350-401 Infrastructure Practice Question
A network engineer is configuring a Cisco IOS router to support NAT for a small office. The inside network uses the 192.168.1.0/24 subnet, and the outside interface is GigabitEthernet0/0 with IP address 203.0.113.5. The engineer wants to translate all inside addresses to the outside interface address. Which command is required to define the NAT source list?
⚠ Common exam trap
Candidates often confuse the access list that defines the source addresses with the NAT translation command that references it, leading to selecting the latter as the answer.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
access-list 1 permit 192.168.1.0 0.0.0.255
To define the NAT source list, an access list must be created that matches the inside local addresses. The command access-list 1 permit 192.168.1.0 0.0.0.255 accomplishes this by permitting the entire 192.168.1.0/24 subnet. This list is then referenced in the ip nat inside source list command to enable translation.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
ip nat pool POOL 203.0.113.5 203.0.113.5 netmask 255.255.255.0
Why it's wrong here
This command creates a NAT pool with a single address. While it could be used for dynamic NAT, the scenario requires translating to the outside interface address, which is better done with interface overload. This command does not define the source list of inside addresses.
- ✗
ip nat inside source list 1 interface GigabitEthernet0/0 overload
Why it's wrong here
This command enables NAT overload using the outside interface, but it requires an existing access list to define the inside addresses. It is part of the configuration but not the command that defines the source list itself. The question asks for the command to define the NAT source list.
- ✓
access-list 1 permit 192.168.1.0 0.0.0.255
Why this is correct
This access list defines the inside local addresses that will be translated. The wildcard mask 0.0.0.255 matches the entire 192.168.1.0/24 subnet. The access list is then referenced in the ip nat inside source list command to specify which traffic should be translated.
- ✗
ip nat inside source static 192.168.1.1 203.0.113.5
Why it's wrong here
This command creates a static NAT translation for a single inside host, not for the entire subnet. The scenario requires translating all inside addresses, so a static entry is insufficient. It also does not define a source list for dynamic translation.
Visual reference
Go deeper
Related to this question
About these practice questions
This 350-401 question is part of Courseiva's 1,923-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.