⭐ Trusted by 700+ Buyers  ·  4.7★ Star Seller on Etsy  ·  $9.99/exam  ·  Grab it now →
Home › Cisco › 200-301 study guide

Cisco CCNA (200-301) Practice Test & Study Guide

Everything you need to plan your 200-301 prep: the exam format, what each domain covers, a week-by-week study plan, original practice questions, and what thousands of study-group comments reveal about where candidates slip up.

Last updated · By the NotJustExam team

About the Cisco CCNA (200-301) exam

The Cisco Certified Network Associate (CCNA) is a single, comprehensive exam, coded 200-301, that certifies you can install, configure, operate, and troubleshoot modern enterprise networks. It is Cisco's associate-level credential and the most widely recognized starting point for a career in networking, covering everything from how a packet moves across a routed network to the security and automation skills that now sit alongside traditional switching and routing.

It is aimed at early-career network engineers, support technicians, help-desk staff moving into infrastructure, and IT generalists who want to prove hands-on competence rather than vendor-neutral theory. Because the exam blends routing, switching, IP services, security fundamentals, and a layer of network automation, it reflects the day-to-day reality of running a real network rather than any single narrow skill.

The CCNA matters because it is a hiring filter many employers trust: passing it signals that you can reason about subnetting, VLANs, OSPF, and access control without hand-holding. It is also the foundation for Cisco's professional-level CCNP tracks, so the time you invest here carries forward.

Cisco CCNA (200-301) exam format at a glance

AttributeDetail (as of 2026, verify on the official page)
Exam code200-301 CCNA
Number of questionsCisco does not publish a fixed count; expect roughly 90-120 items
Question typesMultiple choice (single and multiple answer), drag-and-drop, and simulation/lab-style tasks
DurationApproximately 120 minutes
Passing scoreCisco does not publish an official cut score; aim for strong, consistent practice results
CostUSD $300 (plus local taxes; regional pricing varies)
LanguagesEnglish and Japanese
DeliveryPearson VUE test center or online proctored from home
Validity / recert3 years; renew by re-exam or Cisco continuing-education credits
PrerequisitesNone required; about 1 year of hands-on networking recommended

Cisco CCNA (200-301) domains & what they cover

  • Network Fundamentals (about 20%) — The conceptual bedrock: the role of routers, switches, and endpoints, cabling and interfaces, the OSI/TCP-IP models, and IPv4 plus IPv6 addressing. Subnetting lives here, and it underpins almost every other domain.
  • Network Access (about 20%) — Layer 2 switching: VLANs, trunking, EtherChannel, spanning tree, and wireless LAN basics including how access points connect to controllers. This is where you prove you can segment and connect a local network.
  • IP Connectivity (about 25%) — The largest domain, focused on routing: how the routing table is built, static routes, and dynamic routing with single-area OSPFv2, plus first-hop redundancy concepts. Expect the heaviest configuration and troubleshooting load here.
  • IP Services (about 10%) — The supporting services that keep a network usable: NAT, DHCP, DNS, NTP, SNMP, syslog, and quality-of-service basics. Smaller in weight but rich in real-world detail.
  • Security Fundamentals (about 15%) — Core defensive skills: access control lists, port security, device hardening, AAA concepts, and wireless security and VPN basics. It reflects that security is now part of every network role.
  • Automation and Programmability (about 10%) — The newer layer: controller-based networking, the idea of software-defined access, REST APIs, data formats like JSON, and configuration tools such as Ansible at a conceptual level. You need awareness, not deep coding.

Weightings are approximate and revised periodically, so confirm the current blueprint on Cisco's official exam-topics page before you sit.

How hard is Cisco CCNA (200-301)?

The CCNA is a genuinely challenging associate exam because of its breadth: you are tested on six domains in one sitting, and the simulation tasks demand that you actually configure and troubleshoot, not just recognize correct answers. The most common sticking points are subnetting under time pressure, spanning-tree and VLAN behaviour, and OSPF troubleshooting, while the automation domain trips up candidates who have never seen JSON or a REST call.

For someone with about a year of hands-on exposure, three to four months of focused study is realistic. Career-changers starting from zero should plan for five to six months and prioritize lab time, because reading alone rarely survives contact with the simulation questions.

How to prepare for Cisco CCNA (200-301): a study plan

  1. Weeks 1-3 — Fundamentals. Master the OSI/TCP-IP models, interfaces, and IPv4/IPv6 addressing. Drill subnetting until you can do it on paper in seconds; everything downstream depends on it.
  2. Weeks 4-6 — Switching and access. Build VLANs, trunks, EtherChannel, and spanning tree in a lab (Packet Tracer, CML, or real gear). Configure each feature yourself rather than only watching videos.
  3. Weeks 7-9 — Routing. This is the heaviest domain: static routing, then single-area OSPFv2, plus deliberate break-and-fix troubleshooting so you can read a routing table fluently.
  4. Weeks 10-11 — IP services and security. Layer in NAT, DHCP, DNS, NTP, ACLs, port security, and device hardening.
  5. Week 12 — Automation and review. Cover controller-based networking, REST APIs, and JSON conceptually, then take full-length timed practice exams.

Use practice questions diagnostically, not as memorization. After each set, review every item you missed and every item you guessed, trace the underlying concept back to its domain, and re-lab anything you cannot explain out loud. Treat repeated wrong answers as a study map, and reserve your final week for full-length timed runs to build exam stamina.

Cisco CCNA (200-301) FAQ

How much does the CCNA exam cost?

As of 2026 the 200-301 exam is USD $300 before local taxes, with regional pricing variation; verify the current fee on Cisco's official page when you book through Pearson VUE.

Are there any prerequisites?

No formal prerequisites. Anyone can register, though Cisco recommends roughly one year of hands-on networking experience to be comfortable with the configuration and troubleshooting tasks.

How long is the certification valid?

The CCNA is valid for three years. You can renew by retaking the exam, passing a higher-level exam, or earning Cisco continuing-education credits before it expires.

What is the retake policy if I fail?

Cisco requires a waiting period (typically five calendar days) before you can retake the same exam, and you pay the full fee again each attempt, so it pays to be ready before you book.

Can I take it from home?

Yes. The exam is offered both at Pearson VUE test centers and as an online-proctored exam from home, provided you meet the system, identification, and quiet-room requirements.

Is the CCNA worth it?

For most people entering networking, yes. It is a widely recognized hiring credential, validates practical skills employers care about, and serves as the foundation for Cisco's professional-level CCNP certifications.

Free 200-301 practice questions

5 original questions written for NotJustExam from the public 200-301 exam objectives and independently answer-checked. Try answering before you open the explanation.

Question 1

An access-layer switchport connects directly to a single desktop PC and has PortFast enabled. What is the primary risk that BPDU Guard is designed to mitigate on this port?

  1. A duplex mismatch causing collisions on the link
  2. Excessive broadcast traffic overwhelming the switch CPU
  3. An IP address conflict between the PC and another host
  4. An unauthorized switch or hub being connected to the port, creating a Layer 2 loop
Show answer & explanation

Answer: D. BPDU Guard immediately error-disables a PortFast-enabled port if it receives a BPDU, which normally only happens if another switch was plugged in, preventing a spanning-tree loop from forming on what should be an end-host-only port. A duplex mismatch is a physical/negotiation issue unrelated to BPDU Guard's function, so it is a plausible-sounding but incorrect distractor.

Source: official documentation

Question 2

A small office has one public IP address and needs all internal hosts in 10.0.0.0/24 to reach the internet simultaneously using that single address. Which NAT feature accomplishes this?

  1. Static NAT
  2. Dynamic NAT with a pool of addresses
  3. NAT overload (PAT)
  4. NAT64
Show answer & explanation

Answer: C. NAT overload, also called Port Address Translation (PAT), maps many internal private addresses to one public address by distinguishing sessions with different source port numbers, which is exactly what many-to-one internet access requires. Dynamic NAT with a pool is a tempting distractor because it also translates multiple hosts, but without overload it still needs one public address per active host and would run out with only a single public address available.

Source: official documentation

Question 3

An administrator wants to permit only TCP traffic destined for port 443 from any source to host 10.1.1.10, and deny everything else. Which type of ACL is required?

  1. A standard numbered ACL
  2. A VLAN access map
  3. An extended numbered or named ACL
  4. A reflexive ACL applied inbound only
Show answer & explanation

Answer: C. Only an extended ACL can match on source and destination address together with protocol and port number, which is required to filter specifically on destination host and TCP port 443. A standard ACL is a common wrong answer here because it is simpler and filters by source address only, so it cannot enforce the destination-port requirement in this scenario.

Source: official documentation

Question 4

In a RESTful API used to manage network devices, which HTTP method is typically used to retrieve the current configuration of a resource without modifying it?

  1. POST
  2. PUT
  3. DELETE
  4. GET
Show answer & explanation

Answer: D. GET is the standard, safe, and idempotent HTTP method for retrieving a resource's current state without causing any side effects on the server. POST is a frequent distractor because it is heavily used in APIs, but it is meant for creating a new resource or triggering an action, not simply reading existing data.

Source: official documentation

Question 5

As data moves down the OSI model from the application layer to be transmitted on the wire, at which layer is a source and destination MAC address added to the data?

  1. Layer 2 (Data Link)
  2. Layer 3 (Network)
  3. Layer 4 (Transport)
  4. Layer 1 (Physical)
Show answer & explanation

Answer: A. The Data Link layer encapsulates the Layer 3 packet into a frame and adds source and destination MAC addresses, which are used for local delivery on the same network segment. Layer 3 is a common wrong pick because it adds IP addressing, but IP addresses are logical network addresses, not the MAC (hardware) addresses added at Layer 2.

What 14,282 study-group comments reveal about 200-301

We summarised the public study-group discussion behind every question in our 200-301 bank and compared it with an independent AI review. Where they disagree, a posted answer key alone is not enough to trust — which is why every question in the full bank shows the community vote, a discussion summary and a reasoned explanation side by side.

1,393practice questions reviewed
14,282study-group comments summarised from Q2 2020 – Q3 2025
4%of questions where the answer commonly posted online is disputed
19%of single-answer questions where the community vote is split

The 200-301 traps that come up most

  • Control plane vs data plane vs management plane — The control plane builds routing/STP decisions, the data plane forwards traffic based on those decisions, and the management plane handles admin access like SSH — keep each plane's job separate when a question asks which plane something belongs to.
  • STP blocking ports still process BPDUs — A blocking port does not forward data frames, but it still receives and processes BPDUs — it is not fully inactive, it is simply excluded from the forwarding topology until spanning tree recalculates.
  • WPA3 splits authentication from encryption — WPA3 uses SAE (Simultaneous Authentication of Equals) to perform the authentication handshake, while AES still handles the actual data encryption — the two mechanisms serve different purposes and are not interchangeable.
  • Layer 2 discovery protocols don't need IP — CDP and LLDP operate at Layer 2 and can still exchange device and interface details even when an interface has no IP address configured, since neither protocol depends on IP connectivity to function.
  • Unknown destination MAC means flooding, not broadcast — When a switch has no entry for a destination MAC, it floods the frame out every port in the same VLAN except the source port — this unicast flooding behavior is normal and distinct from a broadcast frame.

Inside the full 200-301 practice bank

  • 1388 practice questions in an interactive web app, plus a printable PDF
  • The community-voted answer and a summary of the study-group discussion for each question
  • A step-by-step AI explanation of why the right answer is right — and why the others are not
  • One-time $9.99, lifetime access, no subscription

More certification study guides

Independent study material. NotJustExam is not affiliated with, endorsed by, or sponsored by any certification body; all certification names, trademarks and exam codes belong to their owners and are used for descriptive purposes only. The sample questions on this page are original items written for NotJustExam from the publicly available exam objectives. Exam facts change — always confirm details on the official exam page before you register.