Courseiva
easyMultiple Choice

350-401 Practice Question: Is configuring NAT on a Cisco router to allow…

A network engineer is configuring NAT on a Cisco router to allow internal hosts to access the internet. The engineer uses the command ip nat inside source list 100 interface GigabitEthernet0/0 overload, where access list 100 permits only the 10.0.0.0/8 network. After testing, hosts in the 10.0.0.0/8 network can access the internet, but hosts in the 172.16.0.0/16 network cannot. The engineer verifies that the 172.16.0.0/16 hosts have connectivity to the router. What is the most likely cause?

⚠ Common exam trap

Cisco often tests the misconception that the `ip nat inside source list` command automatically translates all inside traffic, when in fact the access list explicitly controls which source addresses are translated.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The access list 100 does not permit the 172.16.0.0/16 network.

The command `ip nat inside source list 100 interface GigabitEthernet0/0 overload` uses access list 100 to define which source IP addresses are eligible for NAT. Since ACL 100 permits only the 10.0.0.0/8 network, any traffic from 172.16.0.0/16 is not matched by the ACL and therefore is not translated. Even though the 172.16.0.0/16 hosts have connectivity to the router, their packets are forwarded without NAT and likely dropped by the ISP or the next-hop router because they contain private IP addresses.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    The access list 100 does not permit the 172.16.0.0/16 network.

    Why this is correct

    In Cisco NAT, the access list referenced by ip nat inside source list is evaluated against the source addresses of traffic entering the inside interface. Because ACL 100 does not contain an explicit permit statement for 172.16.0.0/16, the implicit deny any at the end prevents those packets from being translated. The router therefore forwards them with their private source IP unchanged, so return traffic from the Internet cannot be routed back to that subnet. A working ping to the gateway does not imply NAT is working; it only confirms Layer 3 reachability.

  • ✗

    The router's interface GigabitEthernet0/0 is not configured with ip nat outside.

    Why it's wrong here

    If GigabitEthernet0/0 were not marked with ip nat outside, the router would have no outside interface to translate traffic for, and no NAT translation would be created for any inside host—not just 172.16.0.0/16. The problem statement indicates connectivity was verified to the router, but that check does not prove the outside NAT command exists. However, since the failure is isolated to a single subnet, a global misconfiguration like a missing ip nat outside is inconsistent with the symptom. The router is clearly performing NAT for other networks, otherwise the outage would be more widespread.

  • ✗

    The 172.16.0.0/16 hosts have a default gateway pointing to a different router.

    Why it's wrong here

    A device's default gateway is the first-hop router used for all off-subnet traffic; if 172.16.0.0/16 hosts pointed to a different router, they could not reach the router's GigabitEthernet0/0 interface at all. The engineer's successful connectivity test to that router proves the hosts' default gateway is correctly directing traffic to this router. NAT occurs only after the packet arrives at the router, so a default gateway problem would manifest as a total lack of IP reachability, not as a NAT-specific failure. Therefore this is not the cause.

  • ✗

    The NAT pool is exhausted for the 172.16.0.0/16 network.

    Why it's wrong here

    The configuration shown uses ip nat inside source list 100 interface GigabitEthernet0/0 overload, which is Port Address Translation (PAT), not a dynamic NAT pool. With overload, every inside host is translated to the single IP address of the outside interface, differentiated by the source port number. There is no fixed pool of inside global addresses that can be exhausted—PAT supports many concurrent sessions on one address. Even a scenario where port space is exhausted is unrelated to an ACL that denies the source subnet, so this explanation cannot account for the symptom.

Visual reference

Inside (Private) PC-A 10.0.0.1 PC-B 10.0.0.2 NAT Router Outside (Public) 203.0.113.1 Inside Global Server PAT: many private IPs share one public IP via unique port numbers

About these practice questions

One of 1,923 original 350-401 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.