What You Actually Need to Know About the CCNA v7 Final Exam
The CCNA v7 Final Exam is the comprehensive assessment at the end of Cisco Networking Academy's curriculum. It covers everything from subnetting and VLAN configuration to OSPF routing, basic security policies, and automation fundamentals. You get 90 minutes, a mix of multiple choice, drag-and-drop, and performance-based tasks. The pass rate hovers around 70-75% for people who actually do the labs, and maybe 40% for people who just read the materials. That gap matters more than anything else. I took this exam during my second semester at the academy. I'd spent about 80 hours on Packet Tracer labs, done every chapter quiz, and still scored 720 out of 1000. Barely passing. The reason wasn't that I didn't know the material. It was that I hadn't practiced the PBQ format enough. The exam's performance-based questions are not like the scenario questions in course materials. They're live CLI environments where you configure actual devices and then the grading engine checks your running config line by line. If you miss one comma or leave a command in the wrong context, you get zero points for that entire task.
Working Through the Ccna V7 Final Exam
Here is the practical breakdown of how to approach this exam, based on what I've seen people do right and what I've done wrong myself. Phase 1: The subnetting and addressing section. This comes early and it's worth about 15-20% of your total score. You will get a /26, /27, or maybe /28 subnet problem. You need to calculate network address, broadcast address, first usable host, and last usable host. I recommend doing this on scratch paper before touching the keyboard. In the exam interface, you won't have a calculator tool. Writing it out first cuts your time on this section from about 12 minutes down to 4. One thing nobody tells you: the exam sometimes gives you a subnet that's been illegally subnetted, meaning the subnets overlap. You need to spot that and configure based on the largest required host count, not the first one listed. I lost 15 points on a practice exam because I followed the first requirement and ignored the second. Phase 2: VLAN and trunk configuration. This is usually a PBQ where you're given a switch topology and told to create VLANs, assign ports, and configure trunks. The command sequence matters less than the order. If you configure the trunk before the VLAN exists on the switch, the port will still show as trunking but traffic won't pass. Create the VLAN first, assign the access ports, then configure the trunk encapsulation and allowed VLANs. In Packet Tracer, the command is typically:
Switch(config)vlan 10
Switch(config-vlan)name SALES
Switch(config-vlan)exit
Switch(config)interface range fa0/1-24
Switch(config-if-range)switchport mode access
Switch(config-if-range)switchport access vlan 10
Switch(config)interface gi0/1
Switch(config-if)switchport mode trunk I spent two full days just grinding VLAN and trunk PBQs in Packet Tracer. Not the exam simulator. Actual Packet Tracer files from the course. The muscle memory from typing those commands in the right order is what separates people who finish on time from people who are still configuring trunks when the clock hits 60 minutes. Phase 3: Routing protocols. This is where most people fall apart. OSPF configuration on a PBQ requires you to enable the protocol, set the correct area, and use the right wildcard masks. The wildcard mask is the part people mess up. A /24 subnet (255.255.255.0) gets a wildcard of 0.0.0.255. A /26 gets 0.0.0.63. If you use a subnet mask instead of a wildcard mask in the OSPF network statement, the exam marks it wrong. I learned this the hard way on a practice test. The router config looked functionally correct to me but the grader was checking exact command syntax.
Get the Full Details

For EIGRP, you need to know the difference between classic EIGRP and named EIGRP. The v7 curriculum tests named EIGRP. The command structure is: Router(config)router eigrp CCNA
Router(config-rtr)network 192.168.1.0 0.0.0.255
Router(config-rtr)autonomous-system 65001 The autonomous system number must match across all routers in the same domain. If Router A is AS 65001 and Router B is AS 65002, they will not form an adjacency. I've seen this happen in lab environments too, not just exams. Two routers sitting there with full CLI configs that never exchange routes. The debug ip eigrp packets command will show you exactly where the handshake is failing.
Phase 4: Security and ACLs. Standard ACLs go closest to the destination. Extended ACLs go closest to the source. This rule costs people points because they put a standard ACL on the source interface instead of the destination interface. The logic is simple: a standard ACL only filters by source IP, so placing it near the destination means you're not accidentally blocking legitimate traffic that should reach other destinations on the same router. For the PBQ on this topic, you'll often need to create an extended ACL that permits specific traffic and denies everything else. The implicit deny at the end of every ACL is automatic. You don't type it. If you type deny ip any any at the bottom of your ACL, the exam doesn't care—it's redundant but not wrong. However, if you forget to permit the traffic that needs to pass, the implicit deny will block it and your connectivity test will fail. Phase 5: Automation and programmability. This is the newest section in v7 and it's the one most people haven't studied enough. You need to know basic JSON structure, the difference between REST and NETCONF, and how to use Python to pull device data. The PBQ here might show you a Python script with a missing line and ask you to identify what's wrong. Common issue: the script uses requests.get() without specifying auth=(username, password) for device APIs that require authentication. The request returns a 401 and the script fails silently if error handling isn't in place.
One useful shortcut: in the exam simulator, you can pause the timer on PBQs. Use it. When you hit a routing table question that requires manual route summing, pause, work it out on paper, then resume. Don't rush it. The timer doesn't start counting until you submit the PBQ.

Where the Exam Fails You
Let me be clear about the weaknesses in this exam. The PBQs are graded by automated scripts, which means there is no partial credit for getting 90% of the configuration right. If the task asks you to configure OSPF on three interfaces and you get two right but the third wildcard mask is wrong, you get zero for that entire PBQ. This is intentional design from Cisco's side—they want exact compliance. It's also frustrating because in real networking, a near-correct config often works fine. The exam doesn't care about real-world pragmatism here. Another issue: the exam simulator from NetAcad doesn't perfectly replicate the actual exam interface. The timing is the same but the PBQ environments sometimes behave differently. I noticed this when a trunk negotiation that worked in my practice PBQ failed in the actual exam because the DTP negotiation mode was set to desirable on one side and auto on the other, creating an unexpected Dynamic Negotiation outcome. The practice environment had both sides set to trunk mode explicitly. If you're short on time and need a more reliable prep route, I'd recommend supplementing the NetAcad simulator with Jeremy's IT Lab on YouTube. His OSPF and VLAN labs walk through the exact CLI sequences you'll see in the exam, and he explains why each command matters. Free, no subscription, and closer to the actual exam depth than the course material alone.
Bottom line: the CCNA v7 Final Exam tests whether you can configure networks under time pressure, not whether you can explain how they work. Practice the CLI until the commands are automatic. Study the PBQ format specifically. And don't skip the automation section just because it feels tacked on—that's where the exam is adding weight each year.