
Cisco Certified Network Associate (CCNA)
The Cisco Certified Network Associate (CCNA) certification validates your ability to install, configure, operate, and troubleshoot medium-sized routed and switched networks. It covers network fundamentals, IP connectivity, IP services, security fundamentals, and automation. CCNA is the industry standard for entry-level networking roles, opening doors to careers as a network engineer, administrator, or help desk professional.
1573 practice questions · Updated 2025-01-01
6Domains
53Objectives
326Concepts
1573Questions
200-301 Curriculum
Every domain, objective, and concept the 200-301 exam measures.
- Router role and function
- Layer 2 switch function
- Layer 3 switch function
- Next-generation firewall (NGFW) role
- Intrusion prevention system (IPS) role
- Access point (AP) function
- Network controller role
- Endpoint role and function
- Server role and function
- Power over Ethernet (PoE)
- Two-tier architecture
- Three-tier architecture
- Spine-leaf architecture
- WAN topologies
- SOHO topology
- On-premises and cloud architectures
- Single-mode fiber
- Multimode fiber
- Copper cabling
- Ethernet shared media
- Ethernet point-to-point
- Collision detection
- Collision domains
- Interface errors
- Duplex mismatch
- Speed mismatch
- Troubleshooting methodology
- TCP vs UDP overview
- TCP features
- UDP features
- Use cases
- IPv4 Address Structure
- IPv4 Address Classes
- Public and Private IPv4 Addresses
- Subnet Mask Notation
- Subnetting Fundamentals
- Variable Length Subnet Masking (VLSM)
- IPv4 Addressing Configuration
- IPv4 Address Verification
- IPv4 Addressing Troubleshooting
- Definition of private IPv4 addresses
- RFC 1918 address ranges
- Characteristics of private addresses
- Use cases for private addressing
- Network Address Translation (NAT) relationship
- IPv6 addressing fundamentals
- IPv6 address compression
- IPv6 prefix notation
- IPv6 global unicast addressing
- IPv6 link-local addressing
- IPv6 unique local addressing
- IPv6 multicast addressing
- IPv6 anycast addressing
- IPv6 address configuration methods
- IPv6 neighbor discovery
- IPv6 prefix configuration on interfaces
- Verification of IPv6 addressing
- IPv6 Address Types Overview
- Global Unicast Address
- Unique Local Address
- Link-Local Address
- Anycast Address
- Multicast Address
- Modified EUI-64
- IP configuration verification on Windows
- IP configuration verification on macOS
- IP configuration verification on Linux
- Interpreting IP parameter output
- Nonoverlapping Wi-Fi channels
- SSID
- RF fundamentals
- Wireless encryption
- Server Virtualization Fundamentals
- Containers Fundamentals
- VRF (Virtual Routing and Forwarding) Fundamentals
- MAC learning
- MAC aging
- Frame switching
- Frame flooding
- MAC address table
- VLAN Fundamentals
- Access Port Configuration
- Voice VLAN Configuration
- Default VLAN Identification
- VLAN Trunking Between Switches
- InterVLAN Routing via Router-on-a-Stick
- InterVLAN Routing via Layer 3 Switch
- Verification of VLAN Configuration
- Trunk port configuration
- Trunk port operation
- 802.1Q encapsulation
- 802.1Q trunking protocol
- Native VLAN concept
- Native VLAN configuration
- Trunk negotiation (DTP)
- Trunk verification commands
- CDP Overview
- LLDP Overview
- CDP Configuration
- LLDP Configuration
- Verifying CDP
- Verifying LLDP
- CDP vs LLDP
- EtherChannel fundamentals
- LACP configuration
- Layer 2 EtherChannel
- Layer 3 EtherChannel
- EtherChannel verification
- Load balancing
- Root bridge election
- Root port selection
- Designated and blocked ports
- Port states and roles in Rapid PVST+
- PortFast operation
- Root guard
- Loop guard
- BPDU filter
- BPDU guard
- Cisco Wireless Architectures Overview
- Autonomous AP Architecture
- Cloud-based AP Architecture
- Centralized (Split-MAC) Architecture
- AP Modes Overview
- Local AP Mode
- Monitor AP Mode
- Sniffer AP Mode
- Rogue Detector AP Mode
- FlexConnect AP Mode
- WLAN component roles
- AP connectivity options
- Access and trunk ports for WLAN
- Link aggregation (LAG) for WLAN
- Telnet
- SSH
- HTTP
- HTTPS
- Console Access
- TACACS+
- RADIUS
- Cloud Managed
- WLAN Creation
- Security Settings
- QoS Profiles
- Advanced Settings
- Routing protocol code
- Prefix
- Network mask
- Next hop
- Administrative distance
- Metric
- Gateway of last resort
- Longest Prefix Match
- Administrative Distance
- Routing Protocol Metric
- Default route configuration
- Network route configuration
- Host route configuration
- Floating static route configuration
- Static route verification
- IPv4 and IPv6 static route syntax
- OSPFv2 neighbor adjacency states
- OSPFv2 hello protocol and timers
- OSPFv2 neighbor requirements
- OSPFv2 point-to-point network type
- OSPFv2 broadcast network type and DR/BDR election
- OSPFv2 DR/BDR behavior and adjacency
- OSPFv2 router ID selection
- OSPFv2 router ID stability and impact
- Purpose of FHRPs
- Functions of FHRPs
- Concepts of FHRPs
- Common FHRP protocols
- Static NAT configuration
- Static NAT verification
- NAT pool configuration
- Dynamic NAT with access list
- Dynamic NAT verification
- PAT (overload) configuration
- PAT verification
- Inside source NAT terminology
- NAT translation table inspection
- NTP fundamentals
- NTP client and server roles
- NTP configuration on Cisco IOS
- NTP verification commands
- NTP authentication
- DHCP Overview
- DHCP Operation
- DHCP Configuration
- DHCP Relay
- DNS Overview
- DNS Resolution Process
- DNS Records
- DNS Configuration
- DHCP and DNS Integration
- SNMP architecture
- SNMP versions
- SNMP operations
- SNMP MIB and OIDs
- SNMP traps and informs
- SNMP community strings
- SNMPv3 security
- Syslog Overview
- Syslog Facilities
- Syslog Severity Levels
- Configuring Syslog
- Syslog Message Format
- Syslog vs. SNMP
- DHCP client configuration
- DHCP client verification
- DHCP relay configuration
- DHCP relay verification
- Classification
- Marking
- Queuing
- Congestion Management
- Policing
- Shaping
- PHB Overview
- SSH overview
- SSH server configuration
- SSH client configuration
- SSH version and authentication
- SSH verification and troubleshooting
- TFTP Overview
- FTP Overview
- TFTP vs FTP Comparison
- TFTP Operation
- FTP Operation
- TFTP Configuration and Usage
- FTP Configuration and Usage
- Threats
- Vulnerabilities
- Exploits
- Mitigation Techniques
- User Awareness Programs
- Security Training
- Physical Access Control
- Integration of Security Program Elements
- Local password authentication
- Password encryption
- Enable secret
- Line password configuration
- Login authentication methods
- Password verification
- Password Management
- Password Complexity
- Multifactor Authentication
- Certificates
- Biometrics
- IPsec VPN Overview
- IPsec Protocols and Components
- IKE Phases
- IPsec Modes
- Remote Access VPN Configuration
- Site-to-Site VPN Configuration
- VPN Comparison
- ACL Purpose and Types
- ACL Configuration Syntax
- ACL Placement and Direction
- ACL Wildcard Masking
- ACL Implicit Deny and Ordering
- ACL Verification Commands
- ACL Troubleshooting
- DHCP snooping configuration
- DHCP snooping verification
- Dynamic ARP Inspection (DAI) configuration
- Dynamic ARP Inspection verification
- Port security configuration
- Port security verification
- Layer 2 security feature interaction
- Authentication
- Authorization
- Accounting
- AAA Framework
- AAA Implementation Methods
- WPA Overview
- WPA2 Overview
- WPA3 Overview
- WPA vs WPA2 vs WPA3 Comparison
- WPA Personal vs Enterprise Modes
- WPA3 Enhancements
- WLAN GUI navigation
- WPA2 PSK parameters
- WLAN creation
- WLAN verification
- Automation Benefits
- Automation and Network Management
- Automation vs. Traditional Management
- Automation Tools and Technologies
- Impact on Network Operations
- Traditional network architecture
- Controller-based network architecture
- Comparison of control planes
- Comparison of data planes
- Comparison of management and configuration
- Comparison of scalability and agility
- Comparison of failure handling and resilience
- Control plane vs. data plane separation
- Overlay, underlay, and fabric
- Northbound APIs
- Southbound APIs
- Generative AI in Network Operations
- Predictive AI in Network Operations
- Machine Learning Fundamentals
- AI and ML Use Cases in Networking
- AI and ML Benefits and Limitations
- REST API Authentication Types
- CRUD Operations in REST
- HTTP Verbs in REST
- Data Encoding in REST
- Configuration Management Overview
- Ansible Core Concepts
- Ansible Playbooks and YAML
- Ansible Inventory and Ad-Hoc Commands
- Ansible for Network Automation
- Terraform Core Concepts
- Terraform Configuration Language (HCL)
- Terraform State and Planning
- Terraform for Network Automation
- Comparing Ansible and Terraform
- JSON syntax basics
- JSON data types
- JSON formatting rules
- JSON nesting
- JSON vs other data formats
Ready to practice?Test your knowledge with exam-style questions or take an intelligent quiz tailored to your level.
Percentages reflect share of the current practice bank, not official exam weightings — no structured per-skill weight is published for 200-301, so none is invented.