Courseiva
mediumMultiple Choice

350-401 Practice Question: Given this NAT configuration: ``` interface…

Given this NAT configuration: ```

interface GigabitEthernet0/0
 ip address 10.0.0.1 255.255.255.0
 ip nat inside

!

interface GigabitEthernet0/1
 ip address 198.51.100.1 255.255.255.0
 ip nat outside

!

ip nat inside source static 10.0.0.5 198.51.100.5

``` What is the purpose of this configuration?

⚠ Common exam trap

Cisco often tests the misconception that all NAT configurations require an access list, but static NAT is a notable exception—it uses a direct mapping and does not need an ACL to define the inside host.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

It creates a one-to-one mapping between 10.0.0.5 and 198.51.100.5, allowing inbound and outbound traffic.

The configuration uses the 'ip nat inside source static' command to create a permanent one-to-one mapping between the inside local address 10.0.0.5 and the inside global address 198.51.100.5. This static NAT allows both outbound traffic (source translation) and inbound traffic (destination translation) to and from the mapped host, enabling bidirectional communication without the need for an access list.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    It translates all traffic from 10.0.0.0/24 to 198.51.100.0/24 using PAT.

    Why it's wrong here

    This mischaracterizes the configuration. The given command creates a single fixed mapping for host 10.0.0.5 to 198.51.100.5, not a dynamic translation rule for an entire subnet. PAT would require an access list to identify a range of inside hosts and would reuse the outside address with different port numbers, which is a distinctly different operation from the one-to-one static binding shown here.

  • ✓

    It creates a one-to-one mapping between 10.0.0.5 and 198.51.100.5, allowing inbound and outbound traffic.

    Why this is correct

    Static NAT establishes a persistent one-to-one binding between the inside local address 10.0.0.5 and the inside global address 198.51.100.5. Because this entry is permanent, both outbound traffic from the inside host and inbound traffic to the global address are translated, allowing external hosts to initiate sessions to the internal server. This is the defining characteristic of static NAT: the mapping is fixed regardless of direction.

  • ✗

    It translates only outbound traffic from 10.0.0.5 to 198.51.100.5.

    Why it's wrong here

    This is incomplete because static NAT is bidirectional by design. After the static entry is configured, the translation table contains the permanent mapping, so packets arriving on the outside interface destined to 198.51.100.5 are translated to 10.0.0.5 just as packets from 10.0.0.5 are translated to 198.51.100.5 when leaving. Limiting translation to one direction would defeat the purpose of a static mapping, which is precisely to enable unsolicited inbound connections.

  • ✗

    The configuration is incomplete; it needs an access-list.

    Why it's wrong here

    An access-list is only needed for dynamic NAT or PAT to identify the inside hosts eligible for translation. Static NAT uses the explicit ip nat inside source static command itself to define the mapping, and requires only the ip nat inside and ip nat outside designations on the interfaces. There is no additional match criteria required, so the configuration is complete as described.

Visual reference

Inside (Private) PC-A 10.0.0.1 PC-B 10.0.0.2 NAT Router Outside (Public) 203.0.113.1 Inside Global Server PAT: many private IPs share one public IP via unique port numbers

About these practice questions

This 350-401 question is part of Courseiva's 1,923-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.