certslothcertsloth
200-301 v1.1/Topic 08

Cisco / Associate

Network Operations and Recovery

2 min read5 recall promptsReviewed 2026-10-10

Memory hook: Baseline normal; control change; restore what matters.

Must remember

Maintain asset inventory, IPAM, topology, cable/rack diagrams, wireless surveys and current configurations. Know hardware/software end-of-support dates and preserve recoverable configuration backups. Decommissioning includes access revocation, data sanitization, inventory updates and removing obsolete monitoring/DNS entries.

Monitoring sources answer different questions: SNMP polls counters/state, traps notify events, flow records summarize communications, packet captures expose visible protocol detail, syslog centralizes events and APIs support structured telemetry. SNMPv3 can provide authentication and privacy; older community-string modes are weaker. Port mirroring copies selected traffic to an analysis port but may lose packets if oversubscribed.

Establish baselines for utilization, latency, jitter, loss, errors and availability. Thresholds without context create noise. Correlate changes and multiple sources; a high CPU graph is a symptom, not a root cause by itself.

Change management includes authorization, impact, dependency review, testing, maintenance windows, backups, rollback and validation. Store production, baseline and backup configurations distinctly. Emergency changes still need an accountable process and retrospective records.

RPO is tolerable data loss; RTO target restoration time. MTTR measures average repair/recovery time as defined; MTBF estimates time between failures. Do not confuse measured averages with contractual targets. Active-active uses multiple serving systems; active-passive keeps a standby. Recovery sites trade readiness and cost.

Secure remote administration through approved VPN/SSH/API or console access with individual accounts and least privilege. Out-of-band access helps recover from production network failures. Test restoration of configuration, routing, DNS, identity, monitoring and application reachability together.

Choose under exam pressure

Requirement Choice and reason
Identify traffic sources without full payload capture Flow telemetry.
Recover after a bad change Known-good configuration and tested rollback.
Production network unavailable Protected out-of-band management.

Traps

  • Monitoring without baselines and response ownership produces dashboards, not reliability.
  • A configuration backup must match hardware/software and be restorable.

Active recall

1. SNMP polling versus traps?

Polling asks for information; traps send event notifications.

2. Why can a mirrored capture miss traffic?

The mirror destination or capture system may be oversubscribed.

3. RTO versus MTTR?

RTO is a recovery target; MTTR is a measured/estimated average recovery metric.

4. What should follow a network change?

Verification of intended behavior and monitoring for adverse effects.

5. Why preserve an out-of-band path?

To administer devices when the normal forwarding network is unavailable.

Sources

CLOSE THE NOTES. EXPLAIN THE CHOICE.

How well could you recall it?

Your next review is based on this answer. Progress stays in this browser.

Search across every published topic.