CCNA 200-301
The single exam for Cisco Certified Network Associate certification.
Getting Started: Your CCNA Journey
Free knowledge base
Everything from the course in one searchable place: 323 entries. Use it to review before a practice test or look up a word you forgot.
323 results · showing first 300, refine your search
The single exam for Cisco Certified Network Associate certification.
Getting Started: Your CCNA Journey
Major topic areas covered by the exam with specific weightings.
Getting Started: Your CCNA Journey
A simulation-based question requiring CLI interaction on a virtual device.
Getting Started: Your CCNA Journey
Process to renew a Cisco certification before it expires.
Getting Started: Your CCNA Journey
Credits earned through approved activities to recertify.
Getting Started: Your CCNA Journey
Percentage of exam questions from a specific domain.
Getting Started: Your CCNA Journey
Official Cisco platform for exam topics and study resources.
Getting Started: Your CCNA Journey
To remember the exam domains, think: 'Net Access Connects Services Securely with Automation.' (Network Fundamentals, Network Access, IP Connectivity, IP Services, Security Fundamentals, Automation & Programmability)
Getting Started: Your CCNA Journey
The CCNA 200-301 exam is 120 minutes long and typically has 90-120 questions. The official passing score is not published but is generally around 825-850 out of 1000. Recertification is required every three years.
Getting Started: Your CCNA Journey
Underestimating the breadth of topics: The CCNA is a single exam but covers a wide range of foundational networking concepts.
Getting Started: Your CCNA Journey
Ignoring exam weightings: Not prioritizing study time based on the percentage of questions from each domain.
Getting Started: Your CCNA Journey
Neglecting official Cisco resources: Not reviewing the official exam topics list on the Cisco Learning Network.
Getting Started: Your CCNA Journey
Retrieving information from memory without external cues.
Getting Started: Your CCNA Journey
Cisco's free network simulation tool for learning.
Getting Started: Your CCNA Journey
Graphical Network Simulator-3, advanced network emulation software.
Getting Started: Your CCNA Journey
Emulated Virtual Environment - Next Generation, powerful network emulator.
Getting Started: Your CCNA Journey
Using actual hardware devices for hands-on practice.
Getting Started: Your CCNA Journey
Software-based simulation or emulation of network devices.
Getting Started: Your CCNA Journey
A structured schedule for covering exam topics and practice.
Getting Started: Your CCNA Journey
LABS: Learn, Apply, Build, Study. Always be doing LABS!
Getting Started: Your CCNA Journey
The exam expects you to not just know commands, but to understand their output and use them for verification and troubleshooting. Practice interpreting 'show' commands.
Getting Started: Your CCNA Journey
Relying solely on reading and watching videos without hands-on practice.
Getting Started: Your CCNA Journey
Not creating a structured study plan or sticking to it inconsistently.
Getting Started: Your CCNA Journey
Avoiding troubleshooting in labs; only configuring successful scenarios.
Getting Started: Your CCNA Journey
Connects different networks and forwards packets based on IP addresses.
Network Fundamentals: The Building Blocks
Connects devices within a LAN and forwards frames based on MAC addresses.
Network Fundamentals: The Building Blocks
Monitors and controls network traffic based on security rules.
Network Fundamentals: The Building Blocks
Allows wireless devices to connect to a wired network.
Network Fundamentals: The Building Blocks
Centrally manages and configures multiple Access Points.
Network Fundamentals: The Building Blocks
Table on a switch mapping MAC addresses to ports.
Network Fundamentals: The Building Blocks
Table on a router mapping network destinations to next hops.
Network Fundamentals: The Building Blocks
To remember the core devices: 'RSF AW' - Routers, Switches, Firewalls, Access Points, WLCs. It's like 'RSVP' but for network gear!
Network Fundamentals: The Building Blocks
The exam frequently tests the OSI layer at which devices operate. Remember: Switches are primarily Layer 2, Routers are Layer 3, and Firewalls can operate at multiple layers but are often associated with Layer 3/4 and above for filtering.
Network Fundamentals: The Building Blocks
Confusing the function of a switch (Layer 2, MAC addresses, within a LAN) with a router (Layer 3, IP addresses, between networks).
Network Fundamentals: The Building Blocks
Underestimating the importance of a firewall's role in network security; it's not just a fancy router.
Network Fundamentals: The Building Blocks
Forgetting that APs are just the 'on-ramp' for wireless devices, while WLCs manage the whole wireless highway system.
Network Fundamentals: The Building Blocks
The actual physical layout of network devices and cables.
Network Fundamentals: The Building Blocks
How data flows through the network, independent of physical layout.
Network Fundamentals: The Building Blocks
Copper cable with pairs of wires twisted to reduce interference, used for Ethernet.
Network Fundamentals: The Building Blocks
Cable using glass or plastic fibers to transmit data via light pulses.
Network Fundamentals: The Building Blocks
Connection-oriented, reliable transport protocol; guarantees delivery.
Network Fundamentals: The Building Blocks
Connectionless, unreliable transport protocol; fast, no delivery guarantee.
Network Fundamentals: The Building Blocks
TCP process to establish a connection (SYN, SYN-ACK, ACK).
Network Fundamentals: The Building Blocks
Feature allowing network devices to automatically detect and correct cable type.
Network Fundamentals: The Building Blocks
TCP is 'Tender, Caring, Protocol' – it cares about delivery. UDP is 'Uncaring, Don't-care, Protocol' – it just sends and hopes!
Network Fundamentals: The Building Blocks
The CCNA exam frequently tests your understanding of TCP vs. UDP characteristics. Memorize that TCP is 'connection-oriented' and 'reliable', while UDP is 'connectionless' and 'unreliable'. Also, know the common applications associated with each, e.g., HTTP/FTP for TCP, DNS/VoIP for UDP.
Network Fundamentals: The Building Blocks
Confusing physical and logical topologies; they are distinct concepts.
Network Fundamentals: The Building Blocks
Incorrectly using crossover vs. straight-through cables on older equipment (though Auto-MDIX helps).
Network Fundamentals: The Building Blocks
Assuming all network problems are due to physical cabling; sometimes it's protocol-related.
Network Fundamentals: The Building Blocks
32-bit identifier for devices on a network.
Network Fundamentals: The Building Blocks
Defines network and host portions of an IPv4 address.
Network Fundamentals: The Building Blocks
Dividing a large network into smaller subnetworks.
Network Fundamentals: The Building Blocks
Router IP address for traffic leaving the local network.
Network Fundamentals: The Building Blocks
Translates domain names to IP addresses.
Network Fundamentals: The Building Blocks
128-bit identifier, next-generation IP addressing.
Network Fundamentals: The Building Blocks
IPv6 address type for one-to-one communication.
Network Fundamentals: The Building Blocks
IPv6 address valid only on the local link.
Network Fundamentals: The Building Blocks
N-H-S: Network, Host, Subnet. Remember the order for IPv4 address parts and how the subnet mask helps separate them!
Network Fundamentals: The Building Blocks
Memorize the default subnet masks for Class A (/8), B (/16), and C (/24) IPv4 networks, even though CIDR is prevalent. Also, know the common IPv6 address types: Global Unicast, Link-Local, Unique Local, Multicast, and Anycast. The exam often asks to identify these.
Network Fundamentals: The Building Blocks
Confusing network address with host address: The network address has all host bits as 0, and the broadcast address has all host bits as 1. Neither can be assigned to a host.
Network Fundamentals: The Building Blocks
Incorrectly calculating usable host addresses: Always subtract 2 (for network and broadcast addresses) from the total possible host addresses in a subnet.
Network Fundamentals: The Building Blocks
Forgetting the default gateway or DNS: These are common culprits for 'can't reach the internet' issues.
Network Fundamentals: The Building Blocks
Latest Wi-Fi security standard, offering enhanced encryption and authentication.
Network Fundamentals: The Building Blocks
IEEE standard for port-based network access control, often used with RADIUS.
Network Fundamentals: The Building Blocks
Software-based emulation of a physical computer system.
Network Fundamentals: The Building Blocks
Software that creates and runs virtual machines on a physical host.
Network Fundamentals: The Building Blocks
Cloud service model providing virtualized computing resources over the internet.
Network Fundamentals: The Building Blocks
Cloud service model providing a platform for developing and running applications.
Network Fundamentals: The Building Blocks
Cloud service model delivering ready-to-use software applications over the internet.
Network Fundamentals: The Building Blocks
To remember the cloud service models, think 'I P S': Infrastructure, Platform, Software. Or, 'I Can See' for Infrastructure, Control, Software.
Network Fundamentals: The Building Blocks
The exam often tests your knowledge of wireless security standards (WPA2 vs. WPA3), frequency bands (2.4 GHz vs. 5 GHz characteristics), and the differences between cloud service models (IaaS, PaaS, SaaS). Pay attention to the 'who manages what' aspect of cloud services.
Network Fundamentals: The Building Blocks
Confusing the characteristics of 2.4 GHz and 5 GHz bands (e.g., thinking 2.4 GHz has higher speed).
Network Fundamentals: The Building Blocks
Mixing up WPA2 and WPA3 security features or thinking WEP is still a viable security option.
Network Fundamentals: The Building Blocks
Not understanding the 'who manages what' responsibility split between IaaS, PaaS, and SaaS.
Network Fundamentals: The Building Blocks
Logically segments a physical network into multiple broadcast domains.
Network Access: Connecting Devices
Area where a broadcast frame will reach all devices.
Network Access: Connecting Devices
Switch port assigned to a single VLAN, for end devices.
Network Access: Connecting Devices
Switch port carrying traffic for multiple VLANs, between switches/routers.
Network Access: Connecting Devices
IEEE standard for VLAN tagging on Ethernet frames.
Network Access: Connecting Devices
12-bit identifier in 802.1Q tag, identifying the VLAN.
Network Access: Connecting Devices
VLAN assigned to untagged traffic on an 802.1Q trunk link.
Network Access: Connecting Devices
Cisco protocol for dynamic trunk negotiation between switches.
Network Access: Connecting Devices
VLANs: 'Virtual LANs, Less Annoying Networks'. Think of them as invisible walls separating departments in a big open office.
Network Access: Connecting Devices
The exam often tests the difference between access and trunk ports, and the purpose of 802.1Q tagging. Remember that 802.1Q is the industry standard for tagging, while DTP is Cisco proprietary. Pay attention to the default native VLAN (VLAN 1) and how it handles untagged traffic.
Network Access: Connecting Devices
Forgetting to configure the native VLAN to match on both ends of a trunk link, leading to connectivity issues for untagged traffic.
Network Access: Connecting Devices
Leaving DTP enabled on ports connected to non-Cisco devices or end devices, which can cause unexpected trunk formation or security vulnerabilities.
Network Access: Connecting Devices
Confusing the purpose of an access port (single VLAN, end device) with a trunk port (multiple VLANs, inter-switch/router link).
Network Access: Connecting Devices
Cisco Discovery Protocol, proprietary Layer 2 neighbor discovery.
Network Access: Connecting Devices
Link Layer Discovery Protocol, open standard Layer 2 neighbor discovery.
Network Access: Connecting Devices
Groups multiple physical links into one logical link.
Network Access: Connecting Devices
Link Aggregation Control Protocol, dynamic EtherChannel negotiation (802.3ad).
Network Access: Connecting Devices
Port Aggregation Protocol, Cisco proprietary dynamic EtherChannel negotiation.
Network Access: Connecting Devices
Rapid Spanning Tree Protocol (802.1w), faster STP convergence.
Network Access: Connecting Devices
Cisco's implementation of RSTP per VLAN.
Network Access: Connecting Devices
LACP: 'L' for 'Link' and 'A' for 'Aggregation' – it aggregates links dynamically!
Network Access: Connecting Devices
Memorize the default STP mode on Cisco switches (PVST+ for older IOS, Rapid PVST+ for newer IOS) and the port states/roles for RSTP (discarding, learning, forwarding; root, designated, alternate, backup). Know that LACP is 802.3ad.
Network Access: Connecting Devices
Forgetting to configure 'spanning-tree mode rapid-pvst' globally before setting root bridges, leading to slower STP convergence.
Network Access: Connecting Devices
Mixing LACP 'active' and 'passive' modes incorrectly, or trying to mix LACP with PAgP or static ON mode on a single EtherChannel.
Network Access: Connecting Devices
Not ensuring all physical interfaces in an EtherChannel have identical speed, duplex, and VLAN configurations, which will prevent the channel from forming.
Network Access: Connecting Devices
Standalone AP, self-contained, manages its own configuration and clients.
Network Access: Connecting Devices
AP managed by a WLC, primarily acts as a radio transceiver.
Network Access: Connecting Devices
Control and Provisioning of Wireless Access Points protocol, tunnels traffic.
Network Access: Connecting Devices
Default AP mode, serves clients and tunnels traffic to WLC.
Network Access: Connecting Devices
AP mode allowing local data switching when WLC is unreachable.
Network Access: Connecting Devices
Service Set Identifier, the name of a wireless network.
Network Access: Connecting Devices
Think of a WLC as a 'Wireless LAndlord Controller' – it manages all the 'AP-artments' (APs), tells them what to do, and collects all the 'traffic-rent' (data) before sending it out.
Network Access: Connecting Devices
On the exam, be ready to distinguish between autonomous and controller-based architectures. Keywords like 'centralized management' or 'seamless roaming' point to controller-based, while 'individual configuration' suggests autonomous. Memorize the primary function of CAPWAP.
Network Access: Connecting Devices
Confusing autonomous APs with lightweight APs: Autonomous APs don't need a WLC, LAPs do.
Network Access: Connecting Devices
Forgetting that CAPWAP is the protocol used for communication between LAPs and WLCs.
Network Access: Connecting Devices
Not understanding that AP modes like Monitor or Sniffer do NOT serve wireless clients.
Network Access: Connecting Devices
The logical interface created by EtherChannel.
Network Access: Connecting Devices
VLANs, Trunks, EtherChannel: 'V-T-E' – 'Very Tough Exam' if you don't know these commands!
Network Access: Connecting Devices
The CCNA exam expects you to know the exact commands for configuring VLANs, 802.1Q trunks, and LACP EtherChannels. Pay close attention to 'switchport mode access', 'switchport mode trunk', 'switchport trunk encapsulation dot1q', and 'channel-group [number] mode active'.
Network Access: Connecting Devices
Forgetting to set 'switchport trunk encapsulation dot1q' before 'switchport mode trunk' on older switches (though newer ones often default to dot1q).
Network Access: Connecting Devices
Not configuring the Port Channel interface itself (e.g., as a trunk) after creating the channel group.
Network Access: Connecting Devices
Assigning an interface to a VLAN that doesn't exist, leading to the port being inactive or in a default state.
Network Access: Connecting Devices
Indicates how a route was learned (e.g., Connected, Static, OSPF).
IP Connectivity: Routing Traffic
The IP network and subnet mask of the target network.
IP Connectivity: Routing Traffic
The IP address of the next router in the path.
IP Connectivity: Routing Traffic
The local interface used to forward a packet.
IP Connectivity: Routing Traffic
Rule: router chooses the most specific route (longest subnet mask).
IP Connectivity: Routing Traffic
Trustworthiness of a route source; lower is preferred.
IP Connectivity: Routing Traffic
Value used by routing protocols to determine best path.
IP Connectivity: Routing Traffic
Route Source, Destination, AD, Metric, Next-Hop, Exit Interface. Remember: 'RDAMNE' – Routing Decisions Are Made Next, Eventually!
IP Connectivity: Routing Traffic
The 'show ip route' command is your best friend for examining the routing table. Pay close attention to the codes (C, S, O, D, R, etc.) which indicate the route source, and always remember that the longest prefix match takes precedence over administrative distance.
IP Connectivity: Routing Traffic
Confusing administrative distance with metric: AD compares different route sources, while metric compares routes from the same source.
IP Connectivity: Routing Traffic
Forgetting that longest prefix match is evaluated *before* administrative distance.
IP Connectivity: Routing Traffic
Not understanding that a missing default route will cause packets to unknown destinations to be dropped.
IP Connectivity: Routing Traffic
A value (0-255) indicating route source trustworthiness; lower is better.
IP Connectivity: Routing Traffic
A manually configured route entry in a router's routing table.
IP Connectivity: Routing Traffic
A static route (0.0.0.0/0) used for destinations not explicitly known.
IP Connectivity: Routing Traffic
A static route with a higher AD, acting as a backup for a primary route.
IP Connectivity: Routing Traffic
A network with only one entry and exit point, often using static routes.
IP Connectivity: Routing Traffic
AD: 'A'lways 'D'ecide with the 'D'irectly connected (0) first, then 'S'tatic (1), then 'E'IGRP (90), then 'O'SPF (110), then 'R'IP (120).
IP Connectivity: Routing Traffic
Memorize the default AD values for directly connected (0), static (1), EIGRP (90), OSPF (110), and RIP (120). The exam frequently tests your understanding of how AD influences route selection, especially in scenarios involving multiple routing protocols or floating static routes.
IP Connectivity: Routing Traffic
Forgetting to specify the subnet mask for IPv4 static routes, or prefix length for IPv6, leading to incorrect routing.
IP Connectivity: Routing Traffic
Configuring a floating static route with an AD that is too low, making it preferred over the primary route instead of acting as a backup.
IP Connectivity: Routing Traffic
Using an exit interface for a static route on a multi-access network (like Ethernet) without also specifying a next-hop IP, which can cause ARP issues.
IP Connectivity: Routing Traffic
Open Shortest Path First, a link-state routing protocol.
IP Connectivity: Routing Traffic
Routing protocol type that builds a full network topology map.
IP Connectivity: Routing Traffic
A 32-bit value uniquely identifying an OSPF router.
IP Connectivity: Routing Traffic
Link-State Advertisement, used to share link-state information.
IP Connectivity: Routing Traffic
Link-State Database, a router's complete topology map.
IP Connectivity: Routing Traffic
Shortest Path First (Dijkstra's), calculates best paths.
IP Connectivity: Routing Traffic
The backbone area in OSPF, all single-area routers belong here.
IP Connectivity: Routing Traffic
Inverse of a subnet mask, used in OSPF network commands.
IP Connectivity: Routing Traffic
OSPF: Oysters Serve Perfect Freshness. (Open Standard, SPF Algorithm, Process ID, Full Adjacency)
IP Connectivity: Routing Traffic
The CCNA exam frequently tests OSPF Router ID selection. Remember, it's the highest active loopback IP, then highest active physical interface IP, or manually configured. Also, know that OSPF uses cost as its metric, and its default Administrative Distance is 110.
IP Connectivity: Routing Traffic
Forgetting to specify the 'area' keyword in the network command, leading to interfaces not participating in OSPF.
IP Connectivity: Routing Traffic
Using an incorrect wildcard mask, causing OSPF to advertise the wrong networks or not advertise any at all.
IP Connectivity: Routing Traffic
Mismatched Hello/Dead intervals or Area IDs between neighbors, preventing adjacency formation.
IP Connectivity: Routing Traffic
Shared IP address used as default gateway by end devices.
IP Connectivity: Routing Traffic
Shared MAC address associated with the virtual IP.
IP Connectivity: Routing Traffic
Cisco proprietary FHRP, active/standby router roles.
IP Connectivity: Routing Traffic
Open standard FHRP, similar to HSRP.
IP Connectivity: Routing Traffic
Cisco proprietary FHRP, provides load balancing.
IP Connectivity: Routing Traffic
Router currently forwarding traffic for the virtual IP.
IP Connectivity: Routing Traffic
Monitors active router, takes over if active fails.
IP Connectivity: Routing Traffic
Allows higher-priority router to become active immediately.
IP Connectivity: Routing Traffic
HSRP: 'H' stands for 'Hot' and 'Hold' – Hot Standby, and it uses a Hold timer. VRRP: 'V' for 'Vendor-neutral' – it's an Open Standard.
IP Connectivity: Routing Traffic
The CCNA exam expects you to differentiate between HSRP, VRRP, and GLBP. Remember HSRP and GLBP are Cisco proprietary, while VRRP is an open standard. Also, know that GLBP uniquely offers load balancing across multiple active gateways.
IP Connectivity: Routing Traffic
Forgetting to enable preemption: A higher priority router won't take over as active if it comes online unless preemption is enabled.
IP Connectivity: Routing Traffic
Using different HSRP group numbers on routers for the same virtual IP: This prevents them from forming a single standby group.
IP Connectivity: Routing Traffic
Not configuring the virtual IP address on the correct interface: HSRP must be configured on the interface connected to the end devices' VLAN.
IP Connectivity: Routing Traffic
Link-state routing protocol for IPv4, using areas.
IP Connectivity: Routing Traffic
A unique 32-bit identifier for an OSPF router.
IP Connectivity: Routing Traffic
Relationship between OSPF neighbors for exchanging routing info.
IP Connectivity: Routing Traffic
For OSPF 'N-A-R-D': Network, Area, Router-ID, Done! (Don't forget the process ID first!)
IP Connectivity: Routing Traffic
The CCNA exam often includes output from 'show ip route' and expects you to identify static routes ('S') and OSPF routes ('O'), their administrative distances, and next-hop information. Be prepared to interpret these outputs.
IP Connectivity: Routing Traffic
Forgetting the 'network' command's wildcard mask in OSPF, or using the subnet mask instead.
IP Connectivity: Routing Traffic
Not verifying static routes with 'show ip route' after configuration, leading to traffic black holes.
IP Connectivity: Routing Traffic
Mismatching OSPF area IDs between directly connected routers, preventing adjacency formation.
IP Connectivity: Routing Traffic
Network Address Translation; translates private IP addresses to public.
IP Services: Essential Network Functions
Port Address Translation; translates multiple private IPs to one public IP using ports.
IP Services: Essential Network Functions
Private IP address of a host on the internal network.
IP Services: Essential Network Functions
Public IP address of an internal host as seen by the outside.
IP Services: Essential Network Functions
Public IP address of a host on an external network.
IP Services: Essential Network Functions
A range of public IP addresses used for dynamic NAT translations.
IP Services: Essential Network Functions
Keyword used in Cisco CLI to enable PAT (many-to-one translation).
IP Services: Essential Network Functions
Non-routable IP addresses (e.g., 192.168.x.x) used within private networks.
IP Services: Essential Network Functions
To remember the NAT types and their mappings: 'S'tatic is 'S'ingle, 'D'ynamic is 'D'iverse (from a pool), 'P'AT is 'P'lenty (many to one).
IP Services: Essential Network Functions
The CCNA exam often tests your understanding of NAT terminology (inside local, inside global, outside global) and the specific commands for configuring PAT, especially the 'overload' keyword. Pay attention to which interface is 'inside' and 'outside'.
IP Services: Essential Network Functions
Forgetting to configure `ip nat inside` and `ip nat outside` on the correct interfaces, leading to no translations.
IP Services: Essential Network Functions
Incorrectly defining the access list for dynamic NAT or PAT, causing some internal IPs to not be translated.
IP Services: Essential Network Functions
Confusing static NAT (1:1 fixed) with dynamic NAT (1:1 from pool) or PAT (many:1 using ports).
IP Services: Essential Network Functions
Network Time Protocol, synchronizes device clocks across a network.
IP Services: Essential Network Functions
A hierarchical level in the NTP system indicating clock accuracy.
IP Services: Essential Network Functions
Dynamic Host Configuration Protocol, assigns IP addresses automatically.
IP Services: Essential Network Functions
Discover, Offer, Request, Acknowledge; the DHCP lease process steps.
IP Services: Essential Network Functions
Simple Network Management Protocol, monitors network devices.
IP Services: Essential Network Functions
Network Management System, a console for monitoring SNMP devices.
IP Services: Essential Network Functions
A password-like string used for authentication in SNMP.
IP Services: Essential Network Functions
DNS is like a phonebook for the internet: you look up a name to find a number.
IP Services: Essential Network Functions
For NTP, remember the stratum hierarchy and that 'ntp server' configures a client, while 'ntp master' makes a device a server. For DHCP, know the DORA process. For DNS, understand its role in name resolution. For SNMP, identify the three components (managed device, agent, NMS) and the purpose of community strings.
IP Services: Essential Network Functions
Forgetting to configure NTP on all critical devices, leading to inconsistent logs.
IP Services: Essential Network Functions
Not having enough IP addresses in a DHCP pool, causing new devices to fail to connect.
IP Services: Essential Network Functions
Misconfiguring DNS server addresses, leading to internet access issues.
IP Services: Essential Network Functions
Using default or weak SNMP community strings, creating security vulnerabilities.
IP Services: Essential Network Functions
Protocol for collecting and sending event messages from network devices.
IP Services: Essential Network Functions
Indicates the importance/urgency of a Syslog message (e.g., error, warning).
IP Services: Essential Network Functions
Identifies the source process or application generating a Syslog message.
IP Services: Essential Network Functions
Quality of Service; prioritizes network traffic to ensure performance.
IP Services: Essential Network Functions
Identifying specific types of traffic for QoS treatment.
IP Services: Essential Network Functions
Secure Shell; encrypted network protocol for secure remote access.
IP Services: Essential Network Functions
Insecure protocol for remote access, transmits data in plain text.
IP Services: Essential Network Functions
Cryptographic keys used by SSH for secure authentication and encryption.
IP Services: Essential Network Functions
SSH is 'Secure SHell', so remember it's the SECURE way to access your devices, unlike Telnet, which just 'Tells Net' everything in plain text.
IP Services: Essential Network Functions
The exam expects you to know the purpose of Syslog, basic QoS concepts (classification, queuing), and how to configure and verify SSH. Remember that Telnet is insecure and SSH is preferred. Be prepared for commands like `crypto key generate rsa` and `transport input ssh`.
IP Services: Essential Network Functions
Using Telnet instead of SSH for remote management, exposing sensitive credentials.
IP Services: Essential Network Functions
Not configuring a domain name or hostname before generating RSA keys for SSH.
IP Services: Essential Network Functions
Ignoring Syslog messages until a problem occurs, missing early warning signs.
IP Services: Essential Network Functions
Trivial File Transfer Protocol, UDP port 69, simple, no authentication.
IP Services: Essential Network Functions
File Transfer Protocol, TCP ports 20/21, authentication, reliable.
IP Services: Essential Network Functions
FTP's dedicated TCP connection (port 21) for commands and responses.
IP Services: Essential Network Functions
FTP's connection (port 20 or dynamic) for actual file transfer.
IP Services: Essential Network Functions
The operating system software for Cisco routers and switches.
IP Services: Essential Network Functions
To 'T'ransfer 'F'iles 'T'rivially, use 'TFTP' on 'U'DP '69'. For 'F'ull 'T'ransfer 'P'ower, use 'FTP' on 'T'CP '20' and '21'.
IP Services: Essential Network Functions
Memorize the port numbers: TFTP uses UDP 69, FTP uses TCP 20 (data) and 21 (control). The exam often tests these specific details.
IP Services: Essential Network Functions
Using TFTP for sensitive files over an untrusted network, exposing data.
IP Services: Essential Network Functions
Forgetting that FTP sends credentials in plaintext, making it vulnerable to sniffing.
IP Services: Essential Network Functions
Confusing TCP and UDP port numbers for these protocols.
IP Services: Essential Network Functions
A sequential list of permit/deny statements for traffic filtering.
Security Fundamentals: Protecting the Network
An individual permit or deny statement within an ACL.
Security Fundamentals: Protecting the Network
Filters traffic based only on source IP address (1-99, 1300-1999).
Security Fundamentals: Protecting the Network
Filters based on source/destination IP, protocol, and port (100-199, 2000-2699).
Security Fundamentals: Protecting the Network
An invisible 'deny any any' at the end of every ACL.
Security Fundamentals: Protecting the Network
ACL identified by a descriptive name instead of a number.
Security Fundamentals: Protecting the Network
SOURce (Standard) is near the DESTination. EXTended is near the SOURce. 'S-D, E-S' – like saying 'SD card, ESports'.
Security Fundamentals: Protecting the Network
The exam expects you to know the difference between standard and extended ACLs, including their numbering ranges and placement recommendations. You must also understand the 'implicit deny' rule and how ACLs are processed sequentially. Be ready to interpret simple ACL configurations.
Security Fundamentals: Protecting the Network
Forgetting the implicit deny: If you don't explicitly permit desired traffic, it will be blocked.
Security Fundamentals: Protecting the Network
Incorrect ACE order: The first match wins, so specific rules must come before general rules.
Security Fundamentals: Protecting the Network
Applying an ACL to the wrong interface or direction (inbound/outbound), leading to unexpected blocking.
Security Fundamentals: Protecting the Network
Limits MAC addresses on a switch port to prevent unauthorized access.
Security Fundamentals: Protecting the Network
Action taken by Port Security when an unauthorized MAC is detected.
Security Fundamentals: Protecting the Network
Learned MAC addresses saved in configuration, persistent across reboots.
Security Fundamentals: Protecting the Network
Prevents rogue DHCP servers and DHCP starvation attacks.
Security Fundamentals: Protecting the Network
Allows all DHCP messages; connects to legitimate DHCP servers/switches.
Security Fundamentals: Protecting the Network
Filters DHCP messages; connects to end-user devices.
Security Fundamentals: Protecting the Network
Table of valid IP-to-MAC mappings built by DHCP Snooping.
Security Fundamentals: Protecting the Network
Prevents ARP spoofing by validating ARP packets against the binding database.
Security Fundamentals: Protecting the Network
Think of 'P-D-D' for 'Protect Devices Daily': Port Security, DHCP Snooping, Dynamic ARP Inspection – your daily network protection trio!
Security Fundamentals: Protecting the Network
The CCNA exam frequently tests your understanding of the interaction between DHCP Snooping and DAI. Remember that DAI relies on the DHCP snooping binding database to function correctly, so DHCP Snooping must be enabled first.
Security Fundamentals: Protecting the Network
Forgetting to enable DHCP Snooping globally and on specific VLANs before configuring DAI, leading to DAI not functioning correctly.
Security Fundamentals: Protecting the Network
Configuring a port connected to a legitimate DHCP server or another switch as 'untrusted' for DHCP Snooping or DAI, causing legitimate traffic to be dropped.
Security Fundamentals: Protecting the Network
Not saving Port Security sticky MAC addresses to the startup configuration, resulting in lost learned addresses after a reboot.
Security Fundamentals: Protecting the Network
Verifying the identity of a user or device.
Security Fundamentals: Protecting the Network
Determining what resources an authenticated user can access.
Security Fundamentals: Protecting the Network
Tracking user activity for auditing or billing purposes.
Security Fundamentals: Protecting the Network
A secure, encrypted connection over a public network.
Security Fundamentals: Protecting the Network
Suite of protocols providing secure IP communication.
Security Fundamentals: Protecting the Network
Centralized AAA protocol, often for network access.
Security Fundamentals: Protecting the Network
Cisco proprietary AAA protocol, often for device administration.
Security Fundamentals: Protecting the Network
AAA: 'Always Authenticate, Always Authorize, Always Account' for security!
Security Fundamentals: Protecting the Network
The CCNA exam expects you to differentiate between RADIUS and TACACS+ (e.g., RADIUS combines Auth/Auth, TACACS+ separates; TACACS+ is Cisco proprietary). Also, know the key improvements of WPA3 over WPA2, especially SAE and OWE.
Security Fundamentals: Protecting the Network
Confusing the roles of Authentication and Authorization; they are distinct steps in the security process.
Security Fundamentals: Protecting the Network
Assuming WPA2 is sufficient for all modern wireless security needs; WPA3 offers significant improvements.
Security Fundamentals: Protecting the Network
Believing a VPN makes you completely anonymous online; it primarily secures the connection to the VPN endpoint, not necessarily your entire internet activity beyond that point.
Security Fundamentals: Protecting the Network
A highly secure, MD5-encrypted password for privileged EXEC mode.
Security Fundamentals: Protecting the Network
Password required for direct physical access via the console port.
Security Fundamentals: Protecting the Network
Password for remote access (Telnet/SSH) via Virtual Terminal lines.
Security Fundamentals: Protecting the Network
IOS command to encrypt all plain-text passwords in the configuration.
Security Fundamentals: Protecting the Network
Process of securing a system by reducing its attack surface.
Security Fundamentals: Protecting the Network
Message Of The Day, displayed to users upon login, often for warnings.
Security Fundamentals: Protecting the Network
P.A.S.S.W.O.R.D.S. for Device Hardening: P-Passwords (strong), A-Authentication (local users), S-SSH (prefer over Telnet), S-Services (disable unused), W-Warnings (banners), O-Obfuscate (encrypt passwords), R-Recovery (backups), D-Disable (unused ports), S-Synchronize (NTP).
Security Fundamentals: Protecting the Network
The CCNA exam expects you to know the difference between 'enable password' (weak, plain-text or easily reversible encryption) and 'enable secret' (strong, MD5-encrypted). Always choose 'enable secret' for privileged EXEC access. Also, remember 'service password-encryption' only encrypts plain-text passwords in the running-config, it doesn't strengthen the encryption of 'enable secret'.
Security Fundamentals: Protecting the Network
Using 'enable password' instead of 'enable secret' for privileged EXEC mode, leaving it vulnerable.
Security Fundamentals: Protecting the Network
Forgetting to use 'service password-encryption' to encrypt plain-text passwords in the configuration.
Security Fundamentals: Protecting the Network
Leaving Telnet enabled for remote access when SSH is available, exposing traffic to eavesdropping.
Security Fundamentals: Protecting the Network
Port security action that disables the interface.
Security Fundamentals: Protecting the Network
ACLs: 'S'ource for Standard, 'E'verything for Extended. Standard 'S'hould be 'S'low (close to destination), Extended 'E'arly (close to source).
Security Fundamentals: Protecting the Network
Memorize the ACL numbering ranges: Standard (1-99, 1300-1999) and Extended (100-199, 2000-2699). Understand the difference between 'in' and 'out' application on interfaces and the implications of placing standard vs. extended ACLs.
Security Fundamentals: Protecting the Network
Forgetting the implicit 'deny any' at the end of every ACL, leading to unexpected traffic drops.
Security Fundamentals: Protecting the Network
Applying an ACL to the wrong interface or in the wrong direction (in/out), causing connectivity issues.
Security Fundamentals: Protecting the Network
Using 'shutdown' violation mode on a production port without an err-disable recovery timer, requiring manual intervention to restore service.
Security Fundamentals: Protecting the Network
Software-Defined Networking; separates control from data plane.
Automation & Programmability: Modern Networking
Makes decisions about how traffic should be forwarded.
Automation & Programmability: Modern Networking
Forwards packets based on control plane decisions.
Automation & Programmability: Modern Networking
Centralized software managing network devices.
Automation & Programmability: Modern Networking
Interface for applications to communicate with the controller.
Automation & Programmability: Modern Networking
Interface for the controller to communicate with devices.
Automation & Programmability: Modern Networking
A common southbound protocol for SDN.
Automation & Programmability: Modern Networking
Think of an 'SDN' like a 'Smart Driving Network'. The 'Controller' is the GPS, telling all the cars (data plane devices) where to go, while the 'Apps' (Northbound) tell the GPS where you want to go. The 'Roads' (Southbound) are how the GPS talks to the cars.
Automation & Programmability: Modern Networking
The CCNA exam expects you to understand the fundamental concept of separating the control plane from the data plane, and the roles of the SDN controller, northbound, and southbound APIs. Look for questions that describe centralized network management or automated policy enforcement.
Automation & Programmability: Modern Networking
Confusing the data plane (forwarding traffic) with the control plane (making forwarding decisions).
Automation & Programmability: Modern Networking
Thinking SDN replaces all traditional networking devices; it orchestrates them.
Automation & Programmability: Modern Networking
Believing OpenFlow is the ONLY southbound protocol; it's just a common example.
Automation & Programmability: Modern Networking
Rules for software to communicate over HTTP, enabling programmatic interaction.
Automation & Programmability: Modern Networking
Lightweight, human-readable data format for exchanging structured data.
Automation & Programmability: Modern Networking
Actions (GET, POST, PUT, DELETE) performed on resources via REST API.
Automation & Programmability: Modern Networking
Fundamental JSON data structure, associating a name with a value.
Automation & Programmability: Modern Networking
Using software to manage and configure network devices.
Automation & Programmability: Modern Networking
Automating complex workflows across multiple network domains/devices.
Automation & Programmability: Modern Networking
An object or data entity managed by a REST API (e.g., interface).
Automation & Programmability: Modern Networking
JSON is Just Some Object Notation – it's simple, like a shopping list: 'item': 'milk', 'quantity': 2. REST is like a Restaurant: you GET food, POST orders, PUT changes, DELETE mistakes.
Automation & Programmability: Modern Networking
The CCNA exam expects you to recognize the purpose of REST APIs for programmatic interaction and JSON as a data encoding format. Focus on 'GET' for retrieving data and 'POST'/'PUT' for sending configuration, and understand JSON's key-value pair and array structure.
Automation & Programmability: Modern Networking
Confusing JSON syntax with Python dictionaries; while similar, they have distinct rules (e.g., JSON requires double quotes for keys and string values).
Automation & Programmability: Modern Networking
Assuming all network devices support REST APIs; older or simpler devices may only support CLI or SNMP.
Automation & Programmability: Modern Networking
Not understanding HTTP methods: Using a POST request when a GET is appropriate, leading to errors or unintended configuration changes.
Automation & Programmability: Modern Networking
Open-source automation engine for configuration management and application deployment.
Automation & Programmability: Modern Networking
YAML file in Ansible that defines a set of tasks to be executed.
Automation & Programmability: Modern Networking