CompTIA Network+ (N10-009) flashcards
196 free flashcards. Tap a card to flip it.
BGP Multihoming
Flip cardA network design where an organization connects to two or more ISPs, typically using its own AS number and BGP, to achieve redundancy and avoid a single point of failure.
- Requires a public ASN for BGP peering
- Improves availability if one ISP link fails
- Common for enterprises and data centers
Memory trick: Multihomed = many homes (ISPs) for the same network.
Multicast Traffic
Flip cardA one-to-many communication method where data is sent to a specific group of interested hosts using a multicast address, commonly in the 224.0.0.0/4 range for IPv4.
- Uses IGMP for group membership management
- More efficient than broadcast for group communication
- Used in video streaming, stock tickers, and routing protocol updates
Memory trick: Multi-CAST like a cast of a play performing to a select audience
SLAAC vs DHCPv6 Flags
Flip cardIPv6 router advertisements include M (Managed) and O (Other) flags that control whether clients use stateful DHCPv6 for addresses and/or stateless DHCPv6 for extra configuration data like DNS.
- A-flag: enables SLAAC address autoconfiguration on the prefix
- M-flag: triggers full stateful DHCPv6 for address assignment
- O-flag: triggers stateless DHCPv6 just for extra options (e.g., DNS)
Memory trick: O is for 'Other stuff' like DNS, M is for 'Managed' full addressing.
DHCP Snooping
Flip cardA switch security feature that classifies ports as trusted or untrusted and blocks DHCP server messages from untrusted ports to prevent rogue DHCP servers.
- Builds a binding table of IP-to-MAC-to-port mappings
- Untrusted ports cannot send DHCP offers/acks
- Foundation for Dynamic ARP Inspection
Memory trick: Trust the uplink, snoop the rest.
RTO vs DR Site Tier Selection
Flip cardRecovery Time Objective (RTO) is the maximum tolerable downtime after a disaster; the DR site tier chosen (cold, warm, hot) must be capable of meeting that RTO.
- Cold sites have longest recovery times (days)
- Warm sites recover in hours with partially configured systems
- Hot sites recover fastest (minutes to a couple hours) with fully mirrored systems
Memory trick: Cold is slow, Hot is quick — pick the site that fits the clock.
Warm Site
Flip cardA DR facility with infrastructure and some hardware already in place, but requiring additional setup and data restoration to become fully operational.
- Middle tier between hot and cold sites
- Has power, cooling, cabling, partial racks/hardware
- Recovery time is longer than hot site but shorter than cold site
Memory trick: Hot ready now, Warm needs a little work, Cold needs everything.
Maximum Copper Cable Length
Flip cardTwisted-pair Ethernet cabling (Cat 5e/6/6a) is limited to a maximum segment length of 100 meters due to attenuation and signal degradation.
- 100 meters includes patch cords plus horizontal cabling.
- Exceeding this causes attenuation, CRC errors, and intermittent drops.
- Solution: use fiber or add a repeater/switch for longer distances.
Memory trick: '100 meters is the copper Ethernet ceiling.'
Isolating Latency to the Destination Host
Flip cardWhen traceroute shows healthy latency at all intermediate hops but spikes only at the final destination, the problem is likely on the destination host itself rather than in the network path.
- Compare latency across hops to isolate where delay is introduced.
- If only the last hop is affected and neighbors are fine, suspect the host, not the path.
- Common host-side causes: CPU load, disk I/O, or application bottlenecks.
Memory trick: 'If the road is smooth but the destination is slow, blame the house, not the highway.'
Antenna Polarization Mismatch
Flip cardOccurs when two communicating antennas have different polarization orientations (e.g., one vertical, one horizontal), causing significant signal loss and poor link performance.
- Can cause 20dB or more signal loss.
- Critical for point-to-point links with directional antennas.
- Requires physical adjustment of one or both antennas.
Memory trick: When the signal's weak, and the path is clear, check antenna alignment, far and near, especially the polarization, my dear!
Split Tunnel VPN
Flip cardA VPN configuration in which only traffic destined for the corporate network is sent through the encrypted tunnel, while other traffic uses the local internet connection directly.
- Reduces bandwidth and load on the VPN concentrator
- Full tunnel sends all traffic through the VPN, offering more security oversight
- Split tunneling can pose security risks since local traffic bypasses corporate inspection
Memory trick: Split tunnel = 'fork in the road' for corporate vs internet traffic.
DNS Resolution Failure
Flip cardOccurs when a device cannot translate a human-readable hostname into a numerical IP address.
- Symptoms: cannot access resources by name, but can by IP.
- Common causes: incorrect DNS server settings, DNS server offline, or invalid DNS records.
- Tools: `nslookup`, `dig`, `ping hostname`.
Memory trick: Name doesn't work, but number does? It's a 'phone book' problem.
SNMP Ports
Flip cardSNMP uses UDP port 161 for manager-to-agent queries and UDP port 162 for agent-to-manager trap notifications.
- SNMP is used for network device monitoring and management
- Traps are unsolicited alerts sent by devices
- SNMPv3 adds authentication and encryption
Memory trick: 161 asks, 162 alerts
DR Site Tiers
Flip cardHot, warm, and cold sites represent increasing recovery time and decreasing cost for disaster recovery facilities.
- Hot site: fully mirrored, near-instant failover, highest cost
- Warm site: hardware/connectivity ready, data must be restored
- Cold site: bare facility only, longest recovery time, lowest cost
Memory trick: Hot=ready now, Warm=almost ready, Cold=empty shell.
Recursive Route Lookup
Flip cardThe process a router performs when a static route's next hop is not a directly connected interface, requiring the router to look up another route in its table to determine how to reach that next-hop address.
- Occurs when next-hop is an IP address rather than an exit interface
- Adds a small processing overhead compared to directly connected next-hop routes
- Can be avoided by specifying the exit interface directly in the static route
Memory trick: Recursive lookup: the router asks 'how do I get to the next hop?' before it can even start the trip.
Troubleshooting Methodology Order
Flip cardThe structured sequence CompTIA defines for resolving network problems, ensuring consistent and efficient issue resolution.
- Order: Identify problem, establish theory, test theory, plan of action, implement, verify, document
- Testing the theory confirms or rules out the suspected cause before acting
- Documentation always occurs last regardless of outcome
Memory trick: I Eat Tacos Please Implement Verify Documents
Administrative Distance
Flip cardA value representing the trustworthiness of a routing information source; lower AD values are preferred when multiple protocols advertise the same destination.
- Connected routes: AD 0; static routes: AD 1
- EIGRP internal: AD 90; OSPF: AD 110; RIP: AD 120
- Router selects lowest AD route among competing sources
Memory trick: Lower AD = more trusted, like a lower golf score wins.
nslookup Interactive Mode
Flip cardA mode of nslookup entered by typing the command with no arguments, allowing the technician to set query types and options before performing lookups.
- 'set type=MX' restricts results to mail exchange records
- Other types include A, AAAA, PTR, TXT, NS
- Exit interactive mode with 'exit'
Memory trick: Set type first, then ask your question — like choosing a filter before searching.
Asymmetric Routing/Communication Block
Flip cardA network condition where traffic flows successfully in one direction but fails or is blocked in the reverse direction, often due to security devices or misconfigurations.
- Outbound traffic succeeds, inbound fails.
- Commonly caused by stateful firewalls blocking uninitiated return traffic.
- Can also be caused by routing issues where return path is unknown or suboptimal.
Memory trick: Traffic goes out, but doesn't come back in; a firewall's rule might be the sin.
PTR Record
Flip cardA DNS resource record used in the reverse lookup zone that resolves an IP address to a hostname.
- Stored in in-addr.arpa (IPv4) or ip6.arpa (IPv6) zones
- Commonly checked by mail servers to combat spam
- Opposite function of an A/AAAA record
Memory trick: 'PTR = Pointing back' from IP to name.
Implicit Deny
Flip cardThe default rule at the end of every ACL that blocks all traffic not explicitly permitted by a preceding rule.
- ACLs are processed top-down, first match wins
- If no rule matches, the implicit deny drops the packet
- Administrators must add explicit permit statements for needed traffic
Memory trick: No match? No pass—the gate stays shut by default.
DNS Cache Poisoning
Flip cardAn attack that injects falsified DNS resolution data into a resolver's cache, redirecting legitimate domain lookups to malicious IP addresses.
- Also called DNS spoofing
- Exploits weak transaction ID randomization or race conditions
- Mitigated by DNSSEC, source port randomization, and short TTLs
Memory trick: Poison the cache, and every visitor drinks from the wrong well.
Product Lifecycle Milestones
Flip cardVendors define stages such as end-of-sale, end-of-life, and end-of-support to communicate when a product will no longer be sold, developed, or supported.
- End-of-sale: no new units sold
- End-of-life: overall phase-out announcement begins
- End-of-support: patches, updates, and technical support permanently stop
Memory trick: Sale stops first, Life winds down, Support ends last.
Asymmetric Routing (Stateful Firewall Impact)
Flip cardOccurs when inbound and outbound traffic for a session take different network paths; stateful firewalls or NAT devices along only one path may drop return traffic due to missing session state.
- Stateful firewalls require both directions of a flow to pass through the same device.
- Common in networks with multiple internet links/firewalls and asymmetric routing tables.
- Symptoms: server sends replies, but client never receives them.
Memory trick: 'What goes out one door must come back through the same door.'
LAG Load Balancing Per-Flow
Flip cardLink aggregation groups distribute traffic across member links based on a hash of parameters like source/destination MAC or IP, meaning a single conversation is usually confined to one physical link.
- Aggregate bandwidth benefits multiple flows, not a single flow
- Hash algorithms use MAC/IP/port combinations
- A single large transfer will not exceed one link's speed
Memory trick: One conversation, one lane — the highway only helps with many cars.
SNMP Trap
Flip cardAn unsolicited SNMP message sent from a managed device (agent) to the management station to report an event as it happens, without waiting for a poll.
- Push-based, event-driven notification
- Contrasts with polling (pull-based)
- Reduces detection latency for critical events
Memory trick: Traps trigger themselves; polling waits to be asked.
Site-to-Site VPN
Flip cardA VPN tunnel established between two network gateways (e.g., routers or firewalls) that transparently connects two networks over an encrypted channel, without requiring client software on individual devices.
- Configured between gateway/firewall devices, not end-user clients
- Provides always-on, transparent connectivity between branch networks
- Contrasts with client-to-site VPN, which connects individual remote users
Memory trick: Site-to-site links whole buildings, not just people.
Near-End Crosstalk (NEXT)
Flip cardA measurement of signal interference between wire pairs within the same cable, measured at the end closest to the signal source, often caused by poor termination.
- High NEXT often results from excessive untwisting of pairs at the connector
- Measured in dB; higher dB loss values indicate less crosstalk (better performance)
- Certified cable testers report NEXT as pass/fail against category standards
Memory trick: NEXT = Noise EXchanged between Twisted pairs near the plug.
SD-WAN
Flip cardSoftware-Defined WAN uses centralized control and real-time performance metrics to dynamically route traffic over multiple transport types like MPLS, broadband, and LTE.
- Abstracts transport from application policy
- Improves resiliency and cost efficiency across links
- Centralized orchestration simplifies branch management
Memory trick: SD-WAN picks the smartest road for every packet's trip.
Jumbo Frames
Flip cardJumbo frames are Ethernet frames with a payload larger than the standard 1500-byte MTU, often up to 9000 bytes, used to reduce overhead and boost throughput.
- Typical jumbo frame size is up to 9000 bytes
- All devices in the path must support jumbo frames to avoid fragmentation
- Commonly used in storage networks (iSCSI, NFS) and data centers
Memory trick: Jumbo frames are the 'oversized suitcase' carrying more data per trip.
NetFlow
Flip cardA Cisco-developed protocol that collects IP traffic flow information (source/destination, ports, bytes) for network traffic analysis.
- Identifies 'top talkers' consuming bandwidth
- Exports flow records to a collector for analysis
- Complements but does not replace SNMP and packet captures
Memory trick: NetFlow = 'who is flowing the most data'.
SSH Port 22
Flip cardSSH provides encrypted terminal/command-line access to remote devices and servers, using TCP port 22 by default.
- Replaces insecure Telnet (port 23)
- Uses TCP port 22
- Common for managing Linux servers, routers, and switches
Memory trick: SSH = Secure Shell, port 22, the safe twin of Telnet's 23.
Stateful Firewall
Flip cardA firewall that tracks the state of active network connections in a state table and automatically permits related return traffic.
- Maintains a connection state table
- Reduces rule complexity vs. stateless filtering
- Common in modern NGFWs
Memory trick: Stateful firewalls remember the conversation; stateless ones forget after every sentence.
Directional (Yagi) Antenna
Flip cardAn antenna design that concentrates RF energy into a focused beam, providing higher gain in one direction, useful for point-to-point or long narrow coverage areas.
- Contrasts with omnidirectional antennas that spread signal 360°
- Common uses: hallways, warehouse aisles, point-to-point bridges
- Higher gain in one direction means less coverage elsewhere
Memory trick: Yagi = flashlight beam; Omni = light bulb.
Access Port
Flip cardA switch port configured to belong to a single VLAN, sending and receiving untagged Ethernet frames to an end device.
- Used for end devices like PCs, printers, phones
- Contrasts with trunk ports which carry multiple tagged VLANs
- Frames on an access port are untagged
Memory trick: Access = one door, one room; Trunk = hallway with many rooms.
Network Segmentation
Flip cardDividing a network into isolated zones (e.g., via VLANs and firewall rules) to limit the scope of a security breach and control traffic flow between zones.
- Common in IoT/OT environments to isolate risky devices
- Combines VLANs with firewall ACLs for enforcement
- Reduces attack surface via lateral movement containment
Memory trick: Segments are like watertight compartments on a ship—one leak doesn't sink it all.
MAC Flooding
Flip cardAn attack that overwhelms a switch's finite CAM (MAC address) table with fake entries, causing the switch to broadcast traffic to all ports like a hub, enabling sniffing.
- Exploits limited size of the switch's CAM table
- Switch fails open and floods frames out all ports
- Mitigated with port security limiting MACs per port
Memory trick: Flood the table, flood the traffic.
Deauthentication Attack
Flip cardA wireless attack that sends forged 802.11 deauthentication management frames to disconnect a client from its access point, often used to force a reconnection and capture the WPA handshake.
- Exploits unauthenticated 802.11 management frames
- Common precursor to WPA2 handshake capture for offline cracking
- Mitigated by 802.11w (Management Frame Protection)
Memory trick: Kick them off, catch them coming back on.
VLAN Hopping (Double Tagging)
Flip cardAn attack where a frame is crafted with two VLAN tags so it can traverse from the native VLAN into a restricted VLAN by exploiting how trunk switches strip only the outer tag.
- Requires attacker's port to be on the native VLAN of the trunk
- Only works one-way (attacker to victim VLAN)
- Mitigated by not using VLAN 1 as native VLAN and explicitly tagging native VLAN traffic
Memory trick: Two tags, one jump — double tagging hops the fence.
HTTPS (Port 443)
Flip cardHTTPS is HTTP secured with TLS/SSL encryption, using TCP port 443 by default.
- TCP port 443
- Encrypts data in transit with TLS
- Protects confidentiality and integrity of web traffic
Memory trick: '443, lock the door' – HTTPS locks web traffic at port 443.
End-of-Support (EOS)
Flip cardThe point in a product's lifecycle when the vendor stops providing updates, patches, and technical support, even though the device may still be sold or in use.
- Different from end-of-life (EOL), which means the product is no longer sold
- EOS devices become higher security risks over time
- Lifecycle documentation should track EOS dates for planning replacements
Memory trick: EOS = End Of Support, Security Stops.
Gateway Subnet Mismatch
Flip cardA misconfiguration where the default gateway address falls outside the host's own subnet, preventing the host from routing traffic to other networks.
- Gateway must be in the same subnet as the host to be reachable
- Symptom: local traffic works, but no external/internet access
- Fix by correcting gateway IP or host's subnet mask
Memory trick: The gateway must live on your street (subnet), or you can't leave the neighborhood.
IPsec Tunnel Mode
Flip cardAn IPsec mode that encrypts the entire original IP packet, including its header, and encapsulates it within a new IP packet for secure transport, commonly used in site-to-site VPNs.
- Encrypts entire original packet including header
- New outer IP header added for routing between gateways
- Contrasts with transport mode which only encrypts payload
Memory trick: Tunnel wraps the WHOLE package; Transport just seals the contents.
Screened Subnet (DMZ)
Flip cardA network segment placed between an external and internal firewall that hosts public-facing servers, isolating them from the internal LAN.
- Also called a DMZ (demilitarized zone)
- Typically bounded by two firewalls or one firewall with three interfaces
- Limits attacker's lateral movement if a public server is compromised
Memory trick: The DMZ is the castle's outer courtyard—visitors allowed, but the keep stays locked.
Single-Mode vs Multimode Fiber
Flip cardSingle-mode fiber uses a narrow core and laser light for long-distance transmission (10+ km), while multimode fiber uses a wider core and LED/laser light suited for short distances (up to ~550 m).
- Single-mode: yellow jacket, OS1/OS2
- Multimode: orange/aqua jacket, OM1–OM5
- Longer distance = single-mode required
Memory trick: Single strand, single mode, sends signals SUPER far.
Wi-Fi Site Survey
Flip cardA comprehensive process of planning and designing a wireless network to provide adequate coverage, capacity, and performance, involving on-site RF measurements.
- Identifies optimal AP placement and antenna types.
- Determines best channel assignments to minimize interference.
- Locates and quantifies sources of RF interference (Wi-Fi and non-Wi-Fi).
Memory trick: For Wi-Fi woes, a survey shows where the best signals flow.
PoE Power Budget
Flip cardThe total wattage a PoE switch can supply across all its ports; exceeding it causes the switch to shed power from some ports.
- Each PoE switch has a maximum total power budget (e.g., 370W).
- Adding high-draw devices like PoE+ APs or phones can exceed the budget.
- Symptoms include random device reboots or power loss under load.
Memory trick: 'Too many mouths, not enough power pie.'
Auto-MDIX
Flip cardA feature on modern Ethernet ports that automatically detects and corrects for cable type (straight-through vs. crossover), allowing either cable type to establish a working link.
- Eliminates need to manually choose crossover vs. straight-through cables
- Standard on virtually all modern switches and NICs
- Historically required crossover cables for switch-to-switch or PC-to-PC links
Memory trick: Auto-MDIX is the port's 'auto-correct' for backwards wiring.
802.1Q Trunking
Flip cardIEEE standard that inserts a VLAN tag into Ethernet frames so multiple VLANs can traverse a single trunk link between switches.
- Adds a 4-byte tag containing the VLAN ID
- Supports up to 4094 VLAN IDs
- Native VLAN traffic is sent untagged by default
Memory trick: 'Q' for Queue-up tags on the trunk highway.
SDN Control/Data Plane Separation
Flip cardSoftware-Defined Networking separates the control plane (centralized decision-making) from the data plane (packet forwarding by switches), enabling centralized, programmable network control.
- Control plane = decision-making, centralized controller
- Data plane = packet forwarding, executed by switches
- Often implemented using APIs like OpenFlow
Memory trick: SDN = 'Smart brain (controller) directs dumb hands (switches)'.
Hybrid Cloud
Flip cardA hybrid cloud combines private and public cloud infrastructure, allowing data and applications to be shared between them for flexibility and scalability.
- Combines private and public cloud
- Enables cloud bursting for scalability
- Keeps sensitive data on private infrastructure
Memory trick: Hybrid = 'Half Private, Half Public' working together.
2.4GHz vs 5GHz
Flip card2.4GHz offers longer range and better penetration but limited channels and more interference; 5GHz offers higher throughput and more channels but shorter range.
- 2.4GHz: 3 non-overlapping channels (1,6,11)
- 5GHz: many more channels, less interference
- Higher frequency = shorter range, less penetration
Memory trick: Low frequency travels far, high frequency carries more.
IPv6 Global Unicast Address
Flip cardA global unicast address is a globally routable IPv6 address, typically in the 2000::/3 range, analogous to a public IPv4 address.
- Begins with 2000::/3 in current allocations
- Assigned by ISPs or regional internet registries
- Globally routable across the internet, unlike link-local or ULA addresses
Memory trick: Global unicast is the 'passport address' — valid for travel across the whole internet.
Network Service Unavailability
Flip cardA situation where a specific network application or protocol service on a device is unreachable or non-functional, even if the device itself is online.
- Device is pingable, but specific service (e.g., SSH, HTTP, FTP) fails.
- Often due to service being disabled, misconfigured, or firewalled on the device.
- Troubleshoot by checking service status, port listening, and device firewall rules.
Memory trick: The 'house' is there, but one 'door' won't open.
DHCP T1/T2 Timers
Flip cardT1 is the renewal timer that defaults to 50% of the lease duration, when the client unicasts a renewal request to the original server; T2 is the rebinding timer at 87.5% of the lease, when the client broadcasts to any DHCP server.
- T1 default = 50% of lease time (unicast renew)
- T2 default = 87.5% of lease time (broadcast rebind)
- If lease expires with no renewal, client must restart DORA process
Memory trick: Half the lease, try to renew; seven-eighths in, broadcast and plead.
DDoS Attack
Flip cardAn attack where multiple compromised systems flood a target with traffic or requests, overwhelming resources and causing denial of service.
- Uses many distributed sources (often a botnet)
- Common types: SYN flood, UDP flood, HTTP flood
- Mitigated with rate limiting, scrubbing services, and anycast
Memory trick: Distributed = many attackers drown one victim in traffic.
Evil Twin
Flip cardA malicious wireless access point configured to mimic a legitimate network's SSID in order to intercept user traffic or credentials.
- Uses same or similar SSID as trusted network
- Often paired with a stronger signal to lure clients
- Can capture credentials via fake captive portals
Memory trick: Twins look alike — evil twin copies the real Wi-Fi name.
PVST+ (Per-VLAN Spanning Tree)
Flip cardA Cisco enhancement to STP that runs a separate spanning tree instance for each VLAN, allowing different root bridges per VLAN for load balancing.
- Contrasts with Common Spanning Tree (single instance for all VLANs)
- Enables per-VLAN load balancing across redundant links
- Rapid PVST+ combines this with 802.1w's faster convergence
Memory trick: PVST+ = 'Personalized VLAN Spanning Trees' — each VLAN picks its own root.
CIA Triad
Flip cardA security model consisting of Confidentiality, Integrity, and Availability used to guide security policy and controls.
- Confidentiality = preventing unauthorized access/disclosure
- Integrity = data accuracy and no unauthorized modification
- Availability = ensuring systems/data are accessible when needed
Memory trick: Can I Access? — Confidentiality, Integrity, Availability.
Floating Static Route
Flip cardA static route configured with an administrative distance higher than the primary dynamic routing protocol, so it only becomes active if the primary route fails.
- Default static route AD is 1, must be manually raised to float
- Must exceed the AD of the primary protocol (e.g., >110 for OSPF)
- Commonly used for backup ISP links or WAN failover
Memory trick: Float higher than the primary so it only kicks in when needed.
Network Access Control (NAC)
Flip cardA security solution that enforces policy compliance (e.g., patch level, antivirus) on devices before granting them network access.
- Performs posture/health assessment of endpoints
- Can quarantine non-compliant devices to a remediation VLAN
- Often integrates with 802.1X for authentication plus posture checking
Memory trick: NAC is the bouncer checking your health pass before entry.