CCNA Troubleshooting Interview Questions and Answers (With Commands)

Explore essential CCNA troubleshooting interview questions and answers designed for 2024. This comprehensive guide covers a range of troubleshooting scenarios including OSPF issues, VLAN problems, DNS resolution, and more. Perfect for candidates preparing for CCNA interviews or network professionals seeking to enhance their troubleshooting skills.

Aug 14, 2024 - 10:30
Updated: 8 days ago
105.4k
CCNA Troubleshooting Interview Questions and Answers (With Commands)

Quick answer: CCNA troubleshooting interviews test your method more than memorised facts. Expect symptom-based questions about interfaces, VLANs and trunks, spanning tree, routing and OSPF, DHCP, NAT and ACLs. Answer by naming the layer to test, the show command you would run, what output confirms the cause, and how you would verify the fix.

Key takeaways

  • Use a structured method: define the problem, test by layer, change one thing at a time, verify and document.
  • Know the core show commands: ip interface brief, interfaces, vlan brief, interfaces trunk, ip route, ip ospf neighbor, access-lists.
  • Typical faults: duplex mismatch, native VLAN mismatch, OSPF timers or MTU, missing helper-address, ACL or NAT misapplied.
  • Always say how you would verify the fix.
  • Practise on a simulator so the commands come naturally.

How do CCNA troubleshooting interviews work?

Interviewers rarely want a memorised list. They give a symptom and watch your method: what you ask, which command you run first and how you narrow the cause. Practise answering aloud in the order symptom, hypothesis, command, result, fix. The questions below follow the Cisco CCNA (200-301) blueprint topics: interfaces and switching, IP connectivity, OSPF, services such as DHCP, NAT and ACLs, and security basics. Cisco publishes the exam topics on its certifications page.

Commands to know by heart

TaskCommand
Interface summaryshow ip interface brief
Interface errors and duplexshow interfaces <int>
VLANs and trunksshow vlan brief, show interfaces trunk
MAC and ARP tablesshow mac address-table, show ip arp
Routingshow ip route, show ip protocols
OSPFshow ip ospf neighbor, show ip ospf interface
Spanning treeshow spanning-tree
ACL and NATshow access-lists, show ip nat translations
Neighboursshow cdp neighbors detail

Method

1. What is your general approach to troubleshooting a network problem?

Define the problem, gather facts, find the layer, form a hypothesis, test one change at a time, confirm the fix and document it. Using the OSI or TCP/IP model gives structure: start at the physical layer and move up, or start at the application and move down.

2. Bottom-up, top-down or divide and conquer: which do you choose?

Bottom-up suits suspected cable or interface issues. Top-down suits a single failing application. Divide and conquer starts at the middle, for example a ping to the gateway, and moves up or down depending on the result. Say which you chose and why.

3. A user says "the network is down". What is your first question?

Ask what exactly fails, since when, who else is affected and what changed. Then test from the user's side: IP address, default gateway, DNS and reachability.

Layer 1 and 2

4. What does "interface up, line protocol down" mean?

The physical signal is detected but Layer 2 is not working. Common causes are a mismatched encapsulation, no keepalives from the other end, a clocking issue on serial links or a duplex or speed problem.

5. What does "administratively down" mean and how do you fix it?

The interface was shut down by configuration. Enter interface configuration mode and run no shutdown.

6. How do you recognise a duplex mismatch?

Late collisions, CRC errors, runts and very slow throughput on one side while the link shows up. Check with show interfaces and fix by setting both ends to auto or matching speed and duplex.

7. Which command gives a quick view of all interface states?

show ip interface brief lists each interface, its IP, status and protocol. show interfaces status on a switch adds VLAN, duplex and speed.

8. A port is in err-disabled. What do you do?

Run show interfaces status err-disabled to see the cause, such as a port-security violation or BPDU guard. Fix the cause, then shutdown and no shutdown the port, or use err-disable recovery.

9. How do you find which port a device is on?

Use show mac address-table address <mac> on the switch. If the port leads to another switch, repeat there until you reach an access port.

10. Two hosts in the same VLAN on different switches cannot talk. What do you check?

Check that the trunk between the switches is up and allows that VLAN with show interfaces trunk, that the VLAN exists on both switches with show vlan brief, and that the native VLAN matches on both ends.

11. What is a native VLAN mismatch and what are its symptoms?

The two ends of an 802.1Q trunk disagree on the untagged VLAN. IOS logs CDP native VLAN mismatch messages, and traffic can leak between VLANs. Set the same native VLAN on both sides.

12. How do you troubleshoot an EtherChannel that will not form?

Run show etherchannel summary and check that both ends use compatible modes (LACP active or passive, or PAgP desirable or auto, not mixed) and have matching speed, duplex, VLAN and trunk settings on all member ports.

13. What causes a spanning tree loop and how do you detect one?

A switching loop appears when STP is disabled, misconfigured or a unidirectional link occurs. Symptoms are broadcast storms, high CPU, flapping MAC addresses and port LEDs blinking rapidly. Check show spanning-tree and locate the loop by disconnecting links.

IP addressing and routing

14. A host has an address starting with 169.254. What does it mean?

The host could not reach a DHCP server and assigned itself an APIPA address. Check the cable and VLAN, then DHCP server reachability, the scope, and any DHCP relay (ip helper-address) configuration.

15. Ping works to an IP address but not to a hostname. What is wrong?

The IP path works, so the issue is name resolution. Check the DNS server address on the host, whether the DNS server is reachable and whether the name exists. Test with nslookup.

16. How do you verify the path a packet takes?

Use traceroute (tracert on Windows). Each hop answers with the time it took. A row of asterisks can mean a filter or a device that does not reply, so it does not always show a failure.

17. What does a "Destination host unreachable" reply mean compared with "Request timed out"?

Unreachable usually comes from a device, often a router, saying it has no route or cannot resolve ARP. A timeout means no reply arrived, which could be a drop, a filter or a missing return route.

18. Which command shows the routing table, and how do you read it?

show ip route. Codes show how each route was learned: C connected, S static, O OSPF, D EIGRP. The next hop and exit interface show where traffic goes. The gateway of last resort shows the default route.

19. Why would a packet be routed to the wrong place?

The longest prefix match wins over administrative distance. A more specific route, even a stale one, overrides a default. Check for overlapping prefixes and floating static routes.

20. Two routers will not form an OSPF neighbour relationship. What do you check?

Check show ip ospf neighbor and show ip ospf interface. Matching area, hello and dead timers, subnet and mask, authentication and a unique router ID are required, and the interface must not be passive.

21. An OSPF neighbour is stuck in EXSTART or EXCHANGE. What is the likely cause?

An MTU mismatch between the neighbours is the classic cause. Compare show interfaces MTU on both ends and align them.

22. How do you check which routing protocols are running?

show ip protocols lists active protocols, networks advertised, passive interfaces, neighbours and administrative distances.

23. Hosts can reach the gateway but not other subnets. What next?

Check that the gateway has routes to the destination and a return path. Then check for ACLs, a wrong subnet mask on the host and inter-VLAN routing configuration such as router-on-a-stick subinterfaces or SVIs.

24. What is ARP and how does it help troubleshooting?

ARP maps IP addresses to MAC addresses on a local network. show ip arp shows resolved neighbours. An incomplete entry means no reply came, which points to Layer 1 or 2, the wrong VLAN or a wrong address.

Services and security

25. How do you tell whether an ACL is blocking traffic?

Run show access-lists and check the match counters as you test. Remember the implicit deny at the end, the order of entries, and the direction and interface where the ACL is applied (show ip interface).

26. NAT is not translating. What do you check?

Check the inside and outside interface roles, the ACL or pool matching the traffic, and show ip nat translations and show ip nat statistics. Missing route back to the pool or overlapping ACLs are common faults.

27. DHCP clients on a different subnet get no address. Why?

DHCP broadcasts do not cross routers. Configure ip helper-address on the client-facing interface pointing to the DHCP server, and check the pool exists for that subnet and has free addresses.

28. A port-security violation shuts a port. How do you investigate?

Use show port-security interface <int> to see the violation mode, count and last offending MAC. Decide whether the device is legitimate, then clear the err-disabled state.

29. How can you check time and logging when troubleshooting?

Ensure NTP is working, so logs line up, and read show logging. Timestamps across devices are essential to build a timeline.

30. What are the risks of the debug command?

Debug output can overload a router's CPU and flood the console. Use it briefly, filter with conditions where possible, prefer show commands, and turn it off with undebug all.

31. Which tools besides the CLI help you diagnose problems?

Ping, traceroute, Wireshark packet captures, SNMP or syslog monitoring, and CDP or LLDP to map neighbours with show cdp neighbors detail.

How should you answer a scenario question?

  1. Restate the symptom and ask one or two clarifying questions.
  2. Name the layer you will test first and why.
  3. Give the command and say what output would confirm or rule out the cause.
  4. State the fix and how you would verify it, then document it.

Common mistakes in these interviews

  • Changing several things at once, so you cannot tell what fixed it.
  • Jumping to routing when the cable or VLAN is wrong.
  • Using debug on a busy production router.
  • Not saying how you would confirm the fix.

Next steps

Practise each question in a simulator or on lab gear. Our CCNA 200-301 course includes hands-on labs. For more practice, read CCNA troubleshooting scenarios and CCNA interview questions on switch configuration.

Related reading

Frequently Asked Questions

Define the problem precisely: what fails, since when, who is affected and what changed. Then test by layer, usually checking the physical link, the IP configuration and gateway, and then DNS and the application.

Traceroute shows the sequence of routers a packet passes on the way to a destination, with the response time at each hop. It helps locate where traffic stops or slows, though some devices do not reply.

The network path is fine and name resolution is failing. Check the DNS server settings on the host, whether the DNS server is reachable and whether the record exists. Use nslookup to test.

It happens when one end of a link uses full duplex and the other half duplex. The link stays up but shows late collisions, CRC errors and poor throughput. Set both ends to auto or to the same fixed values.

An MTU mismatch between the two interfaces is the classic cause. Compare the MTU on both ends with show interfaces and align them, then check whether the adjacency reaches FULL.

DHCP discovery is a broadcast and routers do not forward it. Configure ip helper-address on the client-facing interface to point to the DHCP server, and ensure the server has a pool for that subnet.

What's Your Reaction?

Like Like 0
Dislike Dislike 0
Love Love 0
Funny Funny 0
Wow Wow 0
Sad Sad 0
Angry Angry 0
Anjali

I am passionate about technology, invention and big challenging tasks on my to- do list. In terms of the work I am doing also at Bunnyshell, I am most passionate about the technologies that we are using., I'm devoted to delivering content that not only informs but also inspires. Whether you need in- depth analysis pieces, educational attendants, or study- provoking opinion pieces, I draft content that resonates with tech suckers and professionals likewise.