mediumMultiple Choice
350-401 Practice Question: Analyze this NAT configuration: ``` ip nat pool…
Analyze this NAT configuration: ```
ip nat pool GLOBAL 203.0.113.10 203.0.113.20 netmask 255.255.255.0 ip nat inside source list 1 pool GLOBAL overload access-list 1 permit 192.168.1.0 0.0.0.255
``` Which statement is correct?
⚠ Common exam trap
Cisco often tests the distinction between dynamic NAT (one-to-one mapping without overload) and PAT (many-to-one with overload); the trap here is that candidates may overlook the 'overload' keyword and assume each host gets a unique IP from the pool.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Traffic from 192.168.1.0/24 is translated to addresses in the range 203.0.113.10-20, using PAT.
The configuration uses a NAT pool with the 'overload' keyword, which enables Port Address Translation (PAT). Access-list 1 matches the inside local network 192.168.1.0/24, and the 'ip nat inside source list 1 pool GLOBAL overload' command translates multiple inside hosts to the pool addresses (203.0.113.10–20) using unique port numbers, allowing many hosts to share a single public IP.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Traffic from 192.168.1.0/24 is translated to addresses in the range 203.0.113.10-20, using PAT.
Why this is correct
This is correct. The ACL identifies inside source addresses 192.168.1.0/24, and the ip nat pool command creates a public address range 203.0.113.10–20. The overload keyword activates Port Address Translation, permitting many inside hosts to share those 11 addresses simultaneously by rewriting source ports, rather than requiring a one-to-one mapping.
- ✗
Each host in 192.168.1.0/24 gets a unique IP from the pool without port translation.
Why it's wrong here
Incorrect because overload enables PAT, so unique per-host addresses are not allocated. Without overload, a one-to-one dynamic NAT would assign each host a single pool address, but those 11 addresses would only support 11 concurrent inside hosts. With overload, many hosts share the same outside IP, differentiated only by transport-layer port numbers, so the statement directly contradicts the configuration.
- ✗
The pool must include the outside interface IP address.
Why it's wrong here
Incorrect because the NAT pool is an independent address range and has no requirement to include the outside interface IP. Cisco IOS allows a pool of any public addresses routed to the outside network; many deployments use a separate subnet. The outside interface address is relevant only if you use overload with 'ip nat inside source list 1 interface' rather than a pool, but including it in a pool is never mandatory.
- ✗
Access-list 1 is used to filter inbound traffic.
Why it's wrong here
Incorrect because access-list 1 is used to identify the inside local source addresses that are eligible for translation, not to filter or secure inbound traffic. Under 'ip nat inside source list 1 pool X overload', the ACL is consulted for packets leaving the inside interface, and matched addresses are translated. It plays no role in controlling inbound traffic; inbound filtering would require a separate ACL applied with 'ip access-group' on the outside interface.
Visual reference
Go deeper
Related to this question
About these practice questions
This 350-401 question is part of Courseiva's 1,923-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.