All certifications / ENCOR / Lessons
ENCOR 350-401 v1.2 lessons
Study ENCOR for free
A week-by-week plan with every lesson, quizzes, checkpoint tests, a practice exam and hands-on labs.
Open the ENCOR study planA week-by-week plan with every lesson, quizzes, checkpoint tests, a practice exam and hands-on labs.
Domain 1: Architecture
- Enterprise design: two-tier (collapsed core) and three-tier campus, fabric/spine-leaf, cloud vs on-premises
- High availability: redundancy, first hop redundancy protocols, stateful switchover (SSO)
- SD-WAN control and data plane: Manager, Validator, Controllers, WAN Edges, OMP and IPsec tunnels
- SD-WAN benefits and limitations compared with traditional WAN
- SD-Access: control plane (LISP), data plane (VXLAN), policy plane (TrustSec), fabric node roles
- Traditional campus vs SD-Access: underlay and overlay, group-based policy from Catalyst Center
- QoS components: classification and marking (DSCP, CoS), policing, shaping, queuing (CBWFQ, LLQ), WRED
- Hardware and software switching: process switching, CEF, FIB, RIB, adjacency table
- CAM and TCAM tables and what each stores
- Punted traffic and its effect on the control plane CPU
Domain 2: Virtualization
- Hypervisors: type 1 vs type 2, virtual machines and virtual switching
- Containers compared with virtual machines
- VRF and VRF-Lite: separate routing tables, overlapping addresses, per-VRF routing
- GRE tunnels: configuration, keepalives, recursive routing problems, MTU and MSS
- IPsec: IKE phases, tunnel vs transport mode, crypto maps vs tunnel protection
- GRE over IPsec and virtual tunnel interfaces for routing protocols over VPNs
- LISP: EID, RLOC, map server and map resolver, ITR and ETR
- VXLAN: VNI, VTEP, UDP encapsulation, overlay vs underlay
Domain 3: Infrastructure
- Layer 2: static and dynamic 802.1Q trunking (DTP), allowed VLANs and native VLAN
- EtherChannel: LACP, PAgP and static; member consistency; load balancing
- Spanning tree: RSTP and MST, port roles, root placement, BPDU guard, root guard, loop guard
- EIGRP vs OSPF: algorithms, metrics, path selection, load balancing, summarization
- EIGRP: feasible successors, variance, stub routing
- OSPFv2 and OSPFv3: multi-area, adjacencies, network types, area types (stub, totally stubby, NSSA), summarization and filtering
- eBGP between directly connected neighbors: neighbor states and best-path selection
- Policy-based routing with route maps
- IP services: NTP and PTP, NAT and PAT, HSRP and VRRP
- Multicast: IGMPv2/v3, PIM sparse mode, RP, RPF check, SSM
Domain 4: Network Assurance
- Diagnose problems with debugs, conditional debugs, ping and traceroute
- SNMP versions (v2c vs v3 authPriv), traps and polling
- Syslog severity levels and logging configuration
- Flexible NetFlow: flow records, exporters and monitors
- SPAN, RSPAN and ERSPAN
- IP SLA probes and object tracking
- Catalyst Center (formerly DNA Center) workflows: assurance, health scores, AI-driven insights
- NETCONF and RESTCONF for configuration and operational data
Domain 5: Security
- Device access control: line and local user authentication, SSH-only VTY access
- AAA with TACACS+ and RADIUS, method lists and fallback
- Infrastructure security: standard and extended ACLs, placement and order
- Control Plane Policing (CoPP)
- REST API security: HTTPS, tokens, secret handling
- Network security design: threat defense, endpoint security, next-generation firewall
- Cisco TrustSec (SGT, SGACL) and MACsec
- Network access control: 802.1X, MAB and WebAuth
- Layer 2 protections: DHCP snooping, dynamic ARP inspection, IP source guard
Domain 6: Automation and AI
- Python basics: variables, loops, functions, dictionaries, the requests library
- JSON syntax and parsing JSON in Python
- YANG data models and how NETCONF and RESTCONF use them
- REST API methods and response codes (200, 201, 204, 400, 401, 403, 404, 500)
- Catalyst Center Intent APIs: token authentication and common calls
- SD-WAN Manager REST APIs
- Embedded Event Manager (EEM) applets
- Orchestration tools: agent-based (Puppet, Chef) vs agentless (Ansible)
- AI in network operations: baselining, anomaly detection, AI-assisted troubleshooting and safe guardrails