StudyToCert

All certifications / ENCOR / Cheat sheet

ENCOR 350-401 v1.2 cheat sheet

Every exam tip and key term from the free ENCOR lessons, by domain. Use your browser's Print to save it as a PDF.

Domain 1: Architecture (15%)

Exam tips

Key terms

Access layer
The layer where endpoints connect; provides port density, PoE, VLAN assignment and edge security.
Distribution layer
Aggregates access switches, usually hosts default gateways, and applies policy and route summarization.
Core layer
The high-speed backbone joining distribution blocks, designed for fast forwarding and fast convergence.
Collapsed core
A two-tier design where one pair of switches performs both core and distribution roles.
Spine-leaf
A data center topology where every leaf connects to every spine, giving equal-cost, two-hop paths between servers.
FHRP
First hop redundancy protocol: lets several routers share a virtual gateway IP and MAC so hosts survive a gateway failure.
HSRP
Hot Standby Router Protocol, a Cisco FHRP with one active and one standby router per group.
VRRP
Virtual Router Redundancy Protocol, an open-standard FHRP with a master and backups.
SSO
Stateful switchover: the standby supervisor stays synchronized and takes over without resetting line cards.
NSF
Nonstop Forwarding: keeps forwarding packets using existing forwarding tables while routing protocols reconverge after a switchover.
SD-WAN Manager (vManage)
The management plane: GUI, templates, policy definition, monitoring and REST API.
SD-WAN Validator (vBond)
The orchestration plane: authenticates WAN Edges, points them to controllers and assists NAT traversal.
SD-WAN Controller (vSmart)
The control plane: runs OMP with WAN Edges, applies control policy and distributes routes and keys.
OMP
Overlay Management Protocol, the routing protocol between WAN Edges and Controllers carrying OMP, TLOC and service routes.
TLOC
Transport locator: identifies a WAN Edge transport attachment by system IP, color and encapsulation.
Transport independence
The ability of the SD-WAN overlay to run over any mix of MPLS, broadband, LTE or 5G links.
Application-aware routing
Choosing a path per application based on measured loss, latency and jitter against an SLA policy.
Zero-touch provisioning
Automatic onboarding where a new device contacts the orchestrator and downloads its configuration without manual setup.
Direct internet access
Sending internet or SaaS traffic straight out of the branch instead of backhauling it through the data center.
EID
Endpoint identifier: the IP or MAC address that identifies an endpoint in LISP.
RLOC
Routing locator: the underlay address (usually a loopback) of the fabric node where an endpoint is attached.
Edge node
The fabric access switch that connects endpoints, registers them with the control plane node and acts as their anycast gateway.
Border node
The fabric node that connects the SD-Access fabric to external networks such as the data center, WAN or internet.
SGT
Scalable Group Tag: a 16-bit group identifier assigned to a user or device and used for group-based policy.
Underlay
The physical routed network that provides IP reachability between fabric node loopbacks.
Overlay
The virtual network (LISP plus VXLAN) built on the underlay that carries endpoint traffic and segmentation.
Anycast gateway
The same default gateway IP and MAC configured on every edge node for a subnet, so hosts keep their gateway anywhere.
Group-based policy
Access rules written between scalable groups (SGTs) instead of IP addresses.
Virtual network
An SD-Access macro-segment that maps to a VRF in the fabric.
DSCP
Differentiated Services Code Point: a 6-bit Layer 3 marking in the IP header, values 0 to 63.
CoS
Class of Service: a 3-bit Layer 2 priority in the 802.1Q tag, values 0 to 7, present only on tagged links.
Policing
Enforcing a rate by dropping or re-marking excess traffic without buffering.
Shaping
Enforcing a rate by buffering excess traffic and sending it later, outbound only.
LLQ
Low Latency Queuing: CBWFQ plus a strict-priority queue, typically for voice.
WRED
Weighted Random Early Detection: drops packets early and selectively by marking to avoid tail drop and TCP global synchronization.
RIB
Routing Information Base: the routing table built by routing protocols, static and connected routes.
FIB
Forwarding Information Base: CEF's lookup-optimized copy of the RIB's best routes with next hops resolved.
Adjacency table
CEF's table of directly connected next hops with prebuilt Layer 2 rewrite headers, built from ARP or ND.
Process switching
Forwarding each packet by a CPU process with a full routing table lookup; slowest method.
CEF
Cisco Express Forwarding: prebuilds the FIB and adjacency table so forwarding needs no per-destination CPU work.
CAM
Content addressable memory that returns a result for an exact match in a single lookup; used for the MAC address table.
TCAM
Ternary CAM whose bits can be 0, 1 or don't care; used for prefix and ACL lookups.
MAC address table
The table mapping MAC address and VLAN to a switch port, stored in CAM.
SDM template
A Catalyst setting that divides TCAM and other hardware resources among features.
Punt
Sending a packet from the hardware data plane up to the route processor CPU for software handling.
Control plane
The functions that build forwarding state, such as routing protocols and spanning tree, running on the CPU.
Data plane
The forwarding path that moves transit packets, ideally in hardware.
CoPP
Control Plane Policing: a QoS policy that rate-limits traffic destined to or punted to the CPU.

Domain 2: Virtualization (10%)

Exam tips

Key terms

Hypervisor
Software that creates and runs virtual machines by sharing physical hardware among them.
Type 1 hypervisor
A bare-metal hypervisor running directly on hardware, such as ESXi, Hyper-V or KVM.
Type 2 hypervisor
A hosted hypervisor running as an application on a host operating system, such as VirtualBox or VMware Workstation.
Virtual switch
A software Layer 2 switch inside the hypervisor connecting virtual NICs to each other and to physical uplinks.
Container
An isolated process environment that shares the host operating system kernel and packages an application with its dependencies.
Container image
A portable, layered package of an application and its libraries used to start containers.
Namespaces and cgroups
Linux kernel features that isolate a container's view of the system and limit its resource use.
Kubernetes
A container orchestration platform that schedules, scales and heals containers across a cluster of hosts.
VRF
Virtual routing and forwarding: an isolated routing and forwarding table with its own interfaces on a router.
VRF-Lite
Using VRFs hop by hop without MPLS, typically with one subinterface per VRF between devices.
Route leaking
Deliberately importing routes from one VRF into another so selected traffic can cross between them.
Route distinguisher
A value prepended to prefixes in MPLS VPNs so overlapping prefixes from different VRFs stay unique in MP-BGP.
GRE
Generic Routing Encapsulation: a tunneling protocol (IP protocol 47) that carries one packet inside another without encryption.
Tunnel source and destination
The underlay addresses the GRE packets use between the two tunnel endpoints.
Recursive routing
A failure where the route to the tunnel destination points through the tunnel itself, causing the tunnel to go down.
MSS
Maximum segment size: the largest TCP payload a host will accept, normally MTU minus 40 bytes.
GRE keepalive
Periodic probes that bring the tunnel line protocol down when the far end stops responding.
IKE phase 1
Negotiates and authenticates the IKE (ISAKMP) SA, a secure channel for further negotiation.
IKE phase 2
Quick mode, which negotiates the IPsec SAs that protect user data.
ESP
Encapsulating Security Payload (IP protocol 50): provides encryption, integrity and anti-replay.
Tunnel mode
Encrypts the whole original packet and adds a new outer IP header; typical for site-to-site VPNs.
Transport mode
Protects only the payload and keeps the original IP header; used when endpoints are the traffic endpoints, such as GRE over IPsec.
Tunnel protection
Applying an IPsec profile to a tunnel interface to encrypt all traffic routed through it.
GRE over IPsec
A GRE tunnel whose packets are encrypted by IPsec, allowing routing protocols and multicast across an encrypted VPN.
Static VTI
An IPsec virtual tunnel interface (tunnel mode ipsec ipv4) that encrypts all traffic routed into it without a GRE header.
IPsec profile
A named set of IPsec parameters, such as the transform set, applied to a tunnel interface with tunnel protection.
DMVPN
Dynamic Multipoint VPN: hub-and-spoke mGRE plus NHRP and IPsec, letting spokes build direct tunnels on demand.
EID
Endpoint identifier: the address that identifies a host and stays with it when it moves.
RLOC
Routing locator: the underlay address of the LISP router through which an EID is reachable.
Map server
Receives Map-Register messages from ETRs and stores EID-to-RLOC mappings.
Map resolver
Receives Map-Request queries from ITRs and resolves them to the correct RLOC.
ITR and ETR
Ingress tunnel router encapsulates traffic toward a remote RLOC; egress tunnel router registers local EIDs and decapsulates arriving traffic.
VXLAN
An encapsulation that carries Ethernet frames inside UDP over an IP network.
VNI
VXLAN network identifier: a 24-bit segment ID, allowing about 16 million segments.
VTEP
VXLAN tunnel endpoint: the device that encapsulates and decapsulates VXLAN traffic, identified by an underlay IP address.
UDP 4789
The IANA-assigned destination port for VXLAN.
BGP EVPN
A control plane that advertises MAC and IP reachability between VTEPs, reducing flood-and-learn behavior.

Domain 3: Infrastructure (30%)

Exam tips

Key terms

802.1Q
The IEEE trunking standard that inserts a 4-byte tag with a 12-bit VLAN ID into Ethernet frames.
DTP
Dynamic Trunking Protocol: Cisco protocol that negotiates whether a link becomes a trunk.
Native VLAN
The VLAN whose frames are sent untagged on an 802.1Q trunk; must match on both ends.
Allowed VLAN list
The set of VLANs permitted to cross a trunk, set with switchport trunk allowed vlan.
Switchport nonegotiate
Disables DTP frames on a port.
LACP
Link Aggregation Control Protocol, the IEEE standard for negotiating EtherChannel; modes active and passive.
PAgP
Port Aggregation Protocol, the Cisco proprietary EtherChannel negotiation protocol; modes desirable and auto.
Mode on
Static EtherChannel with no negotiation protocol; must be on at both ends.
Load-balancing hash
The per-frame calculation on address or port fields that chooses which member link carries a flow.
Root port
The port on a non-root switch with the best path to the root bridge.
Designated port
The forwarding port on each segment toward that segment, chosen by best path to root.
Alternate port
An RSTP discarding port with an alternative path to the root, ready to replace the root port.
BPDU guard
Err-disables a PortFast port that receives a BPDU.
Root guard
Blocks a designated port that receives a superior BPDU, preventing an unwanted switch from becoming root.
Loop guard
Blocks a non-designated port that stops receiving BPDUs, preventing loops from unidirectional links.
Link-state
A routing approach where routers share topology and each computes paths with SPF from a full map.
Advanced distance vector
EIGRP's approach, learning distances from neighbors and using DUAL to keep paths loop-free.
Administrative distance
Trust value for choosing between routing sources: EIGRP internal 90, OSPF 110, EIGRP external 170.
Reference bandwidth
OSPF's value divided by interface bandwidth to get cost; defaults to 100 Mbps.
Unequal-cost load balancing
Sharing traffic across paths with different metrics, supported only by EIGRP through variance.
Feasible distance
The router's total metric to a destination through the best path.
Reported distance
The metric to the destination as advertised by a neighbor.
Feasibility condition
A neighbor's reported distance must be less than the current feasible distance for it to be a feasible successor.
Variance
A multiplier that allows EIGRP to install feasible successors with higher metrics for unequal-cost load balancing.
Stub router
An EIGRP router that tells neighbors not to query it and advertises only selected route types.
ABR
Area border router: connects area 0 to other areas and generates type 3 summary LSAs.
ASBR
Autonomous system boundary router: redistributes external routes into OSPF.
DR and BDR
Designated and backup designated router elected on broadcast networks to reduce adjacencies.
Totally stubby area
An area that blocks type 3 and type 5 LSAs and receives only a default route from the ABR.
NSSA
Not-so-stubby area: blocks type 5 LSAs but allows local externals as type 7 LSAs, translated to type 5 by the ABR.
eBGP
BGP between routers in different autonomous systems; uses TTL 1 by default.
Established
The BGP state in which the session is up and UPDATE messages are exchanged.
Weight
Cisco-specific, router-local attribute; the highest value is preferred first.
Local preference
AS-wide attribute used to choose the exit point; the highest value wins, default 100.
AS_PATH
The list of autonomous systems a route has crossed, used for loop prevention and path length.
MED
Multi-exit discriminator: a lower value suggests a preferred entry point into a neighboring AS.
Policy-based routing
Forwarding packets based on criteria other than the destination, defined by a route map.
Route map
An ordered list of permit or deny statements with match and set clauses.
set ip next-hop
A PBR action that forwards matching packets to a specific directly connected next hop.
ip policy route-map
Interface command that applies PBR to packets arriving on that interface.
ip local policy
Applies PBR to traffic generated by the router itself.
Stratum
NTP's distance from the reference clock; lower is more accurate, 16 means unsynchronized.
PTP
Precision Time Protocol (IEEE 1588): hardware-timestamped time sync with sub-microsecond accuracy.
Inside local and inside global
The host's real private address and the translated address the outside sees.
PAT
NAT overload: many inside hosts share one global address using different source ports.
Preemption
Allows a higher-priority FHRP router to take back the active or master role; off by default in HSRP, on in VRRP.
IGMP
The protocol hosts use to join and leave multicast groups with their local router.
PIM sparse mode
A multicast routing protocol that forwards only after explicit joins, using an RP for shared trees.
Rendezvous point
The router where multicast sources register and receivers join the shared (*,G) tree.
RPF check
Forwarding a multicast packet only if it arrived on the interface used to reach its source.
SSM
Source-Specific Multicast: receivers request (S,G) with IGMPv3, trees go directly to the source, no RP; range 232.0.0.0/8.

Domain 4: Network Assurance (10%)

Exam tips

Key terms

Extended ping
A ping that lets you choose the source, size, count and don't-fragment bit.
Traceroute
A tool that increments TTL on probes to list each Layer 3 hop to a destination.
Conditional debug
Debugging limited to a specific interface, address or other condition.
undebug all
Command that turns off all debugging immediately.
MIB and OID
The structured database of manageable objects and the numeric identifier for each object.
Community string
The clear-text shared password used by SNMPv1 and v2c.
Trap
An unacknowledged notification sent by the agent to the NMS on UDP 162.
Inform
An acknowledged notification, retransmitted if the NMS does not confirm it.
authPriv
The SNMPv3 security level with both authentication and encryption.
Syslog severity
A 0 to 7 scale where 0 is emergencies and 7 is debugging; lower is more severe.
logging trap
Sets the maximum severity level sent to syslog servers.
logging buffered
Stores log messages in device RAM for viewing with show logging.
terminal monitor
Displays log and debug messages in the current SSH or Telnet session.
Facility
The component or category of a message, such as LINEPROTO or OSPF, or the syslog facility like local7.
Flow
A set of packets that share the same values in the defined key fields.
Flow record
Defines key fields (match) and non-key fields (collect) for Flexible NetFlow.
Flow exporter
Defines the collector destination, source, transport port and export format.
Flow monitor
Links a record and exporters with cache settings and is applied to an interface.
IPFIX
The IETF standard flow export protocol based on NetFlow version 9.
SPAN
Switched Port Analyzer: local mirroring of source ports or VLANs to a destination port on the same switch.
RSPAN
Remote SPAN: mirrored traffic carried in a dedicated remote-span VLAN across Layer 2 trunks.
ERSPAN
Encapsulated Remote SPAN: mirrored traffic carried in GRE across a routed Layer 3 network.
Destination port
The port that receives mirrored copies for the analyzer; it no longer forwards normal traffic.
IP SLA operation
A configured synthetic probe, such as icmp-echo or udp-jitter, that measures a path.
IP SLA responder
A Cisco device feature that answers and timestamps probes such as udp-jitter for accurate measurements.
Track object
An object whose up or down state follows an IP SLA, interface or route and is used by other features.
Floating static route
A backup static route with a higher administrative distance that is used only when the primary disappears.
Assurance
Catalyst Center's monitoring and analytics function that measures network, client and application health.
Health score
A rating that summarizes the condition of a device, client, site or application from many metrics.
Path trace
A tool that computes the path between two endpoints and highlights blocking ACLs or problem interfaces.
Dynamic baseline
A machine-learned model of normal behavior used to detect anomalies instead of fixed thresholds.
NETCONF
An XML-based network management protocol over SSH port 830 that uses RPC operations and datastores.
RESTCONF
An HTTPS interface using GET, POST, PUT, PATCH and DELETE on YANG-modeled data encoded in JSON or XML.
Datastore
A copy of configuration, such as running, startup or candidate, that NETCONF operations act on.
Capabilities exchange
The NETCONF hello exchange in which each side lists the features and models it supports.
edit-config
The NETCONF operation that changes configuration in a datastore.

Domain 5: Security (20%)

Exam tips

Key terms

VTY lines
Virtual terminal lines used for remote Telnet or SSH management sessions.
login local
Line command that authenticates users against the device's local username database.
enable secret
The hashed password protecting privileged EXEC mode.
transport input ssh
Line command that permits only SSH for incoming remote sessions.
access-class
Applies an ACL to VTY lines to restrict which source addresses can connect.
AAA
Authentication, authorization and accounting: identifying users, controlling their actions and logging activity.
TACACS+
Cisco-developed AAA protocol on TCP 49 that encrypts the whole body and separates the three A's; best for device administration.
RADIUS
Open-standard AAA protocol on UDP 1812/1813 that encrypts only the password and combines authentication and authorization; used for network access.
Method list
An ordered list of authentication or authorization sources, applied by name or as default.
Fallback
Moving to the next method in a list, which happens only when a method returns an error such as no server response.
Standard ACL
Matches only the source IP address; numbered 1-99 and 1300-1999.
Extended ACL
Matches protocol, source, destination and ports; numbered 100-199 and 2000-2699.
Wildcard mask
A mask where 0 bits must match and 1 bits are ignored.
Implicit deny
The invisible final entry in every ACL that drops anything not permitted.
First match
ACL processing stops at the first entry that matches the packet.
CoPP
Control Plane Policing: an MQC policy applied to the control-plane interface that rate-limits traffic to the CPU.
control-plane
The special configuration mode representing the route processor, where the CoPP service policy is attached.
class-default
The catch-all class for traffic that matches no defined class, usually policed tightly in CoPP.
Exceed action
What a policer does with traffic above the configured rate, such as drop or transmit.
HTTPS
HTTP protected by TLS, encrypting traffic and authenticating the server with a certificate.
Token authentication
Exchanging credentials once for a time-limited token that is sent with later requests.
Bearer token
A token presented in the Authorization header; whoever holds it can use it.
Least privilege
Granting an account only the permissions its task requires.
Secrets manager
A system that stores credentials securely with access control, auditing and rotation.
Defense in depth
Layering multiple security controls so the failure of one does not expose the whole network.
NGFW
Next-generation firewall: a stateful firewall with application awareness, user identity, IPS, URL filtering and malware protection.
IPS
Intrusion prevention system: inspects traffic inline and blocks known attack patterns and anomalies.
EDR
Endpoint detection and response: records endpoint activity to detect, investigate and contain threats.
Zero trust
A model that never assumes trust based on network location and continuously verifies users and devices.
SGT
Scalable (Security) Group Tag: a 16-bit identifier that represents a user or device group.
SGACL
Scalable Group ACL: a permit or deny policy between a source SGT and a destination group.
SXP
SGT Exchange Protocol: shares IP-to-SGT mappings over TCP where inline tagging is not supported.
MACsec
IEEE 802.1AE hop-by-hop Layer 2 encryption and integrity protection on Ethernet links.
MKA
MACsec Key Agreement: the protocol that negotiates and distributes MACsec keys.
Supplicant
The 802.1X client software on the endpoint.
Authenticator
The switch or wireless controller that controls the port and relays EAP to the RADIUS server.
EAPOL
EAP over LAN: carries EAP messages between the supplicant and the switch.
MAB
MAC Authentication Bypass: authenticates devices without supplicants using their MAC address.
Change of authorization
A RADIUS message from ISE that tells the switch to re-authenticate or apply new policy to an active session.
DHCP snooping
Blocks DHCP server messages on untrusted ports and builds a binding table of legitimate leases.
Binding table
The DHCP snooping record of MAC, IP, VLAN and port for each client lease.
Dynamic ARP inspection
Drops ARP packets on untrusted ports whose IP-to-MAC mapping does not match the binding table.
IP source guard
Filters traffic on access ports so only sources matching the port's binding are allowed.
Trusted port
A port, usually an uplink or server port, exempt from DHCP snooping and DAI checks.

Domain 6: Automation and AI (15%)

Exam tips

Key terms

Variable
A name bound to a value; Python infers its type.
List
An ordered, zero-indexed collection written in square brackets.
Dictionary
A collection of key-value pairs written in braces, equivalent to a JSON object.
Function
A reusable block defined with def that takes parameters and can return a value.
requests
A Python library for sending HTTP requests and handling responses.
JSON object
Key-value pairs in curly braces with double-quoted string keys; maps to a Python dict.
JSON array
An ordered list of values in square brackets; maps to a Python list.
json.loads
Parses a JSON string into Python objects.
json.dumps
Serializes Python objects into a JSON string.
null
JSON's empty value, which becomes None in Python.
YANG
A data modeling language that defines the structure and types of network configuration and state data.
Container
A YANG node that groups other nodes and holds no value itself.
Leaf
A YANG node holding a single typed value.
Native model
A vendor-specific YANG model covering all platform features, such as Cisco-IOS-XE-native.
CRUD
Create, read, update, delete: the basic operations mapped to POST, GET, PUT or PATCH, and DELETE.
Idempotent
Repeating the request has the same effect as sending it once; true of GET, PUT and DELETE.
201 Created
Success status indicating a new resource was created.
401 vs 403
401 means not authenticated or token invalid; 403 means authenticated but not permitted.
Content-Type
The header declaring the format of the request or response body.
Intent API
Catalyst Center's northbound REST API for querying and configuring the network in terms of desired outcomes.
X-Auth-Token
The HTTP header that carries the Catalyst Center token on each API request.
Token endpoint
POST /dna/system/api/v1/auth/token with Basic authentication, returning a time-limited token.
taskId
The identifier returned by an asynchronous operation, polled via the task API to get its status and result.
/dataservice
The base path of SD-WAN Manager REST API endpoints.
j_security_check
The login endpoint that accepts form-encoded username and password and returns a JSESSIONID cookie.
JSESSIONID
The session cookie that authenticates subsequent SD-WAN Manager API calls.
X-XSRF-TOKEN
Header carrying the CSRF token from /dataservice/client/token, required for POST, PUT and DELETE.
EEM
Embedded Event Manager: on-device automation that runs actions when defined events occur.
Applet
An EEM policy written in configuration mode with one event and a set of actions.
Event detector
The EEM component that triggers an applet, such as syslog, timer, track or interface.
action cli command
An EEM action that runs a CLI command on the device.
Agent-based
Management where software on each target pulls and enforces its configuration from a central server.
Agentless
Management where a control node connects over existing protocols such as SSH and pushes changes.
Playbook
An Ansible YAML file of plays and tasks applied to hosts from an inventory.
Manifest
A Puppet file that declares desired state in Puppet's language.
Cookbook and recipe
Chef's units of configuration, written in a Ruby-based language.
Baseline
A learned model of normal behavior for a metric in its context, such as time of day and site.
Anomaly detection
Identifying behavior that deviates significantly from the baseline.
Hallucination
A confident but incorrect or fabricated output from a generative AI model.
Human in the loop
Requiring a qualified person to review and approve AI recommendations before changes are made.
Prompt injection
Malicious instructions hidden in input data that attempt to manipulate an AI system's behavior.
Study ENCOR for free
Lessons, quizzes, exam simulations and hands-on labs.
Open the ENCOR study plan