All certifications / CCNA / Cheat sheet
CCNA 200-301 v2.0 cheat sheet
Domain 1: Network infrastructure & connectivity (25%)
Exam tips
- Collisions and late collisions show up on the half-duplex side; CRC errors and runts show up on the full-duplex side. A speed mismatch usually brings the link down, while a duplex mismatch leaves it up but slow and error-prone.
- 'Bare metal' means type 1; 'runs on top of an existing OS' means type 2. If a question stresses sharing the host kernel and fast, lightweight startup, the answer is containers, not VMs.
- In spine-leaf, leaves never connect to each other and spines never connect to each other. Questions often show a diagram and ask which link violates the design, or ask why the design gives predictable latency.
- Watch for 172.x addresses: only 172.16 through 172.31 are private. An address like 172.32.1.1 is public, and questions use that to trap you. Also remember usable hosts is always 2 to the power of host bits minus 2.
- A 169.254.x.x address never means 'fix the PC's IP'; it means the DHCP exchange failed. Look for the answer about VLANs, cabling, the DHCP server or the helper address. Partial reachability points to the mask; local-only reachability points to the gateway.
- Memorize the first characters: 2 or 3 is global unicast, FD is unique local, FE80 is link-local, FF is multicast. Anycast has no prefix of its own, which is a favourite trick question.
- In EUI-64, remember both steps: insert FFFE in the middle and flip the seventh bit. Most wrong answer choices do only one of the two. A host with only an fe80 address is not receiving RAs.
- If the question asks for non-overlapping 2.4 GHz channels, answer 1, 6 and 11. If it asks which band gives the most range, answer 2.4 GHz; if it asks for the most channels and capacity, answer 5 or 6 GHz.
- Know which OS each command belongs to: ipconfig on Windows, ifconfig on macOS, ip addr on Linux. Questions often show output and ask which platform or which setting is wrong.
- The helper address goes on the interface that receives the client broadcasts, not the interface facing the server. This placement is a common exam trap.
Key terms
- CRC error
- A received frame whose frame check sequence does not match its contents, usually caused by noise, a damaged cable or connector, or a duplex mismatch.
- Late collision
- A collision detected after the first 64 bytes of a frame, typically caused by a duplex mismatch or an over-length cable.
- Duplex mismatch
- One end of a link runs full duplex and the other half duplex, causing collisions on one side and CRC errors and runts on the other.
- Runt and giant
- A runt is a frame smaller than 64 bytes; a giant is larger than the maximum allowed frame size.
- Auto-MDIX
- A port feature that detects whether a straight-through or crossover cable is attached and adjusts transmit and receive pairs automatically.
- Multimode vs single-mode fiber
- Multimode has a wider core for shorter runs; single-mode has a narrow core and laser light for long distances.
- Autonegotiation
- The process by which two Ethernet ports agree on the best common speed and duplex.
- Type 1 hypervisor
- A bare-metal hypervisor installed directly on server hardware, such as ESXi, Hyper-V or KVM.
- Type 2 hypervisor
- A hosted hypervisor that runs as an application on a desktop operating system, such as VirtualBox or VMware Workstation.
- Virtual machine (VM)
- A software-defined computer with its own guest operating system and kernel, running on a hypervisor.
- Container
- An isolated application package that shares the host operating system kernel instead of running its own OS.
- Virtual switch (vSwitch)
- Software inside a hypervisor that switches traffic between VM virtual NICs and the host's physical NICs.
- Guest OS
- The operating system installed inside a virtual machine.
- Orchestration
- Automated scheduling, scaling and networking of many containers across hosts, as Kubernetes does.
- Access / distribution / core
- The three campus layers: end-device connectivity, aggregation and policy, and a high-speed backbone.
- Collapsed core
- A two-tier design where the core and distribution layers are combined into one set of switches.
- Spine-leaf
- A data-center design in which every leaf connects to every spine, giving equal hop count between any two servers.
- East-west traffic
- Traffic between servers inside the data center, as opposed to north-south traffic entering or leaving it.
- Hub-and-spoke
- A WAN topology where branch sites connect to a central site rather than directly to each other.
- SOHO
- Small office/home office: a small network usually served by one combined router, switch, access point and firewall.
- IaaS / PaaS / SaaS
- Cloud service models where the provider manages progressively more of the stack, from infrastructure up to the full application.
- Subnet mask / prefix length
- The bits that identify the network portion of an address, written as dotted decimal or as /n.
- Block size
- 256 minus the mask value in the interesting octet; the distance between consecutive subnet IDs.
- Network ID
- The first address in a subnet, with all host bits set to 0, which identifies the subnet itself.
- Broadcast address
- The last address in a subnet, with all host bits set to 1, used to reach every host on that subnet.
- VLSM
- Variable-length subnet masking: using different prefix lengths within one address space to size each subnet to its need.
- RFC 1918
- The standard defining private IPv4 ranges 10.0.0.0/8, 172.16.0.0/12 and 192.168.0.0/16.
- Default gateway
- The router address a host sends off-subnet traffic to; it must be inside the host's own subnet.
- APIPA
- Automatic Private IP Addressing: a self-assigned 169.254.x.x/16 address used when a DHCP client gets no reply.
- Duplicate address
- Two devices configured with the same IP, causing ARP entries to flip and intermittent connectivity.
- ARP
- Address Resolution Protocol, which maps a known IPv4 address to the MAC address on the local segment.
- Subnet mask
- The value that tells a host which part of an address is the network, and therefore which destinations are local.
- ip helper-address
- An IOS interface command that relays client DHCP broadcasts to a DHCP server on another subnet.
- Global unicast address
- A publicly routable IPv6 address, currently allocated from 2000::/3.
- Unique local address
- A private IPv6 address from fc00::/7 (in practice fd00::/8), not routed on the internet.
- Link-local address
- An automatically created fe80::/10 address valid only on one link, used by neighbor discovery and routing protocols.
- Multicast address
- An ff00::/8 address that delivers a packet to every interface that has joined the group.
- Solicited-node multicast
- An ff02::1:ff00:0/104 address derived from the last 24 bits of a unicast address, used for address resolution instead of broadcast.
- Anycast
- A unicast address assigned to multiple devices so that packets are routed to the nearest one.
- Interface ID
- The last 64 bits of a typical IPv6 address, identifying the interface within its /64 subnet.
- EUI-64
- A method of building a 64-bit interface ID from a 48-bit MAC by inserting FFFE and flipping the seventh bit.
- SLAAC
- Stateless address autoconfiguration, where hosts build their own address from the prefix in a router advertisement.
- Router advertisement (RA)
- An ICMPv6 message from a router announcing the prefix, default gateway and configuration flags.
- Router solicitation (RS)
- An ICMPv6 message a host sends to ff02::2 asking routers to send an RA immediately.
- Duplicate address detection (DAD)
- A check in which a host sends a neighbor solicitation for its tentative address to make sure no one else uses it.
- Stateful DHCPv6
- A DHCPv6 mode, signalled by the RA M flag, in which a server assigns and tracks each host's address.
- ipv6 unicast-routing
- The global IOS command that enables IPv6 forwarding and router advertisements.
- SSID
- The service set identifier, the network name that clients use to find and join a WLAN.
- BSSID
- The MAC address of an AP radio, uniquely identifying a basic service set.
- ESS
- An extended service set: several APs with the same SSID joined by a wired network so clients can roam.
- Non-overlapping channels
- Channels whose frequencies do not overlap; in 2.4 GHz these are 1, 6 and 11.
- Co-channel interference
- Contention when nearby APs use the same channel and must share airtime.
- DFS
- Dynamic frequency selection: a 5 GHz rule requiring an AP to move off a channel when it detects radar.
- SNR
- Signal-to-noise ratio: how far the received signal rises above the background noise, a key measure of link quality.
- ipconfig /all
- Windows command that shows full adapter details, including MAC, DHCP server, lease and DNS servers.
- ip addr / ip route
- Linux commands that show interface addresses and the routing table, including the default gateway.
- ifconfig
- Legacy interface command still used on macOS and older Linux to display addresses and interface state.
- nslookup
- A command on all three platforms that queries DNS to test whether a name resolves.
- RSSI
- Received signal strength indicator, a measure of how strong the wireless signal is at the client.
- /etc/resolv.conf
- The Linux file that lists the DNS servers the system resolver uses.
- DORA
- The DHCP exchange: Discover, Offer, Request, Acknowledgment.
- ip dhcp excluded-address
- Global IOS command that prevents the DHCP server from leasing a range of addresses.
- giaddr
- The gateway IP address field a relay agent fills in so the server knows which subnet the client is on.
- DHCP pool
- A named IOS configuration block that defines the subnet, gateway, DNS servers and lease for clients.
- show ip dhcp binding
- Command listing the addresses the IOS DHCP server has leased and to which clients.
Domain 2: Switching & network access (25%)
Exam tips
- Learning uses the source MAC; forwarding uses the destination MAC. If a question asks what the switch does when it has never seen the destination, the answer is flood out all ports in the same VLAN except the one it came in on.
- show vlan brief never lists trunk ports. If a question shows a port missing from that output, suspect it is a trunk, not that it is in no VLAN.
- LACP passive plus passive never forms a channel, because neither side starts negotiation. At least one side must be active. Static on must be matched with static on.
- Two switches with default dynamic auto ports connected together will not trunk. If an exam topology shows auto on both ends, the link is an access link.
- CDP defaults are 60 seconds and 180 seconds holdtime; LLDP defaults are 30 and 120, and LLDP is off by default on Cisco IOS. Expect a question that tests whether you know you must enable LLDP first.
- on is not a negotiation protocol, so it does not work with active, passive, desirable or auto. And LACP passive-passive or PAgP auto-auto never forms a bundle.
- Lower is better at every step: lowest bridge ID for root, lowest cost for root and designated ports, then lowest sender bridge ID, then lowest sender port ID.
- If an SVI shows down/down, check that the VLAN exists and has at least one active port. If routing between SVIs fails with the SVIs up, check for a missing ip routing command.
- Remember which switch-port type each AP needs: an autonomous AP serving several VLANs uses a trunk; a lightweight AP in local mode uses an access port because traffic is tunnelled to the WLC; the WLC itself connects with a trunk.
- Map each symptom to one command: VLAN membership to show vlan brief, trunk issues to show interfaces trunk, bundles to show etherchannel summary, root and port roles to show spanning-tree. Questions reward picking the right one.
Key terms
- MAC address table (CAM table)
- The switch table mapping learned MAC addresses to ports and VLANs.
- Aging time
- How long an unrefreshed MAC entry stays in the table; 300 seconds by default on Cisco switches.
- Unknown unicast flooding
- Sending a frame out all ports in the VLAN except the ingress port because its destination MAC is not yet in the table.
- Filtering
- Dropping a frame whose destination MAC is known on the same port it arrived on.
- Broadcast domain
- The set of devices that receive each other's broadcasts; one per VLAN, bounded by routers.
- Collision domain
- A segment where simultaneous transmissions can collide; each switch port is its own collision domain.
- Store-and-forward
- Switching method that receives and error-checks the entire frame before forwarding it.
- VLAN
- A logical Layer 2 broadcast domain created on switches, usually mapped to one IP subnet.
- Access port
- A switch port that carries untagged traffic for a single data VLAN, optionally plus a voice VLAN.
- Voice VLAN
- A separate VLAN for IP phone traffic on an access port, tagged by the phone while PC traffic stays untagged.
- Default VLAN
- VLAN 1, to which all ports belong by default; it cannot be deleted or renamed.
- Normal-range VLANs
- VLAN IDs 1 to 1005, with 1002 to 1005 reserved for legacy technologies.
- vlan.dat
- The flash file where many Cisco switches store normal-range VLAN definitions.
- Power over Ethernet (PoE)
- Delivery of DC power over Ethernet twisted-pair cabling from a switch to devices such as phones and APs.
- PSE / PD
- Power sourcing equipment (the switch) and powered device (the phone, AP or camera).
- Power budget
- The total PoE power a switch can supply across all ports.
- Port channel (EtherChannel)
- A logical link made of several bundled physical links that load-share and provide redundancy.
- LACP
- The IEEE standard protocol that negotiates EtherChannel bundles, with active and passive modes.
- PAgP
- Port Aggregation Protocol, Cisco's proprietary bundle negotiation protocol with desirable and auto modes.
- PortFast
- A spanning tree feature that lets an edge port move straight to forwarding.
- 802.1Q tag
- A 4-byte field inserted into Ethernet frames carrying a 12-bit VLAN ID and 3-bit priority.
- Native VLAN
- The VLAN whose frames cross an 802.1Q trunk untagged; VLAN 1 by default.
- Allowed VLAN list
- The set of VLANs permitted on a trunk, edited with the add, remove and except keywords.
- DTP
- Dynamic Trunking Protocol, Cisco's protocol for negotiating trunk formation.
- Dynamic auto / dynamic desirable
- Passive and active DTP negotiation modes; auto-auto does not form a trunk.
- switchport nonegotiate
- Interface command that stops a port from sending DTP frames.
- VLAN hopping
- An attack that sends traffic into an unauthorized VLAN, for example by abusing DTP or double tagging.
- CDP
- Cisco Discovery Protocol, a proprietary Layer 2 protocol that shares device details with directly connected Cisco neighbours; on by default.
- LLDP
- Link Layer Discovery Protocol (IEEE 802.1AB), the vendor-neutral equivalent of CDP; enabled on IOS with lldp run.
- Holdtime
- How long a device keeps a neighbour's advertised information without hearing a new advertisement.
- Advertisement timer
- How often a device sends discovery messages: 60 seconds for CDP and 30 seconds for LLDP by default.
- LLDP-MED
- An LLDP extension for media endpoints such as IP phones, carrying voice VLAN and power information.
- Port ID
- The column in neighbor output that shows the neighbour's own interface.
- channel-group
- Interface command that assigns a physical port to an EtherChannel and sets its negotiation mode.
- LACP active / passive
- LACP modes: active initiates negotiation, passive only responds; at least one side must be active.
- Mode on
- Static EtherChannel with no negotiation protocol; works only when both ends are set to on.
- Layer 3 EtherChannel
- A routed port-channel with an IP address, built from members set with no switchport.
- Suspended member
- A port that failed consistency checks and is excluded from the bundle, shown with an s flag.
- Load-balancing hash
- The per-flow calculation, based on MAC or IP fields, that picks which member carries each flow.
- Bridge ID
- A switch's priority (including the VLAN number) plus its MAC address; the lowest wins the root election.
- Root port
- On a non-root switch, the single port with the lowest-cost path to the root bridge.
- Designated port
- The forwarding port on each segment with the best path to the root; all root bridge ports are designated.
- Alternate port
- A discarding RSTP port that offers a backup path to the root and can take over immediately.
- BPDU guard
- A feature that err-disables a PortFast port if it receives a BPDU.
- Root path cost
- The sum of port costs along the path to the root bridge, based on link speed.
- Router-on-a-stick
- Inter-VLAN routing over one router interface using 802.1Q subinterfaces on a trunk link.
- Subinterface
- A logical division of a physical router interface, such as g0/0.10, each with its own VLAN tag and IP address.
- encapsulation dot1Q
- Subinterface command specifying which 802.1Q VLAN tag the subinterface handles.
- SVI
- Switch virtual interface: a Layer 3 interface for a VLAN on a switch, used as that VLAN's gateway.
- Routed port
- A physical multilayer switch port configured with no switchport so it acts like a router interface.
- ip routing
- Global command that enables IPv4 routing on a multilayer switch.
- Autonomous AP
- A standalone AP configured individually that bridges traffic directly onto the wired network.
- Lightweight AP
- An AP that relies on a WLC for management and control using a split-MAC design.
- WLC
- Wireless LAN controller, which centrally manages lightweight APs, clients, RF and security.
- Split-MAC
- The division of 802.11 functions between the AP (real-time radio tasks) and the WLC (management tasks).
- CAPWAP
- Protocol between lightweight APs and a WLC, with a DTLS-encrypted control tunnel (UDP 5246) and a data tunnel (UDP 5247).
- FlexConnect
- An AP mode for branches that switches client traffic locally and keeps serving clients if the controller link fails.
- Monitor mode
- An AP mode that serves no clients and scans channels for intrusion detection, rogue detection and location.
- show interfaces trunk
- Displays trunking ports, their mode, native VLAN, allowed VLANs and forwarding VLANs.
- show etherchannel summary
- Displays each port-channel and its members with status flags such as P, s, I and D.
- show spanning-tree vlan
- Displays the root bridge and each port's role, state and cost for one VLAN.
- err-disabled
- A port state where the switch has shut a port because a protection feature detected a violation.
- MAC flapping
- A MAC address repeatedly learned on different ports, often a symptom of a Layer 2 loop.
- Native VLAN mismatch
- Different native VLANs on the two ends of a trunk, reported by CDP and causing traffic to leak between VLANs.
Domain 3: IP routing (20%)
Exam tips
- In [110/3], the first number is AD and the second is the metric. Questions often swap them in the answer choices.
- First filter by 'does this route contain the destination', then pick the longest mask. Only after that do AD and metric matter, and only for identical prefixes.
- A floating static must have a higher AD than the route it backs up. If an exam option uses a lower value, it would replace the primary route instead of backing it up.
- 2WAY/DROTHER between two non-DR routers is expected. A neighbour stuck in INIT, EXSTART or EXCHANGE is the real sign of a problem.
- Order of RID selection: manual router-id, then highest loopback, then highest physical interface. 'Highest' refers to the numeric address, not the interface number.
- Default reference bandwidth is 100 Mbps, so anything 100 Mbps or faster costs 1. The auto-cost value is in Mbps, while the interface bandwidth command is in kbps, and cost is added on outgoing interfaces only.
- Neighbours stuck in EXSTART or EXCHANGE point to an MTU mismatch. No neighbour at all points to hello-level mismatches: area, subnet and mask, timers, authentication, a passive interface or a duplicate router ID. Process IDs never need to match.
- HSRP: active/standby, Cisco only, preempt off by default. VRRP: master/backup, open standard, preempt on by default. Both default to priority 100 with higher winning, and hosts must use the virtual IP as their gateway.
- A standard router ping uses the exit interface as its source, which can hide return-route problems. When a question says users fail but the router's ping works, the answer usually involves an extended ping from the LAN interface.
- No neighbour at all means hello mismatch or OSPF not enabled; INIT means one-way communication; EXSTART or EXCHANGE means MTU. FULL neighbours with a missing route means the network is not being advertised or a lower-AD route won.
Key terms
- Protocol code
- The letter at the start of a route, such as C, L, S or O, showing how the route was learned.
- Administrative distance (AD)
- A value rating the trustworthiness of a route source; lower wins when the same prefix is learned from different sources.
- Metric
- A routing protocol's measure of path quality, used to compare routes from that same protocol.
- Next hop
- The address of the neighbouring router to which a packet is forwarded for a given route.
- Local route (L)
- A /32 host route for the router's own interface address.
- Gateway of last resort
- The default route used when no more specific route matches a destination.
- Longest prefix match
- Choosing, among all routes that contain the destination, the one with the most specific (longest) mask.
- Administrative distance
- Used only to choose between routes to the identical prefix from different sources; lower wins.
- Equal-cost multipath (ECMP)
- Installing several equal-metric routes to one prefix and load-sharing traffic across them.
- Default route
- The 0.0.0.0/0 route, which matches every destination but is the least specific match possible.
- CEF
- Cisco Express Forwarding, the data-plane table built from the routing table that routers use to forward packets.
- Network route
- A static route to a whole subnet, such as 192.168.20.0/24.
- Host route
- A route to a single address, with a /32 mask in IPv4 or /128 in IPv6.
- Floating static route
- A backup static route configured with a higher AD than the primary, installed only when the primary is gone.
- Fully specified static route
- A static route that includes both the exit interface and the next-hop address.
- Recursive lookup
- Looking up a static route's next hop in the routing table to find the exit interface.
- Link-state advertisement (LSA)
- An OSPF data unit describing a router's links, flooded to build the link-state database.
- Adjacency
- A neighbour relationship that has reached the Full state with synchronized databases.
- Hello and dead intervals
- OSPF timers (10 and 40 seconds by default on broadcast and point-to-point links) that must match between neighbours.
- DR / BDR
- The designated router and backup designated router elected on a multi-access segment to reduce flooding.
- DROTHER
- A router on a broadcast segment that is neither DR nor BDR; it stays 2-Way with other DROTHERs.
- OSPF priority
- Interface value (default 1) used first in DR/BDR election; 0 means never eligible.
- Router ID
- A unique 32-bit OSPF identifier chosen from router-id, the highest loopback IP, or the highest active interface IP, in that order.
- Network statement
- An OSPF process command using an address and wildcard to select which interfaces run OSPF in an area.
- ip ospf area
- Interface command (ip ospf <process> area <area>) that enables OSPF directly on an interface.
- Passive interface
- An interface whose subnet OSPF advertises but on which it sends no hellos and forms no neighbours.
- Wildcard mask
- An inverse mask where 0 bits must match and 1 bits are ignored.
- clear ip ospf process
- Command that restarts OSPF so a changed router ID takes effect, briefly dropping adjacencies.
- Cost
- The OSPF metric of an interface; a route's cost is the sum of outgoing interface costs to the destination.
- Reference bandwidth
- The value divided by interface bandwidth to compute cost; 100 Mbps by default and set in Mbps with auto-cost reference-bandwidth.
- ip ospf cost
- An interface command that sets the OSPF cost directly, overriding the bandwidth-based calculation.
- bandwidth (interface)
- An interface command in kbps that changes the value routing protocols use for calculations, not the real link speed.
- Equal-cost multipath
- Installing several routes with the same lowest cost and load-balancing traffic across them.
- Hello packet
- An OSPF message sent to 224.0.0.5 that discovers neighbours and carries parameters that must match.
- Router ID (RID)
- A unique 32-bit identifier for each OSPF router, written like an IPv4 address.
- MTU mismatch
- Different maximum packet sizes on the two ends, which leaves neighbours stuck in ExStart or Exchange.
- Process ID
- The locally significant number in router ospf; it does not need to match between neighbours.
- Area ID
- The OSPF area an interface belongs to; both ends of a link must use the same area.
- FHRP
- First hop redundancy protocol: routers share a virtual gateway IP and MAC so hosts keep working if one router fails.
- HSRP
- Hot Standby Router Protocol, Cisco proprietary, with active and standby roles and preemption off by default.
- VRRP
- Virtual Router Redundancy Protocol, an open standard with master and backup roles and preemption on by default.
- Virtual IP
- The shared gateway address that hosts are configured to use.
- Priority
- The election value, default 100, where the highest wins and ties go to the highest interface IP.
- Preemption
- Allowing a higher-priority router to take over the active or master role when it comes online.
- GLBP
- Gateway Load Balancing Protocol, a Cisco FHRP that shares load by answering ARP with different virtual MACs.
- ICMP
- Internet Control Message Protocol, used for echo request and reply, unreachable and time exceeded messages.
- Extended ping
- A ping with chosen options such as source interface, repeat count, size and the don't-fragment bit.
- TTL
- Time to live, a counter decremented by each router; at zero the packet is dropped and time exceeded is returned.
- Traceroute
- A tool that sends probes with increasing TTL to reveal each router hop to a destination.
- U (unreachable)
- A ping result showing a router returned an ICMP destination unreachable message.
- Return route
- The route the destination's network needs back to the source; its absence causes timeouts.
- show ip ospf neighbor
- Lists each neighbour's router ID, priority, state, dead timer, address and interface.
- FULL
- The neighbour state where link-state databases are synchronized and the adjacency is complete.
- 2WAY
- A state where bidirectional communication exists; normal between two DROTHER routers on a broadcast segment.
- INIT
- A state where a router hears a neighbour's hello but is not listed in it, indicating one-way communication.
- LSDB
- Link-state database, the collection of LSAs from which each router runs SPF to compute routes.
- show ip protocols
- Shows the OSPF router ID, network statements, passive interfaces, reference bandwidth and routing sources.
Domain 4: Network services & security (20%)
Exam tips
- TACACS+: TCP 49, full-payload encryption, separate AAA functions, device administration. RADIUS: UDP 1812/1813, password-only encryption, combined authentication and authorization, network access. The local fallback applies only when servers do not respond.
- SSH needs a hostname, a domain name and RSA keys before it works. VTY lines are filtered with access-class, interfaces with ip access-group, and enable secret beats enable password.
- Standard near the destination, extended near the source. Always ask whether the ACL ends with a permit, because the implicit deny catches questions where everything else should be allowed.
- Protect drops silently, restrict drops and logs, shutdown err-disables and is the default. DAI depends on the DHCP snooping binding table, and uplinks to real DHCP servers must be trusted.
- Inside local is the private address you configured on the host; inside global is its public face. Remember that inside or outside is where the host is, and local or global is where you are looking from.
- If IP works but names fail, the answer is DNS. If the client has a 169.254 address, the answer is DHCP, and on a remote subnet the first suspect is a missing ip helper-address on the client-facing interface.
- Lower stratum is more accurate, and stratum 16 means not synchronized. An exam question about failed certificate validation or out-of-order logs is usually pointing at NTP.
- Personal means a shared key (PSK for WPA2, SAE for WPA3). Enterprise means 802.1X with a RADIUS server. In 802.1X, the AP or WLC is the authenticator, not the authentication server.
- If the scenario mentions client software, individual users or teleworkers, choose remote access. If it mentions connecting offices with devices at both ends and no user involvement, choose site-to-site IPsec. ESP encrypts; AH does not.
- The weakness is the vulnerability, the potential attacker or event is the threat, and the tool or technique is the exploit. Exam distractors swap them, so match the wording carefully.
Key terms
- AAA
- Authentication, authorization and accounting: who you are, what you may do, and what you did.
- TACACS+
- Cisco-developed AAA protocol on TCP 49 that encrypts the whole payload and separates the three AAA functions.
- RADIUS
- Open-standard AAA protocol on UDP 1812 and 1813 that encrypts only the password and combines authentication and authorization.
- Method list
- An ordered list of authentication sources, such as group tacacs+ then local.
- aaa new-model
- The command that enables the AAA framework on a Cisco IOS device.
- Local fallback
- Using the device's own username database when AAA servers cannot be reached.
- Accounting
- Recording sessions and commands, with usernames and times, for audit.
- SSH
- Secure Shell, an encrypted remote login protocol on TCP port 22 that replaces Telnet.
- RSA key pair
- The public and private keys the device generates to enable its SSH server.
- enable secret
- The privileged EXEC password stored as a strong hash; it overrides enable password.
- Type 7 password
- The weak, reversible obfuscation applied by service password-encryption.
- access-class
- Applies a standard ACL to VTY lines to control which source addresses may connect.
- transport input ssh
- A line command that permits only SSH sessions on the VTY lines.
- MOTD banner
- A message-of-the-day notice shown before login, used for legal warnings.
- ACE
- Access control entry, one permit or deny line in an ACL.
- Standard ACL
- An ACL that matches only the source IP address; numbered 1 to 99 or 1300 to 1999.
- Extended ACL
- An ACL that matches protocol, source, destination and ports; numbered 100 to 199 or 2000 to 2699.
- Wildcard mask
- A mask where 0 bits must match and 1 bits are ignored, such as 0.0.0.255 for a /24.
- First match
- Processing stops at the first entry that matches the packet, so order matters.
- Implicit deny
- The invisible final entry that drops any packet not matched by an earlier entry.
- ip access-group
- The interface command that applies an ACL inbound or outbound.
- Port security
- A switch feature that limits which and how many MAC addresses may use an access port.
- Sticky MAC
- Dynamically learned MAC addresses written into the running configuration by port security.
- Violation modes
- Shutdown (err-disable, default), restrict (drop and log) and protect (drop silently).
- DHCP snooping
- Filters DHCP server messages on untrusted ports and builds a binding table of clients.
- Trusted port
- A port, usually an uplink, where DHCP server messages or ARP are accepted without inspection.
- Dynamic ARP inspection
- Validates ARP messages on untrusted ports against the DHCP snooping binding table.
- Err-disabled
- A port state where the switch has shut the port because of an error such as a security violation.
- NAT
- Network Address Translation, rewriting IP addresses as packets cross a router.
- PAT (overload)
- Port Address Translation, letting many hosts share one public address by tracking port numbers.
- Inside local
- The address actually configured on an inside host, usually private.
- Inside global
- The public address that represents an inside host to the outside world.
- Outside global
- The real address of a remote host on the outside network.
- Outside local
- How a remote host's address appears from inside; normally the same as outside global.
- Static NAT
- A permanent one-to-one mapping, used for servers that must accept inbound connections.
- DORA
- Discover, Offer, Request, Acknowledgment: the four-message DHCP exchange.
- ip helper-address
- Configures a router interface as a DHCP relay, forwarding client broadcasts to a server on another subnet.
- Lease
- The time a DHCP client may use its assigned address before renewing.
- APIPA
- Automatic Private IP Addressing, a 169.254.x.x self-assigned address that signals DHCP failure.
- A and AAAA records
- DNS records mapping a name to an IPv4 or IPv6 address respectively.
- PTR record
- A DNS record mapping an address back to a name for reverse lookups.
- nslookup
- A command-line tool that queries DNS servers directly to test name resolution.
- NTP
- Network Time Protocol, which synchronizes device clocks over UDP port 123.
- Stratum
- The distance from a reference clock; lower is more accurate and 16 means unsynchronized.
- ntp server
- The IOS command that makes a device a client of the named NTP server.
- ntp master
- Makes a router an authoritative time source from its own clock, stratum 8 by default.
- NTP authentication
- Keys that ensure devices accept time only from trusted servers.
- Clock skew
- The difference between two devices' clocks, which can break certificate and Kerberos validation.
- WPA2
- Wi-Fi security generation using AES-CCMP, in Personal (PSK) or Enterprise (802.1X) mode.
- WPA3
- The newer generation adding SAE, mandatory Protected Management Frames and a 192-bit Enterprise suite.
- PSK
- Pre-shared key, the single passphrase-derived secret used by WPA2-Personal.
- SAE
- Simultaneous Authentication of Equals, the WPA3-Personal key exchange that resists offline guessing.
- 802.1X
- Port-based network access control that authenticates each user through an authenticator and server.
- Supplicant
- The client software that requests access in 802.1X.
- Authenticator
- The AP or WLC that relays EAP messages and enforces the server's decision.
- VPN
- Virtual private network, a secure tunnel across an untrusted network.
- Site-to-site VPN
- A permanent tunnel between gateways that connects whole networks, invisible to end users.
- Remote-access VPN
- An on-demand tunnel from one user's device, using client software or a browser, to a headend.
- IPsec
- A framework of protocols, including IKE, ESP and AH, that secures IP traffic.
- ESP
- Encapsulating Security Payload, IP protocol 50, providing encryption, integrity and authentication.
- IKE
- Internet Key Exchange, which authenticates peers and negotiates keys and security settings.
- Split tunnel
- Sending only corporate-bound traffic through the VPN while internet traffic goes directly.
- Vulnerability
- A weakness in a system that could be taken advantage of.
- Threat
- Anything, such as an attacker, malware or natural event, that could exploit a vulnerability to cause harm.
- Exploit
- The specific tool or technique used to take advantage of a vulnerability.
- Mitigation
- A measure that reduces risk by removing a weakness, blocking a threat or limiting damage.
- Defense in depth
- Layering technical, physical and administrative controls so one failure does not expose everything.
- Phishing
- Fraudulent messages that trick recipients into revealing credentials or running malware.
- MFA
- Multifactor authentication, requiring two or more factors from know, have and are.
Domain 5: AI & network operations/management (10%)
Exam tips
- Words like baseline, anomaly, forecast, trend and classification point to predictive AI and machine learning. Words like draft, summarize, generate and natural-language prompt point to generative AI.
- If a scenario describes an AI that decides on steps and executes them through tools, it is agentic AI. The best-practice answer almost always includes least privilege and human approval before production changes.
- A strong prompt names who the model should be, what exactly to do, what data to use and how to format the answer, and it never includes secrets that the data classification policy forbids sharing.
- Match keywords: version control, source of truth and pull request mean infrastructure as code; web dashboard hosted by the vendor means cloud-managed; intent and northbound API mean controller-based.
- Northbound is controller to applications (usually REST and JSON); southbound is controller to devices (NETCONF, RESTCONF, OpenFlow, SSH, SNMP). OSPF and STP are control plane; forwarding a frame is data plane; SSH is management plane.
- Traps are not acknowledged; informs are. For security levels remember the order noAuthNoPriv, authNoPriv, authPriv, and that only authPriv encrypts. Agents listen on UDP 161, managers on UDP 162.
- Ansible is agentless, push-based, uses SSH and YAML. Puppet and Chef are agent-based and pull. An exam question describing no software on managed devices points to Ansible.
- Setting a level includes all lower-numbered, more severe levels. If a question sets logging trap 3, the server receives levels 0 through 3 but not warnings (4) or notifications (5).
- Polling is pull: the collector asks at intervals. Streaming telemetry is push: the device sends by subscription. Event correlation reduces many related alerts to one root cause, and baselines are learned rather than fixed.
Key terms
- Machine learning
- Building systems that learn patterns from data rather than following hand-written rules.
- Predictive AI
- AI that analyses data to detect, classify and forecast, such as anomaly detection.
- Generative AI
- AI that creates new content such as text, code or configuration from a prompt.
- Baseline
- A learned picture of normal behaviour against which deviations are measured.
- Anomaly detection
- Flagging behaviour that deviates significantly from the learned baseline.
- Predictive analytics
- Using historical trends to forecast future events such as capacity exhaustion or failures.
- Hallucination
- Confident but incorrect output from a generative model.
- Agentic AI
- AI that pursues a goal by planning steps, calling tools, observing results and deciding what to do next.
- Tool
- A defined function an agent may call, such as a read-only show command or an API request.
- Guardrails
- Limits and checks around an agent, such as scoped permissions, validation and logging.
- Human-in-the-loop
- Requiring a person to review and approve an agent's proposed action before it runs.
- Least privilege
- Giving the agent only the tools and permissions the task requires.
- Prompt injection
- Untrusted input that contains instructions trying to steer an AI agent.
- Prompt
- The input text that tells a generative AI system what to do.
- Persona
- The role and expertise the model is asked to adopt, which shapes its vocabulary and depth.
- Instructions
- The specific task, steps and constraints the model should follow.
- Context and data
- The background facts and material, such as show output, the model should use.
- Data classification
- Labelling information by sensitivity to decide how it may be handled and shared.
- Redaction
- Removing or replacing sensitive values such as passwords and keys before sharing data.
- Output format
- The required structure of the answer, such as a table, JSON or plain commands.
- Device-by-device CLI
- Managing each device individually by typing commands over SSH or console.
- Cloud-managed networking
- Managing devices from a vendor-hosted dashboard that devices connect out to, such as Meraki.
- Controller-based networking
- A central controller that holds policy, programs devices and exposes APIs.
- Automation
- Using scripts and tools to perform repetitive network tasks consistently and quickly.
- Infrastructure as code
- Describing desired network state in version-controlled files that tools apply automatically.
- Source of truth
- The authoritative record of intended configuration, such as files in Git.
- Configuration drift
- Gradual divergence of device configurations from the intended standard.
- Data plane
- The forwarding function that moves user traffic through a device.
- Control plane
- Functions such as routing protocols and STP that decide how traffic should be forwarded.
- Management plane
- Functions such as SSH, SNMP and syslog used to configure and monitor a device.
- SDN
- Software-defined networking, centralizing control or management in software controllers.
- Northbound interface
- The API between the controller and applications, usually REST with JSON.
- Southbound interface
- The interface between the controller and devices, such as NETCONF, RESTCONF, OpenFlow or SSH.
- Underlay and overlay
- The physical routed network, and the virtual tunnelled network built on top of it.
- SNMP manager
- The network management station software that polls agents and receives alerts.
- SNMP agent
- Software on a managed device that answers requests and sends traps or informs.
- MIB
- Management information base, the tree of variables an agent exposes, each identified by an OID.
- Trap
- An unsolicited, unacknowledged alert sent from agent to manager on UDP 162.
- Inform
- An alert like a trap that the manager acknowledges, so the agent can resend it.
- Community string
- A clear-text shared password used by SNMPv1 and v2c for RO or RW access.
- authPriv
- The SNMPv3 security level that both authenticates and encrypts messages.
- Agentless
- Managing devices without installing software on them, using SSH or APIs from a control node.
- Control node
- The machine where Ansible is installed and from which it pushes changes.
- Inventory
- The file listing managed hosts, their groups and connection variables.
- Playbook
- A YAML file of plays and tasks that describes the automation to perform.
- Module
- A unit of code called by a task to do one job, such as ios_config.
- Idempotency
- Running the same automation repeatedly yields the same end state and changes only what differs.
- Push vs pull
- Ansible pushes changes from the control node; agent-based tools pull configuration from a server.
- Syslog
- The standard protocol and format for sending event messages, traditionally over UDP 514.
- Severity level
- A number from 0 (emergency) to 7 (debugging); lower is more severe.
- Mnemonic
- The short code in a Cisco message, such as UPDOWN, identifying the message type.
- logging trap
- Sets the lowest-severity level (highest number) sent to syslog servers.
- logging buffered
- Stores messages in device RAM for viewing with show logging.
- terminal monitor
- Enables log messages to appear in the current SSH or Telnet session.
- Syslog facility (local0 to local7)
- A server-side label used to sort messages; Cisco uses local7 by default.
- Polling
- A collector periodically requesting values from devices, as SNMP managers do.
- Streaming telemetry
- Devices pushing data to a collector by subscription, periodically or on change.
- YANG
- A data modelling language that structures device configuration and operational data.
- AIOps
- Artificial intelligence for IT operations, applying machine learning to operational data.
- Dynamic baseline
- A learned model of normal behaviour, including time-of-day and weekly patterns.
- Event correlation
- Grouping related alerts by time, topology and dependency to identify a root cause.
- On-change subscription
- Telemetry that sends an update only when a value or state changes.
Study CCNA for free
Lessons, quizzes, exam simulations and hands-on labs.
Open the CCNA study planLessons, quizzes, exam simulations and hands-on labs.