CiscoSeptember 30, 202626 min read

CCNA 200-301 Glossary & Acronyms: 55 Terms (2026)

Every term the CCNA 200-301 v1.1 blueprint leans on, from STP port states to REST verbs, defined in plain English with the exam cue and the look-alike it gets confused with.

  • 55Terms defined
  • 87Acronyms
  • v1.1Blueprint
  • 120 minExam time
  • Not publicPass mark
CCNA 200-301 glossary of networking terms and acronyms

How to use this glossary

CCNA questions rarely ask for a definition outright. They hand you a show output, a topology or a two-line scenario and expect you to recognise that 'discarding' is an RSTP port state, that [110/2] in a routing table is administrative distance and metric, or that a rogue DHCP server is a DHCP snooping problem. Knowing the vocabulary cold is the fastest way into those questions, and the look-alike terms are where most wrong answers come from.

This glossary follows the live 200-301 v1.1 exam topics (released August 2024), which include AI and machine learning in network operations, Ansible and Terraform, VRFs and cloud-managed device access. Cisco published a v2.0 blueprint on May 20, 2026: v1.1 stays testable through February 2, 2027, and v2.0 takes over on February 3, 2027 under the same 200-301 code, with more troubleshooting-level topics.

Every term below is tagged with the exam domain it belongs to. This is where the vocabulary load sits across the 200-301 blueprint:

  • D1Network Fundamentals20%8 terms
  • D2Network Access20%12 terms
  • D3IP Connectivity25%9 terms
  • D4IP Services10%8 terms
  • D5Security Fundamentals15%10 terms
  • D6Automation and Programmability10%8 terms

Each card has three layers: a plain-English definition, an On the exam line describing how questions use the term, and — where one exists — the term it is most often confused with. Click that link to jump straight to the rival definition.

The A–Z glossary

AAAAuthentication, Authorization, and AccountingD5

Framework for controlling access: authentication proves who you are, authorization decides what you may do, and accounting records what you did. Usually centralised on a RADIUS or TACACS+ server.

On the examMatch the verb to the A: 'log which commands were run' is accounting, 'limit an admin to show commands' is authorization, 'verify username and password' is authentication.

Access PortD2

A switch port that belongs to a single data VLAN and sends untagged frames to an end device. It can also carry a separate voice VLAN for an attached IP phone, which tags its own traffic.

On the examA PC, printer or phone on the port means access mode. Voice VLAN questions add switchport voice vlan; the trap is assuming a voice VLAN turns the port into a trunk.

Don’t confuse with Trunk Port

Administrative DistanceD3

A value from 0 to 255 that ranks how trustworthy a route source is. When two sources offer the same prefix, lower wins: connected 0, static 1, eBGP 20, EIGRP 90, OSPF 110, RIP 120.

On the examOnly compared when different sources offer the same prefix length. Memorise the default table; [110/2] in show ip route means AD 110 and metric 2.

Don’t confuse with Metric

AnsibleD6

Agentless configuration management tool that connects to devices over SSH or APIs and applies tasks written in YAML playbooks, pushing the desired configuration from a single control node.

On the examAnsible means agentless, push model, YAML playbooks. Terraform is declarative infrastructure as code that tracks state. Puppet and Chef, which use agents and a pull model, are the distractors.

BPDU GuardD2

Protection that err-disables a port the moment it receives a spanning-tree BPDU. It stops a rogue or accidental switch on an edge port from joining the topology or becoming root.

On the exam'Port went err-disabled after a user plugged in a small switch' is BPDU Guard. Root guard is the distractor: it blocks superior BPDUs but keeps the port up in a root-inconsistent state.

Don’t confuse with PortFast

CDPCisco Discovery ProtocolD2

Cisco-proprietary Layer 2 protocol, on by default, that advertises hostname, platform, software version, interface and management address to directly connected Cisco neighbors every 60 seconds.

On the exam'Identify the neighbor device and its port without logging in' means show cdp neighbors detail. A non-Cisco neighbor flips the answer to LLDP. Disabling CDP on edge ports is a hardening answer.

Don’t confuse with LLDP

Control PlaneD6

The part of a network device that makes decisions and builds tables. Routing protocols, spanning tree, ARP and neighbor relationships all run here and decide how traffic should flow.

On the exam'OSPF exchanging LSAs' or 'building the routing table' is control plane. The management plane (SSH, SNMP) is the usual distractor. SDN centralises the control plane in a controller.

Don’t confuse with Data Plane

DAIDynamic ARP InspectionD5

Switch feature that checks ARP messages on untrusted ports against the DHCP snooping binding table and drops those with forged IP-to-MAC mappings, blocking ARP spoofing and man-in-the-middle attacks.

On the examCue: 'ARP poisoning' or 'attacker claims the gateway's IP address'. DAI depends on DHCP snooping or static ARP ACLs, and uplinks to other switches must be trusted.

Don’t confuse with DHCP Snooping

Data PlaneD6

The part of a device that actually forwards traffic: looking up the destination, rewriting headers and sending frames or packets out the right interface, often in hardware.

On the exam'Forwarding', 'encapsulation' or 'applying an ACL to each packet' is data plane. In SDN the data plane stays on the switches while control moves to the controller.

Don’t confuse with Control Plane

DHCP RelayD4

Router function that forwards DHCP broadcasts from clients to a DHCP server on another subnet as unicast. Configured on the client-facing interface with the ip helper-address command.

On the exam'Clients in VLAN 20 get no address and the DHCP server sits in the data center' means ip helper-address on the VLAN 20 gateway interface, not on the server side.

DHCP SnoopingD5

Switch feature that marks ports trusted, toward the real DHCP server, or untrusted, drops DHCP server messages arriving on untrusted ports, and builds a binding table of IP, MAC, VLAN and port.

On the exam'Rogue DHCP server handing out a bad default gateway' is DHCP snooping. Its binding table is what Dynamic ARP Inspection checks, so the two often appear in the same question.

Don’t confuse with DAI

DRDesignated RouterD3

On broadcast segments such as Ethernet, OSPF elects a DR and a backup DR so other routers form full adjacencies only with them, cutting flooding. Highest interface priority wins, then highest router ID.

On the examPriority 0 means never DR. The election is not preemptive, so a newer higher-priority router does not take over. Point-to-point network types skip the DR/BDR election entirely.

EUI-64Extended Unique Identifier, 64-bitD1

Method for building a 64-bit IPv6 interface ID from a 48-bit MAC address: split the MAC in half, insert FFFE in the middle, then flip the seventh bit of the first byte.

On the examExpect a MAC-to-IPv6 conversion. The two traps are forgetting to invert the seventh bit (00 becomes 02) and inserting FFFE in the wrong place. Configured with ipv6 address 2001:db8::/64 eui-64.

Extended ACLD5

Access list, numbered 100-199 or 2000-2699 or named, that matches source and destination address, protocol and port, allowing precise rules such as permitting only HTTPS to one server.

On the examPlace extended ACLs close to the source to drop traffic early. Trap: the implicit deny blocks everything not permitted, so a closing permit ip any any may be required.

Don’t confuse with Standard ACL

FHRPFirst Hop Redundancy ProtocolD3

Family of protocols, HSRP, VRRP and GLBP, that let two or more routers share a virtual IP and MAC address used as the hosts' default gateway, so the gateway survives a router failure.

On the examCCNA asks only purpose and concepts. Cue: 'hosts keep one default gateway, remove the single point of failure'. HSRP and GLBP are Cisco-proprietary; VRRP is the open standard.

Don’t confuse with HSRP

Floating Static RouteD3

A static route given an administrative distance higher than the primary route, so it stays out of the routing table until the primary route disappears. Used to activate backup links automatically.

On the examSpot the trailing number in the command, such as ip route 0.0.0.0 0.0.0.0 203.0.113.1 130. To back up an OSPF-learned route the AD must be above 110.

Don’t confuse with Administrative Distance

Gateway of Last ResortD3

The default route a router uses when nothing more specific matches the destination. It appears as 0.0.0.0/0, or ::/0 in IPv6, and is shown near the top of the routing table output.

On the exam'Gateway of last resort is not set' means packets to unknown networks are dropped. Fix with ip route 0.0.0.0 0.0.0.0 plus a next hop, usually on the internet edge router.

HSRPHot Standby Router ProtocolD3

Cisco first hop redundancy protocol where one active router forwards traffic for the virtual IP and a standby router takes over if the active fails. Highest priority wins; preemption is off by default.

On the examActive/standby is HSRP wording, master/backup is VRRP wording, a frequent trap. Only GLBP load-balances across gateways natively. Virtual MAC 0000.0c07.acXX identifies HSRP version 1.

Don’t confuse with FHRP

Inside GlobalD4

NAT term for the public address that represents an inside host to the outside world, taken from the router's outside interface or from a configured NAT pool.

On the examIf the stem asks which source address an internet web server sees, answer inside global. Outside local and outside global describe the remote host and rarely differ at CCNA level.

Don’t confuse with Inside Local

Inside LocalD4

NAT term for the address of an inside host as seen on the inside network, normally the private RFC 1918 address actually configured on that host.

On the examRead show ip nat translations columns: inside local is the real private host IP. Local means as seen from inside, global means as seen from outside.

Don’t confuse with Inside Global

IPsecInternet Protocol SecurityD5

Suite of protocols that encrypts and authenticates IP packets between peers, using IKE to negotiate keys and ESP to protect the data. It builds site-to-site tunnels between gateways or remote-access tunnels for users.

On the examSite-to-site: gateways build the tunnel and hosts are unaware. Remote access: the user runs a VPN client. 'Always-on connection between two offices' means site-to-site.

JSONJavaScript Object NotationD6

Lightweight text format for structured data. Objects in curly braces hold key/value pairs, arrays in square brackets hold ordered lists, keys are double-quoted strings, and whitespace carries no meaning.

On the examExpect a JSON snippet: count the objects, spot the syntax error (single quotes, missing or trailing comma) or pick the value of a nested key. Values can be string, number, boolean, null, object or array.

LACPLink Aggregation Control ProtocolD2

IEEE open standard that negotiates bundling several physical links into one logical EtherChannel. Its modes are active, which initiates, and passive, which only responds. Spanning tree treats the bundle as one link.

On the examActive-active or active-passive forms a bundle; passive-passive never does. LACP cannot pair with PAgP desirable/auto. Mismatched speed, duplex or VLAN settings leave member ports suspended.

LLDPLink Layer Discovery ProtocolD2

Vendor-neutral IEEE 802.1AB counterpart to CDP. Devices advertise identity and capabilities to direct neighbors. On Cisco IOS it is disabled by default and enabled globally with lldp run.

On the examMulti-vendor network plus neighbor discovery equals LLDP. Know it is off by default on IOS, and its default timers are 30 seconds between advertisements and a 120-second holdtime.

Don’t confuse with CDP

Longest Prefix MatchD3

The first rule of router forwarding: among all routes containing the destination address, the one with the longest subnet mask, the most specific, is used regardless of administrative distance or metric.

On the examClassic item lists 10.1.0.0/16, 10.1.1.0/24 and 10.1.1.0/26 and asks where 10.1.1.50 goes: the /26. Candidates who compare AD first pick the distractor.

MetricD3

The value a single routing protocol uses to choose between its own paths to one destination. OSPF uses cost derived from bandwidth, RIP uses hop count, and the lowest value wins.

On the examMetric breaks ties inside one protocol, AD breaks ties between sources, and longest prefix beats both. OSPF cost is reference bandwidth divided by interface bandwidth, default reference 100 Mbps.

Don’t confuse with Administrative Distance

NATNetwork Address TranslationD4

Rewriting IP addresses as packets cross a router, most often translating private inside addresses to public ones. Static NAT maps one-to-one; dynamic NAT assigns from a pool of public addresses.

On the examBlueprint 4.1 says inside source NAT using static and pools. Static is the answer when an inside server must be reachable from outside at a fixed address. Interfaces need ip nat inside and ip nat outside.

Don’t confuse with PAT

Native VLAND2

The one VLAN whose frames cross an 802.1Q trunk without a tag. It is VLAN 1 by default and must match on both ends of the trunk, or traffic leaks between VLANs.

On the examA native VLAN mismatch produces CDP error messages and merges two VLANs' traffic. The hardening answer is moving the native VLAN off VLAN 1 to an unused VLAN.

Northbound APID6

Interface between an SDN controller and the applications or scripts above it, usually a REST API returning JSON. Admins and tools use it to request network changes or pull inventory and health data.

On the examThink direction: north is up toward apps, south is down toward devices. 'Python script queries the controller' is northbound; 'controller pushes config to switches' is southbound.

Don’t confuse with Southbound API

NTPNetwork Time ProtocolD4

Protocol that synchronizes device clocks to a reference source over UDP 123. Stratum shows distance from the reference clock, so lower is more accurate. Routers can act as clients, servers or both.

On the examAccurate time matters for log correlation and certificates. Know ntp server (client mode) versus ntp master (acts as a server), and how to read show ntp associations.

OSPFOpen Shortest Path FirstD3

Link-state interior routing protocol. Routers flood LSAs, build an identical link-state database and run the SPF algorithm to find the lowest-cost path. CCNA covers single-area OSPFv2 only.

On the examAdjacency questions dominate: hello and dead timers (10/40 on broadcast), area, subnet and authentication must match. Router ID order: manual, highest loopback, then highest active interface IP.

PATPort Address TranslationD4

NAT overload: many inside hosts share one public IP address, with the router tracking each session by a unique source port number. Almost every home and branch internet connection uses it.

On the examThe overload keyword is the tell. Many hosts sharing one public address equals PAT; a dynamic NAT pool running out of addresses is the failure PAT avoids.

Don’t confuse with NAT

PoEPower over EthernetD1

Delivering DC power to a device over the same copper cable that carries its data. The switch detects a compliant powered device such as an IP phone, access point or camera and negotiates how many watts to supply.

On the examAPs or phones mounted where there is no power outlet is a PoE answer. The switch is the power sourcing equipment, and fiber runs can never deliver PoE.

Port SecurityD5

Switch feature that limits which and how many MAC addresses may use an access port. Violation modes are shutdown (default, err-disables the port), restrict (drops and logs) and protect (drops silently).

On the examKnow which modes log and increment the violation counter: restrict and shutdown do, protect does not. Sticky learning saves MACs to the running config. Shutdown recovery needs shut/no shut.

PortFastD2

Spanning-tree feature that moves an access port straight to forwarding, skipping the usual learning delay. It belongs only on ports connected to end hosts, never on links to other switches.

On the exam'PC waits about 30 seconds for a DHCP address after link up' is fixed by PortFast. PortFast speeds the port up; BPDU Guard protects it if a switch appears there.

Don’t confuse with BPDU Guard

RADIUSRemote Authentication Dial-In User ServiceD5

Open-standard AAA protocol over UDP 1812/1813 that encrypts only the password and combines authentication with authorization. It is the usual choice for end-user network access, 802.1X and enterprise Wi-Fi.

On the exam'User network access', '802.1X' or 'multi-vendor' points to RADIUS. If the stem needs per-command authorization for device administrators, the answer flips to TACACS+.

Don’t confuse with TACACS+

RESTRepresentational State TransferD6

API style that applies standard HTTP verbs to resource URLs. It is stateless: each request carries everything needed, including authentication such as basic auth, an API key or a bearer token.

On the examMap CRUD to HTTP: create is POST, read is GET, update is PUT or PATCH, delete is DELETE. Status codes: 2xx success, 4xx client error (401, 404), 5xx server error.

RFC 1918Private IPv4 address spaceD1

The standard that reserves 10.0.0.0/8, 172.16.0.0/12 and 192.168.0.0/16 for private use. These addresses are not routed on the public internet, so hosts using them need NAT to reach it.

On the examExpect 'which address is private?' items with near-misses like 172.32.1.1 or 192.169.0.1. The 172.16 to 172.31 range is the one people misremember. Private address plus internet access implies NAT.

RSTPRapid Spanning Tree ProtocolD2

IEEE 802.1w upgrade to STP that converges in seconds using a proposal/agreement handshake, alternate and backup port roles, and just three port states: discarding, learning and forwarding.

On the examThe blueprint names Rapid PVST+, Cisco's per-VLAN RSTP. Expect port roles (root, designated, alternate) and states. 'Blocking' and 'listening' belong to legacy STP, not RSTP.

Don’t confuse with STP

SDNSoftware-Defined NetworkingD6

Architecture that moves control-plane decisions from individual devices to a central controller that programs the network through APIs. Cisco examples include Catalyst Center (formerly DNA Center) and SD-Access.

On the examTraditional networks configure each box by CLI; controller-based networks define intent once centrally. Know overlay (virtual tunnels), underlay (physical transport) and fabric (the two combined).

SNMPSimple Network Management ProtocolD4

Protocol for monitoring and managing devices. A manager polls agents with Get requests and changes values with Set; agents send unsolicited traps or informs. Managed data is organised in a MIB.

On the examSNMPv3 alone adds authentication and encryption; v1 and v2c use plain community strings. Informs are acknowledged, traps are not. Polling uses UDP 161, traps UDP 162.

Southbound APID6

Interface a controller uses to program and read the network devices below it. Examples include NETCONF, RESTCONF, OpenFlow and plain SSH/CLI on older hardware.

On the examWhen answer choices name NETCONF or OpenFlow, those signal southbound. OpenFlow is the textbook southbound example; REST to the controller is the northbound decoy.

Don’t confuse with Northbound API

Spine-LeafD1

Data-center topology where every leaf switch connects to every spine switch and never to another leaf. Any server reaches any other in the same number of hops, giving predictable east-west latency and simple horizontal scaling.

On the exam'East-west traffic', 'data center' or 'every leaf connects to every spine' means spine-leaf. Two-tier (collapsed core) and three-tier (access, distribution, core) are the campus distractors.

Standard ACLD5

IPv4 access list, numbered 1-99 or 1300-1999 or named, that filters on source address only. Entries are read top-down, the first match wins, and an implicit deny sits at the end.

On the examPlacement rule: standard ACLs go as close to the destination as possible because they cannot see the destination. Watch wildcard masks: 0.0.0.255 matches a /24.

Don’t confuse with Extended ACL

STPSpanning Tree ProtocolD2

IEEE 802.1D protocol that prevents Layer 2 loops by electing a root bridge and blocking redundant ports. Legacy STP can take 30 to 50 seconds to converge through its listening and learning states.

On the examBroadcast storms and a flapping MAC table signal a loop STP should stop. Root bridge is the lowest bridge ID, priority first then MAC; priority moves in steps of 4096.

Don’t confuse with RSTP

SyslogD4

Standard for sending device log messages to a central server, usually over UDP 514. Each message carries a facility and a severity level from 0, emergency, to 7, debugging.

On the examMemorise the eight levels in order: emergency, alert, critical, error, warning, notification, informational, debugging. logging trap 4 sends levels 0 through 4 only.

TACACS+Terminal Access Controller Access-Control System PlusD5

Cisco-developed AAA protocol over TCP 49 that encrypts the whole payload and separates authentication, authorization and accounting, allowing command-by-command control of device administrators.

On the exam'Device administration', 'command authorization', 'full payload encryption' or 'TCP' means TACACS+. Blueprint 2.8 also lists it under device management access beside SSH and console.

Don’t confuse with RADIUS

TCPTransmission Control ProtocolD1

Connection-oriented Layer 4 protocol that opens a session with a three-way handshake, numbers every segment, acknowledges delivery and retransmits anything lost. Windowing adds flow control. HTTP, SSH and FTP all ride on it.

On the examCue words: 'reliable', 'acknowledgment', 'sequencing', 'three-way handshake', 'windowing'. If the application cannot tolerate loss, such as file transfer, web or SSH, pick TCP.

Don’t confuse with UDP

Trunk PortD2

A switch port that carries frames for many VLANs over one link, inserting an 802.1Q tag so the far end knows each frame's VLAN. Used between switches and toward routers or wireless controllers.

On the examSwitch-to-switch links carrying several VLANs are trunks. Check show interfaces trunk for the allowed list; a VLAN missing there is the usual cause of a single-VLAN outage.

Don’t confuse with Access Port

UDPUser Datagram ProtocolD1

Connectionless Layer 4 protocol with an 8-byte header and no handshake, acknowledgments or retransmission. It trades reliability for low overhead and delay, which suits voice, video, DNS lookups, DHCP, TFTP, SNMP and syslog.

On the exam'Best effort', 'low latency', 'real-time voice' or 'no session setup' means UDP. Remember DHCP, TFTP, SNMP and syslog run over UDP, a common trap in 'which service uses' questions.

Don’t confuse with TCP

VLANVirtual Local Area NetworkD2

A logical Layer 2 broadcast domain carved out of a switch. Ports in different VLANs cannot talk directly; traffic between them needs a router or Layer 3 switch using router-on-a-stick or SVIs.

On the exam'Separate broadcast domains' or 'isolate departments on one switch' means VLAN. When hosts in two VLANs cannot ping, suspect missing inter-VLAN routing or the VLAN absent from the trunk.

Don’t confuse with VRF

VRFVirtual Routing and ForwardingD1

Running several independent routing tables on one router. Each VRF owns its own interfaces and routes, so overlapping IP ranges from different customers or departments can coexist without leaking into each other.

On the examListed in v1.1 under virtualization fundamentals beside VMs and containers. Cue: 'one router, separate routing tables' or 'two tenants with overlapping addresses'. VLANs segment Layer 2 only.

Don’t confuse with VLAN

WLCWireless LAN ControllerD2

Central device that manages lightweight access points: it pushes configuration, handles RF management, roaming and client authentication. Lightweight APs tunnel control and usually data traffic to it with CAPWAP.

On the examExpect WLC GUI tasks: create a WLAN, map it to an interface or VLAN, set WPA2 PSK. Controllers usually connect to a switch trunk, often bundled with LAG.

WPA3Wi-Fi Protected Access 3D5

Current Wi-Fi security standard. WPA3-Personal replaces the pre-shared key handshake with SAE, which resists offline dictionary attacks and adds forward secrecy; protected management frames are mandatory.

On the examCompare WPA (TKIP), WPA2 (AES-CCMP with PSK or 802.1X) and WPA3 (SAE). Note the hands-on blueprint task still configures a WLAN with WPA2 PSK in the WLC GUI.

Terms the exam loves to confuse

These six pairs cause more wrong CCNA answers than any single term, because both options look right until you find the one detail that separates them.

Administrative DistanceRanks route sources against each other; the lower value wins when a static route and a routing protocol offer the same prefix.

MetricRanks paths inside a single routing protocol, such as OSPF cost; the lower value wins among that protocol's own routes.

The tellSame protocol, two paths: compare metric. Different sources, same prefix length: compare AD. Different prefix lengths: longest match wins before either is checked.

STPLegacy 802.1D loop prevention with blocking, listening, learning and forwarding states; convergence takes 30 to 50 seconds.

RSTPThe 802.1w rapid version with a discarding state, alternate and backup roles, and convergence in seconds via proposal and agreement.

The tellPort states in the answer choices give it away: 'blocking' or 'listening' is legacy STP, 'discarding' is RSTP and Rapid PVST+.

Inside LocalThe inside host's real address as seen on the inside network, normally a private RFC 1918 address configured on the host.

Inside GlobalThe public address that stands in for that same inside host when its traffic reaches the outside world through NAT or PAT.

The tellAsk whose viewpoint the address describes. Seen by the LAN is local; seen by the internet is global. Both labels describe the inside host.

Standard ACLFilters on source IPv4 address only, using numbers 1-99 or 1300-1999 or a name, with an implicit deny at the end.

Extended ACLFilters on source and destination address, protocol and port, using numbers 100-199 or 2000-2699 or a name.

The tellIf the rule mentions a port, protocol or destination, it must be extended. Placement follows: standard near the destination, extended near the source.

RADIUSOpen standard over UDP that encrypts only the password and bundles authentication with authorization; built for end-user network access and 802.1X.

TACACS+Cisco-developed protocol over TCP 49 that encrypts the full payload and splits the three A's; built for administering network devices.

The tellUsers joining the network or Wi-Fi points to RADIUS. Admins logging into routers with per-command authorization points to TACACS+.

Northbound APIFaces up from the controller toward applications, scripts and dashboards, typically REST with JSON payloads.

Southbound APIFaces down from the controller toward switches, routers and access points, using NETCONF, RESTCONF, OpenFlow or CLI.

The tellFind the two endpoints in the stem. App or script talking to the controller is northbound; controller talking to network devices is southbound.

Acronym quick-scan

Cisco does not publish an official CCNA acronym list, so this one is built from the v1.1 exam topics and the protocols they name. Expansions follow Cisco documentation.

  • AAAAuthentication, Authorization, and Accounting
  • ACLAccess Control List
  • ADAdministrative Distance
  • AESAdvanced Encryption Standard
  • AIArtificial Intelligence
  • APAccess Point
  • APIApplication Programming Interface
  • ARPAddress Resolution Protocol
  • BDRBackup Designated Router
  • BPDUBridge Protocol Data Unit
  • CAPWAPControl and Provisioning of Wireless Access Points
  • CCMPCounter Mode with CBC-MAC Protocol
  • CDPCisco Discovery Protocol
  • CIDRClassless Inter-Domain Routing
  • CLICommand-Line Interface
  • CRUDCreate, Read, Update, Delete
  • CSMA/CDCarrier Sense Multiple Access with Collision Detection
  • DAIDynamic ARP Inspection
  • DHCPDynamic Host Configuration Protocol
  • DNSDomain Name System
  • DRDesignated Router
  • DSCPDifferentiated Services Code Point
  • EIGRPEnhanced Interior Gateway Routing Protocol
  • ESPEncapsulating Security Payload
  • EUI-64Extended Unique Identifier, 64-bit
  • FHRPFirst Hop Redundancy Protocol
  • FTPFile Transfer Protocol
  • GLBPGateway Load Balancing Protocol
  • GUIGraphical User Interface
  • HSRPHot Standby Router Protocol
  • HTTPHypertext Transfer Protocol
  • HTTPSHypertext Transfer Protocol Secure
  • IaCInfrastructure as Code
  • ICMPInternet Control Message Protocol
  • IKEInternet Key Exchange
  • IPSIntrusion Prevention System
  • IPsecInternet Protocol Security
  • IPv6Internet Protocol version 6
  • JSONJavaScript Object Notation
  • LACPLink Aggregation Control Protocol
  • LAGLink Aggregation Group
  • LANLocal Area Network
  • LLDPLink Layer Discovery Protocol
  • LSALink-State Advertisement
  • MACMedia Access Control
  • MFAMultifactor Authentication
  • MIBManagement Information Base
  • MLMachine Learning
  • MTUMaximum Transmission Unit
  • NATNetwork Address Translation
  • NETCONFNetwork Configuration Protocol
  • NGFWNext-Generation Firewall
  • NTPNetwork Time Protocol
  • OSPFOpen Shortest Path First
  • PAgPPort Aggregation Protocol
  • PATPort Address Translation
  • PHBPer-Hop Behavior
  • PoEPower over Ethernet
  • PSKPre-Shared Key
  • QoSQuality of Service
  • RADIUSRemote Authentication Dial-In User Service
  • RESTRepresentational State Transfer
  • RFRadio Frequency
  • RSTPRapid Spanning Tree Protocol
  • SAESimultaneous Authentication of Equals
  • SDNSoftware-Defined Networking
  • SLAACStateless Address Autoconfiguration
  • SNMPSimple Network Management Protocol
  • SOHOSmall Office/Home Office
  • SSHSecure Shell
  • SSIDService Set Identifier
  • STPSpanning Tree Protocol
  • SVISwitched Virtual Interface
  • TACACS+Terminal Access Controller Access-Control System Plus
  • TCPTransmission Control Protocol
  • TFTPTrivial File Transfer Protocol
  • TKIPTemporal Key Integrity Protocol
  • UDPUser Datagram Protocol
  • VLANVirtual Local Area Network
  • VPNVirtual Private Network
  • VRFVirtual Routing and Forwarding
  • VRRPVirtual Router Redundancy Protocol
  • WANWide Area Network
  • WLANWireless Local Area Network
  • WLCWireless LAN Controller
  • WPAWi-Fi Protected Access
  • YAMLYAML Ain't Markup Language

How to make the terms stick

CCNA vocabulary sticks when every term is tied to something you can see on a real or simulated device.

  1. Pair every term with a commandFor each term, name the show command that proves it: show spanning-tree for port roles, show ip route for AD and metric, show ip nat translations for inside local and global. No command yet means the term is not yours yet.
  2. Drill the confused pairs out loudTake the six pairs above and state the deciding clue in one sentence without notes. Then reverse it: describe a scenario and name the term. CCNA distractors are usually the other half of one of these pairs.
  3. Break it in a labIn Packet Tracer or another lab, deliberately cause a native VLAN mismatch, an OSPF timer mismatch and a port security violation, then read the output. Terms you have watched fail are the ones you recognise under time pressure.

Knowing the word is not the same as answering the question

Knowing a definition is not the same as spotting it in a show command or a two-line scenario. Our CCNA practice questions test these terms in context, with an explanation for every answer.

App StoreGoogle PlayFree practice testCCNA exam page

FAQ

How many acronyms do I need to know for the CCNA 200-301 exam?

Cisco does not publish an official acronym list for CCNA, unlike CompTIA. Working through the v1.1 exam topics and the protocols they name gives roughly 80 to 90 acronyms, from AAA to YAML. You do not need to recite every expansion, but you must recognise each one instantly in a scenario or a show command, because questions use them without explaining them.

What is the passing score for CCNA 200-301?

Not published. Cisco does not release a fixed passing score or question count for 200-301 and says both can change between exam forms. Candidates commonly report a scaled score target somewhere in the 800s out of 1000 and roughly 100 questions in 120 minutes, but treat those as unofficial estimates and aim to understand every blueprint topic rather than chase a number.

Is the CCNA 200-301 exam changing in 2027?

Yes. Cisco published the CCNA v2.0 exam topics on May 20, 2026. The current v1.1 blueprint remains testable through February 2, 2027, and v2.0 becomes the live exam on February 3, 2027. The exam code stays 200-301, but the blueprint moves from six domains to five and brings back troubleshooting-level topics, so check which version your test date falls under.

Do I need to memorise IOS commands as well as terms?

Yes, for the configure-and-verify topics. The blueprint uses verbs like configure, verify and interpret for VLANs, trunks, EtherChannel, static routes, OSPF, NAT, NTP, ACLs and port security, so expect show output and command choices. For describe and explain topics, such as SDN, FHRP concepts and AI in operations, knowing the term and its role is usually enough.

Sources

Scope and domain names on this page come from Cisco’s published exam objectives; definitions are ours, written for exam prep:

Checked September 30, 2026. Exam objectives are revised on the vendor’s schedule — if a term here is not in the current objectives, the objectives win.