mediumMultiple Choice
300-410 Practice Question: Given this partial configuration: ip nat pool…
Given this partial configuration:
ip nat pool MYPOOL 203.0.113.10 203.0.113.20 netmask 255.255.255.0 ip nat inside source list 1 pool MYPOOL access-list 1 permit 192.168.1.0 0.0.0.255
What is the effect?
⚠ Common exam trap
Cisco often tests the distinction between dynamic NAT and PAT by omitting the 'overload' keyword, leading candidates to assume PAT is always used with a pool when in fact it must be explicitly configured.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Inside hosts are dynamically mapped to a pool address; if the pool is exhausted, new translations fail.
The configuration uses a standard ACL to match inside hosts (192.168.1.0/24) and dynamically assigns them a unique address from the pool 203.0.113.10–203.0.113.20. Because no 'overload' keyword is present, PAT is not enabled; each translation consumes a pool address, and once all 11 addresses are used, new translations fail until an existing translation times out or is cleared.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Inside hosts are translated to addresses in the pool using PAT.
Why it's wrong here
Without the 'overload' keyword, the router performs dynamic NAT, mapping each inside host to a distinct pool address one-to-one. PAT, which multiplexes many hosts onto one address via port numbers, requires 'ip nat inside source list 1 pool MYPOOL overload' — the correct choice when conserving public addresses matters.
- ✓
Inside hosts are dynamically mapped to a pool address; if the pool is exhausted, new translations fail.
Why this is correct
The inside source list maps permitted hosts to the MYPOOL range dynamically, one global address per host, since overload is absent. Once all eleven pool addresses are allocated, further translations fail until existing entries expire.
- ✗
The router uses the pool address as the source for all outbound traffic, regardless of ACL.
Why it's wrong here
The 'ip nat inside source list 1 pool MYPOOL' statement translates only traffic matching access-list 1, so non-matching outbound traffic keeps its original source address. Unconditional pool sourcing would need a route-map or ACL permitting any, which is the right design when every flow must egress from the pool.
- ✗
This configuration requires the 'ip nat outside' interface command to function.
Why it's wrong here
The 'ip nat inside' and 'ip nat outside' interface commands are mandatory for NAT to operate at all, not optional extras this configuration uniquely demands. The option is tempting because interface role designation is genuinely required, but it mislabels a universal prerequisite as a special requirement of this snippet.
Visual reference
Go deeper
Related to this question
About these practice questions
One of 1,401 original 300-410 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 300-410 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 300-410 exam.