CCNA · Associate

Cisco Certified Network Associate (CCNA)

Learn to reason through networks: how traffic moves, where it stops and how to secure it.

Start Free

Your free account includes a full CCNA practice exam.

ExamNova practice

Your first session

Questions
110
Time limit
120 min
Coverage
6 domains

Practise, review your answers and see where to focus next.

Preview a question

Is CCNA your next step?

For people building an enterprise networking foundation. The CCNA 200-301 exam connects network fundamentals, switching, routing, services, security and automation.

Follow the packet

Use addressing, routing and forwarding behaviour to explain how traffic reaches its destination.

Understand network access

Work through VLANs, switching and wireless concepts, including common causes of connectivity problems.

Secure and automate

Connect access controls and network services with the concepts behind programmable networks.

Official certification guide ↗

What you’ll study

Explore the domains and topics in your ExamNova study path.

Network Fundamentals20% practice balance

Explore Network Fundamentals

Explain the Role and Function of Network Components

  • Routers and L2/L3 Switches
  • Access Points and Unified Communications Endpoints
  • Security and WAN Edge Platforms

Describe Characteristics of Network Topology Architectures

  • Two-Tier and Three-Tier
  • Spine-Leaf
  • WAN and Remote-Access Topologies

Compare Physical Interface and Cabling Types

  • Copper and Fiber Cabling Media
  • Optical Modules, Power Delivery, and Testing

Identify Interface and Cable Issues

  • Collisions and Errors
  • Duplex and Speed

Compare TCP to UDP

  • TCP Handshake and UDP Best-Effort Delivery
  • Port Numbers
  • TCP Windowing and Flow Control Mechanisms
  • Application Interaction and Performance Effects

Configure and Verify IPv4 Addressing and Subnetting

  • Subnetting and VLSM

Describe Private IPv4 Addressing

  • Private IPv4 Addressing

Configure and Verify IPv6 Addressing and Prefix

  • IPv6 Address Configuration

Describe IPv6 Address Types

  • IPv6 Addressing Basics

Verify IP Parameters for Client OS

  • Client OS IP Parameters

Describe Wireless Principles

  • Wireless Fundamentals and Identification
  • Encryption and WPA2/WPA3
  • Wireless Planning, Surveys, and Interference

Explain Virtualization Fundamentals

  • Virtualized and Cloud-Managed Networking

Describe Switching Concepts

  • Ethernet Switching Concepts
Network Access20% practice balance

Explore Network Access

Configure and Verify VLANs Spanning Multiple Switches

  • VLANs and Access Ports
  • Voice VLAN Configuration

Configure and Verify Interswitch Connectivity

  • IEEE 802.1Q and Native VLAN
  • Inter-VLAN Connectivity

Configure and Verify Layer 2 Discovery Protocols

  • CDP and LLDP

Configure and Verify Layer 2 and Layer 3 EtherChannel

  • Advanced LACP Features
  • LACP and PAgP
  • Static and Active/Passive LACP Modes
  • Layer 3 EtherChannels
  • EtherChannel Troubleshooting

Interpret Basic Operations of Rapid PVST+ Spanning Tree Protocol

  • Fundamentals of Spanning Tree Behavior
  • Rapid Spanning Tree Convergence
  • Edge and Protection Features
  • Operational Troubleshooting
  • Loop Protection and Traffic Limiting

Describe Cisco Wireless Architectures and AP Modes

  • AP Modes and FlexConnect
  • Centralized Vs. Distributed Forwarding

Describe Physical Infrastructure Connections of WLAN Components

  • WLAN Physical Infrastructure

Describe Network Device Management Access

  • Network Device Management Access

Interpret Wireless LAN GUI Configuration for Client Connectivity

  • Cisco WLCs and SSID Configuration
IP Connectivity25% practice balance

Explore IP Connectivity

Interpret the Components of a Routing Table

  • Route Identification and Source Codes
  • Next Hop and Prefix

Determine How a Router Makes a Forwarding Decision by Default

  • Administrative Distance and Metric
  • Path Selection and Forwarding Behavior

Configure and Verify IPv4 and IPv6 Static Routing

  • IPv4 and IPv6 Static Routes
  • Next-Hop Options: IP Address, Exit Interface
  • Default Route and Floating Static Route
  • Equal-Cost Static Route Load Balancing
  • Static Route Control and Resiliency

Configure and Verify Single-Area OSPFv2

  • OSPF Neighbor Formation and Router Identification
  • Point-to-Point and Broadcast
  • OSPF Network Types and DR/BDR Behavior
  • OSPF LSAs and Cost Tuning

Describe First Hop Redundancy Protocols

  • First Hop Redundancy Protocols
IP Services10% practice balance

Explore IP Services

Configure and Verify Inside Source NAT

  • Static NAT
  • Dynamic NAT and Port Address Translation
  • Advanced NAT Configurations
  • NAT Troubleshooting and Protocol Extensions

Configure and Verify NTP Client and Server Mode

  • NTP Client/Server Mode and NTP Stratum
  • NTP Master
  • Time Synchronization Use Cases and Comparisons

Explain the Role of DHCP and DNS

  • DHCP Client and DHCP Server
  • DNS Forwarding and DNS Record Types

Explain the Function of SNMP in Network Operations

  • SNMP Access and Notifications

Describe the Use of Syslog Features

  • Syslog Levels and Facilities
  • Remote Syslog Configuration and Verification

Configure and Verify DHCP Client and Relay

  • DHCP Relay and DHCP Options

Explain Forwarding Per-Hop Behavior for QoS

  • QoS Concepts
  • Traffic Shaping Vs. Traffic Policing

Configure Network Devices for Remote Access Using SSH

  • SSH Remote Access

Describe the Capabilities and Functions of TFTP and FTP

  • TFTP and FTP Capabilities
Security Fundamentals15% practice balance

Explore Security Fundamentals

Define Key Security Concepts

  • Threats and Vulnerabilities
  • Exploits and Mitigation Techniques
  • Confidentiality, Integrity, and Availability
  • Common Attack Types and Defensive Models

Describe Security Program Elements

  • Monitoring, Policy, and Governance Basics
  • Security Program Elements

Configure and Verify Device Access Control Using Local Passwords

  • Local Device Access Control

Describe Security Password Policy Elements

  • Password Policies and Multifactor Authentication

Describe IPsec Remote Access and Site-to-Site VPNs

  • IPsec VPN Fundamentals

Configure and Verify Access Control Lists

  • Standard ACLs and Extended ACLs
  • Numbered/Named ACLs
  • ACL Placement Best Practices and IPv6 ACLs
  • Troubleshooting ACL Hit Counters and Logic

Configure and Verify Layer 2 Security Features

  • Access Port Hardening and MAC Restrictions
  • DHCP Snooping and Dynamic ARP Inspection

Compare Authentication, Authorization, and Accounting Concepts

  • AAA Concepts

Describe Wireless Security Protocols

  • Wireless Encryption Standards
  • PSK and Enterprise
  • EAP Types and RADIUS

Configure and Verify WLAN Within the GUI Using WPA2 PSK

  • WPA2 PSK WLAN GUI Configuration
Automation and Programmability10% practice balance

Explore Automation and Programmability

Explain How Automation Impacts Network Management

  • Automation Design Principles

Compare Traditional Networks with Controller-Based Networking

  • Traditional and Controller-Based Networks

Describe Controller-Based and Software-Defined Architecture

  • Modern Segmentation and Fabric Architectures
  • Cisco DNA Center
  • Intent-Based Networking Principles
  • SDN Architecture and Control Plane
  • Data Plane
  • Controller-Based Network APIs

Explain AI and Machine Learning in Network Operations

  • AI and Machine Learning in Network Operations

Describe Characteristics of REST-Based APIs

  • REST and CRUD
  • HTTP Verbs
  • API Protocols and Security

Recognize the Capabilities of Ansible and Terraform

  • Configuration Management with Ansible and Terraform
  • Ansible and Terraform Configuration Management

Recognize Components of JSON-Encoded Data

  • Data Formats and Modeling

Percentages show ExamNova’s practice balance. Consult the official guide for the vendor’s current exam outline.

Try focused practice

Explore a topic with sample questions and explanations.

Try a question before you start.

Read the scenario. Consider your answer, then reveal the reasoning.

Draw the traffic path before choosing a fix. Pair conceptual practice with reading configurations and interpreting device output.

A branch office wants wireless client traffic to stay local instead of crossing the WAN to a central controller. Which model is more appropriate?

  • Distributed or local forwarding
  • Centralized tunneling for all client traffic
  • Half-duplex forwarding
  • DNSSEC signed forwarding
Show answer and explanations

Distributed or local forwarding — Distributed or local forwarding keeps client data traffic at the branch when that is the design goal.

Centralized tunneling for all client traffic — Centralized tunneling sends client traffic back to the controller.

Half-duplex forwarding — Half-duplex is an Ethernet transmission mode, not a wireless forwarding architecture.

DNSSEC signed forwarding — DNSSEC is a DNS security feature and is unrelated to WLAN forwarding location.

A clearer way to prepare.

One place to practise, understand your results and plan the next session.

Practise with purpose

Start with your free exam. Explore Exam, Endless and Custom practice modes as you build your study routine.

Understand the answer

Review the reasoning behind your answers and return to the decisions that need another look.

Find your next focus

Use domain-level performance and readiness to see strengths, gaps and areas you have yet to assess.

Put it into practice.

Explore hands-on tasks connected to CCNA. These are real Labs from the catalogue.

Make CCNA your next step.

Create your free account. Start practising.

Start Free