Study guide · Core notes

Network+ Core Notes for N10-009

Reference notes for the facts Network+ questions depend on: layers, ports, addresses, routes, VLANs, wireless, services, and the order of a troubleshooting step.

Exam: N10-009Objectives version 4.0Reviewed October 2026

How to read these notes: Items tagged Extra sit outside the N10-009 objective bullets, such as implicit SMTPS on port 465. Learn the unmarked items first. New to the exam? Start with the overview for the format, the 720 passing score, and how retired N10-008 differs. Port numbers that also appear on A+ match the CompTIA A+ port table.

OSI layers and appliances

Domain 1 starts here. Name the layer before you name the product.

OSI reference model as listed for N10-009. PDU names are the usual study labels.
LayerNameWhat it decides
7ApplicationThe service a person or program uses, such as HTTP, DNS, or SMTP.
6PresentationFormat, encryption, and compression of the payload.
5SessionStarting, keeping, and ending a dialogue between applications.
4TransportTCP or UDP, and the port that identifies the service.
3NetworkIP addressing and routing between networks. Routers live here.
2Data linkMAC addresses and frames. Switches live here.
1PhysicalCables, radio, connectors, and signaling. A break here stops every higher layer.
Appliances and functions on the N10-009 list. Pick the device by the decision it makes.
DeviceDecision it makes
RouterForwards packets between IP networks. The default gateway is a router interface on the host's subnet.
SwitchForwards a frame to the port that learned the destination MAC. Unknown unicasts are flooded.
FirewallAllows or blocks by rule. It is not a substitute for a correct route.
IDS and IPSAn IDS detects and alerts. An IPS can block because it sits in the path. A tap copies traffic without sitting inline.
Load balancerSpreads clients across servers. A VIP is the address clients use.
ProxyMakes the request on the client's behalf. It can cache, filter, or hide the client.
NAS and SANNAS shares files. A SAN presents block storage, often over Fibre Channel.
Access pointBridges wireless clients onto the wired LAN. A controller manages lightweight APs.
CDNServes cached content from a location near the user.
QoS and TTLQoS prefers some traffic when the link is busy. TTL is a hop limit. Each router decrements it, and the packet dies at zero.

Traffic types: Unicast is one receiver. Broadcast is every host on the local subnet. Multicast is a subscribed group. Anycast is one address shared by several nodes, and the network delivers to the nearest.

Ports and protocols

These numbers are the N10-009 port table. Transport notes match the A+ table where the ports overlap.

N10-009 ports. "Encrypted" describes the protocol's usual behavior, not a second column in the CompTIA table.
PortProtocolTransportPurpose
20, 21FTPTCPFile transfer. 21 is control and 20 is data. Not encrypted. SFTP is SSH on 22, not FTP.
22SSH, SFTPTCPEncrypted remote shell and file transfer over SSH.
23TelnetTCPRemote shell in clear text. Replace it with SSH.
25SMTPTCPSending and relaying email.
53DNSUDP and TCPNames to addresses. TCP is used for large responses and zone transfers.
67, 68DHCPUDP67 is the server and 68 is the client.
69TFTPUDPSimple file transfer without authentication, often for firmware or network boot.
80HTTPTCPWeb traffic without TLS.
123NTPUDPClock sync. Drift breaks certificates and authentication tickets.
161, 162SNMPUDP161 is queries. 162 is traps. Only SNMPv3 authenticates and encrypts.
389LDAPTCPDirectory queries. LDAPS is 636.
443HTTPSTCPWeb traffic protected by TLS.
445SMBTCPWindows file and printer sharing.
514SyslogUDPSends events to a collector. A SIEM then correlates those logs.
587SMTPSTCPThe N10-009 table pairs SMTPS with 587, the submission port used with TLS.
636LDAPSTCPLDAP protected by TLS.
1433SQL ServerTCPMicrosoft SQL Server.
3389RDPTCPGraphical remote desktop.
5060, 5061SIPUDP and TCPCall signaling. 5061 is the TLS port.
465Implicit SMTPS ExtraTCPNot the number printed in the N10-009 port table. Learn 587 for this exam.

IP protocol types

  • ICMP is the error and query protocol ping uses. It is not a port.
  • TCP handshakes, acknowledges, and retransmits.
  • UDP sends without a session. Loss is acceptable or handled by the application.
  • GRE encapsulates one packet inside another, often for a simple tunnel.
  • IPsec uses IKE to negotiate, AH to authenticate, and ESP to encrypt. ESP is the one that hides the payload.

Which side is encrypted

SSH, HTTPS, LDAPS, and SNMPv3 protect the session. FTP, Telnet, TFTP, and SNMPv2c community strings do not. SMTP on 25 can upgrade with STARTTLS, but the N10-009 secure mail port to remember is 587.

IPv4 addressing

Private ranges, APIPA, and host counts show up in both concept questions and troubleshooting scenes.

IPv4 classes and the special ranges N10-009 names. Usable hosts are addresses minus network and broadcast.
RangeWhat it is
Class A, 0–127Default mask /8. Private block is 10.0.0.0/8. 127.0.0.0/8 is loopback, not a LAN.
Class B, 128–191Default mask /16. Private block is 172.16.0.0/12, which ends at 172.31.255.255. 172.32.0.1 is public.
Class C, 192–223Default mask /24. Private block is 192.168.0.0/16.
Class D, 224–239Multicast. Not assigned to a host interface as a unicast address.
Class E, 240–255Reserved for experiments. Not used on a normal LAN.
APIPA169.254.0.0/16. The host assigned it because DHCP did not answer.
RFC 1918The three private blocks above. They are not routed on the public internet.
Subnet sizes to memorize. VLSM means different masks inside one network. CIDR is the /prefix way of writing the mask.
PrefixMaskAddressesUsable hosts
/24255.255.255.0256254
/25255.255.255.128128126
/26255.255.255.1926462
/27255.255.255.2243230
/28255.255.255.2401614
/29255.255.255.24886
/30255.255.255.25242

Wrong mask versus wrong gateway: A wrong mask makes a host treat a remote address as local, or a local address as remote. A wrong gateway still reaches the local subnet and fails everywhere else. A duplicate address makes ARP flip between two MAC addresses.

Media, connectors, and topologies

Match the connector to the cable, and the topology to the traffic pattern.

Transmission media and connectors named in N10-009.
ItemWhat to remember
Single-mode fiberSmall core, laser, long distance. Do not mix it with multimode optics.
Multimode fiberLarger core, shorter runs, LED or VCSEL. Cheaper optics, less distance.
DAC / twinaxShort copper cable with transceivers built in, used inside a rack.
Plenum cableRequired in air-handling spaces. It makes less toxic smoke than ordinary PVC.
LC, SC, ST, MPOLC is the small latch. SC is the square push connector. ST is the bayonet. MPO carries many fibers.
RJ45 and RJ11RJ45 is Ethernet. RJ11 is a phone connector and does not belong in a switch.
F-type and BNCCoaxial connectors. F-type is the threaded video connector. BNC is the bayonet.
SFP and QSFPSFP is one lane in a small cage. QSFP is four lanes. Match the optic to the port and the fiber.

Topologies

  • Star / hub-and-spoke puts one center between the edges.
  • Mesh gives many paths. Partial mesh connects some, not all.
  • Point-to-point is two nodes.
  • Spine and leaf connects every leaf to every spine so east-west traffic does not climb a core.
  • Three-tier is core, distribution, and access. A collapsed core merges core and distribution.

Traffic direction

North-south is traffic entering or leaving the data center. East-west is server to server inside it. Spine-leaf and VXLAN exist because east-west grew.

Cloud and modern networks

N10-009 added these use cases. They also appear, with different depth, in the networking and cloud notes.

Cloud and software-defined ideas on the N10-009 list.
IdeaThe distinction
IaaS, PaaS, SaaSIaaS gives you the machines and you manage the OS. PaaS gives you the platform and you manage the app. SaaS gives you the finished application.
Public, private, hybridPublic is the provider's shared cloud. Private is for one organization. Hybrid joins both.
VPC and gatewaysA VPC is your isolated network in the cloud. An internet gateway allows public reachability. A NAT gateway lets private instances go out without accepting inbound connections.
Security groups and listsRules that allow or deny traffic to cloud resources. They are not a substitute for a host firewall.
NFVA firewall, router, or load balancer running as software instead of a fixed appliance.
Elasticity and scalabilityElasticity grows and shrinks with demand. Scalability is the ability to grow. Multitenancy means customers share the provider's infrastructure.
SDN and SD-WANSDN separates the control decision from forwarding. SD-WAN is application aware, transport agnostic, centrally policed, and can provision a site with little hands-on work.
VXLANCarries a layer 2 segment across a layer 3 network. The identifier is much larger than a 12-bit VLAN ID. Used for data-center interconnect.
Zero trust and SASE/SSEZero trust authenticates and authorizes each request and keeps least privilege. SASE and SSE deliver security services from the edge rather than from one office firewall.
Infrastructure as codePlaybooks and templates build the network. Version control shows who changed what. Drift is a device that no longer matches the template.
IPv6 transitionDual stack runs both. Tunneling carries IPv6 inside IPv4. NAT64 lets IPv6 clients reach IPv4 servers. Link-local addresses start with fe80::. Loopback is ::1.

Routing

Domain 2. The router picks a path in a fixed order. Learn that order before the protocol names.

  1. Longest prefix. 10.1.1.0/24 beats 10.1.0.0/16 for 10.1.1.10, even if the /16 comes from a more trusted source.
  2. Administrative distance. When two sources offer the same prefix, the lower distance wins. Connected is 0, static is 1, external BGP is 20, internal EIGRP is 90, OSPF is 110, and RIP is 120. A vendor can publish different numbers. RIP is on the N10-009 acronym list. The dynamic-routing bullets name BGP, EIGRP, and OSPF.
  3. Metric. Inside one protocol, the lower metric wins. OSPF uses cost from bandwidth. EIGRP uses a composite metric. BGP prefers attributes such as a shorter AS path.
Routing technologies named for N10-009.
TechnologyRole
Static routeYou type the next hop. It does not discover a failure unless you add a tracking feature.
OSPFLink-state protocol inside an autonomous system. Every router in an area builds the same map.
EIGRPAdvanced distance-vector protocol. Fast local decisions. Historically Cisco.
BGPPath-vector protocol between autonomous systems. The internet's exterior protocol.
NATTranslates one address to another, often one private host to one public address.
PATTranslates addresses and ports so many private hosts share one public address.
FHRP and VIPTwo routers share a virtual IP. If the active router fails, the standby owns the VIP. Hosts keep the same gateway.
SubinterfaceOne physical port split into logical ports, one per VLAN. This is router-on-a-stick.

Switching

VLANs separate broadcast domains. Spanning tree stops a loop from flooding the LAN.

Switch features on the N10-009 implementation list.
FeatureWhat it does
VLANA logical LAN on one switch or across trunks. Hosts in different VLANs need a router or a layer 3 switch to talk.
802.1QInserts a VLAN tag. The native VLAN is sent untagged. Both ends must agree on it.
Voice VLANA VLAN for phones, often advertised so the phone tags its traffic and the PC stays on the data VLAN.
SVIA virtual interface for a VLAN on a multilayer switch. It is the gateway for that VLAN.
Link aggregationSeveral physical links act as one. LACP is the standard negotiation. All member links need matching speed and VLAN settings.
Spanning treeBlocks redundant links so frames cannot circle. The lowest bridge ID becomes root. A port moves through listening and learning before forwarding. RSTP uses discarding, learning, and forwarding.
Speed and duplexBoth ends must match. A duplex mismatch produces late collisions and CRC errors. Autonegotiation on one side and a forced setting on the other is a common cause.
MTU and jumbo framesThe largest frame the path accepts. A jumbo frame that hits a smaller MTU is dropped. Every hop must agree.

Wireless

Band, channel, and encryption are three different settings. Speeds match the A+ wireless table.

802.11 generations. Speeds are theoretical maximums.
StandardBandMax rateWhat to remember
802.11a5 GHz54 MbpsLegacy. Less interference than 2.4 GHz, shorter range.
802.11b2.4 GHz11 MbpsLegacy. Microwaves and Bluetooth overlap this band.
802.11g2.4 GHz54 MbpsBackward-compatible with 802.11b.
802.11n (Wi-Fi 4)2.4 and 5 GHz600 MbpsMIMO and channel bonding.
802.11ac (Wi-Fi 5)5 GHzabout 6.9 GbpsDownlink MU-MIMO and beamforming.
802.11ax (Wi-Fi 6 / 6E)2.4, 5, and 6 GHzabout 9.6 Gbps6 GHz is Wi-Fi 6E. OFDMA helps dense networks. 6 GHz requires WPA3.
802.11be (Wi-Fi 7) Extra2.4, 5, and 6 GHzabout 46 GbpsNot named in the N10-009 bullets. 320 MHz channels and multi-link operation.

Channels and names

  • In the 2.4 GHz band, channels 1, 6, and 11 do not overlap.
  • Wider channels raise speed and reduce how many fit. 802.11h covers radar avoidance and transmit power on 5 GHz.
  • Band steering pushes a capable client to 5 GHz or 6 GHz.
  • The SSID is the name. The BSSID is the AP radio's MAC. The ESSID is the same name across APs so clients can roam.

Security and AP type

  • WPA2-Personal uses a pre-shared key. WPA2-Enterprise uses 802.1X.
  • WPA3 replaces the PSK handshake with SAE. Use it. 6 GHz requires it.
  • An autonomous AP is configured alone. A lightweight AP takes its config from a controller.
  • Infrastructure mode uses an AP. Ad hoc is client to client. A guest SSID with a captive portal should not share the internal VLAN.
  • Omnidirectional antennas cover a floor. Directional antennas aim a link.

Physical installation

The MDF is the main room where outside circuits and the core land. An IDF is a closer closet that feeds a floor. Racks have a stated size, and the hot exhaust must not blow into the next rack's intake. Patch panels and fiber panels are the permanent side. The fly lead is the replaceable side. Lock the room.

A UPS rides through a short outage and lets you shut down cleanly. A PDU distributes power in the rack. It does not add runtime. Fire suppression, temperature, and humidity are part of keeping the gear inside its rating. PoE power comes later, under troubleshooting, when the budget or the standard is wrong.

Operations and network services

Domain 3. Document what you built, watch it, and know how you will recover it.

Records, addressing services, and recovery terms.
TermMeaning
A and AAAAA is an IPv4 address. AAAA is an IPv6 address.
CNAME, MX, TXT, NS, PTRCNAME is an alias. MX is mail. TXT is arbitrary text. NS delegates the zone. PTR is the reverse lookup.
Authoritative and recursiveAuthoritative holds the zone. Recursive asks other servers for the client.
Primary and secondaryThe primary is the writable copy. The secondary transfers a copy.
DHCP scopeThe pool, the lease time, the options such as gateway and DNS, the exclusions, and the reservations that pin a MAC to an address.
DHCP relayForwards the client's broadcast to a server on another subnet. Without it, the server never hears the request.
SLAACAn IPv6 host builds an address from the router's advertisement. No DHCP server is required.
DNSSEC, DoH, DoTDNSSEC signs the records. DoH and DoT encrypt the query. Signing and encrypting solve different problems.
NTP, PTP, NTSNTP is the usual clock. PTP is for tighter timing. NTS protects NTP.
RPO and RTORPO is how much data you can lose. RTO is how long you can be down. MTTR is average repair time. MTBF is average time between failures.
Hot, warm, coldHot can take over quickly. Warm has some equipment. Cold is mostly space.
Active-active and active-passiveBoth sides serve traffic, or one waits. A tabletop exercise talks through the plan. A validation test actually fails something over.

VPN and management

  • Site-to-site joins two networks. Client-to-site joins one user.
  • Full tunnel sends all traffic into the VPN. Split tunnel sends only the networks you list.
  • Clientless access is a browser session, not an installed client.
  • A jump box is the hardened host you enter before anything internal.
  • In-band management uses the production network. Out-of-band uses a console or a separate network, which still works when production does not.

Monitoring

  • SNMPv2c uses a community string in clear text. SNMPv3 adds authentication and encryption. Traps are unsolicited alerts. The MIB names the objects you can read.
  • Flow data summarizes who talked to whom. A packet capture shows the bytes. Port mirroring copies a port to a sensor.
  • A baseline is the normal. An alert without a baseline is a guess. A golden configuration is the known-good template.
  • EOL means the vendor stopped selling it. EOS means they stopped patching it.

Network security

Domain 4 is 14 percent. Name the attack by the table it poisons or the service it impersonates.

Attacks and defenses a network technician is expected to separate.
TermMeaning
CIAConfidentiality is who can read it. Integrity is whether it changed. Availability is whether people can use it.
RADIUS and TACACS+RADIUS uses UDP and combines authentication and authorization. TACACS+ uses TCP and separates them, and it encrypts the whole packet. Both can back 802.1X. SAML carries a sign-in assertion for web SSO.
802.1X and port security802.1X authenticates the user or device before the port forwards. Port security limits MAC addresses. MAC filtering is a list, and an attacker can spoof an allowed MAC.
MAC floodingFills the CAM table so the switch floods frames out every port.
ARP poisoningFalse ARP replies so traffic for a victim goes to the attacker. That is an on-path attack.
DNS poisoningA name resolves to the attacker's address. DNSSEC is the control aimed at forged records.
VLAN hoppingReaches another VLAN by double-tagging or by pretending to be a trunk. Do not leave the native VLAN as a VLAN that users use.
Rogue DHCP and evil twinA rogue DHCP server hands out its own gateway. An evil twin is an AP using a trusted SSID.
DoS and DDoSOne source, or many. The symptom is availability.
Screened subnetA segment that faces untrusted networks. Internal systems stay behind it. An ACL or security rule enforces the boundary.
HardeningDisable unused ports and services. Change default passwords. A honeypot is one decoy. A honeynet is a decoy network.

Segmentation: IoT, OT, SCADA, guest wireless, and BYOD do not belong on the same VLAN as payroll. Geofencing limits an action to a place. Least privilege and role-based access limit it to a job.

Troubleshooting

Domain 5 is 24 percent of the exam. The method is ordered. The tool has to match the layer.

  1. Identify the problem. Ask the user, note symptoms, ask what changed, and duplicate it if you can. Handle one problem at a time.
  2. Establish a theory. Question the obvious. Walk the OSI model from the bottom or the top, or split the path in half.
  3. Test the theory. If it holds, plan the fix. If it does not, make a new theory or escalate.
  4. Plan the action and the side effects.
  5. Implement or escalate.
  6. Verify full function and add a preventive step if one fits.
  7. Document findings, actions, and what you learned. Documentation is last, not a substitute for the test.
Symptoms and the tool or command that answers them.
Symptom or questionWhat to use
Can this host answer at all?ping. It uses ICMP. A filter can block ping while the service still works.
Where does the path stop?traceroute or tracert. Each hop should answer.
What address did the name return?nslookup or dig. A hosts-file entry can override DNS.
What address does this host have?ipconfig, ifconfig, or ip. Look for 169.254 and the mask.
Which MAC owns this IP on the LAN?arp on the host, or show arp on the router. Two MACs for one IP means a duplicate.
Which port learned this MAC?show mac-address-table. This is the switch CAM, not the routing table.
Which route will be used?show route. Check the prefix length before the protocol name.
Why is the interface dropping frames?show interface. CRC, runts, and giants point at the cable or the MTU. Late collisions point at duplex. Drops point at congestion.
Is the port in the right VLAN?show vlan. A wrong VLAN looks like a dead network even when the link light is up.
Why did the phone not power on?show power. The budget may be spent, or the standard may be too weak for the device.
Which cable is this?A toner traces the pair. A cable tester checks the wiremap. A visual fault locator shines down a fiber. A Wi-Fi analyzer shows channel overlap, not a copper fault.
What is on the wire?tcpdump or a protocol analyzer, fed by a tap or a mirror port. nmap discovers hosts and ports. LLDP and CDP show the neighbor.

Interface states

  • Administratively down means someone shut the port.
  • Error-disabled means the switch shut it after a violation, such as port security or a BPDU on an edge port. You clear the cause, then reset the port.
  • Suspended often means a link-aggregation member disagrees with the bundle.

Wireless faults

Channel overlap on 2.4 GHz looks like slow clients, not a dead cable. A coverage hole looks like disassociations at the edge of the floor. Roaming fails when the ESSID, security, or VLAN differs between APs. TX and RX reversed on a fiber jumper lights one side and not the other.

Frequently asked questions

Are these notes the official CompTIA objectives?

No. They are an original summary of the public N10-009 objectives, version 4.0. Confirm the current PDF with CompTIA before you book.

What does the Extra tag mean?

Extra marks a useful idea the N10-009 objective bullets do not name, such as port 465. Learn the unmarked items first.

Which troubleshooting steps does N10-009 list?

Identify the problem, establish a theory, test the theory, plan the fix, implement or escalate, verify and prevent, then document. Do not swap hardware before you identify the problem.

Continue the Network+ study path

Turn the tables into recall, then test them.

Network+ hub →
Available

Overview

Exam format, the 720 passing score, five domain weights, and the N10-008 comparison.

Available · You are here

Core Notes

Reference notes for layers, ports, routing, switching, wireless, services, and troubleshooting.

Available

Flashcards & Memory Notes

40 recall cards in four decks, plus memory notes for ports, masks, and the troubleshooting order.

Available

Practice Exams

200 original questions with custom exams, explanations, and an unofficial score on the 100-900 scale.

Related Tools

Useful companions while you study.

All study topics →