Free Practice Questions for Cisco CCNA Certification

    🔄 Last checked for updates June 30th, 2026

    Study with 346 exam-style practice questions designed to help you prepare for the Cisco CCNA. All questions are aligned with the latest exam guide and include detailed explanations to help you master the material.

    Start Practicing

    All Domains

    Practice with randomly mixed questions from all topics

    Question MixAll Topics
    FormatRandom Order

    Domain Mode

    Practice questions from a specific topic area

    Quiz History

    Exam Details

    Key information about Cisco CCNA

    Official study guide

    View

    Question formats CertSafari offers
    • Multiple choice
    • Matching
    • Fill in the blank
    exam code:

    200-301

    course preparation:

    Implementing and Administering Cisco Solutions (CCNA)

    time limit minutes:

    120

    associated certification:

    CCNA certification

    Exam Topics & Skills Assessed

    Skills measured (from the official study guide)

    Domain 1: Network Fundamentals

    Subdomain 1.1: Explain the role and function of network components

    Explain the role and function of network components: - Routers - Layer 2 and Layer 3 switches - Next-generation firewalls and IPS - Access points - Controllers - Endpoints - Servers - PoE

    Subdomain 1.2: Describe characteristics of network topology architectures

    Describe characteristics of network topology architectures: - Two-tier - Three-tier - Spine-leaf - WAN - Small office/home office (SOHO) - On-premises and cloud

    Subdomain 1.3: Compare physical interface and cabling types

    Compare physical interface and cabling types: - Single-mode fiber, multimode fiber, copper - Connections (Ethernet shared media and point-to-point)

    Subdomain 1.4: Identify interface and cable issues (collisions, errors, mismatch duplex, and/or speed)

    Identify interface and cable issues (collisions, errors, mismatch duplex, and/or speed).

    Subdomain 1.5: Compare TCP to UDP

    Compare TCP to UDP.

    Subdomain 1.6: Configure and verify IPv4 addressing and subnetting

    Configure and verify IPv4 addressing and subnetting.

    Subdomain 1.7: Describe private IPv4 addressing

    Describe private IPv4 addressing.

    Subdomain 1.8: Configure and verify IPv6 addressing and prefix

    Configure and verify IPv6 addressing and prefix.

    Subdomain 1.9: Describe IPv6 address types

    Describe IPv6 address types: - Unicast (global, unique local, and link local) - Anycast - Multicast - Modified EUI 64

    Subdomain 1.10: Verify IP parameters for Client OS (Windows, Mac OS, Linux)

    Verify IP parameters for Client OS (Windows, Mac OS, Linux).

    Subdomain 1.11: Describe wireless principles

    Describe wireless principles: - Nonoverlapping Wi-Fi channels - SSID - RF - Encryption

    Subdomain 1.12: Explain virtualization fundamentals (server virtualization, containers, and VRFs)

    Explain virtualization fundamentals (server virtualization, containers, and VRFs).

    Subdomain 1.13: Describe switching concepts

    Describe switching concepts: - MAC learning and aging - Frame switching - Frame flooding - MAC address table

    Domain 2: Network Access

    Subdomain 2.1: Configure and verify VLANs (normal range) spanning multiple switches

    Configure and verify VLANs (normal range) spanning multiple switches: - Access ports (data and voice) - Default VLAN - InterVLAN connectivity

    Subdomain 2.2: Configure and verify interswitch connectivity

    Configure and verify interswitch connectivity: - Trunk ports - 802.1Q - Native VLAN

    Subdomain 2.3: Configure and verify Layer 2 discovery protocols (Cisco Discovery Protocol and LLDP)

    Configure and verify Layer 2 discovery protocols (Cisco Discovery Protocol and LLDP).

    Subdomain 2.4: Configure and verify (Layer 2/Layer 3) EtherChannel (LACP)

    Configure and verify (Layer 2/Layer 3) EtherChannel (LACP).

    Subdomain 2.5: Interpret basic operations of Rapid PVST+ Spanning Tree Protocol

    Interpret basic operations of Rapid PVST+ Spanning Tree Protocol: - Root port, root bridge (primary/secondary), and other port names - Port states and roles - PortFast - Root guard, loop guard, BPDU filter, and BPDU guard

    Subdomain 2.6: Describe Cisco Wireless Architectures and AP modes

    Describe Cisco Wireless Architectures and AP modes.

    Subdomain 2.7: Describe physical infrastructure connections of WLAN components (AP, WLC, access/trunk ports, and LAG)

    Describe physical infrastructure connections of WLAN components (AP, WLC, access/trunk ports, and LAG).

    Subdomain 2.8: Describe network device management access (Telnet, SSH, HTTP, HTTPS, console, TACACS+/RADIUS, and cloud managed)

    Describe network device management access (Telnet, SSH, HTTP, HTTPS, console, TACACS+/RADIUS, and cloud managed).

    Subdomain 2.9: Interpret the wireless LAN GUI configuration for client connectivity, such as WLAN creation, security settings, QoS profiles, and advanced settings

    Interpret the wireless LAN GUI configuration for client connectivity, such as WLAN creation, security settings, QoS profiles, and advanced settings.

    Domain 3: IP Connectivity

    Subdomain 3.1: Interpret the components of routing table

    Interpret the components of routing table: - Routing protocol code - Prefix - Network mask - Next hop - Administrative distance - Metric - Gateway of last resort

    Subdomain 3.2: Determine how a router makes a forwarding decision by default

    Determine how a router makes a forwarding decision by default: - Longest prefix match - Administrative distance - Routing protocol metric

    Subdomain 3.3: Configure and verify IPv4 and IPv6 static routing

    Configure and verify IPv4 and IPv6 static routing: - Default route - Network route - Host route - Floating static

    Subdomain 3.4: Configure and verify single area OSPFv2

    Configure and verify single area OSPFv2: - Neighbor adjacencies - Point-to-point - Broadcast (DR/BDR selection) - Router ID

    Subdomain 3.5: Describe the purpose, functions, and concepts of first hop redundancy protocols

    Describe the purpose, functions, and concepts of first hop redundancy protocols.

    Domain 4: IP Services

    Subdomain 4.1: Configure and verify inside source NAT using static and pools

    Configure and verify inside source NAT using static and pools.

    Subdomain 4.2: Configure and verify NTP operating in a client and server mode

    Configure and verify NTP operating in a client and server mode.

    Subdomain 4.3: Explain the role of DHCP and DNS within the network

    Explain the role of DHCP and DNS within the network.

    Subdomain 4.4: Explain the function of SNMP in network operations

    Explain the function of SNMP in network operations.

    Subdomain 4.5: Describe the use of syslog features, including facilities and severity levels

    Describe the use of syslog features, including facilities and severity levels.

    Subdomain 4.6: Configure and verify DHCP client and relay

    Configure and verify DHCP client and relay.

    Subdomain 4.7: Explain the forwarding per-hop behavior (PHB) for QoS such as classification, marking, queuing, congestion, policing, and shaping

    Explain the forwarding per-hop behavior (PHB) for QoS such as classification, marking, queuing, congestion, policing, and shaping.

    Subdomain 4.8: Configure network devices for remote access using SSH

    Configure network devices for remote access using SSH.

    Subdomain 4.9: Describe the capabilities and functions of TFTP/FTP in the network

    Describe the capabilities and functions of TFTP/FTP in the network.

    Domain 5: Security Fundamentals

    Subdomain 5.1: Define key security concepts (threats, vulnerabilities, exploits, and mitigation techniques)

    Define key security concepts (threats, vulnerabilities, exploits, and mitigation techniques).

    Subdomain 5.2: Describe security program elements (user awareness, training, and physical access control)

    Describe security program elements (user awareness, training, and physical access control).

    Subdomain 5.3: Configure and verify device access control using local passwords

    Configure and verify device access control using local passwords.

    Subdomain 5.4: Describe security password policy elements, such as management, complexity, and password alternatives (multifactor authentication, certificates, and biometrics)

    Describe security password policy elements, such as management, complexity, and password alternatives (multifactor authentication, certificates, and biometrics).

    Subdomain 5.5: Describe IPsec remote access and site-to-site VPNs

    Describe IPsec remote access and site-to-site VPNs.

    Subdomain 5.6: Configure and verify access control lists

    Configure and verify access control lists.

    Subdomain 5.7: Configure and verify Layer 2 security features (DHCP snooping, dynamic ARP inspection, and port security)

    Configure and verify Layer 2 security features (DHCP snooping, dynamic ARP inspection, and port security).

    Subdomain 5.8: Compare authentication, authorization, and accounting concepts

    Compare authentication, authorization, and accounting concepts.

    Subdomain 5.9: Describe wireless security protocols (WPA, WPA2, and WPA3)

    Describe wireless security protocols (WPA, WPA2, and WPA3).

    Subdomain 5.10: Configure and verify WLAN within the GUI using WPA2 PSK

    Configure and verify WLAN within the GUI using WPA2 PSK.

    Domain 6: Automation and Programmability

    Subdomain 6.1: Explain how automation impacts network management

    Explain how automation impacts network management.

    Subdomain 6.2: Compare traditional networks with controller-based networking

    Compare traditional networks with controller-based networking.

    Subdomain 6.3: Describe controller-based, software defined architecture (overlay, underlay, and fabric)

    Describe controller-based, software defined architecture (overlay, underlay, and fabric): - Separation of control plane and data plane - Northbound and Southbound APIs

    Subdomain 6.4: Explain AI (generative and predictive) and machine learning in network operations

    Explain AI (generative and predictive) and machine learning in network operations.

    Subdomain 6.5: Describe characteristics of REST-based APIs (authentication types, CRUD, HTTP verbs, and data encoding)

    Describe characteristics of REST-based APIs (authentication types, CRUD, HTTP verbs, and data encoding).

    Subdomain 6.6: Recognize the capabilities of configuration management mechanisms such as Ansible and Terraform

    Recognize the capabilities of configuration management mechanisms such as Ansible and Terraform.

    Subdomain 6.7: Recognize components of JSON-encoded data

    Recognize components of JSON-encoded data.

    Techniques & products

    Routers
    Layer 2 switches
    Layer 3 switches
    Next-generation firewalls
    IPS
    Access points
    Controllers
    Endpoints
    Servers
    PoE
    Two-tier architecture
    Three-tier architecture
    Spine-leaf architecture
    WAN
    SOHO
    On-premises
    Cloud
    Single-mode fiber
    Multimode fiber
    Copper cabling
    Ethernet
    TCP
    UDP
    IPv4 addressing
    Subnetting
    Private IPv4 addressing
    IPv6 addressing
    IPv6 prefix
    Unicast
    Anycast
    Multicast
    Modified EUI 64
    Windows OS
    Mac OS
    Linux OS
    Wi-Fi channels
    SSID
    RF
    Wireless encryption
    Server virtualization
    Containers
    VRFs
    MAC learning
    MAC aging
    Frame switching
    Frame flooding
    MAC address table
    VLANs
    Access ports
    Voice VLAN
    Default VLAN
    InterVLAN connectivity
    Trunk ports
    802.1Q
    Native VLAN
    Cisco Discovery Protocol (CDP)
    LLDP
    EtherChannel
    LACP
    Rapid PVST+
    Spanning Tree Protocol
    Root port
    Root bridge
    PortFast
    Root guard
    Loop guard
    BPDU filter
    BPDU guard
    Cisco Wireless Architectures
    AP modes
    Wireless LAN Controller (WLC)
    Link Aggregation Group (LAG)
    Telnet
    SSH
    HTTP
    HTTPS
    Console access
    TACACS+
    RADIUS
    Cloud managed networks
    WLAN GUI configuration
    QoS profiles
    Routing table components
    Routing protocol code
    Prefix
    Network mask
    Next hop
    Administrative distance
    Metric
    Gateway of last resort
    Longest prefix match
    Static routing
    Default route
    Network route
    Host route
    Floating static route
    OSPFv2
    Neighbor adjacencies
    DR/BDR selection
    Router ID
    First hop redundancy protocols
    Network Address Translation (NAT)
    Static NAT
    NAT pools
    NTP client
    NTP server
    DHCP
    DNS
    SNMP
    Syslog
    QoS (Quality of Service)
    Classification
    Marking
    Queuing
    Congestion
    Policing
    Shaping
    TFTP
    FTP
    Security threats
    Vulnerabilities
    Exploits
    Mitigation techniques
    User awareness
    Security training
    Physical access control
    Local passwords
    Password policy management
    Password complexity
    Multifactor authentication (MFA)
    Certificates
    Biometrics
    IPsec VPNs
    Remote access VPNs
    Site-to-site VPNs
    Access Control Lists (ACLs)
    DHCP snooping
    Dynamic ARP inspection
    Port security
    Authentication
    Authorization
    Accounting (AAA)
    WPA
    WPA2
    WPA3
    WPA2 PSK
    Network automation
    Controller-based networking
    Software Defined Architecture (SDA)
    Overlay
    Underlay
    Fabric
    Control plane
    Data plane
    Northbound APIs
    Southbound APIs
    Artificial Intelligence (AI)
    Generative AI
    Predictive AI
    Machine learning
    REST-based APIs
    CRUD operations
    HTTP verbs
    Data encoding
    Ansible
    Terraform
    JSON-encoded data

    CertSafari is not affiliated with, endorsed by, or officially connected to Cisco Systems, Inc.. Full disclaimer