mediumMultiple Choice
300-410 Practice Question: Runs the following command to verify NAT…
A network engineer runs the following command to verify NAT translations:
R1# show ip nat translations verbose
Pro Inside global Inside local Outside local Outside global --- 10.2.2.2 10.1.1.1 192.168.1.1 192.168.1.1 create 00:00:15, use 00:00:05, flags: extended, timing-out
What does the 'extended' flag indicate?
⚠ Common exam trap
Many candidates confuse the 'extended' flag with static NAT or assume it means a single-port translation, when in fact it specifically denotes PAT with port multiplexing, as seen in dynamic overload configurations.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The translation includes port information, typical of PAT.
The 'extended' flag in the output of 'show ip nat translations verbose' indicates that the NAT translation includes Layer 4 port information, which is characteristic of Port Address Translation (PAT) or NAT overload. This allows multiple internal hosts to share a single public IP address by using unique port numbers, as opposed to a simple one-to-one translation without port multiplexing.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The translation is for a single port only.
Why it's wrong here
Extended translation maps the full five-tuple, including inside and outside addresses and ports, rather than restricting to a single port. Single-port mappings describe port forwarding or static PAT, which is a different configuration from the extended flag shown here.
- ✓
The translation includes port information, typical of PAT.
Why this is correct
The 'extended' flag confirms the entry maps IP addresses plus TCP or UDP port numbers, which is the defining behaviour of Port Address Translation. This satisfies the scenario's requirement to identify why a single inside global address can multiplex many inside local hosts through distinct port identifiers.
- ✗
The translation is static and never times out.
Why it's wrong here
The 'extended' flag denotes that the entry tracks full five-tuple translation, including ports and outside addresses, not static permanence; the timing-out flag shows it is dynamic. Static NAT entries suit permanent one-to-one mappings, which is a separate configuration.
- ✗
The translation is for a VPN tunnel.
Why it's wrong here
The flag describes the translation's addressing granularity, not any tunnel encapsulation; VPN traffic appears as ordinary NAT entries. It is tempting because extended translations often carry tunnel traffic, but VPNs are configured separately and are not what the flag itself reports.
Visual reference
Go deeper
Related to this question
About these practice questions
One of 1,401 original 300-410 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 300-410 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 300-410 exam.