Cisco CCNA (200-301) flashcards
226 free flashcards. Tap a card to flip it.
Full Mesh Topology
Flip cardA full mesh topology directly connects every network node to every other node, offering maximum redundancy at the cost of higher cabling and complexity.
- Every node connects to every other node
- Formula: n(n-1)/2 links for n nodes
- High redundancy, high cost
- Common in critical core/data center designs
Memory trick: Full mesh = everyone is friends with everyone.
Controller-Based Networking
Flip cardAn architecture where a centralized controller manages configuration, policy, and monitoring for many network devices, replacing manual per-device configuration.
- Centralizes control plane logic
- Ensures consistent policy across the fabric
- Reduces manual CLI errors and configuration drift
Memory trick: One controller, many puppets — consistent moves every time.
Floating Static Route
Flip cardA static route configured with an administrative distance higher than the primary dynamic routing protocol so it is only used as a backup path when the primary route is unavailable.
- Syntax: ip route <network> <mask> <next-hop> <AD>
- AD must be higher than the primary protocol's AD to float in the background
- Commonly used for backup WAN links or protocol failover
Memory trick: Set the AD higher so it floats below the primary route until needed.
Stateful Firewall
Flip cardA firewall that tracks the state of active network connections in a state table and automatically permits return traffic belonging to an established, allowed session.
- Maintains a state table of active connections
- Automatically allows return traffic for permitted outbound sessions
- Contrasts with stateless firewalls, which require explicit rules for both directions
Memory trick: Stateful firewalls remember the conversation, stateless ones forget instantly.
ESP vs AH
Flip cardESP (protocol 50) encrypts and authenticates IPsec payloads, while AH (protocol 51) only authenticates and provides integrity without encryption.
- ESP = confidentiality + integrity + authentication
- AH = integrity + authentication only, no encryption
- IKE negotiates keys/SAs but doesn't protect traffic itself
Memory trick: ESP Encrypts, AH just Authenticates.
Predictive Capacity Planning (AIOps)
Flip cardAn AI/ML network operations capability that analyzes historical performance trends to forecast future resource needs, enabling proactive capacity upgrades before issues arise.
- Uses historical trend data, not just real-time snapshots
- Differs from anomaly detection, which flags sudden abnormal events
- Enables proactive rather than reactive network management
Memory trick: Forecast the future traffic wave before it crashes the shore.
HTTP Status Codes
Flip cardHTTP status codes indicate the result of an API request: 2xx success, 4xx client error, 5xx server error.
- 200 OK = success
- 401 Unauthorized = authentication failure
- 404 Not Found = resource doesn't exist
- 500 Internal Server Error = server-side failure
Memory trick: 2xx good, 4xx your fault, 5xx server's fault.
Port Security Sticky MAC
Flip cardThe 'switchport port-security mac-address sticky' command causes a switch to dynamically learn a connected device's MAC address and add it to the running configuration as a secure MAC.
- Must save config to persist across reboot
- Learned addresses appear as 'sticky' in show port-security
- Reduces manual MAC configuration effort
Memory trick: Sticky MACs stick to the config once you save it.
EtherChannel Summary Flags
Flip cardThe 'show etherchannel summary' command uses letter flags to indicate the state of each port-channel and its member interfaces.
- P = bundled in port-channel
- D = down, not bundled
- S/U in Po flags = Layer2/in-use
- Common causes of D: mismatched mode, speed/duplex, trunk settings
Memory trick: P for Party (bundled), D for Ditched (not bundled).
VRRP Election and MAC Format
Flip cardVRRP elects a Master router based on the highest priority (default 100, range 1-254); the virtual MAC address format is 0000.5E00.01xx where xx is the VRID in hexadecimal.
- Default VRRP priority is 100
- Virtual MAC: 0000.5E00.01<VRID in hex>
- Owner of the virtual IP automatically becomes Master with priority 255
Memory trick: Five-E for VRRP's Virtual identity
OSPF Cost Calculation
Flip cardOSPF calculates interface cost as reference bandwidth divided by interface bandwidth; the total path cost is the sum of costs of all outgoing interfaces along the path.
- Default reference bandwidth = 100 Mbps (100,000 kbps)
- Formula: cost = reference bandwidth (kbps) / interface bandwidth (kbps)
- IOS truncates the cost to an integer (rounds down)
Memory trick: Divide the reference by the pipe size to get the toll for each road.
IPv4 Default Static Route
Flip cardA route entry matching all destinations (0.0.0.0/0) used when no more specific route exists.
- Command: ip route 0.0.0.0 0.0.0.0 <next-hop or exit-interface>
- Also called the 'gateway of last resort'
- Shown in routing table as S* 0.0.0.0/0
Memory trick: 0.0.0.0 0.0.0.0 = 'match anything, go here'.
OSPF DROTHER 2-WAY Behavior
Flip cardOn broadcast/NBMA multi-access segments, non-DR/BDR routers (DROTHERs) remain in 2-WAY state with each other while forming FULL adjacencies only with the DR and BDR.
- Reduces flooding overhead on multi-access networks
- FULL state only required with DR/BDR, not all neighbors
- Point-to-point links always go to FULL state, no DR/BDR needed
Memory trick: DROTHERs wave hello but only hug the DR
Route Summarization (CIDR)
Flip cardRoute summarization combines multiple contiguous subnets into a single advertised route using the longest common prefix shared by all subnets.
- Count of /24s summarized = 2^(24-summary prefix)
- Must verify subnets are contiguous and power-of-2 aligned
- /22 summarizes exactly 4 /24 networks
Memory trick: Four /24s fold neatly into one /22 blanket.
CAPWAP Ports
Flip cardControl And Provisioning of Wireless Access Points (CAPWAP) is the standard tunneling protocol between lightweight APs and a WLC, using UDP 5246 for control and 5247 for data.
- UDP 5246 = CAPWAP control channel
- UDP 5247 = CAPWAP data channel
- Replaced the older proprietary LWAPP (ports 2246/2247)
- AP discovery can use broadcast, DHCP option 43, DNS, or static WLC IP
Memory trick: 5246 controls, 5247 follows — one number apart, control leads data.
APIPA
Flip cardAutomatic Private IP Addressing is a fallback mechanism where a Windows host assigns itself an address in 169.254.0.0/16 when DHCP is unavailable.
- Range: 169.254.1.0 – 169.254.254.255
- Indicates a failed DHCP lease request
- Allows only local subnet communication, no routing
Memory trick: '1-6-9' means 'I got nothing from DHCP, so I picked my own.'
Trunk Allowed VLAN Modification
Flip cardIOS provides 'add', 'remove', and 'except' keywords to modify an existing trunk's allowed VLAN list incrementally instead of overwriting it.
- 'switchport trunk allowed vlan X' alone overwrites the list
- 'add' appends new VLANs to the existing list
- 'remove' deletes specific VLANs from the list
- 'except' allows all VLANs except those listed
Memory trick: Forget 'add' and you erase the whole guest list!
OSPF MTU Mismatch (EXSTART/EXCHANGE Stall)
Flip cardOSPF neighbors stuck in EXSTART or EXCHANGE state often indicate an MTU mismatch between the two interfaces, since DBD packets larger than the receiving interface's MTU are silently dropped.
- EXSTART/EXCHANGE involves negotiating master/slave roles and exchanging DBD packets describing the LSDB
- MTU mismatch causes large DBD packets to be dropped, stalling progression to FULL
- Fixes: match interface MTUs, or use 'ip ospf mtu-ignore' to disable the MTU check
Memory trick: Big packet, small door — DBDs get stuck at EXCHANGE.
CDP vs LLDP
Flip cardCDP is Cisco's proprietary Layer 2 neighbor discovery protocol, while LLDP (IEEE 802.1AB) is an open standard supported across vendors.
- CDP: Cisco-only, enabled by default on Cisco gear
- LLDP: open standard, works with mixed-vendor equipment
- Both operate at Layer 2 and share info like device ID, port ID, capabilities
- Both can be enabled simultaneously on Cisco switches
Memory trick: CDP speaks only Cisco; LLDP speaks every language.
OSPF Network Type Mismatch
Flip cardOSPF network type (e.g., point-to-point vs broadcast) must match on both ends of a link; mismatches affect whether DR/BDR election occurs and can prevent full adjacency.
- Point-to-point requires no DR/BDR election
- Broadcast/NBMA networks require DR/BDR election
- Mismatched types often cause stuck EXSTART/2-WAY states
Memory trick: Two roads must agree: both point-to-point or both broadcast
OSPF Passive-Interface
Flip cardThe 'passive-interface' command under an OSPF process prevents hello packets from being sent or received on a specified interface, stopping neighbor adjacencies there while still allowing the interface's connected subnet to be advertised.
- Common use: LAN-facing interfaces with hosts, not other routers
- Command syntax: passive-interface <interface> under router ospf process
- Subnet still appears in LSAs as a stub network, just without adjacency formation on that link
Memory trick: Passive means quiet on hellos, but still tells the world about the subnet.
AAA Method List Fallback
Flip cardAn AAA authentication method list is tried in order; the router moves to the next method only when the current method is unavailable (e.g., server unreachable), not merely on a failed login.
- Order in the method list matters
- 'local' is commonly used as a fallback for server outages
- Method lists are applied to lines/interfaces separately from being defined globally
Memory trick: No response, not no access — TACACS+ down means try local next.
PoE Standards (802.3af/at)
Flip cardPower over Ethernet standards define how much electrical power can be delivered to devices over Ethernet cabling; 802.3af (PoE) supports up to ~12.95W delivered, and 802.3at (PoE+) supports up to ~25.5W delivered.
- 802.3af: 15.4W at source, ~12.95W at device
- 802.3at: 30W at source, ~25.5W at device
- 802.3bt: up to 71-90W for high-power devices
- Common for APs, IP phones, cameras
Memory trick: 'af' = a few watts, 'at' = a ton more watts.
Crossover Cable
Flip cardAn Ethernet cable wiring scheme (T568A on one end, T568B on the other) used to directly connect two like devices such as switch-to-switch or PC-to-PC.
- Needed without Auto-MDIX for like-device connections
- Straight-through connects unlike devices (PC-switch)
- Modern NICs/switches usually have Auto-MDIX to auto-detect
Memory trick: 'Like needs a twist' — like devices need crossover.
RSTP Alternate Port
Flip cardIn Rapid PVST+/RSTP, the alternate port provides a backup path to the root bridge and remains in the discarding state to prevent loops.
- Root port = lowest cost path to root on a switch
- Designated port = lowest cost port for a segment
- Alternate port = backup path, discarding state
- Backup port = redundant port on same switch/segment (rare, e.g. hub)
Memory trick: Only one door per hallway can be open — the pricier door for that segment stays shut but ready.
Spine-Leaf Topology
Flip cardA data center network design where every leaf switch connects to every spine switch, ensuring consistent two-hop latency between any two leaf switches.
- Leaf switches connect to servers/hosts
- Spine switches interconnect all leaf switches
- Provides predictable latency and easy horizontal scaling
Memory trick: Spine-leaf: always two hops, like a leaf falling past the spine to another leaf.
CIDR to Subnet Mask Conversion
Flip cardConverting a CIDR prefix length to dotted-decimal notation by counting network bits set to 1 across the four octets.
- /24 = 255.255.255.0
- /21 = 255.255.248.0 (21 bits = 8+8+5)
- Third octet value comes from 256 minus 2^(8-remaining bits)
Memory trick: 'Count the ones, fill the octets' — 8+8+5=21.
Type 1 vs Type 2 Hypervisor
Flip cardType 1 (bare-metal) hypervisors run directly on hardware; Type 2 (hosted) hypervisors run as an application on top of an existing OS.
- Type 1 examples: VMware ESXi, Microsoft Hyper-V
- Type 2 examples: VMware Workstation, VirtualBox
- Type 1 offers better performance for data center use
Memory trick: Type 1 = bare metal, no middleman OS.
5 GHz Channel Bonding
Flip cardChannel bonding combines two or more adjacent 20 MHz channels (e.g., into 40, 80, or 160 MHz) to boost throughput at the cost of fewer available non-overlapping channels.
- Increases throughput but increases interference risk
- Reduces total independent channel count in a band
- Common in 802.11n/ac/ax for higher-speed WLANs
Memory trick: Wider lanes on the highway mean fewer separate roads.
Longest Prefix Match
Flip cardThe rule that a router selects the route with the longest (most specific) matching subnet mask when multiple routes match a destination.
- Always evaluated before administrative distance
- More specific /25 beats less specific /24 or /16
- Applies to both IPv4 and IPv6 routing tables
Memory trick: The most precise address wins the forwarding race.
JSON Array
Flip cardA JSON array is an ordered, comma-separated collection of values enclosed in square brackets [ ], which can hold numbers, strings, objects, or other arrays.
- Denoted by square brackets [ ]
- Values are ordered and accessed by index
- Can contain mixed data types including nested objects/arrays
Memory trick: Square brackets stack items like a list — that's an array.
REST HTTP Methods
Flip cardREST APIs use standard HTTP verbs to perform CRUD operations: GET (read), POST (create), PUT (full update/replace), PATCH (partial update), DELETE (remove).
- GET is safe and idempotent
- PUT is idempotent, replaces whole resource
- PATCH modifies only specified fields, not necessarily idempotent
Memory trick: POST creates, GET reads, PUT replaces, PATCH patches, DELETE destroys.
DHCP Snooping Binding Database
Flip cardA table built by DHCP snooping that records trusted IP-to-MAC-to-VLAN-to-port mappings, used by DAI and IP Source Guard for validation.
- Populated from DHCPACK messages on trusted ports
- Used by DAI to validate ARP packets
- Used by IP Source Guard to filter spoofed traffic
Memory trick: The binding table is the switch's 'address book' for DAI to check IDs.
enable secret vs enable password
Flip cardenable secret uses a strong one-way hash (Type 5/8/9) and takes precedence over enable password, which is stored in weaker, reversible Type 7 form when service password-encryption is enabled.
- enable secret always overrides enable password for authentication
- service password-encryption applies weak Type 7 to plaintext passwords
- Type 7 is easily reversible; Type 5/8/9 hashes are much stronger
Memory trick: Secret is Strong, Service is Sloppy (Type 7)
HSRP Preempt
Flip cardA configuration option that allows a router with a higher HSRP priority to take back the Active role after recovering from a failure.
- Preempt is disabled by default in HSRP
- Command: standby <group> preempt
- Without preempt, the current Active router keeps its role even if a higher-priority router returns
Memory trick: No preempt, no comeback: the throne stays with whoever's sitting.
Ansible Agentless Automation
Flip cardAnsible is a push-based, agentless automation tool that uses SSH (for Linux/network devices) to apply configurations defined in YAML playbooks from a control node.
- No agent software needed on managed nodes
- Uses YAML playbooks and modules
- Push model: control node initiates connections
Memory trick: Ansible pushes with SSH, no agent needed—Ansible answers the call.
Ansible Resource Module States
Flip cardCisco IOS Ansible resource modules use a 'state' parameter (merged, replaced, overridden, deleted) to control how declared configuration interacts with existing device configuration.
- merged: combines new config with existing, non-destructive
- replaced: replaces only the specified config section
- overridden: replaces entire config type, removing unspecified items
- deleted: removes specified configuration
Memory trick: Merged blends in, Overridden wipes out.
TACACS+ vs RADIUS
Flip cardTACACS+ is Cisco's AAA protocol that encrypts entire packets over TCP port 49; RADIUS encrypts only the password and uses UDP ports 1812/1813.
- TACACS+: TCP port 49, full packet encryption
- RADIUS: UDP 1812 (auth)/1813 (accounting), password-only encryption
- TACACS+ separates authentication, authorization, accounting
Memory trick: TACACS+ Totally Covers All the Content Securely
Port Security Violation Modes
Flip cardDetermines the switch action when the number of allowed MAC addresses on a port is exceeded.
- shutdown: err-disables the port (default)
- restrict: drops frames, logs, increments counter, port stays up
- protect: drops frames silently, no logging
Memory trick: Shutdown Shouts, Restrict Records, Protect is Private
Native VLAN Mismatch
Flip cardOccurs when two ends of an 802.1Q trunk are configured with different native VLANs, causing untagged frames to be misclassified.
- CDP detects and logs the mismatch via syslog
- Untagged frames are not tagged with a VLAN ID on the wire
- Mismatch can allow VLAN traffic leakage, a security concern
- Fix by matching 'switchport trunk native vlan' on both ends
Memory trick: Untagged frames trust the native label — if the labels disagree, traffic slips into the wrong room.
Client-Based Remote-Access VPN
Flip cardA VPN solution where individual users run client software (e.g., Cisco AnyConnect) to establish an encrypted tunnel to a corporate network from any internet connection, ideal for remote/traveling users.
- Established on-demand by the user, not permanent
- Commonly uses SSL/TLS or IPsec
- Contrasts with site-to-site VPNs, which connect fixed locations permanently
Memory trick: Traveling employee = client software = remote-access VPN.
IPv6 EUI-64
Flip cardEUI-64 generates a 64-bit interface ID from a 48-bit MAC address by splitting it, inserting FFFE in the middle, and flipping the 7th bit of the first byte.
- Split MAC into two 24-bit halves
- Insert FFFE between the halves
- Flip the universal/local (U/L) bit of the first byte
Memory trick: Split, stuff with FFFE, then flip the switch bit.
Port Address Translation (PAT)
Flip cardPAT, or NAT overload, allows multiple private hosts to share a single public IP address by using unique source port numbers to differentiate simultaneous sessions.
- Also called NAT overload
- Most common form of NAT on home/SOHO routers
- Uses source port numbers to multiplex sessions
- Conserves public IPv4 addresses
Memory trick: PAT = 'Ports Allow The share' of one IP by many.
DAI ARP ACLs for Static Hosts
Flip cardAn ARP access control list can be configured to manually define valid IP-to-MAC bindings for static IP hosts, allowing DAI to validate them without relying on the DHCP snooping binding table.
- Used when hosts don't use DHCP (e.g., servers, printers)
- Applied with 'ip arp inspection filter <acl-name> vlan <id>'
- DHCP clients still validated against snooping bindings normally
Memory trick: Static hosts need a static list — the ARP ACL fills the gap DHCP snooping can't.
GLBP Load Balancing
Flip cardGateway Load Balancing Protocol allows multiple routers to actively forward traffic for a single virtual IP by assigning each router a distinct virtual MAC address as an Active Virtual Forwarder.
- One router is elected AVG to manage virtual MAC assignment
- Up to 4 AVFs can forward traffic simultaneously
- Unlike HSRP/VRRP, GLBP uses all available bandwidth rather than one active path
Memory trick: GLBP Gives Load Balancing Power to everyone
Prefix Length vs Administrative Distance
Flip cardRouters first select the most specific (longest) matching prefix for a destination; administrative distance is only used to break ties between sources advertising the identical prefix length.
- Longest prefix match is evaluated first, always
- AD comparison happens only among routes with the same prefix length
- A /25 route always beats a /24 route for an address within the /25 range
Memory trick: Specificity beats trust: the sharpest match wins first.
OSPF Route Type Preference
Flip cardWithin OSPF, route selection follows a fixed hierarchy: intra-area > inter-area > external Type 1 > external Type 2, regardless of the numeric cost/metric.
- Intra-area routes always beat inter-area and external routes
- E1 costs include external+internal metric; E2 shows only external cost
- This is separate from Administrative Distance which is 110 for all OSPF routes
Memory trick: Home turf always beats foreign turf in OSPF, no matter the price
FlexConnect AP Mode
Flip cardAn AP mode designed for branch offices that allows local switching of client traffic and authentication even when the WLC connection is lost.
- Supports standalone mode during WAN outages
- Can locally switch data traffic instead of tunneling all traffic to WLC
- Ideal for remote/branch sites with WAN links to central WLC
- Contrasts with Local mode which needs continuous WLC connectivity
Memory trick: Flex bends but doesn't break when the WAN link snaps.
Extended ACL Syntax
Flip cardExtended ACLs filter based on protocol, source, destination, and port number using the syntax: access-list <100-199> permit/deny protocol source destination [operator port].
- Port matching requires tcp or udp, not ip
- 'eq 443' matches HTTPS traffic
- Source is listed before destination in the syntax
Memory trick: Protocol-Source-Destination-Port, like mailing an envelope in order.
Routing Table Codes
Flip cardThe leftmost letter code in 'show ip route' output identifies how each route was learned (C=connected, L=local, S=static, O=OSPF, D=EIGRP).
- C = directly connected interface network
- L = local /32 (or /128) address of the router itself
- S* or S with 0.0.0.0/0 indicates a static default route
Memory trick: C-L-O-S-e reading of the code column tells you the route's origin.
Host-based Subnetting
Flip cardTo find the smallest subnet for a required number of hosts, find the smallest power of 2 (minus 2 for network/broadcast) that is greater than or equal to the host requirement.
- Formula: 2^n - 2 >= required hosts
- /26 = 64 addresses, 62 usable
- Always subtract 2 for network and broadcast addresses
Memory trick: Two are lost every time: network and broadcast host slots.
Floating Static Route Syntax
Flip cardAdding a numeric value after the next hop in an 'ip route' command overrides the default administrative distance (1), allowing the route to 'float' as a backup behind a preferred dynamic protocol.
- Syntax: ip route <destination> <mask> <next-hop> <AD>
- Default static AD is 1 if omitted
- AD value must exceed the primary protocol's AD to act as backup
Memory trick: Set the AD higher so the static route floats until the primary sinks.
Idempotency
Flip cardA property of automation modules where running the same task repeatedly against a device results in the same final state without unnecessary or repeated changes.
- Second/subsequent runs report 'changed: 0' if state already matches
- Core design principle of Ansible modules and Terraform providers
- Prevents configuration drift and unintended side effects from repeated runs
Memory trick: Push the button twice, same result — no surprises.
DHCP Snooping Trust
Flip cardDHCP snooping filters DHCP messages based on trusted/untrusted port status to prevent rogue DHCP servers.
- All ports untrusted by default when feature enabled
- Uplink toward legitimate DHCP server must be trusted
- Untrusted ports block DHCP server replies (OFFER, ACK)
Memory trick: Trust the Tower (uplink), Suspect the Street (access ports)
WPA3 SAE
Flip cardSAE is the key establishment protocol in WPA3-Personal that replaces the WPA2 4-way handshake and protects against offline dictionary attacks.
- SAE = Simultaneous Authentication of Equals
- Also called Dragonfly handshake
- Resists offline brute-force even with weak passphrases
Memory trick: SAE 'Says Absolutely no Eavesdropping' on offline guesses.
Port Security Maximum & Default Violation
Flip cardPort security limits the number of secure MAC addresses per port; exceeding the maximum triggers a violation action, defaulting to 'shutdown' which err-disables the port.
- Default violation mode = shutdown
- 'restrict' drops frames and logs, port stays up
- 'protect' drops frames silently, no logging
Memory trick: Default mode SHUTS the door when the max is exceeded.
IPv6 Anycast Address
Flip cardAn anycast address is assigned to multiple interfaces on different devices; traffic sent to it is delivered to the nearest interface as determined by the routing protocol.
- Same address on multiple devices
- Delivered to nearest instance by routing metric
- Common use: DNS root servers, CDNs
- Syntactically identical to unicast addresses
Memory trick: Anycast = 'any nearest one will do' delivery.
DAI Trust Configuration
Flip card'ip arp inspection trust' configures an interface to bypass ARP packet validation, typically used on uplinks toward other switches.
- Separate from 'ip dhcp snooping trust'
- Applied per-interface
- Untrusted ports are validated against DHCP snooping binding table
Memory trick: Trust the trunk, inspect the edge.
IPv6 /64 Addressing Structure
Flip cardA standard IPv6 unicast address is split into a 64-bit network prefix and a 64-bit interface identifier that uniquely addresses the host.
- Global routing prefix + subnet ID = 64 bits
- Interface ID = remaining 64 bits
- Common /64 boundary for LANs
- EUI-64 or random methods generate interface ID
Memory trick: IPv6 splits in half: 64 for network, 64 for host.
IPv6 Exit-Interface Static Route
Flip cardOn point-to-point interfaces, an IPv6 static route can be configured with only the exit interface (no next-hop address) because there is only one reachable neighbor on that link.
- Valid syntax: ipv6 route <prefix>/<len> <interface>
- Works reliably on point-to-point links like serial or point-to-point GRE tunnels
- On multi-access (Ethernet) links, using only an exit interface can cause resolution issues; a next hop or link-local address is preferred
Memory trick: One neighbor, one interface, no address needed.