mediumMultiple Choice
300-410 Practice Question: Is true regarding the default behavior of NAT in…
Which of the following is true regarding the default behavior of NAT in Cisco IOS when handling ICMP traffic?
⚠ Common exam trap
Cisco often tests the misconception that ICMP NAT entries are permanent or use the same timeout as TCP, when in fact they have a distinct and much shorter default timeout of 60 seconds.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
ICMP NAT entries timeout after 60 seconds by default.
C is correct because Cisco IOS NAT uses a default timeout of 60 seconds for ICMP NAT entries. When an ICMP packet is translated, the router creates a NAT translation entry, and if no subsequent traffic matches that entry within 60 seconds, the entry is removed. This behavior is independent of TCP or UDP timeouts and is specific to ICMP.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
ICMP traffic is not translated by NAT unless explicitly configured.
Why it's wrong here
Cisco IOS translates ICMP by default, including embedded query and reply identifiers, so no explicit configuration is needed. The option is tempting because ACLs and some inspection features do require explicit configuration, but NAT's ICMP handling is automatic, making this claim factually wrong for the default behaviour.
- ✗
ICMP NAT entries use the same timeout as TCP entries by default.
Why it's wrong here
ICMP NAT translations use the ICMP timeout (24 hours), not the TCP timeout (24 hours for established, but one minute for others). It is tempting because both are 24 hours in some contexts, yet the mechanisms are separate timers, so equating them misstates the default.
- ✓
ICMP NAT entries timeout after 60 seconds by default.
Why this is correct
Cisco IOS creates ICMP NAT translations with a 60-second timeout by default, unlike TCP's 86400-second and UDP's 300-second defaults. This shorter timer reflects ICMP's connectionless nature, so idle echo entries are removed quickly to conserve translation table space.
- ✗
ICMP NAT entries are permanent and do not time out.
Why it's wrong here
ICMP NAT entries are created dynamically and age out using the ICMP timeout (24 hours by default), not permanence. It is tempting because static NAT mappings do persist, but those are configured manually; default ICMP translations time out, so this misstates the default behaviour.
Visual reference
Go deeper
Related to this question
About these practice questions
Courseiva writes every 300-410 question from scratch — 1,401 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 300-410 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 300-410 exam.