All certifications / Network+ / Cheat sheet
Network+ N10-009 cheat sheet
Domain 1: Networking concepts (23%)
Exam tips
- Memorize the PDU names in order: bits (1), frames (2), packets (3), segments or datagrams (4), data (5 to 7). Also remember that switches are Layer 2 and routers Layer 3 unless the question says multilayer switch.
- IDS is passive and only alerts; IPS is inline and can block. NAS is file-level access over the LAN; SAN is block-level access, usually over a dedicated network.
- If a question mentions choppy voice or video during busy periods, think QoS. If it mentions reaching global users faster, think CDN. If it mentions routing loops or how traceroute works, think TTL.
- Map the models by who manages the OS: IaaS you do, PaaS and SaaS the provider does. SaaS is a finished application. Internet gateway allows inbound and outbound; NAT gateway allows outbound only.
- Watch for pairs that are easy to swap: SNMP 161 (polling) vs 162 (traps), DHCP 67 (server) vs 68 (client), LDAP 389 vs LDAPS 636, SSH 22 vs Telnet 23, FTP 20/21 vs TFTP UDP 69.
- AH authenticates but does not encrypt; ESP encrypts. GRE tunnels but does not encrypt. IPv6 has no broadcast. TCP is reliable and connection-oriented; UDP is fast and connectionless.
- Long distance equals single-mode; short, cheaper runs equal multimode. Copper Ethernet tops out at 100 m. Cat 6a is the first category rated for 10 Gbps at the full 100 m.
- Hub and spoke: cheap but the hub is a single point of failure and spoke-to-spoke traffic transits the hub. Spine and leaf: data centre, east-west heavy. Collapsed core: small or medium campus combining core and distribution.
- Usable hosts = 2^h - 2. Watch for 172.32.x.x: it is public, because the private block stops at 172.31.255.255. A 169.254 address means DHCP failure.
- SDN separates control plane from data plane. VXLAN = Layer 2 over Layer 3 with a 24-bit ID for millions of segments. SSE is the security portion of SASE, without the SD-WAN networking.
- fe80 = link-local, fc00/fd00 = unique local (private), 2000::/3 = global unicast, ff = multicast, ::1 = loopback. The double colon can appear only once in an address. IPv6 has no broadcast.
Key terms
- PDU
- Protocol data unit: the name for the chunk of data at a given layer (bits, frame, packet, segment or datagram, data).
- Encapsulation
- The process of each layer adding its header (and at Layer 2, a trailer) to the data it receives from the layer above.
- De-encapsulation
- The receiver removing each layer's header in reverse order to recover the original data.
- MAC address
- A 48-bit hardware address used at Layer 2 to deliver frames on the local network segment.
- Frame check sequence
- The Layer 2 trailer field containing a CRC value that the receiver uses to detect corrupted frames.
- TCP/IP model
- The four-layer model the internet actually uses (Link, Internet, Transport, Application), which merges OSI Layers 5 to 7 into one.
- Stateful firewall
- A firewall that tracks the state of connections and automatically allows return traffic that belongs to an established session.
- NGFW
- Next-generation firewall: a firewall that adds application awareness, user identity, TLS inspection and intrusion prevention to stateful filtering.
- IDS
- Intrusion detection system: a passive device that monitors a copy of traffic and alerts on suspicious activity without blocking it.
- IPS
- Intrusion prevention system: an inline device that detects and blocks malicious traffic in real time.
- Reverse proxy
- A proxy that sits in front of servers, receiving client requests on their behalf and hiding the servers' details.
- SAN
- Storage area network: a dedicated network that gives servers block-level access to shared storage, typically via Fibre Channel or iSCSI.
- Wireless LAN controller
- A device or service that centrally configures and manages lightweight access points, including channels, power, security and roaming.
- CDN
- Content delivery network: distributed edge servers that cache content close to users to reduce latency and origin load.
- Site-to-site VPN
- A VPN between two network devices that joins entire networks, such as a branch and headquarters, without client software.
- Split tunnel
- A VPN mode where only traffic for corporate networks uses the tunnel and other traffic goes directly to the internet.
- Jitter
- Variation in the delay of packets arriving, which makes voice and video sound or look choppy.
- DSCP
- Differentiated Services Code Point: a field in the IP header used to mark packets for QoS treatment.
- TTL
- Time to live: an IP header counter decremented at each router hop; the packet is discarded at zero to prevent loops.
- Hop limit
- The IPv6 name for the TTL field, with the same decrement-and-discard behaviour.
- NFV
- Network functions virtualization: running network functions like routing and firewalling as software instead of dedicated hardware.
- VPC
- Virtual private cloud: a logically isolated, customer-defined network inside a public cloud provider.
- Security group
- A stateful virtual firewall applied to cloud instances or interfaces that allows specified inbound and outbound traffic.
- Internet gateway
- A VPC component that allows resources with public addresses to send and receive internet traffic.
- NAT gateway
- A cloud gateway that lets resources in private subnets make outbound internet connections without accepting unsolicited inbound traffic.
- Shared responsibility model
- The division of security duties between cloud provider and customer, which shifts toward the provider from IaaS to PaaS to SaaS.
- Hybrid cloud
- A deployment that combines public and private cloud resources and moves or connects workloads between them.
- Well-known ports
- Port numbers 0 to 1023, assigned to common services such as HTTP (80) and SSH (22).
- Ephemeral port
- A temporary high-numbered source port chosen by a client for an outgoing connection.
- SFTP
- SSH File Transfer Protocol: encrypted file transfer that runs inside an SSH session on TCP 22.
- SNMP trap
- An unsolicited alert sent by a managed device to the SNMP manager on UDP 162.
- LDAPS
- LDAP secured with TLS, on TCP 636.
- SMB
- Server Message Block: the Windows file and printer sharing protocol, running over TCP 445.
- SIP
- Session Initiation Protocol: sets up and tears down VoIP and video calls on 5060, or 5061 with TLS.
- Three-way handshake
- The TCP connection setup exchange of SYN, SYN-ACK and ACK.
- UDP
- User Datagram Protocol: a connectionless, best-effort transport with no handshake, acknowledgements or retransmission.
- ICMP
- Internet Control Message Protocol: carries IP error and diagnostic messages such as Echo, Destination Unreachable and Time Exceeded.
- GRE
- Generic Routing Encapsulation: an unencrypted tunnelling protocol that encapsulates packets, including multicast, inside IP.
- ESP
- Encapsulating Security Payload: the IPsec protocol that provides encryption, integrity and authentication.
- Tunnel mode
- IPsec mode that encrypts the whole original packet and adds a new outer IP header, used for site-to-site VPNs.
- Anycast
- Addressing where one address is shared by several nodes and traffic is routed to the nearest one.
- Plenum cable
- Cable with a fire-resistant, low-smoke jacket required for runs through air-handling spaces.
- Single-mode fibre
- Fibre with a narrow core that carries a single light path via laser, supporting long distances.
- Multimode fibre
- Fibre with a wider core that carries multiple light paths, cheaper but limited to shorter distances.
- SFP+
- A hot-swappable small form-factor pluggable transceiver supporting 10 Gbps links.
- QSFP28
- A quad small form-factor pluggable transceiver using four 25 Gbps lanes for 100 Gbps.
- LC connector
- A small form-factor fibre connector with a push-latch, common on SFP transceivers.
- Auto-MDIX
- A port feature that detects the cable wiring and automatically swaps transmit and receive pairs.
- Star topology
- A layout where every device connects to one central device, usually a switch, which becomes a single point of failure.
- Full mesh
- A topology where every node connects directly to every other node, maximizing redundancy; it needs n(n-1)/2 links.
- Hub and spoke
- A WAN design where branch sites connect to a central site, and branch-to-branch traffic passes through the hub.
- Three-tier architecture
- A campus design with access, distribution and core layers, each with a distinct role.
- Collapsed core
- A two-tier design where the core and distribution layers are combined in the same devices.
- Spine and leaf
- A data centre design where every leaf switch connects to every spine switch, giving consistent hop counts.
- East-west traffic
- Traffic moving laterally between systems inside a data centre.
- Subnet mask
- A 32-bit value (or /prefix) that marks which part of an IPv4 address is the network and which part is the host.
- RFC 1918
- The standard defining private IPv4 ranges 10.0.0.0/8, 172.16.0.0/12 and 192.168.0.0/16.
- APIPA
- Automatic Private IP Addressing: self-assigned 169.254.0.0/16 addresses used when DHCP is unavailable.
- Loopback
- The 127.0.0.0/8 range, with 127.0.0.1 used to test the local TCP/IP stack.
- CIDR
- Classless Inter-Domain Routing: notation and routing that use any prefix length instead of fixed classes.
- VLSM
- Variable-length subnet masking: using different subnet mask lengths within one address space to fit each subnet's size.
- Broadcast address
- The last address in a subnet, used to reach every host on it and never assigned to a host.
- Control plane
- The part of a network device or system that decides how traffic should be forwarded, such as routing protocols.
- Data plane
- The part that actually forwards packets and frames according to the control plane's decisions.
- SD-WAN
- Software-defined WAN: centrally managed branch networking that steers applications across multiple transports by measured path quality.
- VXLAN
- An overlay protocol that encapsulates Layer 2 frames in UDP over a Layer 3 network, using a 24-bit segment ID.
- Zero trust
- A security model that grants no implicit trust based on network location and verifies every request by identity and context.
- SASE
- Secure access service edge: a cloud-delivered combination of SD-WAN networking and security services.
- Configuration drift
- The gradual divergence of devices from their intended, documented configuration.
- Global unicast address
- A public, routable IPv6 address, currently from 2000::/3.
- Unique local address
- An IPv6 address in fc00::/7 (fd00::/8 in practice) used privately inside an organization, like RFC 1918 space.
- Link-local address
- An automatically configured fe80::/10 IPv6 address valid only on the local network segment.
- SLAAC
- Stateless address autoconfiguration: hosts build their own IPv6 address from a router-advertised prefix.
- NDP
- Neighbor Discovery Protocol: ICMPv6-based protocol that replaces ARP and provides router discovery in IPv6.
- Dual stack
- Running IPv4 and IPv6 simultaneously on the same devices and network.
- NAT64
- A translation mechanism that lets IPv6-only hosts communicate with IPv4-only hosts, usually paired with DNS64.
Domain 2: Network implementation (20%)
Exam tips
- Order of selection: longest prefix first, then administrative distance, then metric. Do not compare metrics across different protocols. BGP is the only exterior gateway protocol you need to know.
- PAT = many-to-one using ports. Static NAT = one-to-one, used for servers reachable from outside. HSRP is Cisco-only; VRRP is the open standard. Router on a stick uses subinterfaces with 802.1Q tags.
- Access port = one untagged VLAN; trunk = many VLANs with 802.1Q tags. The native VLAN is the untagged one on a trunk and must match on both ends. Hosts in different VLANs need a Layer 3 device to talk.
- Late collisions on one side plus CRC errors on the other point to a duplex mismatch. Jumbo frames must be supported end to end. LACP is the open standard for link aggregation.
- Lowest bridge ID (priority, then MAC) becomes root. Loops cause broadcast storms and MAC flapping. PortFast is for end-device ports only, paired with BPDU guard.
- Remember 1, 6 and 11 for 2.4 GHz. 2.4 GHz = range and penetration; 5 and 6 GHz = speed and capacity with shorter range. Wider channels mean more speed per AP but fewer channels to reuse.
- 802.11ac is 5 GHz only; 802.11n and 802.11ax work in both 2.4 and 5 GHz; 6E adds 6 GHz. SSID = name, BSSID = one radio's MAC, ESS = many APs with one SSID.
- Personal = PSK, Enterprise = 802.1X with RADIUS. WPA3-Personal uses SAE. If a scenario says users must authenticate individually or be revoked individually, choose Enterprise mode.
- Fan direction must match the rack's airflow: if the ports face the hot aisle, choose port-side exhaust; if the ports face the cold aisle, choose port-side intake. 1U = 1.75 inches. MDF is central, IDFs are per floor.
- 802.3af = 15.4 W, 802.3at (PoE+) = 30 W, 802.3bt = 60 W (Type 3) or 90 W (Type 4). Every port supporting PoE+ does not mean the switch can power them all at full wattage; check the total budget.
Key terms
- Default route
- A route to 0.0.0.0/0 (or ::/0) used when no more specific route matches; the gateway of last resort.
- Floating static route
- A static route with a higher administrative distance that acts as a backup when the primary route is lost.
- Administrative distance
- A value rating the trustworthiness of a route source; the lower value is preferred when prefixes are equal.
- Longest prefix match
- The rule that a router uses the most specific matching route (longest subnet mask) for a destination.
- Link-state protocol
- A routing protocol, like OSPF, in which each router builds a full map of the topology and computes best paths.
- Autonomous system
- A network or group of networks under one administrative control, identified in BGP by an ASN.
- Convergence
- The process and time for all routers to agree on routes after a topology change.
- PAT
- Port address translation: maps many private addresses to one public address by using unique source ports.
- Static NAT
- A fixed one-to-one mapping between a private and a public IP address.
- Port forwarding
- A static rule that sends inbound traffic for a specific public port to a chosen inside host and port.
- Inside global
- The public address that represents an inside host after translation.
- FHRP
- First hop redundancy protocol: lets multiple routers share a virtual gateway IP so hosts keep connectivity if one fails.
- VRRP
- Virtual Router Redundancy Protocol: the open-standard FHRP with master and backup routers.
- Subinterface
- A logical interface on a physical port, commonly tagged with a VLAN for router-on-a-stick routing.
- VLAN
- A logical Layer 2 network and broadcast domain created on switches, independent of physical location.
- Access port
- A switch port assigned to a single VLAN that sends and receives untagged frames.
- Trunk port
- A switch port that carries traffic for multiple VLANs using 802.1Q tags.
- 802.1Q
- The IEEE standard for VLAN tagging that inserts a 4-byte tag with a 12-bit VLAN ID into Ethernet frames on trunks.
- Native VLAN
- The VLAN whose frames are sent untagged across an 802.1Q trunk.
- Voice VLAN
- A separate VLAN for IP phone traffic on an access port that also carries a PC's data VLAN.
- SVI
- Switched virtual interface: a virtual Layer 3 interface for a VLAN on a switch, used for inter-VLAN routing or management.
- Full duplex
- A mode in which a link can transmit and receive at the same time without collisions.
- Autonegotiation
- The process by which two connected ports agree on speed and duplex automatically.
- Duplex mismatch
- A misconfiguration where one side of a link runs full duplex and the other half duplex, causing errors and poor performance.
- MTU
- Maximum transmission unit: the largest payload a frame can carry, 1500 bytes on standard Ethernet.
- Jumbo frame
- An Ethernet frame with an MTU larger than 1500 bytes, commonly around 9000 bytes.
- LACP
- Link Aggregation Control Protocol: the IEEE protocol that negotiates bundling multiple links into one logical link.
- Late collision
- A collision detected after the first 64 bytes of a frame, a classic sign of a duplex mismatch.
- Root bridge
- The switch with the lowest bridge ID, which serves as the reference point for the spanning tree.
- Bridge ID
- A switch's STP identifier: priority value plus MAC address; the lowest wins the root election.
- BPDU
- Bridge protocol data unit: the frames switches exchange to run STP.
- Root port
- The single port on each non-root switch with the lowest path cost to the root bridge.
- Broadcast storm
- Uncontrolled circulation and multiplication of broadcast frames caused by a Layer 2 loop.
- BPDU guard
- A feature that disables a port if it receives a BPDU, protecting edge ports from rogue switches.
- RSTP
- Rapid Spanning Tree Protocol (802.1w), which converges much faster than original STP.
- Non-overlapping channels
- Channels whose frequencies do not overlap; in 2.4 GHz North America these are 1, 6 and 11.
- DFS
- Dynamic frequency selection: a requirement on certain 5 GHz channels for access points to detect radar and vacate the channel.
- Transmit power control
- A regulatory mechanism that limits or adjusts an access point's transmit power on certain channels.
- Channel bonding
- Combining adjacent channels into a wider channel to increase throughput.
- Co-channel interference
- Performance loss when nearby access points share the same channel and must take turns transmitting.
- Adjacent-channel interference
- Signal corruption caused by access points on overlapping, but not identical, channels.
- Country code
- An access point setting that applies the local regulator's rules for channels and power.
- SSID
- Service set identifier: the name of a wireless network.
- BSSID
- The unique identifier, usually the MAC address, of a specific access point radio in a basic service set.
- ESS
- Extended service set: multiple access points sharing one SSID to provide a larger network with roaming.
- MIMO
- Multiple-input multiple-output: using several antennas and spatial streams to increase throughput, introduced in 802.11n.
- OFDMA
- Orthogonal frequency-division multiple access: an 802.11ax feature that lets an AP serve multiple clients simultaneously within one channel.
- Wireless LAN controller
- A device or cloud service that centrally configures and manages lightweight access points.
- Mesh network
- A wireless design where access points relay traffic to each other over the air, so only some need a wired uplink.
- SAE
- Simultaneous Authentication of Equals: the WPA3-Personal handshake that resists offline dictionary attacks.
- PSK
- Pre-shared key: a single passphrase shared by all users of a WPA2/WPA3 Personal network.
- 802.1X
- Port-based network access control that authenticates each user or device through EAP and a RADIUS server before granting access.
- Supplicant
- The client device or software requesting access in 802.1X authentication.
- EAP-TLS
- An 802.1X authentication method using certificates on both client and server; considered the strongest EAP method.
- Captive portal
- A web page that must be completed before a user on a network is granted wider access.
- Yagi antenna
- A directional antenna producing a focused beam, often used for point-to-point links.
- MDF
- Main distribution frame: the central wiring and equipment room connecting to carriers and to each IDF.
- IDF
- Intermediate distribution frame: a secondary wiring closet serving a floor or area, linked to the MDF by backbone cabling.
- Demarc
- The demarcation point where the service provider's network ends and the customer's begins.
- Rack unit (U)
- The standard unit of vertical rack space, 1.75 inches (44.45 mm).
- Hot aisle/cold aisle
- A data centre layout where rack fronts face a cooled aisle and rack backs face an exhaust aisle.
- Port-side exhaust
- A switch airflow option where air enters opposite the ports and leaves through the port side.
- Patch panel
- A panel where permanent cable runs terminate, providing ports that are connected to equipment with patch cords.
- UPS
- Uninterruptible power supply: a battery-backed device that keeps equipment running during power loss and conditions power.
- Online UPS
- A double-conversion UPS that always powers equipment from its inverter, giving clean power and no transfer time.
- PDU
- Power distribution unit: a rack-mounted device that distributes, and may meter or switch, power to equipment.
- PoE+
- IEEE 802.3at, providing up to 30 W per port from the switch.
- PoE budget
- The total wattage a PoE switch can supply across all its ports.
- Electrostatic discharge
- A sudden flow of static electricity that can damage components, made more likely by low humidity.
- Clean agent
- A gaseous fire suppressant that leaves no residue and is safe for electronic equipment.
Domain 3: Network operations (19%)
Exam tips
- Physical diagram = cables, ports and locations; logical diagram = subnets, VLANs and traffic flow. If a question asks which document shows device positions in a rack, it is a rack diagram. SLAs define measurable uptime and response commitments.
- Past end of support means no more security patches, which is the key risk the exam wants you to identify. Before upgrading firmware, back up the config and have a rollback plan; before disposal, sanitize.
- Every change needs an approved request, a maintenance window and a rollback plan. Configuration baseline = how it should be configured; performance baseline = how it normally behaves. Save the running config or lose changes on reboot.
- SNMPv3 is the only version with encryption and user authentication. Polls use UDP 161, traps UDP 162. Flow data answers who talked to whom and how much; packet capture shows the full contents. Syslog severity 0 is the most severe.
- Match the need to the solution: 'what is on my network' is discovery; 'what is using my bandwidth' is traffic analysis; 'is it slow' is performance monitoring; 'is it up' is availability monitoring; 'did someone change it' is configuration monitoring.
- RPO = data loss tolerance (how often to back up); RTO = downtime tolerance (how fast to recover). Hot = fastest and costliest, cold = slowest and cheapest. High MTBF and low MTTR are good.
- Exclusion = never hand out this address; reservation = always give this address to this MAC. If clients on only one remote subnet get APIPA addresses, suspect the relay (IP helper).
- A = IPv4, AAAA = IPv6, PTR = reverse, MX = mail, NS = name servers, SOA = zone authority and serial, TXT = SPF/DKIM/verification, CNAME = alias. DNSSEC gives integrity, not encryption; DoH and DoT give encryption.
- NTP = UDP 123, millisecond-level accuracy, stratum hierarchy. PTP = microsecond or better, needs hardware support. NTS = secure (authenticated) NTP. Clock skew breaks Kerberos and log correlation.
- If the question says the network is down but you still need to manage the device, the answer is out-of-band management (console server, separate network, cellular). Replace Telnet with SSH and HTTP with HTTPS. A jump box centralizes and audits admin access.
Key terms
- Physical diagram
- A diagram showing actual devices, their locations and how they are cabled together.
- Logical diagram
- A diagram showing how data flows: subnets, VLANs, addressing and routing, independent of physical layout.
- Rack diagram
- An elevation drawing showing each device's position in a rack by rack unit.
- Cable map
- A record of each cable run with its label, endpoints, type and length.
- IPAM
- IP address management: tools and processes for planning, tracking and managing IP address space, DHCP and DNS.
- SLA
- Service-level agreement: a documented commitment to measurable service levels such as uptime and response time.
- Heat map
- A colour-coded wireless survey output showing signal strength across a floor plan.
- End of life (EOL)
- The vendor's announcement that a product is being retired from sale and, eventually, from support.
- End of support
- The date after which the vendor no longer provides patches, updates or technical support for a product.
- Firmware
- Low-level software embedded in hardware that controls the device's functions and can be updated.
- Release notes
- Vendor documentation describing the fixes, new features, known issues and upgrade requirements of a software version.
- Hash verification
- Comparing a downloaded file's cryptographic hash with the vendor's published value to confirm it is intact and untampered.
- Sanitization
- Securely removing data from a device, by wiping or destruction, so it cannot be recovered.
- Certificate of destruction
- A record from a disposal vendor confirming that equipment or media was securely destroyed.
- Change request
- A formal proposal describing a change, its reason, risk, implementation steps, test plan and rollback plan.
- Change advisory board
- A group that reviews, assesses and approves proposed changes.
- Maintenance window
- A pre-agreed, low-impact time period in which approved changes are carried out.
- Rollback plan
- The documented steps to return a system to its previous state if a change fails.
- Golden configuration
- An approved standard configuration template used to build and audit devices of a given role.
- Baseline
- A documented reference of normal configuration or performance used for comparison.
- Running configuration
- The active configuration in a device's memory, which must be saved to persist across reboots.
- MIB
- Management Information Base: the structured set of variables an SNMP agent exposes, each identified by an OID.
- OID
- Object identifier: the unique numeric address of a single variable in a MIB.
- SNMP trap
- An unsolicited message from an SNMP agent to the manager, sent on UDP 162, reporting an event.
- SNMPv3
- The SNMP version that adds user-based authentication and encryption.
- NetFlow
- A flow-export technology that summarizes traffic conversations for analysis without capturing payloads.
- Syslog severity
- A level from 0 (Emergency) to 7 (Debug) indicating how serious a log message is.
- SIEM
- Security information and event management: a system that aggregates and correlates logs to detect security events.
- Network discovery
- Automatically finding and cataloguing devices on a network, often producing a topology map.
- LLDP
- Link Layer Discovery Protocol: a vendor-neutral protocol devices use to advertise their identity and capabilities to directly connected neighbours.
- Top talkers
- The hosts or applications generating the most traffic, typically identified through flow analysis.
- Performance monitoring
- Tracking metrics such as utilisation, latency, jitter, loss and errors against baselines and thresholds.
- Availability monitoring
- Regularly checking whether devices and services respond, and alerting when they do not.
- Synthetic monitoring
- Generating test traffic or transactions to measure performance and availability proactively.
- Alert fatigue
- Desensitization caused by too many or low-value alerts, leading staff to miss important ones.
- RPO
- Recovery point objective: the maximum tolerable data loss, measured as time before the incident.
- RTO
- Recovery time objective: the maximum tolerable time to restore a service after an incident.
- MTBF
- Mean time between failures: the average operating time between failures of a repairable system.
- MTTR
- Mean time to repair: the average time needed to repair a failure and restore service.
- Hot site
- A fully equipped, up-to-date recovery site that can take over operations almost immediately.
- Cold site
- A recovery location with space, power and cooling but no ready equipment or data.
- Tabletop exercise
- A discussion-based DR test in which staff talk through their response to a scenario.
- DORA
- Discover, Offer, Request, Acknowledge: the four-message DHCP lease process.
- Scope
- The pool of addresses and settings a DHCP server hands out for one subnet.
- Exclusion
- An address or range within a scope that the DHCP server will not assign.
- Reservation
- A DHCP entry that always assigns a specific IP address to a specific MAC address.
- Lease time
- How long a client may use an assigned address before it must renew it.
- DHCP relay
- A router or switch function (IP helper) that forwards DHCP broadcasts to a server on another subnet.
- SLAAC
- Stateless address autoconfiguration: IPv6 hosts build their own addresses from a router-advertised prefix.
- A and AAAA records
- DNS records mapping a name to an IPv4 (A) or IPv6 (AAAA) address.
- CNAME
- A DNS record that makes one name an alias for another name.
- MX record
- A DNS record listing a domain's mail servers with preference values, lowest tried first.
- PTR record
- A DNS record used for reverse lookups, mapping an IP address to a hostname.
- SOA record
- Start of authority: the record at the top of a zone holding the primary server, contact, serial number and refresh timers.
- Recursive resolver
- A DNS server that performs the full lookup on a client's behalf and caches the results.
- DNSSEC
- Extensions that digitally sign DNS records so resolvers can verify their authenticity and integrity.
- NTP
- Network Time Protocol: synchronizes clocks across a network using UDP 123 and a stratum hierarchy.
- Stratum
- The level of an NTP server in the hierarchy; stratum 1 is directly connected to a reference clock.
- Reference clock
- A stratum 0 time source such as a GPS receiver or atomic clock.
- Clock skew
- The difference between the clocks of two systems, which can break authentication and log correlation.
- PTP
- Precision Time Protocol (IEEE 1588): hardware-assisted time synchronization with sub-microsecond accuracy.
- Grandmaster clock
- The authoritative time source in a PTP network that other clocks follow.
- NTS
- Network Time Security: a mechanism that authenticates NTP time using TLS-established keys.
- Site-to-site VPN
- A VPN that persistently connects two networks through their gateways.
- Clientless VPN
- Remote access through a web browser over TLS without a dedicated VPN client.
- SSH
- Secure Shell: encrypted remote command-line access on TCP 22, replacing Telnet.
- API
- Application programming interface: a programmatic way, often REST over HTTPS, for tools to configure and query devices.
- Console port
- A local serial management port that provides CLI access without needing network connectivity.
- Jump box
- A hardened intermediary host that administrators must use to access management interfaces of other systems.
- Out-of-band management
- Managing devices through a separate path independent of the production network, such as a console server.
Domain 4: Network security (14%)
Exam tips
- RADIUS: UDP, network access, encrypts only the password. TACACS+: TCP 49, device administration, encrypts everything, separates the three As. A password plus a security question is not MFA; both are something you know.
- Map attacks to the triad: DoS hits availability, eavesdropping hits confidentiality, tampering hits integrity. 'Grant only what is needed' is least privilege; 'manage by job function' is RBAC; 'multiple layers' is defense in depth; 'never trust, always verify' is zero trust.
- Vulnerability = weakness, threat = potential danger, exploit = the method used, risk = likelihood times impact. PCI DSS is about card data; GDPR is about personal data of people in the EU. Any traffic to a honeypot is suspicious by definition.
- OT and ICS prioritize availability and safety; they need the strongest isolation, even air gaps. Guest and BYOD traffic should go to separate VLANs with internet-only or limited access enforced by ACLs and NAC.
- Pair each attack with its defence: MAC flooding with port security; ARP poisoning with dynamic ARP inspection; rogue DHCP with DHCP snooping; VLAN hopping with disabling trunk negotiation and changing the native VLAN; evil twin with 802.1X and WIPS.
- Distinguish by delivery: phishing = email, vishing = voice, smishing = SMS, whaling = executives. Distinguish malware by behaviour: a worm self-propagates, a virus needs a host file and user action, a Trojan disguises itself.
- The most common hardening answers: change default credentials, disable unused ports and services, and replace insecure protocols with secure ones (Telnet to SSH, HTTP to HTTPS, SNMPv1/v2c to SNMPv3, FTP/TFTP to SFTP/SCP).
- Attack to defence: MAC flooding -> port security; rogue DHCP -> DHCP snooping; ARP poisoning -> dynamic ARP inspection (which depends on DHCP snooping); rogue switch or loop on an edge port -> BPDU guard.
- In 802.1X: supplicant = client, authenticator = switch or AP, authentication server = RADIUS. MAC filtering is easily bypassed by spoofing and is not real authentication.
- ACLs are processed top-down, first match wins, and every list ends with an implicit deny. A list containing only deny statements blocks everything. Public servers go in the screened subnet (DMZ), not the internal network.
Key terms
- Data at rest
- Data stored on disks, databases, backups or media, protected by encryption such as full-disk encryption.
- Certificate authority
- A trusted entity that issues and signs digital certificates binding public keys to identities.
- AAA
- Authentication, authorization and accounting: verifying identity, granting permissions and logging activity.
- MFA
- Multifactor authentication: requiring two or more different types of factor, such as a password and a phone app.
- RADIUS
- An open AAA protocol for network access using UDP 1812 and 1813 that encrypts only the password.
- TACACS+
- A AAA protocol on TCP 49 that encrypts the full payload and separates authentication, authorization and accounting.
- SAML
- An XML-based standard that lets an identity provider send authentication assertions to service providers for SSO.
- CIA triad
- Confidentiality, integrity and availability: the three core goals of information security.
- Least privilege
- Granting only the minimum access rights needed to perform a task, for only as long as needed.
- Separation of duties
- Dividing sensitive tasks so no single person can complete them alone.
- RBAC
- Role-based access control: assigning permissions to roles and users to roles.
- Defense in depth
- Layering multiple independent security controls so one failure does not expose the system.
- Zero trust
- A model that grants no implicit trust based on network location and verifies every request by identity and context.
- Lateral movement
- An attacker moving from one compromised system to others inside a network.
- Access control vestibule
- A two-door entry space where only one door opens at a time, preventing tailgating.
- Honeypot
- A decoy system with no legitimate use, designed to attract and detect attackers.
- Honeynet
- A network of honeypots that simulates a realistic environment to observe attackers.
- Vulnerability
- A weakness in a system that could be exploited by a threat.
- Risk
- The combination of the likelihood that a threat exploits a vulnerability and the impact if it does.
- PCI DSS
- Payment Card Industry Data Security Standard: security requirements for organizations handling payment card data.
- GDPR
- The EU regulation governing the protection and processing of personal data of people in the EU.
- IoT
- Internet of Things: everyday devices, such as cameras and sensors, connected to networks.
- OT
- Operational technology: systems that control physical processes, prioritizing safety and availability.
- SCADA
- Supervisory control and data acquisition: systems that monitor and control distributed industrial processes.
- PLC
- Programmable logic controller: an industrial computer that directly controls machinery in an ICS.
- Air gap
- Complete physical isolation of a system or network from other networks.
- Client isolation
- A wireless setting that stops devices on the same SSID from communicating directly with each other.
- BYOD
- Bring your own device: a policy allowing personal devices to access organizational resources.
- DDoS
- Distributed denial of service: an attack from many sources that overwhelms a target's resources.
- Amplification attack
- A reflection attack in which small spoofed requests make third-party servers send much larger responses to the victim.
- Double tagging
- A VLAN hopping technique using two 802.1Q tags to reach a VLAN through the native VLAN.
- MAC flooding
- Filling a switch's MAC address table with fake entries so it floods traffic out all ports.
- ARP poisoning
- Sending forged ARP messages to link an attacker's MAC with another host's IP, redirecting traffic.
- Evil twin
- A malicious access point that impersonates a legitimate wireless network.
- On-path attack
- An attack where the adversary intercepts, and possibly alters, communication between two parties.
- Phishing
- Fraudulent messages impersonating a trusted party to steal credentials or deliver malware.
- Spear phishing
- A targeted phishing attack tailored to a specific person or group.
- Tailgating
- Following an authorized person into a secure area without their knowledge or without badging in.
- Worm
- Self-replicating malware that spreads across networks without user action.
- Trojan horse
- Malware disguised as legitimate software that hides a malicious function.
- Ransomware
- Malware that encrypts or steals data and demands payment for its release.
- Rootkit
- Malware that hides itself deep in the operating system to maintain concealed access.
- Hardening
- Reducing a system's attack surface by removing unnecessary functions and securing configurations.
- Attack surface
- The total set of points where an attacker could try to enter or extract data from a system.
- Default credentials
- Factory-set usernames and passwords that are publicly known and must be changed at installation.
- Parking lot VLAN
- An unused, isolated VLAN assigned to disabled ports so they give no network access if enabled.
- SNMPv3 authPriv
- The SNMPv3 security level that provides both authentication and encryption.
- Management ACL
- An access list restricting which source addresses may reach a device's management interfaces.
- Login banner
- A legal warning shown before login stating that access is restricted and monitored.
- Port security
- A switch feature that limits and controls the MAC addresses allowed on a port.
- Sticky MAC
- A port security option where the switch learns and saves allowed MAC addresses dynamically.
- Violation mode
- The action port security takes on a violation: protect, restrict or shutdown.
- DHCP snooping
- A switch feature that permits DHCP server messages only on trusted ports and builds a binding table.
- Dynamic ARP inspection
- A switch feature that validates ARP packets against trusted bindings to prevent ARP poisoning.
- BPDU guard
- A feature that err-disables an edge port if it receives a BPDU.
- Err-disabled
- A port state where the switch has shut the port down due to a detected error or violation.
- NAC
- Network access control: technology that checks identity and policy before granting a device network access.
- Supplicant
- The client software that requests network access and provides credentials in 802.1X.
- Authenticator
- The switch or access point that enforces 802.1X by relaying authentication and controlling port access.
- EAP
- Extensible Authentication Protocol: the framework carrying 802.1X authentication methods such as EAP-TLS and PEAP.
- Posture assessment
- Checking a device's security state, such as patches and antivirus, before granting network access.
- MAB
- MAC authentication bypass: using a device's MAC address as its identity for devices that cannot do 802.1X.
- Key rotation
- Replacing cryptographic keys periodically or after potential exposure to limit risk.
- ACL
- Access control list: an ordered set of permit and deny rules used to filter traffic.
- Extended ACL
- An ACL that matches on source, destination, protocol and ports, usually placed close to the source.
- Implicit deny
- The invisible final rule in an ACL or firewall policy that drops any traffic not explicitly permitted.
- Wildcard mask
- The inverse of a subnet mask used in Cisco ACLs, where 0 bits must match and 1 bits are ignored.
- URL filtering
- Allowing or blocking web access based on the site address or its category.
- Security zone
- A group of interfaces or networks with a common trust level, used to define firewall policy.
- Screened subnet
- A network zone, formerly called a DMZ, that hosts internet-facing services separated from the internal network.
Domain 5: Network troubleshooting (24%)
Exam tips
- Learn the order: identify, theorize, test, plan, implement, verify, document. When asked 'what next?', find the step just completed and pick the following one. Documentation is always the final step.
- Distance beyond spec = attenuation. Noise from motors or lights = EMI (fix with rerouting, shielding or fibre). Too much untwisting at the connector = crosstalk. Fibre link dead but everything else correct = try swapping TX/RX.
- Rising CRCs: suspect cabling, EMI or optics first. Giants: MTU/jumbo mismatch. Runts plus late collisions: duplex mismatch. Output drops: congestion. 'Administratively down' is fixed with no shutdown.
- Some PoE devices dead or rebooting = budget exceeded. One device boots with reduced features = wrong PoE class or standard. Fibre link errors with correct cabling = check both optics' speed, wavelength and fibre type, and read their optical power levels.
- Network-wide slowdown with high CPU and MAC flapping = switching loop. One host with the wrong subnet or APIPA = wrong access VLAN. A whole VLAN failing at one remote switch = VLAN missing on the trunk. Selective failures right after a change = check ACL order and direction.
- Local works but remote fails: check gateway, then routes. Some remote subnets fail: check mask and routing tables. APIPA on new clients while old ones work: DHCP pool exhaustion. Repeating hops in traceroute: routing loop.
- Works by IP but not by name = DNS. New clients get APIPA while old ones work = scope exhaustion. Intermittent connectivity and conflict warnings = duplicate IP. Domain logins or certificates failing on one machine = check its time (NTP).
- Choppy or robotic voice points to jitter and packet loss; slow file transfers point to bandwidth, congestion or a bottleneck; delay on every interaction points to latency. QoS helps prioritize but does not create bandwidth.
- Many APs on overlapping 2.4 GHz channels = adjacent channel interference; same channel = co-channel interference. Drops in one area = coverage gap. Drops while walking = roaming configuration (SSID, security and VLAN must match). Non-Wi-Fi noise needs a spectrum analyzer.
- Where does the path break? traceroute. Is the service listening? netstat. What is plugged into this port? LLDP/CDP. What ports are open on hosts? nmap. Name resolution? nslookup or dig. Throughput between two points you control? iperf.
- Which cable is it? Toner and probe. Is it wired right? Cable tester. Does it meet Cat 6 performance? Certifier. How far to the break? TDR (copper) or OTDR (fibre). Is the port itself good? Loopback plug. Where is a fibre patch cord broken? VFL.
- Where is this MAC plugged in? show mac-address-table. What IP belongs to which MAC? show arp. Why can't we reach that network? show route. Errors or duplex? show interface. Wrong VLAN? show vlan. PoE device dead? show power. Unsaved changes? compare running and startup config.
Key terms
- Scope
- How widespread a problem is, such as one user, one area or the whole organization, which helps locate the cause.
- Theory of probable cause
- A hypothesis about what is causing the problem, formed from the gathered information.
- Divide and conquer
- A troubleshooting approach that starts in the middle of the OSI model or path and narrows toward the failing half.
- Bottom-to-top approach
- Troubleshooting that starts at the Physical layer and works upward through the OSI model.
- Escalation
- Passing a problem to someone with more expertise, authority or access when you cannot resolve it.
- Preventive measures
- Actions taken after a fix to stop the problem recurring, such as monitoring or configuration changes.
- Lessons learned
- The documented insights from an incident that improve future troubleshooting and prevention.
- Attenuation
- The loss of signal strength as it travels over distance through a medium.
- EMI
- Electromagnetic interference: noise induced in cabling from external electrical or radio sources.
- Crosstalk
- Unwanted signal coupling between adjacent wire pairs or cables.
- NEXT
- Near-end crosstalk: crosstalk measured at the same end as the transmitter, often caused by excessive untwisting at terminations.
- Split pair
- A wiring fault where wires from two different pairs are used together, breaking the twist and causing crosstalk.
- TX/RX reversal
- A fault where the transmit and receive paths are not correctly crossed, often on fibre, preventing a link.
- OTDR
- Optical time-domain reflectometer: a tool that locates breaks, bends and bad splices along a fibre by distance.
- CRC error
- A frame whose checksum does not match its contents, indicating corruption in transit.
- Runt
- An Ethernet frame smaller than the 64-byte minimum.
- Giant
- An Ethernet frame larger than the maximum allowed size, often from MTU mismatches.
- Output drops
- Frames discarded because the interface's output queue was full, indicating congestion.
- Late collision
- A collision detected after the first 64 bytes of a frame, typical of duplex mismatch or excessive cable length.
- Administratively down
- An interface state meaning it has been disabled by configuration.
- Err-disabled
- A state in which the switch has automatically shut a port because of an error or security violation.
- Power budget
- The total PoE wattage a switch can deliver across its ports.
- PoE class
- A negotiated category indicating how much power a powered device needs from the switch.
- Passive PoE
- Non-standard PoE that supplies power without negotiation and may be incompatible with standard devices.
- Transceiver mismatch
- Incompatible optical or copper modules at each end of a link, such as differing speed, wavelength or fibre type.
- Digital optical monitoring
- Transceiver diagnostics showing temperature, voltage and transmit and receive optical power.
- dBm
- Decibels relative to one milliwatt; a logarithmic unit for signal power, where values closer to zero are stronger.
- Signal-to-noise ratio
- The difference between signal strength and background noise; higher values mean cleaner signals.
- Switching loop
- A Layer 2 path loop that causes frames to circulate endlessly, producing broadcast storms.
- MAC flapping
- A MAC address appearing alternately on different switch ports, a common sign of a loop.
- Storm control
- A switch feature that limits broadcast, multicast or unknown unicast traffic on a port to a set rate.
- Allowed VLAN list
- The set of VLANs permitted to cross a trunk link.
- Native VLAN mismatch
- A configuration where the two ends of a trunk use different untagged VLANs, causing traffic leakage.
- Trunk mode mismatch
- One end of a link configured as a trunk and the other as an access port, breaking multi-VLAN traffic.
- ACL hit counter
- A per-rule count of matching packets that shows which ACL entries are actually being used.
- Default gateway
- The router address a host sends traffic to when the destination is not on its local subnet.
- Default route
- A route to 0.0.0.0/0 used when no more specific route matches, often pointing to the ISP.
- Routing table
- The list of known destination networks and next hops a router or host uses to forward packets.
- Routing loop
- A condition where packets circulate between routers until their TTL expires.
- Asymmetric routing
- Traffic taking a different path in each direction, which can break stateful firewalls.
- Pool exhaustion
- Running out of assignable addresses in a DHCP scope or NAT pool.
- Black hole
- A route or path where traffic is silently discarded.
- Scope exhaustion
- A DHCP condition where all addresses in a scope are leased and new clients cannot obtain one.
- DHCP starvation
- An attack that requests many leases using spoofed MAC addresses to exhaust a DHCP scope.
- IP address conflict
- Two devices configured with the same IP address, causing intermittent connectivity for both.
- Conflict detection
- A DHCP server feature that checks whether an address is in use before offering it.
- DNS cache
- Stored DNS answers on clients and resolvers, kept for each record's TTL.
- Clock skew
- The difference between clocks on two systems, which can break authentication and certificate validation.
- Clock drift
- The gradual divergence of a device's clock from true time when it is not synchronized.
- Bandwidth
- The maximum data rate a link can carry.
- Throughput
- The actual data rate achieved across a link or path, as opposed to its theoretical bandwidth.
- Congestion
- A condition where offered traffic exceeds capacity, causing queuing delay and drops.
- Bottleneck
- The lowest-capacity point in a path that limits overall performance.
- Latency
- The delay for data to travel from source to destination, often measured as round-trip time.
- Jitter
- Variation in packet delay, which degrades real-time voice and video.
- Oversubscription
- Aggregating more potential traffic onto a link than it can carry at once.
- Noise floor
- The level of background RF energy; a higher noise floor reduces signal-to-noise ratio.
- Adjacent-channel interference
- Corruption caused by nearby access points on overlapping, but not identical, channels.
- Co-channel interference
- Capacity loss when nearby access points use the same channel and must share airtime.
- Dead zone
- An area with insufficient wireless signal for reliable connectivity.
- Sticky client
- A wireless client that stays associated to a distant AP instead of roaming to a closer one.
- Deauthentication attack
- Sending forged management frames to force clients off a wireless network.
- Protocol analyzer
- Software that captures and decodes network traffic for detailed inspection, such as Wireshark.
- tcpdump
- A command-line packet capture tool for Linux and Unix that can save captures for later analysis.
- traceroute
- A tool that reveals each router hop to a destination by sending packets with increasing TTL values.
- netstat
- A command that displays network connections, listening ports and routing information on a host.
- nmap
- A network scanner that discovers hosts, open ports, services and operating systems.
- LLDP
- Link Layer Discovery Protocol: a vendor-neutral protocol devices use to advertise identity and capabilities to neighbours.
- iperf
- A tool that measures maximum throughput between a client and a server you control.
- Toner and probe
- A tool pair used to trace and identify a specific cable among many.
- Cable tester
- A tool that checks wiring continuity and detects opens, shorts, miswires and reversed pairs.
- Cable certifier
- A tester that verifies a cabling run meets a specific category's performance standards and produces a report.
- TDR
- Time-domain reflectometer: measures reflections in copper cable to find the distance to a fault.
- Loopback plug
- A connector that routes a port's transmit signal back to its receive pins to test the port.
- Visual fault locator
- A device that injects visible red light into fibre to reveal breaks, sharp bends and continuity.
- MAC address table
- The switch table mapping learned MAC addresses to ports and VLANs.
- Interface counters
- Per-interface statistics such as CRC errors, runts, giants and drops used to diagnose problems.
- Running configuration
- The active configuration currently in use in a device's memory.
- Startup configuration
- The saved configuration loaded when a device boots.
- ARP table
- A table mapping IP addresses to MAC addresses for devices on directly connected networks.
- PoE status
- The show power output listing the PoE budget, usage and per-port power allocation.
Study Network+ for free
Lessons, quizzes, exam simulations and hands-on labs.
Open the Network+ study planLessons, quizzes, exam simulations and hands-on labs.