CCNA Configuration Interview Questions and Answers (With IOS Commands)
Prepare for your CCNA interview with our comprehensive guide on configuration questions and answers. This article covers essential topics including IP address configuration, VLAN setup, NAT, DHCP, and more. Ideal for CCNA candidates seeking to master network device configuration and excel in interviews.
Quick answer: CCNA configuration interviews ask you to configure devices from memory and explain the commands. Common topics are SSH and device security, interfaces, VLANs and trunks, EtherChannel, STP, static and OSPF routing, DHCP, NAT and ACLs. For every task, give the configuration, the show command that verifies it, and the reason it works.
Key takeaways
- Use the pattern configure, verify, explain for every answer.
- Know IOS modes, saving config, SSH setup and password types.
- Be fluent in VLAN, trunk, router-on-a-stick, port security and EtherChannel commands.
- For routing, know static, default, floating static routes and single-area OSPF with wildcard masks.
- For services, know DHCP with helper addresses, PAT overload, standard and extended ACL placement.
What do CCNA configuration interviews test?
Interviewers want to see that you can configure a device from memory, explain why each command is needed and verify the result. The questions below follow the CCNA 200-301 topics: device access, interfaces, VLANs and trunks, STP, routing, DHCP, NAT, ACLs and device security. The addresses use private and documentation ranges and are for lab practice. Cisco lists the current exam topics on its certifications page.
For every configuration, practise this pattern: configure, verify, explain. Say the show command that proves it worked.
Basics and access
1. How do you move between modes on a Cisco device?
User EXEC (>), then enable for privileged EXEC (#), then configure terminal for global configuration. Use exit or end to go back.
2. How do you set a hostname and a secure privileged password?
hostname R1
enable secret StrongPass123enable secret stores a hash, while the older enable password is weak. Also use service password-encryption for line passwords.
3. How do you save and verify the configuration?
Run copy running-config startup-config (or write memory). Verify with show running-config and show startup-config. Unsaved changes are lost on reload.
4. How do you enable SSH on a Cisco device?
hostname R1
ip domain-name lab.local
crypto key generate rsa modulus 2048
username admin secret StrongPass123
line vty 0 4
transport input ssh
login local
ip ssh version 2A hostname and domain name are needed before keys can be generated.
5. How do you secure console and VTY lines?
Require login with local users, set exec-timeout, allow only SSH on VTY, and add a login banner. Example: line console 0, login local, exec-timeout 5 0.
6. How do you set a login banner?
banner motd # Authorised access only #. The delimiter can be any character not used in the text. Banners should warn against unauthorised access.
Interfaces and IP addressing
7. How do you set a static IP address on a router interface?
interface GigabitEthernet0/0
ip address 192.168.10.1 255.255.255.0
no shutdown
8. What does no shutdown do?
It brings an interface administratively up. Interfaces on routers are shut down by default. A shutdown command disables the interface.
9. How do you configure an IPv6 address?
ipv6 unicast-routing
interface GigabitEthernet0/0
ipv6 address 2001:db8:10::1/64
no shutdown2001:db8::/32 is reserved for documentation.
10. How do you set an IP address on a switch for management?
Create a switch virtual interface:
interface vlan 1
ip address 192.168.10.2 255.255.255.0
no shutdown
ip default-gateway 192.168.10.1
11. How do you verify interface configuration?
show ip interface brief, show interfaces and show running-config interface <name>.
Switching
12. How do you create a VLAN and assign a port?
vlan 10
name SALES
interface FastEthernet0/5
switchport mode access
switchport access vlan 10Verify with show vlan brief.
13. How do you configure a trunk?
interface GigabitEthernet0/1
switchport mode trunk
switchport trunk allowed vlan 10,20
switchport trunk native vlan 99On some switches you must first run switchport trunk encapsulation dot1q.
14. How do you configure inter-VLAN routing with router-on-a-stick?
interface GigabitEthernet0/0.10
encapsulation dot1Q 10
ip address 192.168.10.1 255.255.255.0
interface GigabitEthernet0/0
no shutdownThe switch port toward the router must be a trunk.
15. How do you configure port security?
interface FastEthernet0/5
switchport mode access
switchport port-security
switchport port-security maximum 2
switchport port-security mac-address sticky
switchport port-security violation shutdown
16. How do you create an EtherChannel with LACP?
interface range GigabitEthernet0/1 - 2
channel-group 1 mode active
interface port-channel 1
switchport mode trunkBoth ends must use compatible modes, and ports must match in speed, duplex and VLAN settings.
17. How do you change the spanning tree root?
spanning-tree vlan 1 root primary or set a lower priority with spanning-tree vlan 1 priority 4096. Verify with show spanning-tree.
18. How do you enable PortFast and BPDU Guard?
On access ports: spanning-tree portfast and spanning-tree bpduguard enable. PortFast skips listening and learning states, and BPDU Guard shuts the port if a BPDU arrives.
Routing
19. How do you configure a static route and a default route?
ip route 10.1.1.0 255.255.255.0 192.168.10.2
ip route 0.0.0.0 0.0.0.0 192.168.10.2
20. How do you configure OSPF for a single area?
router ospf 1
router-id 1.1.1.1
network 192.168.10.0 0.0.0.255 area 0
passive-interface GigabitEthernet0/1Verify with show ip ospf neighbor and show ip route ospf.
21. What is a wildcard mask?
The inverse of a subnet mask used in OSPF network statements and ACLs. The mask 255.255.255.0 gives wildcard 0.0.0.255, where 0 means "must match" and 1 means "ignore".
22. How do you configure a floating static route?
Add a static route with a higher administrative distance, such as ip route 10.1.1.0 255.255.255.0 192.168.20.2 150, so it is used only if the preferred route disappears.
23. How do you configure first hop redundancy with HSRP?
interface GigabitEthernet0/0
ip address 192.168.10.2 255.255.255.0
standby 1 ip 192.168.10.1
standby 1 priority 110
standby 1 preemptHosts use the virtual address as their default gateway.
Services and security
24. How do you configure a DHCP server on a router?
ip dhcp excluded-address 192.168.10.1 192.168.10.10
ip dhcp pool LAN10
network 192.168.10.0 255.255.255.0
default-router 192.168.10.1
dns-server 8.8.8.8Verify with show ip dhcp binding. For clients on another subnet, add ip helper-address.
25. How do you configure PAT (NAT overload)?
access-list 1 permit 192.168.10.0 0.0.0.255
ip nat inside source list 1 interface GigabitEthernet0/1 overload
interface GigabitEthernet0/0
ip nat inside
interface GigabitEthernet0/1
ip nat outside
26. How do you create and apply a standard ACL?
access-list 10 permit 192.168.10.0 0.0.0.255
interface GigabitEthernet0/1
ip access-group 10 outStandard ACLs filter by source only and are placed close to the destination.
27. How do you create an extended named ACL?
ip access-list extended BLOCK-TELNET
deny tcp any any eq 23
permit ip any any
interface GigabitEthernet0/0
ip access-group BLOCK-TELNET inExtended ACLs match protocol, source, destination and port and are placed close to the source.
28. How do you configure NTP and syslog?
ntp server 192.168.10.5 for time and logging host 192.168.10.6 for syslog. Verify with show ntp status and show logging.
29. How do you back up a configuration?
Copy it to a TFTP or SCP server, for example copy running-config tftp:, and store versions with comments. Keep backups off the device and protected.
A short full-lab practice
Build this in Packet Tracer or on lab gear, then explain each step aloud: two VLANs (10 and 20) on a switch, a trunk to a router using router-on-a-stick, a DHCP pool per VLAN, a default route to an "ISP" router, PAT on the outside interface, an ACL that blocks VLAN 20 from reaching VLAN 10 management addresses and SSH-only access to the router. When it works, break it on purpose (wrong native VLAN, missing helper address) and fix it using show commands.
Common mistakes in configuration interviews
- Forgetting
no shutdownor saving the configuration. - Using a subnet mask where a wildcard mask is needed.
- Applying an ACL in the wrong direction or on the wrong interface.
- Not mentioning how you would verify.
- Typing from memory without explaining the reasoning.
Next steps
Practise each configuration until you can type it without notes. Our CCNA 200-301 course includes lab work. See also CCNA interview questions on router configuration and top 10 CCNA interview questions.
Related reading
Frequently Asked Questions
What's Your Reaction?
Like
0
Dislike
0
Love
0
Funny
0
Wow
0
Sad
0
Angry
0