Topic 13 Practice Test 3 covers NAT, NTP, DHCP, and DNS for Cisco Certified Network Associate 200-301 CCNA and maps to objectives 4.1–4.3, 4.6. For broader exam preparation, review the Cisco CCNA 200-301 Exam Dumps. Every option includes focused technical reasoning explaining both the networking concept and its fit to the scenario.
Question 1
At Kodiak, `show ip nat translations` should always show a fixed pairing for one server. Which configuration approach creates that behavior? Choose ONE.
- Static NAT
- Dynamic NAT from a pool
- PAT overload
- DNS lookup
Correct Answer: A
Correct Answer
Answer A is correct because Static NAT creates a configured one-to-one association between an inside local address and an inside global address. For CHG-10232 at Kodiak, the implementation engineer checks Kodiak’s protocol state; CHG-10232 is judged from the observable result at Kodiak. For CHG-10232, this choice fits Kodiak: the implementation engineer gets the required Kodiak outcome and can verify CHG-10232 directly.
Incorrect Answers
Answer B is incorrect because Dynamic NAT assigns available global addresses as sessions require them rather than guaranteeing one permanent mapping. For CHG-10232 at Kodiak, the implementation engineer checks Kodiak’s protocol state; CHG-10232 is judged from the observable result at Kodiak. For CHG-10232, this choice fails Kodiak: the implementation engineer leaves the required Kodiak condition unmet and, under t13-pt3-q01, should reject it for chg-10232.
Answer C is incorrect because PAT commonly multiplexes many inside hosts onto one or a small number of global addresses by differentiating transport-layer ports. For CHG-10232 at Kodiak, the implementation engineer checks Kodiak’s protocol state; CHG-10232 is judged from the observable result at Kodiak. For CHG-10232, this choice fails Kodiak: the implementation engineer leaves the required Kodiak condition unmet and, under t13-pt3-q01, should reject it for chg-10232.
Answer D is incorrect because DNS resolves names and addresses but does not translate packet source addresses at the NAT boundary. For CHG-10232 at Kodiak, the implementation engineer checks Kodiak’s protocol state; CHG-10232 is judged from the observable result at Kodiak. For CHG-10232, this choice fails Kodiak: the implementation engineer leaves the required Kodiak condition unmet and, under t13-pt3-q01, should reject it for chg-10232.
Question 2
At Nimbus, an inside local address receives one currently free address from a configured global pool. Which mechanism is operating? Choose ONE.
- PAT using one interface address
- Dynamic NAT using an address pool
- DHCP relay
- Static NAT
Correct Answer: B
Correct Answer
Answer B is correct because Dynamic NAT selects an available inside-global address from a configured pool for qualifying inside-local addresses. For CHG-10249 at Nimbus, the deployment lead checks Nimbus’s protocol state; CHG-10249 is judged from the observable result at Nimbus. For CHG-10249, this choice fits Nimbus: the deployment lead gets the required Nimbus outcome and can verify CHG-10249 directly.
Incorrect Answers
Answer D is incorrect because Static NAT fixes a particular one-to-one mapping rather than allocating any free pool member. For CHG-10249 at Nimbus, the deployment lead checks Nimbus’s protocol state; CHG-10249 is judged from the observable result at Nimbus. For CHG-10249, this choice fails Nimbus: the deployment lead leaves the required Nimbus condition unmet and, under t13-pt3-q02, should reject it for chg-10249.
Answer A is incorrect because PAT distinguishes many translations with ports and typically allows many hosts to share one global address. For CHG-10249 at Nimbus, the deployment lead checks Nimbus’s protocol state; CHG-10249 is judged from the observable result at Nimbus. For CHG-10249, this choice fails Nimbus: the deployment lead leaves the required Nimbus condition unmet and, under t13-pt3-q02, should reject it for chg-10249.
Answer C is incorrect because DHCP relay forwards address-assignment broadcasts but is not packet address translation. For CHG-10249 at Nimbus, the deployment lead checks Nimbus’s protocol state; CHG-10249 is judged from the observable result at Nimbus. For CHG-10249, this choice fails Nimbus: the deployment lead leaves the required Nimbus condition unmet and, under t13-pt3-q02, should reject it for chg-10249.
Question 3
At Cedar, multiple inside-local hosts appear under the same inside-global address with different TCP/UDP port numbers. What translation is in use? Choose ONE.
- One-to-one static NAT
- PAT/NAT overload
- NTP client mode
- Dynamic NAT without overload
Correct Answer: B
Correct Answer
Answer B is correct because Port Address Translation lets many inside-local sessions share an inside-global address by using transport-layer port identifiers to keep translations distinct. For CHG-10266 at Cedar, the implementation engineer checks Cedar’s protocol state; CHG-10266 is judged from the observable result at Cedar. For CHG-10266, this choice fits Cedar: the implementation engineer gets the required Cedar outcome and can verify CHG-10266 directly.
Incorrect Answers
Answer A is incorrect because Static NAT consumes a dedicated global address per configured inside local mapping. For CHG-10266 at Cedar, the implementation engineer checks Cedar’s protocol state; CHG-10266 is judged from the observable result at Cedar. For CHG-10266, this choice fails Cedar: the implementation engineer leaves the required Cedar condition unmet and, under t13-pt3-q03, should reject it for chg-10266.
Answer D is incorrect because Ordinary dynamic NAT generally binds hosts to available pool addresses and does not rely on port multiplexing to make one address serve hundreds concurrently. For CHG-10266 at Cedar, the implementation engineer checks Cedar’s protocol state; CHG-10266 is judged from the observable result at Cedar. For CHG-10266, this choice fails Cedar: the implementation engineer leaves the required Cedar condition unmet and, under t13-pt3-q03, should reject it for chg-10266.
Answer C is incorrect because NTP synchronizes time and has no address-conservation role. For CHG-10266 at Cedar, the implementation engineer checks Cedar’s protocol state; CHG-10266 is judged from the observable result at Cedar. For CHG-10266, this choice fails Cedar: the implementation engineer leaves the required Cedar condition unmet and, under t13-pt3-q03, should reject it for chg-10266.
Question 4
At Falcon, engineers document NAT fields. Which label applies to the private address assigned to the inside device before translation? Choose ONE.
- The NAT router’s default gateway only
- The public address representing the inside host externally
- The inside host address as it is known on the inside network
- The outside server’s public address
Correct Answer: C
Correct Answer
Answer C is correct because Inside local refers to the address assigned to the internal host from the perspective of the inside network, commonly a private address. For CHG-10283 at Falcon, the deployment lead checks Falcon’s protocol state; CHG-10283 is judged from the observable result at Falcon. For CHG-10283, this choice fits Falcon: the deployment lead gets the required Falcon outcome and can verify CHG-10283 directly.
Incorrect Answers
Answer B is incorrect because That is the inside global address, not inside local. For CHG-10283 at Falcon, the deployment lead checks Falcon’s protocol state; CHG-10283 is judged from the observable result at Falcon. For CHG-10283, this choice fails Falcon: the deployment lead leaves the required Falcon condition unmet and, under t13-pt3-q04, should reject it for chg-10283.
Answer D is incorrect because That describes an outside global address, not the internal host. For CHG-10283 at Falcon, the deployment lead checks Falcon’s protocol state; CHG-10283 is judged from the observable result at Falcon. For CHG-10283, this choice fails Falcon: the deployment lead leaves the required Falcon condition unmet and, under t13-pt3-q04, should reject it for chg-10283.
Answer A is incorrect because Inside local terminology identifies the translated host address, not merely the router gateway. For CHG-10283 at Falcon, the deployment lead checks Falcon’s protocol state; CHG-10283 is judged from the observable result at Falcon. For CHG-10283, this choice fails Falcon: the deployment lead leaves the required Falcon condition unmet and, under t13-pt3-q04, should reject it for chg-10283.
Question 5
At Indigo, NAT starts working after LAN is marked inside and WAN is marked outside. What configuration requirement was corrected? Choose ONE.
- LAN as `ip nat inside`; Internet interface as `ip nat outside`
- Both interfaces as `ip nat inside`
- Both interfaces as `ip nat outside`
- Neither interface needs a NAT role
Correct Answer: A
Correct Answer
Answer A is correct because Classic IOS NAT classifies interfaces by translation direction so packets can be interpreted as moving between inside and outside address realms. For CHG-10300 at Indigo, the implementation engineer checks Indigo’s protocol state; CHG-10300 is judged from the observable result at Indigo. For CHG-10300, this choice fits Indigo: the implementation engineer gets the required Indigo outcome and can verify CHG-10300 directly.
Incorrect Answers
Answer B is incorrect because Without an outside role, classic inside-source NAT lacks the intended boundary classification. For CHG-10300 at Indigo, the implementation engineer checks Indigo’s protocol state; CHG-10300 is judged from the observable result at Indigo. For CHG-10300, this choice fails Indigo: the implementation engineer leaves the required Indigo condition unmet and, under t13-pt3-q05, should reject it for chg-10300.
Answer C is incorrect because The inside LAN must be identified as inside for inside-source translations. For CHG-10300 at Indigo, the implementation engineer checks Indigo’s protocol state; CHG-10300 is judged from the observable result at Indigo. For CHG-10300, this choice fails Indigo: the implementation engineer leaves the required Indigo condition unmet and, under t13-pt3-q05, should reject it for chg-10300.
Answer D is incorrect because Classic IOS NAT configuration normally requires inside/outside designation on the participating interfaces. For CHG-10300 at Indigo, the implementation engineer checks Indigo’s protocol state; CHG-10300 is judged from the observable result at Indigo. For CHG-10300, this choice fails Indigo: the implementation engineer leaves the required Indigo condition unmet and, under t13-pt3-q05, should reject it for chg-10300.
Question 6
At Lumen, a host is not translated because its source does not match the NAT ACL. What is the ACL doing? Choose ONE.
- The NTP peers
- The inside source addresses eligible for translation
- The HSRP active router only
- The public DNS servers
Correct Answer: B
Correct Answer
Answer B is correct because In common IOS inside-source NAT configuration, an ACL identifies which inside-local source addresses are candidates for the configured translation rule. For CHG-10317 at Lumen, the deployment lead checks Lumen’s protocol state; CHG-10317 is judged from the observable result at Lumen. For CHG-10317, this choice fits Lumen: the deployment lead gets the required Lumen outcome and can verify CHG-10317 directly.
Incorrect Answers
Answer D is incorrect because DNS server selection is unrelated to the NAT source-selection ACL. For CHG-10317 at Lumen, the deployment lead checks Lumen’s protocol state; CHG-10317 is judged from the observable result at Lumen. For CHG-10317, this choice fails Lumen: the deployment lead leaves the required Lumen condition unmet and, under t13-pt3-q06, should reject it for chg-10317.
Answer A is incorrect because NTP peers are configured independently of NAT ACL selection. For CHG-10317 at Lumen, the deployment lead checks Lumen’s protocol state; CHG-10317 is judged from the observable result at Lumen. For CHG-10317, this choice fails Lumen: the deployment lead leaves the required Lumen condition unmet and, under t13-pt3-q06, should reject it for chg-10317.
Answer C is incorrect because An ACL used by NAT is evaluated against traffic addresses, not merely an FHRP role. For CHG-10317 at Lumen, the deployment lead checks Lumen’s protocol state; CHG-10317 is judged from the observable result at Lumen. For CHG-10317, this choice fails Lumen: the deployment lead leaves the required Lumen condition unmet and, under t13-pt3-q06, should reject it for chg-10317.
Question 7
At Orchid, dynamic NAT fails because the pool range was defined on the wrong subnet. Which pool elements should be reviewed? Choose ONE.
- Only the inside ACL number
- Starting and ending global addresses plus the appropriate netmask or prefix information
- Only the DNS domain
- Only an HSRP group number
Correct Answer: B
Correct Answer
Answer B is correct because A dynamic NAT pool defines the inside-global address range and its network mask/prefix so IOS can allocate valid translations. For CHG-10334 at Orchid, the implementation engineer checks Orchid’s protocol state; CHG-10334 is judged from the observable result at Orchid. For CHG-10334, this choice fits Orchid: the implementation engineer gets the required Orchid outcome and can verify CHG-10334 directly.
Incorrect Answers
Answer A is incorrect because The ACL selects inside sources but does not itself define the public pool address range. For CHG-10334 at Orchid, the implementation engineer checks Orchid’s protocol state; CHG-10334 is judged from the observable result at Orchid. For CHG-10334, this choice fails Orchid: the implementation engineer leaves the required Orchid condition unmet and, under t13-pt3-q07, should reject it for chg-10334.
Answer D is incorrect because HSRP grouping does not define NAT pool addresses. For CHG-10334 at Orchid, the implementation engineer checks Orchid’s protocol state; CHG-10334 is judged from the observable result at Orchid. For CHG-10334, this choice fails Orchid: the implementation engineer leaves the required Orchid condition unmet and, under t13-pt3-q07, should reject it for chg-10334.
Answer C is incorrect because DNS domain configuration has no role in building a NAT address pool. For CHG-10334 at Orchid, the implementation engineer checks Orchid’s protocol state; CHG-10334 is judged from the observable result at Orchid. For CHG-10334, this choice fails Orchid: the implementation engineer leaves the required Orchid condition unmet and, under t13-pt3-q07, should reject it for chg-10334.
Question 8
Verification at Redwood shows a translation that exists independent of client-initiated sessions. Which mapping type explains it? Choose ONE.
- An `ntp server` association
- A dynamic pool without a matching rule
- An `ip nat inside source static` mapping
- An `ip helper-address` command
Correct Answer: C
Correct Answer
Answer C is correct because The static inside-source form binds the specified inside-local address to a fixed inside-global address. For CHG-10351 at Redwood, the deployment lead checks Redwood’s protocol state; CHG-10351 is judged from the observable result at Redwood. For CHG-10351, this choice fits Redwood: the deployment lead gets the required Redwood outcome and can verify CHG-10351 directly.
Incorrect Answers
Answer B is incorrect because A pool alone does not create a permanent host-specific translation. For CHG-10351 at Redwood, the deployment lead checks Redwood’s protocol state; CHG-10351 is judged from the observable result at Redwood. For CHG-10351, this choice fails Redwood: the deployment lead leaves the required Redwood condition unmet and, under t13-pt3-q08, should reject it for chg-10351.
Answer D is incorrect because Helper addresses relay certain UDP broadcasts such as DHCP and do not create NAT mappings. For CHG-10351 at Redwood, the deployment lead checks Redwood’s protocol state; CHG-10351 is judged from the observable result at Redwood. For CHG-10351, this choice fails Redwood: the deployment lead leaves the required Redwood condition unmet and, under t13-pt3-q08, should reject it for chg-10351.
Answer A is incorrect because NTP server configuration changes time synchronization, not address translation. For CHG-10351 at Redwood, the deployment lead checks Redwood’s protocol state; CHG-10351 is judged from the observable result at Redwood. For CHG-10351, this choice fails Redwood: the deployment lead leaves the required Redwood condition unmet and, under t13-pt3-q08, should reject it for chg-10351.
Question 9
At Union, `show ntp associations` begins listing 192.0.2.20 after a configuration change. Which command likely created the association? Choose ONE.
- ntp server 192.0.2.20
- ip name-server 192.0.2.20
- ip helper-address 192.0.2.20
- standby 20 ip 192.0.2.20
Correct Answer: A
Correct Answer
Answer A is correct because The `ntp server` command configures the device to poll and synchronize with the specified NTP server. For CHG-10368 at Union, the implementation engineer checks Union’s protocol state; CHG-10368 is judged from the observable result at Union. For CHG-10368, this choice fits Union: the implementation engineer gets the required Union outcome and can verify CHG-10368 directly.
Incorrect Answers
Answer B is incorrect because That configures a DNS resolver, not a time source. For CHG-10368 at Union, the implementation engineer checks Union’s protocol state; CHG-10368 is judged from the observable result at Union. For CHG-10368, this choice fails Union: the implementation engineer leaves the required Union condition unmet and, under t13-pt3-q09, should reject it for chg-10368.
Answer C is incorrect because That relays selected UDP broadcasts and is commonly used for DHCP, not NTP client association. For CHG-10368 at Union, the implementation engineer checks Union’s protocol state; CHG-10368 is judged from the observable result at Union. For CHG-10368, this choice fails Union: the implementation engineer leaves the required Union condition unmet and, under t13-pt3-q09, should reject it for chg-10368.
Answer D is incorrect because That defines an HSRP virtual gateway address and does not configure time synchronization. For CHG-10368 at Union, the implementation engineer checks Union’s protocol state; CHG-10368 is judged from the observable result at Union. For CHG-10368, this choice fails Union: the implementation engineer leaves the required Union condition unmet and, under t13-pt3-q09, should reject it for chg-10368.
Question 10
At Xenon, a device advertises itself as an NTP master for an isolated lab. What configuration enabled that server role? Choose ONE.
- ip dhcp pool
- ntp master
- ip domain lookup
- ntp server
Correct Answer: B
Correct Answer
Answer B is correct because `ntp master` can make a Cisco device act as an authoritative NTP source, a feature that should be used carefully when no better reference is available. For CHG-10385 at Xenon, the deployment lead checks Xenon’s protocol state; CHG-10385 is judged from the observable result at Xenon. For CHG-10385, this choice fits Xenon: the deployment lead gets the required Xenon outcome and can verify CHG-10385 directly.
Incorrect Answers
Answer D is incorrect because `ntp server` normally makes the local device a client of another NTP source rather than declaring its own clock authoritative. For CHG-10385 at Xenon, the deployment lead checks Xenon’s protocol state; CHG-10385 is judged from the observable result at Xenon. For CHG-10385, this choice fails Xenon: the deployment lead leaves the required Xenon condition unmet and, under t13-pt3-q10, should reject it for chg-10385.
Answer A is incorrect because A DHCP pool supplies address configuration and is not an NTP server role command. For CHG-10385 at Xenon, the deployment lead checks Xenon’s protocol state; CHG-10385 is judged from the observable result at Xenon. For CHG-10385, this choice fails Xenon: the deployment lead leaves the required Xenon condition unmet and, under t13-pt3-q10, should reject it for chg-10385.
Answer C is incorrect because DNS lookup resolves names and does not make the device an NTP time source. For CHG-10385 at Xenon, the deployment lead checks Xenon’s protocol state; CHG-10385 is judged from the observable result at Xenon. For CHG-10385, this choice fails Xenon: the deployment lead leaves the required Xenon condition unmet and, under t13-pt3-q10, should reject it for chg-10385.
Question 11
At Aspen, NTP fails because UDP port 123 is blocked. Why is that port relevant? Choose ONE.
- TCP port 22
- UDP port 123
- TCP port 80
- UDP port 53
Correct Answer: B
Correct Answer
Answer B is correct because NTP normally uses UDP port 123 for time synchronization exchanges. For CHG-10402 at Aspen, the implementation engineer checks Aspen’s protocol state; CHG-10402 is judged from the observable result at Aspen. For CHG-10402, this choice fits Aspen: the implementation engineer gets the required Aspen outcome and can verify CHG-10402 directly.
Incorrect Answers
Answer A is incorrect because TCP 22 is associated with SSH, not NTP. For CHG-10402 at Aspen, the implementation engineer checks Aspen’s protocol state; CHG-10402 is judged from the observable result at Aspen. For CHG-10402, this choice fails Aspen: the implementation engineer leaves the required Aspen condition unmet and, under t13-pt3-q11, should reject it for chg-10402.
Answer D is incorrect because UDP 53 is commonly DNS, not NTP. For CHG-10402 at Aspen, the implementation engineer checks Aspen’s protocol state; CHG-10402 is judged from the observable result at Aspen. For CHG-10402, this choice fails Aspen: the implementation engineer leaves the required Aspen condition unmet and, under t13-pt3-q11, should reject it for chg-10402.
Answer C is incorrect because TCP 80 is HTTP and is unrelated to normal NTP exchange. For CHG-10402 at Aspen, the implementation engineer checks Aspen’s protocol state; CHG-10402 is judged from the observable result at Aspen. For CHG-10402, this choice fails Aspen: the implementation engineer leaves the required Aspen condition unmet and, under t13-pt3-q11, should reject it for chg-10402.
Question 12
A Drift engineer wants to see configured NTP association status rather than only the clock value. Which command fits? Choose ONE.
- show interfaces trunk
- show ip route static
- show ntp associations
- show standby
Correct Answer: C
Correct Answer
Answer C is correct because This command displays NTP associations and their state, helping verify configured server or peer relationships. For CHG-10419 at Drift, the deployment lead checks Drift’s protocol state; CHG-10419 is judged from the observable result at Drift. For CHG-10419, this choice fits Drift: the deployment lead gets the required Drift outcome and can verify CHG-10419 directly.
Incorrect Answers
Answer B is incorrect because That verifies static routes rather than NTP relationships. For CHG-10419 at Drift, the deployment lead checks Drift’s protocol state; CHG-10419 is judged from the observable result at Drift. For CHG-10419, this choice fails Drift: the deployment lead leaves the required Drift condition unmet and, under t13-pt3-q12, should reject it for chg-10419.
Answer D is incorrect because That reports HSRP state. For CHG-10419 at Drift, the deployment lead checks Drift’s protocol state; CHG-10419 is judged from the observable result at Drift. For CHG-10419, this choice fails Drift: the deployment lead leaves the required Drift condition unmet and, under t13-pt3-q12, should reject it for chg-10419.
Answer A is incorrect because That reports Layer 2 trunking state, not time synchronization. For CHG-10419 at Drift, the deployment lead checks Drift’s protocol state; CHG-10419 is judged from the observable result at Drift. For CHG-10419, this choice fails Drift: the deployment lead leaves the required Drift condition unmet and, under t13-pt3-q12, should reject it for chg-10419.
Question 13
After `ip address dhcp` is applied at Grove, the interface receives address parameters from a DHCP server. What role is the router interface performing? Choose ONE.
- ip address dhcp
- ip helper-address
- ip nat inside
- ip name-server
Correct Answer: A
Correct Answer
Answer A is correct because The interface command requests its IPv4 address and related parameters from DHCP, making that interface a DHCP client. For CHG-10436 at Grove, the implementation engineer checks Grove’s protocol state; CHG-10436 is judged from the observable result at Grove. For CHG-10436, this choice fits Grove: the implementation engineer gets the required Grove outcome and can verify CHG-10436 directly.
Incorrect Answers
Answer B is incorrect because Helper-address makes the router relay selected broadcasts from other clients; it does not make that interface request its own address. For CHG-10436 at Grove, the implementation engineer checks Grove’s protocol state; CHG-10436 is judged from the observable result at Grove. For CHG-10436, this choice fails Grove: the implementation engineer leaves the required Grove condition unmet and, under t13-pt3-q13, should reject it for chg-10436.
Answer C is incorrect because NAT role classification does not acquire an IPv4 address. For CHG-10436 at Grove, the implementation engineer checks Grove’s protocol state; CHG-10436 is judged from the observable result at Grove. For CHG-10436, this choice fails Grove: the implementation engineer leaves the required Grove condition unmet and, under t13-pt3-q13, should reject it for chg-10436.
Answer D is incorrect because That identifies DNS resolvers but does not request interface addressing. For CHG-10436 at Grove, the implementation engineer checks Grove’s protocol state; CHG-10436 is judged from the observable result at Grove. For CHG-10436, this choice fails Grove: the implementation engineer leaves the required Grove condition unmet and, under t13-pt3-q13, should reject it for chg-10436.
Question 14
After an `ip helper-address 192.0.2.50` is added to the Jasper client gateway, DHCP begins working. What function did the router assume? Choose ONE.
- ntp server 192.0.2.50
- ip helper-address 192.0.2.50
- standby 20 ip 192.0.2.50
- ip name-server 192.0.2.50
Correct Answer: B
Correct Answer
Answer B is correct because The helper address makes the router act as a relay, converting supported local UDP broadcasts such as DHCP into routed traffic toward the specified server. For CHG-10453 at Jasper, the deployment lead checks Jasper’s protocol state; CHG-10453 is judged from the observable result at Jasper. For CHG-10453, this choice fits Jasper: the deployment lead gets the required Jasper outcome and can verify CHG-10453 directly.
Incorrect Answers
Answer D is incorrect because That configures DNS resolution for the router itself and does not relay client DHCP broadcasts. For CHG-10453 at Jasper, the deployment lead checks Jasper’s protocol state; CHG-10453 is judged from the observable result at Jasper. For CHG-10453, this choice fails Jasper: the deployment lead leaves the required Jasper condition unmet and, under t13-pt3-q14, should reject it for chg-10453.
Answer A is incorrect because That configures a time source, not DHCP relay. For CHG-10453 at Jasper, the deployment lead checks Jasper’s protocol state; CHG-10453 is judged from the observable result at Jasper. For CHG-10453, this choice fails Jasper: the deployment lead leaves the required Jasper condition unmet and, under t13-pt3-q14, should reject it for chg-10453.
Answer C is incorrect because That creates an HSRP virtual IP and does not forward DHCP requests to the server. For CHG-10453 at Jasper, the deployment lead checks Jasper’s protocol state; CHG-10453 is judged from the observable result at Jasper. For CHG-10453, this choice fails Jasper: the deployment lead leaves the required Jasper condition unmet and, under t13-pt3-q14, should reject it for chg-10453.
Question 15
At Monarch, the server assigns the wrong subnet because the relay information is incorrect. Which standard field should be examined first? Choose ONE.
- DNS MX record
- giaddr (gateway IP address)
- OSPF router ID
- NTP stratum
Correct Answer: B
Correct Answer
Answer B is correct because A DHCP relay inserts its client-facing interface address into the giaddr field so the server can identify the originating subnet and choose an appropriate pool. For CHG-10470 at Monarch, the implementation engineer checks Monarch’s protocol state; CHG-10470 is judged from the observable result at Monarch. For CHG-10470, this choice fits Monarch: the implementation engineer gets the required Monarch outcome and can verify CHG-10470 directly.
Incorrect Answers
Answer A is incorrect because Mail-exchanger DNS records are unrelated to DHCP scope selection. For CHG-10470 at Monarch, the implementation engineer checks Monarch’s protocol state; CHG-10470 is judged from the observable result at Monarch. For CHG-10470, this choice fails Monarch: the implementation engineer leaves the required Monarch condition unmet and, under t13-pt3-q15, should reject it for chg-10470.
Answer D is incorrect because NTP stratum measures time-source hierarchy and is not carried for DHCP address allocation. For CHG-10470 at Monarch, the implementation engineer checks Monarch’s protocol state; CHG-10470 is judged from the observable result at Monarch. For CHG-10470, this choice fails Monarch: the implementation engineer leaves the required Monarch condition unmet and, under t13-pt3-q15, should reject it for chg-10470.
Answer C is incorrect because OSPF identity is not the DHCP relay gateway field. For CHG-10470 at Monarch, the implementation engineer checks Monarch’s protocol state; CHG-10470 is judged from the observable result at Monarch. For CHG-10470, this choice fails Monarch: the implementation engineer leaves the required Monarch condition unmet and, under t13-pt3-q15, should reject it for chg-10470.
Question 16
At Beacon, two `ip helper-address` statements are present on one SVI. What behavior is intended? Choose ONE.
- Only DNS round-robin can select DHCP servers
- No; only one helper address is allowed per interface
- Yes; configure one helper address for each server
- Only HSRP can provide DHCP redundancy
Correct Answer: C
Correct Answer
Answer C is correct because IOS supports multiple helper addresses on an interface, allowing relayed requests to be forwarded toward multiple configured servers. For CHG-10487 at Beacon, the deployment lead checks Beacon’s protocol state; CHG-10487 is judged from the observable result at Beacon. For CHG-10487, this choice fits Beacon: the deployment lead gets the required Beacon outcome and can verify CHG-10487 directly.
Incorrect Answers
Answer B is incorrect because Multiple helper addresses are supported and commonly used for redundant DHCP servers. For CHG-10487 at Beacon, the deployment lead checks Beacon’s protocol state; CHG-10487 is judged from the observable result at Beacon. For CHG-10487, this choice fails Beacon: the deployment lead leaves the required Beacon condition unmet and, under t13-pt3-q16, should reject it for chg-10487.
Answer D is incorrect because HSRP provides first-hop gateway redundancy but does not replace the ability to relay to multiple DHCP servers. For CHG-10487 at Beacon, the deployment lead checks Beacon’s protocol state; CHG-10487 is judged from the observable result at Beacon. For CHG-10487, this choice fails Beacon: the deployment lead leaves the required Beacon condition unmet and, under t13-pt3-q16, should reject it for chg-10487.
Answer A is incorrect because DNS is not required for multiple numeric helper-address destinations. For CHG-10487 at Beacon, the deployment lead checks Beacon’s protocol state; CHG-10487 is judged from the observable result at Beacon. For CHG-10487, this choice fails Beacon: the deployment lead leaves the required Beacon condition unmet and, under t13-pt3-q16, should reject it for chg-10487.
Question 17
At Ember, clients lose automatic address and gateway assignment after a server outage. Which infrastructure service is affected? Choose ONE.
- Dynamic delivery of IP configuration parameters
- Name-to-address resolution
- Network time synchronization
- Packet address translation
Correct Answer: A
Correct Answer
Answer A is correct because DHCP automates host network configuration, commonly providing an IPv4 address, subnet mask, default gateway, DNS servers, and lease information. For CHG-10504 at Ember, the implementation engineer checks Ember’s protocol state; CHG-10504 is judged from the observable result at Ember. For CHG-10504, this choice fits Ember: the implementation engineer gets the required Ember outcome and can verify CHG-10504 directly.
Incorrect Answers
Answer B is incorrect because That is the principal role of DNS rather than DHCP. For CHG-10504 at Ember, the implementation engineer checks Ember’s protocol state; CHG-10504 is judged from the observable result at Ember. For CHG-10504, this choice fails Ember: the implementation engineer leaves the required Ember condition unmet and, under t13-pt3-q17, should reject it for chg-10504.
Answer C is incorrect because That is NTP. For CHG-10504 at Ember, the implementation engineer checks Ember’s protocol state; CHG-10504 is judged from the observable result at Ember. For CHG-10504, this choice fails Ember: the implementation engineer leaves the required Ember condition unmet and, under t13-pt3-q17, should reject it for chg-10504.
Answer D is incorrect because That is NAT, which rewrites addresses rather than assigning host configuration leases. For CHG-10504 at Ember, the implementation engineer checks Ember’s protocol state; CHG-10504 is judged from the observable result at Ember. For CHG-10504, this choice fails Ember: the implementation engineer leaves the required Ember condition unmet and should reject it for CHG-10504.
Question 18
At Harbor, a client queries a server to learn the IP address associated with a host name. Which protocol service is being used? Choose ONE.
- Synchronizing device clocks
- Mapping domain/host names to IP addresses
- Translating private source addresses at an edge
- Assigning IPv4 leases
Correct Answer: B
Correct Answer
Answer B is correct because DNS provides distributed name resolution so clients can translate human-readable names into address information and other resource records. For CHG-10521 at Harbor, the deployment lead checks Harbor’s protocol state; CHG-10521 is judged from the observable result at Harbor. For CHG-10521, this choice fits Harbor: the deployment lead gets the required Harbor outcome and can verify CHG-10521 directly.
Incorrect Answers
Answer D is incorrect because DHCP supplies address configuration; it does not primarily resolve application host names. For CHG-10521 at Harbor, the deployment lead checks Harbor’s protocol state; CHG-10521 is judged from the observable result at Harbor. For CHG-10521, this choice fails Harbor: the deployment lead leaves the required Harbor condition unmet and should reject it for CHG-10521.
Answer A is incorrect because NTP provides time synchronization. For CHG-10521 at Harbor, the deployment lead checks Harbor’s protocol state; CHG-10521 is judged from the observable result at Harbor. For CHG-10521, this choice fails Harbor: the deployment lead leaves the required Harbor condition unmet and should reject it for CHG-10521.
Answer C is incorrect because NAT changes packet addresses and ports; it does not perform name resolution. For CHG-10521 at Harbor, the deployment lead checks Harbor’s protocol state; CHG-10521 is judged from the observable result at Harbor. For CHG-10521, this choice fails Harbor: the deployment lead leaves the required Harbor condition unmet and should reject it for CHG-10521.
Question 19
After `ip name-server 192.0.2.53` is configured at Keystone, router-generated name lookups succeed. What did the command define? Choose ONE.
- ip helper-address 192.0.2.53
- ip name-server 192.0.2.53
- ip nat pool DNS 192.0.2.53 192.0.2.53
- ntp server 192.0.2.53
Correct Answer: B
Correct Answer
Answer B is correct because The command identifies a DNS name server that the IOS resolver can query for host-name-to-address information. For CHG-10538 at Keystone, the implementation engineer checks Keystone’s protocol state; CHG-10538 is judged from the observable result at Keystone. For CHG-10538, this choice fits Keystone: the implementation engineer gets the required Keystone outcome and can verify CHG-10538 directly.
Incorrect Answers
Answer A is incorrect because That relays selected client UDP broadcasts and is not the router resolver-server setting. For CHG-10538 at Keystone, the implementation engineer checks Keystone’s protocol state; CHG-10538 is judged from the observable result at Keystone. For CHG-10538, this choice fails Keystone: the implementation engineer leaves the required Keystone condition unmet and should reject it for CHG-10538.
Answer D is incorrect because That configures a time source. For CHG-10538 at Keystone, the implementation engineer checks Keystone’s protocol state; CHG-10538 is judged from the observable result at Keystone. For CHG-10538, this choice fails Keystone: the implementation engineer leaves the required Keystone condition unmet and should reject it for CHG-10538.
Answer C is incorrect because A NAT pool defines translation addresses and does not identify a DNS resolver. For CHG-10538 at Keystone, the implementation engineer checks Keystone’s protocol state; CHG-10538 is judged from the observable result at Keystone. For CHG-10538, this choice fails Keystone: the implementation engineer leaves the required Keystone condition unmet and should reject it for CHG-10538.
Question 20
After `ip domain lookup` is entered at Northstar, router-generated host-name queries resume. What service was re-enabled? Choose ONE.
- standby preempt
- ip dhcp relay information option
- ip domain lookup
- ip nat inside
Correct Answer: C
Correct Answer
Answer C is correct because This command enables IOS DNS-based host-name lookup when that function has previously been disabled. For CHG-10555 at Northstar, the deployment lead checks Northstar’s protocol state; CHG-10555 is judged from the observable result at Northstar. For CHG-10555, this choice fits Northstar: the deployment lead gets the required Northstar outcome and can verify CHG-10555 directly.
Incorrect Answers
Answer B is incorrect because That affects DHCP relay metadata rather than DNS resolution. For CHG-10555 at Northstar, the deployment lead checks Northstar’s protocol state; CHG-10555 is judged from the observable result at Northstar. For CHG-10555, this choice fails Northstar: the deployment lead leaves the required Northstar condition unmet and should reject it for CHG-10555.
Answer D is incorrect because That marks a NAT interface role and does not enable name lookup. For CHG-10555 at Northstar, the deployment lead checks Northstar’s protocol state; CHG-10555 is judged from the observable result at Northstar. For CHG-10555, this choice fails Northstar: the deployment lead leaves the required Northstar condition unmet and should reject it for CHG-10555.
Answer A is incorrect because That changes HSRP active-role behavior and is unrelated to DNS. For CHG-10555 at Northstar, the deployment lead checks Northstar’s protocol state; CHG-10555 is judged from the observable result at Northstar. For CHG-10555, this choice fails Northstar: the deployment lead leaves the required Northstar condition unmet and should reject it for CHG-10555.