Courseiva
Infrastructure →hardMultiple Select

350-401 Infrastructure Practice Question

A network engineer is configuring a Cisco IOS router to support NAT overload (PAT) for a small office. The inside network is 192.168.1.0/24, and the outside interface is GigabitEthernet0/1 with IP address 203.0.113.5. The engineer wants to translate all inside addresses to the outside interface address. Which two commands are required to complete this configuration? (Choose two.)

⚠ Common exam trap

Many exam-takers confuse the direction of NAT (inside source vs. outside source) or forgetting the 'overload' keyword, which is essential for PAT.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

access-list 1 permit 192.168.1.0 0.0.0.255

To configure NAT overload (PAT) using the outside interface address, two commands are needed: an access list to define the inside local addresses, and the 'ip nat inside source list' command with the 'overload' keyword referencing that list and the outside interface. The access list permits the 192.168.1.0/24 subnet, and the NAT command translates all permitted addresses to the outside interface's IP. The other options either use a pool, configure the wrong direction, or create a static translation, none of which meet the requirement.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    access-list 1 permit 192.168.1.0 0.0.0.255

    Why this is correct

    This access list defines the inside local addresses that are eligible for NAT translation. It permits the entire 192.168.1.0/24 subnet. The NAT command references this list to identify which traffic should be translated. Without this access list, the NAT configuration would not know which addresses to translate. Therefore, it is a required command.

  • ✗

    ip nat outside source list 1 interface GigabitEthernet0/1 overload

    Why it's wrong here

    This command configures NAT for outside source addresses, which is used for translating outside addresses to inside addresses. It is not the correct direction for translating inside hosts to the outside. The scenario requires inside source NAT. Therefore, this command is incorrect and would not achieve the desired translation.

  • ✓

    ip nat inside source list 1 interface GigabitEthernet0/1 overload

    Why this is correct

    This command configures NAT overload (PAT) by referencing an access list (list 1) that defines the inside local addresses to be translated. It uses the outside interface's IP address for translation. The 'overload' keyword enables PAT, allowing multiple inside hosts to share the single outside IP. This is a required command to enable NAT overload for the specified traffic.

  • ✗

    ip nat inside source static 192.168.1.10 203.0.113.5

    Why it's wrong here

    This command creates a static NAT translation for a single inside host (192.168.1.10) to the outside address. Static NAT does not provide overload and only translates one address. The requirement is to translate all inside addresses using PAT. Therefore, this command is not suitable and is not required for the scenario.

  • ✗

    ip nat inside source list 1 pool MYPOOL overload

    Why it's wrong here

    This command uses a NAT pool named MYPOOL instead of the outside interface address. The scenario specifies translating to the outside interface address, not a pool. While this command would also enable overload, it does not match the requirement of using the interface IP. Therefore, it is not one of the required commands for this specific configuration.

Visual reference

Inside (Private) PC-A 10.0.0.1 PC-B 10.0.0.2 NAT Router Outside (Public) 203.0.113.1 Inside Global Server PAT: many private IPs share one public IP via unique port numbers

About these practice questions

Courseiva writes every 350-401 question from scratch — 1,923 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.