Question 1
What is TTL?
Correct Answer:
Time to live
Explanation:
TTL stands for Time to Live. It is a field in the IP header that determines how long a packet is allowed to live in the network, effectively limiting how many hops it can traverse. With each router the value is decreased by one, and when it reaches zero the packet is dropped to prevent endless looping. This behavior also enables network diagnostics like traceroute, which probes paths by sending packets with progressively higher TTL values. Note that TTL is not about time to login, total time latency, or time to link; it’s about the maximum number of routers a packet can pass through before being discarded. In IPv6 the concept is similar and is referred to as Hop Limit.
Question 2
Is the order of Access List and Control List rules important?
Correct Answer:
Yes
Explanation:
The order of Access Lists and Control Lists determines what actually happens to traffic because rules are evaluated in sequence and the first match wins. As a packet is processed, the device checks each rule from top to bottom and applies the action of the first rule that matches. That means where you place a specific deny or permit changes the outcome for many packets. For example, if you want to block a single host but allow others, you must place that block rule before any broader permit rule; otherwise the broad permit might match first and the block would never take effect. There’s usually an implicit deny at the end for anything that doesn’t match any rule, which reinforces why you must be explicit about what should be allowed. This is why the order is important for implementing the intended traffic policy.
Question 3
Where do you specify what type of encryption is used for a PPP based tunnel?
Correct Answer:
Highest match between client and server
Explanation:
PPP-based tunnels establish encryption through negotiation between the two peers. Neither side fixes the algorithm in advance; instead, each end advertises its supported encryption options and the tunnel settles on the strongest common option. That’s why encryption is determined by the highest match between client and server—the strongest cipher both sides support is automatically chosen during setup. You can influence the result by configuring what each side allows, but you don’t pick a single cipher in the tunnel configuration itself.
Question 4
Which statement correctly matches the two RouterOS firewall sections with their chains?
Correct Answer:
Filter uses Forward, Input, Output; NAT uses src-nat, dst-nat
Explanation:
In RouterOS, firewall rules are organized into two sections with different purposes and chain concepts. The Filter section handles general packet filtering and uses the chains that describe where a packet is in its journey: input for traffic destined to the router, forward for traffic passing through the router, and output for traffic generated by the router itself. The NAT section deals with address translation and uses the NAT actions src-nat (source NAT) and dst-nat (destination NAT) to rewrite addresses as packets enter or leave the network. So, the correct pairing is that Filter uses Forward, Input, and Output, while NAT uses src-nat and dst-nat. The other options mix these roles, which doesn’t align with how RouterOS structures firewall rules.
Question 5
What are custom chains used for?
Correct Answer:
Organize our rules
Explanation:
Custom chains are a way to organize firewall rules into logical blocks, making complex filtering policies easier to read and manage. In RouterOS, you can put a group of related rules into a single custom chain and use a jump from the main chains (like input or forward) to that chain. The rules inside the custom chain run, then control returns to the main chain. This modular approach lets you reuse and modify a whole set of rules in one place, or apply the same block of rules from multiple places without duplicating them. For example, you could create a custom chain for all VPN-related filtering and jump to it from several interfaces. Then you keep the VPN rules centralized in that chain, keeping the primary chains clean. Custom chains don’t increase throughput by themselves, don’t encrypt rules, and don’t define routes. They’re simply a tool for organizing and modularizing policy.
Question 1
Exam overview

About this Exam

Prepare with the MikroTik Certified Network Associate (MTCNA) Modules Practice Test practice quiz. This question bank includes 10 questions covering tunnel, list, encryption, chains, and mikrotik. Use it to review important concepts, identify knowledge gaps, and build confidence for the related exam, course, or assessment.

More details

Additional Information

MikroTik Certified Network Associate (MTCNA) Modules Practice Test

This practice set contains 10 questions from the matching question bank and focuses on tunnel, list, encryption, chains, and mikrotik. Work through each question carefully, review the provided solutions, and revisit topics that need more study before your next attempt.

This is an independent study resource intended for practice and review; it is not an official examination or an endorsement by any organization named in the title.

Quiz information

Frequently Asked Questions

The complete question count is available after full access is unlocked.
No fixed duration is currently configured for this quiz.
Question explanations are included where they are available in the quiz content, helping you review the reasoning after answering.
Yes. You can retake the practice test again as you continue studying during your available access period.
After your access is confirmed, you can continue into the complete practice exam from this quiz flow.
Unless explicitly stated otherwise, this page provides independent practice material for study and exam preparation and is not the official examination itself.
Keep studying

Related Questions