All certifications / Network+ / Lessons
Network+ N10-009 lessons
Study Network+ for free
A week-by-week plan with every lesson, quizzes, checkpoint tests, a practice exam and hands-on labs.
Open the Network+ study planA week-by-week plan with every lesson, quizzes, checkpoint tests, a practice exam and hands-on labs.
Domain 1: Networking concepts
- OSI model layers and the data unit at each layer
- Network appliances: routers, switches, firewalls, IDS/IPS, load balancers, proxies, NAS/SAN, wireless controllers
- Network functions: CDN, VPN, QoS, TTL
- Cloud concepts: NFV, VPC, security groups, cloud gateways, deployment and service models (IaaS, PaaS, SaaS)
- Common ports and protocols: FTP, SSH, Telnet, SMTP, DNS, DHCP, HTTP/S, NTP, SNMP, LDAP/S, SMB, Syslog, SQL, RDP, SIP
- Protocol types (TCP, UDP, ICMP, GRE, IPsec) and traffic types (unicast, multicast, anycast, broadcast)
- Transmission media and transceivers: copper categories, single-mode vs multimode fiber, coax, SFP/QSFP, connectors
- Topologies and architectures: mesh, star, hub and spoke, spine and leaf, three-tier, collapsed core, north-south vs east-west
- IPv4 addressing: public vs private (RFC 1918), APIPA, loopback, classes, subnetting and VLSM, CIDR
- Evolving use cases: SDN and SD-WAN, VxLAN, zero trust, SASE/SSE, infrastructure as code
- IPv6: address types, dual stack, tunneling, NAT64
Domain 2: Network implementation
- Static vs dynamic routing; OSPF, EIGRP and BGP; route selection (longest prefix, administrative distance, metrics)
- NAT and PAT, first hop redundancy (FHRP/VRRP/HSRP), subinterfaces
- VLANs, VLAN database, SVIs, 802.1Q trunking, native and voice VLANs
- Interface settings: speed, duplex, MTU and jumbo frames, link aggregation
- Spanning Tree Protocol and loop prevention
- Wireless channels and bands: 2.4, 5 and 6 GHz, channel width, non-overlapping channels, regulatory impacts
- 802.11 standards, SSID/BSSID/ESSID, autonomous vs controller-based APs, mesh networks
- Wireless security: WPA2/WPA3 Personal and Enterprise, PSK vs 802.1X, captive portals; antenna types
- Physical installation: IDF/MDF, rack sizes, port-side exhaust/intake, cable management, patch panels
- Power and environment: UPS, PDU, PoE/PoE+ budgets, temperature, humidity, fire suppression
Domain 3: Network operations
- Documentation: physical vs logical diagrams, rack diagrams, cable maps, IPAM, asset inventory, SLAs, wireless surveys
- Life-cycle management: end of life/support, software and firmware management, decommissioning
- Change management and configuration management: baselines, golden configs, backups
- Monitoring: SNMP versions, traps, MIBs, flow data, packet capture, baselines, log aggregation and syslog, API integration
- Monitoring solutions: network discovery, traffic analysis, performance and availability monitoring, configuration monitoring
- Disaster recovery metrics: RPO, RTO, MTTR, MTBF; hot, warm and cold sites; active-active vs active-passive; DR testing
- DHCP: scopes, exclusions, reservations, lease time, options, relay/IP helper; SLAAC for IPv6
- DNS: record types (A, AAAA, CNAME, MX, TXT, NS, PTR, SOA), zones, recursive vs authoritative, DNSSEC, DoH/DoT, hosts file
- Time protocols: NTP, PTP and NTS
- Access and management methods: site-to-site and client VPNs, SSH, GUI, API, console, jump box, in-band vs out-of-band
Domain 4: Network security
- Logical security: encryption in transit and at rest, PKI and certificates, IAM, AAA, MFA, SSO, RADIUS, TACACS+, LDAP, SAML
- Security principles: least privilege, role-based access, CIA triad, defense in depth, zero trust, segmentation
- Physical security, deception technologies (honeypots, honeynets), risk terms, audits and compliance (PCI DSS, GDPR)
- Network segmentation enforcement for IoT, IIoT, SCADA/ICS/OT, guest and BYOD
- Attacks: DoS/DDoS, VLAN hopping, MAC flooding, ARP and DNS poisoning/spoofing, rogue DHCP and APs, evil twin, on-path
- Social engineering: phishing, dumpster diving, shoulder surfing, tailgating; malware
- Device hardening: disable unused ports and services, change default passwords, secure management protocols
- Switch security: port security, DHCP snooping, dynamic ARP inspection, BPDU guard
- Network access control: 802.1X, MAC filtering, key management
- Security rules: ACLs, implicit deny, URL and content filtering, zones and screened subnets
Domain 5: Network troubleshooting
- The seven-step troubleshooting methodology and its order
- Cabling issues: wrong cable type, signal degradation, crosstalk, EMI, attenuation, improper termination, TX/RX transposed
- Interface issues: increasing CRC and runt/giant counters, port status, duplex and speed mismatches
- Hardware issues: PoE power budget exceeded, wrong PoE standard, transceiver mismatch, signal strength
- Switching issues: STP loops, incorrect VLAN assignment, ACLs
- Routing issues: routing tables, default routes, address pool exhaustion, incorrect gateway, subnet mask or IP
- Service issues: DHCP scope exhaustion, duplicate IPs, DNS failures, NTP issues
- Performance issues: congestion, bottlenecks, bandwidth, latency, packet loss, jitter
- Wireless issues: interference, channel overlap, signal degradation, coverage gaps, client disassociation, roaming misconfiguration
- Software tools: protocol analyzer, command line (ping, traceroute, nslookup, dig, tcpdump, netstat, arp, ip/ipconfig), nmap, LLDP/CDP, speed testers, iperf
- Hardware tools: toner and probe, cable tester, cable certifier, TDR/OTDR, loopback plug, Wi-Fi analyzer, visual fault locator
- Basic device commands: show mac-address-table, show route, show interface, show config, show arp, show vlan, show power