https://partners.comptia.org/docs/default-source/resources/comptia-network-n10-009-exam-objectives-(4-0)
- Networking Concepts
- OSI Model
- Physical
- Data Link
- Network
- Transport
- Sessions
- Presentation
- Application
- Appliances
- Physical & Virtual
- Router
- Switch
- Firewall
- Intrusion Detection System (IDS)
- Load Balancer
- Proxy
- Network-Attached Storage (NAS)
- Storage Area Network (SAN)
- Wireless Access Point (WAP)
- Wireless Controller
- Applications
- Content Delivery Network (CDN)
- Functions
- Virtual Private Network (VPN)
- Quality of Service (QoS)
- Time-to-Live (TTL)
- Cloud Concepts
- Network Functions Virtualisation (NFV)
- Virtual Private Cloud (VPC)
- Network Security Groups
- Network Security Lists
- Cloud Gateways
- Internet Gateway
- Network Address Translation (NAT) Gateway
- Cloud Connectivity Options
- VPN
- Direct Connect
- Deployment Models
- Public
- Private
- Hybrid
- Service Models
- Software as a Service (SaaS)
- Infrastructure as a Service (IaaS)
- Platform as a Service (PaaS)
- Scalability
- Elasticity
- Multi-tenancy
- Common Ports, Protocols, Services and Traffic
- Protocols
- File Transfer Protocl (FTP)
- Secure File Transfer Protocol (SFTP)
- Secure Shell (SSH)
- Telnet
- Simple Mail Transfer Protocol (SMTP)
- Domain Name System (DNS)
- Dynamic Host Configuration Protocol (DHCP)
- Trivial File Transfer Protocol (TFTP)
- Hypertext Transfer Protocol (HTTP)
- Network Time Protocol (NTP)
- Simple Network Management Protocol (SNMP)
- Lightweight Directory Access Protocol (LDAP)
- Hypertext Transfer Protocol Secure (HTTPS)
- Server Message Block (SMB)
- Syslog
- Simple Mail Transfer Protocol Secure (SMTPS)
- Lightweight Directory Access Protocol Secure (LDAPS)
- Structure Query Language (SQL) Server
- Remote Desktop Protocol (RDP)
- Sessions Initiation Protocol (SIP)
- Internet Protocol (IP) Type
- Internet Control Message Protocol (ICMP)
- Transmission Control Protocol (TCP)
- User Datagram Protocol (UDP)
- Generic Routing Encapsulation (GRE)
- Internet Protocol Security (IPSec)
- Authentication Header (AH)
- Encapsulating Security Payload (ESP)
- Internet Key Exchange (IKE)
- Traffic Types
- Unicast
- Multicast
- Anycast
- Broadcast
- Transmission Media and Transceivers
- Wireless
- 802.11
- Cellular
- Satellite
- Wired
- 802.3
- Single-mode vs Multi-mode fibre
- Direct Attach copper (DAC)
- Twinaxial cable
- Coaxial cable
- Cable speeds
- Plenum vs non-plenum cable
- Transceivers
- Ethernet
- Fibre Channel (FC)
- Form Factors
- Small form-factor pluggable (SFP)
- Quad small form-factor pluggable (QSFP)
- Connector types
- Subscriber connector (SC)
- Local connector (LC)
- Straight tip (ST)
- Multi-fibre push on (MPO)
- Registered jack (RJ)11
- RJ45
- F-type
- Network Topologies, Architectures and Types
- Mesh
- Hybrid
- Star/hub and spoke
- Spine and leaf
- Point to point
- Three-tier hierarchical model
- Core
- Distribution
- Access
- Collapsed Core
- Traffic Flows
- North-south
- East-west
- IPv4 Network Addresses
- Public vs Private
- Automatic Private IP Addressing (APIPA)
- RFC1918
- Loopback/localhost
- Subnetting
- Variable Length Subnet Mask (VLSM)
- Classless Inter-domain Routing (CIDR)
- IPv4 Address Classes
- Class A
- Class B
- Class C
- Class D
- Class E
- Modern Network Environments
- Software-defined network (SND) and Software-defined wide area network (SD-WAN)
- Application aware
- Zero-touch provisioning
- Transport agnostic
- Central policy management
- Virtual Extensible Local Area Network (VXLAN)
- Data centre interconnect (DCI)
- Layer 2 encapsulation
- Zero trust architecture (ZTA)
- Policy-based authentication
- Authorisation
- Least Privilege Access
- Secure Access Secure Edge (SASE) / Security Service Edge (SSE)
- Infrastructure as Code (IaC)
- Automation
- Playbooks/templates/reusable tasks
- Configuration drift/compliance
- Upgrades
- Dynamic Inventories
- Source Control
- Version Control
- Central Repository
- Conflict Identification
- Branching
- IPv6 Addressing
- Mitigating address exhaustion
- Compatibility requirements
- Tunnelling
- Dual stack
- NAT64
- Network Implementation
- Routing Technologies
- Static routing
- Dynamic Routing
- Border Gateway Protocol (BGP)
- Enhanced Interior Gateway Routing Protocol (EIGRP)
- Open Shortest Path First (OSPF)
- Route Selection
- Administrative distance
- Prefix length
- Metric
- Address translation
- NAT
- Port address translation (PAT)
- First Hop Redundancy Protocol (FHRP)
- Virtual IP (VIP)
- Subinterfaces
- Switching Technologies
- Virtual Local Area Network (VLAN)
- VLAN database
- Switch Virtual Interface (SVI)
- Interface configuration
- Native VLAN
- Voice VLAN
- 802.1Q tagging
- Link aggregation
- Speed
- Duplex
- Spanning Tree
- Maximum Transmission Unit (MTU)
- Jumbo frames
- Wireless Technologies
- Channels
- Channel width
- Non-overlapping channels
- Regulatory impacts
- 802.11h
- Frequency options
- 2.4GHz
- 5Ghz
- 6Ghz
- Band steering
- Service set identifier (SSID)
- Basic service set identifier (BSSID)
- Extended service set identifier (ESSID)
- Network Types
- Mesh networks
- Ad hoc
- Point to point
- Infrastructure
- Encryption
- Wi-Fi Protected Access 2 (WPA2)
- WPA3
- Guest Networks
- Captive portals
- Authentication
- Pre-shared Key (PSK) vs Enterprise
- Antennas
- Omnidirectional vs Directional
- Autonomous vs Lightweight access point
- Physical Installations
- Important implications
- Locations
- Intermediate distribution frame (IDF)
- Main distribution frame (MDF)
- Rack size
- Port-side exhaust intake
- Cabling
- Patch panel
- Fibre distribution panel
- Lockable
- Power
- Uninterrupted power supply (UPS)
- Power distribution unit (PDU)
- Power load
- Voltage
- Environmental factors
- Humidity
- Fire suppression
- Temperature
- Network Operations
- Organisational Processes
- Documentation
- Physical vs logical diagrams
- Rack diagrams
- Cable maps and diagrams
- Network diagrams
- Layer 1
- Layer 2
- Layer 3
- Asset inventory
- Hardware
- Software
- Licensing
- Warranty support
- IP address management (IPAM)
- Service-level agreement (SLA)
- Wireless survey/heat map
- Life-cycle management
- End-of-life (EOL)
- End-of-support (EOS)
- Software management
- Patches and bug fixes
- Operating system (OS)
- Firmware
- Decommissioning
- Change management
- Request process tracking/service request
- Configuration management
- Production configuration
- Backup configuration
- Baseline/golden configuration
- Network Monitoring Technologies
- Methods
- SNMP
- Traps
- Management information base (MIB)
- Versions
- v2c
- v3
- Community strings
- Authentication
- Flow data
- Packet capture
- Baseline metrics
- Anomaly alerting notifications
- Log aggregation
- Syslog collector
- Security information and event management (SIEM)
- Application programming interface (API) integration
- Port mirroring
- Solutions
- Network discovery
- Ad-hoc
- Scheduled
- Traffic analysis
- Performance monitoring
- Availability monitoring
- Configuration monitoring
- Disaster Recovery
- DR metrics
- Recovery point objective (RPO)
- Recovery time obejctive (RTO)
- Mean time to repair (MTTR)
- Mean time between failures (MTBF)
- DR sites
- Cold site
- Warm site
- Hot site
- High-availability appraoches
- Active-active
- Active-passive
- Testing
- Tabletop exercises
- Validation tests
- IPv5 and IPv6 Network Services
- Dynamic Addressing
- DHCP
- Reservations
- Scope
- Lease time
- Options
- Relay/IP helper
- Exclusions
- Stateless Address Autoconfiguration (SLAAC)
- Name Resolution
- DNS
- Domain Name Security Extensions (DNSSEC)
- DNS over HTTPS (DoH) and DNS over TLS (DoT)
- Record types
- Address (A)
- AAAA
- Canonical (CNAME)
- Mail exchange (MX)
- Text (TXT)
- Nameserver (NS)
- Pointer (PTR)
- Zone types
8. Forward
9. Reverse
- Authoritative vs non-Authoritative
- Primary vs Secondary
- Recursive
- Hosts file
- Time protocols
- NTP
- Precision time protocol (PTP)
- Network time security (NTS)
- Network Access and Management Methods
- Site-to-site VPN
- Client-to-site VPN
- Clientless
- Split tunnel vs full tunnel
- Connection methods
- SSH
- Graphical User Interface (GUI)
- API
- Console
- Jump box/host
- In-band vs out-of-band management
- Network Security
- Basic Network Security
- Logical Security
- Encryption
- Data in transit
- Data at rest
- Certificates
- Public key infrastructure (PKI)
- Self-signed
- Identity and access management (IAM)
- Authentication
- Multifactor authentication (MFA)
- Single sign-on (SSO)
- Remote Authentication Dial-in User Service (RADIUS)
- LDAP
- Security Assertion Markup Language (SAML)
- Terminal Access Controller Access Control System Plus (TACACS+)
- Time-based authentication
- Authorisation
- Least privilege
- Role-based access control
- Geofencing
- Physical Security
- Camera
- Locks
- Deception technologies
- Honeypot
- Honeynet
- Common Security Terminology
- Risk
- Vulnerability
- Exploit
- Threat
- Confidentiality, Integrity and Availability (CIA) triad
- Audits and Regulatory Compliance
- Data locality
- Payment Card Industry Data Security Standards (PCI DSS)
- General Data Protection Regulation (GDPR)
- Network Segmentation enforcement
- Internet of Things (IoT) and Industrial Internet of Things (IIoT)
- Supervisory Control and Data Acquisition (SCADA),
- Industrial Control System (ICS)
- Operational Technology (OT)
- Guest
- Bring your own device (BYOD)
- Types of Network Attacks and Impact
- (Distributed) Denial of Service ((D)DoS)
- VLAN hopping
- MAC flooding
- ARP poisoning + spoofing
- DNS poisoning + poisoning
- Rogue devices and services
- DHCP
- AP
- Evil twin
- On-path attack
- Social Engineering
- Phishing
- Dumpster-diving
- Shoulder-surfing
- Tailgating
- Malware
- Network Security and Defense Techniques
- Device hardening
- Disable unused ports and services
- Change default passwords
- Network Access Control (NAC)
- Port security
- 802.1X
- MAC filtering
- Key management
- Security rules
- Access control list (ACL)
- Uniform Resource Locator (URL) filtering
- Content filtering
- Zones
- Trusted vs untrusted
- Screened subnet
- Network Troubleshooting
- Troubleshooting Methodology
- Identify the problem
- Gather information
- Question users
- Identify symptoms
- Determine is anything has changed
- Duplicate the problem, if possible
- Approach multiple problems individually
- Establish a theory of probable cause
- Question the obvious
- Consider multiple approaches
- Top-to-bottom/bottom-to-top OSI model
- Divide and conquer
- Test the theory to determine the cause
- If confirmed, determine next steps
- If not confirmed, establish new theory or escalate
- Establish a plan of action to resolve problem and identify potential effects
- Implement the solution or escalate as necessary
- Verify full system functionality and implement preventative measures if applicable
- Document findings, actions, outcomes and lessons learned throughout the process
- Troubleshooting Common Cabling and Physical Interface Issues
- Cable issues
- Incorrect cable
- Single mode vs multimode
- Category 5/6/7/8
- Shielded twisted pair (STP) vs unshielded twisted pair (UTP)
- Signal degradation
- Crosstalk
- Interference
- Attenuation
- Improper termination
- Transmitter (TX) / Receiver (RX) transposed
- Interface issues
- Increasing interface counters
- Cyclic redundancy check (CRC)
- Runts
- Giants
- Drops
- Port status
- Error disabled
- Administratively down
- Suspended
- Hardware issues
- Power over Ethernet (PoE)
- Power budget exceeded
- Incorrect standard
- Transceivers
- Mismatch
- Signal strength
- Common issues with network services
- Switching issues
- STP
- Network loops
- Root bridge selection
- Port roles
- Port states
- Incorrect VLAN assignment
- ACLS
- Route selection
- Routing table
- Default routes
- Address pool exhaustion
- Incorrect default gateway
- Incorrect IP address
- Duplicate IP address
- Incorrect subnet mask
- Common performance issues
- Congestion/contention
- Bottlenecking
- Bandwidth
- Throughput capacity
- Latency
- Packet loss
- Jitter
- Wireless
- Interference
- Channel overlap
- Signal degradation or loss
- Insufficient wireless coverage
- Client disassociation issues
- Roaming misconfiguration
- Tools & Protocols
- Software Tools
- Protocol Analyzer
- Command Line
- ping
- traceroute/tracert
- nslookup
- tcpdump
- dig
- netstat
- ip/ifconfig/ipconfig
- arp
- nmap
- Link Layer Discovery Protocol (LLDP)
- Speed tester
- Hardware tools
- Toner
- Cable tester
- Taps
- Wi-Fi analyzer
- Visual fault locator
- Basic networking device commands
- show mac-address-table
- show route
- show interface
- show config
- show arp
- show vlan
- show power