CredenTrek
Library / CCNA / Guide 07 of 8
CCNA · Practice questions

Ten CCNA scenario questions, and why the runner-up answer loses

By Mustafa K. Al-Dori · Edition 2026.2, verified 9 October 2026 · 7 min read

The short answer

Try the ten questions below in 15 minutes, counting only your first answer. They are original, not Cisco questions, and each is mapped to a v2.0 domain and topic. Then sort your misses by habit using the table at the end. If you miss three or more in one domain, give that domain extra lab hours before you book.

Candidates who fail CCNA by a few points rarely lack effort. They pick the answer that is true but not the one the scenario needs, or they read output too fast. These ten questions are built to punish both habits, and each explanation says why the runner-up loses.

How should you use these questions?

Cisco does not publish the number of questions or the pass mark, so no practice score predicts your result. A set like this one does something more useful: it shows which habits cost you marks. Answer on paper, count only your first choice and read every explanation, including those for questions you got right.

The ten questions below are original, mapped to a v2.0 domain and topic. They suit v1.1 candidates too, because each topic has a close v1.1 match. Allow 15 minutes. Facts were drawn from Cisco's exam topics and the CredenTrek book in October 2026.

For hands-on practice, build the small network from the study hours guide and check each answer at the command line.

Infrastructure and switching: five questions

Question 1 · Network Infrastructure · 1.3

A branch VLAN needs 28 hosts today and a little room for growth. Which is the smallest IPv4 subnet that fits?

A. /26
B. /27
C. /28
D. /29

Show answer
Answer: B. Topic 1.3 (v1.1 1.6 and 1.7) covers subnetting. A /27 has 5 host bits, so 32 addresses and 30 usable. A is the runner-up: a /26 works but gives 62 usable addresses, double what you need. C fails: a /28 offers only 14.

Question 2 · Network Infrastructure · 1.7

A PC on a switch port sends a DHCP request, but the DHCP server sits on another subnet behind the router. What must the router interface facing the PC have?

A. A secondary IP address on the server's subnet
B. ip helper-address pointing to the DHCP server
C. ip nat inside
D. A static route to the PC

Show answer
Answer: B. Topic 1.7 (v1.1 4.3 and 4.6) covers DHCPv4 on IOS devices. A DHCP discover is a broadcast that routers do not forward, so the interface relays it to the server with ip helper-address. A is the runner-up: a secondary address does not carry the broadcast to the server.

Question 3 · Network Infrastructure · 1.4

An interface has the MAC address 0011.2233.4455 and uses modified EUI-64 on an IPv6 prefix. What is its 64-bit interface ID?

A. 0011:22FF:FE33:4455
B. 0211:22FF:FE33:4455
C. 0211:2233:4455:FFFE
D. 0011:2233:4455:0000

Show answer
Answer: B. Topic 1.4 (v1.1 1.8 and 1.9) covers IPv6 addressing. Split the MAC in half, insert FFFE in the middle and flip the seventh bit of the first byte, so 00 becomes 02. A is the runner-up: it inserts FFFE correctly but forgets the flipped bit.

Question 4 · Switching and Network Access · 2.4

Hosts in VLAN 10 on two different switches cannot reach each other, though each host reaches its own switch. The trunk between the switches lists allowed VLANs 20 and 30 only. What is the fault?

A. VLAN 10 is not allowed on the trunk
B. The routers lack a default route
C. The hosts use different DNS servers
D. Rapid PVST+ is enabled

Show answer
Answer: A. Topic 2.4 (new in v2.0) is troubleshooting Layer 2 and Layer 3 connectivity with show commands. The trunk only carries VLANs on its allowed list, so VLAN 10 frames never cross. B is the runner-up: a default route matters for traffic leaving the VLAN, not for hosts that share one.

Question 5 · Switching and Network Access · 2.5

A user plugs a small unmanaged switch into a PortFast access port. The switch sends BPDUs, and the port should shut down at once. Which feature does that?

A. Root guard
B. BPDU guard
C. Loop guard
D. Port security

Show answer
Answer: B. Topic 2.5 (v1.1 2.5) covers Rapid PVST+ and its protections. BPDU guard err-disables an edge port that receives a BPDU. A is the runner-up: root guard reacts only to a superior BPDU and holds the port in a root-inconsistent state; it belongs on ports facing switches you manage.

Routing, services and operations: five questions

Question 6 · IP Routing · 3.1

A router learns 172.16.4.0/24 from OSPF with metric 20 and also has a static route to it with the default administrative distance. Which route enters the routing table?

A. The OSPF route, because its metric is higher
B. The static route, because its administrative distance is lower
C. Both, in a load-sharing pair
D. Neither; the router uses the default route

Show answer
Answer: B. Topic 3.1 (v1.1 3.1 and 3.2) is interpreting the routing table. A static route has administrative distance 1 and OSPF has 110, and the lowest distance wins. A is the runner-up: metrics are compared only between routes from the same source.

Question 7 · IP Routing · 3.3

Four routers share one Ethernet segment running OSPF. R1 has priority 1 and router ID 10.0.0.1. R2 has priority 1 and router ID 10.0.0.9. R3 has priority 0 and router ID 10.0.0.20. R4 has priority 100 and router ID 10.0.0.4. They all start together. Which becomes the DR?

A. R1
B. R2
C. R3
D. R4

Show answer
Answer: D. Topic 3.3 (v1.1 3.4) covers DR and BDR election. The highest priority wins, and R4 has 100. C is the runner-up: R3 has the highest router ID, but priority 0 means it can never be DR or BDR.

Question 8 · Network Services and Security · 4.6

An interface ACL has line 10: permit ip any any and line 20: deny tcp any any eq 23. A host tries to Telnet through that interface. What happens?

A. It is denied by line 20
B. It is permitted by line 10
C. It is denied because of the implicit deny
D. The router logs it and drops it

Show answer
Answer: B. Topic 4.6 (v1.1 5.6) covers IPv4 ACLs. A router reads the lines in order and stops at the first match, so line 10 permits the packet and line 20 never gets a turn. A is the runner-up: it is what the author intended, which is why order matters.

Question 9 · Network Services and Security · 4.3

A router has ip nat inside source list 1 interface GigabitEthernet0/1 overload, and access list 1 permits the LAN subnet. Clients cannot reach the internet and show ip nat translations is empty. GigabitEthernet0/1 already has ip nat outside. What is missing?

A. ip nat inside on the LAN-facing interface
B. ip nat outside on the LAN-facing interface
C. A second ACL permitting 0.0.0.0
D. ip helper-address on GigabitEthernet0/1

Show answer
Answer: A. Topic 4.3 (v1.1 4.1) covers NAT and PAT. Translation only happens when traffic enters an interface marked inside and leaves one marked outside. B is the runner-up: it marks the LAN as outside, which makes the router translate in the wrong direction.

Question 10 · AI, and Network Operations · 5.4

A device sends an unsolicited alert to the network management system when an interface fails, without waiting to be polled. What does SNMP call that message?

A. A get-request
B. A trap
C. A community string
D. A MIB

Show answer
Answer: B. Topic 5.4 (v1.1 4.4) covers what SNMP does for monitoring. A trap is sent by the device on its own; a get-request is the manager asking. D is the runner-up: a MIB defines the objects a device can report but is not itself a message.

What does your score tell you?

Count first answers only, then sort your misses by habit, which repeats across domains.

If you missed The habit to fix
1 or 3 Doing subnet and address arithmetic in your head instead of on paper
2 or 8 Knowing the feature but not where or in what order it applies
4 or 9 Reading the symptom without reading the output that explains it
5 or 10 Mixing up what a protection reacts to, or who sends a message
6 or 7 Trusting the wrong tiebreaker: metric, ID or priority

How many hours you need turns your misses into a dated plan, and the exam map explains every domain.

Chapter 5 of CredenTrek For Cisco CCNA has you rate yourself on all 29 v2.0 topics, and Appendix G adds 16 more timed questions mapped to them.

Your next step
  1. Answer all ten questions in 15 minutes, counting only your first choice.
  2. Write down the v2.0 topic behind each miss and rate yourself from 1 to 5 on it.
  3. Rebuild one missed scenario in Packet Tracer and prove the answer at the command line.
  4. Check that your practice-test source names the version you will sit and includes simulations.

Questions readers ask

Are these real CCNA exam questions?
No. They were written for this page and are not Cisco questions. Each is mapped to a v2.0 topic and its closest v1.1 topic. Use them to find weak topics, not to predict the wording you will see.
What practice-test results show I am ready?
No single score does. Look for consistent results across two or three full practice exams, no domain far behind the others and confidence in a timed simulation. Book when that pattern holds, not after one good result.
How do I choose a practice-test source?
Choose one and use it thoroughly. Check that it names your version, follows the topic list, includes labs or simulations as well as reading and states its refund policy in writing.
Do v1.1 questions still work for v2.0?
Many do, because most topics map across. A v1.1 bank still uses v1.1 weights and misses new material such as OSPFv3, named HSRP and VRRP, DNS record diagnosis and the two AI topics.
Sources

This guide is independent and is not endorsed by Cisco. Facts change: confirm them on the official page before you act.