Cisco CCNA Study Library
200-301
41 free articles on the concepts the 200-301 exam tests, grouped by exam domain. Each one backs real questions in our practice exam.
Automation and Programmability
- How Automation Changes Network Management Consistency, scale, and version-controlled intent are the gains; identical damage on every device is the cost. Plus controllers, APIs, and AI/ML in NetOps.
- Underlay, Overlay, and Fabric in Controller-Based Networks The underlay is routed IP transport, the overlay is a VXLAN-tunnelled topology, and the fabric is both plus policy. SD-Access node roles and SD-WAN basics.
IP Connectivity
- Administrative Distance: The Full Table and How Routes Compete Administrative distance ranks route sources on Cisco routers: connected 0, static 1, eBGP 20, EIGRP 90, OSPF 110, RIP 120, iBGP 200, and 255 for unusable.
- Floating Static Routes: Backup Paths Using Administrative Distance A floating static route uses a raised administrative distance to hold a backup path out of the routing table until the preferred route is withdrawn.
- How a Cisco Router Chooses a Route: Longest Prefix, then AD, then Metric Route selection runs in a fixed order: longest prefix match, then administrative distance, then metric. A longer prefix beats a more trusted route source.
- HSRP vs VRRP vs GLBP: Choosing a First Hop Redundancy Protocol Virtual IPs and virtual MACs, HSRP active/standby versus VRRP master/backup versus GLBP load sharing, plus the tracking decrement candidates get wrong.
- Reading show ip route: Code Letters, AD/Metric Brackets, and Next Hops Decode a Cisco routing table: C, L, S, S*, O and D codes, the [110/12] bracket, next hop, uptime, exit interface, and the gateway of last resort header.
- Single-Area OSPFv2: Configuration, Wildcards, and Verification Process IDs, wildcard masks, router-ID selection, passive interfaces, and the 100 Mbps reference bandwidth, with the show commands that prove each one.
- Static Routing on Cisco: Next Hop vs Exit Interface Configure IPv4 and IPv6 static routes on IOS: next-hop, exit-interface and fully specified forms, default routes, distance values, and the proxy ARP trap.
- Why OSPF Neighbors Will Not Form The parameters two OSPF routers must agree on, the MTU mismatch that freezes adjacency in EXSTART, and how to read each neighbor state as a diagnosis.
IP Services
- Cisco DHCP: Server Pools, Relay, and ip helper-address DORA over UDP 67 and 68, ip dhcp pool syntax, excluded addresses, ip address dhcp on a client interface, and why ip helper-address faces the clients.
- Inside Source NAT and PAT on Cisco Routers Inside local versus inside global, static NAT versus a pool versus overload, exact IOS syntax, and why a missing ip nat inside breaks the whole thing.
- TFTP and FTP on IOS: Backing Up Configs and Upgrading Images TFTP on UDP 69 versus FTP on TCP 20/21, config backup and restore, checking flash space, copy tftp flash, verify /md5, and the save-before-reload trap.
Network Access
- 802.1Q Trunking on Cisco: Tags, Native VLAN, and Allowed Lists Inside the 4-byte 802.1Q tag, the trunk configuration commands, and the add/remove/except/none keywords that quietly black-hole production VLANs.
- Access Port or Trunk? Wiring a Cisco Access Point Correctly A local-mode lightweight AP needs an access port; an autonomous AP or FlexConnect local switching needs a trunk. Why, and the symptom when it is wrong.
- CDP vs LLDP: Timers, Defaults, and What Each Neighbor Table Reveals CDP is Cisco-proprietary and on by default at 60/180 seconds. LLDP is IEEE 802.1AB, off by default at 30/120. Commands, output reading, and security.
- Cisco AP Modes and CAPWAP: Local, FlexConnect, Monitor, Sniffer, Bridge CAPWAP control on UDP 5246 and data on UDP 5247, plus every Cisco access point mode and the deployment scenario each one exists to solve.
- Creating a WPA2 PSK WLAN on a Cisco WLC Walk the WLC GUI: profile name vs SSID, interface mapping, WPA+WPA2 with AES, PSK key management, key format rules, and why clients fail to join.
- DTP Modes: Which Combinations Actually Form a Trunk Cisco's Dynamic Trunking Protocol decides trunk or access. The full mode matrix, why auto plus auto fails, and where switchport nonegotiate is legal.
- EtherChannel: LACP, PAgP, and On Modes Explained Which channel-group mode pairings actually bundle, how LACP and PAgP differ, where to apply trunk and IP settings, and why one flow never exceeds one link.
- Inter-VLAN Routing: Router-on-a-Stick vs Layer 3 Switch SVIs Router-on-a-stick uses dot1Q subinterfaces on one trunk. A Layer 3 switch uses SVIs plus ip routing. Configuration, failure modes, and design trade-offs.
- Native VLAN Mismatch: Symptoms, Security Risk, and the Fix What happens when trunk ends disagree on the native VLAN: the PVID inconsistency syslog, the CDP warning, the double-tagging attack, and how to clear it.
- PortFast, BPDU Guard, Root Guard, and Loop Guard What PortFast really does, why BPDU guard err-disables a port, why BPDU filter is dangerous, and where root guard and loop guard belong.
- Rapid PVST+: Port Roles, Port States, and Fast Convergence How Rapid PVST+ implements 802.1w per VLAN: the four port roles, the three port states, edge and point-to-point link types, and proposal/agreement.
- Reading show interfaces trunk: Allowed vs Active vs Forwarding The three VLAN lists in show interfaces trunk mean different things. Learn what removes a VLAN from each one and how to diagnose a trunk from the output.
- STP Root Bridge Election: Bridge ID, Priority, and Tiebreakers How the bridge ID, extended system ID, and 4096 priority increments decide the root bridge, plus the root-port tiebreaker chain and default STP path costs.
- VLANs on Cisco Switches: Creating, Assigning, and Verifying Create VLANs, assign access ports, and read show vlan brief on Catalyst switches, including vlan.dat persistence and why deleted VLANs strand their ports.
- Voice VLAN: How a Cisco Phone and a PC Share One Switch Port The switchport voice vlan command, what the phone tags, what the PC sends untagged, and why the feature fails silently without CDP or LLDP-MED.
- VTP Explained: Server, Client, Transparent, and the Revision-Number Outage How VTP synchronizes VLAN databases across Cisco switches, why a client can overwrite a server, and the reset procedure that prevents a campus-wide outage.
- Why an EtherChannel Will Not Bundle Suspended versus stand-alone members, the parameters IOS compares before aggregating, the %EC-5 log messages that name the culprit, and summary flags.
- Wireless RRM and Roaming: DCA, TPC, Mobility Groups, and Rogue Detection How Cisco RRM picks channels with DCA and trims power with TPC, what mobility groups need for seamless roaming, and how rogue detector APs work.
- WLC Ports and Interfaces: Management, Virtual, Dynamic, and Service A wireless LAN controller's physical ports versus its logical interfaces, what each one is for, and the subnet mistakes that break out-of-band management.
Network Fundamentals
- Cisco CCNA 200-301 Study Guide: Exam Format, Domains, Cost, and a Study Plan Cisco CCNA 200-301 v1.1 explained: the 120-minute format, all six domains and weights, the $300 cost, and a phased plan for passing it.
- Cisco Transceivers and Cabling: SFP, QSFP, Single-Mode vs Multimode SFP, SFP+, SFP28, QSFP+ and QSFP28 speeds; DAC and AOC versus optics; single-mode and multimode distances; Cat 6 at 55 m against Cat 6a at 100 m.
- Duplex Mismatch: The Counter Fingerprint and How to Confirm It One side hard-set, the other autonegotiating to half duplex. CRC errors on one end, late collisions on the other, and how to confirm it from both ends.
- Network Architectures: Two-Tier, Three-Tier, and Spine-Leaf Collapsed core, the three campus layers and their jobs, spine-leaf cabling rules and east-west traffic, plus WAN topologies and full-mesh link math.
- Reading show interfaces Counters: CRC, Runts, Giants, and Drops Separate cable faults from congestion in an IOS counter block: what CRC, runts, giants, overruns, and output drops each accuse, and what they rule out.
- Router, Layer 3 Switch, Firewall, AP, WLC: Which Device Does What Router versus Layer 3 switch, stateful firewall versus NGFW, IDS versus IPS, AP versus WLC: what each device does and when a design actually needs it.
Security Fundamentals
- Cisco IOS CLI Modes: User, Privileged, Global, Interface, and Line Every IOS mode, the exact prompt it shows, and how to move between them, plus interface range, do, logging synchronous, and console versus vty access.
- Cisco IOS Password Types 0, 7, 5, 8, and 9 The leading digit in an IOS password names its algorithm. Type 7 is reversible obfuscation, type 5 is MD5, type 8 is PBKDF2, and type 9 is scrypt.
- Securing Cisco Device Access: enable secret, line vty, and Privilege Levels Why enable secret always beats enable password, how login differs from login local, what exec-timeout 0 0 does, and where privilege levels 1 and 15 apply.
Reading is step one — practicing is what passes the exam.
2,650 original 200-301 questions, every answer explained, $79 once — no subscription.