CompTIA Network+ (N10-009) flashcards
196 free flashcards. Tap a card to flip it.
PoE Standards (802.3af/at/bt)
Flip cardIEEE standards defining how much power can be delivered over Ethernet cabling to powered devices.
- 802.3af (PoE): up to 15.4W at source / 12.95W at device
- 802.3at (PoE+): up to 30W at source / 25.5W at device
- 802.3bt (PoE++): up to 60W or 100W depending on type
Memory trick: 'af < at < bt' — more letters, more watts.
Bus Topology
Flip cardA network design where all devices connect to a single shared backbone cable terminated at both ends to prevent signal reflection.
- Requires terminators at both ends
- Single point of failure (the cable)
- Largely obsolete, replaced by star topologies
Memory trick: Bus = one long road, everyone shares the same lane.
eBGP vs iBGP Administrative Distance
Flip cardBGP routes learned from external peers (eBGP) have a default AD of 20, while routes learned from internal peers (iBGP) have a default AD of 200, making eBGP routes preferred by default.
- eBGP default AD = 20
- iBGP default AD = 200
- Lower AD wins when comparing routes to the same destination
Memory trick: 'e' comes before 'i' in the alphabet, and eBGP's AD (20) beats iBGP's (200).
Route Summarization (Supernetting)
Flip cardRoute summarization combines multiple contiguous subnets into a single, larger CIDR block to reduce the number of routes advertised.
- Number of /24s summarized = 2^(24-new prefix)
- 4 x /24 networks combine into one /22
- Summarization reduces routing table size and improves efficiency
Memory trick: 4 blocks of /24 = borrow 2 bits = /22, since 2^2=4.
Cat6a Cable
Flip cardCat6a (Category 6 augmented) twisted-pair cable supports 10 Gbps Ethernet (10GBASE-T) at the full 100-meter distance with improved crosstalk shielding.
- Supports 10Gbps up to 100 meters
- Improved shielding reduces alien crosstalk
- Backward compatible with Cat6 and Cat5e
Memory trick: Cat6a = 'a' for 'always 100 meters at 10 gig'.
Recovery Time Objective (RTO)
Flip cardThe maximum acceptable amount of time a system or service can be down after a disruption before business impact becomes unacceptable.
- Measures downtime tolerance, not data loss
- Compared against actual restoration time to judge DR success
- Works alongside RPO to define full DR requirements
Memory trick: RTO = Time to Turn it back On.
Out-of-Band Management
Flip cardA management method that uses a separate, independent connection (e.g., console port with cellular modem) to access network devices, bypassing the primary production network.
- Survives outages affecting the main LAN/WAN
- Commonly implemented via console servers with cellular backup
- Contrasts with in-band management, which uses the production network path
Memory trick: Out-of-band means out-of-the-storm — a backdoor when the front door is down.
tcpdump Syntax
Flip cardA command-line packet analyzer used to capture and filter network traffic, using flags like -i for interface and BPF filter expressions like 'port'.
- -i specifies the capture interface (e.g., eth0)
- 'port 80' filters traffic on TCP or UDP port 80
- -D lists available capture interfaces rather than filtering traffic
- tcpdump uses BPF syntax, different from Wireshark display filter syntax
Memory trick: Interface first, then filter the port
DNS Port 53
Flip cardDNS translates hostnames to IP addresses and operates over port 53, using UDP for standard queries and TCP for larger responses or zone transfers.
- UDP 53 for typical queries
- TCP 53 for zone transfers and large responses
- Blocking port 53 breaks name resolution but not raw IP connectivity
Memory trick: Dial 53 to find the name behind the number.
Change Management
Flip cardA formal process for proposing, reviewing, approving, and documenting changes to IT systems to reduce risk and maintain accountability.
- Includes change request, impact analysis, and rollback plan
- Requires approval from a change advisory board (CAB) in many orgs
- Reduces unplanned outages caused by unreviewed changes
Memory trick: No change goes live without a chaperone (CAB approval).
802.1Q VLAN Tagging
Flip cardIEEE 802.1Q is the standard that inserts a VLAN tag into Ethernet frames so a single trunk link can carry traffic for multiple VLANs.
- Adds a 4-byte tag with VLAN ID (0-4094)
- Enables trunking between switches
- Native VLAN traffic is typically untagged
Memory trick: Q marks the tag that keeps VLANs distinct on one wire.
SDN Southbound API
Flip cardThe interface used by an SDN controller to communicate with and program the underlying network devices (switches/routers) in the data plane, commonly using protocols like OpenFlow.
- Connects controller to physical/virtual switches
- OpenFlow is a common southbound protocol
- Contrasts with northbound API, which connects controller to applications
Memory trick: Southbound goes down to devices; northbound goes up to apps.
Unlit Link Lights
Flip cardIndicates a lack of physical connection or active link between two network devices, typically at Layer 1 of the OSI model.
- Symptoms: No network connectivity, no link activity.
- Common causes: Disconnected cable, faulty cable, faulty NIC/port, device powered off.
- Troubleshooting starts with checking physical connections.
Memory trick: No light, no fight! Check the cable, make it right.
DHCP DORA Process
Flip cardDHCP assigns IP addresses through a four-step handshake: Discover, Offer, Request, and Acknowledge (DORA).
- Discover: client broadcasts for a DHCP server
- Offer: server proposes an IP lease
- Request: client accepts the offered lease
- Acknowledge: server confirms the lease
Memory trick: Dora Offers Requests Acknowledged - remember DORA in order.
Clientless SSL VPN
Flip cardA remote access method that provides secure, browser-based access to specific internal applications over HTTPS without requiring dedicated VPN client software or full network access.
- Operates at the application layer via a web browser
- Limits exposure by restricting access to specific apps, not the whole network
- Contrasts with IPSec VPNs, which typically grant network-layer access
Memory trick: Clientless SSL = 'just the app, not the whole map'.
Reversed Pair
Flip cardA wiring fault where the two wires of a single pair are connected to swapped pin positions on one end of the cable.
- Detected by cable testers via wire-map test
- Different from split pairs, which mix wires from separate pairs
- Causes connectivity or performance issues even though continuity exists
Memory trick: Reversed = same pair, swapped ends; Split = different pairs, mixed up.
SSH (Port 22)
Flip cardSSH is a secure protocol using TCP port 22 that provides encrypted remote command-line access to network devices and servers.
- TCP port 22
- Encrypts entire session including login credentials
- Replaces insecure Telnet (port 23)
Memory trick: SSH = 'Secure Shell, port 22' - lock the door before you walk in remotely.
EAP-TLS
Flip cardAn 802.1X EAP method requiring digital certificates on both the client and authentication server, providing strong mutual authentication without transmitting reusable credentials.
- Requires PKI infrastructure for client and server certs
- Considered the strongest EAP method against credential theft
- Contrast: PEAP typically only requires a server-side certificate
Memory trick: TLS means Two-sided (mutual) Lock-Step certificates.
BPDU Guard
Flip cardAn STP feature applied to access ports that immediately err-disables the port if a BPDU is received, protecting the network from rogue switches or accidental loops.
- Typically paired with PortFast on edge ports
- Disables port entirely, unlike Root Guard which just blocks root role
- Requires manual or automatic recovery to re-enable port
Memory trick: BPDU Guard slams the door the instant it hears any BPDU knock.
Native VLAN Mismatch
Flip cardOccurs when two ends of an 802.1Q trunk are configured with different native (untagged) VLANs, causing untagged frames to be placed in the wrong VLAN.
- Native VLAN carries untagged traffic on a trunk
- Mismatches can leak traffic between VLANs
- Best practice: set native VLAN to an unused VLAN, and match on both ends
Memory trick: No tag, no home — untagged frames go wherever the native VLAN says.
Loopback Address Test
Flip cardPinging 127.0.0.1 verifies that a host's own TCP/IP stack and NIC driver are operational before testing external connectivity.
- 127.0.0.1 is the IPv4 loopback address (::1 for IPv6).
- A successful loopback ping isolates the problem away from cabling/switch.
- It's typically the very first diagnostic step for 'no connectivity' issues on a single host.
Memory trick: 'Loop back to yourself before blaming the network.'
Subnetting for Segmentation
Flip cardDividing a larger block into equal subnets requires calculating total addresses in the block and dividing by the desired number of segments to determine the correct mask.
- /22 = 2^(32-22) = 1024 total addresses
- Dividing by number of desired subnets gives subnet size
- Match resulting size to correct CIDR mask (256 addresses = /24)
Memory trick: 1024 divided by 4 departments equals 256 each — that's a /24.
Configuration Baseline
Flip cardA documented snapshot of a device's normal, approved configuration and performance metrics, used as a reference point to detect unauthorized changes or abnormal behavior.
- Includes both performance metrics (CPU, bandwidth) and configuration settings
- Deviations from baseline can indicate unauthorized changes or faults
- Complements monitoring tools like SNMP/syslog but focuses on config comparison
Memory trick: Baseline is your 'before' photo — compare it to catch what changed.
Static NAT
Flip cardStatic NAT is a fixed one-to-one translation between a single private IP address and a single public IP address.
- Mapping never changes
- Commonly used for servers needing consistent external reachability
- Different from PAT, which multiplexes many hosts on one public IP using ports
Memory trick: Static NAT is a 'one-to-one marriage' of IP addresses that never divorces.
Full Mesh Topology
Flip cardA network design where every node has a dedicated point-to-point link to every other node, providing maximum redundancy at the cost of high cabling and configuration complexity.
- Number of links = n(n-1)/2 for n nodes
- Highly fault tolerant since multiple paths exist
- Impractical for large networks due to cost and complexity
Memory trick: Mesh = a web where everyone talks to everyone
Ring Topology
Flip cardA network layout where each device connects to exactly two other devices, forming a continuous closed loop for data transmission.
- Each node has exactly two neighbors
- Data travels in one or both directions around the loop
- A single break can disrupt the entire ring unless dual-ring redundancy exists
Memory trick: Picture a circle of friends passing a note hand to hand — that's a ring.
DHCP Relay Agent (IP Helper)
Flip cardA router configuration (ip helper-address) that forwards DHCP broadcast requests from a remote subnet to a centralized DHCP server.
- DHCP discover/request messages are broadcasts and don't cross routers by default.
- IP helper-address converts broadcasts to unicast toward the DHCP server.
- Missing relay config is a common cause of DHCP failure across subnets.
Memory trick: 'Broadcasts stop at the router — someone has to relay the message.'
nmap Port Scanning
Flip cardnmap is a network scanning tool used to discover hosts and services, including open ports, on a network.
- -p specifies target port(s) to scan, e.g., -p 3389
- -sn performs host discovery only (no port scan)
- -sL lists targets and does basic reverse-DNS without actually scanning them
- CIDR notation like /24 allows scanning an entire subnet range
Memory trick: -p for Port, -sn for 'no port', -sL for List only
NTP Stratum Levels
Flip cardA numbering system describing a device's distance from an authoritative time reference, with lower numbers being closer to the source.
- Stratum 0: reference clocks (GPS, atomic) - not networked
- Stratum 1: servers directly connected to stratum 0 sources
- Each additional hop from the source increases the stratum number by 1
Memory trick: Stratum counts hops from the GPS 'ground zero'.
OSPF DR/BDR Election
Flip cardOn multiaccess (broadcast) networks, OSPF elects a Designated Router and Backup Designated Router so all other routers only peer with them, reducing adjacency count.
- Election based on OSPF priority, then highest Router ID
- DROTHER routers don't form full adjacency with each other
- Not needed on point-to-point links
Memory trick: DR is the 'hub' everyone talks to instead of gossiping with everyone.
dig Command
Flip cardA DNS lookup utility (Domain Information Groper) used to query DNS servers for detailed record information, commonly used on Linux/macOS.
- Can query specific record types (MX, A, TXT, NS, etc.) with the -t flag
- Allows querying a specific server directly, e.g., dig @8.8.8.8 domain.com
- Provides more detailed output than nslookup, including TTL and authority sections
Memory trick: Dig deeper than nslookup for DNS details
BGP AS_PATH Selection
Flip cardBGP's best path algorithm prefers routes with shorter AS_PATH attributes when higher-priority attributes like Weight and Local Preference are tied.
- AS_PATH lists the autonomous systems a route has traversed
- Shorter AS_PATH is generally preferred
- BGP decision process checks Weight and Local Preference before AS_PATH
Memory trick: Shorter road, faster BGP victory.
Punch-Down Tool
Flip cardA hand tool used to insert and seat individual wire strands into insulation-displacement connectors (IDCs) found on patch panels and keystone jacks.
- Cuts through wire insulation to make contact
- Common blade types include 66 and 110
- Used with T568A or T568B wiring standards
Memory trick: 'Punch it down' to seat the wire into the panel.
Router-on-a-Stick
Flip cardA configuration where a single physical router or switch interface is divided into 802.1Q-tagged subinterfaces to provide inter-VLAN routing.
- Requires a trunk link to the switch
- Each subinterface gets its own IP and VLAN tag
- Alternative to using a Layer 3 switch with SVIs
Memory trick: One stick, many branches — one wire, many VLANs.
Subnetting for Host Requirements
Flip cardTo determine the subnet mask for a required number of hosts, find the smallest number of host bits h such that 2^h - 2 is greater than or equal to the required host count.
- 2^6 - 2 = 62 hosts requires 6 host bits (/26)
- 2^5 - 2 = 30 hosts requires 5 host bits (/27)
- Subtract 2 for network and broadcast addresses
Memory trick: Powers of 2 minus 2 for network and broadcast
Star Topology
Flip cardA network layout where each device connects individually to a central switch or hub, so failures are isolated to that single link.
- Most common LAN topology today
- Central device failure affects the whole network
- Easy to troubleshoot single-device issues
Memory trick: Star topology shines from one central hub.
SSL Stripping (On-Path Downgrade Attack)
Flip cardA man-in-the-middle technique where an attacker intercepts a session and forces communication to fall back from HTTPS to unencrypted HTTP to capture sensitive data.
- Requires the attacker to be positioned in the traffic path (on-path/MITM)
- Victim's browser may show HTTP instead of HTTPS without obvious warning
- Mitigated by HSTS (HTTP Strict Transport Security)
Memory trick: Strip the 'S' from HTTPS, and the lock on the door disappears.
Default Gateway
Flip cardThe IP address of the router interface that a host uses to forward traffic destined for networks outside its own local subnet.
- Required for inter-network communication
- Missing gateway causes local-only connectivity
- Configured manually or via DHCP option 3
Memory trick: No gateway, no getaway — traffic stays trapped on the local subnet.
MTU Mismatch
Flip cardA condition where devices along a network path have differing Maximum Transmission Unit settings, causing large packets to be dropped or improperly fragmented.
- Default Ethernet MTU is 1500 bytes; jumbo frames use up to 9000 bytes
- Symptom: small packets succeed, large packets fail or hang ('black hole' MTU issue)
- Diagnosed with ping using specific packet sizes and the Don't Fragment flag
Memory trick: Big boxes get stuck at a small doorway — mismatched MTU blocks large packets.
2.4GHz Non-Overlapping Channels
Flip cardIn the 2.4GHz Wi-Fi band, only channels 1, 6, and 11 do not overlap with each other, minimizing interference between nearby access points.
- 2.4GHz band spans channels 1-11 (US) with 20MHz width each
- Only 1, 6, 11 avoid overlap
- Using other channels causes adjacent channel interference and throughput loss
Memory trick: Remember '1-6-11' like a stoplight — the only safe channels in 2.4GHz.
Zero Trust Architecture
Flip cardA security model in which no user, device, or system is trusted by default, even inside the network perimeter, requiring continuous verification for every access request based on identity, device health, and context.
- Core principle: 'never trust, always verify'
- Relies on least privilege access and micro-segmentation
- Continuously authenticates and authorizes rather than trusting a single login
Memory trick: Trust no one, verify everyone, every time
Outbound Connectivity Issue
Flip cardA problem where a device can communicate within its local network but cannot access resources outside of it.
- Often points to a gateway or firewall issue.
- Local pings succeed, external pings fail.
- DNS issues can also manifest similarly, but pinging an IP bypasses DNS.
Memory trick: Local is fine, but the 'door' to the outside is shut.
SNMPv3 Security
Flip cardSNMPv3 is the version of SNMP that introduced message integrity, authentication, and encryption using per-user credentials.
- v1/v2c use plaintext community strings
- v3 supports noAuthNoPriv, authNoPriv, and authPriv security levels
- v3 is required when encryption and authentication are mandated
Memory trick: '3 is the secure tree' — SNMPv3 brings security.
PAT (Port Address Translation)
Flip cardPAT, or NAT overload, allows multiple internal devices to share one public IP address by assigning unique port numbers to each session.
- Also called NAT overload
- Maps many private IPs to one public IP
- Uses port numbers to track individual sessions
Memory trick: PAT packs many devices behind one public port-labeled door.
IPv6 Unique Local Address (ULA)
Flip cardULA addresses use the fc00::/7 prefix and provide private, non-internet-routable addressing for internal IPv6 networks, similar to RFC 1918 private IPv4 space.
- Prefix range: fc00::/7 (commonly fd00::/8 in practice)
- Not routable on the public internet
- Analogous to IPv4 private addresses (10.x, 172.16.x, 192.168.x)
Memory trick: ULA = 'Unrouted Local Address' - stays home like private IPv4.
Private VLAN / Protected Ports
Flip cardA configuration where hosts in the same VLAN/subnet can reach an uplink port but cannot communicate directly with each other, commonly used for guest Wi-Fi and hotel networks.
- Also called isolated or protected ports
- Preserves single subnet while blocking peer-to-peer traffic
- Common use case: guest networks, hotel/hospitality Wi-Fi
Memory trick: Everyone can see the door, nobody can see each other.
Quality of Service (QoS)
Flip cardNetwork mechanisms that ensure certain traffic types (e.g., VoIP, video) receive preferential treatment over others to guarantee performance requirements.
- Prioritizes critical traffic to reduce latency, jitter, and packet loss.
- Achieved through classification, marking, queuing, and policing.
- Essential for real-time applications like VoIP and video conferencing.
Memory trick: Voice calls breaking up? They need VIP treatment!
RF Jamming
Flip cardA wireless denial-of-service attack that floods the radio frequency spectrum with noise or interference, disrupting legitimate Wi-Fi communication.
- Detected via a spectrum analyzer showing elevated noise floor
- Does not require broadcasting a fake SSID
- Difficult to trace since it operates at the physical layer
Memory trick: Jamming is the airwave equivalent of shouting so loud nobody else can be heard.
Electromagnetic Interference (EMI)
Flip cardDisruption of operation of an electronic device when it is in the vicinity of an electromagnetic field (EM field) in the radio frequency (RF) spectrum that is caused by another electronic device.
- Can cause intermittent connectivity, data corruption, and signal degradation.
- Sources include power lines, fluorescent lights, motors, and radio transmitters.
- Mitigated by shielding cables, proper grounding, and physical separation.
Memory trick: When the signal 'flickers', think of outside 'noise'.
Traceroute Asterisks
Flip cardAsterisks (*) in traceroute output indicate no response was received from a hop within the timeout window, often due to ICMP filtering.
- Traceroute uses TTL expiration and ICMP Time Exceeded messages to map the path
- Many routers/firewalls silently drop or deprioritize ICMP without blocking actual traffic
- A successful response at a later hop confirms the path continues normally despite silent hops
Memory trick: Silent hops don't mean broken hops
Isolating DNS Issues
Flip cardWhen a host can reach resources by IP address but not by name, the fault is almost always DNS resolution rather than a physical or routing problem.
- Symptom pattern: 'works by IP, fails by name' points to DNS
- nslookup and dig are the fastest tools to test DNS resolution
- Physical connectivity is already proven if IP-based access succeeds
Memory trick: If IP works but names don't, blame DNS, not the wire.
FTP Ports (20/21)
Flip cardFile Transfer Protocol uses TCP port 21 for control commands and TCP port 20 for data transfer in active mode.
- Port 21 = control channel
- Port 20 = active mode data channel
- FTP transmits credentials in cleartext
Memory trick: '21 controls, 20 delivers' — control comes first alphabetically and numerically.
EIGRP Feasible Successor
Flip cardA backup route in EIGRP's topology table whose reported distance is less than the successor's feasible distance, allowing instant failover without recomputation.
- Feasibility Condition: RD < FD
- Provides loop-free backup paths
- Enables fast convergence without going Active
Memory trick: If the neighbor's reported cost beats your best cost, keep it as backup.
Port Security Violation Modes
Flip cardA switch security feature limiting the number of MAC addresses allowed on a port; violation actions include protect (drop silently), restrict (drop + log), and shutdown (err-disable the port).
- Shutdown mode disables the port and requires manual/automatic re-enable
- Protect mode drops excess traffic without logging
- Restrict mode drops excess traffic and logs/counts violations
Memory trick: Shutdown mode = slam the door shut on violations.
STP Port States
Flip cardSpanning Tree Protocol progresses ports through Blocking, Listening, Learning, and Forwarding states to prevent loops while building a loop-free topology.
- Blocking: no forwarding, no learning, receives BPDUs
- Listening: processes BPDUs, no learning/forwarding
- Learning: builds MAC table, no forwarding
- Forwarding: full data traffic flow
Memory trick: Blocking, Listening, Learning, Forwarding — BLLF, the loop-free march.
Recovery Point Objective (RPO)
Flip cardThe maximum acceptable amount of data loss, measured in time, that an organization can tolerate after a disruption.
- Determined by backup frequency
- Answers 'how much data can we afford to lose?'
- Different from RTO, which measures downtime, not data loss
Memory trick: RPO = Point of data loss; RTO = Time to restore.
DHCP Scope Exhaustion
Flip cardA condition where all addresses in a DHCP pool are leased out, preventing new clients from receiving an IP address.
- Common on VLANs with many transient devices (guest Wi-Fi, BYOD)
- Shortening lease time speeds address reclamation
- Long-term fix may require expanding the scope or subnet
Memory trick: Short leases, quick releases.
IaaS (Infrastructure as a Service)
Flip cardIaaS provides virtualized computing infrastructure such as servers, storage, and networking, while the customer manages the operating system and applications.
- Customer manages OS, middleware, and apps
- Provider manages physical hardware and virtualization
- Examples: AWS EC2, Azure VMs
Memory trick: IaaS hands you the bare metal cloud stack to build on.
Channel Bonding Trade-off
Flip cardCombining multiple 20MHz channels (e.g., into 40/80/160MHz) increases per-client throughput but reduces the number of non-overlapping channels available, raising the risk of co-channel interference in dense AP deployments.
- 80MHz channel = four bonded 20MHz channels
- Fewer available channels means more APs must reuse the same frequency
- Trade-off: higher speed vs. more interference in dense environments
Memory trick: Wider highway lanes = fewer total roads to share.
Dynamic Frequency Selection (DFS)
Flip cardA regulatory requirement for 5GHz UNII-2/UNII-2e channels that requires APs to detect radar signals and switch channels to avoid interference with radar systems.
- Required on UNII-2 and UNII-2 Extended bands
- AP must vacate channel if radar detected
- Can cause brief service interruption during channel switch
Memory trick: Radar's coming — DFS jumps ship to a clear channel.