All certifications / CCST Networking / Cheat sheet
CCST Networking 100-150 v1.0 cheat sheet
Domain 1: Standards and concepts (20%)
Exam tips
- Match devices to layers: hub = 1, switch = 2, router = 3. Also remember that the TCP/IP Application layer covers OSI Layers 5, 6 and 7, and the TCP/IP Link layer covers OSI Layers 1 and 2.
- If a question asks which address changes at every router hop, the answer is the MAC address. The IP addresses stay the same end to end unless NAT is involved.
- Choppy voice or video calls with an otherwise fast connection usually point to jitter or latency, not bandwidth. And iperf tests between two points you choose, while a speed test measures your path to an internet server.
- Look for clues about area and ownership. 'Multiple buildings on one site' means CAN, 'across a city' means MAN, 'between cities or countries' means WAN, and 'Bluetooth around a person' means PAN.
- Ask 'who manages the operating system?' If the customer does, it is IaaS. If the provider does but the customer writes the code, it is PaaS. If the customer only uses the app, it is SaaS.
- Internal resources for remote users need a VPN (or a similar secure access service); public SaaS apps just need working internet access. Use that split to narrow down which part of the path is failing.
- Order matters: SYN, SYN-ACK, ACK. And if a question emphasizes 'reliable, ordered, acknowledged', pick TCP; 'low overhead, real-time, no handshake', pick UDP.
- Know the transport too: DHCP, TFTP, NTP and normal DNS queries use UDP; FTP, SSH/SFTP, HTTP and HTTPS use TCP. SFTP shares port 22 with SSH, not port 21 with FTP.
- ICMP has no ports. If an answer choice says 'ping uses TCP or UDP port X', it is wrong. Also, 'Request timed out' does not prove a host is off; a firewall may simply be dropping ICMP.
Key terms
- OSI model
- A seven-layer reference model (Physical, Data Link, Network, Transport, Session, Presentation, Application) used to describe and troubleshoot networking.
- TCP/IP model
- The four-layer model (Link, Internet, Transport, Application) that describes how internet protocols are actually organized.
- Layer 2 device
- A device, such as a switch, that forwards frames based on MAC addresses within a local network.
- Layer 3 device
- A device, such as a router, that forwards packets between networks based on IP addresses.
- Encapsulation
- Adding a layer's header (and trailer) to data as it moves down the stack before transmission.
- PDU
- Protocol data unit, the name for data at a given layer: data, segment, packet, frame or bits.
- MAC address
- A 48-bit hardware address used to deliver frames on the local network segment.
- IP address
- A logical address that identifies a host and its network, used by routers to forward packets between networks.
- ARP
- Address Resolution Protocol, which finds the MAC address that matches a known IPv4 address on the local network.
- Bandwidth
- The maximum theoretical data rate of a link, measured in bits per second.
- Throughput
- The actual data rate achieved in practice, always at or below bandwidth.
- Latency
- The time it takes data to travel across the network, often measured as round-trip time in milliseconds.
- Jitter
- Variation in latency from packet to packet, which harms real-time voice and video.
- iperf3
- A client/server tool that measures throughput between two hosts you control.
- LAN
- Local area network: devices in one building or site connected by switches and owned by the organization.
- WAN
- Wide area network: links between distant sites, usually leased from service providers; the internet is the largest WAN.
- CAN
- Campus area network: multiple LANs across nearby buildings of one organization.
- MAN
- Metropolitan area network: a network spanning a city or metro region.
- PAN
- Personal area network: devices around one person, such as Bluetooth earbuds and a phone.
- WLAN
- Wireless LAN: a local network whose clients connect using Wi-Fi.
- On-premises
- Infrastructure the organization owns and operates in its own facilities.
- Hybrid cloud
- A combination of on-premises or private cloud with public cloud, connected so workloads can span both.
- IaaS
- Infrastructure as a Service: rented virtual machines, storage and networks; the customer manages the OS and apps.
- PaaS
- Platform as a Service: the provider manages the OS and runtime; the customer deploys code and data.
- SaaS
- Software as a Service: a complete application delivered over the network and managed by the provider.
- VPN
- Virtual private network: an encrypted tunnel across an untrusted network such as the internet.
- Remote-access VPN
- A VPN from one user's device, usually running a client app, to a company VPN gateway.
- Site-to-site VPN
- A VPN between two networks' routers or firewalls, so every device at each site can communicate.
- Split tunnel
- A VPN setting that sends only company-bound traffic through the tunnel and other traffic directly to the internet.
- TCP
- Transmission Control Protocol: connection-oriented, reliable, ordered delivery with acknowledgments and retransmission.
- UDP
- User Datagram Protocol: connectionless, best-effort delivery with minimal overhead and no retransmission.
- Three-way handshake
- The SYN, SYN-ACK, ACK exchange TCP uses to open a connection.
- Flow control
- TCP's windowing mechanism that limits how much data a sender transmits before receiving acknowledgment.
- Port number
- A 16-bit number in the TCP or UDP header that identifies the application or service on a host.
- Well-known ports
- Ports 0 to 1023, reserved for standard services such as HTTP (80) and HTTPS (443).
- Socket
- The combination of an IP address, transport protocol and port that identifies one end of a conversation.
- DORA
- The four DHCP messages: Discover, Offer, Request, Acknowledge.
- SFTP
- SSH File Transfer Protocol, encrypted file transfer running over SSH on TCP 22.
- ICMP
- Internet Control Message Protocol, a Network layer protocol for error reporting and diagnostics.
- Echo Request / Echo Reply
- ICMP types 8 and 0, the messages ping sends and receives.
- Destination Unreachable
- ICMP type 3, reporting that a packet could not be delivered, with a code that gives the reason.
- Time Exceeded
- ICMP type 11, sent when a packet's TTL reaches zero; traceroute depends on it.
Domain 2: Addressing and subnet formats (12%)
Exam tips
- The 172 range is the one people miss: only 172.16.x.x through 172.31.x.x are private. Any address outside the three ranges (and outside special ranges like 127 and 169.254) is public.
- 'Many to one using ports' is PAT (NAT overload). 'One to one, permanent' is static NAT. 'Many to many from a pool' is dynamic NAT.
- 169.254.x.x in a question almost always means 'the host could not reach a DHCP server'. Do not confuse it with a private RFC 1918 address.
- Know the mask octet values cold: 128, 192, 224, 240, 248, 252, 254, 255, which add 1, 2, 3, 4, 5, 6, 7 and 8 bits. For example, /27 is 24 + 3, so the last octet is 224.
- Usable hosts = 2^(host bits) minus 2. Remember the table: /24 254, /25 126, /26 62, /27 30, /28 14, /29 6, /30 2.
- Matching first three octets does not mean same subnet when the mask is longer than /24. Always find the network address for each host using the mask.
- An address with two double colons is always invalid. And only leading zeros can be removed from a hextet, never trailing ones.
- IPv6 has no broadcast addresses; multicast (ff) does that job. And an fe80 address on an interface is normal, unlike a 169.254 address in IPv4.
- In EUI-64, remember 'insert fffe, flip the seventh bit'. And the IPv6 default gateway always comes from the router advertisement, never from DHCPv6.
Key terms
- Private address
- An IPv4 address from the RFC 1918 ranges, usable inside any organization but not routed on the internet.
- Public address
- A globally unique, internet-routable IP address assigned through registries and providers.
- RFC 1918
- The standard that defines the private IPv4 ranges 10.0.0.0/8, 172.16.0.0/12 and 192.168.0.0/16.
- Carrier-grade NAT
- Provider-level NAT that places many customers behind shared public addresses.
- NAT
- Network Address Translation: rewriting IP addresses as packets cross a router, typically private to public.
- PAT
- Port Address Translation (NAT overload): many inside hosts share one public address, distinguished by port numbers.
- Static NAT
- A fixed one-to-one mapping between a private and a public address.
- Port forwarding
- A static rule that sends inbound traffic on a specific public port to a chosen inside host.
- Translation table
- The router's list of active mappings between inside addresses/ports and outside addresses/ports.
- Loopback
- The 127.0.0.0/8 range (usually 127.0.0.1) that sends traffic back to the same host to test the local IP stack.
- APIPA
- Automatic Private IP Addressing: a self-assigned 169.254.x.x address used when DHCP fails.
- Limited broadcast
- 255.255.255.255, sent to all hosts on the local segment and never routed.
- Directed broadcast
- The last address in a subnet (all host bits 1), which reaches all hosts in that subnet.
- Octet
- One 8-bit group of an IPv4 address, written as a decimal number from 0 to 255.
- Subnet mask
- A 32-bit value whose 1 bits mark the network portion of an address and 0 bits mark the host portion.
- CIDR notation
- Writing the mask as a slash followed by the number of network bits, such as /24.
- Prefix length
- The number of network bits in an address, the number after the slash.
- Network address
- The first address in a subnet, with all host bits 0; it identifies the subnet and cannot be assigned to a host.
- Broadcast address
- The last address in a subnet, with all host bits 1; it reaches all hosts in the subnet.
- Usable host range
- The addresses between the network and broadcast addresses that can be assigned to devices.
- Block size
- 256 minus the last non-255 mask octet; the spacing between subnet boundaries.
- Subnet calculator
- A tool that computes network address, broadcast address, host range and host count from an address and mask.
- Bitwise AND
- The operation that combines an address with its mask to find the network address.
- Same subnet
- Two hosts whose addresses produce the same network address under the same mask; they communicate directly without a router.
- ipcalc
- A command-line subnet calculator available on many Linux systems.
- Hextet
- One 16-bit group of an IPv6 address, written as four hexadecimal digits.
- Double colon (::)
- Notation that replaces one run of consecutive all-zero hextets; it can be used only once per address.
- Interface ID
- The host portion of an IPv6 address, usually the last 64 bits.
- Global unicast address
- A globally routable IPv6 address from 2000::/3, similar to a public IPv4 address.
- Link-local address
- An automatically created fe80::/10 address valid only on the local link and never routed.
- Unique local address
- An fc00::/7 address (in practice fd00::/8) for internal use, similar to IPv4 private addresses.
- Multicast address
- An ff00::/8 address that delivers traffic to a group of interfaces; IPv6 uses multicast instead of broadcast.
- SLAAC
- Stateless Address Autoconfiguration: a host builds its IPv6 address from the router's advertised prefix plus its own interface ID.
- Router Advertisement
- An ICMPv6 message from a router announcing the prefix, default gateway and address assignment method.
- Modified EUI-64
- A method that builds a 64-bit interface ID from a MAC address by inserting fffe and flipping the seventh bit.
- DHCPv6
- The IPv6 version of DHCP; stateful mode assigns addresses, stateless mode supplies only extra settings like DNS.
- Dual stack
- Running IPv4 and IPv6 simultaneously on the same devices and network.
Domain 3: Endpoints and media types (16%)
Exam tips
- The 100 m limit applies to Cat 5e, Cat 6 and Cat 6a alike. The difference is speed: Cat 6a supports 10 Gbps at the full 100 m, while Cat 6 supports 10 Gbps only at shorter distances.
- Small core, laser, long distance: single-mode. Larger core, LED or VCSEL, shorter distance: multimode. Coax today usually means a cable modem or TV connection.
- Memory aids: SC 'stick and click' (square, push-pull), ST 'stick and twist' (round, bayonet), LC 'little connector' (small, latched). F-type screws on; BNC twists on.
- Fiber is the answer when a question asks for a medium immune to EMI. Microwave ovens and Bluetooth interfere with 2.4 GHz Wi-Fi, not with 5 GHz.
- Lower frequency means longer range and better wall penetration; higher frequency means more channels and speed but shorter range. The only non-overlapping 2.4 GHz channels in North America are 1, 6 and 11.
- Cellular = licensed, carrier-managed, wide coverage, subscription. Wi-Fi = unlicensed, locally managed, shorter range, shared channels. A hotspot turns the phone into a Wi-Fi router using the cellular link.
- Hiding the SSID does not secure a network. Security comes from WPA2 or WPA3 encryption with a strong passphrase or 802.1X credentials.
- Servers and printers should have static or reserved addresses; ordinary clients use DHCP. IoT devices are a security concern and belong on their own segment with changed default passwords.
- Know the command per platform: Windows uses ipconfig and tracert; Linux uses ip and traceroute; macOS uses ifconfig and traceroute. Phones use the Wi-Fi details screen.
Key terms
- UTP
- Unshielded twisted pair: copper cable with twisted pairs that reduce interference, the standard for Ethernet LANs.
- Cat 6a
- Augmented Category 6 cable supporting 10 Gbps Ethernet at up to 100 meters.
- Straight-through cable
- A cable wired with the same standard on both ends, used between unlike devices such as PC and switch.
- Crossover cable
- A cable wired T568A on one end and T568B on the other, traditionally used between like devices.
- Auto-MDIX
- A port feature that automatically adjusts for straight-through or crossover cabling.
- Coaxial cable
- Cable with a central conductor and a surrounding shield, used mainly for cable TV and cable internet.
- Single-mode fiber
- Fiber with a small core (about 9 micrometers) that uses lasers and reaches many kilometers.
- Multimode fiber
- Fiber with a larger core (50 or 62.5 micrometers), using LEDs or VCSELs, for shorter distances such as within buildings.
- Modal dispersion
- Spreading of a light signal because different paths through a multimode core arrive at different times, which limits distance.
- RJ-45
- 8-pin modular connector used for Ethernet twisted-pair cables and Cisco console ports.
- RJ-11
- Smaller modular connector used for analog telephone and DSL lines.
- F-type
- Threaded coaxial connector used for cable TV and cable modems.
- LC connector
- Small latching fiber connector, usually duplex, common on SFP modules.
- SFP
- Small form-factor pluggable: a hot-swappable transceiver that adapts a switch port to a particular fiber or copper medium.
- EMI
- Electromagnetic interference: electrical noise from motors, lights, power cables and similar sources that disrupts signals.
- Crosstalk
- Signal bleeding from one wire pair into another within or between cables.
- Attenuation
- The loss of signal strength as it travels over distance or through obstacles.
- Co-channel interference
- Interference between Wi-Fi networks or access points using the same channel.
- 2.4 GHz band
- Wi-Fi band with the best range and penetration but few non-overlapping channels (1, 6, 11) and much interference.
- 5 GHz band
- Wi-Fi band with many channels and higher speeds but shorter range than 2.4 GHz.
- 6 GHz band
- Newest Wi-Fi band, used by Wi-Fi 6E and Wi-Fi 7, with abundant clean spectrum and the shortest range.
- Wi-Fi 6
- The Wi-Fi Alliance name for 802.11ax, focused on efficiency in busy environments.
- MIMO
- Multiple input, multiple output: using several antennas to send multiple data streams at once.
- Licensed spectrum
- Radio frequencies assigned exclusively to a carrier in a region, used by cellular networks.
- Unlicensed spectrum
- Radio frequencies anyone may use with approved equipment, such as the Wi-Fi bands.
- Tethering
- Sharing a phone's cellular data connection with another device over Wi-Fi, USB or Bluetooth.
- Mobile hotspot
- A phone or dedicated device acting as a Wi-Fi access point and router for a cellular connection.
- SIM / eSIM
- The physical or embedded module that identifies a subscriber to a cellular carrier.
- SSID
- Service set identifier: the case-sensitive name of a wireless network.
- Pre-shared key (PSK)
- A passphrase shared by all users of a WPA2- or WPA3-Personal network.
- 802.1X
- Port-based authentication used by Enterprise Wi-Fi, where each user or device is checked by an authentication server.
- Captive portal
- A web page that users must complete, such as accepting terms or signing in, before getting internet access.
- Endpoint
- A device at the edge of the network, such as a computer, phone, printer, server or IoT device, that users or applications use.
- Server
- A computer that provides services to clients, usually with a static IP address.
- IoT device
- An Internet of Things device, such as a camera, sensor or smart appliance, that connects to the network with limited user interface.
- BYOD
- Bring your own device: employees using personal phones, tablets or laptops for work.
- MDM
- Mobile device management: software for enforcing settings, apps and security on phones, tablets and laptops.
- ipconfig
- Windows command that displays IP configuration; /all adds details, /release and /renew refresh DHCP, /flushdns clears the DNS cache.
- ip
- Linux command for viewing and configuring interfaces (ip addr), routes (ip route) and links (ip link).
- ifconfig
- Older Unix command to view interface settings, still used on macOS.
- Test-NetConnection
- PowerShell command that tests reachability and can check whether a specific TCP port is open.
Domain 4: Infrastructure (20%)
Exam tips
- Off means no link, green means link (blinking means traffic), amber means blocked or faulty, and alternating green-amber means errors. A port that is briefly amber after connecting is often Spanning Tree still checking the link.
- Physical diagrams answer 'which port and cable', logical diagrams answer 'which subnet and VLAN'. In interface names like Gi1/0/24, the last number is the port.
- Console access works even when the network is down, because it is out-of-band. The default console settings to remember are 9600 baud, 8 data bits, no parity, 1 stop bit, no flow control.
- The switch (or injector) is the PSE and the phone, AP or camera is the PD. PoE+ (802.3at) provides about 30 W, basic PoE (802.3af) about 15.4 W. When some PoE devices fail to power on, think power budget.
- Classic symptom: local devices work, remote networks and the internet do not. Think missing or wrong default gateway. Also, the gateway must be in the same subnet as the host.
- When routes overlap, the longest prefix (most specific route) wins, not the one listed first. With no match and no default route, the packet is dropped.
- Switches forward on MAC addresses and routers forward on IP addresses. Routers separate broadcast domains; Layer 2 switches do not (except by VLAN). A Layer 3 switch routes between VLANs using SVIs.
- Switches learn from the source address and forward based on the destination address. Unknown unicasts and broadcasts are flooded within the VLAN only, never to other VLANs.
- Access port = one VLAN, untagged, to an end device. Trunk port = many VLANs, 802.1Q tagged, usually between switches. Inter-VLAN traffic always needs Layer 3 routing.
- Label both ends of every cable and keep documentation current. Patch panels are passive; they provide organized termination but do not switch or amplify signals.
Key terms
- SYST LED
- The system status LED; green means normal operation, amber means a problem such as a failed self-test.
- POST
- Power-on self-test: hardware checks a device runs at startup, shown by a blinking system LED.
- Port LED
- Per-port light showing link and activity; off means no link, green means link up, amber means not forwarding.
- MODE button
- A button on many Cisco switches that changes what the port LEDs display, such as status, speed, duplex or PoE.
- Physical diagram
- A diagram showing real devices, their locations, specific ports and cable types.
- Logical diagram
- A diagram showing subnets, VLANs, IP addressing and traffic flow rather than physical placement.
- Interface identifier
- A name such as Gi1/0/24 that gives the interface type and its switch, module and port numbers.
- Legend
- The key on a diagram that explains its symbols and line styles.
- Console port
- A port for direct out-of-band command-line access to a device, using an RJ-45 rollover cable or USB.
- Management port
- A dedicated Ethernet port for administrative access over a separate management network.
- SFP port
- A slot for a pluggable transceiver, commonly used for fiber uplinks.
- Serial port
- A router port for older WAN connections such as leased lines.
- PoE port
- An Ethernet port that also supplies electrical power to a connected device.
- PoE
- Power over Ethernet: sending DC power along with data over a twisted-pair Ethernet cable.
- PSE
- Power sourcing equipment: the device that supplies PoE, such as a PoE switch or injector.
- PD
- Powered device: the device receiving PoE, such as an IP phone, access point or camera.
- Power budget
- The total wattage a PoE switch can supply across all its ports.
- PoE injector
- A device that adds power to an Ethernet cable when the switch does not provide PoE.
- Default gateway
- The router address a host sends traffic to when the destination is not on its own subnet.
- Local destination
- An address in the host's own subnet, reached directly by ARP and a frame to that device.
- Remote destination
- An address on a different subnet, reached by sending the frame to the default gateway.
- ip default-gateway
- Cisco command that sets the gateway a Layer 2 switch uses for its own management traffic.
- Routing table
- A router's list of known networks and the interface or next hop used to reach each.
- Directly connected route
- A route to a subnet on one of the router's own active interfaces, added automatically.
- Static route
- A route manually configured by an administrator.
- Default route
- The 0.0.0.0/0 route used when no more specific route matches, often pointing to the internet.
- Longest prefix match
- The rule that the most specific matching route wins when several match.
- Layer 2 switch
- A switch that forwards frames within a VLAN using MAC addresses.
- Router
- A device that forwards packets between networks using IP addresses and separates broadcast domains.
- Layer 3 switch
- A multilayer switch that switches frames and also routes between VLANs, usually through SVIs.
- SVI
- Switched virtual interface: a virtual VLAN interface with an IP address on a switch, used for management or inter-VLAN routing.
- Broadcast domain
- The set of devices that receive a broadcast frame; routers and VLANs separate broadcast domains.
- MAC address table
- A switch's list mapping MAC addresses to ports and VLANs; also called the CAM table.
- Learning
- Recording a frame's source MAC address against the port it arrived on.
- Flooding
- Sending a frame out all ports in the VLAN except the incoming one, for broadcasts and unknown destinations.
- Filtering
- Not forwarding a frame out ports where it is not needed, including dropping it when the destination is on the incoming port.
- Aging time
- How long a dynamic MAC entry stays without being refreshed; 300 seconds by default on Cisco switches.
- VLAN
- A virtual LAN: a logical network on a switch that forms its own broadcast domain, usually its own subnet.
- Access port
- A switch port assigned to one VLAN, carrying untagged frames to an end device.
- Trunk port
- A switch port carrying multiple VLANs, identifying each frame with an 802.1Q tag.
- 802.1Q
- The IEEE standard for VLAN tagging that inserts a 4-byte tag into Ethernet frames on trunks.
- Native VLAN
- The VLAN whose frames cross an 802.1Q trunk untagged; VLAN 1 by default.
- Patch panel
- A rack-mounted panel of numbered jacks where permanent building cables terminate, connected to switches with short patch cables.
- Structured cabling
- An organized, standards-based system of horizontal cables, patch panels and patch cords.
- Rack unit (U)
- The standard height unit for rack equipment, 1.75 inches (44.45 mm).
- Bend radius
- The minimum curve a cable can be bent through without damage or signal loss.
- Cable manager
- Horizontal or vertical rack hardware that routes and holds cables neatly.
Domain 5: Diagnosing problems (20%)
Exam tips
- Know the order: identify, theory, test, plan, implement, verify, document. Documentation is always the last step, and you should consider the impact of a fix before implementing it.
- Escalate with complete notes: symptoms, tests run and results. Priority depends on impact and urgency, so an outage affecting many users outranks a single-user inconvenience.
- Choose the interface that actually carries the traffic. Display filters (like ip.addr == x) change only what you see; capture filters limit what gets recorded. The default save format is .pcapng.
- IP works but name does not: DNS problem, use nslookup. A traceroute that shows asterisks from one hop onward suggests where traffic is dropped, but single asterisks with later replies are often harmless.
- A failed ping does not prove a host or service is down, and a successful ping does not prove the service works. Test the actual port the application uses.
- Console is out-of-band and works without network settings. Choose SSH over Telnet because Telnet sends passwords in clear text. RDP is graphical Windows access and should sit behind a VPN.
- If a cloud-managed device loses its cloud connection, it typically keeps passing traffic with its last configuration; only management and monitoring are lost. The device needs internet access to be managed.
- Prompt ending > means user EXEC, # means privileged EXEC, (config)# means global configuration.
enablemoves up from user to privileged, andconfigure terminalenters global configuration. - Match the question to the command: uptime or IOS version, show version; IP and up/down status, show ip interface brief; errors and duplex, show interfaces; which device is on the other end, show cdp neighbors; serial numbers and modules, show inventory.
Key terms
- Theory of probable cause
- A reasoned guess at what is causing the problem, based on gathered facts, to be tested.
- Bottom-up approach
- Troubleshooting that starts at the physical layer and works upward through the OSI model.
- Divide and conquer
- Starting troubleshooting in the middle of the OSI model and moving up or down based on test results.
- Escalation
- Passing a problem to someone with more expertise or access when you cannot resolve it.
- Verification
- Confirming the whole system works for the user after a fix, not just that one test passes.
- Ticket
- A record in a tracking system of one incident or request, from report to resolution.
- Priority
- The order in which work is handled, based on impact and urgency.
- SLA
- Service level agreement: agreed targets for response and resolution times.
- Knowledge base
- A searchable collection of documented solutions and procedures.
- Wireshark
- A packet analyzer that captures and decodes network traffic.
- Display filter
- A Wireshark expression that shows only matching packets from a capture, such as ip.addr == 10.1.1.5.
- Capture filter
- A filter applied before capturing that limits which packets are recorded at all.
- .pcapng
- Wireshark's default capture file format, storing packets plus interface and comment information.
- SPAN
- Switched Port Analyzer: a switch feature that mirrors traffic from ports or VLANs to a monitoring port.
- ping
- A tool that sends ICMP Echo Requests to test reachability and measure round-trip time.
- tracert / traceroute
- Tools that list each router hop to a destination by using increasing TTL values.
- nslookup
- A tool that queries DNS servers to resolve names to addresses.
- Non-authoritative answer
- A DNS answer from a server that is not authoritative for the domain, such as a recursive resolver or its cache.
- ICMP filtering
- A firewall policy that blocks some or all ICMP messages, causing ping or traceroute to fail.
- Host-based firewall
- Firewall software running on a computer that controls its inbound and outbound traffic.
- Port test
- Checking whether a TCP connection to a specific port succeeds, for example with Test-NetConnection or nc.
- Rate limiting
- Restricting how many ICMP replies a router sends, which can make some traceroute hops show asterisks.
- Out-of-band management
- Accessing a device through a path independent of the production network, such as a console port.
- Terminal emulator
- Software such as PuTTY or Tera Term that provides a text session over serial, SSH or Telnet.
- SSH
- Secure Shell, encrypted remote command-line access on TCP 22.
- Telnet
- Unencrypted remote command-line access on TCP 23; not safe for management.
- RDP
- Remote Desktop Protocol, graphical remote access to Windows computers, TCP 3389 by default.
- Cloud-managed network
- Network devices configured and monitored through a vendor-hosted web platform over the internet.
- Cisco Meraki dashboard
- Cisco's cloud management portal for Meraki switches, access points, security appliances and other devices.
- Zero-touch provisioning
- Deploying a device that automatically fetches its configuration when connected, with no local setup.
- Configuration template
- A reusable set of settings applied to many sites or devices for consistency.
- User EXEC mode
- The limited initial CLI mode, with a prompt ending in >.
- Privileged EXEC mode
- The full-access CLI mode entered with enable, with a prompt ending in #.
- Global configuration mode
- The mode entered with configure terminal, where changes are made to the running configuration.
- Context-sensitive help
- Using ? to list available commands or the next valid options in the current mode.
- Tab completion
- Pressing Tab to complete a partially typed IOS keyword.
- show running-config
- Displays the active configuration in memory.
- show version
- Displays IOS version, uptime, last reload reason, model, memory and serial number.
- show ip interface brief
- One-line summary of each interface's IP address, status and protocol.
- show cdp neighbors
- Lists directly connected Cisco devices, their platforms and the ports that connect them.
- show inventory
- Lists hardware components, product IDs and serial numbers, including transceivers.
Domain 6: Security (12%)
Exam tips
- Rules are read top-down and the first match wins. Anything not permitted is blocked by the implicit deny at the end.
- Stateful firewalls automatically allow replies to permitted outbound connections; stateless filters need explicit rules for return traffic. Host-based protects one device; network-based protects a whole segment.
- Map the scenario to one property: data seen by the wrong person means confidentiality; data changed means integrity; system unreachable means availability. A DoS attack targets availability.
- Vulnerability = weakness; threat = who or what could cause harm; exploit = how it is done; risk = likelihood times impact. Patching removes vulnerabilities; it does not remove threats.
- Worms spread by themselves; viruses need a host file and user action; Trojans pretend to be legitimate. DoS comes from one source, DDoS from many, and both attack availability.
- MFA needs different factor categories; two passwords or a password plus a PIN is still single-factor. Changing default credentials is one of the first steps when installing any device.
- Personal = one shared passphrase; Enterprise = individual credentials through 802.1X and RADIUS. WPA3-Personal's SAE defeats offline dictionary attacks that threaten WPA2-Personal.
- WPS PIN attacks recover the passphrase itself, so a strong password does not help while WPS is on. WEP is broken no matter how long the key is, and open networks provide no over-the-air encryption.
Key terms
- Firewall
- A device or software that permits or denies traffic according to a security policy.
- ACL
- Access control list: an ordered list of permit and deny statements used to filter traffic.
- Implicit deny
- The unseen rule at the end of a policy that blocks any traffic not explicitly permitted.
- First match
- Rule processing where the first rule that matches a packet determines the action.
- Least privilege
- Allowing only the access necessary and denying everything else.
- Stateless packet filter
- A firewall that evaluates each packet independently against rules, without tracking connections.
- Stateful firewall
- A firewall that tracks connections in a state table and automatically allows matching return traffic.
- State table
- The firewall's record of active connections used to match returning packets.
- Host-based firewall
- Firewall software that protects a single device.
- Network-based firewall
- A firewall at a network boundary that protects all devices behind it.
- Confidentiality
- Ensuring information is accessible only to those authorized, typically protected by encryption and access control.
- Integrity
- Ensuring information is accurate and unaltered, protected by hashing, signatures and change control.
- Availability
- Ensuring systems and data are accessible when needed, protected by redundancy, backups and resilience.
- Hash
- A fixed-length value computed from data; any change in the data produces a different hash.
- Vulnerability
- A weakness in software, configuration, hardware or process that could be used to cause harm.
- Threat
- A potential cause of harm, deliberate or accidental, that could take advantage of a vulnerability.
- Exploit
- The method or code used to take advantage of a specific vulnerability.
- Risk
- The likelihood that a threat exploits a vulnerability combined with the impact if it does.
- Zero-day
- A vulnerability exploited before the vendor has made a fix available.
- Worm
- Malware that spreads across networks by itself without user action.
- Ransomware
- Malware that encrypts data and demands payment for its release.
- Phishing
- Fraudulent messages that trick people into revealing information, clicking malicious links or opening malicious files.
- Social engineering
- Manipulating people into breaking security practices or giving up information.
- DDoS
- Distributed denial of service: overwhelming a target with traffic from many sources, usually a botnet.
- Authentication
- Verifying the identity of a user or device.
- MFA
- Multifactor authentication: requiring factors from two or more different categories, such as know, have and are.
- Passphrase
- A long password made of several words, easier to remember and harder to crack.
- Default credentials
- Factory-set usernames and passwords that are widely known and must be changed.
- AAA
- Authentication, authorization and accounting: verifying identity, granting permissions and logging activity.
- WPA2
- Wi-Fi Protected Access 2, using AES-CCMP encryption; Personal mode is vulnerable to offline passphrase guessing.
- WPA3
- The current Wi-Fi security standard, using SAE in Personal mode and requiring Protected Management Frames.
- SAE
- Simultaneous Authentication of Equals, WPA3-Personal's handshake that resists offline dictionary attacks.
- Personal (PSK) mode
- Wi-Fi security using one shared passphrase for all users.
- Enterprise (802.1X) mode
- Wi-Fi security where each user or device authenticates individually through a RADIUS server.
- WEP
- Wired Equivalent Privacy, the original Wi-Fi encryption, now broken and deprecated.
- Open network
- A Wi-Fi network with no authentication or encryption at the wireless layer.
- WPS
- Wi-Fi Protected Setup, an easy-join feature whose PIN method can be brute-forced to reveal the passphrase.
- Evil twin
- A rogue access point that imitates a legitimate SSID to lure users into connecting.
- Enhanced Open (OWE)
- A Wi-Fi mode that encrypts traffic on open networks without requiring a password.
Study CCST Networking for free
Lessons, quizzes, exam simulations and hands-on labs.
Open the CCST Networking study planLessons, quizzes, exam simulations and hands-on labs.