Click Study Flashcards above to open the flashcard hub — hundreds of CCNA cards you can flip, match, type, or quiz yourself on. Every card is drawn from the six official 200-301 domains, so you study exactly what the exam tests.[1] Pair them with our free practice test and study guide.
CCNA Flashcard Study Modes
Flip mode walks you through each card front and back at your own pace. Match is a timed game that pairs terms with their definitions. Type shows the definition and asks you to produce the term, so a front like DORA has to come back from memory. Quiz rebuilds the same cards as multiple choice for fast self-checks.

Why Flashcards Work for the CCNA
IP Connectivity carries the heaviest official weight at 25%, and its 48 cards drill the routing vocabulary that weight rests on. You get protocol cards such as OSPF, EIGRP and OSPFv2, older distance-vector terms like RIP, and the first-hop redundancy family where FHRP sits alongside HSRP, VRRP and GLBP.
Network Fundamentals is weighted at 20% and is the largest block in the deck with 66 cards. These fronts cover the hardware, addressing and encapsulation terms the rest of the exam assumes you already know, from Hub and NIC to ARP and PDU, plus sizing and addressing terms such as MTU, VLSM and SSID.
Network Access also sits at 20% and brings 50 cards built around switching, trunking and wireless. Expect VLAN and SVI for segmentation and interface terms, DTP and BPDU for trunk negotiation and spanning tree, and discovery and wireless cards including CDP, LLDP, WLC and WLAN.
Security Fundamentals is weighted at 15% across 44 cards. The fronts lean on access control and encryption terminology: AAA with its supporting protocols RADIUS and TACACS+, port-based control through 802.1X, tunneling with IPsec, and the wireless security progression from WPA to WPA2 and WPA3.
The two 10% domains close the deck. IP Services has 43 cards on the day-to-day protocols and address translation terms, including NAT, DHCP and DORA, plus management and transfer fronts such as NTP, SSH and FTP. Automation and Programmability has 37 cards on data formats like JSON, XML and YAML, configuration tools including Ansible, Chef and Puppet, and interface terms such as API and NETCONF.
The CCNA is dense with things you simply have to know cold — port numbers, administrative distances, OSPF neighbor states, command syntax, and security acronyms.[1] Spaced flashcards are the most efficient way to keep it all fresh. Used alongside our practice test and study guide, they turn review time into measurable progress.
CCNA Flashcards by Domain
The cards are organized by the six official 200-301 domains. Drill the highest-weighted ones first — IP Connectivity, Network Fundamentals, and Network Access make up 65% of the exam:[1]
| Domain | Exam weight |
|---|---|
| IP Connectivity | 25% |
| Network Fundamentals | 20% |
| Network Access | 20% |
| Security Fundamentals | 15% |
| IP Services | 10% |
| Automation & Programmability | 10% |
How to Get the Most Out of These CCNA Flashcards
- Start with IP Connectivity. Its 48 cards map to the 25% slice, and routing terms like OSPF and HSRP come up again inside troubleshooting and redundancy questions elsewhere.
- Type-drill the acronyms. Fronts such as VLSM and TACACS+ are easy to recognize and hard to recall, so force yourself to produce the term from the definition alone.
- Use Match for protocol families. It is fast for the first-hop redundancy set and the wireless security cards, where WPA2 and WPA3 blur together under any time pressure.
- Switch to the practice test. Once Quiz runs clean across Network Fundamentals and Network Access, move to full-length questions that combine domains in one scenario.
- Set a repeatable cadence. With 288 cards, take one domain per sitting, re-Flip the misses the next day, and use the study guide wherever a definition still feels thin.
CCNA Flashcards FAQ
Hundreds of free CCNA flashcards, organized across all six 200-301 domains — Network Fundamentals, Network Access, IP Connectivity, IP Services, Security Fundamentals, and Automation & Programmability. They're free with no account required.
Yes. Flashcards use active recall — retrieving an answer from memory — which research shows is one of the most effective study methods, especially in short, spaced sessions. They're ideal for the CCNA's heavy memorization load: ports, administrative distances, OSPF states, and command syntax.
All six 200-301 domains: Network Fundamentals (OSI, IP, subnetting), Network Access (VLANs, STP, wireless), IP Connectivity (routing, OSPF, FHRP), IP Services (NAT, DHCP, DNS, QoS), Security Fundamentals (AAA, ACLs, Layer 2 security), and Automation & Programmability (SDN, REST, JSON).
Lead with the heaviest domain — IP Connectivity (25%) — then Network Fundamentals and Network Access (20% each). Drill subnetting, administrative distances, and OSPF with Type and Quiz modes until automatic, then mix in the other domains. Pair the cards with our full practice test before exam day.
Yes — 100% free, all four study modes, no paywall.
Yes. The cards are organized to the current Cisco CCNA 200-301 exam topics (version 1.1), covering all six scored domains in their official proportions.
CCNA flashcard bank
All 288 cards, by topic
A reference copy of every card in this deck. Each answer stays hidden until you choose to show it. To study with Flip, Match, Type and Quiz modes and track what you have mastered, use Study Flashcards at the top of the page.
Network Fundamentals (66)
- OSI model
Show answerHide answer
A seven-layer framework for network communication: Physical, Data Link, Network, Transport, Session, Presentation, Application (L1→L7).
- Router
Show answerHide answer
A Layer 3 device that forwards packets between different IP networks using a routing table.
- Switch
Show answerHide answer
A Layer 2 device that forwards frames within a network using a MAC address table.
- Subnet mask
Show answerHide answer
Marks which bits of an IPv4 address are the network portion (1s) and which are the host portion (0s).
- TCP vs UDP
Show answerHide answer
TCP is connection-oriented and reliable (3-way handshake, ACKs); UDP is connectionless, best-effort, and faster.
- Default gateway
Show answerHide answer
The router IP a host sends traffic to when the destination is on a different subnet.
- Layer 1 (Physical)
Show answerHide answer
Transmits raw bits over the medium — cables, connectors, radio, voltage. PDU: bits.
- Layer 2 (Data Link)
Show answerHide answer
Local delivery using MAC addresses; switches operate here. PDU: frame.
- Layer 3 (Network)
Show answerHide answer
Logical addressing and routing between networks using IP; routers operate here. PDU: packet.
- Layer 4 (Transport)
Show answerHide answer
End-to-end delivery and ports; TCP and UDP. PDU: segment.
- Encapsulation
Show answerHide answer
Wrapping data with each layer's header going down the stack: data → segment → packet → frame → bits.
- MAC address
Show answerHide answer
A 48-bit hardware address burned into a NIC, written in hex; used for Layer 2 delivery on the local link.
- ARP
Show answerHide answer
Address Resolution Protocol — maps a known IPv4 address to its MAC address on the local network.
- Broadcast domain
Show answerHide answer
The set of devices that receive a Layer 2 broadcast frame; a router or a VLAN boundary separates them.
- Collision domain
Show answerHide answer
A network segment where frames can collide; each switch port is its own collision domain (full duplex avoids collisions).
- Three-way handshake
Show answerHide answer
TCP connection setup: SYN, then SYN-ACK, then ACK. The connection is open after the ACK.
- IPv4 address
Show answerHide answer
A 32-bit logical address written as four dotted-decimal octets (e.g., 192.168.1.10).
- CIDR notation
Show answerHide answer
Slash notation (e.g., /24) showing how many leading bits of an IP are the network portion.
- Usable hosts formula
Show answerHide answer
Usable hosts = 2ⁿ − 2, where n = host bits (subtract the network and broadcast addresses).
- Block size trick
Show answerHide answer
Block size = 256 − the mask's interesting octet; subnets increment by the block size.
- Private IPv4 (RFC 1918)
Show answerHide answer
Non-routable ranges 10.0.0.0/8, 172.16.0.0/12, and 192.168.0.0/16 — translated by NAT to reach the internet.
- APIPA
Show answerHide answer
169.254.0.0/16 address a host self-assigns when no DHCP server answers — a DHCP-failure clue.
- Loopback address
Show answerHide answer
127.0.0.0/8 (usually 127.0.0.1) — tests the local TCP/IP stack.
- IPv6 address
Show answerHide answer
A 128-bit address written as eight groups of four hex digits, separated by colons.
- IPv6 global unicast
Show answerHide answer
A publicly routable IPv6 address, typically in the 2000::/3 range.
- IPv6 link-local
Show answerHide answer
An automatically configured FE80::/10 address used only on the local link (e.g., for neighbor discovery).
- IPv6 unique local
Show answerHide answer
FC00::/7 (commonly FD00::/8) — private IPv6, like RFC 1918 for IPv4; not internet-routable.
- Modified EUI-64
Show answerHide answer
A method to build the 64-bit IPv6 interface ID from a 48-bit MAC by inserting FFFE and flipping the 7th bit.
- IPv6 anycast
Show answerHide answer
An address assigned to multiple interfaces; traffic goes to the nearest one (by routing metric).
- IPv6 multicast
Show answerHide answer
FF00::/8 addresses that deliver to a group; IPv6 has no broadcast — it uses multicast instead.
- Single-mode fiber
Show answerHide answer
Fiber with a thin core for long distances using a laser; lower attenuation than multimode.
- Multimode fiber
Show answerHide answer
Fiber with a wider core for shorter, high-speed runs; typically uses LED/VCSEL light sources.
- Twisted-pair copper
Show answerHide answer
Cat 5e/6/6a/8 UTP cabling; cheap and common but limited to about 100 meters per run.
- Duplex mismatch
Show answerHide answer
One end half-duplex and the other full-duplex — causes collisions, late collisions, and poor throughput.
- Spine-leaf topology
Show answerHide answer
A two-tier data-center fabric where every leaf switch connects to every spine — predictable, low latency.
- Two-tier (collapsed core)
Show answerHide answer
Combines core and distribution into one layer plus an access layer; common in smaller networks.
- Three-tier architecture
Show answerHide answer
Core (backbone), distribution (policy/routing), and access (endpoints) layers in enterprise networks.
- PoE (Power over Ethernet)
Show answerHide answer
802.3af/at/bt — delivers electrical power and data over one Ethernet cable to APs, phones, and cameras.
- Next-generation firewall
Show answerHide answer
A firewall adding deep packet inspection, application awareness, and IPS beyond stateful filtering.
- Server virtualization
Show answerHide answer
Running multiple virtual machines on one physical server via a hypervisor, each with its own OS.
- Containers
Show answerHide answer
Lightweight, isolated app environments that share the host OS kernel (e.g., Docker) — faster and smaller than VMs.
- VRF
Show answerHide answer
Virtual Routing and Forwarding — multiple independent routing tables on one router for traffic separation.
- MAC learning
Show answerHide answer
A switch records the source MAC and ingress port of each frame to build its MAC address table.
- Frame flooding
Show answerHide answer
A switch floods a frame out all ports (except the source) when the destination MAC is unknown (unknown unicast).
- Nonoverlapping 2.4 GHz channels
Show answerHide answer
Channels 1, 6, and 11 — the only non-overlapping channels in the 2.4 GHz band.
- SSID
Show answerHide answer
Service Set Identifier — the human-readable name of a wireless network.
- OSI Layer 5 (Session)
Show answerHide answer
Establishes, manages, and terminates sessions between applications. PDU: data.
- OSI Layer 6 (Presentation)
Show answerHide answer
Translation, encryption/decryption, and compression of data (TLS, ASCII, JPEG). PDU: data.
- OSI Layer 7 (Application)
Show answerHide answer
User-facing network services and protocols: HTTP, FTP, DNS, SMTP. PDU: data.
- TCP/IP model
Show answerHide answer
The 4-layer model the internet runs on: Link, Internet, Transport, Application; maps onto OSI.
- PDU
Show answerHide answer
Protocol Data Unit — the name of data at each layer: bits (L1), frame (L2), packet (L3), segment (L4).
- Hub
Show answerHide answer
An obsolete Layer 1 device that repeats incoming bits out every port, creating one collision domain.
- Endpoint
Show answerHide answer
A host such as a PC, phone, or server that consumes or provides network services.
- NIC
Show answerHide answer
Network Interface Card — the hardware (with a MAC address) that connects a host to the network.
- Octet
Show answerHide answer
One of the four 8-bit segments of an IPv4 address (range 0–255).
- Subnetting
Show answerHide answer
Dividing a network into smaller subnetworks by borrowing host bits for the network portion.
- VLSM
Show answerHide answer
Variable Length Subnet Masking — using different mask lengths within a network to size subnets efficiently.
- /24 prefix
Show answerHide answer
255.255.255.0 — 254 usable hosts, block size 256 (last octet).
- /26 prefix
Show answerHide answer
255.255.255.192 — 62 usable hosts, block size 64.
- /30 prefix
Show answerHide answer
255.255.255.252 — 2 usable hosts; used for point-to-point links.
- IPv6 abbreviation rules
Show answerHide answer
Drop leading zeros in each group; replace one run of all-zero groups with :: (only once).
- Dual stack
Show answerHide answer
Running IPv4 and IPv6 simultaneously on the same device during migration.
- Bandwidth vs throughput
Show answerHide answer
Bandwidth is the link's capacity; throughput is the actual data rate achieved in practice.
- Latency
Show answerHide answer
The delay for data to travel from source to destination, often measured as round-trip time.
- Jitter
Show answerHide answer
Variation in packet delay — disruptive to real-time traffic such as voice and video.
- MTU
Show answerHide answer
Maximum Transmission Unit — the largest frame payload that can be sent without fragmentation (Ethernet default 1500 bytes).
Network Access (50)
- VLAN
Show answerHide answer
A logical Layer 2 segment that splits one switch into multiple broadcast domains; devices in different VLANs need a router to talk.
- Access port
Show answerHide answer
A switch port that belongs to a single VLAN and carries untagged traffic to one end device.
- Trunk port
Show answerHide answer
A switch link that carries traffic for multiple VLANs, tagging frames with 802.1Q.
- 802.1Q
Show answerHide answer
The IEEE standard that inserts a 4-byte VLAN tag into Ethernet frames so VLANs span trunk links.
- Native VLAN
Show answerHide answer
The one VLAN whose traffic is sent untagged across an 802.1Q trunk (default VLAN 1; change it for security).
- Voice VLAN
Show answerHide answer
A separate VLAN on an access port for an IP phone, while a daisy-chained PC uses the data VLAN.
- Default VLAN
Show answerHide answer
VLAN 1 — all switch ports belong to it by default; best practice is not to use it for user data.
- Inter-VLAN routing
Show answerHide answer
Routing between VLANs using a router-on-a-stick (subinterfaces) or a Layer 3 switch (SVIs).
- CDP
Show answerHide answer
Cisco Discovery Protocol — a Cisco proprietary Layer 2 protocol that discovers directly connected Cisco neighbors.
- LLDP
Show answerHide answer
Link Layer Discovery Protocol — the vendor-neutral (IEEE 802.1AB) equivalent of CDP.
- EtherChannel
Show answerHide answer
Bundling multiple physical links into one logical link for more bandwidth and redundancy.
- LACP
Show answerHide answer
Link Aggregation Control Protocol (802.3ad) — the standard protocol that negotiates an EtherChannel.
- PAgP
Show answerHide answer
Port Aggregation Protocol — Cisco's proprietary EtherChannel negotiation protocol.
- Spanning Tree Protocol (STP)
Show answerHide answer
Prevents Layer 2 loops by electing a root bridge and blocking redundant paths until needed.
- Rapid PVST+
Show answerHide answer
Cisco's per-VLAN Rapid Spanning Tree (based on 802.1w) — runs a separate, fast-converging STP instance per VLAN.
- Root bridge
Show answerHide answer
The switch with the lowest bridge ID (priority + MAC); it becomes the reference point of the spanning tree.
- Bridge ID
Show answerHide answer
A switch's STP identity = bridge priority (default 32768 + VLAN) plus its MAC address.
- Root port
Show answerHide answer
The single port on a non-root switch with the lowest cost path to the root bridge.
- Designated port
Show answerHide answer
The forwarding port on each segment with the lowest cost to the root; non-designated ports block.
- PortFast
Show answerHide answer
Puts an access port directly into forwarding, skipping STP listening/learning — for end-device ports only.
- BPDU Guard
Show answerHide answer
Disables a PortFast port if it receives a BPDU, protecting the topology from rogue switches.
- RSTP port states
Show answerHide answer
Discarding, Learning, and Forwarding (RSTP simplifies the older STP blocking/listening/learning/forwarding).
- Lightweight AP
Show answerHide answer
An access point that relies on a Wireless LAN Controller for configuration and management (split-MAC).
- Autonomous AP
Show answerHide answer
A standalone access point that is configured and managed individually (no controller).
- WLC
Show answerHide answer
Wireless LAN Controller — centrally manages lightweight APs, pushing config, security, and RF settings.
- CAPWAP
Show answerHide answer
Control And Provisioning of Wireless Access Points — the tunnel protocol between a lightweight AP and a WLC.
- LAG (wireless)
Show answerHide answer
Link Aggregation on a WLC — bundles its physical ports into one logical interface to the switch.
- WLC management access
Show answerHide answer
Console, Telnet, SSH, HTTP/HTTPS, plus AAA via RADIUS/TACACS+ for admin authentication.
- WLAN creation (GUI)
Show answerHide answer
On a WLC you define the SSID, map it to an interface/VLAN, and set security, QoS, and advanced settings.
- QoS profile (WLAN)
Show answerHide answer
A WLC setting (Platinum/Gold/Silver/Bronze) that prioritizes wireless traffic such as voice and video.
- Trunk vs access
Show answerHide answer
A trunk carries many tagged VLANs between switches; an access port carries one untagged VLAN to a host.
- DTP
Show answerHide answer
Dynamic Trunking Protocol — Cisco protocol that auto-negotiates trunking; disable it for security.
- VLAN normal range
Show answerHide answer
VLANs 1–1005; the CCNA focuses on the normal range for access/trunk configuration.
- show vlan brief
Show answerHide answer
IOS command that lists VLANs and the access ports assigned to each.
- switchport mode access
Show answerHide answer
Sets a port to access mode (single VLAN, untagged).
- switchport mode trunk
Show answerHide answer
Sets a port to trunk mode to carry multiple tagged VLANs.
- switchport access vlan
Show answerHide answer
Assigns an access port to a specific VLAN (e.g., switchport access vlan 10).
- Router-on-a-stick
Show answerHide answer
Inter-VLAN routing using one router interface with 802.1Q subinterfaces, one per VLAN.
- SVI
Show answerHide answer
Switched Virtual Interface — a Layer 3 VLAN interface on a multilayer switch for inter-VLAN routing.
- STP convergence
Show answerHide answer
The time STP takes to reach a stable, loop-free topology after a change; RSTP converges far faster.
- BPDU
Show answerHide answer
Bridge Protocol Data Unit — the STP message switches exchange to elect the root and build the tree.
- Root Guard
Show answerHide answer
Prevents a port from becoming a root port, protecting the chosen root bridge's position.
- Loop Guard
Show answerHide answer
Prevents a blocking port from wrongly transitioning to forwarding if BPDUs stop arriving.
- EtherChannel load balancing
Show answerHide answer
Distributes frames across the bundle by hashing source/destination MAC, IP, or port.
- channel-group mode active
Show answerHide answer
Configures an interface for LACP active mode in an EtherChannel.
- WLAN
Show answerHide answer
Wireless LAN — an 802.11 network identified by an SSID and served by APs.
- RF (radio frequency)
Show answerHide answer
The wireless spectrum used by Wi-Fi — 2.4 GHz, 5 GHz, and 6 GHz bands.
- 5 GHz band
Show answerHide answer
Faster with many non-overlapping channels but shorter range than 2.4 GHz.
- 6 GHz band
Show answerHide answer
Clean spectrum used by Wi-Fi 6E/7 for high throughput and low interference.
- Cloud-managed AP
Show answerHide answer
An access point configured and monitored through a cloud dashboard (e.g., Cisco Meraki).
IP Connectivity (48)
- Routing table
Show answerHide answer
The list of known networks a router uses to forward packets: prefix, mask, next hop, AD, and metric.
- Longest prefix match
Show answerHide answer
A router selects the most specific matching route (the longest matching network mask) to forward a packet.
- Administrative distance
Show answerHide answer
A router's trust ranking of routing sources; lower is preferred when multiple sources offer a route.
- AD: connected
Show answerHide answer
Directly connected route — administrative distance 0 (most trusted).
- AD: static
Show answerHide answer
Static route — administrative distance 1.
- AD: OSPF
Show answerHide answer
OSPF — administrative distance 110.
- AD: EIGRP (internal)
Show answerHide answer
EIGRP internal — administrative distance 90.
- AD: RIP
Show answerHide answer
RIP — administrative distance 120.
- Routing metric
Show answerHide answer
A value a routing protocol uses to pick the best path among routes it learned (e.g., OSPF cost).
- Static route
Show answerHide answer
A manually configured route; predictable but does not adapt automatically to topology changes.
- Default route
Show answerHide answer
A 'route of last resort' (0.0.0.0/0 in IPv4, ::/0 in IPv6) used when no more specific route matches.
- Network route
Show answerHide answer
A static route to a specific destination subnet via a next hop or exit interface.
- Host route
Show answerHide answer
A static route to a single host — a /32 (IPv4) or /128 (IPv6) prefix.
- Floating static route
Show answerHide answer
A backup static route with a higher administrative distance that activates only if the primary route fails.
- IPv4 static route command
Show answerHide answer
ip route <network> <mask> <next-hop|exit-interface> — e.g., ip route 10.0.0.0 255.0.0.0 192.168.1.2
- IPv6 static route command
Show answerHide answer
ipv6 route <prefix/length> <next-hop|exit-interface> — e.g., ipv6 route 2001:db8::/32 2001:db8:1::1
- OSPF
Show answerHide answer
Open Shortest Path First — a fast, link-state interior gateway protocol that uses cost as its metric.
- OSPFv2
Show answerHide answer
The OSPF version for IPv4; the CCNA tests single-area OSPFv2 configuration and verification.
- OSPF cost
Show answerHide answer
Default OSPF metric = reference bandwidth (100 Mbps) ÷ interface bandwidth; lower cost is preferred.
- OSPF router ID
Show answerHide answer
A 32-bit ID for an OSPF router — chosen by manual config, then highest loopback IP, then highest active interface IP.
- OSPF neighbor adjacency
Show answerHide answer
Two OSPF routers form an adjacency by exchanging Hello packets and agreeing on parameters before sharing routes.
- OSPF Hello/Dead timers
Show answerHide answer
Routers must agree on Hello (default 10s on broadcast) and Dead (default 40s) timers to become neighbors.
- OSPF DR/BDR
Show answerHide answer
On broadcast/multiaccess networks OSPF elects a Designated Router and Backup DR to reduce adjacencies.
- DR/BDR election
Show answerHide answer
Highest OSPF interface priority wins; ties break to the highest router ID. Priority 0 means never DR/BDR.
- OSPF point-to-point
Show answerHide answer
On a point-to-point link OSPF forms an adjacency directly with no DR/BDR election.
- OSPF area 0
Show answerHide answer
The backbone area; single-area OSPF places all routers and links in area 0.
- FHRP
Show answerHide answer
First Hop Redundancy Protocol — provides a redundant default gateway so hosts keep connectivity if a router fails.
- HSRP
Show answerHide answer
Hot Standby Router Protocol — Cisco FHRP; active and standby routers share a virtual IP/MAC for the gateway.
- VRRP
Show answerHide answer
Virtual Router Redundancy Protocol — the open-standard FHRP (master/backup) sharing a virtual gateway IP.
- GLBP
Show answerHide answer
Gateway Load Balancing Protocol — Cisco FHRP that also load-balances across multiple gateways.
- Gateway of last resort
Show answerHide answer
The next hop used for the default route, shown in the routing table when a default route exists.
- Connected vs static route
Show answerHide answer
A connected route is learned automatically from an up/up interface; a static route is manually configured.
- show ip route
Show answerHide answer
Displays the IPv4 routing table — codes, prefixes, next hops, AD, and metrics.
- Routing protocol code
Show answerHide answer
The letter in the routing table showing how a route was learned (C connected, S static, O OSPF, D EIGRP).
- Distance vector vs link state
Show answerHide answer
Distance vector shares its whole table with neighbors (RIP); link state shares topology to compute paths (OSPF).
- EIGRP
Show answerHide answer
Cisco's advanced distance-vector IGP; fast convergence using a composite metric (bandwidth + delay).
- RIP
Show answerHide answer
A simple distance-vector IGP using hop count (max 15) as its metric; rarely used today.
- Autonomous system (AS)
Show answerHide answer
A collection of networks under one administrative control; OSPF runs inside one, BGP between them.
- IGP vs EGP
Show answerHide answer
Interior Gateway Protocols (OSPF, EIGRP) route within an AS; Exterior (BGP) route between ASes.
- OSPF DR purpose
Show answerHide answer
Reduces the number of full adjacencies on a multiaccess segment so updates flow through the DR.
- OSPF passive-interface
Show answerHide answer
Stops OSPF from sending Hellos out an interface while still advertising its subnet.
- OSPF process / network command
Show answerHide answer
'router ospf <id>' starts the process; 'network <addr> <wildcard> area <n>' enables OSPF on matching interfaces.
- show ip ospf neighbor
Show answerHide answer
Verifies OSPF adjacencies, neighbor router IDs, and DR/BDR roles.
- Equal-cost load balancing
Show answerHide answer
A router can install multiple equal-metric routes to the same destination and balance traffic across them.
- Static default route command
Show answerHide answer
ip route 0.0.0.0 0.0.0.0 <next-hop> — sends all unmatched traffic to the next hop.
- Recursive vs directly attached
Show answerHide answer
A next-hop static route requires a recursive lookup; an exit-interface static route forwards directly.
- HSRP virtual IP
Show answerHide answer
The shared gateway IP that hosts use; the active HSRP router answers for it.
- HSRP active/standby
Show answerHide answer
HSRP elects one active router (highest priority) to forward; the standby takes over on failure.
IP Services (43)
- NAT
Show answerHide answer
Network Address Translation — maps private (RFC 1918) addresses to public ones so internal hosts reach the internet.
- Static NAT
Show answerHide answer
A one-to-one fixed mapping between a private (inside local) and a public (inside global) address.
- Dynamic NAT
Show answerHide answer
Maps inside addresses to a pool of public addresses on a first-come, first-served basis.
- PAT (NAT overload)
Show answerHide answer
Port Address Translation — many private hosts share one public IP, distinguished by source port numbers.
- Inside local / inside global
Show answerHide answer
Inside local = the private host address inside the network; inside global = its translated public address.
- NTP
Show answerHide answer
Network Time Protocol — synchronizes device clocks; runs client/server mode and uses a stratum hierarchy. UDP 123.
- NTP stratum
Show answerHide answer
A measure of distance from an authoritative clock; stratum 0 is the reference, stratum 1 is directly attached.
- DHCP
Show answerHide answer
Dynamic Host Configuration Protocol — auto-assigns IP, mask, gateway, and DNS via DORA. UDP 67 (server) / 68 (client).
- DORA
Show answerHide answer
The DHCP exchange: Discover, Offer, Request, Acknowledge.
- DHCP relay (IP helper)
Show answerHide answer
Forwards DHCP broadcasts across subnets to a central server, configured with 'ip helper-address'.
- DNS
Show answerHide answer
Domain Name System — resolves names to IP addresses using a hierarchy of resolvers. Mainly UDP 53 (TCP 53 for large/zone).
- DNS record types
Show answerHide answer
A (IPv4), AAAA (IPv6), CNAME (alias), MX (mail), NS (name server), PTR (reverse), TXT (text).
- SNMP
Show answerHide answer
Simple Network Management Protocol — a manager polls agents on UDP 161; agents send traps on UDP 162. Use v3 for security.
- SNMP versions
Show answerHide answer
v1/v2c use clear-text community strings; SNMPv3 adds authentication and encryption.
- Syslog
Show answerHide answer
A protocol for sending log messages to a central server (UDP 514) with facility and severity levels.
- Syslog severity levels
Show answerHide answer
0 Emergency, 1 Alert, 2 Critical, 3 Error, 4 Warning, 5 Notice, 6 Informational, 7 Debugging (mnemonic: 'Every Awesome Cisco Engineer Will Need Ice cream Daily').
- QoS
Show answerHide answer
Quality of Service — prioritizes traffic so latency-sensitive flows (voice, video) get preferential treatment.
- QoS classification
Show answerHide answer
Identifying and grouping traffic (by port, protocol, or DSCP) so policies can be applied to each class.
- QoS marking
Show answerHide answer
Setting a value (e.g., DSCP or CoS) on a packet so downstream devices honor its priority.
- QoS queuing
Show answerHide answer
Buffering and scheduling packets so high-priority traffic is sent first when a link is congested.
- Policing vs shaping
Show answerHide answer
Policing drops or remarks traffic that exceeds a rate; shaping buffers and delays it to smooth the rate.
- Per-hop behavior (PHB)
Show answerHide answer
How each device independently treats a marked packet (e.g., expedited forwarding for voice).
- SSH
Show answerHide answer
Secure Shell — encrypted remote CLI access (TCP 22); replaces clear-text Telnet for device management.
- SSH config requirements
Show answerHide answer
A hostname, an IP domain name, and an RSA key pair (crypto key generate rsa) plus a local user and 'transport input ssh'.
- FTP
Show answerHide answer
File Transfer Protocol — TCP 20/21; transfers files (e.g., IOS images) but is unencrypted.
- TFTP
Show answerHide answer
Trivial File Transfer Protocol — UDP 69; a simple, lightweight file transfer often used for IOS/config backups.
- DHCP vs DNS
Show answerHide answer
DHCP hands out IP configuration to clients; DNS resolves names to IP addresses — different jobs.
- show ip nat translations
Show answerHide answer
Displays the current NAT/PAT translation table on a Cisco router.
- ip nat inside / outside
Show answerHide answer
Marks router interfaces as the NAT inside (private) or outside (public) interface.
- Why PAT is common
Show answerHide answer
One public IP can serve thousands of internal hosts by tracking unique source ports — conserves IPv4.
- NTP client/server
Show answerHide answer
A device set as an NTP client syncs its clock to a configured NTP server.
- Why NTP matters
Show answerHide answer
Accurate, synchronized time makes logs, certificates, and troubleshooting correlate correctly.
- DHCP scope / pool
Show answerHide answer
The range of addresses and options (gateway, DNS, lease) a DHCP server hands out for a subnet.
- DHCP lease
Show answerHide answer
The time a client may use an assigned address before it must renew.
- ip helper-address
Show answerHide answer
Configures a router interface to relay DHCP (and other) broadcasts to a server on another subnet.
- nslookup / dig
Show answerHide answer
Tools that query DNS to resolve a name and diagnose DNS problems.
- 'ping by IP works, name fails'
Show answerHide answer
The classic symptom of a DNS problem — connectivity is fine but resolution is broken.
- SNMP trap vs poll
Show answerHide answer
A poll is the manager requesting data (UDP 161); a trap is the agent sending an unsolicited alert (UDP 162).
- MIB / OID
Show answerHide answer
A MIB is the structured database of manageable objects; an OID identifies a specific object within it.
- Syslog severity 0–3
Show answerHide answer
Emergency, Alert, Critical, Error — the most severe messages.
- DSCP
Show answerHide answer
Differentiated Services Code Point — a 6-bit field in the IP header used to mark QoS class.
- Voice QoS marking
Show answerHide answer
Voice traffic is typically marked Expedited Forwarding (DSCP EF / 46) for low-latency queuing.
- FTP vs TFTP
Show answerHide answer
FTP uses TCP 20/21 with authentication; TFTP uses UDP 69 with no authentication — simpler but less capable.
Security Fundamentals (44)
- CIA triad
Show answerHide answer
The core security goals: Confidentiality, Integrity, and Availability.
- Threat / vulnerability / exploit
Show answerHide answer
A threat is a potential danger; a vulnerability is a weakness; an exploit is the method that abuses a vulnerability.
- Mitigation
Show answerHide answer
A control or technique that reduces the likelihood or impact of a threat (e.g., patching, ACLs, segmentation).
- AAA
Show answerHide answer
Authentication (who you are), Authorization (what you may do), and Accounting (logging what you did).
- RADIUS
Show answerHide answer
An open AAA protocol (UDP) that encrypts only the password and combines authentication and authorization; common for network access.
- TACACS+
Show answerHide answer
A Cisco AAA protocol (TCP 49) that encrypts the whole payload and separates AAA; preferred for device administration.
- Access Control List (ACL)
Show answerHide answer
An ordered set of permit/deny rules that filter traffic by address, protocol, or port.
- Standard ACL
Show answerHide answer
Filters on the source IP address only; placed close to the destination.
- Extended ACL
Show answerHide answer
Filters on source and destination IP, protocol, and port; placed close to the source.
- Implicit deny
Show answerHide answer
Every ACL ends with an invisible 'deny any' — traffic matching no entry is dropped.
- ACL processing order
Show answerHide answer
Top-down, first match wins; order your entries from most specific to least specific.
- Wildcard mask
Show answerHide answer
An inverse mask in ACLs where 0 = must match and 1 = ignore (e.g., 0.0.0.255 matches a /24).
- Port security
Show answerHide answer
Limits the MAC addresses learned on a switch access port; violation actions are protect, restrict, or shutdown.
- Sticky MAC
Show answerHide answer
Port security option that dynamically learns and saves MAC addresses to the running config.
- DHCP snooping
Show answerHide answer
Marks ports trusted/untrusted and drops rogue DHCP server replies on untrusted ports; builds a binding table.
- Dynamic ARP Inspection (DAI)
Show answerHide answer
Validates ARP packets against the DHCP snooping binding table, blocking ARP spoofing / on-path attacks.
- WPA
Show answerHide answer
Wi-Fi Protected Access — interim Wi-Fi security using TKIP; now deprecated as insecure.
- WPA2
Show answerHide answer
Wi-Fi security using AES/CCMP; strong, but its PSK 4-way handshake is vulnerable to offline guessing.
- WPA3
Show answerHide answer
Current Wi-Fi standard; uses SAE to resist offline password attacks and adds forward secrecy.
- WPA2 PSK (GUI)
Show answerHide answer
On a WLC you secure a WLAN by selecting WPA2, AES, and a Pre-Shared Key (PSK).
- Multifactor authentication (MFA)
Show answerHide answer
Requires two or more factors: something you know, something you have, and/or something you are.
- Site-to-site VPN
Show answerHide answer
An always-on encrypted tunnel between two networks via gateways (often IPsec).
- Remote-access VPN
Show answerHide answer
Connects an individual user's device to the corporate network over an encrypted tunnel (e.g., SSL/AnyConnect).
- Password policy
Show answerHide answer
Rules for password management, complexity, and alternatives (MFA, certificates, biometrics).
- enable secret
Show answerHide answer
Sets a privileged-EXEC password stored as a strong one-way hash (preferred over 'enable password').
- service password-encryption
Show answerHide answer
Applies weak (type 7) encryption to clear-text passwords in the config so they aren't readable at a glance.
- On-path attack
Show answerHide answer
An attacker positioned between two parties to intercept or alter traffic (formerly 'man-in-the-middle').
- MAC flooding (CAM overflow)
Show answerHide answer
Flooding a switch with bogus MACs to overflow the address table, forcing it to flood frames; mitigated by port security.
- VLAN hopping
Show answerHide answer
An attack to reach another VLAN via double-tagging or DTP abuse; mitigate by disabling DTP and changing the native VLAN.
- Defense in depth
Show answerHide answer
Layering multiple security controls so no single failure exposes the network.
- Zero trust
Show answerHide answer
A model that trusts no user or device by default and verifies every access request.
- Least privilege
Show answerHide answer
Grant users and devices only the access their role actually requires.
- 802.1X
Show answerHide answer
Port-based network access control that authenticates a device (often via RADIUS) before granting access.
- Stateful firewall
Show answerHide answer
Tracks the state of connections and allows return traffic for sessions it initiated.
- DMZ / screened subnet
Show answerHide answer
A segmented network for public-facing servers, isolated from the internal LAN.
- IPsec
Show answerHide answer
A protocol suite that authenticates and encrypts IP traffic — the basis of many VPNs.
- Numbered vs named ACL
Show answerHide answer
ACLs can be identified by number (1–99 standard) or by a descriptive name for easier management.
- Apply ACL to interface
Show answerHide answer
'ip access-group <acl> in|out' applies an ACL to an interface in a chosen direction.
- Port security violation modes
Show answerHide answer
Protect (drop silently), Restrict (drop + log/counter), Shutdown (err-disable the port) — default is Shutdown.
- err-disabled port
Show answerHide answer
A port shut down by a security violation; it must be re-enabled (shutdown/no shutdown or errdisable recovery).
- Brute-force attack
Show answerHide answer
Repeatedly guessing credentials; mitigated by strong passwords, lockouts, and MFA.
- Social engineering
Show answerHide answer
Manipulating people to reveal information or access; countered by user awareness training.
- Biometrics
Show answerHide answer
Authentication using a physical trait (fingerprint, face) — a 'something you are' factor.
- Certificate-based auth
Show answerHide answer
Using digital certificates instead of (or with) passwords to prove identity.
Automation and Programmability (37)
- Network automation
Show answerHide answer
Using software and scripts to configure, manage, and monitor devices — reducing manual error and speeding changes.
- Controller-based networking
Show answerHide answer
A central controller manages many devices and pushes policy, versus configuring each device by hand (traditional).
- Software-defined networking (SDN)
Show answerHide answer
Separates the control plane (decisions) from the data plane (forwarding), managing the network centrally in software.
- Control plane
Show answerHide answer
The 'brain' that decides how traffic should be forwarded (builds routing/switching tables).
- Data plane
Show answerHide answer
The 'muscle' that forwards traffic based on the control plane's decisions.
- Overlay vs underlay
Show answerHide answer
The underlay is the physical IP transport network; the overlay is a virtual network (tunnels) built on top of it.
- Network fabric
Show answerHide answer
The combined underlay plus overlay that a controller manages as a single programmable system.
- Northbound API
Show answerHide answer
The interface between the SDN controller and applications/automation tools (often REST).
- Southbound API
Show answerHide answer
The interface between the SDN controller and the network devices it manages (e.g., NETCONF, OpenFlow).
- Cisco DNA Center
Show answerHide answer
Cisco's controller for intent-based campus networking — central management, automation, and assurance.
- Traditional vs DNA Center
Show answerHide answer
Traditional management configures each device via CLI; DNA Center centralizes provisioning, policy, and monitoring.
- REST API
Show answerHide answer
An API style over HTTP using URLs and verbs (GET/POST/PUT/DELETE) to read and change data; usually stateless.
- CRUD operations
Show answerHide answer
Create, Read, Update, Delete — mapped to HTTP POST, GET, PUT/PATCH, and DELETE.
- HTTP verbs
Show answerHide answer
GET (read), POST (create), PUT/PATCH (update), DELETE (remove) — the actions in REST APIs.
- HTTP status codes
Show answerHide answer
2xx success (200 OK, 201 Created), 4xx client error (401, 404), 5xx server error.
- Data encoding (REST)
Show answerHide answer
REST APIs exchange structured data, most commonly in JSON (also XML or YAML).
- JSON
Show answerHide answer
JavaScript Object Notation — human-readable data as key/value pairs in objects {} and arrays [].
- JSON syntax
Show answerHide answer
Objects use {} with "key": value pairs; arrays use []; strings are double-quoted; values can be string, number, boolean, null, object, or array.
- Configuration management
Show answerHide answer
Tools that define device state as code so it's consistent, repeatable, and version-controlled.
- Ansible
Show answerHide answer
An agentless configuration-management tool using YAML 'playbooks' pushed over SSH; uses a push model.
- Puppet
Show answerHide answer
A configuration-management tool using a declarative language and (typically) agents that pull config from a master.
- Chef
Show answerHide answer
A configuration-management tool using Ruby-based 'recipes' and 'cookbooks'; agent/pull model.
- Push vs pull (config mgmt)
Show answerHide answer
Ansible pushes config to devices; Puppet and Chef agents typically pull config from a central server.
- Infrastructure as code (IaC)
Show answerHide answer
Managing and provisioning infrastructure through machine-readable definition files instead of manual setup.
- Benefit of automation
Show answerHide answer
Faster, consistent deployments, fewer human errors, and easier scaling and rollback of changes.
- Intent-based networking
Show answerHide answer
Expressing what the network should do (policy/intent); the controller translates it into device config.
- API
Show answerHide answer
Application Programming Interface — a defined way for software components to exchange data and commands.
- Stateless API
Show answerHide answer
Each API request contains all needed information; the server keeps no client session state (REST is stateless).
- REST vs RPC
Show answerHide answer
REST exposes resources via URLs and HTTP verbs; RPC calls remote procedures/functions directly.
- YAML
Show answerHide answer
A human-readable data-serialization format using indentation; used by Ansible playbooks.
- XML
Show answerHide answer
Extensible Markup Language — a tag-based data format; an alternative to JSON in some APIs.
- NETCONF
Show answerHide answer
A southbound protocol that manages device configuration using XML over a secure transport (often SSH).
- Idempotency
Show answerHide answer
Applying the same automation repeatedly yields the same end state — a goal of config management.
- Version control (Git)
Show answerHide answer
Tracking changes to configuration-as-code so changes are reviewable and reversible.
- Agent vs agentless
Show answerHide answer
Puppet/Chef typically need an agent on each device; Ansible is agentless (uses SSH).
- JSON key/value
Show answerHide answer
Data in JSON is stored as "key": value pairs inside objects {}.
- JSON array
Show answerHide answer
An ordered list of values in JSON, written in square brackets [ ].
References
- 1.Cisco. “CCNA 200-301 Exam Topics (v1.1).” learningnetwork.cisco.com. ↑
- 2.Internet Engineering Task Force. “RFC 1918 — Address Allocation for Private Internets.” rfc-editor.org. ↑
- 3.Institute of Electrical and Electronics Engineers. “IEEE 802.1Q — Bridges and Bridged Networks (VLANs).” standards.ieee.org. ↑

Career Employer
Career Employer is the ultimate resource to help you get started working the job of your dreams. We cover topics from general career information, career searching, exam preparation with free study materials, career interviewing, and becoming successful in your career of choice.
All PostsCareer Employer’s Editorial Process
Here at Career Employer, we focus a lot on providing factually accurate information that is always up to date. We strive to provide correct information using strict editorial processes, article editing, and fact-checking for all of the information found on our website. We only utilize trustworthy and relevant resources. To find out more, make sure to read our full editorial process page here.
