Cisco Certified Support Technician (CCST) Networking flashcards
150 free flashcards. Tap a card to flip it.
JSON (JavaScript Object Notation)
Flip cardA lightweight data-interchange format that is easy for humans to read and write and easy for machines to parse and generate. It is widely used for transmitting data in web applications.
- Human-readable and machine-parseable
- Uses key-value pairs and arrays
- Commonly used in REST APIs for data exchange
Memory trick: APIs speak in structured data languages.
Webhook/Callback API
Flip cardA Webhook (also known as a web callback or HTTP push API) is a method of augmenting or altering the behavior of a web page or web application with custom callbacks. These callbacks are triggered by specific events and send data to a URI specified by the client, enabling real-time, event-driven communication.
- Server-initiated communication.
- Real-time event notification.
- Client registers a URL (endpoint) to receive data.
- Often uses HTTP POST to deliver event data.
Memory trick: POLL for STATUS, REST for RESOURCES, WEBHOOK for EVENTS, BATCH for BULK.
API Query
Flip cardAn API interaction type where a request is made to retrieve specific information or data from a system without altering its state or resources.
- Retrieves data only
- Does not modify the resource or system state
- Often uses HTTP GET method
Memory trick: APIs let you Talk, Ask, and Change.
Virtual Private Network (VPN)
Flip cardA technology that creates a secure, encrypted connection (a 'tunnel') over a less secure network, such as the internet, to provide remote access to private network resources.
- Encrypts data in transit
- Establishes a secure tunnel
- Enables remote access
- Uses protocols like IPsec or SSL/TLS
Memory trick: VPN: Virtual Path for Nifty access.
Authentication
Flip cardThe process of verifying the identity of a user, device, or system trying to access a resource.
- Proves 'who you are'
- Can use passwords, biometrics, tokens
- Often paired with authorization
- MFA significantly strengthens authentication
Memory trick: CIA: Confidentiality, Integrity, Availability. Authentication 'A'lways comes first for access.
Software-Defined Networking (SDN)
Flip cardAn architecture that decouples the network control and forwarding functions, enabling network programmability and abstracting underlying infrastructure from applications and network services.
- Separates control plane from data plane
- Enables centralized network management
- Allows for programmatic network control
Memory trick: SDN: Smartly Directing Networks.
SQL Injection
Flip cardA web security vulnerability that allows an attacker to interfere with the queries that an application makes to its database. It allows an attacker to view, modify, or delete data, or even execute administrative operations on the database server.
- Exploits improper input validation
- Targets database-driven web applications
- Allows execution of arbitrary SQL commands
- Can lead to data breach or system compromise
Memory trick: Web 'W'eaknesses: SQL, XSS, CSRF.
HTTP GET Method
Flip cardThe HTTP GET method is used to request data from a specified resource. It is a read-only operation and should not have any side effects on the server.
- Retrieves data from a server.
- Idempotent (multiple identical requests have the same effect as a single one).
- Can be cached and bookmarked.
Memory trick: GET to GRAB, POST to PUT, PUT to UPDATE, DELETE to DITCH.
Idempotent API Operation
Flip cardAn API operation that, when executed multiple times with the same input, produces the same result as if it had been executed only once, without causing unintended side effects.
- Safe to repeat multiple times
- Prevents unintended side effects (e.g., duplicates)
- Common for PUT, DELETE, and some POST operations
Memory trick: Good APIs are RESTful, Idempotent, and Stateless.
Intent-Based Networking (IBN)
Flip cardAn advanced networking approach that captures business intent and translates it into network policies, automatically configuring and continuously verifying the network to achieve and maintain that desired state.
- Focuses on business intent, not low-level configurations
- Automates configuration and policy enforcement
- Continuously verifies network compliance
Memory trick: SDN evolves from protocols to intent.
MAC Address Filtering
Flip cardA security feature that controls access to a network based on the unique Media Access Control (MAC) address of a device's network interface card.
- Uses a whitelist or blacklist of MAC addresses
- Operates at Layer 2 (Data Link Layer)
- Provides basic network access control
- Can be bypassed by MAC spoofing
Memory trick: NAC 'N'arrowly 'A'llows 'C'onnections.
API Authentication
Flip cardThe process by which an API verifies the identity of a client (user or application) attempting to access its resources, often using API keys, tokens, or credentials.
- Verifies client identity
- Ensures only authorized access
- Commonly uses API keys, OAuth tokens, or basic auth
Memory trick: APIs need security: Authenticate, Authorize, Limit.
XML (Extensible Markup Language)
Flip cardXML is a markup language that defines a set of rules for encoding documents in a format that is both human-readable and machine-readable. It is widely used for data exchange, especially in older web services and network APIs.
- Uses tags to define elements and attributes.
- Platform-independent and extensible.
- Often used in SOAP-based web services and NetConf.
Memory trick: JSON is JAZZY, XML is X-cellent, YAML is YUMMY for data exchange.
Brute-Force Attack
Flip cardAn attack method that involves systematically trying every possible combination of characters until the correct password or key is found.
- Targets authentication mechanisms
- Can be slow and resource-intensive
- Often uses automated tools
- Mitigated by strong passwords, account lockout policies
Memory trick: Password 'P'roblems: Brute-force is persistent.
Demilitarized Zone (DMZ)
Flip cardA physical or logical subnetwork that contains and exposes an organization's external-facing services to a larger and untrusted network, usually the internet, while isolating the internal local-area network (LAN).
- Acts as a buffer zone
- Hosts public-facing servers (web, email, DNS)
- Provides an extra layer of security
- Protects the internal network from direct external access
Memory trick: DMZ: 'D'efense 'M'easures 'Z'one for public servers.
Transport Layer Security (TLS)
Flip cardA cryptographic protocol designed to provide communication security over a computer network. It is the successor to SSL and is widely used for securing web browsing (HTTPS), email, instant messaging, and other data transfers.
- Encrypts data in transit
- Ensures data integrity
- Provides server authentication
- Forms the 'S' in HTTPS
Memory trick: TLS 'T'ransmits 'L'ocked 'S'ecurely for web.
Python 'json' Module
Flip cardThe Python 'json' module provides an API to encode and decode JSON objects. It allows Python data structures (like dictionaries and lists) to be converted to JSON strings and vice-versa, facilitating data exchange with web services and APIs.
- Used to serialize Python objects to JSON strings (json.dumps()).
- Used to deserialize JSON strings to Python objects (json.loads()).
- Handles nested structures like dictionaries and lists.
Memory trick: JSON for JAZZ, XML for X-MEN, CSV for SPREADSHEETS.
SSL/TLS Certificate Validation Errors
Flip cardIssues arising during the process of verifying the authenticity and validity of an SSL/TLS certificate, often preventing a secure connection from being established.
- Can be caused by expired/invalid certificates
- Mismatched hostnames are a common cause
- Incorrect system time can lead to validation failures
Memory trick: Secure connections need Valid Times, Valid Names, and Trusted Roots.
Ping (Packet Internet Groper)
Flip cardPing is a network utility used to test the reachability of a host on an Internet Protocol (IP) network. It measures the round-trip time for messages sent from the originating host to a destination computer and reports errors.
- Uses ICMP (Internet Control Message Protocol) echo request/reply messages.
- Determines if a host is alive and reachable.
- Measures latency (round-trip time) and packet loss.
Memory trick: PING for REACH, TRACE for PATH, NETSTAT for CONNECTIONS, IPCONFIG for INTERFACES.
Distributed Denial of Service (DDoS) Attack
Flip cardA malicious attempt to disrupt the normal traffic of a targeted server, service, or network by overwhelming the target or its surrounding infrastructure with a flood of Internet traffic from multiple compromised computer systems.
- Uses multiple sources (botnet)
- Aims to exhaust resources (bandwidth, CPU, memory)
- Makes services unavailable to legitimate users
- Harder to mitigate than single-source DoS
Memory trick: DoS: 'D'isrupting 'o'perations 'S'everely.
Malware Indicators
Flip cardSigns that a system may be infected with malicious software, often including unusual network activity, performance degradation, or unexpected pop-ups.
- Unusual outbound network connections
- System performance issues without clear cause
- Unexpected pop-ups or browser redirects
- Modified system files or settings
Memory trick: Malware's 'M' for Mysterious Moves: Check the Network, Performance, and Pop-ups.
Declarative Automation
Flip cardAn automation approach where the desired end state of a system or network is defined, and the automation engine is responsible for executing the necessary actions to achieve and maintain that state.
- Focuses on 'what' the state should be, not 'how' to get there
- The system manages the implementation details
- Often used with configuration management tools
Memory trick: Automate by saying what you want, or how to get it.
Confidentiality
Flip cardThe security principle that ensures that information is not disclosed to unauthorized individuals, entities, or processes.
- Protects against unauthorized disclosure
- Achieved through encryption, access controls
- Part of the CIA triad
- Breaches often involve sensitive data exposure
Memory trick: CIA: 'C'onceal, 'I'ntegrate, 'A'ccess.
NETCONF (Network Configuration Protocol)
Flip cardNETCONF is an XML-based protocol designed for configuring, monitoring, and managing network devices. It provides a programmatic and standardized way to interact with network devices, using structured data models (YANG) to define configuration and state information.
- Uses XML for communication (can be JSON with RESTCONF).
- Operates over a secure transport (e.g., SSH).
- Employs YANG data models for structured configuration.
- Provides transactional configuration capabilities.
Memory trick: CLI for COMMANDS, SNMP for STATUS, NETCONF for CONFIGS, RESTCONF for WEB APPS.
API Payload
Flip cardThe data part of an API request or response. It contains the actual information being exchanged between the client and the server, typically in a structured format like JSON or XML.
- Contains the core data of the API interaction
- Format is crucial for data parsing and processing
- Can be part of both requests (input) and responses (output)
Memory trick: APIs have URLs, methods, headers, and the important payload.
Intrusion Prevention System (IPS)
Flip cardA network security device that monitors network traffic for malicious activity and can automatically take action to prevent or block identified threats.
- Performs deep packet inspection
- Uses signature-based and anomaly-based detection
- Actively blocks malicious traffic
- Often deployed in-line with network traffic
Memory trick: IPS 'I'nspects 'P'ackets 'S'ecretly and Stops threats.
HTTP Status Code 403 Forbidden
Flip cardThe HTTP 403 Forbidden status code indicates that the server understood the request but refuses to authorize it. This often means the client does not have the necessary permissions to access the resource.
- Server understood the request.
- Access is denied due to authorization issues.
- Different from 401 Unauthorized (authentication failure).
Memory trick: 400s are CLIENT's FAULT, 500s are SERVER's FAULT.
JSON Parsing (Python)
Flip cardThe process of converting a JSON string into native Python data structures (dictionaries and lists), allowing for programmatic access and manipulation of the data.
- JSON objects map to Python dictionaries
- JSON arrays map to Python lists
- Elements accessed via keys (dictionaries) or indices (lists)
Memory trick: JSON is like a dictionary, use keys to find values.
HTTP POST Method
Flip cardAn HTTP request method used to send data to a server to create or update a resource. It often results in a change of state or side effects on the server.
- Used for creating new resources
- Used for submitting data for processing
- Can update existing resources
Memory trick: CRUD operations map to HTTP methods.
Phishing
Flip cardA social engineering attack where an attacker attempts to trick individuals into revealing sensitive information (like usernames, passwords, credit card details) by impersonating a trustworthy entity in electronic communication.
- Uses deception and impersonation
- Often delivered via email or text (smishing)
- Aims to steal credentials or install malware
- Indicators include suspicious links, generic greetings, urgent tone
Memory trick: Social 'S'chemes: Phishing, Pretexting, Tailgating.
Northbound API (SDN)
Flip cardAn interface exposed by an SDN controller to applications and orchestration systems, allowing them to request network services and provision resources without needing to understand the underlying network infrastructure.
- Controller to application/orchestration communication
- Abstracts network complexity
- Used for provisioning and service requests
Memory trick: North is for apps, South is for devices.
HTTP Status Code 200 OK
Flip cardAn HTTP response status code indicating that the request has succeeded. The information returned with the response depends on the method used in the request.
- Indicates successful request
- For GET, response body contains requested data
- Most common success code
Memory trick: Status codes tell you if it's Good, Redirect, Client bad, or Server bad.
Administrative Distance (AD)
Flip cardAdministrative Distance (AD) is a value used by Cisco routers to rank the trustworthiness of routing information sources, with lower values indicating higher preference.
- Used when multiple routing protocols offer paths to the same destination.
- Compares protocols, not metrics within a protocol.
- Static routes (1) and connected interfaces (0) have the lowest ADs.
Memory trick: Always Determine Every Router's Decision.
Cisco IOS Static NAT Configuration
Flip cardConfiguring static NAT on a Cisco router involves using the 'ip nat inside source static' command to create a one-to-one mapping between private and public IP addresses.
- Requires defining inside and outside NAT interfaces.
- Command: `ip nat inside source static <local-ip> <global-ip>`.
- Enables external access to internal servers.
Memory trick: Inside Source Static is Simple and Sure for Servers.
Static NAT
Flip cardStatic Network Address Translation (NAT) creates a one-to-one, permanent mapping between a specific private IP address and a specific public IP address.
- Used for servers or devices needing consistent inbound access from the internet.
- Mapping is always maintained in the NAT table.
- Consumes one public IP address per translated private IP.
Memory trick: NAT types are like different doors: some for many, some for one-to-one.
Route Summarization (CIDR)
Flip cardRoute summarization, or Classless Inter-Domain Routing (CIDR), combines multiple contiguous IP network addresses into a single, more general address to reduce routing table size.
- Reduces routing table entries.
- Improves routing efficiency and stability.
- Calculated by finding the longest common binary prefix.
Memory trick: Binary Conversion Finds Common Prefix for Consolidation.
Inter-VLAN Routing with SVIs
Flip cardInter-VLAN routing on a Layer 3 switch uses Switch Virtual Interfaces (SVIs), which are logical Layer 3 interfaces associated with VLANs, allowing the switch to route traffic between these directly connected VLAN networks.
- Each SVI acts as the default gateway for its respective VLAN.
- SVIs are treated as directly connected networks in the routing table.
- Enables communication between devices in different VLANs on the same switch.
Memory trick: Each VLAN is a room, the switch is the hallway, and SVIs are the doors.
OSPF DR/BDR Election
Flip cardIn OSPF, a Designated Router (DR) and a Backup Designated Router (BDR) are elected on broadcast multi-access network segments to centralize the exchange of Link-State Advertisements (LSAs) and reduce the number of adjacencies.
- Occurs only on broadcast multi-access networks (e.g., Ethernet).
- DR and BDR manage LSA flooding.
- Reduces the number of OSPF adjacencies from N*(N-1)/2 to N-1.
Memory trick: Many choices need a leader and a backup.
Cisco IOS Default Static Route
Flip cardA Cisco IOS default static route (0.0.0.0/0) is denoted by 'S*' in the routing table, indicating it's a manually configured route that serves as the gateway of last resort.
- S = Static route.
- * = Candidate default route.
- Used when no more specific route exists.
- Traffic is forwarded to the specified next-hop IP or exit interface.
Memory trick: Stars Signal Static Start for Sending.
EIGRP for IPv6 Interface Activation
Flip cardTo enable EIGRP for IPv6 on a Cisco router interface, the `ipv6 eigrp <AS>` command is configured directly under the interface configuration mode.
- Requires `ipv6 unicast-routing` enabled globally.
- `ipv6 router eigrp <AS>` defines the EIGRPv6 process.
- `ipv6 eigrp <AS>` directly activates EIGRPv6 on the interface.
Memory trick: To plug IPv6 into EIGRP, flip the switch directly on the interface.
Static Route Administrative Distance
Flip cardStatic routes, manually configured by an administrator, have a default administrative distance of 1 in Cisco IOS, signifying high trustworthiness.
- Manually configured.
- Default AD of 1.
- Preferred over most dynamic routing protocols.
Memory trick: AD values are like a trust hierarchy, with 0 being absolute truth.
IPv6 Router Advertisement (RA)
Flip cardRouter Advertisement (RA) messages are part of IPv6 Neighbor Discovery Protocol, used by routers to announce their presence and network configuration information to hosts on a link.
- Enables Stateless Address Autoconfiguration (SLAAC).
- Includes network prefixes, default router, and other parameters.
- Sent periodically or in response to Router Solicitation (RS) messages.
Memory trick: Routers Announce Addresses Automatically.
Network Address Translation (NAT)
Flip cardA method of remapping an IP address space into another by modifying network address information in the IP header of packets while they are in transit across a traffic routing device.
- Enables multiple devices on a private network to share a single public IP address.
- Conserves public IPv4 addresses.
- Provides a layer of security by hiding internal network topology.
Memory trick: NAT is like a translator for your house's private language to the public internet's language.
Default Route
Flip cardA default route is a special type of route (0.0.0.0/0 in IPv4, ::/0 in IPv6) that specifies the path for all traffic for which a more specific route is not found in the routing table.
- Acts as the 'gateway of last resort'.
- Essential for connecting to external networks like the Internet.
- Can be static or learned dynamically.
Memory trick: Default Routes Deal with Destinations Unknown.
OSPFv3 for IPv6
Flip cardOSPFv3 is the version of the Open Shortest Path First (OSPF) routing protocol that supports IPv6 (and IPv4) addresses.
- Link-state routing protocol.
- Supports IPv6 (and IPv4 in later implementations).
- Scalable, fast convergence, hierarchical design with areas.
Memory trick: For big IPv6 roads, OSPFv3 is the open, scalable map.
Routing Table Lookup Failure
Flip cardWhen a router receives a packet for a destination network, it consults its routing table. If no matching entry is found, the router discards the packet or forwards it to a default route if one exists.
- A routing table entry is essential for forwarding packets.
- Missing entries can be due to misconfigured static routes or dynamic routing protocol issues.
- Without an entry, traffic cannot be forwarded to that destination.
Memory trick: No map, no path, just a dead end.
OSPFv3 Adjacency Requirements
Flip cardFor OSPFv3 routers to form an adjacency, several parameters must match, including the OSPF area ID, authentication, and network type.
- Neighbors must be in the same OSPF area.
- Hello/Dead timers must match.
- Authentication (if used) must match.
- Network type must be compatible.
Memory trick: Areas Must Align, Or Adjacency Wont Shine.
EIGRP Features
Flip cardEIGRP (Enhanced Interior Gateway Routing Protocol) is a Cisco proprietary hybrid routing protocol known for its rapid convergence and support for unequal-cost load balancing.
- Uses DUAL (Diffusing Update Algorithm) for fast convergence.
- Supports unequal-cost load balancing.
- Cisco proprietary (though open standard in limited form now).
- Uses composite metric (bandwidth, delay, reliability, load).
Memory trick: Each protocol has its own 'personality' for speed and sharing.
BGP Router Command
Flip cardThe `router bgp <AS_number>` command initiates the BGP routing process on a Cisco router and specifies the autonomous system (AS) number for the local router.
- Essential first step for BGP configuration.
- AS number identifies the local BGP domain.
- Enters BGP router configuration mode.
Memory trick: Router BGP Starts the Journey, Neighbors Nurture.
Port Address Translation (PAT)
Flip cardA form of Network Address Translation (NAT) that allows multiple private IP addresses to share a single public IP address by using unique port numbers for each translation.
- Also known as NAT overload.
- Uses port numbers to distinguish between internal hosts.
- Most common type of NAT for internet access in small networks.
Memory trick: Many homes, one street address, different doors.
IPv6 Link-Local Next-Hop
Flip cardAn IPv6 link-local address (FE80::/10) can be used as a next-hop in a routing table, but it is only relevant for the specific local link (interface) it is associated with.
- Only valid on the local segment/interface.
- Requires the outgoing interface to be specified (or implied).
- If the interface is down, the link-local next-hop is unreachable.
Memory trick: IPv6 routes need a clear path and a live next-hop.
Cisco IOS PAT Configuration
Flip cardPort Address Translation (PAT) on Cisco IOS allows multiple private IP addresses to share a single public IP address by using different port numbers.
- Uses 'ip nat inside source list <acl> interface <interface> overload' for one-to-many translation.
- Requires 'ip nat inside' and 'ip nat outside' commands on respective interfaces.
- Saves public IP addresses by mapping multiple private IPs to a single public IP and unique port numbers.
Memory trick: PAT: 'I'm In, Source, List, Interface, Overload' to get Out!
OSPF Network Command
Flip cardThe `network` command in OSPF configuration globally enables OSPF on interfaces whose IP addresses fall within the specified range and assigns them to a particular OSPF area.
- Uses a wildcard mask (inverse of subnet mask) to define the range.
- Activates OSPF on matching interfaces.
- Assigns interfaces to a specific OSPF area.
Memory trick: To plug an interface into OSPF, you declare its network and its area.
EIGRP Passive-Interface
Flip cardA configuration command in EIGRP (and other routing protocols) that disables the sending and receiving of routing updates on a specified interface, while still advertising the network connected to it.
- Prevents neighbor adjacency formation on the interface.
- Conserves bandwidth and router resources.
- Enhances security by not sending routing updates to untrusted networks.
Memory trick: Passive: Quiet on the network front.
IPv6 Static Route Configuration
Flip cardConfiguring an IPv6 static route involves specifying the destination prefix, next-hop IPv6 address, and often the exit interface, especially on multi-access networks.
- Command starts with `ipv6 route`.
- Destination prefix includes the prefix length (e.g., /64).
- For global unicast next-hops on multi-access links, specify both interface and next-hop IP.
Memory trick: Interface and Next-Hop Ensure Correct Route Resolution.
IPv6 Static Route with Link-Local Next-Hop
Flip cardWhen configuring an IPv6 static route with a link-local address (FE80::/10) as the next-hop, it is mandatory to specify the outgoing interface because link-local addresses are only significant on the local link.
- Link-local addresses are not globally routable.
- Requires `ipv6 route <destination> <interface> <link-local-next-hop>` syntax.
- Ensures the router knows which specific local link to use for the next-hop.
Memory trick: For a link-local IPv6 hop, you need both the road (interface) and the house number (next-hop).
EIGRP Metric
Flip cardEIGRP uses a composite metric based on bandwidth and delay (by default) to determine the best path to a destination.
- Metric is calculated using the DUAL algorithm.
- Default K-values prioritize bandwidth and delay.
- Can be tuned to include reliability, load, and MTU.
Memory trick: Every Router Intelligently Guides Routes with Bandwidth and Delay.
Denial of Service (DoS)
Flip cardA cyber-attack where the perpetrator seeks to make a machine or network resource unavailable to its intended users by temporarily or indefinitely disrupting services of a host connected to the Internet.
- Originates from a single source.
- Aims to consume resources or crash services.
- Prevents legitimate users from accessing services.
Memory trick: Availability attacks are like closing a store during business hours.
Multi-factor Authentication (MFA)
Flip cardA security system that requires a user to provide two or more verification factors to gain access to a resource such as an application, online account, or VPN.
- Combines different types of authentication factors.
- Common factors: something you know, something you have, something you are.
- Significantly reduces the risk of unauthorized access.
Memory trick: Authentication factors are how you prove you are who you say you are.
Least Privilege
Flip cardThe security principle that states users or processes should be granted only the minimum necessary access rights to perform their job or function.
- Minimizes potential damage from errors or malicious acts.
- Reduces the attack surface.
- Applies to users, applications, and systems.
Memory trick: Security principles are the foundational rules for keeping things safe.