StudyToCert

All certifications / Network+ / Cheat sheet

Network+ N10-009 cheat sheet

Every exam tip and key term from the free Network+ lessons, by domain. Use your browser's Print to save it as a PDF.

Domain 1: Networking concepts (23%)

Exam tips

Key terms

PDU
Protocol data unit: the name for the chunk of data at a given layer (bits, frame, packet, segment or datagram, data).
Encapsulation
The process of each layer adding its header (and at Layer 2, a trailer) to the data it receives from the layer above.
De-encapsulation
The receiver removing each layer's header in reverse order to recover the original data.
MAC address
A 48-bit hardware address used at Layer 2 to deliver frames on the local network segment.
Frame check sequence
The Layer 2 trailer field containing a CRC value that the receiver uses to detect corrupted frames.
TCP/IP model
The four-layer model the internet actually uses (Link, Internet, Transport, Application), which merges OSI Layers 5 to 7 into one.
Stateful firewall
A firewall that tracks the state of connections and automatically allows return traffic that belongs to an established session.
NGFW
Next-generation firewall: a firewall that adds application awareness, user identity, TLS inspection and intrusion prevention to stateful filtering.
IDS
Intrusion detection system: a passive device that monitors a copy of traffic and alerts on suspicious activity without blocking it.
IPS
Intrusion prevention system: an inline device that detects and blocks malicious traffic in real time.
Reverse proxy
A proxy that sits in front of servers, receiving client requests on their behalf and hiding the servers' details.
SAN
Storage area network: a dedicated network that gives servers block-level access to shared storage, typically via Fibre Channel or iSCSI.
Wireless LAN controller
A device or service that centrally configures and manages lightweight access points, including channels, power, security and roaming.
CDN
Content delivery network: distributed edge servers that cache content close to users to reduce latency and origin load.
Site-to-site VPN
A VPN between two network devices that joins entire networks, such as a branch and headquarters, without client software.
Split tunnel
A VPN mode where only traffic for corporate networks uses the tunnel and other traffic goes directly to the internet.
Jitter
Variation in the delay of packets arriving, which makes voice and video sound or look choppy.
DSCP
Differentiated Services Code Point: a field in the IP header used to mark packets for QoS treatment.
TTL
Time to live: an IP header counter decremented at each router hop; the packet is discarded at zero to prevent loops.
Hop limit
The IPv6 name for the TTL field, with the same decrement-and-discard behaviour.
NFV
Network functions virtualization: running network functions like routing and firewalling as software instead of dedicated hardware.
VPC
Virtual private cloud: a logically isolated, customer-defined network inside a public cloud provider.
Security group
A stateful virtual firewall applied to cloud instances or interfaces that allows specified inbound and outbound traffic.
Internet gateway
A VPC component that allows resources with public addresses to send and receive internet traffic.
NAT gateway
A cloud gateway that lets resources in private subnets make outbound internet connections without accepting unsolicited inbound traffic.
Shared responsibility model
The division of security duties between cloud provider and customer, which shifts toward the provider from IaaS to PaaS to SaaS.
Hybrid cloud
A deployment that combines public and private cloud resources and moves or connects workloads between them.
Well-known ports
Port numbers 0 to 1023, assigned to common services such as HTTP (80) and SSH (22).
Ephemeral port
A temporary high-numbered source port chosen by a client for an outgoing connection.
SFTP
SSH File Transfer Protocol: encrypted file transfer that runs inside an SSH session on TCP 22.
SNMP trap
An unsolicited alert sent by a managed device to the SNMP manager on UDP 162.
LDAPS
LDAP secured with TLS, on TCP 636.
SMB
Server Message Block: the Windows file and printer sharing protocol, running over TCP 445.
SIP
Session Initiation Protocol: sets up and tears down VoIP and video calls on 5060, or 5061 with TLS.
Three-way handshake
The TCP connection setup exchange of SYN, SYN-ACK and ACK.
UDP
User Datagram Protocol: a connectionless, best-effort transport with no handshake, acknowledgements or retransmission.
ICMP
Internet Control Message Protocol: carries IP error and diagnostic messages such as Echo, Destination Unreachable and Time Exceeded.
GRE
Generic Routing Encapsulation: an unencrypted tunnelling protocol that encapsulates packets, including multicast, inside IP.
ESP
Encapsulating Security Payload: the IPsec protocol that provides encryption, integrity and authentication.
Tunnel mode
IPsec mode that encrypts the whole original packet and adds a new outer IP header, used for site-to-site VPNs.
Anycast
Addressing where one address is shared by several nodes and traffic is routed to the nearest one.
Plenum cable
Cable with a fire-resistant, low-smoke jacket required for runs through air-handling spaces.
Single-mode fibre
Fibre with a narrow core that carries a single light path via laser, supporting long distances.
Multimode fibre
Fibre with a wider core that carries multiple light paths, cheaper but limited to shorter distances.
SFP+
A hot-swappable small form-factor pluggable transceiver supporting 10 Gbps links.
QSFP28
A quad small form-factor pluggable transceiver using four 25 Gbps lanes for 100 Gbps.
LC connector
A small form-factor fibre connector with a push-latch, common on SFP transceivers.
Auto-MDIX
A port feature that detects the cable wiring and automatically swaps transmit and receive pairs.
Star topology
A layout where every device connects to one central device, usually a switch, which becomes a single point of failure.
Full mesh
A topology where every node connects directly to every other node, maximizing redundancy; it needs n(n-1)/2 links.
Hub and spoke
A WAN design where branch sites connect to a central site, and branch-to-branch traffic passes through the hub.
Three-tier architecture
A campus design with access, distribution and core layers, each with a distinct role.
Collapsed core
A two-tier design where the core and distribution layers are combined in the same devices.
Spine and leaf
A data centre design where every leaf switch connects to every spine switch, giving consistent hop counts.
East-west traffic
Traffic moving laterally between systems inside a data centre.
Subnet mask
A 32-bit value (or /prefix) that marks which part of an IPv4 address is the network and which part is the host.
RFC 1918
The standard defining private IPv4 ranges 10.0.0.0/8, 172.16.0.0/12 and 192.168.0.0/16.
APIPA
Automatic Private IP Addressing: self-assigned 169.254.0.0/16 addresses used when DHCP is unavailable.
Loopback
The 127.0.0.0/8 range, with 127.0.0.1 used to test the local TCP/IP stack.
CIDR
Classless Inter-Domain Routing: notation and routing that use any prefix length instead of fixed classes.
VLSM
Variable-length subnet masking: using different subnet mask lengths within one address space to fit each subnet's size.
Broadcast address
The last address in a subnet, used to reach every host on it and never assigned to a host.
Control plane
The part of a network device or system that decides how traffic should be forwarded, such as routing protocols.
Data plane
The part that actually forwards packets and frames according to the control plane's decisions.
SD-WAN
Software-defined WAN: centrally managed branch networking that steers applications across multiple transports by measured path quality.
VXLAN
An overlay protocol that encapsulates Layer 2 frames in UDP over a Layer 3 network, using a 24-bit segment ID.
Zero trust
A security model that grants no implicit trust based on network location and verifies every request by identity and context.
SASE
Secure access service edge: a cloud-delivered combination of SD-WAN networking and security services.
Configuration drift
The gradual divergence of devices from their intended, documented configuration.
Global unicast address
A public, routable IPv6 address, currently from 2000::/3.
Unique local address
An IPv6 address in fc00::/7 (fd00::/8 in practice) used privately inside an organization, like RFC 1918 space.
Link-local address
An automatically configured fe80::/10 IPv6 address valid only on the local network segment.
SLAAC
Stateless address autoconfiguration: hosts build their own IPv6 address from a router-advertised prefix.
NDP
Neighbor Discovery Protocol: ICMPv6-based protocol that replaces ARP and provides router discovery in IPv6.
Dual stack
Running IPv4 and IPv6 simultaneously on the same devices and network.
NAT64
A translation mechanism that lets IPv6-only hosts communicate with IPv4-only hosts, usually paired with DNS64.

Domain 2: Network implementation (20%)

Exam tips

Key terms

Default route
A route to 0.0.0.0/0 (or ::/0) used when no more specific route matches; the gateway of last resort.
Floating static route
A static route with a higher administrative distance that acts as a backup when the primary route is lost.
Administrative distance
A value rating the trustworthiness of a route source; the lower value is preferred when prefixes are equal.
Longest prefix match
The rule that a router uses the most specific matching route (longest subnet mask) for a destination.
Link-state protocol
A routing protocol, like OSPF, in which each router builds a full map of the topology and computes best paths.
Autonomous system
A network or group of networks under one administrative control, identified in BGP by an ASN.
Convergence
The process and time for all routers to agree on routes after a topology change.
PAT
Port address translation: maps many private addresses to one public address by using unique source ports.
Static NAT
A fixed one-to-one mapping between a private and a public IP address.
Port forwarding
A static rule that sends inbound traffic for a specific public port to a chosen inside host and port.
Inside global
The public address that represents an inside host after translation.
FHRP
First hop redundancy protocol: lets multiple routers share a virtual gateway IP so hosts keep connectivity if one fails.
VRRP
Virtual Router Redundancy Protocol: the open-standard FHRP with master and backup routers.
Subinterface
A logical interface on a physical port, commonly tagged with a VLAN for router-on-a-stick routing.
VLAN
A logical Layer 2 network and broadcast domain created on switches, independent of physical location.
Access port
A switch port assigned to a single VLAN that sends and receives untagged frames.
Trunk port
A switch port that carries traffic for multiple VLANs using 802.1Q tags.
802.1Q
The IEEE standard for VLAN tagging that inserts a 4-byte tag with a 12-bit VLAN ID into Ethernet frames on trunks.
Native VLAN
The VLAN whose frames are sent untagged across an 802.1Q trunk.
Voice VLAN
A separate VLAN for IP phone traffic on an access port that also carries a PC's data VLAN.
SVI
Switched virtual interface: a virtual Layer 3 interface for a VLAN on a switch, used for inter-VLAN routing or management.
Full duplex
A mode in which a link can transmit and receive at the same time without collisions.
Autonegotiation
The process by which two connected ports agree on speed and duplex automatically.
Duplex mismatch
A misconfiguration where one side of a link runs full duplex and the other half duplex, causing errors and poor performance.
MTU
Maximum transmission unit: the largest payload a frame can carry, 1500 bytes on standard Ethernet.
Jumbo frame
An Ethernet frame with an MTU larger than 1500 bytes, commonly around 9000 bytes.
LACP
Link Aggregation Control Protocol: the IEEE protocol that negotiates bundling multiple links into one logical link.
Late collision
A collision detected after the first 64 bytes of a frame, a classic sign of a duplex mismatch.
Root bridge
The switch with the lowest bridge ID, which serves as the reference point for the spanning tree.
Bridge ID
A switch's STP identifier: priority value plus MAC address; the lowest wins the root election.
BPDU
Bridge protocol data unit: the frames switches exchange to run STP.
Root port
The single port on each non-root switch with the lowest path cost to the root bridge.
Broadcast storm
Uncontrolled circulation and multiplication of broadcast frames caused by a Layer 2 loop.
BPDU guard
A feature that disables a port if it receives a BPDU, protecting edge ports from rogue switches.
RSTP
Rapid Spanning Tree Protocol (802.1w), which converges much faster than original STP.
Non-overlapping channels
Channels whose frequencies do not overlap; in 2.4 GHz North America these are 1, 6 and 11.
DFS
Dynamic frequency selection: a requirement on certain 5 GHz channels for access points to detect radar and vacate the channel.
Transmit power control
A regulatory mechanism that limits or adjusts an access point's transmit power on certain channels.
Channel bonding
Combining adjacent channels into a wider channel to increase throughput.
Co-channel interference
Performance loss when nearby access points share the same channel and must take turns transmitting.
Adjacent-channel interference
Signal corruption caused by access points on overlapping, but not identical, channels.
Country code
An access point setting that applies the local regulator's rules for channels and power.
SSID
Service set identifier: the name of a wireless network.
BSSID
The unique identifier, usually the MAC address, of a specific access point radio in a basic service set.
ESS
Extended service set: multiple access points sharing one SSID to provide a larger network with roaming.
MIMO
Multiple-input multiple-output: using several antennas and spatial streams to increase throughput, introduced in 802.11n.
OFDMA
Orthogonal frequency-division multiple access: an 802.11ax feature that lets an AP serve multiple clients simultaneously within one channel.
Wireless LAN controller
A device or cloud service that centrally configures and manages lightweight access points.
Mesh network
A wireless design where access points relay traffic to each other over the air, so only some need a wired uplink.
SAE
Simultaneous Authentication of Equals: the WPA3-Personal handshake that resists offline dictionary attacks.
PSK
Pre-shared key: a single passphrase shared by all users of a WPA2/WPA3 Personal network.
802.1X
Port-based network access control that authenticates each user or device through EAP and a RADIUS server before granting access.
Supplicant
The client device or software requesting access in 802.1X authentication.
EAP-TLS
An 802.1X authentication method using certificates on both client and server; considered the strongest EAP method.
Captive portal
A web page that must be completed before a user on a network is granted wider access.
Yagi antenna
A directional antenna producing a focused beam, often used for point-to-point links.
MDF
Main distribution frame: the central wiring and equipment room connecting to carriers and to each IDF.
IDF
Intermediate distribution frame: a secondary wiring closet serving a floor or area, linked to the MDF by backbone cabling.
Demarc
The demarcation point where the service provider's network ends and the customer's begins.
Rack unit (U)
The standard unit of vertical rack space, 1.75 inches (44.45 mm).
Hot aisle/cold aisle
A data centre layout where rack fronts face a cooled aisle and rack backs face an exhaust aisle.
Port-side exhaust
A switch airflow option where air enters opposite the ports and leaves through the port side.
Patch panel
A panel where permanent cable runs terminate, providing ports that are connected to equipment with patch cords.
UPS
Uninterruptible power supply: a battery-backed device that keeps equipment running during power loss and conditions power.
Online UPS
A double-conversion UPS that always powers equipment from its inverter, giving clean power and no transfer time.
PDU
Power distribution unit: a rack-mounted device that distributes, and may meter or switch, power to equipment.
PoE+
IEEE 802.3at, providing up to 30 W per port from the switch.
PoE budget
The total wattage a PoE switch can supply across all its ports.
Electrostatic discharge
A sudden flow of static electricity that can damage components, made more likely by low humidity.
Clean agent
A gaseous fire suppressant that leaves no residue and is safe for electronic equipment.

Domain 3: Network operations (19%)

Exam tips

Key terms

Physical diagram
A diagram showing actual devices, their locations and how they are cabled together.
Logical diagram
A diagram showing how data flows: subnets, VLANs, addressing and routing, independent of physical layout.
Rack diagram
An elevation drawing showing each device's position in a rack by rack unit.
Cable map
A record of each cable run with its label, endpoints, type and length.
IPAM
IP address management: tools and processes for planning, tracking and managing IP address space, DHCP and DNS.
SLA
Service-level agreement: a documented commitment to measurable service levels such as uptime and response time.
Heat map
A colour-coded wireless survey output showing signal strength across a floor plan.
End of life (EOL)
The vendor's announcement that a product is being retired from sale and, eventually, from support.
End of support
The date after which the vendor no longer provides patches, updates or technical support for a product.
Firmware
Low-level software embedded in hardware that controls the device's functions and can be updated.
Release notes
Vendor documentation describing the fixes, new features, known issues and upgrade requirements of a software version.
Hash verification
Comparing a downloaded file's cryptographic hash with the vendor's published value to confirm it is intact and untampered.
Sanitization
Securely removing data from a device, by wiping or destruction, so it cannot be recovered.
Certificate of destruction
A record from a disposal vendor confirming that equipment or media was securely destroyed.
Change request
A formal proposal describing a change, its reason, risk, implementation steps, test plan and rollback plan.
Change advisory board
A group that reviews, assesses and approves proposed changes.
Maintenance window
A pre-agreed, low-impact time period in which approved changes are carried out.
Rollback plan
The documented steps to return a system to its previous state if a change fails.
Golden configuration
An approved standard configuration template used to build and audit devices of a given role.
Baseline
A documented reference of normal configuration or performance used for comparison.
Running configuration
The active configuration in a device's memory, which must be saved to persist across reboots.
MIB
Management Information Base: the structured set of variables an SNMP agent exposes, each identified by an OID.
OID
Object identifier: the unique numeric address of a single variable in a MIB.
SNMP trap
An unsolicited message from an SNMP agent to the manager, sent on UDP 162, reporting an event.
SNMPv3
The SNMP version that adds user-based authentication and encryption.
NetFlow
A flow-export technology that summarizes traffic conversations for analysis without capturing payloads.
Syslog severity
A level from 0 (Emergency) to 7 (Debug) indicating how serious a log message is.
SIEM
Security information and event management: a system that aggregates and correlates logs to detect security events.
Network discovery
Automatically finding and cataloguing devices on a network, often producing a topology map.
LLDP
Link Layer Discovery Protocol: a vendor-neutral protocol devices use to advertise their identity and capabilities to directly connected neighbours.
Top talkers
The hosts or applications generating the most traffic, typically identified through flow analysis.
Performance monitoring
Tracking metrics such as utilisation, latency, jitter, loss and errors against baselines and thresholds.
Availability monitoring
Regularly checking whether devices and services respond, and alerting when they do not.
Synthetic monitoring
Generating test traffic or transactions to measure performance and availability proactively.
Alert fatigue
Desensitization caused by too many or low-value alerts, leading staff to miss important ones.
RPO
Recovery point objective: the maximum tolerable data loss, measured as time before the incident.
RTO
Recovery time objective: the maximum tolerable time to restore a service after an incident.
MTBF
Mean time between failures: the average operating time between failures of a repairable system.
MTTR
Mean time to repair: the average time needed to repair a failure and restore service.
Hot site
A fully equipped, up-to-date recovery site that can take over operations almost immediately.
Cold site
A recovery location with space, power and cooling but no ready equipment or data.
Tabletop exercise
A discussion-based DR test in which staff talk through their response to a scenario.
DORA
Discover, Offer, Request, Acknowledge: the four-message DHCP lease process.
Scope
The pool of addresses and settings a DHCP server hands out for one subnet.
Exclusion
An address or range within a scope that the DHCP server will not assign.
Reservation
A DHCP entry that always assigns a specific IP address to a specific MAC address.
Lease time
How long a client may use an assigned address before it must renew it.
DHCP relay
A router or switch function (IP helper) that forwards DHCP broadcasts to a server on another subnet.
SLAAC
Stateless address autoconfiguration: IPv6 hosts build their own addresses from a router-advertised prefix.
A and AAAA records
DNS records mapping a name to an IPv4 (A) or IPv6 (AAAA) address.
CNAME
A DNS record that makes one name an alias for another name.
MX record
A DNS record listing a domain's mail servers with preference values, lowest tried first.
PTR record
A DNS record used for reverse lookups, mapping an IP address to a hostname.
SOA record
Start of authority: the record at the top of a zone holding the primary server, contact, serial number and refresh timers.
Recursive resolver
A DNS server that performs the full lookup on a client's behalf and caches the results.
DNSSEC
Extensions that digitally sign DNS records so resolvers can verify their authenticity and integrity.
NTP
Network Time Protocol: synchronizes clocks across a network using UDP 123 and a stratum hierarchy.
Stratum
The level of an NTP server in the hierarchy; stratum 1 is directly connected to a reference clock.
Reference clock
A stratum 0 time source such as a GPS receiver or atomic clock.
Clock skew
The difference between the clocks of two systems, which can break authentication and log correlation.
PTP
Precision Time Protocol (IEEE 1588): hardware-assisted time synchronization with sub-microsecond accuracy.
Grandmaster clock
The authoritative time source in a PTP network that other clocks follow.
NTS
Network Time Security: a mechanism that authenticates NTP time using TLS-established keys.
Site-to-site VPN
A VPN that persistently connects two networks through their gateways.
Clientless VPN
Remote access through a web browser over TLS without a dedicated VPN client.
SSH
Secure Shell: encrypted remote command-line access on TCP 22, replacing Telnet.
API
Application programming interface: a programmatic way, often REST over HTTPS, for tools to configure and query devices.
Console port
A local serial management port that provides CLI access without needing network connectivity.
Jump box
A hardened intermediary host that administrators must use to access management interfaces of other systems.
Out-of-band management
Managing devices through a separate path independent of the production network, such as a console server.

Domain 4: Network security (14%)

Exam tips

Key terms

Data at rest
Data stored on disks, databases, backups or media, protected by encryption such as full-disk encryption.
Certificate authority
A trusted entity that issues and signs digital certificates binding public keys to identities.
AAA
Authentication, authorization and accounting: verifying identity, granting permissions and logging activity.
MFA
Multifactor authentication: requiring two or more different types of factor, such as a password and a phone app.
RADIUS
An open AAA protocol for network access using UDP 1812 and 1813 that encrypts only the password.
TACACS+
A AAA protocol on TCP 49 that encrypts the full payload and separates authentication, authorization and accounting.
SAML
An XML-based standard that lets an identity provider send authentication assertions to service providers for SSO.
CIA triad
Confidentiality, integrity and availability: the three core goals of information security.
Least privilege
Granting only the minimum access rights needed to perform a task, for only as long as needed.
Separation of duties
Dividing sensitive tasks so no single person can complete them alone.
RBAC
Role-based access control: assigning permissions to roles and users to roles.
Defense in depth
Layering multiple independent security controls so one failure does not expose the system.
Zero trust
A model that grants no implicit trust based on network location and verifies every request by identity and context.
Lateral movement
An attacker moving from one compromised system to others inside a network.
Access control vestibule
A two-door entry space where only one door opens at a time, preventing tailgating.
Honeypot
A decoy system with no legitimate use, designed to attract and detect attackers.
Honeynet
A network of honeypots that simulates a realistic environment to observe attackers.
Vulnerability
A weakness in a system that could be exploited by a threat.
Risk
The combination of the likelihood that a threat exploits a vulnerability and the impact if it does.
PCI DSS
Payment Card Industry Data Security Standard: security requirements for organizations handling payment card data.
GDPR
The EU regulation governing the protection and processing of personal data of people in the EU.
IoT
Internet of Things: everyday devices, such as cameras and sensors, connected to networks.
OT
Operational technology: systems that control physical processes, prioritizing safety and availability.
SCADA
Supervisory control and data acquisition: systems that monitor and control distributed industrial processes.
PLC
Programmable logic controller: an industrial computer that directly controls machinery in an ICS.
Air gap
Complete physical isolation of a system or network from other networks.
Client isolation
A wireless setting that stops devices on the same SSID from communicating directly with each other.
BYOD
Bring your own device: a policy allowing personal devices to access organizational resources.
DDoS
Distributed denial of service: an attack from many sources that overwhelms a target's resources.
Amplification attack
A reflection attack in which small spoofed requests make third-party servers send much larger responses to the victim.
Double tagging
A VLAN hopping technique using two 802.1Q tags to reach a VLAN through the native VLAN.
MAC flooding
Filling a switch's MAC address table with fake entries so it floods traffic out all ports.
ARP poisoning
Sending forged ARP messages to link an attacker's MAC with another host's IP, redirecting traffic.
Evil twin
A malicious access point that impersonates a legitimate wireless network.
On-path attack
An attack where the adversary intercepts, and possibly alters, communication between two parties.
Phishing
Fraudulent messages impersonating a trusted party to steal credentials or deliver malware.
Spear phishing
A targeted phishing attack tailored to a specific person or group.
Tailgating
Following an authorized person into a secure area without their knowledge or without badging in.
Worm
Self-replicating malware that spreads across networks without user action.
Trojan horse
Malware disguised as legitimate software that hides a malicious function.
Ransomware
Malware that encrypts or steals data and demands payment for its release.
Rootkit
Malware that hides itself deep in the operating system to maintain concealed access.
Hardening
Reducing a system's attack surface by removing unnecessary functions and securing configurations.
Attack surface
The total set of points where an attacker could try to enter or extract data from a system.
Default credentials
Factory-set usernames and passwords that are publicly known and must be changed at installation.
Parking lot VLAN
An unused, isolated VLAN assigned to disabled ports so they give no network access if enabled.
SNMPv3 authPriv
The SNMPv3 security level that provides both authentication and encryption.
Management ACL
An access list restricting which source addresses may reach a device's management interfaces.
Login banner
A legal warning shown before login stating that access is restricted and monitored.
Port security
A switch feature that limits and controls the MAC addresses allowed on a port.
Sticky MAC
A port security option where the switch learns and saves allowed MAC addresses dynamically.
Violation mode
The action port security takes on a violation: protect, restrict or shutdown.
DHCP snooping
A switch feature that permits DHCP server messages only on trusted ports and builds a binding table.
Dynamic ARP inspection
A switch feature that validates ARP packets against trusted bindings to prevent ARP poisoning.
BPDU guard
A feature that err-disables an edge port if it receives a BPDU.
Err-disabled
A port state where the switch has shut the port down due to a detected error or violation.
NAC
Network access control: technology that checks identity and policy before granting a device network access.
Supplicant
The client software that requests network access and provides credentials in 802.1X.
Authenticator
The switch or access point that enforces 802.1X by relaying authentication and controlling port access.
EAP
Extensible Authentication Protocol: the framework carrying 802.1X authentication methods such as EAP-TLS and PEAP.
Posture assessment
Checking a device's security state, such as patches and antivirus, before granting network access.
MAB
MAC authentication bypass: using a device's MAC address as its identity for devices that cannot do 802.1X.
Key rotation
Replacing cryptographic keys periodically or after potential exposure to limit risk.
ACL
Access control list: an ordered set of permit and deny rules used to filter traffic.
Extended ACL
An ACL that matches on source, destination, protocol and ports, usually placed close to the source.
Implicit deny
The invisible final rule in an ACL or firewall policy that drops any traffic not explicitly permitted.
Wildcard mask
The inverse of a subnet mask used in Cisco ACLs, where 0 bits must match and 1 bits are ignored.
URL filtering
Allowing or blocking web access based on the site address or its category.
Security zone
A group of interfaces or networks with a common trust level, used to define firewall policy.
Screened subnet
A network zone, formerly called a DMZ, that hosts internet-facing services separated from the internal network.

Domain 5: Network troubleshooting (24%)

Exam tips

Key terms

Scope
How widespread a problem is, such as one user, one area or the whole organization, which helps locate the cause.
Theory of probable cause
A hypothesis about what is causing the problem, formed from the gathered information.
Divide and conquer
A troubleshooting approach that starts in the middle of the OSI model or path and narrows toward the failing half.
Bottom-to-top approach
Troubleshooting that starts at the Physical layer and works upward through the OSI model.
Escalation
Passing a problem to someone with more expertise, authority or access when you cannot resolve it.
Preventive measures
Actions taken after a fix to stop the problem recurring, such as monitoring or configuration changes.
Lessons learned
The documented insights from an incident that improve future troubleshooting and prevention.
Attenuation
The loss of signal strength as it travels over distance through a medium.
EMI
Electromagnetic interference: noise induced in cabling from external electrical or radio sources.
Crosstalk
Unwanted signal coupling between adjacent wire pairs or cables.
NEXT
Near-end crosstalk: crosstalk measured at the same end as the transmitter, often caused by excessive untwisting at terminations.
Split pair
A wiring fault where wires from two different pairs are used together, breaking the twist and causing crosstalk.
TX/RX reversal
A fault where the transmit and receive paths are not correctly crossed, often on fibre, preventing a link.
OTDR
Optical time-domain reflectometer: a tool that locates breaks, bends and bad splices along a fibre by distance.
CRC error
A frame whose checksum does not match its contents, indicating corruption in transit.
Runt
An Ethernet frame smaller than the 64-byte minimum.
Giant
An Ethernet frame larger than the maximum allowed size, often from MTU mismatches.
Output drops
Frames discarded because the interface's output queue was full, indicating congestion.
Late collision
A collision detected after the first 64 bytes of a frame, typical of duplex mismatch or excessive cable length.
Administratively down
An interface state meaning it has been disabled by configuration.
Err-disabled
A state in which the switch has automatically shut a port because of an error or security violation.
Power budget
The total PoE wattage a switch can deliver across its ports.
PoE class
A negotiated category indicating how much power a powered device needs from the switch.
Passive PoE
Non-standard PoE that supplies power without negotiation and may be incompatible with standard devices.
Transceiver mismatch
Incompatible optical or copper modules at each end of a link, such as differing speed, wavelength or fibre type.
Digital optical monitoring
Transceiver diagnostics showing temperature, voltage and transmit and receive optical power.
dBm
Decibels relative to one milliwatt; a logarithmic unit for signal power, where values closer to zero are stronger.
Signal-to-noise ratio
The difference between signal strength and background noise; higher values mean cleaner signals.
Switching loop
A Layer 2 path loop that causes frames to circulate endlessly, producing broadcast storms.
MAC flapping
A MAC address appearing alternately on different switch ports, a common sign of a loop.
Storm control
A switch feature that limits broadcast, multicast or unknown unicast traffic on a port to a set rate.
Allowed VLAN list
The set of VLANs permitted to cross a trunk link.
Native VLAN mismatch
A configuration where the two ends of a trunk use different untagged VLANs, causing traffic leakage.
Trunk mode mismatch
One end of a link configured as a trunk and the other as an access port, breaking multi-VLAN traffic.
ACL hit counter
A per-rule count of matching packets that shows which ACL entries are actually being used.
Default gateway
The router address a host sends traffic to when the destination is not on its local subnet.
Default route
A route to 0.0.0.0/0 used when no more specific route matches, often pointing to the ISP.
Routing table
The list of known destination networks and next hops a router or host uses to forward packets.
Routing loop
A condition where packets circulate between routers until their TTL expires.
Asymmetric routing
Traffic taking a different path in each direction, which can break stateful firewalls.
Pool exhaustion
Running out of assignable addresses in a DHCP scope or NAT pool.
Black hole
A route or path where traffic is silently discarded.
Scope exhaustion
A DHCP condition where all addresses in a scope are leased and new clients cannot obtain one.
DHCP starvation
An attack that requests many leases using spoofed MAC addresses to exhaust a DHCP scope.
IP address conflict
Two devices configured with the same IP address, causing intermittent connectivity for both.
Conflict detection
A DHCP server feature that checks whether an address is in use before offering it.
DNS cache
Stored DNS answers on clients and resolvers, kept for each record's TTL.
Clock skew
The difference between clocks on two systems, which can break authentication and certificate validation.
Clock drift
The gradual divergence of a device's clock from true time when it is not synchronized.
Bandwidth
The maximum data rate a link can carry.
Throughput
The actual data rate achieved across a link or path, as opposed to its theoretical bandwidth.
Congestion
A condition where offered traffic exceeds capacity, causing queuing delay and drops.
Bottleneck
The lowest-capacity point in a path that limits overall performance.
Latency
The delay for data to travel from source to destination, often measured as round-trip time.
Jitter
Variation in packet delay, which degrades real-time voice and video.
Oversubscription
Aggregating more potential traffic onto a link than it can carry at once.
Noise floor
The level of background RF energy; a higher noise floor reduces signal-to-noise ratio.
Adjacent-channel interference
Corruption caused by nearby access points on overlapping, but not identical, channels.
Co-channel interference
Capacity loss when nearby access points use the same channel and must share airtime.
Dead zone
An area with insufficient wireless signal for reliable connectivity.
Sticky client
A wireless client that stays associated to a distant AP instead of roaming to a closer one.
Deauthentication attack
Sending forged management frames to force clients off a wireless network.
Protocol analyzer
Software that captures and decodes network traffic for detailed inspection, such as Wireshark.
tcpdump
A command-line packet capture tool for Linux and Unix that can save captures for later analysis.
traceroute
A tool that reveals each router hop to a destination by sending packets with increasing TTL values.
netstat
A command that displays network connections, listening ports and routing information on a host.
nmap
A network scanner that discovers hosts, open ports, services and operating systems.
LLDP
Link Layer Discovery Protocol: a vendor-neutral protocol devices use to advertise identity and capabilities to neighbours.
iperf
A tool that measures maximum throughput between a client and a server you control.
Toner and probe
A tool pair used to trace and identify a specific cable among many.
Cable tester
A tool that checks wiring continuity and detects opens, shorts, miswires and reversed pairs.
Cable certifier
A tester that verifies a cabling run meets a specific category's performance standards and produces a report.
TDR
Time-domain reflectometer: measures reflections in copper cable to find the distance to a fault.
Loopback plug
A connector that routes a port's transmit signal back to its receive pins to test the port.
Visual fault locator
A device that injects visible red light into fibre to reveal breaks, sharp bends and continuity.
MAC address table
The switch table mapping learned MAC addresses to ports and VLANs.
Interface counters
Per-interface statistics such as CRC errors, runts, giants and drops used to diagnose problems.
Running configuration
The active configuration currently in use in a device's memory.
Startup configuration
The saved configuration loaded when a device boots.
ARP table
A table mapping IP addresses to MAC addresses for devices on directly connected networks.
PoE status
The show power output listing the PoE budget, usage and per-port power allocation.
Study Network+ for free
Lessons, quizzes, exam simulations and hands-on labs.
Open the Network+ study plan