Reference notes for the facts CCNA questions depend on: addresses, VLANs, spanning tree, OSPFv2, NAT, ACLs, and the difference between a northbound API and a southbound one.
Exam: 200-301 v1.1Six domainsReviewed October 2026
How to read these notes: Items tagged Extra sit outside the v1.1 topic list, such as Chef and Puppet. Items tagged v2.0 belong to the blueprint that opens on February 3, 2027. Learn the unmarked items first if you test by February 2, 2027. New to the exam? Start with the overview for the format and the domain weights. Shared port facts also appear in the networking and cloud notes.
Devices, media, and topologies
Domain 1 starts here. Name the decision the device makes before you name the product.
Network components on the v1.1 topic list.
Component
What it does
Router
Forwards packets between IP networks. The default gateway is a router address on the host's subnet.
Layer 2 switch
Forwards a frame by the destination MAC. Unknown unicasts are flooded in the VLAN. The source MAC is learned on the arrival port.
Layer 3 switch
Switches frames and can route between VLANs with switched virtual interfaces.
Next-generation firewall and IPS
A firewall allows or blocks by policy. An IPS can drop traffic because it sits in the path.
Access point and WLC
An autonomous AP is configured on its own. A lightweight AP takes its configuration from a wireless LAN controller.
Cisco DNA Center
A campus controller for inventory, assurance, and automation. It is not the WLC that joins lightweight APs.
PoE
The switch supplies power on the Ethernet cable. 802.3af offers up to 15.4 W at the port. 802.3at (PoE+) offers up to 30 W. The switch budget is the limit, not the standard's maximum on every port at once.
Topologies and media. Pick the design by the traffic pattern, not by the vendor logo.
Design or medium
How to recognize it
Two-tier
Access switches connect to a collapsed core. Distribution and core are the same layer.
Three-tier
Access, distribution, and core are separate. The core moves traffic quickly and does not apply every policy.
Spine-leaf
Every leaf connects to every spine. Leaves do not connect to each other. East-west traffic has a predictable hop count.
SOHO
A small site, often one device that routes, switches, and offers wireless.
Single-mode fiber
One path for light, a laser, and longer distances. Do not mix it with a multimode optic.
Multimode fiber
A wider core and a shorter reach, used inside a building or a campus.
Duplex or speed mismatch
A duplex mismatch often stays up and shows late collisions on the half-duplex side. A speed mismatch often leaves the link down.
TCP and UDP. TCP sets up a session, retransmits lost segments, and keeps order. UDP does not. DNS queries, DHCP, NTP, and SNMP usually use UDP. HTTP, SSH, and FTP use TCP.
Virtualization. A virtual machine has a guest operating system on a hypervisor. A container shares the host kernel. A VRF is a separate routing table on one physical router, not a virtual machine. v2.0 pushes harder on diagnosing these, but the three ideas are already on v1.1.
IPv4 addressing
Subtract the network and broadcast addresses before you count hosts. A /30 is the usual point-to-point mask on this exam.
Masks CCNA expects you to calculate without a calculator. Hosts means usable addresses.
Prefix
Mask
Block size
Usable hosts
/24
255.255.255.0
256
254
/25
255.255.255.128
128
126
/26
255.255.255.192
64
62
/27
255.255.255.224
32
30
/28
255.255.255.240
16
14
/29
255.255.255.248
8
6
/30
255.255.255.252
4
2
Private and special
10.0.0.0/8, 172.16.0.0/12, and 192.168.0.0/16 are private. 172.16.0.0/12 runs through 172.31.255.255. 172.32.0.1 is public.
169.254.0.0/16 is an automatic address a host picks when DHCP fails. It is not a range you planned.
127.0.0.1 is loopback. Traffic to it never leaves the host.
How to find the network
Find the block size in the interesting octet, then step back to the multiple of that size. 192.168.10.70/26 is in 192.168.10.64 through 192.168.10.127. The network is .64, the broadcast is .127, and the usable hosts are .65 through .126. The wildcard of a /26 is 0.0.0.63, which is the inverse of 255.255.255.192.
IPv6 addresses
Know the prefix by the job. You do not need to memorize every hextet.
IPv6 types on the v1.1 list.
Type
How to recognize it
Global unicast
2000::/3. This is the routable address, similar in role to a public IPv4 address.
Unique local
fc00::/7. Addresses you assign in practice usually start with fd. They are not meant for the public Internet.
Link-local
fe80::/10. Every IPv6 interface has one. It is used on the link, including as an OSPFv3 next hop. v2.0 OSPFv3 itself is not a v1.1 configuration task.
Multicast
ff00::/8. ff02::1 is all nodes on the link. ff02::2 is all routers on the link.
Anycast
The same unicast address on more than one device. The nearest one answers. There is no separate prefix.
Loopback
::1. It stays on the host.
Modified EUI-64
Split the MAC, insert fffe in the middle, and invert the U/L bit. 00:11:22:33:44:55 becomes 0211:22ff:fe33:4455.
Client checks: Windows uses ipconfig. Linux uses ip address. macOS uses ifconfig. Look for the mask, the gateway, and a 169.254 address before you blame the router.
VLANs, trunks, and EtherChannel
Domain 2. A VLAN is a broadcast domain. A trunk is how that domain crosses a switch.
Switching facts v1.1 asks you to configure or verify.
Idea
What to remember
Access port
One data VLAN, sent untagged. A voice VLAN can be added and is tagged. The normal VLAN range is 1 to 1005. VLAN 1 is the default.
802.1Q trunk
Inserts a VLAN tag. The native VLAN is sent untagged. Both ends must agree, or traffic leaks or drops.
Inter-VLAN routing
A router-on-a-stick uses subinterfaces with encapsulation dot1Q. A Layer 3 switch uses an SVI per VLAN and ip routing.
CDP and LLDP
Both discover the neighbor at Layer 2. CDP is Cisco. LLDP is the multi-vendor protocol. Neither is a routing protocol.
LACP
active and passive form a channel. Passive with passive does not. Speed, duplex, and the VLAN list must match. PAgP (desirable and auto) is Cisco-only and is not the protocol v1.1 names.
Wireless on this domain. A local-mode AP tunnels client traffic to the WLC. FlexConnect can switch locally at a branch. Monitor mode watches the RF and does not serve clients. The WLC connects to the switched network on an access port, a trunk, or a link aggregation group. The GUI task is to create a WLAN, set security, and pick a QoS profile. WPA2 PSK is the security setting v1.1 asks you to verify.
Rapid PVST+
One spanning tree per VLAN. The goal is one forwarding path, so a loop cannot multiply a broadcast.
Spanning-tree roles and the protections v1.1 added or kept.
Term
Meaning
Root bridge
The switch with the lowest bridge ID. The ID is priority plus MAC, and the default priority is 32768. Set a primary and a secondary on purpose. Do not leave the root to the lowest MAC.
Root port
The port on this switch with the best path to the root. A switch has one root port, unless it is the root.
Designated port
The forwarding port for a segment. Every segment has one.
Alternate port
A backup path toward the root. It discards frames until the root port fails.
PortFast
Skips listening and learning on an edge port so a PC comes up quickly. Do not enable it on a link to another switch.
BPDU Guard
Error-disables a PortFast port that receives a BPDU. That is how you stop someone from plugging in a switch.
Root Guard
If a superior BPDU arrives, the port is blocked so this switch keeps the root you chose.
Loop Guard
If BPDUs stop on a root or alternate port, the port stays discarding instead of becoming designated and closing a loop.
BPDU Filter
Stops BPDUs on a port. v1.1 lists it. It can hide a loop, so it is not a substitute for BPDU Guard.
How a router forwards
Domain 3 is 25 percent. Read the prefix before you read the protocol letter.
Longest matching prefix. 10.1.1.0/24 beats 10.1.0.0/16 for 10.1.1.10.
Lowest administrative distance, only when the prefixes are equal.
Lowest metric, only inside the protocol that won the previous step.
Administrative distances that show up when you read a routing table. A lower number is more trusted.
Source
Code
Distance
Connected
C
0
Static
S
1
eBGP Extra
B
20
EIGRP internal Extra
D
90
OSPF
O
110
RIP Extra
R
120
v1.1 asks you to configure static routes and OSPFv2, and to interpret a table. Configuring EIGRP, RIP, or BGP is outside that list. You still need their distances when a show command prints them. A floating static uses an administrative distance worse than the primary protocol, such as 130, so OSPF (110) is used while it is up and the static route takes over when OSPF withdraws. A host route is a /32. A default route is 0.0.0.0/0, and the gateway of last resort is that default.
First-hop redundancy. HSRP, VRRP, and GLBP give hosts one virtual gateway. If the active router fails, another router owns the virtual IP. Hosts do not change their gateway setting. v1.1 asks you to describe this, not to build a full HSRP lab. v2.0 asks you to interpret HSRP and VRRP output.
Single-area OSPFv2
Neighbors must agree before a route is exchanged. Area 0 is the backbone, and a single-area design is all area 0.
What must match, and what the router ID and DR election use.
Check
Rule
Router ID
The manual ID if you set one. Otherwise the highest loopback, otherwise the highest active interface address. It does not have to be a reachable address, but it must be unique.
Hello and dead
Must match. On Ethernet broadcast and point-to-point, the defaults are 10 and 40 seconds.
Area and subnet
The interfaces must be in the same area and the same subnet on a broadcast link. A wildcard in the network statement selects interfaces. It is not a subnet mask.
Point-to-point
No DR or BDR. Use this on a WAN link between two routers.
Broadcast DR
Highest priority wins, then the highest router ID. Priority 0 never becomes DR. The default priority is 1.
Cost
Reference bandwidth divided by interface bandwidth. The default reference is 100 Mbps, so Fast Ethernet and Gigabit Ethernet both cost 1 until you raise the reference.
IP services
Domain 4 is 10 percent. These are the services you turn on, not a second routing exam.
Services v1.1 asks you to configure, verify, or explain.
Service
What to remember
NAT
Inside local is the private address. Inside global is the public address the outside sees. Mark interfaces ip nat inside and ip nat outside. overload is PAT.
DHCP
Discover, offer, request, acknowledge. The server uses UDP 67 and the client uses UDP 68. A relay (ip helper-address) forwards the broadcast to a server on another subnet. v1.1 configures the client and the relay. v2.0 also troubleshoots a DHCP server on the router.
DNS
Turns a name into an address. An A record is IPv4. An AAAA record is IPv6. The router can point at a DNS server. It is not the public resolver for the Internet unless you built it to be.
NTP
A client points at a server. A lower stratum is closer to the reference clock. Time matters because logs and certificates depend on it.
SNMP
Queries use UDP 161. Traps use UDP 162. v2c uses a community string. v3 can authenticate and encrypt.
Syslog
0 emergency, 1 alert, 2 critical, 3 error, 4 warning, 5 notification, 6 informational, 7 debug. A lower number is more severe. A trap level of 4 sends 0 through 4.
SSH
Set a domain name, generate an RSA key, create a local user, and allow SSH on the VTY lines. Telnet is TCP 23 in clear text. SSH is TCP 22.
TFTP and FTP
TFTP is UDP 69 and has no login. FTP is TCP 21 and 20. Both move images and configurations. TFTP is the usual IOS copy method on this exam.
QoS
Classify, mark, queue, then either police (drop or remark) or shape (buffer). Policing does not store the extra traffic. Shaping does.
Security fundamentals
Domain 5 is 15 percent. Configure the control that matches the threat. Do not enable every feature on every port.
Security tasks on the v1.1 list.
Control
What it stops
Threats and exploits
A threat is the possible harm. A vulnerability is the weakness. An exploit is the method that uses the weakness. Mitigation is the control.
Local passwords
enable secret is hashed. enable password is weak. service password-encryption hides type 7 passwords and is not a strong hash. Prefer a local username with a secret.
AAA
Authentication is who you are. Authorization is what you may do. Accounting is the record of what you did. RADIUS and TACACS+ are the servers. RADIUS uses UDP. TACACS+ uses TCP and separates the three functions.
Standard ACL
Numbers 1 to 99 and 1300 to 1999. Filters the source only. Place it close to the destination.
Extended ACL
Numbers 100 to 199 and 2000 to 2699. Filters protocol, source, destination, and port. Place it close to the source. Every ACL ends with an implicit deny.
Port security
Limits MAC addresses on an access port. Sticky learns them into the running config. Shutdown is the default violation and error-disables the port. Restrict drops and counts. Protect drops quietly.
DHCP snooping
Trusted ports face the real DHCP server. Untrusted ports drop server messages, which stops a rogue DHCP server.
Dynamic ARP inspection
Checks ARP against the DHCP snooping table, so a host cannot claim someone else's IP.
WPA2 and WPA3
WPA2-Personal is a pre-shared key with AES-CCMP. WPA3-Personal uses SAE. The configuration task on v1.1 is WPA2 PSK in the WLAN GUI.
IPsec VPN
Site-to-site joins two networks. Remote access joins one user. v1.1 asks you to describe them, not to build a full tunnel lab.
Automation and programmability
Domain 6 is 10 percent. Explain the architecture. You are not asked to write a production playbook.
Automation ideas on the v1.1 list. Chef and Puppet were removed from this version.
Idea
Meaning
Traditional versus controller
Traditional management logs into each device. A controller holds intent and pushes it, so one change does not mean fifty CLI sessions.
Underlay and overlay
The underlay is the routed network that provides reachability. The overlay is the tunnel, such as VXLAN, built on top. The fabric is both working together.
Control and data plane
The control plane decides. The data plane forwards. A controller centralizes the decision.
Northbound and southbound
Northbound faces the application, often REST. Southbound faces the devices.
REST
GET reads, POST creates, PUT replaces, PATCH changes part of a resource, and DELETE removes it. The API is stateless. Authenticate with a token rather than pasting a password into the URL.
JSON
Objects, arrays, strings, numbers, true, false, and null. Keys are strings. There are no comments and no trailing commas.
Ansible
Agentless. It pushes YAML playbooks over SSH. You describe the tasks.
Terraform
Declarative infrastructure as code. It stores state and converges the devices to that state. v1.1 names it. v2.0 drops Terraform from the topic list and keeps Ansible.
AI on v1.1
Generative AI creates text or a config draft. Predictive AI estimates what happens next. Machine learning finds a pattern in data. You still verify the result before you apply it.
Chef and Puppet Extra
Not on the v1.1 list. Do not pick them as the current configuration-management answer.
Frequently asked questions
Are these notes the official Cisco exam topics?
No. They are an original summary of the public 200-301 v1.1 exam topics. Confirm the current PDF with Cisco before you book.
What do the Extra and v2.0 tags mean?
Extra marks a useful idea the v1.1 topic list does not name, such as Chef and Puppet. v2.0 marks an idea that belongs to the blueprint that opens on February 3, 2027. Learn the unmarked items first if you test on v1.1.
Which route does a Cisco router prefer?
The longest matching prefix wins. If two sources offer that same prefix, the lower administrative distance wins. Metric is compared only inside one routing protocol.
NodnWebTools provides general informational, educational, and convenience resources. Calculations, conversions, estimates, and learning materials may contain errors or become outdated. Financial, tax, medical, legal, and travel information is not professional advice. Verify important results and current requirements with qualified professionals or authoritative sources. Protect sensitive files and personal information, review each tool’s privacy limitations, and use only content you are authorized to process. You are responsible for how you use and share results. Study resources are independent and do not guarantee exam success or imply certification-provider endorsement. Cisco, CCNA, and Cisco IOS are trademarks of Cisco Systems, Inc. NodnWebTools is not affiliated with, endorsed by, or sponsored by Cisco.