Career Employer

Your FREE CompTIA Network+ Flashcards 2026 – 250+ Cards

Realistic, Network+ (N10-009) exam-style flashcards across all 5 domains — flip, match, type, and quiz yourself.

How well do you know them?

To find us again, just search “Career Employer CompTIA Network+”

By

Click Study Flashcards above to open the flashcard hub — hundreds of Network+ cards you can flip, match, type, or quiz yourself on. Every card is drawn from the five official N10-009 domains, so you study exactly what the exam tests.[1]

Pair them with our free practice test and study guide. Want extra insurance for exam day? Capital Prep’s CompTIA Network+ premium study materials come with a CompTIA Network+ exam pass guarantee: your money back if you don’t pass, plus up to $399 toward your retake fee — and Career Employer students get a special discount.

CompTIA Network+ is one of the 14 CompTIA certifications — explore our CompTIA flashcards to compare and prep across the whole family.

Network+ Flashcard Study Modes

Four modes run on the same 293 cards. Flip is quiet study, one side at a time. Match is a timed race pairing terms with their definitions. Type shows the definition and asks you to produce the term, so a description of variable-length subnet masking should pull VLSM out of you. Quiz turns the same cards into multiple choice.

Free CompTIA Network+ flashcards from Career Employer — active recall for the N10-009 exam

Why Flashcards Work for the Network+

Network Troubleshooting carries the heaviest official weight at 24%, and its 50 cards drill the tools, symptoms, and physical causes you have to name fast. You get command-line utilities such as ping, nmap, and iperf, fiber test gear in the card for OTDR, interference in EMI, and performance vocabulary like Jitter and Latency.

Networking Concepts is the biggest block in the deck with 91 cards against 23% of the exam. These fronts cover protocol behavior, addressing math, and design vocabulary: the transport pair TCP and UDP, subnetting shorthand in VLSM, naming in FQDN, plus modern architecture terms such as SDN and VPC, and delivery concepts like CDN and MTU.

Network Implementation holds 58 cards for 20% of the exam, and the terms lean toward switching, routing, and the hardware around them. You will see wired and wireless building blocks such as Hub and WEP, switch-side items like SVI and DTP, address resolution in ARP, routing protocols in BGP and RIP, and power protection in UPS.

Network Operations gives you 46 cards for 19%, mostly services, monitoring, and continuity planning. Expect name and address services in DNS and DHCP, the lease exchange summarized by DORA, monitoring in SNMP, admission control in NAC, and agreement and recovery metrics including SLA, RTO, and RPO.

Network Security closes the deck with 48 cards for 14%, focused on access control and encrypted transport. The cards drill authentication frameworks such as AAA and MFA, filtering in ACL, tunneling in VPN and IPsec, directory-backed authentication in RADIUS and TACACS+, and signed name resolution in DNSSEC.

The Network+ is dense with things you simply have to know cold — port numbers, the OSI layers, routing and switching terms, security acronyms, and troubleshooting commands.[1] Spaced flashcards are the most efficient way to keep it all fresh. Used alongside our practice test and study guide, they turn review time into measurable progress.

Network+ Flashcards by Domain

The cards are organized by the five official N10-009 domains. Drill the highest-weighted ones first — Network Troubleshooting and Networking Concepts make up nearly half the exam:[1]

Network+ flashcards by domain and weight
DomainExam weight
Network Troubleshooting24%
Networking Concepts23%
Network Implementation20%
Network Operations19%
Network Security14%

How to Get the Most Out of These Flashcards

  • Start with Network Troubleshooting. Its 50 cards map to the exam’s heaviest 24%, and the tool names carry into every other domain once you can recall them cold.
  • Type-drill the math and process cards. Fronts like VLSM and DORA are easy to recognize and hard to produce, so typing them from the definition exposes gaps that flipping hides.
  • Use Match for acronym clusters. Timed pairing works well on the authentication group, where RADIUS, TACACS+, and AAA blur together until you have seen them side by side repeatedly.
  • Move to the practice test when Quiz stops surprising you. Once Networking Concepts and Network Implementation cards come back clean, scenario questions are the better use of your time.
  • Rotate rather than grind. With 293 cards, work one domain per session, revisit missed cards the next day, and keep the study guide open for anything a card front leaves unexplained.

Network+ Flashcards FAQ

Hundreds of free Network+ flashcards, organized across all five N10-009 domains — Networking Concepts, Network Implementation, Network Operations, Network Security, and Network Troubleshooting. They're free with no account required.

Network+ flashcard bank

All 293 cards, by topic

A reference copy of every card in this deck. Each answer stays hidden until you choose to show it. To study with Flip, Match, Type and Quiz modes and track what you have mastered, use Study Flashcards at the top of the page.

Networking Concepts (91)

OSI model
Show answer

A seven-layer framework for network communication: Physical, Data Link, Network, Transport, Session, Presentation, Application (L1→L7).

OSI Layer 1
Show answer

Physical — bits on the medium: cables, connectors, radio, voltage, hubs, NICs, repeaters.

OSI Layer 2
Show answer

Data Link — local (MAC) addressing and framing on the link. Switches, bridges, 802.3, 802.11. PDU: frame.

OSI Layer 3
Show answer

Network — logical addressing and routing between networks. IP, ICMP, routers. PDU: packet.

OSI Layer 4
Show answer

Transport — end-to-end delivery, segmentation, and ports. TCP and UDP. PDU: segment/datagram.

OSI Layer 5
Show answer

Session — establishes, manages, and terminates sessions between applications (RPC, NetBIOS).

OSI Layer 6
Show answer

Presentation — translation, encryption/decryption, and compression (TLS, ASCII, JPEG).

OSI Layer 7
Show answer

Application — user-facing network services and protocols (HTTP, FTP, DNS, SMTP).

OSI mnemonic (L7→L1)
Show answer

All People Seem To Need Data Processing (Application, Presentation, Session, Transport, Network, Data Link, Physical).

Encapsulation
Show answer

Adding each layer's header to data as it moves down the stack: data → segment → packet → frame → bits.

PDU (Protocol Data Unit)
Show answer

The data unit at each OSI layer: bits (L1), frame (L2), packet (L3), segment/datagram (L4).

TCP
Show answer

Transmission Control Protocol — connection-oriented, reliable Layer 4 protocol using a three-way handshake, sequencing, acknowledgments, and retransmission.

UDP
Show answer

User Datagram Protocol — connectionless, best-effort Layer 4 protocol with low overhead; no handshake or acknowledgments.

TCP three-way handshake
Show answer

SYN → SYN-ACK → ACK. Establishes a reliable TCP connection before data flows.

TCP vs UDP
Show answer

TCP is reliable and connection-oriented (web, email, SSH); UDP is fast and connectionless (DNS, DHCP, VoIP, streaming).

IPv4 address
Show answer

A 32-bit logical address written as four dotted-decimal octets (e.g., 192.168.1.10), split into network and host portions.

IPv6 address
Show answer

A 128-bit address written in eight groups of hexadecimal (e.g., 2001:db8::1); vastly larger space, no NAT needed.

Subnet mask
Show answer

Marks which bits of an IP address are the network portion (1s) and which are the host portion (0s).

CIDR notation
Show answer

Classless Inter-Domain Routing — a slash and number (e.g., /24) showing how many leading bits are the network portion.

Usable hosts formula
Show answer

Usable hosts = 2 raised to the number of host bits − 2 (subtract the network and broadcast addresses).

/24 subnet
Show answer

Mask 255.255.255.0; 8 host bits; 254 usable hosts.

/30 subnet
Show answer

Mask 255.255.255.252; 2 host bits; 2 usable hosts — common for point-to-point links.

Default gateway
Show answer

The router IP a host sends traffic to when the destination is on a different subnet.

Private IP ranges (RFC 1918)
Show answer

10.0.0.0/8, 172.16.0.0/12, and 192.168.0.0/16 — internal use only, not internet-routable.

APIPA
Show answer

Automatic Private IP Addressing (169.254.0.0/16); self-assigned when no DHCP server responds — a DHCP-failure clue.

Loopback address
Show answer

127.0.0.1 (127.0.0.0/8) — tests the local TCP/IP stack on the host itself.

Broadcast address
Show answer

The last address in a subnet (all host bits = 1); reaches every host on that subnet.

Network address
Show answer

The first address in a subnet (all host bits = 0); identifies the subnet itself, not a host.

Port 20/21 (FTP)
Show answer

File Transfer Protocol — 20 is data, 21 is control. TCP. Unencrypted.

Port 22 (SSH)
Show answer

Secure Shell / SFTP / SCP — encrypted remote access and file transfer. TCP.

Port 23 (Telnet)
Show answer

Remote terminal access, unencrypted — avoid; use SSH instead. TCP.

Port 25 (SMTP)
Show answer

Simple Mail Transfer Protocol — sending email. TCP.

Port 53 (DNS)
Show answer

Domain Name System — name resolution. UDP (TCP for zone transfers / large responses).

Port 67/68 (DHCP)
Show answer

Dynamic Host Configuration Protocol — 67 server, 68 client. UDP.

Port 69 (TFTP)
Show answer

Trivial File Transfer Protocol — simple, no authentication. UDP.

Port 80 (HTTP)
Show answer

Hypertext Transfer Protocol — unencrypted web. TCP.

Port 123 (NTP)
Show answer

Network Time Protocol — clock synchronization. UDP.

Port 161/162 (SNMP)
Show answer

Simple Network Management Protocol — 161 polling, 162 traps. UDP.

Port 389 (LDAP)
Show answer

Lightweight Directory Access Protocol — directory services. TCP/UDP.

Port 443 (HTTPS)
Show answer

HTTP over TLS — encrypted web traffic. TCP.

Port 445 (SMB)
Show answer

Server Message Block — Windows file and printer sharing. TCP.

Port 514 (Syslog)
Show answer

Syslog — centralized event logging. UDP.

Port 636 (LDAPS)
Show answer

LDAP over TLS — secure directory services. TCP.

Port 3389 (RDP)
Show answer

Remote Desktop Protocol — Windows remote graphical access. TCP.

ICMP
Show answer

Internet Control Message Protocol — Layer 3 messaging used by ping and traceroute for errors and diagnostics.

Twisted-pair copper
Show answer

Cat 5e/6/6a/8 cabling; cheap and common, limited to about 100 m per run.

Single-mode fiber (SMF)
Show answer

Fiber with a tiny core and a laser source; carries signals over very long distances.

Multimode fiber (MMF)
Show answer

Fiber with a larger core and LED/VCSEL source; high speed over shorter distances.

RJ45 connector
Show answer

The 8-pin connector used to terminate twisted-pair copper Ethernet cable.

SFP / SFP+ / QSFP
Show answer

Hot-swappable transceiver modules that connect a device to fiber or copper at various speeds.

Star topology
Show answer

All nodes connect to a central switch; simple, but the central device is a single point of failure.

Mesh topology
Show answer

Many or all nodes interconnect; maximum redundancy but expensive and complex.

Spine-and-leaf
Show answer

A data-center fabric where each leaf switch connects to every spine switch; predictable low latency.

Three-tier architecture
Show answer

Core (fast backbone), distribution (policy/routing), and access (end-device connection) layers.

Collapsed core
Show answer

A design that merges the core and distribution layers into one for smaller networks.

North-south traffic
Show answer

Traffic between clients and servers, in and out of the data center (client ↔ server).

East-west traffic
Show answer

Traffic between servers within the data center (server ↔ server).

SDN
Show answer

Software-Defined Networking — separates the control plane (decisions) from the data plane (forwarding), managed centrally in software.

SD-WAN
Show answer

Software-Defined WAN — uses software to manage and optimize traffic across multiple WAN links (broadband, MPLS, LTE).

SASE
Show answer

Secure Access Service Edge — converges networking (SD-WAN) and security services in the cloud.

IaaS / PaaS / SaaS
Show answer

Cloud service models: Infrastructure, Platform, and Software as a Service — increasing levels of provider management.

Public / private / hybrid cloud
Show answer

Deployment models: shared provider, dedicated/internal, or a mix of both.

Infrastructure as code (IaC)
Show answer

Managing and provisioning network/device configuration through version-controlled code instead of manual setup.

VPC
Show answer

Virtual Private Cloud — an isolated, logically segmented network within a public cloud provider.

MTU
Show answer

Maximum Transmission Unit — the largest frame size that can be sent without fragmentation (typically 1500 bytes for Ethernet).

DoD / TCP-IP model layers
Show answer

Four layers: Link (Network Access), Internet, Transport, Application — maps onto the seven OSI layers.

Unicast
Show answer

One-to-one communication: a packet sent to a single destination host.

Broadcast
Show answer

One-to-all communication within a subnet (all hosts receive it). IPv4 only; IPv6 uses multicast instead.

Multicast
Show answer

One-to-many communication to a group of subscribed hosts (e.g., streaming, routing updates).

Anycast
Show answer

One-to-nearest communication: the same address is advertised from multiple locations; traffic goes to the closest.

Classful address Class A
Show answer

1.0.0.0–126.0.0.0, default mask /8; huge networks.

Classful address Class B
Show answer

128.0.0.0–191.255.0.0, default mask /16; medium networks.

Classful address Class C
Show answer

192.0.0.0–223.255.255.0, default mask /24; small networks.

VLSM
Show answer

Variable Length Subnet Masking — using different mask lengths to size subnets efficiently.

/25 subnet
Show answer

Mask 255.255.255.128; 7 host bits; 126 usable hosts; block size 128.

/26 subnet
Show answer

Mask 255.255.255.192; 6 host bits; 62 usable hosts; block size 64.

/27 subnet
Show answer

Mask 255.255.255.224; 5 host bits; 30 usable hosts; block size 32.

/28 subnet
Show answer

Mask 255.255.255.240; 4 host bits; 14 usable hosts; block size 16.

Block size shortcut
Show answer

Block size = 256 − the mask's interesting octet; subnets increment by the block size.

IPv6 link-local
Show answer

fe80::/10 — an automatically configured address used only on the local link.

IPv6 unique local
Show answer

fc00::/7 (commonly fd00::/8) — the IPv6 equivalent of RFC 1918 private addresses.

SLAAC
Show answer

Stateless Address Autoconfiguration — how IPv6 hosts self-assign an address using router advertisements.

Dual stack
Show answer

Running IPv4 and IPv6 simultaneously on the same devices during migration.

FQDN
Show answer

Fully Qualified Domain Name — the complete name of a host including its domain (e.g., host.example.com).

HTTP vs HTTPS
Show answer

HTTP (port 80) is unencrypted; HTTPS (port 443) wraps HTTP in TLS for confidentiality and integrity.

POP3 / IMAP
Show answer

Email retrieval protocols — POP3 (110) downloads and often removes mail; IMAP (143) syncs mail on the server.

Proxy server
Show answer

An intermediary that forwards client requests, providing caching, filtering, and anonymity.

Load balancer
Show answer

Distributes incoming traffic across multiple servers for performance and availability.

CDN
Show answer

Content Delivery Network — geographically distributed servers that cache content near users.

IDS vs IPS
Show answer

An IDS detects and alerts on suspicious traffic; an IPS sits inline and can actively block it.

NAS vs SAN
Show answer

NAS provides file-level storage over the LAN; a SAN provides block-level storage over a dedicated high-speed network.

Network Implementation (58)

Router
Show answer

A Layer 3 device that forwards packets between different networks using IP addresses and a routing table.

Switch
Show answer

A Layer 2 device that forwards frames within a network using MAC addresses and a MAC address table.

Layer 3 switch
Show answer

A switch that also performs routing in hardware, including inter-VLAN routing.

Hub
Show answer

An obsolete Layer 1 device that repeats incoming bits to every port, creating one collision domain.

MAC address
Show answer

A 48-bit hardware address burned into a NIC, used for Layer 2 delivery on the local link.

ARP
Show answer

Address Resolution Protocol — maps a known IPv4 address to its MAC address on the local network.

Static routing
Show answer

Manually configured routes; predictable and low-overhead, but no automatic adaptation to changes.

Dynamic routing
Show answer

Routes learned automatically via protocols (OSPF, EIGRP, BGP, RIP) that adapt to topology changes.

OSPF
Show answer

Open Shortest Path First — a fast link-state interior gateway protocol using cost (bandwidth) as its metric.

BGP
Show answer

Border Gateway Protocol — the path-vector exterior gateway protocol that routes between autonomous systems on the internet.

EIGRP
Show answer

Enhanced Interior Gateway Routing Protocol — Cisco's advanced distance-vector IGP using a composite metric.

RIP
Show answer

Routing Information Protocol — a simple distance-vector IGP using hop count (max 15); rarely used today.

Administrative distance
Show answer

A router's trust ranking of routing sources; lower is preferred when multiple protocols offer a route.

NAT
Show answer

Network Address Translation — maps private IP addresses to public ones at the network edge.

PAT
Show answer

Port Address Translation (NAT overload) — lets many private hosts share one public IP using unique port numbers.

FHRP (VRRP/HSRP)
Show answer

First Hop Redundancy Protocols — provide a redundant default gateway so the network survives a router failure.

VLAN
Show answer

Virtual LAN — a logical Layer 2 segment that splits one switch into multiple broadcast domains.

802.1Q
Show answer

The IEEE standard that tags Ethernet frames with a VLAN ID so VLANs span trunk links between switches.

Trunk port
Show answer

A switch port that carries traffic for multiple VLANs (tagged with 802.1Q) between switches.

Access port
Show answer

A switch port that belongs to a single VLAN and connects to an end device.

Native VLAN
Show answer

The VLAN whose traffic is sent untagged across a trunk link.

Inter-VLAN routing
Show answer

Routing between VLANs using a router-on-a-stick (subinterfaces) or a Layer 3 switch (SVIs).

STP
Show answer

Spanning Tree Protocol — prevents Layer 2 loops by electing a root bridge and blocking redundant paths.

RSTP (802.1w)
Show answer

Rapid Spanning Tree Protocol — a faster-converging version of STP.

Root bridge
Show answer

The switch with the lowest bridge ID; the reference point STP uses to build a loop-free topology.

Link aggregation (LACP)
Show answer

Bundling multiple physical links into one logical link for more bandwidth and redundancy (IEEE 802.3ad).

Port mirroring (SPAN)
Show answer

Copies traffic from one or more ports to a monitoring port for analysis.

PoE (802.3af/at/bt)
Show answer

Power over Ethernet — delivers electrical power and data over a single cable to APs, phones, and cameras.

Jumbo frames
Show answer

Ethernet frames larger than the standard 1500-byte MTU (up to ~9000 bytes); improve throughput for storage networks.

802.11 standards
Show answer

The IEEE wireless LAN family: a/b/g/n (Wi-Fi 4)/ac (Wi-Fi 5)/ax (Wi-Fi 6/6E).

Wi-Fi 6 (802.11ax)
Show answer

The current mainstream Wi-Fi standard; works on 2.4/5 GHz (and 6 GHz as 6E) with higher efficiency in dense areas.

2.4 GHz band
Show answer

Longer range and better penetration but slower; only channels 1, 6, 11 are non-overlapping — congested.

5 GHz band
Show answer

Faster with many non-overlapping channels but shorter range than 2.4 GHz.

CSMA/CA
Show answer

Carrier-Sense Multiple Access with Collision Avoidance — the wireless access method (collisions can't be detected on air).

SSID
Show answer

Service Set Identifier — the human-readable name of a wireless network.

WPA2
Show answer

Wi-Fi Protected Access 2 — uses AES (CCMP); the older secure standard, vulnerable to offline PSK guessing.

WPA3
Show answer

The current Wi-Fi security standard; uses SAE to resist offline guessing and adds forward secrecy.

WEP
Show answer

Wired Equivalent Privacy — an obsolete, easily cracked wireless encryption; never use it.

IDF / MDF
Show answer

Intermediate and Main Distribution Frames — wiring closets where cabling and equipment are terminated.

UPS
Show answer

Uninterruptible Power Supply — battery backup that keeps equipment running through power interruptions.

Router-on-a-stick
Show answer

Inter-VLAN routing using one physical router interface divided into VLAN subinterfaces.

SVI
Show answer

Switched Virtual Interface — a virtual Layer 3 interface on a switch used for inter-VLAN routing.

BPDU Guard
Show answer

Disables a port that receives a BPDU, protecting the STP topology at the edge.

PortFast
Show answer

Lets an edge access port skip STP listening/learning and go straight to forwarding.

Auto-MDIX
Show answer

Automatically detects and corrects cable type (straight-through vs crossover) on a port.

Full duplex
Show answer

Both ends can transmit and receive simultaneously; no collisions on a switched link.

Half duplex
Show answer

Only one end transmits at a time; used by hubs and shared media, prone to collisions.

Default gateway redundancy
Show answer

Provided by FHRPs like VRRP and HSRP via a shared virtual IP.

BSSID
Show answer

The MAC address of a wireless access point's radio, identifying a basic service set.

ESSID
Show answer

The SSID shared by multiple APs forming one extended wireless network.

Channel bonding
Show answer

Combining adjacent Wi-Fi channels for more bandwidth (wider channels = higher throughput).

Omnidirectional antenna
Show answer

Radiates signal evenly in all directions; good general coverage.

Directional (Yagi) antenna
Show answer

Focuses signal in one direction for longer-range, point-to-point links.

WPA3-Enterprise
Show answer

WPA3 mode using 802.1X/RADIUS for individual authentication, with up to 192-bit security.

Captive portal
Show answer

A web page that requires sign-in or acceptance before granting wireless network access.

Wireless site survey
Show answer

Measuring signal, interference, and coverage to plan AP placement and channels.

DTP
Show answer

Dynamic Trunking Protocol — auto-negotiates trunks; disable it to prevent VLAN hopping.

Spanning tree root election
Show answer

STP picks the switch with the lowest bridge priority (then lowest MAC) as the root bridge.

Network Operations (46)

DHCP
Show answer

Dynamic Host Configuration Protocol — automatically assigns IP, mask, gateway, and DNS to clients.

DORA
Show answer

The DHCP exchange: Discover, Offer, Request, Acknowledge.

DHCP relay (IP helper)
Show answer

Forwards DHCP requests across subnets to a centralized DHCP server.

DNS
Show answer

Domain Name System — resolves human-readable names to IP addresses using a hierarchy of servers.

DNS A record
Show answer

Maps a hostname to an IPv4 address.

DNS AAAA record
Show answer

Maps a hostname to an IPv6 address.

DNS CNAME record
Show answer

An alias that points one name to another canonical name.

DNS MX record
Show answer

Specifies the mail server(s) for a domain.

DNS PTR record
Show answer

Maps an IP address back to a hostname (reverse DNS).

DNS NS record
Show answer

Identifies the authoritative name servers for a domain.

SNMP
Show answer

Simple Network Management Protocol — monitors and manages devices; manager polls UDP 161, agents send traps on UDP 162.

SNMPv3
Show answer

The secure version of SNMP, adding authentication and encryption; prefer it over v1/v2c.

Syslog
Show answer

A standard for centralized event/error logging from network devices (UDP 514).

NetFlow / flow data
Show answer

Records traffic flows so you can analyze who is sending how much data and to where.

SIEM
Show answer

Security Information and Event Management — aggregates and correlates logs/alerts across the network.

Baseline
Show answer

A reference of normal performance/behavior used to detect anomalies later.

Logical network diagram
Show answer

Shows IP addressing, VLANs, routing, and data flow — the network's logical structure.

Physical network diagram
Show answer

Shows actual devices, ports, and cabling — racks, runs, and connections.

IPAM
Show answer

IP Address Management — tools/processes for tracking and assigning IP address space.

SLA
Show answer

Service Level Agreement — a contract defining expected uptime, performance, and support response.

High availability (HA)
Show answer

Designing systems with redundancy so a single failure does not cause an outage.

Active-active
Show answer

A redundancy model where multiple nodes share the load simultaneously.

Active-passive
Show answer

A redundancy model where a standby node takes over only when the active node fails.

RTO
Show answer

Recovery Time Objective — the maximum acceptable time to restore service after an outage.

RPO
Show answer

Recovery Point Objective — the maximum acceptable amount of data loss (how far back you recover).

MTTR
Show answer

Mean Time To Repair — the average time to fix a failed component.

MTBF
Show answer

Mean Time Between Failures — the average operating time between failures (a reliability measure).

NAC
Show answer

Network Access Control — enforces policy (posture, identity) before a device is allowed onto the network.

802.1X
Show answer

Port-based network access control that authenticates a device before granting network access (often via RADIUS).

Port security
Show answer

A switch feature limiting which/how many MAC addresses may use a port, defending against MAC flooding.

EOL / EOS
Show answer

End of Life / End of Support — lifecycle milestones after which a product no longer receives updates.

Quality of Service (QoS)
Show answer

Prioritizing certain traffic (e.g., VoIP) to guarantee performance under congestion.

Traffic shaping
Show answer

Delaying lower-priority packets to smooth bandwidth use and meet QoS targets.

Bandwidth management
Show answer

Controlling how much capacity applications or users may consume.

Configuration management
Show answer

Tracking and controlling device configurations and changes (often version-controlled).

Change management
Show answer

A formal process for reviewing and approving network changes to reduce risk.

Hot site
Show answer

A fully equipped, ready-to-run backup site for fast disaster recovery.

Cold site
Show answer

A backup site with space and power but no preinstalled equipment; slow to bring online.

Warm site
Show answer

A backup site partially equipped; a middle ground between hot and cold.

Full backup
Show answer

A complete copy of all selected data.

Incremental backup
Show answer

Backs up only data changed since the last backup of any type; fast backup, slower restore.

Differential backup
Show answer

Backs up data changed since the last full backup; slower backup, faster restore than incremental.

DHCP reservation
Show answer

A fixed IP a DHCP server always assigns to a specific MAC address.

DHCP lease
Show answer

The time period a client may use an assigned DHCP address before renewing.

Network policy / AUP
Show answer

Acceptable Use Policy and related rules governing how the network may be used.

Environmental sensors
Show answer

Monitor temperature, humidity, and power in equipment rooms to prevent failures.

Network Security (48)

CIA triad
Show answer

Confidentiality, Integrity, and Availability — the three core goals of information security.

Confidentiality
Show answer

Ensuring information is accessible only to authorized parties (e.g., via encryption).

Integrity
Show answer

Ensuring data is not altered without authorization (e.g., via hashing).

Availability
Show answer

Ensuring systems and data are accessible when needed (e.g., via redundancy).

AAA
Show answer

Authentication, Authorization, and Accounting — who you are, what you can do, and logging it.

RADIUS
Show answer

Remote Authentication Dial-In User Service — a common AAA protocol; often used with 802.1X.

TACACS+
Show answer

A Cisco AAA protocol that separates authentication, authorization, and accounting and encrypts the full payload.

Zero trust
Show answer

A model that trusts no user or device by default and verifies every access request (NIST SP 800-207).

Least privilege
Show answer

Granting users and systems only the access they actually need.

Defense in depth
Show answer

Layering multiple security controls so no single failure exposes the network.

MFA
Show answer

Multi-Factor Authentication — requiring two or more factors (something you know/have/are).

Firewall
Show answer

A device or software that permits or blocks traffic based on rules.

Stateful firewall
Show answer

Tracks the state of active connections and allows return traffic for established sessions.

Stateless firewall
Show answer

Filters each packet independently against rules, without tracking connection state.

ACL
Show answer

Access Control List — an ordered set of permit/deny rules filtering traffic by address, port, or protocol.

VPN
Show answer

Virtual Private Network — an encrypted tunnel carrying private traffic across a public network.

IPsec
Show answer

A suite securing IP traffic with authentication (AH) and encryption (ESP); common for site-to-site VPNs.

Site-to-site VPN
Show answer

A persistent encrypted tunnel connecting two networks (e.g., two offices).

Client (remote-access) VPN
Show answer

An encrypted tunnel from an individual device into the corporate network.

DMZ / screened subnet
Show answer

A buffer network exposing public-facing servers while isolating them from the internal LAN.

Network segmentation
Show answer

Dividing a network into zones so a breach in one area cannot spread freely.

DoS attack
Show answer

Denial of Service — overwhelming a target so legitimate users cannot access it.

DDoS attack
Show answer

Distributed Denial of Service — many compromised hosts flood a target simultaneously.

On-path attack
Show answer

Formerly man-in-the-middle — an attacker intercepts or alters traffic between two parties.

ARP spoofing
Show answer

Sending forged ARP replies to associate the attacker's MAC with another host's IP, enabling on-path attacks.

DNS poisoning
Show answer

Corrupting DNS data so name lookups resolve to a malicious server.

MAC flooding
Show answer

Overwhelming a switch's MAC table so it floods traffic, letting an attacker capture it. Countered by port security.

VLAN hopping
Show answer

Gaining access to traffic on other VLANs (via double-tagging or switch spoofing). Counter with a unique native VLAN and disabling DTP.

Rogue AP
Show answer

An unauthorized access point connected to the network, creating a security hole.

Evil twin
Show answer

A malicious access point impersonating a legitimate SSID to capture credentials and traffic.

Dynamic ARP Inspection (DAI)
Show answer

A switch feature that validates ARP packets to stop ARP spoofing.

DHCP snooping
Show answer

A switch feature that blocks rogue DHCP servers by trusting only designated ports.

Phishing
Show answer

A social-engineering attack tricking users into revealing credentials or clicking malicious links.

DNSSEC
Show answer

DNS Security Extensions — adds cryptographic signatures to DNS data to prevent poisoning.

Defense control types
Show answer

Preventive, detective, and corrective controls; also physical, technical, and administrative.

Hashing
Show answer

One-way function producing a fixed-size digest to verify integrity (e.g., SHA-256).

Encryption (symmetric)
Show answer

Uses one shared key to encrypt and decrypt; fast (e.g., AES).

Encryption (asymmetric)
Show answer

Uses a public/private key pair; the basis of TLS and digital signatures (e.g., RSA).

Geofencing
Show answer

Restricting access based on a device's physical location.

Honeypot
Show answer

A decoy system that lures attackers to study them and divert them from real assets.

Screened subnet (DMZ) purpose
Show answer

Isolates internet-facing servers so a compromise there can't directly reach the internal LAN.

Port-based vs MAC filtering
Show answer

802.1X authenticates the device/user; MAC filtering allows/denies by hardware address (weak, spoofable).

Social engineering
Show answer

Manipulating people into breaking security (phishing, pretexting, tailgating).

Tailgating
Show answer

Following an authorized person through a secure door without credentials.

Brute-force attack
Show answer

Trying many passwords/keys until one works; countered by lockouts and strong passwords/MFA.

Deauthentication attack
Show answer

Forcing wireless clients off an AP, often to set up an evil twin or capture handshakes.

Spoofing
Show answer

Faking a source identity (IP, MAC, ARP, or DNS) to bypass controls or intercept traffic.

Posture assessment
Show answer

Checking a device's security state (patches, AV) before NAC grants access.

Network Troubleshooting (50)

Troubleshooting methodology
Show answer

CompTIA's 7 steps: identify the problem; theorize a cause; test it; plan; implement or escalate; verify; document.

Step 1: Identify the problem
Show answer

Gather information, question users, identify symptoms, and determine if anything recently changed.

Step 2: Theory of probable cause
Show answer

Question the obvious; consider multiple causes (top-down, bottom-up, or divide and conquer the OSI stack).

Step 3: Test the theory
Show answer

Confirm the cause; if not confirmed, form a new theory or escalate.

Step 4: Plan of action
Show answer

Establish a plan to resolve the problem and identify the potential effects of the fix.

Step 5: Implement or escalate
Show answer

Apply the solution, or escalate to someone with more access or expertise.

Step 6: Verify functionality
Show answer

Confirm the fix works and, if applicable, implement preventive measures.

Step 7: Document
Show answer

Record the findings, actions, and outcomes — always the last step.

Attenuation
Show answer

Loss of signal strength over distance; a Layer 1 cabling problem.

Crosstalk
Show answer

Interference between adjacent wire pairs in a cable, degrading the signal.

EMI
Show answer

Electromagnetic Interference — outside electrical noise that corrupts a copper signal; reroute away from sources.

Duplex mismatch
Show answer

When the two ends of a link disagree on half/full duplex, causing collisions, errors, and poor throughput.

Speed mismatch
Show answer

When link ends negotiate different speeds, causing the link to fail or perform poorly.

TX/RX reversed
Show answer

Transmit and receive pairs are swapped, preventing the link from coming up (fixed by a crossover or auto-MDIX).

Cable tester
Show answer

A tool that verifies continuity and wiring of a copper cable to find opens, shorts, and miswires.

Tone generator and probe
Show answer

A 'toner' used to trace and identify a specific cable run among many.

OTDR
Show answer

Optical Time-Domain Reflectometer — locates breaks and measures loss on fiber runs.

Latency
Show answer

The delay for data to travel from source to destination (round-trip time).

Jitter
Show answer

Variation in packet delay over time — especially disruptive to VoIP and video.

Packet loss
Show answer

Packets that fail to reach the destination, caused by congestion, errors, or faulty hardware.

Bandwidth saturation
Show answer

When a link is fully utilized, causing queuing, latency, and loss.

CRC errors
Show answer

Cyclic Redundancy Check failures indicating corrupted frames — often from a bad cable, EMI, or duplex mismatch.

ping
Show answer

Uses ICMP echo request/reply to test reachability and round-trip time to a host.

traceroute / tracert
Show answer

Maps the per-hop path to a destination to find where traffic stops.

nslookup / dig
Show answer

Query DNS to diagnose name-resolution problems.

ipconfig / ifconfig / ip
Show answer

Show and manage a host's IP address, mask, gateway, and DNS (spot an APIPA address).

arp -a
Show answer

Displays the local IP-to-MAC address mapping table.

netstat
Show answer

Shows active network connections, listening ports, and protocol statistics.

tcpdump / Wireshark
Show answer

Capture and inspect actual packets to diagnose hard problems at the protocol level.

nmap
Show answer

A scanner that discovers hosts, open ports, and services on a network.

iperf
Show answer

A tool that measures achievable bandwidth/throughput between two endpoints.

Pings by IP but not by name
Show answer

A classic symptom of a DNS problem (Layers 1-3 work; name resolution fails).

APIPA address (169.254.x.x)
Show answer

Indicates the client could not reach a DHCP server.

Incorrect default gateway
Show answer

A misconfigured gateway lets local communication work but blocks access to other networks/the internet.

Rogue DHCP server
Show answer

An unauthorized DHCP server handing out bad addresses; causes intermittent connectivity. Counter with DHCP snooping.

DHCP scope exhaustion
Show answer

When all addresses in a DHCP pool are leased, new clients can't get an IP.

Top-down vs bottom-up
Show answer

Troubleshooting approaches that work the OSI model from L7 down or L1 up to localize a fault.

Show interface counters
Show answer

CLI output revealing errors (CRC, runts, giants), drops, and utilization on a port.

Runts and giants
Show answer

Frames smaller than the minimum or larger than the maximum size — signs of errors or duplex/MTU issues.

Light meter (fiber)
Show answer

Measures optical power to confirm a fiber link's signal strength is within tolerance.

Multimeter
Show answer

Measures voltage, current, and resistance; used to check cabling and power.

Loopback plug
Show answer

A connector that loops a port's transmit to its receive to test the port itself.

Bad SFP / transceiver
Show answer

A faulty optic causing a down or error-prone link; swap to isolate.

Asymmetrical routing
Show answer

Traffic taking different paths each direction, which can break stateful firewalls.

Blocked port / ACL
Show answer

A firewall rule or ACL silently dropping traffic, mimicking a connectivity outage.

Incorrect subnet mask
Show answer

A wrong mask makes a host miscalculate local vs remote, breaking some communication.

Wireless interference
Show answer

Overlapping channels, microwaves, or Bluetooth degrading 2.4 GHz Wi-Fi; fix with channel planning and 5 GHz.

Captive portal not loading
Show answer

Often a DNS or HTTPS-redirect issue on a guest network.

hostname command
Show answer

Displays or sets the device's network name.

route / show ip route
Show answer

Displays the routing table to verify how a device reaches destinations.

References

  1. 1.CompTIA. “Network+ (N10-009) Certification Exam Objectives.” comptia.org. ↑
  2. 2.Internet Engineering Task Force. “RFC 1918 — Address Allocation for Private Internets.” rfc-editor.org. ↑
  3. 3.Institute of Electrical and Electronics Engineers. “IEEE 802.1Q — Bridges and Bridged Networks (VLANs).” standards.ieee.org. ↑
Career Employer

Career Employer is the ultimate resource to help you get started working the job of your dreams. We cover topics from general career information, career searching, exam preparation with free study materials, career interviewing, and becoming successful in your career of choice.

Follow Us:

All Posts

Career Employer’s Editorial Process

Here at Career Employer, we focus a lot on providing factually accurate information that is always up to date. We strive to provide correct information using strict editorial processes, article editing, and fact-checking for all of the information found on our website. We only utilize trustworthy and relevant resources. To find out more, make sure to read our full editorial process page here.