Courseiva
hardMultiple Choice

350-401 Practice Question: Issues the following command on Router R6: R6#…

A network engineer issues the following command on Router R6:

R6# show ip nat translations

Pro Inside global Inside local Outside local Outside global --- 192.168.1.100 10.0.0.10 --- --- --- 192.168.1.101 10.0.0.11 --- --- udp 192.168.1.100:1234 10.0.0.10:1234 203.0.113.5:53 203.0.113.5:53 tcp 192.168.1.101:80 10.0.0.11:80 198.51.100.2:443 198.51.100.2:443

Based on this output, what is true about the NAT translations?

⚠ Common exam trap

Cisco often tests the distinction between dynamic NAT without PAT and PAT by showing entries with and without port numbers, leading candidates to mistakenly assume all entries are PAT or all are static when the output contains a mix.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The translation for 10.0.0.10 to 192.168.1.100 is a dynamic NAT without PAT.

The output shows two static-like entries (the first two lines with no protocol or port) and two dynamic entries with PAT (the UDP and TCP lines). The first translation for 10.0.0.10 to 192.168.1.100 has no protocol or port information, indicating it is a dynamic NAT entry without PAT (port address translation), because PAT would show specific ports. Option B correctly identifies this translation as dynamic NAT without PAT.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    All translations are static NAT entries.

    Why it's wrong here

    Static NAT entries are manually configured and persist in the translation table indefinitely, regardless of traffic. The provided output shows no such persistence evidence: every entry is accompanied by an idle timer context, and several entries carry TCP/UDP port numbers, which static NAT never creates. Static NAT would never mix port-based translations with portless ones, so the statement that all translations are static is false.

  • ✓

    The translation for 10.0.0.10 to 192.168.1.100 is a dynamic NAT without PAT.

    Why this is correct

    The translation for 10.0.0.10 to 192.168.1.100 appears in the show ip nat translations output without any protocol or port information, meaning the mapping is a pure IP-to-IP rewrite. That is the signature of a dynamic NAT translation taken from a pool without the overload keyword, not a PAT entry. It is dynamic because the router instantiated it on the first packet from 10.0.0.10 and will remove it after the idle timeout expires, unlike a static entry that is always present.

  • ✗

    The router is performing only PAT (overload).

    Why it's wrong here

    If the router were performing only PAT (overload), every translation would include a protocol field and port numbers in the inside local/inside global columns, because PAT multiplexes many inside hosts onto a single outside address. The output, however, contains a portless one-to-one translation for 10.0.0.10, which cannot occur with pure PAT. Additionally, the outside global addresses are not all the same; a single overloaded interface would reuse one public IP for all translations, so the observed diversity of outside global addresses contradicts this option.

  • ✗

    The outside global address is the same for all translations.

    Why it's wrong here

    The translation table clearly lists different outside global addresses: 203.0.113.5 is used in some entries, while 198.51.100.2 appears in others. If every translation shared the same outside global address, the configuration would have to be a single-address pool or one overloaded interface. Since the output shows at least two distinct outside global addresses, the statement that the outside global address is the same for all translations is incorrect.

Visual reference

Inside (Private) PC-A 10.0.0.1 PC-B 10.0.0.2 NAT Router Outside (Public) 203.0.113.1 Inside Global Server PAT: many private IPs share one public IP via unique port numbers

About these practice questions

This 350-401 question is part of Courseiva's 1,923-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.