CISCO CCNA EXAM – EXAM-STYLE QUESTIONS AND ANSWERS | VERIFIED AND
WELL DETAILED ANSWERS | PLUS RATIONALES | GUARANTEED PASS | 2026/27
LATEST UPDATE | EXAM PREP | STUDY GUIDE | PRACTICE TEST
SECTION ONE: QUESTIONS 1-50
1. A network administrator is configuring a new switch and needs to ensure
that only devices with specific MAC addresses can access the network through
a particular port. Which security feature should be configured to meet this
requirement?
A. Port Security
B. DHCP Snooping
C. Dynamic ARP Inspection
D. IP Source Guard
Correct Answer: A. Port Security
Rationale: Port Security is the correct feature for restricting access to a switch port
based on MAC addresses. It allows the administrator to specify which MAC
addresses are permitted to send traffic through the interface. DHCP Snooping is a
security feature that filters DHCP messages, Dynamic ARP Inspection mitigates ARP
spoofing attacks, and IP Source Guard prevents IP spoofing attacks. These other
options are important security features, but they do not directly provide the MAC
address-based filtering requested in the scenario.**
,2. Which of the following best describes the operational difference between a
router and a layer 3 switch in an enterprise network?
A. A router uses ASICs for packet forwarding, while a layer 3 switch uses a CPU.
B. A layer 3 switch typically forwards traffic at wire speed using hardware, while a
router makes forwarding decisions primarily via software-based routing.
C. A router can only forward packets based on MAC addresses, whereas a layer 3
switch forwards based on IP addresses.
D. Layer 3 switches cannot support dynamic routing protocols, whereas routers
can.
Correct Answer: B. A layer 3 switch typically forwards traffic at wire speed using
hardware, while a router makes forwarding decisions primarily via software-
based routing.
Rationale: The primary architectural difference is that a layer 3 switch uses
specialized hardware (ASICs) to forward traffic at high speeds, whereas a router
generally uses a general-purpose CPU to make forwarding decisions, which can be
slower. Option A is incorrect because routers primarily use CPUs, and layer 3
switches use ASICs. Option C is backward; both forward based on IP addresses, but
switches also use MAC addresses at layer 2. Option D is false, as modern layer 3
switches can run dynamic routing protocols like OSPF and EIGRP.**
3. An engineer is configuring IPv6 on an interface and needs to generate a link-
local address automatically. Which of the following statements accurately
describes the process used by the device?
,A. The interface will use the MAC address to create a modified EUI-64 format
interface identifier.
B. The device will randomly generate a 64-bit interface identifier for the link-local
address.
C. The link-local address will be manually configured using a static address in the
FE80::/10 range.
D. The interface will use its IPv4 address to derive a unique IPv6 link-local address.
Correct Answer: A. The interface will use the MAC address to create a modified
EUI-64 format interface identifier.
Rationale: When a device automatically generates an IPv6 link-local address, it
typically uses the MAC address of the interface to create a 64-bit interface identifier
in the modified EUI-64 format. While modern operating systems may implement
privacy extensions that can use random identifiers, the standard process defined in
RFCs uses the EUI-64 format from the MAC address. Option B describes an
alternative method but is not the standard automatic process for all devices. Option
C describes manual configuration, not automatic generation. Option D is incorrect
because IPv4 addresses are not used to derive IPv6 link-local addresses.**
4. What is the primary function of the Spanning Tree Protocol (STP) in a
switched network?
A. To create multiple broadcast domains and segment network traffic.
B. To provide a path for routing traffic between VLANs.
C. To prevent layer 2 loops by logically blocking redundant links.
D. To assign IP addresses to hosts dynamically.
, Correct Answer: C. To prevent layer 2 loops by logically blocking redundant
links.
Rationale: The primary purpose of STP is to ensure a loop-free logical topology in a
network with redundant physical links. It accomplishes this by placing certain ports
in a blocking state, preventing the forwarding of frames, which eliminates the
possibility of broadcast storms and MAC address instability. Option A is a function
of VLANs. Option B is a function of a router or layer 3 switch. Option D is the
function of DHCP.**
5. An employee reports that they are unable to access the corporate web server
using its hostname, but can access it by typing the IP address. Which of the
following is the most likely cause of this issue?
A. The DHCP server is unreachable.
B. The DNS server is not resolving the hostname correctly.
C. The ARP cache on the client is corrupted.
D. The default gateway is misconfigured.
Correct Answer: B. The DNS server is not resolving the hostname correctly.
Rationale: Accessing a resource by hostname requires DNS resolution to translate
the name into an IP address. Since the user can access the server by its IP address,
the network connectivity and routing are functional, isolating the problem to name
resolution. A DHCP issue would prevent the client from obtaining an IP
configuration. An ARP issue would cause communication failures to the default
gateway or local hosts. A misconfigured default gateway would prevent access to
resources on different networks entirely.**
WELL DETAILED ANSWERS | PLUS RATIONALES | GUARANTEED PASS | 2026/27
LATEST UPDATE | EXAM PREP | STUDY GUIDE | PRACTICE TEST
SECTION ONE: QUESTIONS 1-50
1. A network administrator is configuring a new switch and needs to ensure
that only devices with specific MAC addresses can access the network through
a particular port. Which security feature should be configured to meet this
requirement?
A. Port Security
B. DHCP Snooping
C. Dynamic ARP Inspection
D. IP Source Guard
Correct Answer: A. Port Security
Rationale: Port Security is the correct feature for restricting access to a switch port
based on MAC addresses. It allows the administrator to specify which MAC
addresses are permitted to send traffic through the interface. DHCP Snooping is a
security feature that filters DHCP messages, Dynamic ARP Inspection mitigates ARP
spoofing attacks, and IP Source Guard prevents IP spoofing attacks. These other
options are important security features, but they do not directly provide the MAC
address-based filtering requested in the scenario.**
,2. Which of the following best describes the operational difference between a
router and a layer 3 switch in an enterprise network?
A. A router uses ASICs for packet forwarding, while a layer 3 switch uses a CPU.
B. A layer 3 switch typically forwards traffic at wire speed using hardware, while a
router makes forwarding decisions primarily via software-based routing.
C. A router can only forward packets based on MAC addresses, whereas a layer 3
switch forwards based on IP addresses.
D. Layer 3 switches cannot support dynamic routing protocols, whereas routers
can.
Correct Answer: B. A layer 3 switch typically forwards traffic at wire speed using
hardware, while a router makes forwarding decisions primarily via software-
based routing.
Rationale: The primary architectural difference is that a layer 3 switch uses
specialized hardware (ASICs) to forward traffic at high speeds, whereas a router
generally uses a general-purpose CPU to make forwarding decisions, which can be
slower. Option A is incorrect because routers primarily use CPUs, and layer 3
switches use ASICs. Option C is backward; both forward based on IP addresses, but
switches also use MAC addresses at layer 2. Option D is false, as modern layer 3
switches can run dynamic routing protocols like OSPF and EIGRP.**
3. An engineer is configuring IPv6 on an interface and needs to generate a link-
local address automatically. Which of the following statements accurately
describes the process used by the device?
,A. The interface will use the MAC address to create a modified EUI-64 format
interface identifier.
B. The device will randomly generate a 64-bit interface identifier for the link-local
address.
C. The link-local address will be manually configured using a static address in the
FE80::/10 range.
D. The interface will use its IPv4 address to derive a unique IPv6 link-local address.
Correct Answer: A. The interface will use the MAC address to create a modified
EUI-64 format interface identifier.
Rationale: When a device automatically generates an IPv6 link-local address, it
typically uses the MAC address of the interface to create a 64-bit interface identifier
in the modified EUI-64 format. While modern operating systems may implement
privacy extensions that can use random identifiers, the standard process defined in
RFCs uses the EUI-64 format from the MAC address. Option B describes an
alternative method but is not the standard automatic process for all devices. Option
C describes manual configuration, not automatic generation. Option D is incorrect
because IPv4 addresses are not used to derive IPv6 link-local addresses.**
4. What is the primary function of the Spanning Tree Protocol (STP) in a
switched network?
A. To create multiple broadcast domains and segment network traffic.
B. To provide a path for routing traffic between VLANs.
C. To prevent layer 2 loops by logically blocking redundant links.
D. To assign IP addresses to hosts dynamically.
, Correct Answer: C. To prevent layer 2 loops by logically blocking redundant
links.
Rationale: The primary purpose of STP is to ensure a loop-free logical topology in a
network with redundant physical links. It accomplishes this by placing certain ports
in a blocking state, preventing the forwarding of frames, which eliminates the
possibility of broadcast storms and MAC address instability. Option A is a function
of VLANs. Option B is a function of a router or layer 3 switch. Option D is the
function of DHCP.**
5. An employee reports that they are unable to access the corporate web server
using its hostname, but can access it by typing the IP address. Which of the
following is the most likely cause of this issue?
A. The DHCP server is unreachable.
B. The DNS server is not resolving the hostname correctly.
C. The ARP cache on the client is corrupted.
D. The default gateway is misconfigured.
Correct Answer: B. The DNS server is not resolving the hostname correctly.
Rationale: Accessing a resource by hostname requires DNS resolution to translate
the name into an IP address. Since the user can access the server by its IP address,
the network connectivity and routing are functional, isolating the problem to name
resolution. A DHCP issue would prevent the client from obtaining an IP
configuration. An ARP issue would cause communication failures to the default
gateway or local hosts. A misconfigured default gateway would prevent access to
resources on different networks entirely.**