certslothcertsloth
← 200-301 v1.1 overview

Cisco Certified Network Associate / STUDY TOOLS

200-301 v1.1 quick review

Targets v1.1, including AI/ML and Terraform concepts. Cisco announces v2.0 testing from 3 February 2027. Do not assume this v1.1 map covers the new blueprint; verify your booked version. Practise configure-and-verify objectives in a simulator or lab.

Reviewed 10 October 2026 against the linked published scope. Domains: fundamentals 20%, access 20%, IP connectivity 25%, IP services 10%, security 15%, automation 10%.

Memory hook: Longest prefix chooses the route; VLANs separate links; policy controls access.

Read the essentials, cover the answers and explain the decision aloud. Open the topic summaries below whenever a distinction is unclear.

Network fundamentals and access

  • A switch learns source MAC addresses, floods appropriate unknown/broadcast traffic and forwards known destinations. A router separates IP networks. IPv4 ARP resolves a local next-hop MAC; IPv6 Neighbor Discovery uses ICMPv6.
  • Read prefix length before host counts. Conventional IPv4 usable hosts are 2^(32-prefix) - 2, with /31 and /32 exceptions. Know RFC1918 ranges, IPv6 link-local/global/unique-local addressing, multicast and the absence of IPv6 broadcast.
  • Match cable/transceiver, speed and duplex; interface errors and discards imply different faults. PoE also needs sufficient power budget. show interfaces and show ip interface brief reveal different levels of detail.
  • An access port belongs to its client VLAN; an 802.1Q trunk carries allowed VLANs and handles its native VLAN according to configuration. A native mismatch or omitted allowed VLAN can break selected traffic while the physical link stays up.
  • STP elects the lowest bridge ID as root and selects loop-free paths. PortFast is for suitable edge ports; BPDU Guard can disable a protected port receiving BPDUs. Neither replaces correct topology design.
  • LACP active initiates negotiation; passive responds. At least one side must initiate. EtherChannel member settings must agree; hashing usually places one flow on one member link.
  • Wireless design considers channel/interference, SSID, security, roaming and controller/AP roles. A WLC can centralize control; flexibly placed forwarding does not mean every frame must always traverse the controller.

IP connectivity and services

  • Forwarding chooses the longest matching prefix. For competing routes to the same prefix, administrative distance selects between sources, then the relevant routing protocol uses its metric. Connected AD 0, static 1 and OSPF 110 are common defaults.
  • Static routes need a valid next hop or exit path. A floating static route has deliberately higher distance for backup. Defaults are 0.0.0.0/0 and ::/0; a black-hole route discards traffic intentionally.
  • Single-area OSPF builds adjacencies, exchanges topology and computes cost-based paths. Diagnose area, subnet, timers, network type, authentication and MTU. Router IDs must be unique. DR/BDR elections apply to appropriate multiaccess networks, not every OSPF link.
  • First-hop redundancy supplies a virtual gateway so hosts can keep one default-gateway address across a router failure. It is separate from learning remote network routes.
  • DHCP supplies addresses/options; a relay forwards requests between subnets. DNS resolves names; NTP synchronizes clocks; SNMP provides management information; syslog sends event messages. Match ports and protected versions to their purpose.
  • NAT maps address identities; PAT distinguishes sessions with ports. QoS classifies/marks, queues and may police/shape; shaping buffers to smooth traffic while policing typically drops or remarks excess.

Security and programmability

  • Standard IPv4 ACLs match source address; extended ACLs can match protocol, source/destination and ports. Rules are processed in order, with an implicit deny when nothing permits. A wildcard 0 means compare that bit; 1 means ignore it.
  • AAA separates authentication, authorization and accounting. Restrict management interfaces, use SSH and least privilege. DHCP snooping builds trusted binding information; Dynamic ARP Inspection uses relevant bindings/policy; port security restricts allowed source MAC behavior.
  • A controller's northbound API connects applications; southbound interfaces manage devices. REST commonly uses HTTP methods: GET read, POST create/action, PUT replace and DELETE remove. JSON objects use key/value pairs; arrays are ordered lists.
  • Ansible applies automation through inventory/playbooks; Terraform manages declared resource lifecycles and state. AI/ML can assist analysis, but generated configurations and predictions require verification.
  • Inspect show vlan brief, show interfaces trunk, show etherchannel summary, show spanning-tree, show ip route, show ip ospf neighbor and ACL counters before guessing. Save intended running changes to startup configuration when persistence is required.

Traps

  • A /24 wins over a /0 before administrative distance is compared.
  • Two passive LACP ends do not initiate negotiation. VLAN separation alone is not encryption.
  • An ACL on the wrong interface or direction may be syntactically valid and operationally useless.

Final active recall

1. A /24 OSPF route and /0 static both match. Which forwards the packet?

The /24, because it is more specific.

2. Two LACP passive interfaces form a bundle?

Not through negotiation alone; an active side must initiate.

3. A host reaches its VLAN peers but no other network. What do you check?

Host default gateway, gateway interface/VLAN status, routing and relevant ACLs.

4. OSPF peers never become fully adjacent. What evidence matters?

Interface network type, area, timers, authentication, router IDs, subnet/MTU and neighbor state.

5. What does wildcard 0.0.0.255 mean for an IPv4 ACL address?

Compare the first 24 bits and ignore the last 8.

Sources and further practice

Every topic at a glance

Open any topic to revisit its essential facts, decisions and exam traps. Use the full topic for active recall and supporting references.

01 · Models, Packets and Network Devices

Memory hook: Name the layer, then name the job.

Must remember

OSI layer Remember
7 Application Protocols used by applications, such as HTTP and DNS.
6 Presentation Data representation, encoding and related transformation concepts.
5 Session Dialog/session coordination concepts.
4 Transport TCP/UDP, ports and end-to-end transport behavior.
3 Network IP addressing and routing between networks.
2 Data link Local frames, MAC addresses, switching and VLANs.
1 Physical Signals, media, connectors and bit transmission.

The TCP/IP model groups functions differently; real protocols do not always fit neatly into one textbook box. Encapsulation adds headers as data descends the stack. On a routed path, link-layer addresses change at each link; the IP destination normally remains the end host unless translation/tunneling changes it.

TCP establishes a connection, sequences bytes, acknowledges delivery and handles retransmission/flow control. UDP sends datagrams without those built-in guarantees; an application protocol can add its own reliability. TCP reliability does not mean a business transaction executed exactly once.

A switch learns source MAC addresses and forwards frames within its Layer 2 domain. A router selects next hops between IP networks. A multilayer switch can do both. Firewalls enforce traffic policy; proxies terminate/mediate connections; load balancers distribute service traffic. NAS provides file access, while a SAN commonly presents block storage over a storage network.

Unicast addresses one recipient; broadcast a local IPv4 broadcast domain; multicast a group; anycast the routing-selected instance of a shared address. IPv6 uses multicast rather than broadcast. Routers normally separate broadcast domains.

Star, mesh, hub-and-spoke, spine-leaf, three-tier and collapsed-core designs trade cost, fault paths and scale. A logical topology and a physical cabling diagram describe different views.

Choose under exam pressure

Requirement Choice and reason
Forward between IP subnets A routing function.
Share files with clients NAS/file service rather than raw block storage.
Reach a nearby service instance using the same address Anycast with appropriate routing.

Traps

  • A switch can implement several layers; identify the function being tested.
  • UDP is not automatically inappropriate for reliable applications.

Practise this topic

02 · IPv4, IPv6 and Subnetting

Memory hook: Prefix is the boundary; longest match wins.

Must remember

IPv4 has 32 bits. CIDR /n reserves n network bits, leaving 32-n host bits. A conventional IPv4 subnet has 2^(32-n) addresses and usually two reserved endpoints. /31 point-to-point and /32 host routes are exceptions to the usual minus-two rule.

Worked example: 192.168.10.77/26 has blocks of 64: network .64, broadcast .127, ordinary hosts .65–.126, 62 usable. Four /26 networks fit within a /24. For VLSM, allocate the largest required blocks first and check overlap.

Range Meaning
10.0.0.0/8, 172.16.0.0/12, 192.168.0.0/16 RFC1918 private addresses; not public Internet destinations.
169.254.0.0/16 IPv4 link-local/APIPA; often a DHCP failure clue.
127.0.0.0/8 IPv4 loopback.
224.0.0.0/4 IPv4 multicast.
::1 / :: IPv6 loopback / unspecified address.
fe80::/10 IPv6 link-local.
fc00::/7 IPv6 unique-local range.
ff00::/8 IPv6 multicast.

IPv6 uses 128 bits in hexadecimal groups. Remove leading zeros and compress one consecutive run of zero groups with ::; using it twice would make the address ambiguous. Many LAN subnets use /64, but do not assume every IPv6 prefix is /64.

ARP discovers IPv4 next-hop MAC addresses on a local link. IPv6 Neighbor Discovery uses ICMPv6; blocking all ICMPv6 can break normal operation. Router advertisements supply on-link/default-router information and can support SLAAC. DHCPv6 does not replace every router-advertisement function.

Historical class A/B/C boundaries are vocabulary; current route decisions use actual prefixes. Two hosts with mismatched masks can disagree about whether traffic is local. Verify address, prefix, gateway and duplicate-address evidence together.

Choose under exam pressure

Requirement Choice and reason
Need 50 ordinary IPv4 hosts A /26 provides 62 usable addresses.
Host has 169.254 address unexpectedly Investigate DHCP/link configuration.
IPv6 address works locally but not remotely Check router advertisements/default route and policy.

Traps

  • 172.16/12 covers 172.16 through 172.31, not all 172 addresses.
  • A default gateway must be reachable through the host’s local routing configuration.

Practise this topic

03 · Ports, DNS, DHCP and Time

Memory hook: Resolve the name, obtain the lease, trust the clock.

Must remember

Service Conventional port(s)
FTP / SSH-SFTP / Telnet TCP 21 control (FTP data varies) / 22 / 23.
SMTP / submission TCP 25 / 587; implicit TLS submission commonly 465.
DNS UDP and TCP 53.
DHCPv4 / DHCPv6 UDP 67 server, 68 client / 547 server, 546 client.
HTTP / HTTPS 80 / 443; HTTP/3 uses QUIC over UDP 443.
POP3 / IMAP TCP 110 / 143; implicit TLS 995 / 993.
SNMP queries / traps Usually UDP 161 / 162.
LDAP / LDAPS 389 / 636.
SMB / RDP TCP 445 / TCP and UDP 3389.
NTP / SIP UDP 123 / commonly 5060, TLS 5061.

Ports are conventions, not proof of application identity. Secure FTP (SFTP over SSH) differs from FTP with TLS (FTPS).

DNS A/AAAA map names to IPv4/IPv6; CNAME aliases another name; MX specifies mail exchangers; NS delegates authoritative service; PTR supports reverse lookup; TXT carries text used by policies and verification. A resolver asks authoritative servers and caches answers according to TTL. DNSSEC authenticates signed DNS data; it does not encrypt ordinary DNS queries. Encrypted DNS protects the resolver connection through its selected protocol.

DHCPv4 commonly follows Discover, Offer, Request, Acknowledge. Scopes define pools, options, exclusions and reservations. A relay forwards requests across routed boundaries. Exhausted pools, rogue servers, wrong options and blocked relay paths produce different symptoms. Reservations provide predictable leases, not static manual configuration on the host.

NTP synchronizes time broadly; PTP supports more precise timing in suitable networks; NTS adds authenticated security to NTP. Time matters for logs, certificates and ticket-based authentication.

Choose under exam pressure

Requirement Choice and reason
Name resolves to wrong address Check authoritative record, cached answer, TTL and split-DNS view.
Clients across router cannot obtain leases Inspect DHCP relay and server scope.
Need trustworthy signed DNS answers DNSSEC; use separate transport protection if confidentiality is required.

Traps

  • DNS can use TCP, not only UDP.
  • A DHCP reservation does not prevent every rogue device from using an address.

Practise this topic

04 · Switching, VLANs and Loop Prevention

Memory hook: VLAN separates; trunk carries; spanning tree prevents loops.

Must remember

An access port normally places untagged client traffic into one data VLAN. An 802.1Q trunk carries multiple VLANs using tags, with native/untagged behavior defined by configuration. A voice VLAN can separate phone traffic from an attached workstation. VLAN membership does not by itself authorize routing between VLANs.

Switches learn source MAC addresses, forward known unicasts to the learned port and flood unknown unicasts/broadcasts within the VLAN as appropriate. MAC-table instability, duplicate paths and loops can create storms. Spanning Tree elects a root bridge and blocks redundant forwarding paths while preserving connectivity. Rapid variants converge more quickly; root selection and path cost remain important.

Link aggregation combines compatible links into one logical bundle for capacity/resilience. LACP negotiates the bundle. Traffic is usually distributed by a hash, so one flow may not use the sum of all link bandwidth. Member speed, VLAN and trunk settings must agree.

MTU determines maximum packet/frame payload behavior at a layer. Jumbo frames need consistent path support; an MTU mismatch can allow small pings while breaking larger transfers. Duplex mismatch, CRC errors, discards and speed negotiation faults require different fixes.

Use switch port status/counters, MAC tables, VLAN/trunk information, spanning-tree state and neighbor discovery to trace a client path. Document intended native/allowed VLANs and avoid unnecessary trunks to untrusted devices.

For a new segment, verify the access port, VLAN existence, trunk allowance, routed interface/gateway and policy. A single missing VLAN on an intermediate trunk can mimic a routing problem.

Choose under exam pressure

Requirement Choice and reason
Separate guest broadcast traffic A dedicated VLAN plus controlled Layer 3 access.
Redundant Layer 2 links Spanning tree or a correctly configured logical aggregation.
One flow slower than aggregate link capacity Inspect hash distribution and single-member limits.

Traps

  • A trunk does not mean all VLANs are necessarily allowed.
  • PortFast/edge behavior belongs on suitable endpoint links, not arbitrary switch loops.

Practise this topic

05 · Routing, NAT and Resilient Gateways

Memory hook: Specific route first; preference next; metric within the protocol.

Must remember

Routers select the longest matching prefix for a destination. For competing routes to the same prefix, route-source preference/administrative distance and the protocol's metric determine which route is installed/used. A lower metric in one protocol cannot be compared directly to another protocol's metric as though they were the same units.

Static routes are explicit; a default route (0.0.0.0/0 or ::/0) handles destinations lacking a more specific match. A floating static route has a less-preferred administrative distance so another route wins while available. Dynamic protocols exchange reachability: OSPF is link-state, BGP policy-driven path-vector between routing domains, and EIGRP an advanced distance-vector protocol.

NAT rewrites addresses; PAT/NAT overload also distinguishes flows by ports so many internal clients share an external address. Static NAT fixes a mapping; dynamic pools allocate mappings. Translation is not a substitute for firewall policy or end-to-end authorization. Return traffic must traverse a path with the needed translation/session state.

First-hop redundancy provides a virtual gateway shared by routers. It protects gateway availability, not every upstream link or application. Route convergence, asymmetric paths, health tracking and failover capacity affect actual resilience.

Subinterfaces can route tagged VLANs over a trunk (router-on-a-stick). Switch virtual interfaces on a multilayer switch provide another inter-VLAN routing design. Both require the right VLAN/trunk and routing configuration.

Worked choice: routes 10.0.0.0/8, 10.4.0.0/16 and 10.4.8.0/24 all match 10.4.8.9; /24 wins even if its metric is numerically larger than another protocol's broader route.

Choose under exam pressure

Requirement Choice and reason
Backup route only when primary disappears A suitable floating static route with reachable next hop.
Many private clients share one public IPv4 PAT/NAT overload.
Gateway device fails First-hop redundancy plus healthy upstream paths.

Traps

  • Default routes do not beat a more specific route.
  • NAT does not automatically permit unsolicited inbound access.

Practise this topic

06 · Wireless and Network Access Security

Memory hook: Signal quality, channel plan and identity all matter.

Must remember

Wi-Fi shares airtime. Signal strength alone does not measure usable performance: interference, signal-to-noise ratio, channel contention, client capability and retries matter. In 2.4 GHz, 1/6/11 are the familiar nonoverlapping 20 MHz plan where permitted; 5/6 GHz offer more spectrum with region/device restrictions. Wider channels trade peak capacity for fewer independent channels and more overlap.

An SSID identifies a wireless network name; a BSSID identifies a basic service set/radio identity. Roaming requires compatible configuration and suitable coverage, not simply giving every AP the same name. Directional/omnidirectional antennas shape coverage; survey placement, walls, power and channel use.

WPA2/WPA3 protect Wi-Fi; enterprise modes use 802.1X/EAP with an authentication service such as RADIUS. Validate the server certificate and choose suitable EAP methods. Guest networks should have appropriate isolation and a controlled route to required services. A captive portal is not equivalent to strong link encryption or enterprise identity.

NAC can assess and authorize endpoints. Hardening includes management restrictions, secure firmware, disabled unused services, changed defaults, centralized logging and protected secrets. ACLs, firewall zones and URL/content filtering enforce different boundaries. TACACS+ is often chosen for network-device administrative AAA; RADIUS is common for network admission.

Threat cues: an evil twin imitates a trusted AP; ARP/DNS poisoning redirects traffic; MAC flooding pressures switch tables; VLAN hopping abuses weak trunk/native configurations; a rogue DHCP server supplies malicious addressing/gateway options. Segmentation, DHCP snooping, appropriate ARP inspection, port controls and user training address different paths.

Encryption, MFA and PKI complement physical locks/cameras. Treat IoT, BYOD and industrial systems according to their capabilities and risk, with controlled access rather than unconditional internal trust.

Choose under exam pressure

Requirement Choice and reason
Strong signal but poor throughput Inspect interference, channel contention, retries and client capabilities.
Enterprise user/device authentication 802.1X/EAP with validated RADIUS server identity.
Unmanaged guests Separate access and limited reachability.

Traps

  • Hidden SSIDs do not provide meaningful authentication.
  • Increasing transmit power can worsen interference or create asymmetric links.

Practise this topic

07 · Cabling, Cloud and Physical Design

Memory hook: Match medium, distance, power and failure domain.

Must remember

Copper twisted pair commonly uses RJ45 connectors; telephone cabling uses smaller RJ11. Fiber connectors include LC, SC, ST and multifiber MPO. Coaxial systems may use F-type or BNC. Connector fit alone does not prove the correct medium, wavelength, speed or polarity.

Single-mode fiber supports long-distance optical paths with suitable optics; multimode fiber serves shorter links under its own distance/speed limits. DAC cables connect nearby compatible equipment economically. Match transceiver form factor, wavelength, fiber type and supported standard at both ends. Dirty fiber, reversed transmit/receive pairs, excessive bend radius, bad termination and electromagnetic interference have distinct symptoms.

PoE supplies power over compatible Ethernet links. Check per-port standard/class and the switch's total power budget; enough data connectivity does not prove enough power for an AP or phone. Racks need appropriate airflow, grounding, cable management, labeling, temperature and humidity. UPS provides short-term continuity; generators and diverse feeds address longer/different failures.

Cloud networking includes virtual networks/subnets, security groups/policies, gateways, load balancers and virtual appliances. IaaS, PaaS and SaaS shift operational responsibility. NFV implements network functions in software; SDN programs/control-separates networking. SD-WAN steers overlay paths using policy; SASE combines distributed access and security capabilities.

Hybrid connectivity joins cloud and on-premises environments; overlapping CIDRs complicate routing. VPN encryption and private circuits solve different transport requirements. Elasticity changes resources with demand; scalability is the ability to grow. Cloud data-transfer and public-address costs can dominate an apparently cheap design.

Document physical and logical diagrams, rack elevation, cable maps, circuits and IP allocations. Label both ends so future troubleshooting starts with evidence instead of guesswork.

Choose under exam pressure

Requirement Choice and reason
Long optical distance Compatible single-mode optics/fiber and verified link budget.
AP reboots under load Check PoE negotiation/budget and physical power conditions.
Hybrid routing conflict Inspect overlapping address ranges before adding routes.

Traps

  • Two fiber connectors mating does not guarantee compatible optics.
  • A private circuit is not automatically encrypted.

Practise this topic

08 · Network Operations and Recovery

Memory hook: Baseline normal; control change; restore what matters.

Must remember

Maintain asset inventory, IPAM, topology, cable/rack diagrams, wireless surveys and current configurations. Know hardware/software end-of-support dates and preserve recoverable configuration backups. Decommissioning includes access revocation, data sanitization, inventory updates and removing obsolete monitoring/DNS entries.

Monitoring sources answer different questions: SNMP polls counters/state, traps notify events, flow records summarize communications, packet captures expose visible protocol detail, syslog centralizes events and APIs support structured telemetry. SNMPv3 can provide authentication and privacy; older community-string modes are weaker. Port mirroring copies selected traffic to an analysis port but may lose packets if oversubscribed.

Establish baselines for utilization, latency, jitter, loss, errors and availability. Thresholds without context create noise. Correlate changes and multiple sources; a high CPU graph is a symptom, not a root cause by itself.

Change management includes authorization, impact, dependency review, testing, maintenance windows, backups, rollback and validation. Store production, baseline and backup configurations distinctly. Emergency changes still need an accountable process and retrospective records.

RPO is tolerable data loss; RTO target restoration time. MTTR measures average repair/recovery time as defined; MTBF estimates time between failures. Do not confuse measured averages with contractual targets. Active-active uses multiple serving systems; active-passive keeps a standby. Recovery sites trade readiness and cost.

Secure remote administration through approved VPN/SSH/API or console access with individual accounts and least privilege. Out-of-band access helps recover from production network failures. Test restoration of configuration, routing, DNS, identity, monitoring and application reachability together.

Choose under exam pressure

Requirement Choice and reason
Identify traffic sources without full payload capture Flow telemetry.
Recover after a bad change Known-good configuration and tested rollback.
Production network unavailable Protected out-of-band management.

Traps

  • Monitoring without baselines and response ownership produces dashboards, not reliability.
  • A configuration backup must match hardware/software and be restorable.

Practise this topic

09 · Troubleshooting Networks

Memory hook: Define the symptom; test one layer; verify the whole path.

Must remember

Start by identifying scope, symptoms, recent changes and what still works. Establish a plausible theory, test it, plan a low-impact fix, implement under the change process, verify full functionality and document cause/results. Escalate when the evidence or authority requires it.

Symptom Useful next check
No link Cable/optic, administrative state, speed and power.
Increasing CRC errors Physical quality, interference, optic/cable mismatch.
Link up, no usable address VLAN and DHCP/relay/pool state.
Local works, remote fails Prefix, gateway, route and ACL.
IP works, name fails Resolver settings, DNS records and cache.
Small traffic works, large transfers stall MTU/path-MTU and filtered ICMP.
Wireless intermittent Channel contention, roaming, SNR and retries.

ipconfig/ip inspect host configuration; ping checks selected reachability; traceroute/tracert expose responding hops; nslookup/dig query DNS; arp/ip neigh show neighbor bindings; netstat/ss show sockets; tcpdump or Wireshark inspect packets. Command availability differs by OS. A blocked ICMP response or a router deprioritizing probes does not necessarily mean the application path is broken.

Use cable testers for continuity/wiremap, toner/probe tools for cable identification, optical meters/OTDR for suitable fiber diagnosis and Wi-Fi analyzers for channel/radio evidence. Choose the instrument for the suspected fault; a speed test does not identify every wiring defect.

Inspect both directions. A request can leave successfully while the reply lacks a route, session state or policy permission. Duplicate addresses, wrong masks, exhausted DHCP pools, native-VLAN mismatches and stale DNS can appear intermittent.

Finish by testing the actual user service from the intended source, not just the nearest gateway. Record the fixed cause and update diagrams/baselines when the intended design changed.

Choose under exam pressure

Requirement Choice and reason
Only one user fails Compare that client/port/configuration with a working peer.
Everything fails after a change Correlate the changed dependency and use the approved rollback if warranted.
Ping succeeds but web request fails Test DNS, transport port, TLS and application behavior.

Traps

  • Traceroute timeouts can reflect filtering rather than a failed forwarding hop.
  • Changing several variables at once destroys diagnostic clarity.

Practise this topic

10 · Cisco VLANs, Trunks, EtherChannel and STP

Memory hook: Configure the path, then inspect the operational result.

Must remember

Know IOS navigation: user EXEC, privileged EXEC, global configuration and interface configuration. show running-config describes active configuration; show startup-config the saved boot configuration. Save deliberate changes with the appropriate copy operation; a successful command is not proof of the intended forwarding state.

Useful verification commands include show vlan brief, show interfaces trunk, show interfaces switchport, show mac address-table, show etherchannel summary, show spanning-tree and show cdp neighbors detail/show lldp neighbors detail.

An access interface uses the intended VLAN; a trunk must have compatible tagging/native VLAN and allowed VLANs. Voice VLAN behavior supports a phone plus data endpoint. Router subinterfaces or SVIs provide inter-VLAN routing, with forwarding enabled and interfaces operational.

LACP active initiates negotiation; passive responds. Passive/passive does not negotiate a bundle. Member configuration must match. Inspect the logical port-channel and member status; cables being connected is not enough.

STP chooses the lowest bridge ID as root, combining priority and identifying information. Nonroot switches choose root paths based on cost and tie-breakers; designated ports forward for segments and redundant alternatives block/discard as appropriate. Know Rapid PVST+ roles/states, PortFast/edge behavior, BPDU Guard, root guard, loop guard and BPDU filtering conceptually. BPDU Guard protects suitable edge ports from unexpected bridge participation; do not enable edge shortcuts indiscriminately.

Wireless controller designs separate AP and controller roles; control/data paths vary by deployment mode. Trace AP, switch, controller, WLAN, VLAN and authentication settings. GUI success must still be verified through a real client association and correct policy.

Choose under exam pressure

Requirement Choice and reason
Bundle two links with negotiation Compatible port-channel members and LACP active on at least one side.
Unexpected switch on an endpoint port Appropriate BPDU Guard on a correctly designated edge port.
VLAN configured but not reaching gateway Inspect trunk allowance, SVI/subinterface and operational state.

Traps

  • A configured trunk may not be operationally carrying the intended VLAN.
  • PortFast does not replace spanning tree or make loops safe.

Practise this topic

11 · Cisco Routing Tables and OSPF

Memory hook: Neighbor first, route second, packet path last.

Must remember

Read a route entry's prefix, source code, next hop, outgoing interface, administrative distance and metric. A connected route requires the associated interface to be operational. Longest prefix determines forwarding; protocol preference resolves competing sources for the same destination prefix.

Static route forms include network, default, host and floating routes for IPv4/IPv6. Specify a reachable next hop or suitable exit-interface/next-hop combination. IPv6 link-local next hops require interface context because the same link-local address can exist on different links.

For single-area OSPFv2, know router ID, area, hello/dead timers, network type, interface participation, cost and passive interfaces. Adjacent routers must agree on critical parameters; subnet/mask, authentication and MTU mismatches can prevent the expected adjacency or full exchange. A passive interface can advertise its connected network while suppressing neighbor formation there.

On appropriate multiaccess networks, OSPF elects a designated router and backup to reduce adjacency complexity. Priority influences eligibility/selection, with router ID used as a tie-breaker; priority zero is ineligible. Elections are not simply repeated every time a higher-ID router appears. Point-to-point OSPF links do not need DR/BDR election.

Use show ip ospf neighbor, show ip ospf interface, show ip protocols, show ip route and targeted pings/traces. A full adjacency does not guarantee a desired route is advertised, selected or allowed through an ACL. Check both ends and the return route.

First-hop redundancy presents a shared virtual gateway. Understand active/standby roles and virtual addresses independently of OSPF, which exchanges routing information. A gateway failover protocol and dynamic routing solve related but different problems.

Choose under exam pressure

Requirement Choice and reason
OSPF neighbor stuck before full adjacency Compare interface/network parameters and relevant logs.
Advertise a LAN without forming neighbors there An appropriate passive-interface configuration.
Backup static route Higher administrative distance than the intended primary source.

Traps

  • OSPF router ID is not necessarily an address currently assigned to a forwarding interface.
  • A full neighbor relationship is not proof of end-to-end application access.

Practise this topic

12 · Cisco IP Services and Management

Memory hook: Translate, relay, mark and monitor deliberately.

Must remember

For NAT, identify inside/outside interfaces, matching internal traffic and the external address/pool. Static mappings differ from dynamic pool mappings and PAT overload. Verify translation and statistics tables as well as actual traffic; an ACL used to select NAT traffic is not necessarily a filtering ACL applied to an interface.

DHCP clients discover a server locally; a relay/helper on the appropriate routed interface forwards requests to a remote server. Confirm scope, excluded/reserved addresses, default gateway, DNS options and return routing. DNS resolves names; DHCP assigns configuration; NTP synchronizes time. Their failures can look like application faults.

QoS classification identifies traffic; marking labels it; queueing/scheduling allocates transmission opportunity; policing drops/remarks excess traffic while shaping buffers it to a rate. Congestion avoidance and prioritization trade delay/loss between classes. QoS does not create bandwidth and untrusted endpoint markings should not automatically determine priority.

Syslog severity runs from 0 (emergency) through 7 (debugging); lower numbers are more severe. Collect timestamps and appropriate levels without flooding storage with unneeded debug detail. SNMP supports monitoring; secure versions and restricted managers reduce exposure. NetFlow-like telemetry provides communication summaries rather than full payload capture.

Protect device management using SSH rather than Telnet, individual AAA identities, access restrictions and secure configurations. TFTP is simple and lacks built-in authentication/encryption; FTP has separate control/data behavior. Choose secure transfer methods where supported and protect backups because they can include credentials and topology.

Choose under exam pressure

Requirement Choice and reason
WAN queue delays voice Classify/mark and apply a suitable congestion/QoS policy.
Remote subnet cannot obtain DHCP Check relay and scope/return path.
Need to verify NAT behavior Translation/statistics outputs plus end-to-end traffic.

Traps

  • Policing and shaping are not the same operation.
  • A NAT-selection ACL does not necessarily filter interface traffic.

Practise this topic

13 · Cisco ACLs, Layer 2 Protections and AAA

Memory hook: Match the packet before you apply the rule.

Must remember

An ACL processes entries in order and normally stops on the first match, with an implicit deny at the end. Standard IPv4 ACLs primarily match source address; extended ACLs can match source, destination, protocol and ports. Interpret inbound/outbound relative to the interface, not to a vague “Internet direction.”

Wildcard masks use zero bits for comparison and one bits for “ignore.” 0.0.0.255 matches the varying last octet of a /24 pattern. Host/any shortcuts still express match scope. Test intended permitted and denied flows, including return traffic and essential DNS/DHCP/management paths.

Port security constrains learned/allowed source MAC addresses with configured violation behavior. It is not strong cryptographic device identity. DHCP snooping distinguishes trusted server paths and builds bindings; dynamic ARP inspection can use trustworthy bindings to reject invalid ARP claims. Configuration must account for static-address devices and legitimate infrastructure paths.

AAA separates authentication, authorization and accounting. Local accounts can support fallback; centralized RADIUS/TACACS+ improves policy consistency and attribution. Protect administrator sessions, store secrets appropriately and avoid locking out the recovery path when changing AAA.

IPsec site-to-site VPNs protect network-to-network tunnels; remote-access VPNs connect users/devices. Identity, routing and access policy remain required. Wireless WPA2/WPA3 and enterprise authentication protect different aspects from a web captive portal. Physical access controls, secure defaults and user awareness complete the picture.

Choose under exam pressure

Requirement Choice and reason
Permit web from one subnet to one server A correctly ordered extended ACL matching source, destination and port.
Reject rogue DHCP servers Snooping with only legitimate server-facing paths trusted.
Record per-command device administration Appropriate centralized AAA and accounting policy.

Traps

  • The implicit deny can block necessary traffic you forgot to allow.
  • A permitted MAC address can be spoofed; it is not equivalent to certificate identity.

Practise this topic

14 · Network Automation, APIs, AI and Terraform

Memory hook: Model desired state; authenticate the API; verify the result.

Must remember

Traditional device-by-device administration differs from controller-based management. Controllers expose APIs and coordinate policy; the data plane still forwards traffic. Northbound interfaces connect applications/automation to controllers; southbound interfaces connect control systems to devices. Centralization improves consistency while making controller availability and access critical.

REST-style APIs use resources and HTTP methods: GET reads, POST commonly creates/requests actions, PUT replaces a resource representation, PATCH partially updates and DELETE removes. Read the API's actual semantics. Status families include 2xx success, 4xx client/request issues and 5xx server issues. Authentication, authorization, rate limits and pagination remain part of automation design.

JSON uses objects with string keys, arrays, strings, numbers, booleans and null. Double quotes matter; trailing commas and comments are not valid standard JSON. Data serialization is not executable configuration by itself.

Ansible commonly uses agentless playbooks/modules for configuration tasks. Terraform describes desired resources and keeps state linking them to remote objects. Plans, provider versions, state protection and review matter. Idempotence means repeating an operation with the same desired input should not create unintended additional changes; tool names do not guarantee every task is idempotent.

Predictive AI/ML can detect patterns or forecast demand; generative AI produces new text/configuration based on learned patterns and context. Treat generated commands as proposals: verify syntax, platform version, topology, policy and rollback before execution. Sensitive configurations should not be sent to an unapproved model service.

Automate small, testable changes with input validation, least-privilege credentials, useful logs and post-change verification. A syntactically valid API call can still target the wrong device or tenant.

Choose under exam pressure

Requirement Choice and reason
Consistent intended infrastructure Versioned Terraform configuration with reviewed plans and protected state.
Repeated device configuration tasks Appropriate configuration-management playbooks and verification.
AI suggests a router change Review against real topology and policy before execution.

Traps

  • Valid JSON does not imply a valid API request.
  • An automation success status does not prove the network meets the business requirement.

Practise this topic

Search across every published topic.