mediumMultiple Choice
350-401 Practice Question: Consider the following configuration snippet: ```…
Consider the following configuration snippet: ```
interface GigabitEthernet0/1 ip address 192.168.1.1 255.255.255.0 ip nat inside
!
interface GigabitEthernet0/2 ip address 203.0.113.1 255.255.255.0 ip nat outside
!
ip nat inside source list 1 interface GigabitEthernet0/2 overload access-list 1 permit 192.168.1.0 0.0.0.255
``` What is the effect of this configuration?
⚠ Common exam trap
Cisco often tests the distinction between dynamic NAT (with or without overload) and static NAT, and the trap here is that candidates may think 'overload' implies static mapping or that the access list only applies to the first host, when in fact it applies to the entire subnet and enables PAT.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
It translates all traffic from 192.168.1.0/24 to the IP address 203.0.113.1, using port address translation.
This configuration implements dynamic NAT with Port Address Translation (PAT), also known as NAT overload. The access list matches the 192.168.1.0/24 source network, and the 'ip nat inside source list 1 interface GigabitEthernet0/2 overload' command translates all matching inside local addresses to the single outside interface IP (203.0.113.1) using unique port numbers to differentiate sessions. This allows multiple internal hosts to share the public IP simultaneously.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
It translates all traffic from 192.168.1.0/24 to the IP address 203.0.113.1, using port address translation.
Why this is correct
The presence of the 'overload' keyword in the NAT configuration, combined with an access list that matches the entire 192.168.1.0/24 subnet, causes the router to perform Port Address Translation. Every inside host sharing the single public IPv4 address 203.0.113.1 is differentiated by a unique TCP/UDP port number, while the configuration does not reserve any pool of public addresses. This is the expected behavior for many-to-one internet access.
- ✗
It performs static NAT for each host in 192.168.1.0/24 to a unique IP in the 203.0.113.0/24 network.
Why it's wrong here
This describes static or dynamic NAT without overload, where each private host would require a one-to-one mapping to a unique public address in the 203.0.113.0/24 pool. However, the shown configuration uses a single interface IP with the 'overload' keyword, so it does not create per-host static mappings nor consume multiple public addresses. If a pool were used without overload, the router would allocate a different public IP for each concurrent session, but that is not the case here.
- ✗
It translates only traffic from 192.168.1.1 to the outside interface IP.
Why it's wrong here
The access list referenced by the NAT statement is not a host-specific match; it is a wildcard mask that permits the whole 192.168.1.0/24 network, not just 192.168.1.1/32. Even if the ACL used 'host 192.168.1.1', PAT with overload would still translate only that one host, but the correct configuration translates any source in the subnet. Therefore, saying only .1 is translated misstates the matching logic of the wildcard mask.
- ✗
The configuration is invalid because 'ip nat inside' and 'ip nat outside' are on the wrong interfaces.
Why it's wrong here
The 'ip nat inside' and 'ip nat outside' commands are placed on the correct interfaces: the LAN interface facing 192.168.1.0/24 is marked as inside, and the WAN interface with address 203.0.113.1 is marked as outside. This is the standard and required placement for NAT translation to operate bidirectionally. The configuration is therefore valid, and the error lies elsewhere if any.
Visual reference
Go deeper
Related to this question
About these practice questions
One of 1,923 original 350-401 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.