Courseiva
Infrastructure →easyMultiple Choice

350-401 Infrastructure Practice Question

A network engineer is configuring a Cisco IOS router to support NAT for a small office. The inside network uses the 192.168.1.0/24 subnet, and the outside interface is GigabitEthernet0/0 with IP address 203.0.113.5. The engineer wants to translate all inside addresses to the outside interface address. Which command is required to define the NAT source list?

⚠ Common exam trap

Candidates often confuse the access list that defines the source addresses with the NAT translation command that references it, leading to selecting the latter as the answer.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

access-list 1 permit 192.168.1.0 0.0.0.255

To define the NAT source list, an access list must be created that matches the inside local addresses. The command access-list 1 permit 192.168.1.0 0.0.0.255 accomplishes this by permitting the entire 192.168.1.0/24 subnet. This list is then referenced in the ip nat inside source list command to enable translation.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    ip nat pool POOL 203.0.113.5 203.0.113.5 netmask 255.255.255.0

    Why it's wrong here

    This command creates a NAT pool with a single address. While it could be used for dynamic NAT, the scenario requires translating to the outside interface address, which is better done with interface overload. This command does not define the source list of inside addresses.

  • ✗

    ip nat inside source list 1 interface GigabitEthernet0/0 overload

    Why it's wrong here

    This command enables NAT overload using the outside interface, but it requires an existing access list to define the inside addresses. It is part of the configuration but not the command that defines the source list itself. The question asks for the command to define the NAT source list.

  • ✓

    access-list 1 permit 192.168.1.0 0.0.0.255

    Why this is correct

    This access list defines the inside local addresses that will be translated. The wildcard mask 0.0.0.255 matches the entire 192.168.1.0/24 subnet. The access list is then referenced in the ip nat inside source list command to specify which traffic should be translated.

  • ✗

    ip nat inside source static 192.168.1.1 203.0.113.5

    Why it's wrong here

    This command creates a static NAT translation for a single inside host, not for the entire subnet. The scenario requires translating all inside addresses, so a static entry is insufficient. It also does not define a source list for dynamic translation.

Visual reference

Inside (Private) PC-A 10.0.0.1 PC-B 10.0.0.2 NAT Router Outside (Public) 203.0.113.1 Inside Global Server PAT: many private IPs share one public IP via unique port numbers

About these practice questions

This 350-401 question is part of Courseiva's 1,923-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.