certslothcertsloth
← N10-009 overview

Network+ / STUDY TOOLS

N10-009 quick review

Reviewed 10 October 2026 against the linked published scope. Domains: concepts 23%, implementation 20%, operations 19%, security 14%, troubleshooting 24%. Includes performance-based questions.

Memory hook: Cable → link → address → route → name → application.

Read the essentials, cover the answers and explain the decision aloud. Open the topic summaries below whenever a distinction is unclear.

Concepts, addressing and ports

  • OSI: physical bits, data-link frames/MACs, network packets/IPs, transport ports, session coordination, presentation representation and application protocols. A switch learns source MACs; a router forwards by destination IP.
  • TCP provides connection-oriented ordered delivery; UDP provides datagrams without that transport guarantee. Throughput is achieved work, bandwidth is capacity, latency is delay, jitter is delay variation and packet loss is missing traffic.
  • IPv4 private ranges: 10/8, 172.16/12, 192.168/16. APIPA is 169.254/16. IPv6 loopback is ::1, link-local fe80::/10, unique-local fc00::/7. IPv6 uses Neighbor Discovery, not ARP or broadcast.
  • Prefix first: a /26 has 64 addresses, conventionally 62 usable host addresses. For 192.168.10.77/26, network is .64 and broadcast .127. /31 point-to-point and /32 host routes are exceptions to subtracting two.
  • Recall ports by function: SSH/SFTP 22, DNS 53 TCP/UDP, DHCPv4 67/68 UDP, HTTP 80, HTTPS 443, NTP 123 UDP, SNMP 161/162 UDP, LDAP 389, LDAPS 636, SMB 445, RDP 3389. SMTP 25/587, IMAP 143/993 and POP3 110/995 distinguish mail transfer from retrieval and protected variants.
  • DNS: A/AAAA addresses, CNAME alias, MX mail, PTR reverse, TXT text and SRV service. DHCP DORA is discover, offer, request, acknowledge; a relay crosses routed boundaries. A lease or cached answer can outlast a server-side change.

Implementation

  • Access ports carry one client VLAN; trunks carry permitted VLANs with tagging rules. Inter-VLAN traffic needs routing. STP prevents Layer-2 loops; LACP negotiates aggregation, not arbitrary doubling of one flow's speed.
  • Route choice starts with longest matching prefix; compare routing-source preference and then protocol metrics for competing routes to the same prefix. A default route is least specific. NAT translates addressing; PAT also multiplexes ports.
  • 2.4 GHz travels farther but has fewer nonoverlapping channels; 5/6 GHz offer more spectrum with different reach/device requirements. Match channel width, interference, placement, roaming, encryption and authentication to the environment. WPA3 security does not compensate for a rogue AP.
  • Copper distance, fiber type/wavelength, transceiver compatibility, connector type, duplex and PoE budget all matter. Single-mode suits longer optical runs; multimode suits suitable shorter runs. Diagnose damaged/dirty fiber and mismatched optics before replacing a router.
  • Cloud networks still need routes, security rules, DNS and identity. VPN encryption, private connectivity, SD-WAN path selection and overlays solve different problems. Infrastructure as code and APIs help repeat changes, but must be reviewed and validated.

Operations, security and troubleshooting

  • Maintain diagrams, IP address management, configuration baselines, asset records, backups and change/rollback plans. Flow records describe communication; packet capture exposes packet details; logs and metrics supply complementary context.
  • Restrict management access, use AAA, secure protocols and least privilege. ACLs filter selected headers; stateful firewalls track connections; IDS detects while IPS can block. NAC evaluates endpoint admission; segmentation limits movement.
  • Diagnose systematically: establish symptoms and scope, form/test a theory, plan a fix with impact, implement or escalate, verify full operation and document. Compare a working client to a failing one.
  • Link up but no usable address suggests DHCP/VLAN problems. IP works but hostname fails suggests DNS. Same subnet works but remote fails suggests gateway/routes/filtering. Intermittent slowness needs utilization, error, retransmission and latency evidence.
  • Use ipconfig/ip, ping, traceroute/tracert, dig/nslookup, ss/netstat, cable testers and packet capture for the layer in question. ICMP failure alone does not prove a host is down.

Final active recall

1. Which route wins: a /24 learned dynamically or a static /0?

The matching /24: prefix length is considered before administrative distance.

2. What are the hosts in 192.168.10.64/26?

Conventionally .65 through .126; .64 is the network and .127 the broadcast.

3. A website works by IP but not name. First area to inspect?

DNS server settings, responses, cache and resolution path.

4. Does a VLAN encrypt traffic?

No. It creates logical Layer-2 separation; routing and policy govern communication between VLANs.

5. Why can a port-channel fail to accelerate one transfer?

Hashing commonly assigns a flow to one member link; aggregate capacity benefits multiple flows.

Sources and further practice

Every topic at a glance

Open any topic to revisit its essential facts, decisions and exam traps. Use the full topic for active recall and supporting references.

01 · Models, Packets and Network Devices

Memory hook: Name the layer, then name the job.

Must remember

OSI layer Remember
7 Application Protocols used by applications, such as HTTP and DNS.
6 Presentation Data representation, encoding and related transformation concepts.
5 Session Dialog/session coordination concepts.
4 Transport TCP/UDP, ports and end-to-end transport behavior.
3 Network IP addressing and routing between networks.
2 Data link Local frames, MAC addresses, switching and VLANs.
1 Physical Signals, media, connectors and bit transmission.

The TCP/IP model groups functions differently; real protocols do not always fit neatly into one textbook box. Encapsulation adds headers as data descends the stack. On a routed path, link-layer addresses change at each link; the IP destination normally remains the end host unless translation/tunneling changes it.

TCP establishes a connection, sequences bytes, acknowledges delivery and handles retransmission/flow control. UDP sends datagrams without those built-in guarantees; an application protocol can add its own reliability. TCP reliability does not mean a business transaction executed exactly once.

A switch learns source MAC addresses and forwards frames within its Layer 2 domain. A router selects next hops between IP networks. A multilayer switch can do both. Firewalls enforce traffic policy; proxies terminate/mediate connections; load balancers distribute service traffic. NAS provides file access, while a SAN commonly presents block storage over a storage network.

Unicast addresses one recipient; broadcast a local IPv4 broadcast domain; multicast a group; anycast the routing-selected instance of a shared address. IPv6 uses multicast rather than broadcast. Routers normally separate broadcast domains.

Star, mesh, hub-and-spoke, spine-leaf, three-tier and collapsed-core designs trade cost, fault paths and scale. A logical topology and a physical cabling diagram describe different views.

Choose under exam pressure

Requirement Choice and reason
Forward between IP subnets A routing function.
Share files with clients NAS/file service rather than raw block storage.
Reach a nearby service instance using the same address Anycast with appropriate routing.

Traps

  • A switch can implement several layers; identify the function being tested.
  • UDP is not automatically inappropriate for reliable applications.

Practise this topic

02 · IPv4, IPv6 and Subnetting

Memory hook: Prefix is the boundary; longest match wins.

Must remember

IPv4 has 32 bits. CIDR /n reserves n network bits, leaving 32-n host bits. A conventional IPv4 subnet has 2^(32-n) addresses and usually two reserved endpoints. /31 point-to-point and /32 host routes are exceptions to the usual minus-two rule.

Worked example: 192.168.10.77/26 has blocks of 64: network .64, broadcast .127, ordinary hosts .65–.126, 62 usable. Four /26 networks fit within a /24. For VLSM, allocate the largest required blocks first and check overlap.

Range Meaning
10.0.0.0/8, 172.16.0.0/12, 192.168.0.0/16 RFC1918 private addresses; not public Internet destinations.
169.254.0.0/16 IPv4 link-local/APIPA; often a DHCP failure clue.
127.0.0.0/8 IPv4 loopback.
224.0.0.0/4 IPv4 multicast.
::1 / :: IPv6 loopback / unspecified address.
fe80::/10 IPv6 link-local.
fc00::/7 IPv6 unique-local range.
ff00::/8 IPv6 multicast.

IPv6 uses 128 bits in hexadecimal groups. Remove leading zeros and compress one consecutive run of zero groups with ::; using it twice would make the address ambiguous. Many LAN subnets use /64, but do not assume every IPv6 prefix is /64.

ARP discovers IPv4 next-hop MAC addresses on a local link. IPv6 Neighbor Discovery uses ICMPv6; blocking all ICMPv6 can break normal operation. Router advertisements supply on-link/default-router information and can support SLAAC. DHCPv6 does not replace every router-advertisement function.

Historical class A/B/C boundaries are vocabulary; current route decisions use actual prefixes. Two hosts with mismatched masks can disagree about whether traffic is local. Verify address, prefix, gateway and duplicate-address evidence together.

Choose under exam pressure

Requirement Choice and reason
Need 50 ordinary IPv4 hosts A /26 provides 62 usable addresses.
Host has 169.254 address unexpectedly Investigate DHCP/link configuration.
IPv6 address works locally but not remotely Check router advertisements/default route and policy.

Traps

  • 172.16/12 covers 172.16 through 172.31, not all 172 addresses.
  • A default gateway must be reachable through the host’s local routing configuration.

Practise this topic

03 · Ports, DNS, DHCP and Time

Memory hook: Resolve the name, obtain the lease, trust the clock.

Must remember

Service Conventional port(s)
FTP / SSH-SFTP / Telnet TCP 21 control (FTP data varies) / 22 / 23.
SMTP / submission TCP 25 / 587; implicit TLS submission commonly 465.
DNS UDP and TCP 53.
DHCPv4 / DHCPv6 UDP 67 server, 68 client / 547 server, 546 client.
HTTP / HTTPS 80 / 443; HTTP/3 uses QUIC over UDP 443.
POP3 / IMAP TCP 110 / 143; implicit TLS 995 / 993.
SNMP queries / traps Usually UDP 161 / 162.
LDAP / LDAPS 389 / 636.
SMB / RDP TCP 445 / TCP and UDP 3389.
NTP / SIP UDP 123 / commonly 5060, TLS 5061.

Ports are conventions, not proof of application identity. Secure FTP (SFTP over SSH) differs from FTP with TLS (FTPS).

DNS A/AAAA map names to IPv4/IPv6; CNAME aliases another name; MX specifies mail exchangers; NS delegates authoritative service; PTR supports reverse lookup; TXT carries text used by policies and verification. A resolver asks authoritative servers and caches answers according to TTL. DNSSEC authenticates signed DNS data; it does not encrypt ordinary DNS queries. Encrypted DNS protects the resolver connection through its selected protocol.

DHCPv4 commonly follows Discover, Offer, Request, Acknowledge. Scopes define pools, options, exclusions and reservations. A relay forwards requests across routed boundaries. Exhausted pools, rogue servers, wrong options and blocked relay paths produce different symptoms. Reservations provide predictable leases, not static manual configuration on the host.

NTP synchronizes time broadly; PTP supports more precise timing in suitable networks; NTS adds authenticated security to NTP. Time matters for logs, certificates and ticket-based authentication.

Choose under exam pressure

Requirement Choice and reason
Name resolves to wrong address Check authoritative record, cached answer, TTL and split-DNS view.
Clients across router cannot obtain leases Inspect DHCP relay and server scope.
Need trustworthy signed DNS answers DNSSEC; use separate transport protection if confidentiality is required.

Traps

  • DNS can use TCP, not only UDP.
  • A DHCP reservation does not prevent every rogue device from using an address.

Practise this topic

04 · Switching, VLANs and Loop Prevention

Memory hook: VLAN separates; trunk carries; spanning tree prevents loops.

Must remember

An access port normally places untagged client traffic into one data VLAN. An 802.1Q trunk carries multiple VLANs using tags, with native/untagged behavior defined by configuration. A voice VLAN can separate phone traffic from an attached workstation. VLAN membership does not by itself authorize routing between VLANs.

Switches learn source MAC addresses, forward known unicasts to the learned port and flood unknown unicasts/broadcasts within the VLAN as appropriate. MAC-table instability, duplicate paths and loops can create storms. Spanning Tree elects a root bridge and blocks redundant forwarding paths while preserving connectivity. Rapid variants converge more quickly; root selection and path cost remain important.

Link aggregation combines compatible links into one logical bundle for capacity/resilience. LACP negotiates the bundle. Traffic is usually distributed by a hash, so one flow may not use the sum of all link bandwidth. Member speed, VLAN and trunk settings must agree.

MTU determines maximum packet/frame payload behavior at a layer. Jumbo frames need consistent path support; an MTU mismatch can allow small pings while breaking larger transfers. Duplex mismatch, CRC errors, discards and speed negotiation faults require different fixes.

Use switch port status/counters, MAC tables, VLAN/trunk information, spanning-tree state and neighbor discovery to trace a client path. Document intended native/allowed VLANs and avoid unnecessary trunks to untrusted devices.

For a new segment, verify the access port, VLAN existence, trunk allowance, routed interface/gateway and policy. A single missing VLAN on an intermediate trunk can mimic a routing problem.

Choose under exam pressure

Requirement Choice and reason
Separate guest broadcast traffic A dedicated VLAN plus controlled Layer 3 access.
Redundant Layer 2 links Spanning tree or a correctly configured logical aggregation.
One flow slower than aggregate link capacity Inspect hash distribution and single-member limits.

Traps

  • A trunk does not mean all VLANs are necessarily allowed.
  • PortFast/edge behavior belongs on suitable endpoint links, not arbitrary switch loops.

Practise this topic

05 · Routing, NAT and Resilient Gateways

Memory hook: Specific route first; preference next; metric within the protocol.

Must remember

Routers select the longest matching prefix for a destination. For competing routes to the same prefix, route-source preference/administrative distance and the protocol's metric determine which route is installed/used. A lower metric in one protocol cannot be compared directly to another protocol's metric as though they were the same units.

Static routes are explicit; a default route (0.0.0.0/0 or ::/0) handles destinations lacking a more specific match. A floating static route has a less-preferred administrative distance so another route wins while available. Dynamic protocols exchange reachability: OSPF is link-state, BGP policy-driven path-vector between routing domains, and EIGRP an advanced distance-vector protocol.

NAT rewrites addresses; PAT/NAT overload also distinguishes flows by ports so many internal clients share an external address. Static NAT fixes a mapping; dynamic pools allocate mappings. Translation is not a substitute for firewall policy or end-to-end authorization. Return traffic must traverse a path with the needed translation/session state.

First-hop redundancy provides a virtual gateway shared by routers. It protects gateway availability, not every upstream link or application. Route convergence, asymmetric paths, health tracking and failover capacity affect actual resilience.

Subinterfaces can route tagged VLANs over a trunk (router-on-a-stick). Switch virtual interfaces on a multilayer switch provide another inter-VLAN routing design. Both require the right VLAN/trunk and routing configuration.

Worked choice: routes 10.0.0.0/8, 10.4.0.0/16 and 10.4.8.0/24 all match 10.4.8.9; /24 wins even if its metric is numerically larger than another protocol's broader route.

Choose under exam pressure

Requirement Choice and reason
Backup route only when primary disappears A suitable floating static route with reachable next hop.
Many private clients share one public IPv4 PAT/NAT overload.
Gateway device fails First-hop redundancy plus healthy upstream paths.

Traps

  • Default routes do not beat a more specific route.
  • NAT does not automatically permit unsolicited inbound access.

Practise this topic

06 · Wireless and Network Access Security

Memory hook: Signal quality, channel plan and identity all matter.

Must remember

Wi-Fi shares airtime. Signal strength alone does not measure usable performance: interference, signal-to-noise ratio, channel contention, client capability and retries matter. In 2.4 GHz, 1/6/11 are the familiar nonoverlapping 20 MHz plan where permitted; 5/6 GHz offer more spectrum with region/device restrictions. Wider channels trade peak capacity for fewer independent channels and more overlap.

An SSID identifies a wireless network name; a BSSID identifies a basic service set/radio identity. Roaming requires compatible configuration and suitable coverage, not simply giving every AP the same name. Directional/omnidirectional antennas shape coverage; survey placement, walls, power and channel use.

WPA2/WPA3 protect Wi-Fi; enterprise modes use 802.1X/EAP with an authentication service such as RADIUS. Validate the server certificate and choose suitable EAP methods. Guest networks should have appropriate isolation and a controlled route to required services. A captive portal is not equivalent to strong link encryption or enterprise identity.

NAC can assess and authorize endpoints. Hardening includes management restrictions, secure firmware, disabled unused services, changed defaults, centralized logging and protected secrets. ACLs, firewall zones and URL/content filtering enforce different boundaries. TACACS+ is often chosen for network-device administrative AAA; RADIUS is common for network admission.

Threat cues: an evil twin imitates a trusted AP; ARP/DNS poisoning redirects traffic; MAC flooding pressures switch tables; VLAN hopping abuses weak trunk/native configurations; a rogue DHCP server supplies malicious addressing/gateway options. Segmentation, DHCP snooping, appropriate ARP inspection, port controls and user training address different paths.

Encryption, MFA and PKI complement physical locks/cameras. Treat IoT, BYOD and industrial systems according to their capabilities and risk, with controlled access rather than unconditional internal trust.

Choose under exam pressure

Requirement Choice and reason
Strong signal but poor throughput Inspect interference, channel contention, retries and client capabilities.
Enterprise user/device authentication 802.1X/EAP with validated RADIUS server identity.
Unmanaged guests Separate access and limited reachability.

Traps

  • Hidden SSIDs do not provide meaningful authentication.
  • Increasing transmit power can worsen interference or create asymmetric links.

Practise this topic

07 · Cabling, Cloud and Physical Design

Memory hook: Match medium, distance, power and failure domain.

Must remember

Copper twisted pair commonly uses RJ45 connectors; telephone cabling uses smaller RJ11. Fiber connectors include LC, SC, ST and multifiber MPO. Coaxial systems may use F-type or BNC. Connector fit alone does not prove the correct medium, wavelength, speed or polarity.

Single-mode fiber supports long-distance optical paths with suitable optics; multimode fiber serves shorter links under its own distance/speed limits. DAC cables connect nearby compatible equipment economically. Match transceiver form factor, wavelength, fiber type and supported standard at both ends. Dirty fiber, reversed transmit/receive pairs, excessive bend radius, bad termination and electromagnetic interference have distinct symptoms.

PoE supplies power over compatible Ethernet links. Check per-port standard/class and the switch's total power budget; enough data connectivity does not prove enough power for an AP or phone. Racks need appropriate airflow, grounding, cable management, labeling, temperature and humidity. UPS provides short-term continuity; generators and diverse feeds address longer/different failures.

Cloud networking includes virtual networks/subnets, security groups/policies, gateways, load balancers and virtual appliances. IaaS, PaaS and SaaS shift operational responsibility. NFV implements network functions in software; SDN programs/control-separates networking. SD-WAN steers overlay paths using policy; SASE combines distributed access and security capabilities.

Hybrid connectivity joins cloud and on-premises environments; overlapping CIDRs complicate routing. VPN encryption and private circuits solve different transport requirements. Elasticity changes resources with demand; scalability is the ability to grow. Cloud data-transfer and public-address costs can dominate an apparently cheap design.

Document physical and logical diagrams, rack elevation, cable maps, circuits and IP allocations. Label both ends so future troubleshooting starts with evidence instead of guesswork.

Choose under exam pressure

Requirement Choice and reason
Long optical distance Compatible single-mode optics/fiber and verified link budget.
AP reboots under load Check PoE negotiation/budget and physical power conditions.
Hybrid routing conflict Inspect overlapping address ranges before adding routes.

Traps

  • Two fiber connectors mating does not guarantee compatible optics.
  • A private circuit is not automatically encrypted.

Practise this topic

08 · Network Operations and Recovery

Memory hook: Baseline normal; control change; restore what matters.

Must remember

Maintain asset inventory, IPAM, topology, cable/rack diagrams, wireless surveys and current configurations. Know hardware/software end-of-support dates and preserve recoverable configuration backups. Decommissioning includes access revocation, data sanitization, inventory updates and removing obsolete monitoring/DNS entries.

Monitoring sources answer different questions: SNMP polls counters/state, traps notify events, flow records summarize communications, packet captures expose visible protocol detail, syslog centralizes events and APIs support structured telemetry. SNMPv3 can provide authentication and privacy; older community-string modes are weaker. Port mirroring copies selected traffic to an analysis port but may lose packets if oversubscribed.

Establish baselines for utilization, latency, jitter, loss, errors and availability. Thresholds without context create noise. Correlate changes and multiple sources; a high CPU graph is a symptom, not a root cause by itself.

Change management includes authorization, impact, dependency review, testing, maintenance windows, backups, rollback and validation. Store production, baseline and backup configurations distinctly. Emergency changes still need an accountable process and retrospective records.

RPO is tolerable data loss; RTO target restoration time. MTTR measures average repair/recovery time as defined; MTBF estimates time between failures. Do not confuse measured averages with contractual targets. Active-active uses multiple serving systems; active-passive keeps a standby. Recovery sites trade readiness and cost.

Secure remote administration through approved VPN/SSH/API or console access with individual accounts and least privilege. Out-of-band access helps recover from production network failures. Test restoration of configuration, routing, DNS, identity, monitoring and application reachability together.

Choose under exam pressure

Requirement Choice and reason
Identify traffic sources without full payload capture Flow telemetry.
Recover after a bad change Known-good configuration and tested rollback.
Production network unavailable Protected out-of-band management.

Traps

  • Monitoring without baselines and response ownership produces dashboards, not reliability.
  • A configuration backup must match hardware/software and be restorable.

Practise this topic

09 · Troubleshooting Networks

Memory hook: Define the symptom; test one layer; verify the whole path.

Must remember

Start by identifying scope, symptoms, recent changes and what still works. Establish a plausible theory, test it, plan a low-impact fix, implement under the change process, verify full functionality and document cause/results. Escalate when the evidence or authority requires it.

Symptom Useful next check
No link Cable/optic, administrative state, speed and power.
Increasing CRC errors Physical quality, interference, optic/cable mismatch.
Link up, no usable address VLAN and DHCP/relay/pool state.
Local works, remote fails Prefix, gateway, route and ACL.
IP works, name fails Resolver settings, DNS records and cache.
Small traffic works, large transfers stall MTU/path-MTU and filtered ICMP.
Wireless intermittent Channel contention, roaming, SNR and retries.

ipconfig/ip inspect host configuration; ping checks selected reachability; traceroute/tracert expose responding hops; nslookup/dig query DNS; arp/ip neigh show neighbor bindings; netstat/ss show sockets; tcpdump or Wireshark inspect packets. Command availability differs by OS. A blocked ICMP response or a router deprioritizing probes does not necessarily mean the application path is broken.

Use cable testers for continuity/wiremap, toner/probe tools for cable identification, optical meters/OTDR for suitable fiber diagnosis and Wi-Fi analyzers for channel/radio evidence. Choose the instrument for the suspected fault; a speed test does not identify every wiring defect.

Inspect both directions. A request can leave successfully while the reply lacks a route, session state or policy permission. Duplicate addresses, wrong masks, exhausted DHCP pools, native-VLAN mismatches and stale DNS can appear intermittent.

Finish by testing the actual user service from the intended source, not just the nearest gateway. Record the fixed cause and update diagrams/baselines when the intended design changed.

Choose under exam pressure

Requirement Choice and reason
Only one user fails Compare that client/port/configuration with a working peer.
Everything fails after a change Correlate the changed dependency and use the approved rollback if warranted.
Ping succeeds but web request fails Test DNS, transport port, TLS and application behavior.

Traps

  • Traceroute timeouts can reflect filtering rather than a failed forwarding hop.
  • Changing several variables at once destroys diagnostic clarity.

Practise this topic

Search across every published topic.