Step2Study
IT & Technology200-301100% Free

Cisco CCNA (200-301)

Practice bank
254 Qs
Real exam
100 Qs
Time limit
120 min
Passing
Cisco does not publish it (commonly ~80–85%)

Exam blueprint

Network Fundamentals
20%
Network Access
20%
IP Connectivity
25%
IP Services
10%
Security Fundamentals
15%
Automation and Programmability
10%

Practice

Untimed · instant feedback · 4 practice tests of 90 questions

Questions per test

Custom practice

Flashcard on every question Mental map when you miss

Exam simulation

4 timed tests · 100 questions each · 120 min · pass 82% · 254 questions in the bank

+50 XP per test · +100 XP for a pass

Random simulation (weighted by domain)

Everything is open to everyone. Create a free account to save scores, XP, badges and get progress emails.

Free study resources

All resources →

Part of a learning path

Study with friends

Challenge a friend to beat your score.

Cisco CCNA (200-301) practice test questions

Sample questions from the 254-question bank, with answers and explanations.

All questions
  1. 1. A wireless engineer configures an access point to use 40 MHz channel bonding in the 5 GHz band to increase throughput. What is a direct consequence of this configuration?

    Network Fundamentals

    • A. The number of available non-overlapping channels decreases because pairs of 20 MHz channels are combined
    • B. The number of available non-overlapping channels in the deployment increases
    • C. The AP's transmit power automatically doubles to compensate for wider channels
    • D. The AP switches from 802.11ac to 802.11b to support the wider channel
    Show answer

    A. The number of available non-overlapping channels decreases because pairs of 20 MHz channels are combined

    Channel bonding combines two adjacent 20 MHz channels into a single 40 MHz channel to increase throughput, but this reduces the total number of independent non-overlapping channels available in a given band, which can increase co-channel interference in dense deployments.

  2. 2. A router's routing table contains the following entries: 10.1.0.0/16, 10.1.1.0/24, and 10.1.1.128/25, each via a different next hop. A packet arrives destined for 10.1.1.130. Which route will the router use to forward this packet?

    IP Connectivity

    • A. 10.1.1.128/25, because it is the longest (most specific) matching prefix
    • B. 10.1.1.0/24, because it has a lower administrative distance
    • C. The router will load-balance across all three routes
    • D. 10.1.0.0/16, because it was learned first
    Show answer

    A. 10.1.1.128/25, because it is the longest (most specific) matching prefix

    10.1.1.130 falls within all three ranges, but routers always use the longest prefix match first, before considering administrative distance. The /25 route (10.1.1.128-10.1.1.255) is the most specific match, so it is used.

  3. 3. A developer examines a JSON payload returned from a controller API and sees the following field: "vlan_ids": [10, 20, 30] What JSON data type is used to represent "vlan_ids"?

    Automation and Programmability

    • A. String
    • B. Boolean
    • C. Object
    • D. Array
    Show answer

    D. Array

    An array in JSON is an ordered list of values enclosed in square brackets [ ]. The three numeric values 10, 20, and 30 are elements of that ordered list, making it an array rather than an object (which uses curly braces and key-value pairs).

  4. 4. An automation engineer is writing a script that calls a REST API to update the description field on an existing interface object without replacing the entire resource. Which HTTP method is most appropriate for a partial update?

    Automation and Programmability

    • A. POST
    • B. PUT
    • C. DELETE
    • D. PATCH
    Show answer

    D. PATCH

    PATCH is designed for partial modifications to an existing resource, updating only the specified fields. PUT typically replaces the entire resource, POST creates a new resource, and DELETE removes one.

  5. 5. A network engineer wants a switch to remember which DHCP-assigned IP-to-MAC-to-VLAN-to-interface mappings are valid so that Dynamic ARP Inspection can validate future ARP packets. Where is this dynamically-learned information stored?

    Security Fundamentals

    • A. In the DHCP snooping binding database
    • B. In the MAC address table
    • C. In the running-configuration as static entries
    • D. In the ARP cache of the switch's CPU
    Show answer

    A. In the DHCP snooping binding database

    DHCP snooping builds and maintains a binding database (also called the DHCP snooping table) that records IP address, MAC address, lease time, VLAN, and interface for each client that receives an address via a trusted DHCP server. DAI uses this table to validate ARP packets on untrusted ports.

  6. 6. An engineer configures 'enable secret Cisco123' on a router that already has 'enable password Cisco123' configured. A colleague later runs 'show running-config' and notices the enable password line is still readable in plaintext even though 'service password-encryption' is enabled. Which statement explains this scenario?

    Security Fundamentals

    • A. The enable secret uses a stronger one-way hash and takes precedence for login, while service password-encryption only applies a weak reversible Type 7 obfuscation to the enable password
    • B. The enable secret is ignored whenever an enable password also exists
    • C. Both passwords will always be identical, so this behavior is expected
    • D. service password-encryption failed because two passwords cannot coexist on the same device
    Show answer

    A. The enable secret uses a stronger one-way hash and takes precedence for login, while service password-encryption only applies a weak reversible Type 7 obfuscation to the enable password

    When both are configured, the router uses the enable secret (a strong MD5/Type 5 or SHA hash) for authentication and ignores the enable password for login purposes. However, 'service password-encryption' only applies a weak, easily reversible Type 7 encoding to plaintext passwords like the enable password, not the already-hashed enable secret.

  7. 7. Two routers, R1 and R2, run HSRP for the 10.10.10.0/24 VLAN. R1 has priority 150 and is currently Active. R2 has priority 100 with default preempt settings. R1 experiences an interface failure and recovers a few minutes later. What will happen to the Active role after R1 recovers?

    IP Connectivity

    • A. Both routers become Active simultaneously, causing a split-brain condition
    • B. R1 becomes the new Standby router and stays that way permanently
    • C. R2 remains Active because preempt is not enabled on R1 by default
    • D. R1 automatically becomes Active again immediately because it has higher priority
    Show answer

    C. R2 remains Active because preempt is not enabled on R1 by default

    HSRP does not preempt by default; even though R1 has a higher priority, it will not reclaim the Active role automatically once R2 has taken over unless 'standby preempt' is explicitly configured on R1.

  8. 8. A company wants to automate configuration of 200 switches using a tool that does not require installing any agent software on the managed devices and instead connects over SSH to push changes. Which automation tool best fits this description?

    Automation and Programmability

    • A. Chef
    • B. Ansible
    • C. SaltStack (using minions)
    • D. Puppet
    Show answer

    B. Ansible

    Ansible is agentless, using SSH (or NETCONF/API for network devices) from a control node to push configuration changes to managed nodes without requiring installed agents. Puppet, Chef, and Salt (in minion mode) traditionally rely on agents installed on managed nodes.

  9. 9. An engineer runs an Ansible playbook containing the following task against Cisco IOS switches: - name: Create VLAN 10 cisco.ios.ios_vlans: config: - vlan_id: 10 name: SALES state: merged What is the effect of setting 'state: merged' in this task?

    Automation and Programmability

    • A. It replaces the entire VLAN database with only VLAN 10
    • B. It deletes all existing VLANs before applying VLAN 10
    • C. It causes the playbook to fail if VLAN 10 already exists
    • D. It combines the specified VLAN 10 configuration with existing VLANs, leaving others untouched
    Show answer

    D. It combines the specified VLAN 10 configuration with existing VLANs, leaving others untouched

    The 'merged' state in Cisco IOS Ansible resource modules combines the specified configuration with the device's existing configuration, adding or updating only what is defined without removing unrelated existing settings. 'Replaced' or 'overridden' states would have more destructive effects on other VLANs.

  10. 10. A security team is comparing AAA protocols for network device administration. They require an option that encrypts the entire packet payload (not just the password) and uses TCP for reliable delivery. Which protocol meets this requirement?

    Security Fundamentals

    • A. Kerberos
    • B. TACACS+
    • C. RADIUS
    • D. SNMPv2
    Show answer

    B. TACACS+

    TACACS+ encrypts the entire packet body and uses TCP port 49, providing more robust confidentiality for device administration traffic, whereas RADIUS only encrypts the password field and uses UDP.

  11. 11. A switch port is configured with 'switchport port-security violation restrict' and a maximum of 2 MAC addresses. A third unauthorized device sends traffic on the port. What is the result?

    Security Fundamentals

    • A. The frame from the unauthorized device is dropped, a syslog message is generated, and the violation counter increments, but the port stays up
    • B. The port is immediately placed into err-disabled state
    • C. The switch adds the new MAC address and removes the oldest learned address
    • D. The frame is silently dropped with no logging and no counter increment
    Show answer

    A. The frame from the unauthorized device is dropped, a syslog message is generated, and the violation counter increments, but the port stays up

    The 'restrict' violation mode drops traffic from unauthorized MAC addresses, increments the security violation counter, and generates a log/SNMP trap, but unlike 'shutdown' mode it does not disable the port.

  12. 12. A syslog message '%CDP-4-NATIVE_VLAN_MISMATCH' appears on SW1's Gi0/1 trunk to SW2. CDP shows SW1's native VLAN as 1 while SW2's native VLAN on the matching port is 99. The trunk remains up and passes tagged traffic normally. What is the primary security/operational risk this mismatch creates?

    Network Access

    • A. The trunk link will immediately be disabled by CDP
    • B. Both switches will fail to elect a spanning-tree root bridge
    • C. The EtherChannel bundle carrying this trunk will automatically shut down
    • D. Untagged frames from VLAN 1 on one switch could be received into VLAN 99 on the other switch, crossing VLAN boundaries
    Show answer

    D. Untagged frames from VLAN 1 on one switch could be received into VLAN 99 on the other switch, crossing VLAN boundaries

    Untagged (native VLAN) frames are not tagged when sent across a trunk, so if the two ends disagree on which VLAN is native, an untagged frame sent as VLAN 1 by one switch will be interpreted as VLAN 99 by the other, effectively leaking traffic between VLANs. CDP only logs a warning; it does not disable the trunk.

  13. 13. Employees frequently travel and need secure encrypted access to internal company resources from any internet-connected location using a software client installed on their laptops. A permanent tunnel between fixed sites is not required. Which VPN type best meets this requirement?

    Security Fundamentals

    • A. GRE tunnel without encryption
    • B. Client-based remote-access VPN
    • C. Site-to-site VPN
    • D. MPLS VPN
    Show answer

    B. Client-based remote-access VPN

    A client-based remote-access VPN (such as Cisco AnyConnect) allows individual users to establish an encrypted tunnel from any internet connection to the corporate network using client software, ideal for traveling employees needing on-demand access rather than a permanent site-to-site link.

  14. 14. A host has the MAC address 00:1A:2B:3C:4D:5E and receives the IPv6 prefix 2001:DB8:ACAD:1::/64 via SLAAC. Using the EUI-64 process, what is the resulting IPv6 address?

    Network Fundamentals

    • A. 2001:DB8:ACAD:1::21A:2BFF:FE3C:4D5E
    • B. 2001:DB8:ACAD:1::21A:2BFE:FF3C:4D5E
    • C. 2001:DB8:ACAD:1::1A:2BFF:FE3C:4D5E
    • D. 2001:DB8:ACAD:1::1A2B:3CFF:FE4D:5E00
    Show answer

    A. 2001:DB8:ACAD:1::21A:2BFF:FE3C:4D5E

    EUI-64 splits the 48-bit MAC into two 24-bit halves (001A2B and 3C4D5E), inserts FFFE in the middle, and flips the 7th bit (universal/local bit) of the first byte. 00 (00000000) becomes 02 (00000010), yielding the interface ID 021A:2BFF:FE3C:4D5E, which with the leading zero dropped displays as 21A:2BFF:FE3C:4D5E appended to the prefix.

  15. 15. A network administrator configures a router so that multiple internal hosts share a single public IPv4 address for internet access, with each session distinguished by a unique source port number. Which technique is being used?

    Network Fundamentals

    • A. Dynamic NAT
    • B. NAT64
    • C. Port Address Translation (PAT)
    • D. Static NAT
    Show answer

    C. Port Address Translation (PAT)

    PAT, also known as NAT overload, allows many internal private addresses to share a single public IP address by tracking sessions using unique source port numbers. Static NAT maps one private address to one public address permanently, dynamic NAT maps from a pool without port sharing, and NAT64 translates between IPv6 and IPv4.

  16. 16. An administrator has enabled Dynamic ARP Inspection (DAI) on all access switches, using DHCP snooping bindings for validation. Several servers use statically configured IP addresses and never send DHCP requests, so their legitimate ARP replies are now being dropped by DAI. What should the administrator configure to permit these servers' ARP traffic while keeping DAI enforced for all DHCP clients?

    Security Fundamentals

    • A. Disable DHCP snooping on the VLAN containing the servers
    • B. Configure 'ip arp inspection validate src-mac dst-mac ip' globally
    • C. Configure the server switchports as DAI trusted interfaces
    • D. Create an ARP ACL that maps each server's static IP to its MAC address and apply it to the DAI configuration
    Show answer

    D. Create an ARP ACL that maps each server's static IP to its MAC address and apply it to the DAI configuration

    Since DAI validates ARP packets against the DHCP snooping binding table, hosts with static IPs (never seen by DHCP snooping) will fail validation. An ARP ACL manually defines valid IP-to-MAC mappings for these static hosts and can be applied to DAI so their traffic is permitted, while DHCP clients are still validated dynamically against the snooping database.

  17. 17. A company implements GLBP for the 172.16.30.0/24 VLAN using four member routers. Which statement accurately describes how GLBP differs from HSRP and VRRP in this deployment?

    IP Connectivity

    • A. GLBP allows only one router to actively forward traffic while the others remain in standby
    • B. GLBP requires a separate virtual IP address to be configured on each of the four routers
    • C. GLBP elects a single Active Virtual Gateway that also becomes the only Active Virtual Forwarder
    • D. GLBP allows all four routers to simultaneously forward traffic by assigning multiple virtual MAC addresses
    Show answer

    D. GLBP allows all four routers to simultaneously forward traffic by assigning multiple virtual MAC addresses

    GLBP's key advantage over HSRP/VRRP is active load balancing: one router is elected Active Virtual Gateway (AVG) and assigns different virtual MAC addresses to each participating router, making them Active Virtual Forwarders (AVFs) that all actively forward traffic for different clients simultaneously.

  18. 18. A router's routing table shows two entries for destination network 192.168.50.0/24: one static route with administrative distance 1 and one OSPF-learned route with administrative distance 110. A separate OSPF route also exists for 192.168.50.0/25 learned via a different path. Which route does the router use to forward a packet destined for 192.168.50.10?

    IP Connectivity

    • A. Both /24 routes are installed and load-balanced since they share the same prefix length
    • B. The OSPF route to 192.168.50.0/25, because it is the longest matching prefix
    • C. The OSPF route to 192.168.50.0/24, because OSPF is more scalable
    • D. The static route to 192.168.50.0/24, because static routes always win regardless of prefix length
    Show answer

    B. The OSPF route to 192.168.50.0/25, because it is the longest matching prefix

    Longest prefix match takes priority over administrative distance. Even though the static /24 route has a lower AD than the competing /24 OSPF route, the separate /25 OSPF route is more specific for 192.168.50.10 and is chosen regardless of AD comparisons among the /24 entries.

  19. 19. A router's routing table contains two routes learned via OSPF for the same destination network 10.20.0.0/16: one as an intra-area route (O) with metric 20, and another as an external Type 2 route (O E2) with metric 15 redistributed from another protocol. Which route will the router install and use for forwarding?

    IP Connectivity

    • A. The O E2 route, because external routes are always preferred over intra-area routes
    • B. Both routes will be installed and traffic will load balance between them
    • C. The intra-area O route with metric 20, because intra-area routes have a lower administrative distance than external OSPF routes
    • D. The O route with metric 20, because within OSPF, intra-area routes are always preferred over external routes regardless of the AD value assigned to each type
    Show answer

    D. The O route with metric 20, because within OSPF, intra-area routes are always preferred over external routes regardless of the AD value assigned to each type

    OSPF has an internal route preference hierarchy independent of Cisco's overall AD table entry (which lists OSPF as AD 110 for all types): intra-area routes are always preferred over inter-area routes, which are preferred over external (E1/E2) routes, regardless of the numeric metric value. So the intra-area route wins even though its metric (20) is higher than the external route's metric (15).

  20. 20. A branch office has a single lightweight AP whose CAPWAP control connection to the central WLC traverses an unreliable WAN link. The design requirement is that wireless clients must still authenticate and pass traffic locally even if the WAN link to the WLC fails. Which AP mode meets this requirement?

    Network Access

    • A. FlexConnect mode
    • B. Monitor mode
    • C. Sniffer mode
    • D. Local mode
    Show answer

    A. FlexConnect mode

    FlexConnect mode allows an AP to switch client data locally and, in standalone mode, continue authenticating clients using locally stored credentials or open/PSK authentication even when the CAPWAP link to the WLC is down. Local mode fully depends on the WLC for control and typically tunnels all data, and monitor/sniffer modes don't serve clients at all.

  21. 21. Which extended ACL statement correctly permits only HTTPS traffic from any source to the server at 10.10.20.50?

    Security Fundamentals

    • A. access-list 110 permit tcp host 10.10.20.50 any eq 443
    • B. access-list 110 permit ip any host 10.10.20.50 eq 443
    • C. access-list 110 permit tcp any 10.10.20.50 0.0.0.0 eq 80
    • D. access-list 110 permit tcp any host 10.10.20.50 eq 443
    Show answer

    D. access-list 110 permit tcp any host 10.10.20.50 eq 443

    The correct syntax is 'permit tcp any host 10.10.20.50 eq 443', matching any source, the specific destination host, and TCP port 443 (HTTPS). Option B reverses source and destination, option C uses the 'ip' protocol which doesn't support port filtering, and option D uses port 80 (HTTP) instead of 443.

  22. 22. A technician runs 'show ip route' on a branch router and sees the following output: C 10.1.1.0/24 is directly connected, GigabitEthernet0/1 L 10.1.1.1/32 is directly connected, GigabitEthernet0/1 O 10.2.2.0/24 [110/2] via 10.1.1.2, 00:01:12, GigabitEthernet0/1 S 0.0.0.0/0 [1/0] via 10.1.1.254 Which line represents a manually configured default route?

    IP Connectivity

    • A. L 10.1.1.1/32 is directly connected, GigabitEthernet0/1
    • B. C 10.1.1.0/24 is directly connected, GigabitEthernet0/1
    • C. O 10.2.2.0/24 [110/2] via 10.1.1.2, 00:01:12, GigabitEthernet0/1
    • D. S 0.0.0.0/0 [1/0] via 10.1.1.254
    Show answer

    D. S 0.0.0.0/0 [1/0] via 10.1.1.254

    The 'S' code identifies a static route, and 0.0.0.0/0 is the default route matching any destination not covered by a more specific entry. The [1/0] shows the default AD (1) for static routes and metric 0.

  23. 23. A campus network designer wants every core switch to have a direct physical connection to every other core switch, maximizing redundancy so a single link failure cannot isolate any device. Which topology describes this design?

    Network Fundamentals

    • A. Star topology
    • B. Hub-and-spoke topology
    • C. Full mesh topology
    • D. Partial mesh topology
    Show answer

    C. Full mesh topology

    In a full mesh topology, every node has a direct connection to every other node, providing maximum redundancy and eliminating single points of failure between core devices. Partial mesh only connects some nodes directly, while star and hub-and-spoke rely on a central device.

  24. 24. A company wants to run multiple isolated operating systems directly on server hardware for maximum performance, without installing a host operating system first. Which virtualization approach should be used?

    Network Fundamentals

    • A. Type 1 hypervisor
    • B. Type 2 hypervisor
    • C. Application virtualization
    • D. Container-based virtualization
    Show answer

    A. Type 1 hypervisor

    A Type 1 (bare-metal) hypervisor installs directly on the physical server hardware and manages guest virtual machines without needing an underlying host OS, providing better performance and resource efficiency than Type 2 hypervisors.

  25. 25. A network administrator receives documentation stating a subnet mask of /21 for a newly assigned network. Which subnet mask in dotted-decimal notation corresponds to this CIDR value?

    Network Fundamentals

    • A. 255.255.248.0
    • B. 255.255.240.0
    • C. 255.255.255.0
    • D. 255.255.252.0
    Show answer

    A. 255.255.248.0

    A /21 mask means 21 bits are network bits. The first three octets (24 bits) are all 1s, and the fourth octet has 24 total minus... actually the third octet needs 5 bits from it: 21 = 8+8+5, so the third octet is 11111000 = 248. Thus the mask is 255.255.248.0.

Cisco CCNA (200-301) flashcards

Tap a card to flip it. 226 flashcards in the full deck.

  • 5 GHz Channel Bonding

    Flip card

    Channel bonding combines two or more adjacent 20 MHz channels (e.g., into 40, 80, or 160 MHz) to boost throughput at the cost of fewer available non-overlapping channels.

    • Increases throughput but increases interference risk
    • Reduces total independent channel count in a band
    • Common in 802.11n/ac/ax for higher-speed WLANs
    Study this card →
  • Longest Prefix Match

    Flip card

    The rule that a router selects the route with the longest (most specific) matching subnet mask when multiple routes match a destination.

    • Always evaluated before administrative distance
    • More specific /25 beats less specific /24 or /16
    • Applies to both IPv4 and IPv6 routing tables
    Study this card →
  • JSON Array

    Flip card

    A JSON array is an ordered, comma-separated collection of values enclosed in square brackets [ ], which can hold numbers, strings, objects, or other arrays.

    • Denoted by square brackets [ ]
    • Values are ordered and accessed by index
    • Can contain mixed data types including nested objects/arrays
    Study this card →
  • REST HTTP Methods

    Flip card

    REST APIs use standard HTTP verbs to perform CRUD operations: GET (read), POST (create), PUT (full update/replace), PATCH (partial update), DELETE (remove).

    • GET is safe and idempotent
    • PUT is idempotent, replaces whole resource
    • PATCH modifies only specified fields, not necessarily idempotent
    Study this card →
  • DHCP Snooping Binding Database

    Flip card

    A table built by DHCP snooping that records trusted IP-to-MAC-to-VLAN-to-port mappings, used by DAI and IP Source Guard for validation.

    • Populated from DHCPACK messages on trusted ports
    • Used by DAI to validate ARP packets
    • Used by IP Source Guard to filter spoofed traffic
    Study this card →
  • enable secret vs enable password

    Flip card

    enable secret uses a strong one-way hash (Type 5/8/9) and takes precedence over enable password, which is stored in weaker, reversible Type 7 form when service password-encryption is enabled.

    • enable secret always overrides enable password for authentication
    • service password-encryption applies weak Type 7 to plaintext passwords
    • Type 7 is easily reversible; Type 5/8/9 hashes are much stronger
    Study this card →
  • HSRP Preempt

    Flip card

    A configuration option that allows a router with a higher HSRP priority to take back the Active role after recovering from a failure.

    • Preempt is disabled by default in HSRP
    • Command: standby <group> preempt
    • Without preempt, the current Active router keeps its role even if a higher-priority router returns
    Study this card →
  • Ansible Agentless Automation

    Flip card

    Ansible is a push-based, agentless automation tool that uses SSH (for Linux/network devices) to apply configurations defined in YAML playbooks from a control node.

    • No agent software needed on managed nodes
    • Uses YAML playbooks and modules
    • Push model: control node initiates connections
    Study this card →
  • Ansible Resource Module States

    Flip card

    Cisco IOS Ansible resource modules use a 'state' parameter (merged, replaced, overridden, deleted) to control how declared configuration interacts with existing device configuration.

    • merged: combines new config with existing, non-destructive
    • replaced: replaces only the specified config section
    • overridden: replaces entire config type, removing unspecified items
    Study this card →
  • TACACS+ vs RADIUS

    Flip card

    TACACS+ is Cisco's AAA protocol that encrypts entire packets over TCP port 49; RADIUS encrypts only the password and uses UDP ports 1812/1813.

    • TACACS+: TCP port 49, full packet encryption
    • RADIUS: UDP 1812 (auth)/1813 (accounting), password-only encryption
    • TACACS+ separates authentication, authorization, accounting
    Study this card →
  • Port Security Violation Modes

    Flip card

    Determines the switch action when the number of allowed MAC addresses on a port is exceeded.

    • shutdown: err-disables the port (default)
    • restrict: drops frames, logs, increments counter, port stays up
    • protect: drops frames silently, no logging
    Study this card →
  • Native VLAN Mismatch

    Flip card

    Occurs when two ends of an 802.1Q trunk are configured with different native VLANs, causing untagged frames to be misclassified.

    • CDP detects and logs the mismatch via syslog
    • Untagged frames are not tagged with a VLAN ID on the wire
    • Mismatch can allow VLAN traffic leakage, a security concern
    Study this card →
  • Client-Based Remote-Access VPN

    Flip card

    A VPN solution where individual users run client software (e.g., Cisco AnyConnect) to establish an encrypted tunnel to a corporate network from any internet connection, ideal for remote/traveling users.

    • Established on-demand by the user, not permanent
    • Commonly uses SSL/TLS or IPsec
    • Contrasts with site-to-site VPNs, which connect fixed locations permanently
    Study this card →
  • IPv6 EUI-64

    Flip card

    EUI-64 generates a 64-bit interface ID from a 48-bit MAC address by splitting it, inserting FFFE in the middle, and flipping the 7th bit of the first byte.

    • Split MAC into two 24-bit halves
    • Insert FFFE between the halves
    • Flip the universal/local (U/L) bit of the first byte
    Study this card →
  • Port Address Translation (PAT)

    Flip card

    PAT, or NAT overload, allows multiple private hosts to share a single public IP address by using unique source port numbers to differentiate simultaneous sessions.

    • Also called NAT overload
    • Most common form of NAT on home/SOHO routers
    • Uses source port numbers to multiplex sessions
    Study this card →
  • DAI ARP ACLs for Static Hosts

    Flip card

    An ARP access control list can be configured to manually define valid IP-to-MAC bindings for static IP hosts, allowing DAI to validate them without relying on the DHCP snooping binding table.

    • Used when hosts don't use DHCP (e.g., servers, printers)
    • Applied with 'ip arp inspection filter <acl-name> vlan <id>'
    • DHCP clients still validated against snooping bindings normally
    Study this card →
  • GLBP Load Balancing

    Flip card

    Gateway Load Balancing Protocol allows multiple routers to actively forward traffic for a single virtual IP by assigning each router a distinct virtual MAC address as an Active Virtual Forwarder.

    • One router is elected AVG to manage virtual MAC assignment
    • Up to 4 AVFs can forward traffic simultaneously
    • Unlike HSRP/VRRP, GLBP uses all available bandwidth rather than one active path
    Study this card →
  • Prefix Length vs Administrative Distance

    Flip card

    Routers first select the most specific (longest) matching prefix for a destination; administrative distance is only used to break ties between sources advertising the identical prefix length.

    • Longest prefix match is evaluated first, always
    • AD comparison happens only among routes with the same prefix length
    • A /25 route always beats a /24 route for an address within the /25 range
    Study this card →
  • OSPF Route Type Preference

    Flip card

    Within OSPF, route selection follows a fixed hierarchy: intra-area > inter-area > external Type 1 > external Type 2, regardless of the numeric cost/metric.

    • Intra-area routes always beat inter-area and external routes
    • E1 costs include external+internal metric; E2 shows only external cost
    • This is separate from Administrative Distance which is 110 for all OSPF routes
    Study this card →
  • FlexConnect AP Mode

    Flip card

    An AP mode designed for branch offices that allows local switching of client traffic and authentication even when the WLC connection is lost.

    • Supports standalone mode during WAN outages
    • Can locally switch data traffic instead of tunneling all traffic to WLC
    • Ideal for remote/branch sites with WAN links to central WLC
    Study this card →
  • Extended ACL Syntax

    Flip card

    Extended ACLs filter based on protocol, source, destination, and port number using the syntax: access-list <100-199> permit/deny protocol source destination [operator port].

    • Port matching requires tcp or udp, not ip
    • 'eq 443' matches HTTPS traffic
    • Source is listed before destination in the syntax
    Study this card →
  • Routing Table Codes

    Flip card

    The leftmost letter code in 'show ip route' output identifies how each route was learned (C=connected, L=local, S=static, O=OSPF, D=EIGRP).

    • C = directly connected interface network
    • L = local /32 (or /128) address of the router itself
    • S* or S with 0.0.0.0/0 indicates a static default route
    Study this card →
  • Full Mesh Topology

    Flip card

    A full mesh topology directly connects every network node to every other node, offering maximum redundancy at the cost of higher cabling and complexity.

    • Every node connects to every other node
    • Formula: n(n-1)/2 links for n nodes
    • High redundancy, high cost
    Study this card →
  • Type 1 vs Type 2 Hypervisor

    Flip card

    Type 1 (bare-metal) hypervisors run directly on hardware; Type 2 (hosted) hypervisors run as an application on top of an existing OS.

    • Type 1 examples: VMware ESXi, Microsoft Hyper-V
    • Type 2 examples: VMware Workstation, VirtualBox
    • Type 1 offers better performance for data center use
    Study this card →

Questions are original practice items written to match the published exam objectives. Step2Study is not affiliated with or endorsed by any certification body.