Cisco CCNA (200-301) flashcards
226 free flashcards. Tap a card to flip it.
Well-Known Port Numbers
Flip cardWell-known ports (0-1023) are standardized TCP/UDP port numbers assigned to common protocols and services.
- HTTP = TCP 80
- HTTPS = TCP 443
- FTP = TCP 20/21
- Telnet = TCP 23
Memory trick: '80 is plain, 443 is locked' for web traffic.
Default Gateway
Flip cardThe default gateway is the router interface a host uses to send traffic destined for networks outside its own subnet.
- Configured on end devices via static IP or DHCP option 3
- Without it, hosts can only reach local subnet devices
- Routers/L3 switches typically serve as the default gateway
Memory trick: No gateway, no getaway from your own subnet.
Gateway of Last Resort
Flip cardThe route used when no more specific match exists in the routing table, typically the default route 0.0.0.0/0.
- Marked with '*' in show ip route output
- Can be static (S*) or learned dynamically (e.g., O*E2)
- AD and metric shown in brackets [AD/metric]
Memory trick: Star marks the map's emergency exit route
Type 7 Password Weakness
Flip card'service password-encryption' applies a weak, reversible Type 7 cipher to plaintext passwords, which offers only minimal protection since it can be decrypted using freely available tools.
- Type 7 is reversible; type 5/9 hashes are not
- Protects against casual viewing only, not real attacks
- 'enable secret' should always be used instead of 'enable password' for stronger protection
Memory trick: Type 7 hides passwords from your coworker, not from a hacker.
Implicit Deny
Flip cardEvery Cisco ACL has an unwritten 'deny any' statement at the end, causing any unmatched traffic to be dropped.
- Not shown in running-config
- Applies to standard and extended ACLs
- At least one permit statement is needed to allow any traffic
Memory trick: No match? No mercy — implicit deny drops it.
DTP Default Negotiation
Flip cardDynamic Trunking Protocol lets adjacent switchports automatically negotiate trunk or access mode based on configured DTP states.
- dynamic desirable + dynamic desirable = trunk
- dynamic desirable + dynamic auto = trunk
- dynamic auto + dynamic auto = access (no trunk)
- access mode never trunks regardless of the peer
Memory trick: Desirable asks, Auto answers, two Autos stay silent forever.
Containers vs Virtual Machines
Flip cardContainers share the host OS kernel and isolate only the application layer, making them lighter and faster than VMs, which each run a full guest OS.
- Containers start in seconds; VMs take longer to boot a full OS
- Containers have smaller resource footprint
- Docker is a common container platform
Memory trick: VMs pack a whole house; containers just pack a suitcase.
DHCP Snooping Rate Limiting
Flip cardThe 'ip dhcp snooping limit rate' command restricts the number of DHCP packets per second on untrusted ports, mitigating DHCP flooding/DoS attacks.
- Applied per interface, typically on untrusted access ports
- Exceeding the rate causes the port to be error-disabled (if configured)
- Complements trust configuration to fully secure DHCP
Memory trick: Rate-limit the flood before it drowns the DHCP pool.
OSPF Equal-Cost Multipath (ECMP)
Flip cardWhen OSPF calculates multiple paths to the same destination with identical total cost, it installs all of them in the routing table (default maximum of 4) and load-balances traffic across them.
- Default maximum equal-cost paths is 4 (varies by platform, can be changed with 'maximum-paths')
- Only routes with identical cost are eligible; OSPF has no unequal-cost load balancing like EIGRP variance
- Traffic is typically load-balanced per-destination by default using CEF
Memory trick: Same cost, both roads open, up to four lanes.
RFC 1918 Private Addressing
Flip cardRFC 1918 defines IPv4 address blocks reserved for use inside private networks and not routed on the public internet.
- 10.0.0.0/8
- 172.16.0.0/12
- 192.168.0.0/16
Memory trick: '10, 172(16-31), 192.168' — private house numbers.
ACL Line-by-Line Evaluation
Flip cardCisco ACLs are processed top-down; the first matching line determines the action, and remaining lines (including implicit deny) are only evaluated if no prior match occurs.
- Match is based on protocol, source/destination, and port together
- A deny for one specific port does not affect other ports/protocols
- Explicit 'permit ip any any' catches everything not explicitly denied above it
Memory trick: First Match Wins, then Move On
HSRP Interface Tracking
Flip cardHSRP tracking monitors the state of a specified interface and decrements the router's HSRP priority by a configured value if that interface goes down, potentially triggering a failover to another router.
- Command: standby 1 track <interface> decrement <value>
- Default decrement value if unspecified is 10
- Lower resulting priority can allow a standby router to become active if preempt is set
Memory trick: Track the link, dock the priority, hand off the throne.
Site-to-Site VPN
Flip cardAn IPsec VPN tunnel established between two gateway devices (routers/firewalls) to securely connect entire networks, typically always-on.
- Connects networks, not individual users
- No client software needed on end hosts
- Contrasts with remote-access VPNs for individual clients
Memory trick: Site-to-Site Sticks two buildings together permanently
DMZ (Demilitarized Zone)
Flip cardA separate, firewall-isolated network segment used to host public-facing servers, providing a buffer between the internet and the internal LAN.
- Typically has its own firewall interface/zone
- Limits exposure of internal LAN to external threats
- Common hosts: web, email, DNS servers
Memory trick: 'DMZ = no-man's-land between internet and LAN.'
Standard ACL Placement
Flip cardStandard ACLs filter only by source address, so they should be placed as close to the destination as possible to avoid unintentionally blocking traffic to other destinations.
- Standard ACLs use only source IP for matching
- Placing near destination limits collateral blocking
- Extended ACLs, which match source and destination, are placed close to the source
Memory trick: Standard = near destination (Same target); Extended = near source (Everything specific).
SDN Control Plane Centralization
Flip cardIn SDN, the control plane logic is removed from individual devices and centralized in a controller, which then pushes forwarding instructions to devices' data planes.
- Controller = brain, devices = muscle
- Southbound APIs connect controller to devices (OpenFlow, NETCONF, RESTCONF)
- Separates decision-making from packet forwarding
Memory trick: Control plane thinks, Data plane forwards, Management plane configures.
WPA2-Enterprise (802.1X)
Flip cardWPA2-Enterprise uses 802.1X authentication with a RADIUS server to authenticate each user individually, typically integrated with a directory service like Active Directory.
- Requires a RADIUS/AAA server for authentication
- Each user has unique credentials, unlike shared PSK
- Commonly used in corporate/enterprise environments
Memory trick: Enterprise = everyone logs in individually via RADIUS.
OSPF Wildcard Mask Calculation
Flip cardThe wildcard mask used in the OSPF network statement is the inverse of the subnet mask, calculated as 255 minus each subnet mask octet (or block size minus 1 for the interesting octet).
- /26 = 255.255.255.192 -> wildcard 0.0.0.63
- /24 = 255.255.255.0 -> wildcard 0.0.0.255
- /27 = 255.255.255.224 -> wildcard 0.0.0.31
Memory trick: Block size minus one equals your wildcard.
Exit-Interface Static Routes on Multi-Access Links
Flip cardConfiguring a static route with only an exit interface on a broadcast multi-access network causes the router to ARP for every destination host, unlike specifying a next-hop IP.
- Best practice: use next-hop IP on multi-access networks
- Exit-interface-only is fine on point-to-point links
- Causes proxy ARP overhead and potential performance issues
Memory trick: On a busy street, ask for directions (IP), don't guess every door (interface)
SD-Access Overlay
Flip cardThe logical VXLAN-based network built on top of the physical underlay in Cisco SD-Access, used to carry encapsulated user traffic between fabric edge nodes.
- Uses VXLAN encapsulation for data plane traffic
- Runs independently of physical topology (underlay)
- Enables mobility and segmentation across the fabric
Memory trick: Underlay is the road, overlay is the tunnel traffic rides through.
OSPF DR/BDR Election
Flip cardOn multi-access networks, OSPF elects a Designated Router (DR) and Backup DR (BDR) to reduce the number of adjacencies; election is based on highest interface priority, then highest router ID.
- Default priority is 1; range is 0-255
- Priority 0 makes a router ineligible to be DR/BDR (DROTHER)
- Election is non-preemptive once DR/BDR are chosen
Memory trick: Priority 0 means 'I refuse the crown.'
Null0 Discard Route
Flip cardA static route pointing to interface Null0 causes the router to silently drop any packets matching that route, commonly used to prevent routing loops when advertising summarized address blocks.
- Command: ip route <network> <mask> Null0
- Longest prefix match still applies: specific in-use subnets are preferred over the summarized Null0 route
- Prevents black-hole loops when an aggregate is advertised but some subnets don't exist
Memory trick: Advertise the whole block, drop the empty corners into the void.
LACP Active/Passive Modes
Flip cardLACP EtherChannel requires at least one side configured as 'active' to initiate negotiation; 'passive' only responds.
- active + active = forms channel
- active + passive = forms channel
- passive + passive = never forms channel
- PAgP uses desirable/auto instead of active/passive
Memory trick: Two passives just wait for someone to speak first — silence forever.
IPv6 Static Route with Link-Local Next Hop
Flip cardAn IPv6 static route pointing to a next-hop link-local address must include the exit interface because link-local addresses are not unique across interfaces.
- Syntax: ipv6 route <prefix>/<len> <exit-intf> <link-local-addr>
- Link-local addresses (fe80::/10) are interface-scoped
- Global unicast next hops do not require the exit interface
Memory trick: Link-local needs a map (interface) to know where it lives.
OSPF Hello/Dead Timer Matching
Flip cardNeighboring OSPF routers on the same segment must have identical hello and dead intervals or the adjacency will not form correctly.
- Default hello=10s/dead=40s on broadcast and point-to-point links
- Mismatched timers show as a debug/log error and adjacency stalls
- Process ID and router-id do not need to match between neighbors
Memory trick: Clocks must tick together or the handshake breaks
Dynamic ARP Inspection (DAI)
Flip cardA security feature that validates ARP packets using the DHCP snooping binding table to prevent ARP spoofing attacks.
- Relies on DHCP snooping binding table
- Drops ARP packets with mismatched IP-MAC bindings
- Configured per VLAN, trusted ports skip inspection
Memory trick: DAI is the Detective checking ARP IDs against the Binding Book
First Hop Redundancy Protocol (FHRP)
Flip cardA protocol that provides transparent failover of the default gateway using a shared virtual IP and MAC address.
- Examples: HSRP (Cisco), VRRP (standard), GLBP (Cisco, load balancing)
- Hosts are configured with the virtual IP as their gateway
- Active router forwards traffic; standby takes over on failure
Memory trick: One virtual door, two guards ready to swap in.
Unique Local Address (ULA)
Flip cardAn IPv6 address type in the FC00::/7 block (commonly FD00::/8) used for private, internal-only routing, analogous to IPv4 private addressing.
- Range: FC00::/7, practical use FD00::/8
- Not routable on the public internet
- Different from link-local (FE80::/10) which is not routed at all
Memory trick: FD is Family and friends Domain—stay inside the house.
Errdisable Recovery
Flip cardGlobal commands that allow a switch to automatically bring an err-disabled port back up after a specified time interval for a given cause.
- errdisable recovery cause <cause> enables auto-recovery for that trigger
- errdisable recovery interval <seconds> sets the timer (default 300s)
- Without these commands, manual shutdown/no shutdown is required
Memory trick: Set the cause, set the clock, let the port wake itself up.
Centralized WLC Architecture
Flip cardA design where a wireless LAN controller centrally manages configuration, RF settings, and control functions for multiple lightweight access points.
- Uses CAPWAP tunnels between APs and WLC
- Simplifies large-scale wireless deployments
- Contrasts with autonomous AP model where each AP is independently configured
Memory trick: 'One brain, many antennas' — WLC is the brain for all APs.
AAA Authorization
Flip cardAuthorization is the AAA process that determines what resources or commands an authenticated user is permitted to access or execute.
- Comes after authentication in the AAA model
- TACACS+ supports per-command authorization
- Configured with 'aaa authorization' statements
Memory trick: Authenticate WHO you are, Authorize WHAT you can do, Account for WHAT you did.
Full Tunneling vs Split Tunneling
Flip cardFull tunneling routes all client traffic through the VPN for inspection, while split tunneling only routes traffic destined for corporate resources through the tunnel, letting other traffic go directly to the internet.
- Full tunneling increases security but consumes more bandwidth at the VPN gateway
- Split tunneling improves performance but reduces visibility/control
- Configured via VPN group policy on the ASA or router
Memory trick: Full tunnel = all roads lead through headquarters; split tunnel = some roads go straight to town.
Recursive Static Route
Flip cardA static route whose next hop is an IP address (not an exit interface) requires the router to look up that next-hop IP again in the routing table to determine the actual outgoing interface.
- Contrasts with exit-interface static routes, which need no recursive lookup
- Adds slight CPU overhead due to the extra table lookup
- Next hop must be reachable via another route entry, or the static route stays inactive
Memory trick: Next-hop IP? Look it up twice before you leap.
Extended System ID (Bridge Priority)
Flip cardModern Catalyst switches embed the VLAN ID into the lower bits of the bridge priority field so priority values must be multiples of 4096, with the VLAN ID added to form the actual advertised priority.
- Priority must be configured in increments of 4096 (0-61440)
- Actual advertised priority = configured priority + VLAN ID
- Default STP priority is 32768
- Lower bridge ID (priority+MAC) wins root election
Memory trick: Configured priority plus the VLAN number equals what's really sent.
WPA3-SAE
Flip cardWPA3-Personal replaces the WPA2 PSK 4-way handshake with Simultaneous Authentication of Equals (SAE), a secure key-agreement protocol.
- SAE resists offline dictionary attacks
- No RADIUS server needed for Personal mode
- WPA2 4-way handshake is vulnerable to KRACK attacks
Memory trick: SAE Says Attackers Excluded
IPv6 Multicast (ff02::1)
Flip cardff02::1 is the reserved link-local scope multicast address representing all IPv6 nodes on a local network segment.
- ff02::1 = all-nodes multicast
- ff02::2 = all-routers multicast
- IPv6 has no broadcast; multicast replaces it
Memory trick: 'ff02::1 = everybody on the block gets the memo.'
Ansible Inventory Groups
Flip cardNamed collections of hosts in an Ansible inventory file, defined using square brackets, that allow playbooks to target specific sets of devices.
- Defined with [group_name] syntax
- Playbooks reference groups via the 'hosts:' key
- A host can belong to multiple groups
Memory trick: Brackets build buckets — sort devices into groups.
Terraform Plan
Flip cardA Terraform command that compares the current state to the desired configuration and displays a preview of additions, changes, and deletions before applying them.
- Runs after 'terraform init'
- Does not make actual changes to infrastructure
- Helps prevent unintended changes before 'terraform apply'
Memory trick: Init, Plan, Apply — map it, check it, build it.
Collision vs Broadcast Domain (Switch)
Flip cardOn a switch, each port is a separate collision domain, but all ports in the same VLAN share one broadcast domain.
- Switches eliminate collisions per port via full duplex
- VLANs define broadcast domain boundaries
- Routers are needed to separate broadcast domains between VLANs
Memory trick: 'Every port collides alone, but VLANs shout together.'
Token-Based API Authentication
Flip cardAn authentication method where a client submits credentials once, receives a token, and then includes that token in a header (e.g., X-Auth-Token) on subsequent API requests instead of resending credentials.
- Reduces repeated transmission of passwords
- Tokens often expire and must be refreshed
- Cisco DNA Center uses X-Auth-Token after a POST to /dna/system/api/v1/auth/token
Memory trick: Get the key once, flash it in every header after.
TCP RST Flag
Flip cardThe RST (reset) flag in TCP immediately terminates a connection attempt, commonly sent when a port is closed or a firewall rejects the connection.
- Normal handshake: SYN → SYN-ACK → ACK
- RST in response to SYN means port closed/connection refused
- Different from a timeout, which shows no response at all
Memory trick: RST is TCP slamming the door shut immediately.
Router (Layer 3 Forwarding)
Flip cardA router is a network device that forwards packets between different IP networks using destination IP address and a routing table.
- Operates at Layer 3 (Network layer)
- Separates broadcast domains
- Uses routing table/protocols to choose best path
Memory trick: Routers Route between networks, Switches Switch within one.
Terraform State File
Flip cardA file (terraform.tfstate) that tracks the current known state of managed infrastructure, used by Terraform to detect drift and determine what changes are needed to reach the desired configuration.
- Stored typically as JSON
- Refreshed during plan/apply to detect drift
- Critical for accurate diffing between desired and actual state
Memory trick: The state file is Terraform's memory of what it built.
Declarative vs Imperative
Flip cardDeclarative configuration defines the desired end-state and lets the tool figure out how to achieve it (e.g., Terraform); imperative configuration specifies exact steps to execute (e.g., traditional scripts).
- Terraform is declarative infrastructure-as-code
- Ansible playbooks are largely declarative but task order matters
- Imperative = 'how', Declarative = 'what'
Memory trick: Declarative says WHAT you want; imperative says HOW to get it.
VLSM Subnet Sizing
Flip cardVariable Length Subnet Masking allows different subnet sizes within the same major network, sized to match each segment's host requirement to minimize address waste.
- Formula: 2^n - 2 >= required hosts, solve for smallest n
- /25 = 126 usable hosts, fits 100-host requirement
- VLSM assigns the largest subnets first when dividing address space
Memory trick: Fit the subnet like a tailored suit—not too big, not too small.
ACL 'established' Keyword
Flip cardThe 'established' keyword in an extended ACL permits TCP packets with the ACK or RST flag set, allowing return traffic from internally initiated sessions while blocking externally initiated new connections.
- Only applies to TCP, not UDP
- Matches ACK or RST flags, not SYN-only packets
- Provides basic stateful-like filtering without a full stateful firewall
Memory trick: 'established' lets the reply in, but blocks the knock at the door (SYN).
Type 9 (scrypt) Secret
Flip cardType 9 enable/user secrets use the scrypt hashing algorithm, which is computationally and memory intensive, making them much harder to brute-force than Type 5 MD5-based hashes.
- Type 5 = MD5-based hash, faster to crack with modern hardware
- Type 9 = scrypt-based hash, resistant to GPU/ASIC cracking
- Type 7 is reversible and considered very weak, unrelated to Type 9
Memory trick: Type 9 is the slow tortoise that outlasts crackers; Type 7 is a paper lock.
Directional Antenna
Flip cardAn antenna type (e.g., Yagi, patch) that focuses RF energy into a specific direction rather than radiating equally in all directions, useful for long corridors or point-to-point links.
- Directional antennas increase range/gain in one direction
- Omnidirectional antennas spread coverage evenly in 360 degrees
- Warehouse aisles, hallways, and point-to-point bridges benefit from directional antennas
Memory trick: 'Aisle needs a beam, not a bubble' — directional focuses the signal.
Autonomous vs Lightweight AP
Flip cardAutonomous APs are standalone devices with full configuration and control locally, while lightweight APs rely on a WLC via CAPWAP for centralized management.
- Autonomous = no controller needed
- Lightweight = requires WLC and CAPWAP
- Autonomous better for very small networks
- Lightweight scales better for large deployments
Memory trick: Autonomous APs think for themselves; Lightweight APs need a brain (WLC).
Point-to-Point Subnetting (/30)
Flip cardA /30 subnet is commonly used for WAN links between two routers because it provides exactly 2 usable host addresses, minimizing wasted address space.
- /30 = 4 total addresses, 2 usable (network + broadcast reserved)
- /31 (RFC 3021) can also be used, providing 2 usable addresses with no reserved network/broadcast
- Larger subnets waste addresses on point-to-point links
Memory trick: 'Two routers, two addresses — /30 fits like a glove.'
Terraform vs Ansible for Provisioning
Flip cardTerraform excels at infrastructure provisioning and lifecycle management via a persistent state file that tracks resources and detects drift, while Ansible focuses on agentless configuration management and orchestration tasks.
- Terraform: state file tracks infrastructure lifecycle
- Ansible: agentless, playbook-driven configuration management
- Both are declarative but serve different primary use cases
Memory trick: Terraform builds and remembers; Ansible configures and moves on.
Wildcard Mask Calculation
Flip cardA wildcard mask is the inverse of a subnet mask, used in ACLs to define which bits must match.
- Wildcard = 255 - subnet mask octet
- /21 = 255.255.248.0 subnet mask
- Wildcard mask 0.0.7.255 matches /21
Memory trick: Wild subtracts from 255 to find the flip side
IPv6 Link-Local Address
Flip cardA link-local address (FE80::/10) is automatically assigned to every IPv6 interface for communication only within the local network segment.
- Never routed off the local link
- Used for protocols like OSPFv3 and NDP
- Automatically generated via EUI-64 or random interface ID
Memory trick: FE80 stays local, like a note stuck to your own fridge.
Single-mode vs Multimode Fiber
Flip cardSingle-mode fiber uses a narrow core and laser light for long-distance, high-bandwidth transmission; multimode fiber uses a wider core and LED/laser light for shorter distances.
- Single-mode: distances up to 40+ km depending on optics
- Multimode: typically under 2 km
- Both are immune to electromagnetic interference
Memory trick: Single-mode goes the single longest distance.
OSPF Router ID Selection
Flip cardOSPF chooses its Router ID in this order: manually configured router-id, highest IP on an active loopback, then highest IP on an active physical interface.
- Loopbacks always beat physical interfaces
- Router ID must be unique per OSPF domain
- Changing router-id requires clearing OSPF process or reboot
Memory trick: Loopback is loyal—it always wins the ID crown
TCP Three-Way Handshake Failure
Flip cardWhen a client's SYN segment receives no SYN-ACK response, the TCP connection cannot be established, indicating a problem with the destination server or path, not the application layer.
- Handshake steps: SYN → SYN-ACK → ACK
- Missing SYN-ACK means connection setup failed early
- Common causes: server down, firewall blocking port, routing failure
Memory trick: 'No SYN-ACK, no handshake, no connection.'
2.4 GHz Non-overlapping Channels
Flip cardIn the 2.4 GHz Wi-Fi band, only three 20 MHz-wide channels (1, 6, 11) do not overlap with each other, making them the standard choice for multi-AP deployments.
- 2.4 GHz band channels are 5 MHz apart but 20-22 MHz wide
- Only 1, 6, 11 avoid overlap
- 5 GHz band has many more non-overlapping channels due to wider spectrum
Memory trick: One, Six, Eleven—the golden trio of clean 2.4 GHz channels.
IPv6 Default Static Route
Flip cardAn IPv6 default route directs all unmatched traffic to a specified next hop, configured with 'ipv6 route ::/0 [interface] [next-hop]'.
- ::/0 is the IPv6 equivalent of 0.0.0.0/0
- Exit interface often required with link-local next-hops
- IPv6 routing must be enabled with 'ipv6 unicast-routing'
Memory trick: Double-colon zero slash zero opens every IPv6 door
CAPWAP Control and Data Channels
Flip cardCAPWAP (Control And Provisioning of Wireless Access Points) uses two logical tunnels between AP and WLC: a control channel (always DTLS-encrypted by default) and a data channel (DTLS encryption optional).
- Control channel: UDP port 5246, DTLS encrypted by default
- Data channel: UDP port 5247, encryption optional, must be enabled manually
- Enabling data DTLS increases CPU load on WLC and APs
Memory trick: Control is always locked, Data's lock is optional.
Usable Hosts Calculation
Flip cardFor any subnet, usable hosts = 2^(host bits) - 2, subtracting the network and broadcast addresses.
- /27 = 5 host bits = 30 usable hosts
- /28 = 4 host bits = 14 usable hosts
- /26 = 6 host bits = 62 usable hosts
Memory trick: Take 2 to the host bits, then evict 2 tenants (network & broadcast).