easyMultiple Choice
300-410 Practice Question: Which statement accurately describes the behavior…
Which statement accurately describes the behavior of the ip nat inside source static command when configuring static NAT for a single inside host?
⚠ Common exam trap
Cisco often tests the misconception that static NAT requires an access list or that it behaves like dynamic NAT with timeouts, leading candidates to incorrectly choose options A or C.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
It creates a permanent mapping that remains in the NAT table until the configuration is removed.
The `ip nat inside source static` command creates a permanent one-to-one mapping between an inside local IP address and an inside global IP address. This static entry remains in the NAT table indefinitely until the administrator explicitly removes it with the `no ip nat inside source static` command, making option B correct.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
It dynamically allocates the global address from a pool and removes the entry after an idle timeout.
Why it's wrong here
Dynamic pool allocation with idle-timeout removal describes ip nat inside source list with a pool, not the static keyword, which creates a permanent one-to-one mapping. Static entries suit servers needing a stable, externally reachable address.
- ✓
It creates a permanent mapping that remains in the NAT table until the configuration is removed.
Why this is correct
Static NAT installs a fixed one-to-one entry in the translation table that persists indefinitely, unlike dynamic translations which age out after the timeout. The mapping survives until the engineer removes the ip nat inside source static command, satisfying the permanent-mapping requirement.
- ✗
It requires the use of an access list to define which traffic is translated.
Why it's wrong here
The static form maps one inside local address to one global address directly, needing no access list; ACLs belong to dynamic NAT with overload, where they select interesting traffic. Static one-to-one translation is correct when a fixed, predictable mapping is required.
- ✗
It translates only TCP and UDP traffic by default.
Why it's wrong here
Static NAT translates any IP protocol, including ICMP and GRE, not just TCP and UDP, so this claim misstates the command's behaviour. It is tempting because PAT overload relies on TCP/UDP port numbers, making protocol restriction sound plausible, but that mechanism belongs to dynamic translation, not static one-to-one mappings.
Visual reference
About these practice questions
This 300-410 question is part of Courseiva's 1,401-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 300-410 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 300-410 exam.