Top 100 CCNA Interview Questions for Network Engineers (2026)
CCNA interviewers usually want to know whether you understand how networks behave in real life. This guide keeps the same 100 questions, but explains the answers in simple technical words that are easier to revise before an interview.
In This Lesson
Practice 100 CCNA interview questions across the core networking domains. Strong answers connect a concise definition to packet behavior, a configuration example, and verification.
Quick Learning Map
Keep this three-step view in mind as you work through the detailed lesson.
Cover the foundations
Review addressing, switching, routing, services, wireless, security, IPv6, and automation.
Explain with examples
Use small topologies, packet flows, and commands instead of isolated definitions.
Practice troubleshooting
State what evidence you would collect and how it narrows the fault domain.
Top 100 CCNA Interview Questions for Network Engineers (2026) at a Glance
Use this summary before moving into the detailed explanations, examples, commands, and checks.
Core focus
Practice 100 CCNA interview questions across the core networking domains.
Key connection
Cover the foundations → Explain with examples → Practice troubleshooting
Practical outcome
Strong answers connect a concise definition to packet behavior, a configuration example, and verification.
Exam Version Covered
This guide aligns with Cisco CCNA 200-301 topics: network fundamentals, network access, IP connectivity, IP services, security fundamentals, automation, and programmability. A few answers include practical job knowledge that interviewers commonly ask beyond the exam outline.
| Area | Focus |
|---|---|
| Certification | CCNA 200-301 |
| Best for | Entry-level to mid-level network engineers |
| Core topics | IPv4, IPv6, routing, switching, wireless, security, services, automation |
| Read time | Long-form interview revision guide |
10 Categories
Category 1: OSI Model and Network Fundamentals
Q1. Name the seven OSI model layers and what each one does.
Physical sends bits. Data Link uses frames and MAC addresses. Network uses IP packets and routing. Transport uses TCP or UDP ports. Session manages sessions. Presentation handles format, encryption, and compression. Application is where protocols like HTTP, DNS, and FTP live.
Q2. What is the difference between TCP and UDP?
TCP is reliable and connection-based. It uses a handshake, acknowledgments, retransmission, and ordered delivery. UDP is faster and connectionless. It is used when speed matters more than retransmitting old data, such as voice, video, DNS, and gaming.
Q3. What is the TCP three-way handshake?
The client sends SYN. The server replies SYN-ACK. The client sends ACK. After this, both sides agree on sequence numbers and the TCP session is ready.
Q4. What happens when you type a URL into a browser and press Enter?
The device checks DNS cache, resolves the domain to an IP, uses ARP for the local next-hop MAC, builds a TCP connection, performs TLS for HTTPS, sends an HTTP request, and receives the web page from the server.
Q5. What is ARP and how does it work?
ARP maps an IPv4 address to a MAC address on the same LAN. A host broadcasts “Who has this IP?” and the owner replies with its MAC. Routers do not forward ARP broadcasts.
show arp
clear arp-cacheQ6. What is a broadcast domain vs a collision domain?
A collision domain is where devices can collide while transmitting. Each switch port is its own collision domain. A broadcast domain is where Layer 2 broadcasts are received. VLANs and routers separate broadcast domains.
Q7. What is the difference between a hub, a switch, and a router?
A hub repeats bits to all ports. A switch forwards frames using MAC addresses. A router forwards packets between networks using IP addresses and a routing table.
Q8. What is encapsulation in networking?
Each layer adds its header as data moves down the stack: segment, packet, frame, and bits. The receiver removes those headers in reverse order.
Q9. What is a MAC address and how is it structured?
A MAC address is a 48-bit hardware address written in hexadecimal. The first half identifies the vendor OUI and the second half identifies the interface. Broadcast MAC is FF:FF:FF:FF:FF:FF.
Q10. Explain the difference between full-duplex and half-duplex.
Half-duplex sends or receives, but not both at the same time. Full-duplex sends and receives at the same time. Modern switched Ethernet is full-duplex; duplex mismatches cause errors and poor performance.
Category 2: IP Addressing and Subnetting
Q11. What are the IPv4 address classes and their default subnet masks?
Class A is /8, Class B is /16, Class C is /24, Class D is multicast, and Class E is reserved. Today networks use CIDR, but classes are still asked in interviews. Private ranges are 10.0.0.0/8, 172.16.0.0/12, and 192.168.0.0/16.
Q12. Subnet a /24 network into subnets that each support at least 30 hosts.
You need 5 host bits because 2^5 - 2 = 30. That gives a /27 mask, 255.255.255.224. A /24 becomes eight /27 subnets, each with 30 usable hosts and block size 32.
Q13. What is VLSM and why does it matter?
VLSM lets you use different subnet masks inside the same network. It saves IP addresses because each subnet gets the size it actually needs.
Q14. What is CIDR and how does it differ from classful addressing?
CIDR uses prefix notation like /24 and allows any prefix length. Classful addressing forced networks into A, B, or C sizes. CIDR saves addresses and supports route summarization.
Q15. How do you determine the network, broadcast, and host range for 172.16.45.14/20?
/20 is 255.255.240.0. The block size in the third octet is 16. The 45 falls in the 32-47 block. Network is 172.16.32.0, broadcast is 172.16.47.255, usable range is 172.16.32.1 to 172.16.47.254.
Q16. What is route summarization and when should you use it?
Route summarization combines many routes into one larger route. Use it at routing boundaries when addresses are contiguous. It makes routing tables smaller and convergence cleaner.
Q17. What is a loopback interface and why is it used on Cisco routers?
A loopback is a logical interface that stays up while the router is running. It is used for router IDs, management, BGP peering, and stable reachability.
Q18. What is the difference between unicast, multicast, and broadcast?
Unicast is one-to-one. Broadcast is one-to-all in the subnet. Multicast is one-to-a-group, using addresses from 224.0.0.0/4 in IPv4.
Q19. How many usable hosts are in a /30 subnet and what is it used for?
A /30 has four total addresses and two usable hosts. It is commonly used for point-to-point router links. /31 is also used on modern point-to-point links.
Q20. What is the purpose of the subnet mask?
The subnet mask tells the device which part of the IP is network and which part is host. It helps a device decide whether to ARP locally or send traffic to a gateway.
Category 3: VLANs and Switching
Q21. What is a VLAN and why do we use them?
A VLAN creates a separate Layer 2 broadcast domain on the same switch. VLANs improve segmentation, reduce broadcasts, and separate users or services without needing separate physical switches.
Q22. What is 802.1Q trunking and how does it work?
802.1Q adds a VLAN tag to frames on trunk links so multiple VLANs can cross one physical link. The native VLAN crosses untagged.
interface Gi0/1
switchport mode trunk
switchport trunk allowed vlan 10,20,30
switchport trunk native vlan 99Q23. How does a switch learn MAC addresses?
A switch reads the source MAC of incoming frames and maps that MAC to the incoming port. If the destination MAC is unknown, it floods the frame out other ports in the VLAN.
Q24. What is STP and why is it needed?
STP prevents Layer 2 loops by blocking redundant paths. Without STP, broadcasts can loop forever and bring down the network.
Q25. How is the STP Root Bridge elected?
The switch with the lowest bridge ID wins. Bridge ID includes priority and MAC address. Lower priority is preferred; if tied, lower MAC wins.
Q26. What is PortFast and when should you enable it?
PortFast moves an access port to forwarding immediately. Use it only on end-device ports. Pair it with BPDU Guard to protect against accidental switch connections.
spanning-tree portfast
spanning-tree bpduguard enableQ27. What is EtherChannel and what protocols negotiate it?
EtherChannel bundles multiple physical links into one logical link. LACP is the open standard. PAgP is Cisco proprietary. Member links must match speed, duplex, VLAN, and trunk settings.
Q28. How does inter-VLAN routing work on a Layer 3 switch?
The switch creates an SVI for each VLAN and enables IP routing. Each SVI acts as the gateway for that VLAN, and routing happens in hardware.
Q29. What is DTP and should you leave it enabled?
DTP negotiates trunks automatically between Cisco switches. Best practice is to hardcode access or trunk mode and disable negotiation on user-facing ports.
Q30. What is DHCP Snooping and how does it work?
DHCP Snooping allows DHCP server messages only from trusted ports. It blocks rogue DHCP servers and builds a binding table used by Dynamic ARP Inspection and IP Source Guard.
Category 4: Routing Protocols
Q31. What is administrative distance and why does it matter?
Administrative distance tells how trusted a route source is. Lower is better. Connected is 0, static is 1, EIGRP internal is 90, OSPF is 110, RIP is 120, and iBGP is 200.
Q32. What is the difference between distance-vector and link-state routing protocols?
Distance-vector protocols learn from neighbors. Link-state protocols build a topology database and calculate best paths. Link-state protocols usually scale and converge better.
Q33. How does OSPF elect a DR and BDR?
On broadcast networks, OSPF elects a DR and BDR to reduce adjacencies. Highest priority wins. If tied, highest router ID wins. Priority 0 means the router cannot become DR or BDR.
Q34. What is OSPF cost and how is it calculated?
OSPF cost is reference bandwidth divided by interface bandwidth. The default reference can make Fast Ethernet and Gigabit both cost 1, so many networks change the reference bandwidth.
Q35. What are the OSPF neighbor states?
Common states are Down, Init, 2-Way, Exstart, Exchange, Loading, and Full. Full means the OSPF database is synchronized.
Q36. What are the EIGRP successor and feasible successor?
The successor is the best route. The feasible successor is a loop-free backup route that can be used immediately if the successor fails.
Q37. What is a floating static route?
A floating static route has a higher administrative distance than the main route. It stays inactive until the primary route disappears.
Q38. What is the purpose of a routing table and how does a router select a best path?
The routing table stores best routes. The router uses longest prefix match first, then administrative distance, then metric if needed.
Q39. What is BGP and when would a CCNA-level engineer encounter it?
BGP is the internet routing protocol between autonomous systems. CCNA engineers may see it on ISP edge, multi-homed internet, data center, or SD-WAN networks.
Q40. What commands show the routing table and verify OSPF neighbors?
show ip route
show ip route ospf
show ip ospf neighbor
show ip ospf interface brief
show ip eigrp topologyCategory 5: Network Services: DHCP, DNS, NAT
Q41. Walk me through the DHCP DORA process.
DORA means Discover, Offer, Request, Acknowledge. The client asks for an IP, the server offers one, the client requests it, and the server confirms the lease.
Q42. What is a DHCP relay agent?
A relay forwards DHCP requests from one subnet to a DHCP server on another subnet. On Cisco, configure ip helper-address on the gateway interface.
Q43. How does DNS resolution work?
The client asks a recursive resolver. If not cached, the resolver queries root, TLD, and authoritative servers, then returns the final record to the client.
Q44. What is NAT and what are the three types?
Static NAT maps one private IP to one public IP. Dynamic NAT maps private IPs to a public pool. PAT or NAT overload lets many inside hosts share one public IP using ports.
Q45. What is the difference between NTP client and NTP server modes?
An NTP client receives time. An NTP server provides time. A device can sync from an upstream server and also serve time to downstream devices.
Q46. What ports do common protocols use?
HTTP 80 TCP, HTTPS 443 TCP, SSH 22 TCP, DNS 53 UDP/TCP, DHCP 67/68 UDP, SNMP 161/162 UDP, SMTP 25 TCP, FTP 20/21 TCP.
Q47. What is SNMP and what are its three versions?
SNMP monitors network devices. v1 and v2c use plain community strings. SNMPv3 supports authentication and encryption and is the preferred production version.
Q48. What is Syslog and how does Cisco IOS use it?
Syslog sends device logs to a central server. Cisco severity levels go from 0 emergency to 7 debugging.
logging host 192.168.1.100
logging trap informational
service timestamps log datetime msecQ49. What is FTP and how does active vs passive mode differ?
FTP uses port 21 for control and port 20 or dynamic ports for data. Active mode can break through firewalls because the server connects back to the client. Passive mode is usually firewall-friendlier.
Q50. What is QoS and what are the three models?
QoS controls traffic priority. Best effort treats all traffic equally. IntServ reserves resources per flow. DiffServ marks traffic with DSCP and is the common enterprise model.
Category 6: WAN Technologies and VPN
Q51. What is the difference between a leased line, MPLS, and broadband WAN?
A leased line is dedicated private bandwidth. MPLS is a provider-managed private WAN. Broadband is cheaper shared internet, often used with SD-WAN.
Q52. What is a GRE tunnel and what problem does it solve?
GRE creates a virtual tunnel over IP and can carry multicast. It is often combined with IPsec when routing protocols need to run across encrypted WAN links.
Q53. What is IPsec and what are its two protocols?
IPsec secures IP traffic. AH provides authentication without encryption. ESP provides encryption and integrity and is the common real-world choice.
Q54. What is the difference between transport mode and tunnel mode in IPsec?
Transport mode protects only the payload. Tunnel mode protects the entire original IP packet inside a new packet and is used for site-to-site VPNs.
Q55. What is PPPoE and where is it used?
PPPoE runs PPP over Ethernet and is common on DSL links. It uses authentication and lowers usable MTU to 1492 because of overhead.
Q56. What is SD-WAN and how is it different from traditional WAN?
SD-WAN uses central policy and live link quality to choose paths per application. Traditional WAN usually uses static routing decisions and manual configuration.
Q57. What is DMVPN and what problem does it solve?
DMVPN lets spoke sites build direct VPN tunnels to each other when needed, instead of sending all traffic through the hub. It uses NHRP, GRE, and IPsec.
Q58. What is the difference between a site-to-site VPN and a remote access VPN?
Site-to-site VPN connects two networks through gateways. Remote access VPN connects one user device to the company network through a client or browser.
Q59. What is MTU and why does it cause problems in tunnels?
MTU is the largest packet a link can carry. Tunnels add headers, so large packets may need fragmentation. MSS clamping helps avoid black-hole issues.
Q60. What is HSRP and how does it provide gateway redundancy?
HSRP lets two routers share a virtual gateway IP and MAC. One is active and one is standby. If active fails, standby takes over.
Category 7: Wireless Networking
Q61. What are the key differences between 802.11 Wi-Fi standards?
802.11b/g use 2.4 GHz with lower speed. 802.11n adds MIMO and 2.4/5 GHz. 802.11ac improves 5 GHz performance. 802.11ax, Wi-Fi 6/6E, adds OFDMA, BSS coloring, and 6 GHz support.
Q62. What is CSMA/CA and how does it differ from CSMA/CD?
CSMA/CD detects collisions on half-duplex Ethernet. CSMA/CA avoids collisions in wireless by listening first and using random backoff.
Q63. What is the difference between 2.4 GHz and 5 GHz Wi-Fi?
2.4 GHz has better range but more interference and fewer clean channels. 5 GHz has more channels and higher speed but shorter range.
Q64. What are the main wireless security protocols and which should you use?
WEP and WPA/TKIP are weak. WPA2 with AES is common. WPA3 is stronger. Enterprises should use WPA2/WPA3 Enterprise with 802.1X where possible.
Q65. What is the difference between an autonomous AP and a controller-based AP?
An autonomous AP is managed individually. A controller-based AP is managed by a WLC using CAPWAP, which simplifies RF, roaming, policy, and firmware operations.
Q66. What is a BSS, SSID, and BSSID?
SSID is the wireless network name. BSS is one AP radio and its clients. BSSID is the MAC address for that specific AP radio/SSID instance.
Q67. What is 802.1X authentication for wireless?
802.1X uses a supplicant, AP, and RADIUS server to authenticate users individually. Common EAP methods include EAP-TLS and PEAP.
Q68. What causes wireless interference and how do you mitigate it?
Interference comes from overlapping channels, nearby APs, microwaves, Bluetooth, and poor power planning. Use proper channel design, site surveys, and 5 GHz/6 GHz where suitable.
Q69. What is a wireless site survey and when is one needed?
A site survey checks coverage, interference, signal strength, and AP placement. It is important for new deployments, high-density areas, and troubleshooting.
Q70. What is the difference between FlexConnect and local switching in wireless?
With central switching, client traffic tunnels to the WLC. With FlexConnect/local switching, traffic exits locally at the branch AP, which saves WAN bandwidth.
Category 8: Network Security
Q71. What is an ACL and what are the two types on Cisco?
A standard ACL filters mainly by source IP. An extended ACL filters by source, destination, protocol, and ports. Every ACL ends with an implicit deny.
Q72. What is the difference between a firewall and an IPS?
A firewall permits or denies sessions based on policy and state. An IPS inspects traffic for attacks and blocks malicious traffic inline.
Q73. What is AAA in network security?
AAA means Authentication, Authorization, and Accounting: who you are, what you can do, and what you did.
Q74. What is the difference between RADIUS and TACACS+?
RADIUS is commonly used for user network access and uses UDP. TACACS+ is common for device administration, uses TCP 49, and supports command authorization.
Q75. What is a common Layer 2 attack and how do you prevent it?
MAC flooding is stopped with port security. VLAN hopping is reduced by disabling DTP and changing the native VLAN. ARP spoofing is reduced with DHCP Snooping and Dynamic ARP Inspection.
Q76. How do you secure a Cisco switch against unauthorized access?
Use SSH, AAA, strong enable secret, SNMPv3, disabled unused ports, DHCP Snooping, DAI, BPDU Guard, PortFast on access ports, and proper management VLANs.
Q77. What is port security and what are the three violation modes?
Port security limits allowed MAC addresses. Shutdown disables the port, restrict drops and logs, protect drops silently.
Q78. What is the CIA triad in security?
Confidentiality protects data from unauthorized access. Integrity protects data from tampering. Availability keeps systems usable when needed.
Q79. What is the difference between symmetric and asymmetric encryption?
Symmetric encryption uses one shared key and is fast. Asymmetric encryption uses public/private keys and is slower but solves secure key exchange and digital signatures.
Q80. What is a VPN and what are the key components that make it secure?
A VPN creates an encrypted tunnel. It needs encryption, integrity checking, peer authentication, key exchange, and anti-replay protection.
Category 9: Troubleshooting and Network Management
Q81. What is the OSI troubleshooting methodology and which direction do you go?
You can troubleshoot bottom-up, top-down, or divide-and-conquer. In interviews, explain where you start based on symptoms, then move layer by layer.
Q82. What does each field mean in show interfaces?
It shows physical and protocol state, errors, drops, bandwidth, duplex, reliability, and counters. CRC errors often point to physical or duplex problems.
Q83. What are ping and traceroute used for?
Ping tests IP reachability with ICMP. Traceroute shows the path and where packets may stop by using TTL expiry responses.
Q84. What does show ip interface brief tell you?
It gives a fast view of interface names, IP addresses, physical status, and line protocol status.
Q85. A user can ping the gateway but cannot access the internet. How do you troubleshoot?
Check DNS, then ping an internet IP, verify default route, NAT, ACLs, WAN interface, and whether the router itself can reach the internet.
Q86. How do you find which interface or VLAN a host is connected to?
Use ARP to find the MAC, then use the MAC address table to find the switch port. Follow uplinks switch by switch if needed.
Q87. What is CDP and what does it reveal?
CDP shows directly connected Cisco devices, including hostname, platform, IP, and ports. Disable it on untrusted links.
Q88. How do you recover a Cisco switch from an incorrect configuration?
If changes are unsaved, reload to return to startup-config. If saved or locked out, use console access, backups, or password recovery depending on the problem.
Q89. What is the difference between running-config and startup-config?
Running-config is active in RAM. Startup-config is saved in NVRAM and loads after reload. Save changes with copy running-config startup-config.
Q90. What are the most useful Cisco IOS show commands for daily troubleshooting?
show ip interface brief
show interfaces status
show ip route
show vlan brief
show interfaces trunk
show mac address-table
show ip ospf neighbor
show ip nat translations
show arp
show cdp neighbors detailCategory 10: IPv6, SDN, and Network Automation
Q91. Why was IPv6 created and what is its address size?
IPv6 was created because IPv4 addresses were running out. IPv6 uses 128-bit addresses, written in hexadecimal groups.
Q92. What are the main types of IPv6 addresses?
Global unicast is internet-routable. Link-local starts with FE80 and stays on the local link. Unique local is private. Multicast starts with FF. Loopback is ::1.
Q93. What is SLAAC and how does IPv6 address autoconfiguration work?
SLAAC lets a host build its own IPv6 address using router advertisements and a local interface ID. IPv6 uses NDP instead of ARP.
Q94. What is SDN and how does it differ from traditional networking?
SDN separates control from forwarding and uses a controller to manage policy centrally. Traditional networking configures each device more independently.
Q95. What is the difference between northbound and southbound API in SDN?
Northbound APIs connect applications to the controller. Southbound APIs connect the controller to network devices.
Q96. What is a REST API and how is it used in network automation?
A REST API uses HTTP methods like GET, POST, PUT, PATCH, and DELETE. Network tools use REST APIs to read state and push changes without CLI scraping.
Q97. What is the difference between NETCONF and RESTCONF?
NETCONF commonly uses SSH and XML with strong configuration operations. RESTCONF exposes YANG data through HTTPS and is easier for beginners using JSON.
Q98. What is Ansible and how is it used for network automation?
Ansible uses YAML playbooks to automate devices over SSH or APIs. It is agentless and useful for repeatable network configuration and checks.
Q99. What is the difference between JSON and XML in network automation?
JSON is lightweight and common in REST APIs. XML is more verbose and common in NETCONF. Both describe structured data.
Q100. What certifications and skills should a CCNA engineer pursue next?
Good next steps include CCNP Enterprise, CCNP Security, CCNP Data Center, cloud networking, Python basics, Ansible, Terraform, GNS3, Cisco CML, and real lab practice.
Quick Reference: CCNA Must-Know Commands
| Command | Use |
|---|---|
| show ip interface brief | Interface IP and status overview |
| show ip route | Routing table |
| show vlan brief | VLANs and access ports |
| show interfaces trunk | Trunk state and allowed VLANs |
| show mac address-table | MAC-to-port mappings |
| show spanning-tree | STP root and port states |
| show ip ospf neighbor | OSPF adjacency state |
| show ip nat translations | NAT table |
| show arp | IP-to-MAC cache |
| show cdp neighbors detail | Connected Cisco neighbors |
| show ip access-lists | ACL entries and counters |
| copy run start | Save configuration |
What Interviewers Are Actually Looking For
- Concept clarity: Explain why something works, not just a memorized line.
- Troubleshooting process: Move through the problem logically.
- CLI comfort: Know daily show commands without hesitation.
- Honesty: Admit gaps and explain how you would verify the answer.