show standby
Vlan10 - Group 1
State is Standby
3 state changes, last state change 00:03:42
Virtual IP address is 192.168.10.1
Active virtual MAC address is 0000.0c07.ac01
Local virtual MAC address is 0000.0c07.ac02 (v1 default)
Hello time 3 sec, hold time 10 sec
Next hello sent in 0.432 secs
Preemption disabled
Active router is 192.168.10.2, priority 110
Standby router is local
Priority 100 (configured 100)
Group name is "hsrp-Vlan10-1" (v1)A network administrator is troubleshooting a connectivity issue on a subnet where two routers, R1 and R2, are configured with HSRP to provide a virtual gateway. Hosts on the subnet can ping the virtual IP address but cannot reach destinations outside the subnet. The administrator discovers that R1 is the active HSRP router. What is the most likely root cause of the problem?
⚠ Common exam trap
Cisco often tests the misconception that HSRP configuration alone provides full connectivity, when in fact the routers still need proper routing (e.g., a default route) to forward traffic beyond the subnet.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Configure a default route on R1 pointing to the next-hop router.
Configure a default route on R1 pointing to the next-hop router. Since R1 is the active HSRP router, it owns the virtual IP and forwards traffic from hosts; if hosts can ping the virtual IP but cannot reach outside destinations, R1 is likely missing a default route (or a route to external networks) so it drops the off-subnet traffic. Preemption (B) only affects which router becomes active and does not fix forwarding. Changing R2's virtual MAC (C) is unnecessary and could break HSRP, since the virtual MAC is shared and managed by HSRP. Increasing R1's hello timer (D) would not resolve routing and could cause HSRP timer mismatches or slower failover.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Configure a default route on R1 pointing to the next-hop router.
Why this is correct
HSRP provides only the virtual gateway address; R1 as active router still needs a default route to forward off-subnet traffic. Without it, hosts reach the virtual IP but packets to external destinations are dropped, matching the reported symptom.
- ✗
Enable preemption on both routers to ensure the higher-priority router stays active.
Why it's wrong here
Preemption governs which router becomes active after a priority change; it does not affect forwarding of off-subnet traffic. The symptom points to R1 lacking a route or NAT for external destinations. Preemption would be correct when ensuring a preferred, higher-priority router reclaims the active role after recovery.
- ✗
Change the virtual MAC address on R2 to match the one on R1.
Why it's wrong here
The virtual MAC address is automatically derived from the HSRP group and is the same for both routers (0000.0c07.ac01 for Active). R2's local virtual MAC is different because it is used only when R2 becomes Active.
- ✗
Increase the hello timer on R1 to match the hold timer on R2.
Why it's wrong here
Mismatched hello and hold timers cause HSRP peering instability, not silent failure to route off-subnet. Hosts reaching the virtual IP proves the gateway is up. Timer alignment would be the right fix when routers fail to form or maintain the HSRP group relationship.
Option-by-option analysis
Why each answer is right or wrong
Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The 200-301 exam frequently reuses these exact scenarios with slightly different constraints.
✓Configure a default route on R1 pointing to the next-hop router.Correct answer▾
Why this is correct
HSRP provides only the virtual gateway address; R1 as active router still needs a default route to forward off-subnet traffic. Without it, hosts reach the virtual IP but packets to external destinations are dropped, matching the reported symptom.
✗Enable preemption on both routers to ensure the higher-priority router stays active.Wrong answer — click to see why▾
Why this is wrong here
Preemption is not needed because the current Active router already has the higher priority (110 vs 100). Preemption only becomes relevant when a higher-priority router recovers after a failure and needs to reclaim the Active role. The issue here is routing, not HSRP state stability.
Why candidates choose this
Students often confuse preemption with general HSRP stability. They may think enabling preemption ensures the best router is always active, but in this scenario, the Active router is already the higher-priority one, so preemption would not change anything.
✗Change the virtual MAC address on R2 to match the one on R1.Wrong answer — click to see why▾
Why this is wrong here
The virtual MAC address is automatically derived from the HSRP group number and is the same for both routers when they are in the same group. R2's local virtual MAC is different because it is used only when R2 becomes Active. The mismatch in the output is normal and does not affect connectivity.
Why candidates choose this
Students might think that both routers must have identical virtual MAC addresses for HSRP to work, but in reality, the virtual MAC is shared only by the Active router. The Standby router uses a different local virtual MAC until it becomes Active.
✗Increase the hello timer on R1 to match the hold timer on R2.Wrong answer — click to see why▾
Why this is wrong here
The hello and hold timers are consistent (3 sec hello, 10 sec hold) and are not causing any issues. Adjusting timers would not fix the routing problem. The root cause is the lack of a default route on the Active router.
Why candidates choose this
Students may think that timer mismatches can cause HSRP instability, leading to connectivity issues. However, in this case, the timers are consistent, and the problem is purely routing-related.
Analysis generated from the official 200-301blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”
Visual reference
Quick reference
Access Control Model Comparison
| Model | Acronym | Who Controls Access? | Best For |
|---|---|---|---|
| Discretionary Access Control | DAC | Resource owner | Small teams, file shares |
| Mandatory Access Control | MAC | System / security labels | Classified govt / military |
| Role-Based Access Control | RBAC | Administrator (via roles) | Enterprise environments |
| Attribute-Based Access Control | ABAC | Policy engine (user + resource attributes) | Fine-grained, dynamic policies |
| Rule-Based Access Control | RuBAC | System rules / ACLs | Firewall rules, network ACLs |
Go deeper
Related to this question
Learn chapter
Troubleshoot Wired and Wireless Client Connectivity on Windows, macOS, and Linux
Key term
HSRP
HSRP stands for Hot Standby Router Protocol, a Cisco proprietary protocol that allows multiple routers to work together as a single virtual router to provide default gateway redundancy.
Key term
Ping
Ping is a network utility used to test whether a remote computer or device is reachable across an IP network and to measure the round-trip time of data packets.
About these practice questions
This 200-301 question is part of Courseiva's 1,450-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 200-301 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-301 exam.