Masks
/24 has 254 hosts, /25 has 126, /26 has 62, /27 has 30, /28 has 14, /29 has 6, and /30 has 2. Subtract two from the address count.
Study guide · Flashcards & memory notes
40 recall cards for the facts CCNA 200-301 v1.1 keeps asking you to separate: masks and address types, VLANs and spanning tree, routes and services, and security and automation.
How to use these cards: Say the answer out loud before you flip the card, and mark it honestly. Revisit the cards you missed tomorrow rather than rereading them right away. Progress is kept only while this page is open. For the full explanations behind each card, see the core notes.
Choose a deck, flip each card, and mark what you already know.
You marked every card in this deck as known. Shuffle and run through it again, or choose another deck.
Select a question to reveal its answer.
Masks, private ranges, IPv6 types, and what each device decides.
30. A /27 has 32 addresses. Subtract the network and broadcast addresses.
172.16.0.0/12. That block runs through 172.31.255.255. 172.32.0.1 is public.
DHCP did not answer. It is an automatic address, not a private range you assigned.
0.0.0.63. It is the inverse of 255.255.255.192. OSPF and ACLs use the wildcard, not the subnet mask.
fe80::/10. Global unicast is 2000::/3. Unique local addresses in practice start with fd.
fffe in the middle, and it inverts the U/L bit. 00:11:22:33:44:55 becomes 0211:22ff:fe33:4455.
The switch forwards by MAC address. The router forwards by IP network. A Layer 3 switch can do both.
A VM has a guest OS. A container shares the host kernel. A VRF is another routing table on one router.
1, 6, and 11. The SSID is the name of the wireless network, not a channel.
Late collisions, with the link still up. A speed mismatch is more likely to leave the link down.
Trunks, the native VLAN, and which port is allowed to forward.
A VLAN tag. The native VLAN is untagged. Both ends of the trunk must use the same native VLAN.
1 to 1005 is normal. VLAN 1 is the default. An access port carries one data VLAN untagged.
Subinterfaces, each with encapsulation dot1Q for one VLAN. A Layer 3 switch uses an SVI and ip routing instead.
Active with active, or active with passive. Passive with passive does not. Speed, duplex, and the VLAN list must match.
The lowest bridge ID wins. The ID is priority plus MAC. The default priority is 32768.
The port on this switch with the best path to the root bridge. The designated port is the forwarding port for a segment.
On an edge port facing a PC, not on a link to another switch. BPDU Guard error-disables the port if a BPDU arrives.
Root Guard blocks a port that receives a superior BPDU. Loop Guard keeps a port discarding if expected BPDUs stop.
Both discover a Layer 2 neighbor. CDP is Cisco. LLDP is multi-vendor. Neither chooses an IP route.
A lightweight AP takes its configuration from a WLC. An autonomous AP is configured on its own. FlexConnect can switch locally at a branch.
Administrative distance, OSPF, NAT, and the log level.
The longest prefix. Administrative distance is used only when the prefixes are the same length.
0, 1, and 110. A lower number is more trusted. RIP is 120 and is not a protocol v1.1 asks you to configure.
An administrative distance worse than the primary protocol. OSPF at 110 stays installed, and a static route at 130 is the backup.
The manual ID, else the highest loopback, else the highest active interface. It must be unique. It does not have to be reachable.
On a broadcast network, not on a point-to-point link. Highest priority wins, then the highest router ID. Priority 0 never becomes DR.
The public address the outside network sees. Inside local is the private address. Overload means PAT, which also translates ports.
It relays a client's DHCP broadcast to a server on another subnet. The server listens on UDP 67. The client uses UDP 68.
3, which is error. 6 is informational. A lower number is more severe. 0 is emergency and 7 is debug.
Policing drops or remarks extra traffic. Shaping buffers it. Both come after classification and marking.
The gateway address hosts keep using if the active router fails. Another router takes over that address.
ACLs, Layer 2 controls, WPA2, and the API direction.
A standard ACL filters the source only. An extended ACL can filter protocol, source, destination, and port. Both end with an implicit deny.
A standard ACL close to the destination. An extended ACL close to the source. That keeps a standard list from blocking too early.
Shutdown, which error-disables the port. Restrict drops and counts. Protect drops without a count.
The port that faces the real DHCP server. Server messages on an untrusted port are dropped, which stops a rogue server.
Authentication is who you are. Authorization is what you may do. Accounting is the record. TACACS+ separates them and uses TCP.
WPA2 with a pre-shared key. WPA3-Personal uses SAE. WPA2 uses AES-CCMP.
GET reads. PUT replaces. POST creates, PATCH changes part of a resource, and DELETE removes it.
Northbound faces the application. Southbound faces the devices. The underlay is the routed reachability. The overlay is the tunnel on top.
Ansible pushes playbooks over SSH and has no agent. Terraform declares a desired state. Chef and Puppet are not on the v1.1 list.
Generative AI creates new text or a draft. Predictive AI estimates what happens next. You still verify the result before you apply it.
Groupings that make the highest-yield CCNA facts easier to recall.
/24 has 254 hosts, /25 has 126, /26 has 62, /27 has 30, /28 has 14, /29 has 6, and /30 has 2. Subtract two from the address count.
Connected 0, static 1, OSPF 110. Longest prefix first. A floating static uses a worse distance, such as 130, so it waits.
0 emergency, 1 alert, 2 critical, 3 error, 4 warning, 5 notification, 6 informational, 7 debug. Lower is more severe.
Lowest bridge ID is root. PortFast and BPDU Guard face the PC. Root Guard protects the root you chose. Loop Guard stays discarding if BPDUs stop.
Standard is 1–99 and 1300–1999, source only, near the destination. Extended is 100–199 and 2000–2699, near the source. Implicit deny is last.
Global 2000::/3, link-local fe80::/10, multicast ff00::/8. GET, POST, PUT, PATCH, DELETE. Northbound faces the app. Southbound faces the devices.
Test what you have learned with a timed practice exam.
Exam format, pass/fail scoring, six domain weights, and the February 2027 v2.0 change.
Reference notes for addresses, VLANs, spanning tree, OSPF, services, security, and automation.
40 recall cards in four decks, plus memory notes for masks, administrative distance, and syslog.
200 original questions with custom exams, explanations, and an unofficial percentage.
Useful companions while you study.
Calculate trigonometric functions, logarithms, powers, roots, factorials, and advanced expressions.
Convert structured data between JSON and YAML with formatting and validation.
Encode text and files to Base64 or decode Base64 data with UTF-8 support.
Generate strong random passwords with custom length, characters, symbols, and security options.
NodnWebTools provides general informational, educational, and convenience resources. Calculations, conversions, estimates, and learning materials may contain errors or become outdated. Financial, tax, medical, legal, and travel information is not professional advice. Verify important results and current requirements with qualified professionals or authoritative sources. Protect sensitive files and personal information, review each tool’s privacy limitations, and use only content you are authorized to process. You are responsible for how you use and share results. Study resources are independent and do not guarantee exam success or imply certification-provider endorsement. Cisco, CCNA, and Cisco IOS are trademarks of Cisco Systems, Inc. NodnWebTools is not affiliated with, endorsed by, or sponsored by Cisco.