All certifications / CCST Networking / Lessons
CCST Networking 100-150 v1.0 lessons
Study CCST Networking for free
A week-by-week plan with every lesson, quizzes, checkpoint tests, a practice exam and hands-on labs.
Open the CCST Networking study planA week-by-week plan with every lesson, quizzes, checkpoint tests, a practice exam and hands-on labs.
Domain 1: Standards and concepts
- The TCP/IP and OSI models: layer names, what each layer does and where devices and protocols fit
- Encapsulation: data, segments, packets, frames and bits; MAC addresses vs IP addresses
- Bandwidth vs throughput; latency, delay and jitter; speed tests vs iperf
- Network types: LAN, WAN, MAN, CAN, PAN and WLAN
- Cloud vs on-premises: public, private and hybrid cloud; SaaS, PaaS and IaaS
- How cloud and hybrid work change where apps run and how users reach them (VPN, internet access)
- TCP vs UDP: connection-oriented vs connectionless, the three-way handshake, when each is used
- Common protocols and ports: FTP 20/21, SFTP/SSH 22, TFTP 69, HTTP 80, HTTPS 443, DNS 53, DHCP 67/68, NTP 123
- ICMP and what ping uses it for
Domain 2: Addressing and subnet formats
- Private IPv4 ranges (10.0.0.0/8, 172.16.0.0/12, 192.168.0.0/16) vs public addresses
- NAT and PAT: how a home router shares one public address
- Special IPv4 addresses: loopback 127.0.0.1, APIPA 169.254.x.x, broadcast
- IPv4 format: dotted decimal, subnet masks and slash (CIDR) notation
- Network address, broadcast address, usable host range and host count for common masks
- Using a subnet calculator and checking whether two hosts are on the same subnet
- IPv6 format: eight hextets, leading-zero and :: compression, prefix length (usually /64)
- IPv6 address types: global unicast (2000::/3), link-local (fe80::/10), unique local (fc00::/7), multicast (ff00::/8), loopback ::1
- IPv6 address assignment: SLAAC, modified EUI-64, DHCPv6, and dual stack
Domain 3: Endpoints and media types
- Copper cable categories: Cat 5e, Cat 6, Cat 6a; straight-through vs crossover; 100 m Ethernet limit
- Coaxial cable, and single-mode vs multimode fiber (distance, light source, core size)
- Connectors: RJ-45, RJ-11, BNC, F-type, LC, SC and ST; SFP transceivers
- Sources of interference on copper and wireless: EMI, crosstalk, microwaves, walls and distance
- Wi-Fi bands 2.4, 5 and 6 GHz and their trade-offs; 802.11 generations
- Cellular 4G/5G as licensed spectrum vs unlicensed Wi-Fi; hotspots and tethering
- What a client needs to join Wi-Fi: SSID, security type and password or credentials
- Endpoint types: desktops, laptops, phones, tablets, servers, printers and IoT devices
- Checking connectivity on Windows, Linux, macOS, Android and iOS: settings screens and command-line tools
Domain 4: Infrastructure
- Cisco device LEDs: system and port lights, green vs amber, solid vs blinking, and what they tell an engineer on the phone
- Reading a network diagram to patch the right cable into the right port
- Device ports: RJ-45 Ethernet, SFP/fiber, console (RJ-45 and USB), management, serial, USB and PoE ports
- Power over Ethernet: powering phones, APs and cameras from the switch
- Default gateway: why a host needs one and what happens without it
- Local vs remote networks and how a router decides where to send a packet
- Layer 2 vs Layer 3 switches, and routers vs switches
- MAC address tables: how a switch learns, forwards, floods and filters
- VLANs: separating broadcast domains on one switch; access vs trunk ports
- Cable management and labeling in racks and patch panels
Domain 5: Diagnosing problems
- Troubleshooting methodology: identify the problem, theory, test, plan, fix, verify, document
- Help desk practice: tickets, gathering information, priorities, escalation and clear documentation
- Wireshark: capturing on the right interface, simple display filters and saving a .pcapng file
- Ping, tracert/traceroute, ipconfig/ifconfig/ip and nslookup: running them and reading the results
- How firewalls can make ping or traceroute fail even when the service works
- Remote access and data collection: console cable and terminal emulator, SSH vs Telnet, RDP, VPN
- Cloud-managed devices (for example Cisco Meraki dashboard)
- Cisco IOS basics: user vs privileged EXEC, `?` help and tab completion
- Show commands: show running-config, show version, show ip interface brief, show interfaces, show interfaces status, show ip route, show mac address-table, show cdp neighbors, show inventory
Domain 6: Security
- How firewalls filter traffic: permit and deny rules, ports and protocols, implicit deny
- Stateful firewalls vs simple packet filters; host-based vs network firewalls
- CIA triad: confidentiality, integrity, availability
- Vulnerability, threat, exploit and risk
- Malware types, phishing and other social engineering, DoS and DDoS
- Authentication basics: strong passwords, MFA, changing default credentials
- Home router wireless security: WPA2 vs WPA3, Personal (pre-shared key) vs Enterprise (802.1X)
- Why WEP and open networks should not be used, and why WPS should be turned off