200-301 Sample Questions & Answers
IP connectivity and routing-table forwarding carry the most weight, alongside network components and topology types, VLANs and Layer 2 discovery protocols, NAT, NTP, DHCP and DNS services, local device-access security, and controller-based automation.
Launch the full 200-301 simulator →Showing 11 of 23 free samples.
- Question 1
Which of the following accurately describes the purpose of a trunk?
Show answer & explanation
Correct answer: C
Trunk links are designed to carry traffic for multiple VLANs simultaneously between network infrastructure devices, primarily switches. Trunking uses frame tagging protocols like IEEE 802.1Q or ISL (Inter-Switch Link) to identify which VLAN each frame belongs to as it traverses the trunk link. This enables hosts in the same VLAN but connected to different switches to communicate while maintaining VLAN isolation for security and broadcast domain separation. Trunk links are essential in multi-switch environments for extending VLANs across the network infrastructure. Without trunking, each VLAN would require a separate physical link between switches, making large VLAN deployments impractical and expensive.
- Question 2
Which Ethernet LAN contention or access method listens for a signal on the channel before transmitting data, and stops transmitting if a collision is detected?
Show answer & explanation
Correct answer: B
Carrier Sense Multiple Access with Collision Detection (CSMA/CD) is the fundamental access method used in traditional Ethernet networks operating in half-duplex mode. The protocol requires devices to listen to the transmission medium before sending data (carrier sense), allows multiple devices to access the medium (multiple access), and stops transmission immediately when a collision is detected (collision detection). Upon detecting a collision, devices execute a binary exponential backoff algorithm, waiting a random time period before retransmitting. Modern full-duplex Ethernet eliminates collisions by providing separate transmit and receive paths, making CSMA/CD unnecessary in switched environments. However, understanding CSMA/CD remains crucial for troubleshooting legacy networks and hub-based segments.
- Question 3Select 4
What will be the effects of executing the following set of commands? (Choose all that apply.)
router(config)# router eigrp 44
router (config-router)# network 10.0.0.0
router (config-router)# network 192.168.5.0Show answer & explanation
Correct answers: A, C, D, E
The router eigrp 44 command enables Enhanced Interior Gateway Routing Protocol (EIGRP) in Autonomous System (AS) 44, creating a routing process that will form adjacencies with other EIGRP routers in the same AS. The AS number is a logical identifier that must match between routers for adjacency formation and route exchange. EIGRP uses the AS number to identify routing domains and prevent inadvertent route advertisement between different administrative domains. Multiple EIGRP processes can run simultaneously on a single router using different AS numbers. The AS number also affects metric calculation and route tagging in enterprise networks with complex routing policies and redistribution requirements.
The network 10.0.0.0 command activates EIGRP on all interfaces with IP addresses in the 10.0.0.0/8 network range, using classful network boundaries by default. Any interface matching this network statement will begin sending EIGRP hello packets, attempting to form adjacencies with neighboring EIGRP routers, and advertising connected networks. EIGRP uses wildcard masks (similar to OSPF) for precise network matching, but when omitted, it assumes classful boundaries. Interfaces activated for EIGRP will participate in the DUAL (Diffusing Update Algorithm) for loop-free routing calculations. The network statement also determines which networks are advertised to EIGRP neighbors, making it crucial for route propagation and reachability.
The network 192.168.5.0 command enables EIGRP on interfaces within the 192.168.5.0/24 network range, activating neighbor discovery and route advertisement for this subnet. EIGRP will begin sending multicast hello packets (224.0.0.10) on matching interfaces to discover adjacent EIGRP routers. Once adjacencies form, the router will advertise this network to EIGRP neighbors and receive topology updates for optimal path calculation. The Diffusing Update Algorithm (DUAL) will calculate feasible successors and backup routes for resilient routing. Interface-specific EIGRP parameters like hello intervals, hold times, and authentication can be configured per interface for fine-tuned neighbor relationships and convergence behavior.
Any interface with an IP address in the 10.0.5.8/16 range would be activated for EIGRP due to the network 10.0.0.0 statement, as this address falls within the Class A 10.0.0.0/8 network range. EIGRP performs classful network matching by default unless wildcard masks are specified, so the 10.0.0.0 statement encompasses all subnets within the 10.x.x.x address space. This interface would participate in EIGRP neighbor discovery, topology exchange, and route calculation processes. The DUAL algorithm would calculate metric values based on bandwidth and delay by default, with options for load and reliability inclusion. Proper subnet design and summarization become critical when activating EIGRP across large Class A networks to prevent routing table bloat.
- Question 4
Users on the LAN are unable to access the Internet. How would you correct the immediate problem?
Router# show ip interface brief
Interface IP-Address OK? Method Status
Protocol FastEthernet 0/0 unassigned YES
unset down down FastEthernet 0/1
172.16.1.254 YES NVRAM up up
Serial0/0 200.16.4.25 YES NVRAM administratively down
down Serial0/1 unassigned YES
unset down down
Show answer & explanation
Correct answer: B
Explanation:
The output indicates that the serial interface leading to the Internet is administratively down. All router interfaces are disabled by default due to the presence of a shutdown command in the running configuration. The no shutdown command removes this configuration, and the interface becomes active. The command sequence is:
Router(config)# interface serial0/0 Router(config-if)# no shutdown
Although it was not the problem in the scenario, the S0/0 interface could also cause an error if it is configured as shown in this output:
Interface IP-Address OK? Method Status Protocol Serial0/0 200.16.4.25 YES NVRAM up down
In this example, the S0/0 interface has been enabled, and while there is Layer 1 connectivity (the Status column), Layer 2 is not functioning (the Protocol column). There are two possible reasons for this result:Configuring a bandwidth on the serial interface is incorrect because the output indicates the interface is administratively down, which does not pertain to bandwidth.
Configuring a private IP address on the Fastethernet0/0 LAN interface is incorrect because the output indicates the problem is with the disabled serial interface.
The IP address on the serial interface may or may not be valid, but it is not the immediate cause of the connectivity problem. The serial interface is disabled.
Objective:
LAN Switching Fundamentals Sub-Objective:
Troubleshoot interface and cable issues (collisions, errors, duplex, speed)References:
Cisco > Support > Administrative Commands > shutdown
- Question 5
When a packet is forwarded through a network from one host to another host, which of the following fields in the Ethernet frame will change at every hop?
Show answer & explanation
Correct answer: B
When packets traverse routers between different network segments, the destination MAC address changes at each hop to reflect the next-hop MAC address required for Layer 2 forwarding. Initially, the destination MAC is the local router default gateway MAC, then it becomes the next-hop router MAC for inter-router communication, and finally the destination host MAC on the target segment. This MAC address rewriting is essential for proper frame delivery as MAC addresses only have significance within individual collision domains. Routers strip and rebuild Ethernet headers for each network segment while preserving Layer 3 IP addresses throughout the routing process. Understanding MAC address changes during routing is fundamental to troubleshooting connectivity issues across routed networks.
- Question 6
Which Cisco IOS Cisco Discovery Protocol (CDP) command displays the IP address of the directly connected Cisco devices?
Show answer & explanation
Correct answer: D
References:
Cisco > Cisco IOS Network Management Command Reference > schema through show event manager session cli username > show cdp neighbors detail
- Question 7
Your assistant is interested in gathering statistics about connection-oriented operations.
Which of the following should be done to enhance the accuracy of the information gathered?Show answer & explanation
Correct answer: A
Any IP SLA operations accuracy can be enhanced by configure an IP SLA responder on the destination device. It is important to note that only Cisco devices support the configuration as a responder.
You do not configure an IP SLA responder on the source device. You schedule the operation on the source device and the destination device is the one that is configured as a responder.
You do not schedule the operation on the destination device. You schedule the operation on the
source device and the destination device is the one that is configured as a responder.
Adding the verify-data command to the configuration of the operation will not enhance the accuracy of the information gathered. When data verification is enabled, each operation response is checked for corruption. Use the verify-data command with caution during normal operations because it generates unnecessary overhead.
Objective:
Infrastructure Management Sub-Objective:
Troubleshoot network connectivity issues using ICMP echo-based IP SLAReferences:
IP SLAs Configuration Guide, Cisco IOS Release 15M > Configuring IP SLAs TCP Connect Operations
- Question 8
You are the network administrator for your company. You have installed a new router in your network. You want to establish a remote connection from your computer to the new router so it can be configured. You are not concerned about security during the remote connection.
Which Cisco IOS command should you use to accomplish the task?
Show answer & explanation
Correct answer: B
Explanation:
The telnet command should be used to establish a remote connection from your computer to the router. The syntax of the command is as follows:
telnet {hostname | IP_address mask interface_name} | {IPv6_address interface_name} |
{timeoutnumber}The following parameters are used with the telnet command: hostname: Specifies the name of the host.
interface_name: Specifies the name of the network interface to which you need to telnet. IP_address: Specifies the IP address of the host.
IPv6_address: Specifies the IPv6 address associated to the host.timeout number: Specifies the number of minutes that a telnet session can be idle. The following features are the key characteristics of Telnet:
The ssh command is incorrect because this command is used to remotely establish a secure connection between two computers over the network.The terminal command is incorrect because this command is used to change console terminal settings.
The virtual command is incorrect because this command is used along with the http and telnet parameters to configure a virtual server.
Objective:
Infrastructure Management Sub-Objective:
Configure and verify device managementReferences:
Cisco > Cisco IOS Terminal Services Command Reference > telnet
- Question 9
You are configuring a WAN connection between two offices. You cannot ping between the routers in a test. The Serial0 interface on RouterA is connected to the Serial1 interface on RouterB.
The commands you have executed are shown below. What is the problem with the configuration?

Show answer & explanation
Correct answer: C
Based on the configuration shown in the image, RouterB has been configured with PPP authentication commands on interface Serial0, but the physical connection uses Serial1 on RouterB connecting to Serial0 on RouterA. This interface mismatch means the authentication configuration is applied to the wrong interface, preventing the PPP link establishment and subsequent connectivity. WAN point-to-point links require authentication parameters to be configured on the correct physical interfaces to establish the Layer 2 connection before IP connectivity can function. The PPP encapsulation, usernames, and passwords appear correctly configured, but they must be applied to the Serial1 interface on RouterB to match the physical topology.
- Question 10
Which Cisco 2950 switch command or set of commands would be used to create a Virtual LAN (VLAN) named MARKETING with a VLAN number of 25?
Show answer & explanation
Correct answer: B
The correct VLAN creation sequence uses the global configuration command "vlan 25" followed by the VLAN configuration submode command "name MARKETING". This creates VLAN 25 and assigns it the descriptive name MARKETING for network documentation and management purposes. Modern Cisco switches store VLAN configuration in the VLAN database (vlan.dat file) rather than the running configuration for IOS-based switches. The VLAN configuration mode (config-vlan) provides additional parameters including state (active/suspend), MTU size, and SAID values for advanced VLAN management. Once created, ports can be assigned to this VLAN using switchport access vlan 25 commands in interface configuration mode.
- Question 11
What command would be used to verify trusted DHCP ports?
Show answer & explanation
Correct answer: B
The show ip dhcp snooping command displays the DHCP snooping configuration and status, including which ports are configured as trusted or untrusted for DHCP traffic. DHCP snooping is a security feature that prevents rogue DHCP servers by allowing DHCP responses only from trusted ports while blocking unauthorized DHCP offers from untrusted ports. Trusted ports typically connect to legitimate DHCP servers or upstream network infrastructure, while access ports connecting to end-user devices remain untrusted. This command output shows the DHCP snooping database entries, binding table information, and security violation statistics, making it essential for troubleshooting DHCP-related connectivity issues and security policy enforcement.
Ready for the real thing?
The full 200-301 simulator has every exam-style question, timed mode, and instant scoring.