All certifications / ENCOR / Cheat sheet
ENCOR 350-401 v1.2 cheat sheet
Domain 1: Architecture (15%)
Exam tips
- If a question describes predictable latency for east-west server traffic and every leaf connecting to every spine, the answer is spine-leaf. If it describes a small site merging core and distribution, it is a two-tier collapsed core.
- SSO alone does not keep routing adjacencies up. Pair SSO with NSF (and graceful restart on neighbors) to keep forwarding during a supervisor failover.
- Match the component to the plane: Manager is management, Validator is orchestration, Controller is control (OMP), WAN Edge is data (IPsec plus BFD). OMP never runs directly between two WAN Edges.
- Exam answers favor SD-WAN for active use of multiple transports, centralized policy, SLA-based path choice and cloud breakout. Watch for distractors claiming SD-WAN guarantees internet performance; it measures and steers but cannot guarantee a provider's network.
- Memorize the triad: control plane LISP, data plane VXLAN, policy plane TrustSec (SGT). Intermediate nodes are the only fabric role that knows nothing about the overlay.
- Underlay equals physical routed reachability between fabric nodes; overlay equals the virtual tunnels carrying user traffic. Questions about avoiding stretched VLANs and spanning tree point to the SD-Access routed underlay.
- Policing drops (no delay, both directions); shaping buffers (adds delay, outbound only). CoS lives in the 802.1Q tag and disappears on untagged or routed hops; DSCP survives end to end.
- The RIB is built by the control plane; the FIB and adjacency table are derived from it by CEF for the data plane. CEF tables are built before traffic arrives, unlike fast switching's demand-built route cache.
- Exact match equals CAM (MAC addresses). Longest-prefix or masked match equals TCAM (routes, ACLs, QoS). The 'T' for ternary means the third value: don't care.
- If a question links high CPU with flapping adjacencies, think punted traffic and protect with CoPP. TTL-expired packets, IP options, glean (ARP) and ACL logging are classic punt causes.
Key terms
- Access layer
- The layer where endpoints connect; provides port density, PoE, VLAN assignment and edge security.
- Distribution layer
- Aggregates access switches, usually hosts default gateways, and applies policy and route summarization.
- Core layer
- The high-speed backbone joining distribution blocks, designed for fast forwarding and fast convergence.
- Collapsed core
- A two-tier design where one pair of switches performs both core and distribution roles.
- Spine-leaf
- A data center topology where every leaf connects to every spine, giving equal-cost, two-hop paths between servers.
- FHRP
- First hop redundancy protocol: lets several routers share a virtual gateway IP and MAC so hosts survive a gateway failure.
- HSRP
- Hot Standby Router Protocol, a Cisco FHRP with one active and one standby router per group.
- VRRP
- Virtual Router Redundancy Protocol, an open-standard FHRP with a master and backups.
- SSO
- Stateful switchover: the standby supervisor stays synchronized and takes over without resetting line cards.
- NSF
- Nonstop Forwarding: keeps forwarding packets using existing forwarding tables while routing protocols reconverge after a switchover.
- SD-WAN Manager (vManage)
- The management plane: GUI, templates, policy definition, monitoring and REST API.
- SD-WAN Validator (vBond)
- The orchestration plane: authenticates WAN Edges, points them to controllers and assists NAT traversal.
- SD-WAN Controller (vSmart)
- The control plane: runs OMP with WAN Edges, applies control policy and distributes routes and keys.
- OMP
- Overlay Management Protocol, the routing protocol between WAN Edges and Controllers carrying OMP, TLOC and service routes.
- TLOC
- Transport locator: identifies a WAN Edge transport attachment by system IP, color and encapsulation.
- Transport independence
- The ability of the SD-WAN overlay to run over any mix of MPLS, broadband, LTE or 5G links.
- Application-aware routing
- Choosing a path per application based on measured loss, latency and jitter against an SLA policy.
- Zero-touch provisioning
- Automatic onboarding where a new device contacts the orchestrator and downloads its configuration without manual setup.
- Direct internet access
- Sending internet or SaaS traffic straight out of the branch instead of backhauling it through the data center.
- EID
- Endpoint identifier: the IP or MAC address that identifies an endpoint in LISP.
- RLOC
- Routing locator: the underlay address (usually a loopback) of the fabric node where an endpoint is attached.
- Edge node
- The fabric access switch that connects endpoints, registers them with the control plane node and acts as their anycast gateway.
- Border node
- The fabric node that connects the SD-Access fabric to external networks such as the data center, WAN or internet.
- SGT
- Scalable Group Tag: a 16-bit group identifier assigned to a user or device and used for group-based policy.
- Underlay
- The physical routed network that provides IP reachability between fabric node loopbacks.
- Overlay
- The virtual network (LISP plus VXLAN) built on the underlay that carries endpoint traffic and segmentation.
- Anycast gateway
- The same default gateway IP and MAC configured on every edge node for a subnet, so hosts keep their gateway anywhere.
- Group-based policy
- Access rules written between scalable groups (SGTs) instead of IP addresses.
- Virtual network
- An SD-Access macro-segment that maps to a VRF in the fabric.
- DSCP
- Differentiated Services Code Point: a 6-bit Layer 3 marking in the IP header, values 0 to 63.
- CoS
- Class of Service: a 3-bit Layer 2 priority in the 802.1Q tag, values 0 to 7, present only on tagged links.
- Policing
- Enforcing a rate by dropping or re-marking excess traffic without buffering.
- Shaping
- Enforcing a rate by buffering excess traffic and sending it later, outbound only.
- LLQ
- Low Latency Queuing: CBWFQ plus a strict-priority queue, typically for voice.
- WRED
- Weighted Random Early Detection: drops packets early and selectively by marking to avoid tail drop and TCP global synchronization.
- RIB
- Routing Information Base: the routing table built by routing protocols, static and connected routes.
- FIB
- Forwarding Information Base: CEF's lookup-optimized copy of the RIB's best routes with next hops resolved.
- Adjacency table
- CEF's table of directly connected next hops with prebuilt Layer 2 rewrite headers, built from ARP or ND.
- Process switching
- Forwarding each packet by a CPU process with a full routing table lookup; slowest method.
- CEF
- Cisco Express Forwarding: prebuilds the FIB and adjacency table so forwarding needs no per-destination CPU work.
- CAM
- Content addressable memory that returns a result for an exact match in a single lookup; used for the MAC address table.
- TCAM
- Ternary CAM whose bits can be 0, 1 or don't care; used for prefix and ACL lookups.
- MAC address table
- The table mapping MAC address and VLAN to a switch port, stored in CAM.
- SDM template
- A Catalyst setting that divides TCAM and other hardware resources among features.
- Punt
- Sending a packet from the hardware data plane up to the route processor CPU for software handling.
- Control plane
- The functions that build forwarding state, such as routing protocols and spanning tree, running on the CPU.
- Data plane
- The forwarding path that moves transit packets, ideally in hardware.
- CoPP
- Control Plane Policing: a QoS policy that rate-limits traffic destined to or punted to the CPU.
Domain 2: Virtualization (10%)
Exam tips
- Type 1 runs on bare metal (production, data center); type 2 runs on a host OS (labs, desktops). The physical port facing a hypervisor is usually a trunk, not an access port.
- The core distinction is the kernel: every VM has its own guest OS kernel; containers share the host kernel. That is why containers are lighter and faster but less isolated and must match the host OS family.
- When a lab says a host is unreachable but the interface is up, check whether you forgot the vrf keyword in ping, traceroute or show ip route. Also remember that applying vrf forwarding to an interface deletes its IP address.
- A GRE tunnel is up/up whenever the destination is routable, even if the far end is dead, unless keepalives are enabled. GRE adds 24 bytes; set ip mtu and ip tcp adjust-mss (MTU minus 40).
- Crypto maps are policy-based (ACL chooses traffic, applied to the physical interface); tunnel protection is route-based (routing chooses traffic, applied to a tunnel interface) and supports routing protocols and multicast. AH breaks with NAT; ESP with NAT-T uses UDP 4500.
- If the scenario needs multicast or a routing protocol across an encrypted tunnel, pick GRE over IPsec or a VTI, not a crypto map. A VTI has less overhead but carries a single IP family; GRE can carry multiple protocols and supports multipoint designs.
- Registration goes to the map server (ETR sends Map-Register); lookups go to the map resolver (ITR sends Map-Request). Identity is the EID; location is the RLOC.
- Know the numbers: VNI is 24 bits (about 16 million segments) versus 12-bit VLAN IDs, VXLAN uses UDP destination port 4789, and it adds about 50 bytes, so raise the underlay MTU.
Key terms
- Hypervisor
- Software that creates and runs virtual machines by sharing physical hardware among them.
- Type 1 hypervisor
- A bare-metal hypervisor running directly on hardware, such as ESXi, Hyper-V or KVM.
- Type 2 hypervisor
- A hosted hypervisor running as an application on a host operating system, such as VirtualBox or VMware Workstation.
- Virtual switch
- A software Layer 2 switch inside the hypervisor connecting virtual NICs to each other and to physical uplinks.
- Container
- An isolated process environment that shares the host operating system kernel and packages an application with its dependencies.
- Container image
- A portable, layered package of an application and its libraries used to start containers.
- Namespaces and cgroups
- Linux kernel features that isolate a container's view of the system and limit its resource use.
- Kubernetes
- A container orchestration platform that schedules, scales and heals containers across a cluster of hosts.
- VRF
- Virtual routing and forwarding: an isolated routing and forwarding table with its own interfaces on a router.
- VRF-Lite
- Using VRFs hop by hop without MPLS, typically with one subinterface per VRF between devices.
- Route leaking
- Deliberately importing routes from one VRF into another so selected traffic can cross between them.
- Route distinguisher
- A value prepended to prefixes in MPLS VPNs so overlapping prefixes from different VRFs stay unique in MP-BGP.
- GRE
- Generic Routing Encapsulation: a tunneling protocol (IP protocol 47) that carries one packet inside another without encryption.
- Tunnel source and destination
- The underlay addresses the GRE packets use between the two tunnel endpoints.
- Recursive routing
- A failure where the route to the tunnel destination points through the tunnel itself, causing the tunnel to go down.
- MSS
- Maximum segment size: the largest TCP payload a host will accept, normally MTU minus 40 bytes.
- GRE keepalive
- Periodic probes that bring the tunnel line protocol down when the far end stops responding.
- IKE phase 1
- Negotiates and authenticates the IKE (ISAKMP) SA, a secure channel for further negotiation.
- IKE phase 2
- Quick mode, which negotiates the IPsec SAs that protect user data.
- ESP
- Encapsulating Security Payload (IP protocol 50): provides encryption, integrity and anti-replay.
- Tunnel mode
- Encrypts the whole original packet and adds a new outer IP header; typical for site-to-site VPNs.
- Transport mode
- Protects only the payload and keeps the original IP header; used when endpoints are the traffic endpoints, such as GRE over IPsec.
- Tunnel protection
- Applying an IPsec profile to a tunnel interface to encrypt all traffic routed through it.
- GRE over IPsec
- A GRE tunnel whose packets are encrypted by IPsec, allowing routing protocols and multicast across an encrypted VPN.
- Static VTI
- An IPsec virtual tunnel interface (tunnel mode ipsec ipv4) that encrypts all traffic routed into it without a GRE header.
- IPsec profile
- A named set of IPsec parameters, such as the transform set, applied to a tunnel interface with tunnel protection.
- DMVPN
- Dynamic Multipoint VPN: hub-and-spoke mGRE plus NHRP and IPsec, letting spokes build direct tunnels on demand.
- EID
- Endpoint identifier: the address that identifies a host and stays with it when it moves.
- RLOC
- Routing locator: the underlay address of the LISP router through which an EID is reachable.
- Map server
- Receives Map-Register messages from ETRs and stores EID-to-RLOC mappings.
- Map resolver
- Receives Map-Request queries from ITRs and resolves them to the correct RLOC.
- ITR and ETR
- Ingress tunnel router encapsulates traffic toward a remote RLOC; egress tunnel router registers local EIDs and decapsulates arriving traffic.
- VXLAN
- An encapsulation that carries Ethernet frames inside UDP over an IP network.
- VNI
- VXLAN network identifier: a 24-bit segment ID, allowing about 16 million segments.
- VTEP
- VXLAN tunnel endpoint: the device that encapsulates and decapsulates VXLAN traffic, identified by an underlay IP address.
- UDP 4789
- The IANA-assigned destination port for VXLAN.
- BGP EVPN
- A control plane that advertises MAC and IP reachability between VTEPs, reducing flood-and-learn behavior.
Domain 3: Infrastructure (30%)
Exam tips
- Two dynamic auto ports never form a trunk. Without the add keyword, switchport trunk allowed vlan replaces the whole list. A native VLAN mismatch leaks traffic between VLANs and triggers CDP warnings.
- Passive-passive (LACP) and auto-auto (PAgP) never form a channel. On does not negotiate and only pairs with on. A single flow never uses more than one member link's bandwidth.
- BPDU guard shuts the port (err-disabled) on any BPDU; root guard blocks only on superior BPDUs and recovers by itself; loop guard acts when BPDUs stop arriving. MST regions must match name, revision and VLAN mapping exactly.
- OSPF: link-state, SPF, cost, summarize only on ABR or ASBR, equal-cost only. EIGRP: DUAL, bandwidth plus delay, summarize anywhere, unequal-cost with variance. Lower administrative distance wins before metric is compared.
- Feasible successor test: RD of the backup less than FD of the successor, strictly less. Variance only ever uses feasible successors. Stub routing is the main fix for stuck-in-active problems at hub sites.
- Stub blocks type 5; totally stubby blocks 3 and 5; NSSA blocks type 5 but allows type 7 from a local ASBR. Neighbors stuck in ExStart or Exchange usually mean an MTU mismatch; routers stuck in 2-Way on Ethernet are normal between DROTHERs.
- Idle or Active means the session is not up; Active does not mean healthy. Remember the order Weight, Local preference, Originated, AS_PATH, Origin, MED, eBGP over iBGP. Weight and local preference are high-wins; AS_PATH length and MED are low-wins.
- PBR is applied inbound on the ingress interface and is checked before the routing table. A packet that matches a deny statement or no statement is routed normally, not dropped.
- HSRP preemption is off by default; VRRP preemption is on. In NAT, inside local is the real private address and inside global is what the internet sees. NTP is millisecond class; PTP uses hardware timestamps for sub-microsecond accuracy.
- IGMP is host to router; PIM is router to router. (*,G) means shared tree through the RP; (S,G) means source tree. SSM needs IGMPv3 and no RP.
Key terms
- 802.1Q
- The IEEE trunking standard that inserts a 4-byte tag with a 12-bit VLAN ID into Ethernet frames.
- DTP
- Dynamic Trunking Protocol: Cisco protocol that negotiates whether a link becomes a trunk.
- Native VLAN
- The VLAN whose frames are sent untagged on an 802.1Q trunk; must match on both ends.
- Allowed VLAN list
- The set of VLANs permitted to cross a trunk, set with switchport trunk allowed vlan.
- Switchport nonegotiate
- Disables DTP frames on a port.
- LACP
- Link Aggregation Control Protocol, the IEEE standard for negotiating EtherChannel; modes active and passive.
- PAgP
- Port Aggregation Protocol, the Cisco proprietary EtherChannel negotiation protocol; modes desirable and auto.
- Mode on
- Static EtherChannel with no negotiation protocol; must be on at both ends.
- Load-balancing hash
- The per-frame calculation on address or port fields that chooses which member link carries a flow.
- Root port
- The port on a non-root switch with the best path to the root bridge.
- Designated port
- The forwarding port on each segment toward that segment, chosen by best path to root.
- Alternate port
- An RSTP discarding port with an alternative path to the root, ready to replace the root port.
- BPDU guard
- Err-disables a PortFast port that receives a BPDU.
- Root guard
- Blocks a designated port that receives a superior BPDU, preventing an unwanted switch from becoming root.
- Loop guard
- Blocks a non-designated port that stops receiving BPDUs, preventing loops from unidirectional links.
- Link-state
- A routing approach where routers share topology and each computes paths with SPF from a full map.
- Advanced distance vector
- EIGRP's approach, learning distances from neighbors and using DUAL to keep paths loop-free.
- Administrative distance
- Trust value for choosing between routing sources: EIGRP internal 90, OSPF 110, EIGRP external 170.
- Reference bandwidth
- OSPF's value divided by interface bandwidth to get cost; defaults to 100 Mbps.
- Unequal-cost load balancing
- Sharing traffic across paths with different metrics, supported only by EIGRP through variance.
- Feasible distance
- The router's total metric to a destination through the best path.
- Reported distance
- The metric to the destination as advertised by a neighbor.
- Feasibility condition
- A neighbor's reported distance must be less than the current feasible distance for it to be a feasible successor.
- Variance
- A multiplier that allows EIGRP to install feasible successors with higher metrics for unequal-cost load balancing.
- Stub router
- An EIGRP router that tells neighbors not to query it and advertises only selected route types.
- ABR
- Area border router: connects area 0 to other areas and generates type 3 summary LSAs.
- ASBR
- Autonomous system boundary router: redistributes external routes into OSPF.
- DR and BDR
- Designated and backup designated router elected on broadcast networks to reduce adjacencies.
- Totally stubby area
- An area that blocks type 3 and type 5 LSAs and receives only a default route from the ABR.
- NSSA
- Not-so-stubby area: blocks type 5 LSAs but allows local externals as type 7 LSAs, translated to type 5 by the ABR.
- eBGP
- BGP between routers in different autonomous systems; uses TTL 1 by default.
- Established
- The BGP state in which the session is up and UPDATE messages are exchanged.
- Weight
- Cisco-specific, router-local attribute; the highest value is preferred first.
- Local preference
- AS-wide attribute used to choose the exit point; the highest value wins, default 100.
- AS_PATH
- The list of autonomous systems a route has crossed, used for loop prevention and path length.
- MED
- Multi-exit discriminator: a lower value suggests a preferred entry point into a neighboring AS.
- Policy-based routing
- Forwarding packets based on criteria other than the destination, defined by a route map.
- Route map
- An ordered list of permit or deny statements with match and set clauses.
- set ip next-hop
- A PBR action that forwards matching packets to a specific directly connected next hop.
- ip policy route-map
- Interface command that applies PBR to packets arriving on that interface.
- ip local policy
- Applies PBR to traffic generated by the router itself.
- Stratum
- NTP's distance from the reference clock; lower is more accurate, 16 means unsynchronized.
- PTP
- Precision Time Protocol (IEEE 1588): hardware-timestamped time sync with sub-microsecond accuracy.
- Inside local and inside global
- The host's real private address and the translated address the outside sees.
- PAT
- NAT overload: many inside hosts share one global address using different source ports.
- Preemption
- Allows a higher-priority FHRP router to take back the active or master role; off by default in HSRP, on in VRRP.
- IGMP
- The protocol hosts use to join and leave multicast groups with their local router.
- PIM sparse mode
- A multicast routing protocol that forwards only after explicit joins, using an RP for shared trees.
- Rendezvous point
- The router where multicast sources register and receivers join the shared (*,G) tree.
- RPF check
- Forwarding a multicast packet only if it arrived on the interface used to reach its source.
- SSM
- Source-Specific Multicast: receivers request (S,G) with IGMPv3, trees go directly to the source, no RP; range 232.0.0.0/8.
Domain 4: Network Assurance (10%)
Exam tips
- Always prefer show commands, send debug output to the buffer, scope debugs with conditions or ACLs, and know undebug all. In ping output, '.' is a timeout and 'U' is an unreachable message returned by a router.
- Polling is NMS to agent on UDP 161; traps and informs are agent to NMS on UDP 162. Only SNMPv3 authPriv both authenticates and encrypts. Informs are acknowledged; traps are not.
- Setting a level includes every lower number. logging trap 4 (warnings) sends 0 to 4. Level 7 is debugging and level 0 is emergencies. Syslog uses UDP 514 by default.
- Order of building: record, then exporter, then monitor that references both, then apply the monitor to an interface. Match fields are keys that define a flow; collect fields are just gathered data.
- Same switch: SPAN. Different switch across Layer 2: RSPAN with a remote-span VLAN allowed on trunks. Across a routed network: ERSPAN with GRE.
- IP SLA operations must be scheduled with ip sla schedule or they never run. Tracking an interface misses failures beyond the link; tracking an IP SLA detects them.
- Know the lifecycle names: Design, Policy, Provision, Assurance. Assurance questions revolve around health scores, issues with suggested actions, 360 views with time travel, path trace and AI baselines rather than static thresholds.
- NETCONF: SSH, port 830, XML, RPC operations, datastores and locking. RESTCONF: HTTPS, JSON or XML, HTTP verbs, no candidate datastore or locking. Both are driven by YANG models.
Key terms
- Extended ping
- A ping that lets you choose the source, size, count and don't-fragment bit.
- Traceroute
- A tool that increments TTL on probes to list each Layer 3 hop to a destination.
- Conditional debug
- Debugging limited to a specific interface, address or other condition.
- undebug all
- Command that turns off all debugging immediately.
- MIB and OID
- The structured database of manageable objects and the numeric identifier for each object.
- Community string
- The clear-text shared password used by SNMPv1 and v2c.
- Trap
- An unacknowledged notification sent by the agent to the NMS on UDP 162.
- Inform
- An acknowledged notification, retransmitted if the NMS does not confirm it.
- authPriv
- The SNMPv3 security level with both authentication and encryption.
- Syslog severity
- A 0 to 7 scale where 0 is emergencies and 7 is debugging; lower is more severe.
- logging trap
- Sets the maximum severity level sent to syslog servers.
- logging buffered
- Stores log messages in device RAM for viewing with show logging.
- terminal monitor
- Displays log and debug messages in the current SSH or Telnet session.
- Facility
- The component or category of a message, such as LINEPROTO or OSPF, or the syslog facility like local7.
- Flow
- A set of packets that share the same values in the defined key fields.
- Flow record
- Defines key fields (match) and non-key fields (collect) for Flexible NetFlow.
- Flow exporter
- Defines the collector destination, source, transport port and export format.
- Flow monitor
- Links a record and exporters with cache settings and is applied to an interface.
- IPFIX
- The IETF standard flow export protocol based on NetFlow version 9.
- SPAN
- Switched Port Analyzer: local mirroring of source ports or VLANs to a destination port on the same switch.
- RSPAN
- Remote SPAN: mirrored traffic carried in a dedicated remote-span VLAN across Layer 2 trunks.
- ERSPAN
- Encapsulated Remote SPAN: mirrored traffic carried in GRE across a routed Layer 3 network.
- Destination port
- The port that receives mirrored copies for the analyzer; it no longer forwards normal traffic.
- IP SLA operation
- A configured synthetic probe, such as icmp-echo or udp-jitter, that measures a path.
- IP SLA responder
- A Cisco device feature that answers and timestamps probes such as udp-jitter for accurate measurements.
- Track object
- An object whose up or down state follows an IP SLA, interface or route and is used by other features.
- Floating static route
- A backup static route with a higher administrative distance that is used only when the primary disappears.
- Assurance
- Catalyst Center's monitoring and analytics function that measures network, client and application health.
- Health score
- A rating that summarizes the condition of a device, client, site or application from many metrics.
- Path trace
- A tool that computes the path between two endpoints and highlights blocking ACLs or problem interfaces.
- Dynamic baseline
- A machine-learned model of normal behavior used to detect anomalies instead of fixed thresholds.
- NETCONF
- An XML-based network management protocol over SSH port 830 that uses RPC operations and datastores.
- RESTCONF
- An HTTPS interface using GET, POST, PUT, PATCH and DELETE on YANG-modeled data encoded in JSON or XML.
- Datastore
- A copy of configuration, such as running, startup or candidate, that NETCONF operations act on.
- Capabilities exchange
- The NETCONF hello exchange in which each side lists the features and models it supports.
- edit-config
- The NETCONF operation that changes configuration in a datastore.
Domain 5: Security (20%)
Exam tips
- SSH needs a hostname, domain name and RSA keys. Use access-class (not ip access-group) to filter VTY access. Type 7 passwords are reversible; prefer secret with type 8 or 9 hashing.
- Fallback to the next method happens only on error (no response), never on a rejected password. TACACS+ equals TCP 49, full-body encryption, per-command authorization; RADIUS equals UDP, password-only encryption, 802.1X.
- First match wins and every ACL ends with an implicit deny. Extended ACLs go near the source; standard ACLs go near the destination. Use access-class for VTY lines and ip access-group for interfaces.
- CoPP is applied with service-policy input under control-plane. ACL permit only classifies traffic into a class; the police action decides whether it is dropped. Baseline first, then tighten.
- Basic authentication is only encoded, not encrypted, so it needs HTTPS. 401 means authenticate again; 403 means you lack permission. A leaked secret must be rotated, not just deleted from the file.
- The NGFW's distinguishing features are application awareness, identity-based policy and integrated IPS and malware inspection, on top of stateful filtering. Questions about an infected laptop outside the office point to endpoint security, not the perimeter firewall.
- Classification assigns the SGT, propagation carries it (inline tag or SXP), enforcement applies the SGACL, usually at egress. MACsec is hop-by-hop Layer 2 encryption, not end-to-end.
- Know the three 802.1X roles: supplicant, authenticator, authentication server. EAPOL runs between endpoint and switch; RADIUS runs between switch and ISE. MAB is for devices with no supplicant and is weak because MACs can be spoofed.
- DHCP snooping comes first because DAI and IP source guard both use its binding table. Mark uplinks toward DHCP servers and other switches as trusted, or DHCP and ARP will break.
Key terms
- VTY lines
- Virtual terminal lines used for remote Telnet or SSH management sessions.
- login local
- Line command that authenticates users against the device's local username database.
- enable secret
- The hashed password protecting privileged EXEC mode.
- transport input ssh
- Line command that permits only SSH for incoming remote sessions.
- access-class
- Applies an ACL to VTY lines to restrict which source addresses can connect.
- AAA
- Authentication, authorization and accounting: identifying users, controlling their actions and logging activity.
- TACACS+
- Cisco-developed AAA protocol on TCP 49 that encrypts the whole body and separates the three A's; best for device administration.
- RADIUS
- Open-standard AAA protocol on UDP 1812/1813 that encrypts only the password and combines authentication and authorization; used for network access.
- Method list
- An ordered list of authentication or authorization sources, applied by name or as default.
- Fallback
- Moving to the next method in a list, which happens only when a method returns an error such as no server response.
- Standard ACL
- Matches only the source IP address; numbered 1-99 and 1300-1999.
- Extended ACL
- Matches protocol, source, destination and ports; numbered 100-199 and 2000-2699.
- Wildcard mask
- A mask where 0 bits must match and 1 bits are ignored.
- Implicit deny
- The invisible final entry in every ACL that drops anything not permitted.
- First match
- ACL processing stops at the first entry that matches the packet.
- CoPP
- Control Plane Policing: an MQC policy applied to the control-plane interface that rate-limits traffic to the CPU.
- control-plane
- The special configuration mode representing the route processor, where the CoPP service policy is attached.
- class-default
- The catch-all class for traffic that matches no defined class, usually policed tightly in CoPP.
- Exceed action
- What a policer does with traffic above the configured rate, such as drop or transmit.
- HTTPS
- HTTP protected by TLS, encrypting traffic and authenticating the server with a certificate.
- Token authentication
- Exchanging credentials once for a time-limited token that is sent with later requests.
- Bearer token
- A token presented in the Authorization header; whoever holds it can use it.
- Least privilege
- Granting an account only the permissions its task requires.
- Secrets manager
- A system that stores credentials securely with access control, auditing and rotation.
- Defense in depth
- Layering multiple security controls so the failure of one does not expose the whole network.
- NGFW
- Next-generation firewall: a stateful firewall with application awareness, user identity, IPS, URL filtering and malware protection.
- IPS
- Intrusion prevention system: inspects traffic inline and blocks known attack patterns and anomalies.
- EDR
- Endpoint detection and response: records endpoint activity to detect, investigate and contain threats.
- Zero trust
- A model that never assumes trust based on network location and continuously verifies users and devices.
- SGT
- Scalable (Security) Group Tag: a 16-bit identifier that represents a user or device group.
- SGACL
- Scalable Group ACL: a permit or deny policy between a source SGT and a destination group.
- SXP
- SGT Exchange Protocol: shares IP-to-SGT mappings over TCP where inline tagging is not supported.
- MACsec
- IEEE 802.1AE hop-by-hop Layer 2 encryption and integrity protection on Ethernet links.
- MKA
- MACsec Key Agreement: the protocol that negotiates and distributes MACsec keys.
- Supplicant
- The 802.1X client software on the endpoint.
- Authenticator
- The switch or wireless controller that controls the port and relays EAP to the RADIUS server.
- EAPOL
- EAP over LAN: carries EAP messages between the supplicant and the switch.
- MAB
- MAC Authentication Bypass: authenticates devices without supplicants using their MAC address.
- Change of authorization
- A RADIUS message from ISE that tells the switch to re-authenticate or apply new policy to an active session.
- DHCP snooping
- Blocks DHCP server messages on untrusted ports and builds a binding table of legitimate leases.
- Binding table
- The DHCP snooping record of MAC, IP, VLAN and port for each client lease.
- Dynamic ARP inspection
- Drops ARP packets on untrusted ports whose IP-to-MAC mapping does not match the binding table.
- IP source guard
- Filters traffic on access ports so only sources matching the port's binding are allowed.
- Trusted port
- A port, usually an uplink or server port, exempt from DHCP snooping and DAI checks.
Domain 6: Automation and AI (15%)
Exam tips
- Know how to index nested data: resp.json()['key'][0]['name'] means dictionary key, then first list element, then another key. List indexes start at 0. response.json() parses the body; response.status_code gives the HTTP code.
- Valid JSON uses double quotes only, lowercase true, false and null, and no trailing commas or comments. loads and dumps work with strings; load and dump work with files.
- Remember the layers: YANG is the model, XML or JSON is the encoding, NETCONF or RESTCONF is the transport. A list needs a key; a container does not.
- 200 OK, 201 Created, 204 No Content; 400 malformed request, 401 authentication problem, 403 permission problem, 404 wrong URL or resource, 500 server fault. PUT replaces, PATCH merges.
- Token first: POST to /dna/system/api/v1/auth/token with Basic auth, then send X-Auth-Token on every call. Long-running actions return a taskId to poll, not the final result.
- SD-WAN Manager uses a session cookie (JSESSIONID from j_security_check) plus an X-XSRF-TOKEN for changes; Catalyst Center uses X-Auth-Token. Don't mix them up.
- Every applet needs exactly one event and at least one action. Action labels run in sorted string order. Start CLI actions with 'enable', and watch for AAA command authorization blocking EEM commands.
- Ansible: agentless, push, YAML playbooks, SSH or API. Puppet: agent, pull, manifests. Chef: agent, pull, Ruby recipes and cookbooks. For network devices that cannot host agents, Ansible is the usual answer.
- Exam answers favor dynamic baselines over static thresholds, and human review, least privilege and verification over letting AI make unreviewed production changes. Treat AI output as a recommendation, not an authority.
Key terms
- Variable
- A name bound to a value; Python infers its type.
- List
- An ordered, zero-indexed collection written in square brackets.
- Dictionary
- A collection of key-value pairs written in braces, equivalent to a JSON object.
- Function
- A reusable block defined with def that takes parameters and can return a value.
- requests
- A Python library for sending HTTP requests and handling responses.
- JSON object
- Key-value pairs in curly braces with double-quoted string keys; maps to a Python dict.
- JSON array
- An ordered list of values in square brackets; maps to a Python list.
- json.loads
- Parses a JSON string into Python objects.
- json.dumps
- Serializes Python objects into a JSON string.
- null
- JSON's empty value, which becomes None in Python.
- YANG
- A data modeling language that defines the structure and types of network configuration and state data.
- Container
- A YANG node that groups other nodes and holds no value itself.
- Leaf
- A YANG node holding a single typed value.
- Native model
- A vendor-specific YANG model covering all platform features, such as Cisco-IOS-XE-native.
- CRUD
- Create, read, update, delete: the basic operations mapped to POST, GET, PUT or PATCH, and DELETE.
- Idempotent
- Repeating the request has the same effect as sending it once; true of GET, PUT and DELETE.
- 201 Created
- Success status indicating a new resource was created.
- 401 vs 403
- 401 means not authenticated or token invalid; 403 means authenticated but not permitted.
- Content-Type
- The header declaring the format of the request or response body.
- Intent API
- Catalyst Center's northbound REST API for querying and configuring the network in terms of desired outcomes.
- X-Auth-Token
- The HTTP header that carries the Catalyst Center token on each API request.
- Token endpoint
- POST /dna/system/api/v1/auth/token with Basic authentication, returning a time-limited token.
- taskId
- The identifier returned by an asynchronous operation, polled via the task API to get its status and result.
- /dataservice
- The base path of SD-WAN Manager REST API endpoints.
- j_security_check
- The login endpoint that accepts form-encoded username and password and returns a JSESSIONID cookie.
- JSESSIONID
- The session cookie that authenticates subsequent SD-WAN Manager API calls.
- X-XSRF-TOKEN
- Header carrying the CSRF token from /dataservice/client/token, required for POST, PUT and DELETE.
- EEM
- Embedded Event Manager: on-device automation that runs actions when defined events occur.
- Applet
- An EEM policy written in configuration mode with one event and a set of actions.
- Event detector
- The EEM component that triggers an applet, such as syslog, timer, track or interface.
- action cli command
- An EEM action that runs a CLI command on the device.
- Agent-based
- Management where software on each target pulls and enforces its configuration from a central server.
- Agentless
- Management where a control node connects over existing protocols such as SSH and pushes changes.
- Playbook
- An Ansible YAML file of plays and tasks applied to hosts from an inventory.
- Manifest
- A Puppet file that declares desired state in Puppet's language.
- Cookbook and recipe
- Chef's units of configuration, written in a Ruby-based language.
- Baseline
- A learned model of normal behavior for a metric in its context, such as time of day and site.
- Anomaly detection
- Identifying behavior that deviates significantly from the baseline.
- Hallucination
- A confident but incorrect or fabricated output from a generative AI model.
- Human in the loop
- Requiring a qualified person to review and approve AI recommendations before changes are made.
- Prompt injection
- Malicious instructions hidden in input data that attempt to manipulate an AI system's behavior.
Study ENCOR for free
Lessons, quizzes, exam simulations and hands-on labs.
Open the ENCOR study planLessons, quizzes, exam simulations and hands-on labs.