Courseiva
mediumMultiple Choice

350-401 Practice Question: Is configuring a Cisco router to provide internet…

A network engineer is configuring a Cisco router to provide internet access to a small office using a single public IP address assigned by the ISP. The engineer wants to allow internal hosts to initiate connections to the internet, but also needs to make a web server on the internal network reachable from the internet. The engineer configures a standard access list for NAT and an ip nat inside source list command. However, external users cannot reach the internal web server. What is the most likely cause?

⚠ Common exam trap

Cisco often tests the distinction between dynamic NAT (using 'ip nat inside source list') and static NAT (using 'ip nat inside source static'), leading candidates to incorrectly assume that a single NAT configuration can handle both outbound and inbound traffic without additional commands.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The engineer forgot to add the ip nat inside source static command for the web server.

The scenario describes a need for both dynamic PAT (for internal hosts to reach the internet) and static NAT (to make the internal web server reachable from the internet). The 'ip nat inside source list' command alone performs dynamic NAT/PAT, translating multiple inside addresses to the single public IP. To allow inbound connections to the web server, a static one-to-one mapping is required using the 'ip nat inside source static tcp' command, which creates a permanent translation entry. Without this static command, the router has no way to know which inside host should receive incoming traffic destined for the public IP on port 80.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The access list used for NAT does not permit the web server's IP address.

    Why it's wrong here

    An ACL referenced in a NAT configuration (e.g., ip nat inside source list) serves only to match inside local addresses for dynamic translation. Static NAT entries are created with an explicit ip nat inside source static command and are never filtered by an ACL. Therefore, even if the ACL denied the web server's address, it would have no bearing on a static mapping; the inability to reach the web server is due solely to the missing static entry.

  • ✓

    The engineer forgot to add the ip nat inside source static command for the web server.

    Why this is correct

    For inbound traffic to reach an internal web server, the router must translate the public destination IP back to the server's private IP. This requires an explicit ip nat inside source static command (or the TCP/UDP port-specific variant) that defines the one-to-one binding between the public address and the private address. Without this command, the router has no entry in its NAT table for the destination address and will drop the packets, so external clients cannot connect.

  • ✗

    The ip nat inside and ip nat outside commands are applied on the wrong interfaces.

    Why it's wrong here

    If ip nat inside and ip nat outside were swapped on the interfaces, the router would fail to correctly translate traffic for all hosts, and outbound sessions would typically break as well. The scenario focuses on a single internal web server being unreachable from outside, which indicates a missing static mapping rather than a global interface configuration error. Correct interface placement is a prerequisite, but the specific symptom of only the web server failing points to the absence of the static NAT command, not to misapplied interface directives.

  • ✗

    The global configuration mode is missing the ip nat pool command.

    Why it's wrong here

    An ip nat pool defines a range of global addresses for use with dynamic NAT or PAT, typically paired with a source ACL in a command like ip nat inside source list <acl> pool <name>. Static NAT, which is what a web server requires for inbound access, does not involve a pool; it uses the ip nat inside source static command to map one specific inside local address to one inside global address. The absence of a pool is irrelevant because static NAT never references a pool, so this cannot explain why the web server is unreachable.

Visual reference

Inside (Private) PC-A 10.0.0.1 PC-B 10.0.0.2 NAT Router Outside (Public) 203.0.113.1 Inside Global Server PAT: many private IPs share one public IP via unique port numbers

About these practice questions

Courseiva writes every 350-401 question from scratch — 1,923 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.