CCNA Routing and Switching Interview Questions, Updated for CCNA 200-301
Prepare for your CCNA Routing and Switching interview with our comprehensive list of 50 advanced interview questions and detailed answers. Covering essential topics such as OSPF, EIGRP, VLAN configuration, and NAT, this guide will help you showcase your networking expertise and excel in your interview.
Quick answer: CCNA Routing and Switching was retired by Cisco in February 2020. The current exam is the single CCNA 200-301, which covers network fundamentals, network access, IP connectivity, IP services, security fundamentals, and automation. This page gives 34 interview questions with model answers on those topics, including OSPF, VLANs, STP, NAT, ACLs and troubleshooting.
Key takeaways
- CCNA Routing and Switching no longer exists. Its topics moved into CCNA 200-301, so prepare for that blueprint.
- Interviewers ask for reasoning and commands. Be ready to explain a concept, write the configuration and say how you would verify it.
- Know your
showcommands. Troubleshooting questions are about method: check the physical layer first, then work up. - EIGRP is not in the 200-301 blueprint. It still appears in interviews and in the CCNP ENARSI track.
What replaced CCNA Routing and Switching?
In February 2020 Cisco merged its separate CCNA tracks (Routing and Switching, Security, Wireless, Voice, Data Center) into a single exam, CCNA 200-301. If a job post or a certificate still says "CCNA R&S", the holder certified before the change, and the skills are broadly what 200-301 covers now, with the addition of security, wireless and automation basics. Check Cisco's current exam page for the blueprint, as weightings change between versions.
The domains of 200-301 are network fundamentals, network access, IP connectivity, IP services, security fundamentals, and automation and programmability. The questions below follow that order. To study them with a trainer, see our CCNA 200-301 course.
Networking fundamentals
1. What is the difference between TCP and UDP?
TCP is connection-oriented. It sets up a session with a three-way handshake, numbers segments, retransmits losses and controls flow. UDP is connectionless and sends datagrams with no guarantee, so it has less overhead. Web, email and SSH use TCP. DNS queries, voice and video usually use UDP.
2. Walk me through the OSI and TCP/IP models and where common devices fit.
OSI has seven layers: physical, data link, network, transport, session, presentation, application. TCP/IP groups them into four or five. A hub works at Layer 1, a switch at Layer 2, a router at Layer 3, and a firewall at Layer 3 to 7 depending on type. Use troubleshooting as the example: start at the bottom.
3. How do you subnet 192.168.10.0/24 into subnets of 50 hosts each?
You need at least 6 host bits, since 2^6 minus 2 gives 62 usable hosts. That is a /26, giving four subnets of 64 addresses:.0,.64,.128 and.192. Work the block size out loud (256 minus 192 is 64). Show the network, first host, last host and broadcast for one subnet.
4. What is the difference between a public and a private IPv4 address?
Private ranges (10.0.0.0/8, 172.16.0.0/12, 192.168.0.0/16) are not routed on the internet and are reused by every organisation. Public addresses are globally unique. NAT lets private hosts reach the internet through public addresses.
5. What is an IPv6 link-local address?
It is an address in FE80::/10 used only on the local link, generated automatically on every IPv6-enabled interface. Neighbour discovery and routing protocols use it, and it is not routable beyond the segment.
6. What does ARP do?
ARP maps an IPv4 address to a MAC address on the local network. A host broadcasts an ARP request, the owner replies with its MAC address, and the host caches the result. If the destination is on another subnet, the host ARPs for its default gateway instead.
Switching
7. What does a switch do when a frame arrives?
It learns the source MAC address and port into its MAC address table. If the destination MAC is known, it forwards out that port only. If it is unknown or a broadcast, it floods out all ports in the VLAN except the one it arrived on.
8. What is a VLAN and how do you configure one?
A VLAN is a separate broadcast domain on a switch. Create it, name it and assign access ports.
vlan 10
name SALES
interface g0/1
switchport mode access
switchport access vlan 10Verify with show vlan brief.9. What is a trunk port and what is the native VLAN?
A trunk carries multiple VLANs on one link using 802.1Q tags. The native VLAN is the one sent untagged. Both ends must agree on it. Set it to an unused VLAN for security.
interface g0/24
switchport mode trunk
switchport trunk native vlan 99910. What problem does Spanning Tree solve and how does it choose a root bridge?
STP stops Layer 2 loops and broadcast storms by blocking redundant paths. The switch with the lowest bridge ID, which is priority then MAC address, becomes the root. The default priority is 32768. Set it deliberately on the switch you want as root.
11. What is the difference between STP, RSTP and Rapid PVST+?
Classic STP (802.1D) can take 30 to 50 seconds to converge. RSTP (802.1w) converges in seconds. Rapid PVST+ is Cisco's per-VLAN version of RSTP and is the usual choice on Cisco switches.
12. What is EtherChannel and what protocols can negotiate it?
EtherChannel bundles several physical links into one logical link for more bandwidth and redundancy, and STP treats it as one link. LACP (open standard) and PAgP (Cisco) negotiate it. Settings such as speed, duplex and VLANs must match on all member ports.
13. How does inter-VLAN routing work?
Hosts in different VLANs need a Layer 3 device. Options are router-on-a-stick, with subinterfaces on one trunk, or a Layer 3 switch with SVIs. Each VLAN needs its own gateway address in its own subnet.
Routing
14. What is the difference between static and dynamic routing?
Static routes are entered by hand, are predictable and cost nothing in CPU or bandwidth, but do not adapt to failures. Dynamic protocols such as OSPF learn and update routes automatically, at the cost of more configuration and overhead.
15. What is administrative distance?
It ranks the trustworthiness of route sources when several offer the same prefix. Lower wins. Connected is 0, static 1, EIGRP 90, OSPF 110, RIP 120. Metric is compared only within the same protocol.
16. What is OSPF and how does it differ from RIP?
OSPF is a link-state protocol. Each router builds a map of the area and runs Dijkstra's SPF algorithm using cost, so convergence is fast and it scales with areas. RIP is distance-vector, uses hop count with a maximum of 15 and periodic updates every 30 seconds, and suits only tiny networks.
17. How do you configure single-area OSPFv2?
Enable the process, set a router ID and advertise the interfaces.
router ospf 1
router-id 1.1.1.1
network 10.0.0.0 0.0.0.255 area 0
passive-interface g0/2Verify with show ip ospf neighbor and show ip route ospf.18. What are the OSPF neighbour states?
Down, Init, 2-Way, ExStart, Exchange, Loading and Full. Neighbours must agree on area, hello and dead timers, subnet and authentication. Stuck in 2-Way is normal between non-DR routers on a broadcast network. Stuck in ExStart often points to an MTU mismatch.
19. What are the DR and BDR in OSPF?
On multi-access networks such as Ethernet, routers form full adjacency only with a designated router and a backup, to avoid a mesh of adjacencies. They are elected by highest priority, then highest router ID.
20. Is EIGRP still on the CCNA?
EIGRP configuration is not part of the current CCNA 200-301 exam, which concentrates on OSPF and routing concepts, but many networks run EIGRP and interviewers still ask about it. Know that it is an advanced distance-vector protocol using bandwidth and delay, and that it is Cisco-origin. EIGRP sits in the CCNP ENARSI track.
21. How do you read a line in the routing table?
Example: O 10.2.0.0/24 [110/20] via 10.0.0.2, g0/0. O means OSPF, the prefix is 10.2.0.0/24, 110 is the administrative distance, 20 is the metric, and the next hop is 10.0.0.2 out g0/0. Know that the longest matching prefix wins.
IP services
22. What is NAT and what is PAT?
NAT translates one address into another, usually private to public. PAT, also called NAT overload, maps many private hosts to one public address using different port numbers.
ip nat inside source list 1 interface g0/1 overload
access-list 1 permit 192.168.1.0 0.0.0.255
interface g0/0
ip nat inside
interface g0/1
ip nat outside23. Explain how DHCP works.
DORA: Discover (client broadcast), Offer (server), Request (client) and Acknowledge (server). A relay agent, set with ip helper-address, forwards the broadcast to a DHCP server on another subnet.
24. What is a first-hop redundancy protocol?
FHRPs such as HSRP, VRRP and GLBP give hosts one virtual default gateway that survives a router failure. Know that HSRP is Cisco proprietary and VRRP is the open standard.
25. What is the purpose of NTP and syslog?
NTP keeps device clocks in step, which makes logs comparable. Syslog sends log messages to a central server. Without accurate time, correlating events across devices is guesswork.
26. What is QoS and why does voice need it?
Quality of Service marks and prioritises traffic. Voice is sensitive to delay and jitter, so it is classified, for example by DSCP EF, and sent through a priority queue.
Security
27. What is the difference between a standard and an extended ACL?
A standard ACL filters on source IP only and is placed close to the destination. An extended ACL filters on source, destination, protocol and port, and is placed close to the source. ACLs are processed top down, and an implicit deny ends every list.
ip access-list extended WEB-ONLY
permit tcp 192.168.10.0 0.0.0.255 host 10.1.1.10 eq 443
deny ip any any log
interface g0/0
ip access-group WEB-ONLY in28. How do you secure switch ports?
Use port security to limit MAC addresses, shut down unused ports and put them in an unused VLAN, and enable BPDU guard on edge ports.
interface g0/5
switchport mode access
switchport port-security
switchport port-security maximum 2
switchport port-security violation restrict29. What are DHCP snooping and Dynamic ARP Inspection?
DHCP snooping marks ports as trusted or untrusted so a rogue DHCP server cannot hand out addresses. DAI uses the snooping table to drop forged ARP replies, which protects against ARP spoofing.
30. How do you secure device access?
Use SSH, not Telnet, with local or AAA users, a strong enable secret, passwords stored with type 8 or 9 where supported, login banners and access lists on VTY lines. Disable unused services.
31. What is the difference between AAA and RADIUS or TACACS+?
AAA means authentication, authorisation and accounting. RADIUS and TACACS+ are the protocols that carry those requests to a server. TACACS+ is Cisco-originated, encrypts the whole payload and separates the three functions, which suits device administration.
Automation and programmability
32. What is the difference between a traditional and a controller-based network?
In a traditional network each device holds its own control plane and is configured one by one. In a controller-based design a central controller handles the control plane and pushes policy through APIs. Cisco DNA Center and SD-Access are examples.
33. What is a REST API and what format does it return?
A REST API uses HTTP methods (GET, POST, PUT, DELETE) on resource URLs. It commonly returns JSON. You should be able to read a small JSON object and identify keys and values.
34. What is the difference between Ansible, Puppet and Chef?
All are configuration-management tools. Ansible is agentless and uses SSH with YAML playbooks. Puppet and Chef are agent-based and use their own languages. The CCNA expects the concept, not syntax.
Troubleshooting: the method interviewers want
- Define the problem. One user or many? New or old? What changed?
- Check Layer 1. Link lights, cable, interface status with
show ip interface brief, errors withshow interfaces. - Check Layer 2. VLAN, trunk, MAC table (
show mac address-table), STP state. - Check Layer 3. IP, mask, gateway,
ping,traceroute,show ip route. - Check services and policy. ACLs, NAT, DNS, DHCP.
- Fix, verify and document.
Always say why you chose each step. A candidate who explains the order of checks scores higher than one who guesses a command.
Next steps
For more practice, read advanced CCNA interview questions and differences between RIP, OSPF, EIGRP and BGP. For EIGRP specifically, see CCNA interview questions on EIGRP.
Related reading
Frequently Asked Questions
What's Your Reaction?
Like
0
Dislike
0
Love
0
Funny
0
Wow
0
Sad
0
Angry
0