Study guide · Flashcards & memory notes

CCNA Flashcards & Memory Notes

40 recall cards for the facts CCNA 200-301 v1.1 keeps asking you to separate: masks and address types, VLANs and spanning tree, routes and services, and security and automation.

Exam: 200-301 v1.14 decks · 40 cardsNo sign-up required

How to use these cards: Say the answer out loud before you flip the card, and mark it honestly. Revisit the cards you missed tomorrow rather than rereading them right away. Progress is kept only while this page is open. For the full explanations behind each card, see the core notes.

Study mode

Choose a deck, flip each card, and mark what you already know.

All flashcards

Select a question to reveal its answer.

Deck 1 · Addresses and devices

Masks, private ranges, IPv6 types, and what each device decides.

10 cards
1.1How many usable hosts are in a /27?

30. A /27 has 32 addresses. Subtract the network and broadcast addresses.

1.2Which private block contains 172.20.1.1?

172.16.0.0/12. That block runs through 172.31.255.255. 172.32.0.1 is public.

1.3What does 169.254.5.5 on a Windows host mean?

DHCP did not answer. It is an automatic address, not a private range you assigned.

1.4What is the wildcard mask for a /26?

0.0.0.63. It is the inverse of 255.255.255.192. OSPF and ACLs use the wildcard, not the subnet mask.

1.5Which IPv6 prefix is link-local?

fe80::/10. Global unicast is 2000::/3. Unique local addresses in practice start with fd.

1.6What does modified EUI-64 insert into a MAC address?

fffe in the middle, and it inverts the U/L bit. 00:11:22:33:44:55 becomes 0211:22ff:fe33:4455.

1.7How does a Layer 2 switch differ from a router?

The switch forwards by MAC address. The router forwards by IP network. A Layer 3 switch can do both.

1.8How do a virtual machine, a container, and a VRF differ?

A VM has a guest OS. A container shares the host kernel. A VRF is another routing table on one router.

1.9Which 2.4 GHz channels do not overlap?

1, 6, and 11. The SSID is the name of the wireless network, not a channel.

1.10What does a duplex mismatch usually show?

Late collisions, with the link still up. A speed mismatch is more likely to leave the link down.

Deck 2 · VLANs and spanning tree

Trunks, the native VLAN, and which port is allowed to forward.

10 cards
2.1What does 802.1Q add, and which VLAN stays untagged?

A VLAN tag. The native VLAN is untagged. Both ends of the trunk must use the same native VLAN.

2.2Which VLAN range is the normal range, and which VLAN is the default?

1 to 1005 is normal. VLAN 1 is the default. An access port carries one data VLAN untagged.

2.3How does a router-on-a-stick route between VLANs?

Subinterfaces, each with encapsulation dot1Q for one VLAN. A Layer 3 switch uses an SVI and ip routing instead.

2.4Which LACP modes form an EtherChannel?

Active with active, or active with passive. Passive with passive does not. Speed, duplex, and the VLAN list must match.

2.5How does the root bridge get elected?

The lowest bridge ID wins. The ID is priority plus MAC. The default priority is 32768.

2.6What is a root port?

The port on this switch with the best path to the root bridge. The designated port is the forwarding port for a segment.

2.7Where do PortFast and BPDU Guard belong?

On an edge port facing a PC, not on a link to another switch. BPDU Guard error-disables the port if a BPDU arrives.

2.8How do Root Guard and Loop Guard differ?

Root Guard blocks a port that receives a superior BPDU. Loop Guard keeps a port discarding if expected BPDUs stop.

2.9How do CDP and LLDP differ?

Both discover a Layer 2 neighbor. CDP is Cisco. LLDP is multi-vendor. Neither chooses an IP route.

2.10How does a lightweight AP differ from an autonomous AP?

A lightweight AP takes its configuration from a WLC. An autonomous AP is configured on its own. FlexConnect can switch locally at a branch.

Deck 3 · Routing and services

Administrative distance, OSPF, NAT, and the log level.

10 cards
3.1Which check wins when two prefixes both match a packet?

The longest prefix. Administrative distance is used only when the prefixes are the same length.

3.2What are the administrative distances of connected, static, and OSPF?

0, 1, and 110. A lower number is more trusted. RIP is 120 and is not a protocol v1.1 asks you to configure.

3.3What makes a static route floating?

An administrative distance worse than the primary protocol. OSPF at 110 stays installed, and a static route at 130 is the backup.

3.4How does OSPF choose a router ID?

The manual ID, else the highest loopback, else the highest active interface. It must be unique. It does not have to be reachable.

3.5When does OSPF elect a DR?

On a broadcast network, not on a point-to-point link. Highest priority wins, then the highest router ID. Priority 0 never becomes DR.

3.6What is inside global in NAT?

The public address the outside network sees. Inside local is the private address. Overload means PAT, which also translates ports.

3.7What does ip helper-address do?

It relays a client's DHCP broadcast to a server on another subnet. The server listens on UDP 67. The client uses UDP 68.

3.8Which syslog number is more severe, 3 or 6?

3, which is error. 6 is informational. A lower number is more severe. 0 is emergency and 7 is debug.

3.9How do policing and shaping differ?

Policing drops or remarks extra traffic. Shaping buffers it. Both come after classification and marking.

3.10What is the virtual IP in a first-hop redundancy protocol?

The gateway address hosts keep using if the active router fails. Another router takes over that address.

Deck 4 · Security and automation

ACLs, Layer 2 controls, WPA2, and the API direction.

10 cards
4.1How does a standard ACL differ from an extended ACL?

A standard ACL filters the source only. An extended ACL can filter protocol, source, destination, and port. Both end with an implicit deny.

4.2Where should each ACL sit?

A standard ACL close to the destination. An extended ACL close to the source. That keeps a standard list from blocking too early.

4.3What is the default port-security violation?

Shutdown, which error-disables the port. Restrict drops and counts. Protect drops without a count.

4.4What does DHCP snooping trust?

The port that faces the real DHCP server. Server messages on an untrusted port are dropped, which stops a rogue server.

4.5How do authentication, authorization, and accounting differ?

Authentication is who you are. Authorization is what you may do. Accounting is the record. TACACS+ separates them and uses TCP.

4.6Which WLAN security does v1.1 ask you to configure in the GUI?

WPA2 with a pre-shared key. WPA3-Personal uses SAE. WPA2 uses AES-CCMP.

4.7Which REST verb reads, and which verb replaces a whole resource?

GET reads. PUT replaces. POST creates, PATCH changes part of a resource, and DELETE removes it.

4.8Which API faces the application, and which faces the devices?

Northbound faces the application. Southbound faces the devices. The underlay is the routed reachability. The overlay is the tunnel on top.

4.9How do Ansible and Terraform differ on the v1.1 list?

Ansible pushes playbooks over SSH and has no agent. Terraform declares a desired state. Chef and Puppet are not on the v1.1 list.

4.10How do generative AI and predictive AI differ?

Generative AI creates new text or a draft. Predictive AI estimates what happens next. You still verify the result before you apply it.

Memory notes

Groupings that make the highest-yield CCNA facts easier to recall.

Masks

/24 has 254 hosts, /25 has 126, /26 has 62, /27 has 30, /28 has 14, /29 has 6, and /30 has 2. Subtract two from the address count.

Distances

Connected 0, static 1, OSPF 110. Longest prefix first. A floating static uses a worse distance, such as 130, so it waits.

Syslog

0 emergency, 1 alert, 2 critical, 3 error, 4 warning, 5 notification, 6 informational, 7 debug. Lower is more severe.

STP edge

Lowest bridge ID is root. PortFast and BPDU Guard face the PC. Root Guard protects the root you chose. Loop Guard stays discarding if BPDUs stop.

ACL numbers

Standard is 1–99 and 1300–1999, source only, near the destination. Extended is 100–199 and 2000–2699, near the source. Implicit deny is last.

IPv6 and REST

Global 2000::/3, link-local fe80::/10, multicast ff00::/8. GET, POST, PUT, PATCH, DELETE. Northbound faces the app. Southbound faces the devices.

Continue the CCNA study path

Test what you have learned with a timed practice exam.

CCNA hub →
Available

Overview

Exam format, pass/fail scoring, six domain weights, and the February 2027 v2.0 change.

Available

Core Notes

Reference notes for addresses, VLANs, spanning tree, OSPF, services, security, and automation.

Available · You are here

Flashcards & Memory Notes

40 recall cards in four decks, plus memory notes for masks, administrative distance, and syslog.

Available

Practice Exams

200 original questions with custom exams, explanations, and an unofficial percentage.

Related Tools

Useful companions while you study.

All study topics →