CompTIASeptember 30, 202626 min read

Network+ N10-009 Acronyms & Glossary: 56 Terms (2026)

Every term below maps to a current N10-009 objective. Each card tells you what it means, how CompTIA phrases it in a scenario, and which look-alike answer to rule out.

  • 56Terms defined
  • 85Acronyms
  • N10-009Exam
  • Up to 90Questions
  • 720 / 900Pass mark
CompTIA Network+ N10-009 glossary of networking acronyms and key terms

How to use this glossary

Network+ questions are short scenarios, and the answer usually hinges on one word: a symptom (jitter, CRC errors), a protocol (OSPF or BGP) or a metric (RPO or RTO). If you cannot tell two look-alike acronyms apart in a few seconds, the performance-based questions and the 90-minute clock will punish you. This glossary covers the terms the current objectives actually name, grouped by domain, with the exam angle for each.

This page targets N10-009, which CompTIA launched on June 20, 2024. The English N10-008 exam retired in December 2024, and CompTIA estimates N10-009 will retire around 2027 (roughly three years after launch). N10-009 added newer topics such as SASE, VXLAN, infrastructure as code and zero trust, so older N10-008 flashcard decks will miss them.

Every term below is tagged with the exam domain it belongs to. This is where the vocabulary load sits across the N10-009 blueprint:

  • D1Networking Concepts23%14 terms
  • D2Network Implementation20%13 terms
  • D3Network Operations19%10 terms
  • D4Network Security14%10 terms
  • D5Network Troubleshooting24%9 terms

Each card has three layers: a plain-English definition, an On the exam line describing how questions use the term, and — where one exists — the term it is most often confused with. Click that link to jump straight to the rival definition.

The A–Z glossary

802.1QIEEE VLAN tagging standardD2

The IEEE standard that inserts a 4-byte tag carrying a 12-bit VLAN ID into Ethernet frames, so a single trunk link between switches can carry traffic for many VLANs while keeping them separate.

On the examA scenario with two switches that must share several VLANs over one uplink wants a trunk using 802.1Q tagging, not an access port or link aggregation.

Don’t confuse with Native VLAN

802.1XPort-based network access controlD4

An IEEE standard for port-based access control. A supplicant on the client asks the authenticator (switch or access point) for access, which relays EAP credentials to an authentication server, usually RADIUS, before opening the port.

On the examWhen a question says users must authenticate before a wired port or Wi-Fi network passes any traffic, pick 802.1X. MAC filtering and port security are weaker distractors.

Don’t confuse with RADIUS

ACLAccess Control ListD4

An ordered list of permit and deny rules on a router, switch or firewall that filters traffic by criteria such as source, destination, protocol and port. Rules are checked top-down and the first match applies.

On the examRemember the implicit deny at the end and rule order. A broad permit placed above a specific deny means the deny never matches, a common troubleshooting answer.

Administrative DistanceD2

A number a router assigns to each route source to rank how trustworthy it is. Lower wins: connected is 0, static is 1, eBGP 20, EIGRP 90 and OSPF 110 on Cisco-style defaults.

On the examUsed only when the same prefix is learned from two sources. Expect a question where OSPF and a static route both offer 10.0.0.0/8 and you must pick the static route.

Don’t confuse with Longest Prefix Match

APIPAAutomatic Private IP AddressingD1

A fallback that lets a Windows host give itself an address in 169.254.0.0/16 when no DHCP server answers. The host can reach neighbors on the same link but has no gateway.

On the examA user with a 169.254.x.x address and no internet is the classic tell: the DHCP server, relay or scope is the problem, not DNS or the browser.

Don’t confuse with SLAAC

ARP SpoofingAlso ARP poisoningD4

Sending forged ARP replies on a local segment so other hosts map a trusted IP address, usually the default gateway, to the attacker's MAC address, redirecting their traffic through the attacker.

On the examDuplicate MAC entries for the gateway IP in arp -a output signals ARP spoofing. Dynamic ARP inspection on the switch is the mitigation to pick.

Don’t confuse with On-Path Attack

AttenuationD5

The gradual loss of signal strength as it travels along copper, fiber or through the air. Too much loss makes the receiver misread bits, which is why twisted-pair Ethernet runs are limited to 100 meters.

On the examA cable run longer than 100 meters, or a long fiber path with dirty connectors, points to attenuation. Fixes are shorter runs, a switch or repeater midway, or fiber.

BGPBorder Gateway ProtocolD2

The path-vector routing protocol that exchanges routes between autonomous systems, such as between an enterprise and its ISPs or across the internet. It chooses paths using attributes and policy rather than a simple speed metric.

On the examKeywords like multiple ISPs, autonomous system numbers or internet edge routing point to BGP. If the scenario is routing inside one company campus, OSPF is usually the answer.

Don’t confuse with OSPF

BSSIDBasic Service Set IdentifierD2

The unique identifier of one access point radio's wireless cell, normally the radio's MAC address. Several APs can broadcast the same network name while each keeps its own BSSID.

On the examWi-Fi analyzer output showing one SSID with several different MAC-style values means several APs or radios. Seeing an unknown BSSID for your corporate SSID suggests an evil twin.

Don’t confuse with SSID

Channel OverlapD5

Interference caused when nearby access points use channels whose frequency ranges overlap. In the 2.4 GHz band only channels 1, 6 and 11 avoid overlapping each other in North America.

On the examSlow Wi-Fi in a dense office with neighboring APs on channels 1, 3 and 6 is a channel overlap problem. The fix is re-planning channels, not adding power.

CIDRClassless Inter-Domain RoutingD1

The addressing method that replaces fixed class boundaries with a prefix length, written as a slash such as /26. The prefix sets the network portion, and the remaining host bits decide how many addresses the subnet holds.

On the examExpect subnet math: a /26 gives 64 addresses and 62 usable hosts, mask 255.255.255.192. Questions ask for the smallest prefix that fits a stated number of hosts.

CRC ErrorCyclic Redundancy Check errorD5

A frame whose checksum does not match its contents when it arrives, so the receiving interface discards it. The counter climbs when bits are being corrupted on the wire.

On the examRising CRC counters on a switch interface usually mean a bad cable, EMI or a duplex mismatch. Replace or re-terminate the cable before changing VLANs or routing.

DHCP RelayAlso called IP helperD3

A router or Layer 3 switch function that forwards DHCP broadcasts from clients on one subnet to a DHCP server on another subnet, since routers do not pass broadcasts by default.

On the examNew VLAN clients get APIPA addresses while other VLANs work fine and the server is central: configure a DHCP relay or IP helper on that VLAN's gateway interface.

DNSSECDomain Name System Security ExtensionsD3

Extensions that add digital signatures to DNS records so a resolver can verify that answers really came from the authoritative zone and were not altered. They prove integrity and origin but do not encrypt queries.

On the examPick DNSSEC to stop forged or poisoned DNS answers. If the question is about hiding DNS queries from eavesdroppers, DNS over HTTPS or over TLS fits instead.

Dual StackD1

Running IPv4 and IPv6 at the same time on the same hosts and network devices, so each connection can use whichever protocol the destination supports during a gradual IPv6 migration.

On the examWhen a scenario needs IPv6 rolled out without breaking IPv4 services, dual stack is the usual answer. Tunneling and NAT64 are the alternatives when one side is single-protocol.

Evil TwinD4

An attacker-controlled access point that copies a legitimate network's SSID, and sometimes its captive portal, to lure users into connecting so their traffic or credentials can be captured.

On the examUsers near a coffee shop or lobby see the company SSID twice and get a strange login page. That impersonation is an evil twin, a type of rogue AP used for on-path attacks.

Don’t confuse with Rogue Access Point

FHRPFirst Hop Redundancy ProtocolD2

A family of protocols, including HSRP, VRRP and GLBP, that lets two or more routers share a virtual IP address used as hosts' default gateway, so a backup takes over if the active router fails.

On the examHosts lose all off-subnet access when one gateway router dies. The fix that keeps the same gateway IP on every host is an FHRP with a virtual IP.

IaCInfrastructure as CodeD1

Defining network and cloud infrastructure in machine-readable templates or scripts, kept in version control, so environments can be built, changed and rebuilt consistently through automation instead of manual configuration.

On the examLook for configuration drift, repeatable deployments or playbooks and templates in version control. IaC is one of the newer N10-009 objectives alongside SASE and VXLAN.

IPsecInternet Protocol SecurityD1

A suite that secures IP packets at Layer 3. IKE negotiates keys, AH provides integrity and authentication without encryption, and ESP adds encryption. It runs in tunnel or transport mode and underpins most site-to-site VPNs.

On the examIf the question needs confidentiality, ESP is required because AH does not encrypt. Site-to-site VPN between two offices over the internet usually means IPsec in tunnel mode.

JitterD5

The variation in delay between packets that should arrive at a steady rate. Real-time traffic such as voice and video suffers when packets arrive unevenly, even if average delay is acceptable.

On the examChoppy or robotic VoIP calls with low average ping points to jitter. The expected fixes are QoS prioritizing voice traffic and reducing congestion, not more bandwidth alone.

Don’t confuse with Latency

LatencyD5

The time a packet takes to travel from source to destination, usually measured as round-trip time in milliseconds. Distance, queuing, and slow links or devices all add to it.

On the examConsistently high delay on a satellite link or distant cloud region is latency. Tools like ping and traceroute measure it and show which hop adds the delay.

Don’t confuse with Jitter

Longest Prefix MatchD2

The rule a router applies first when choosing a route: of all routing table entries that contain the destination address, the one with the most specific prefix, the longest mask, wins.

On the examGiven routes to 10.1.0.0/16 and 10.1.5.0/24, traffic for 10.1.5.9 uses the /24, even if the /16 has a better administrative distance.

Don’t confuse with Administrative Distance

MTTRMean Time to RepairD3

The average time taken to fix a failed component and return it to service, calculated from past incidents. It measures actual repair performance rather than a business target.

On the examMTTR is measured history; RTO is a goal. If a question describes averaging how long past repairs took, the answer is MTTR, not RTO or MTBF.

Don’t confuse with RTO

Multimode FiberMMFD1

Optical fiber with a wider core, typically 50 or 62.5 microns, that carries multiple light paths from LED or VCSEL sources. It is cheaper but suited to shorter runs inside buildings and data centers.

On the examA mismatched transceiver or patch cable is a common troubleshooting answer: a multimode SFP on a single-mode run will not link reliably. Short in-building runs point to multimode.

Don’t confuse with Single-Mode Fiber

Native VLAND2

The VLAN whose frames cross an 802.1Q trunk without a tag. Both ends of the trunk must agree on it, and by default it is often VLAN 1.

On the examA native VLAN mismatch between two trunk ends causes traffic leaking between VLANs. Security questions recommend changing it from VLAN 1 to an unused VLAN to limit VLAN hopping.

Don’t confuse with 802.1Q

On-Path AttackFormerly man-in-the-middleD4

An attack where the adversary places themselves between two communicating parties so they can read, alter or relay traffic without either side noticing. ARP spoofing and evil twins are common ways to get there.

On the examCompTIA uses the term on-path rather than man-in-the-middle. Any scenario where intercepted traffic is silently modified in transit is an on-path attack; encryption like TLS is the mitigation.

Don’t confuse with ARP Spoofing

OSI ModelOpen Systems Interconnection modelD1

A seven-layer reference model describing how network communication is divided: physical, data link, network, transport, session, presentation and application. Each layer serves the one above and relies on the one below.

On the examQuestions ask which layer a device or problem belongs to: switches and MAC addresses at Layer 2, routers and IP at Layer 3, TCP and UDP ports at Layer 4.

OSPFOpen Shortest Path FirstD2

A link-state interior gateway protocol in which routers flood link information, build a full map of the area and calculate best paths with a cost metric based on bandwidth. It supports areas for scaling.

On the examPick OSPF for a fast-converging, vendor-neutral dynamic routing protocol inside one organization. Link-state, areas and cost are the keywords; distance vector and hop count are distractors.

Don’t confuse with BGP

Out-of-Band ManagementD3

Managing network devices through a separate path, such as a console server, dedicated management network or cellular modem, that does not depend on the production network being up.

On the examIf a router's misconfiguration has cut off SSH access, out-of-band management through the console port is how you reach it. In-band uses the same production network.

PATPort Address TranslationD2

A form of NAT, also called NAT overload, that maps many private inside addresses to one public address by tracking a unique source port for each session.

On the examA small office with dozens of devices and one public IP from its ISP uses PAT. Static one-to-one NAT is the distractor when a single inside server must be reachable.

PoEPower over EthernetD5

Delivering DC power and data over the same twisted-pair cable. Standards include 802.3af at 15.4 W, 802.3at PoE+ at 30 W and 802.3bt at up to 60 or 90 W per port.

On the examNew cameras or APs that stay dark while older ones work suggest the switch's total PoE power budget is exceeded or the device needs a higher standard than the port supplies.

RADIUSRemote Authentication Dial-In User ServiceD4

An open AAA protocol that centralizes authentication for network access such as Wi-Fi, VPN and 802.1X. It runs over UDP and encrypts only the password field of the exchange.

On the examChoose RADIUS for authenticating end users onto the network, especially WPA2/WPA3-Enterprise and 802.1X. UDP and password-only encryption are the details that separate it from TACACS+.

Don’t confuse with TACACS+

Rogue Access PointD4

Any wireless access point attached to the network without authorization, such as a consumer router an employee plugs into a wall jack. It creates an uncontrolled path around the network's security.

On the examAn unapproved AP found plugged into an office port during a wireless survey is a rogue AP. Mitigations are 802.1X on switch ports and wireless intrusion detection.

Don’t confuse with Evil Twin

RPORecovery Point ObjectiveD3

The maximum amount of data, measured as time, that the business can afford to lose in an outage. It sets how often backups or replication must run.

On the examIf losing more than four hours of transactions is unacceptable, the RPO is four hours, so backups must run at least that often. Data loss equals RPO.

Don’t confuse with RTO

RTORecovery Time ObjectiveD3

The maximum acceptable time a system or service can be down before it must be restored after a disruption. It drives choices such as hot versus cold disaster recovery sites.

On the examA requirement that the service be back online within two hours is an RTO. A short RTO pushes the answer toward a hot site or active-active high availability.

Don’t confuse with MTTR

SASESecure Access Service EdgeD1

A cloud-delivered architecture that combines SD-WAN networking with security services such as secure web gateway, CASB, zero trust network access and firewall as a service, applied close to users wherever they connect.

On the examRemote and branch users needing consistent security without backhauling to headquarters points to SASE. SSE is the security-only subset without the SD-WAN piece.

Don’t confuse with SD-WAN

Screened SubnetFormerly DMZD4

A network segment between the internet and the internal network, protected by firewall rules, where public-facing servers such as web and mail are placed so a compromise does not expose internal hosts.

On the examCompTIA now says screened subnet rather than DMZ. A public web server that must be reachable from outside while isolated from internal systems belongs there.

SD-WANSoftware-Defined Wide Area NetworkD1

A WAN approach that uses a central controller to manage branch connections across several transports, such as broadband, MPLS and LTE, and steer each application over the best path based on policy.

On the examBranch offices wanting to use cheap broadband alongside MPLS with application-aware path selection and central management point to SD-WAN. It handles connectivity, not cloud security.

Don’t confuse with SASE

SIEMSecurity Information and Event ManagementD3

A platform that collects logs and events from many devices, normalizes and correlates them, and raises alerts or reports when patterns suggest an incident or policy violation.

On the examNeeding one place to aggregate syslog from firewalls, switches and servers and correlate events points to SIEM. SNMP polls device health; it does not correlate security logs.

Don’t confuse with SNMP

Single-Mode FiberSMFD1

Optical fiber with a very narrow core, about 9 microns, that carries a single light path from a laser source. It supports much longer distances, into tens of kilometers, than multimode.

On the examLinks between buildings kilometers apart need single-mode fiber and matching transceivers. Yellow jackets often signal single-mode; mismatched optics are a common troubleshooting cause.

Don’t confuse with Multimode Fiber

SLAACStateless Address AutoconfigurationD3

An IPv6 method where a host builds its own global address from the network prefix announced in router advertisements plus an interface identifier, without needing a DHCP server.

On the examIPv6 hosts getting addresses with no DHCPv6 server configured are using SLAAC. Do not confuse it with APIPA, which is the IPv4 failure fallback.

Don’t confuse with APIPA

SNMPSimple Network Management ProtocolD3

A protocol for monitoring and managing network devices. Managers poll agents on UDP 161, agents send unsolicited traps on UDP 162, and data is organized in a MIB. Version 3 adds authentication and encryption.

On the examChoose SNMPv3 when monitoring must be secure; v2c sends community strings in plaintext. Traps are the push-alert answer, polling is the scheduled-query answer.

Don’t confuse with SIEM

Split TunnelD3

A client VPN setting that sends only traffic for corporate networks through the encrypted tunnel, while other internet traffic goes directly out the user's local connection.

On the examSplit tunnel saves VPN bandwidth; full tunnel sends everything through headquarters for inspection. Remote users slowing the VPN with streaming traffic suggests enabling split tunnel.

SSIDService Set IdentifierD2

The human-readable name a wireless network advertises, such as CorpWiFi. Several access points can share one SSID so clients can roam between them as a single network.

On the examHiding the SSID is not real security, a frequent distractor. Separate SSIDs mapped to separate VLANs are the usual answer for isolating guest users from staff.

Don’t confuse with BSSID

STPSpanning Tree ProtocolD2

An IEEE 802.1D protocol that prevents Layer 2 loops in switched networks with redundant links by electing a root bridge and placing some ports into a blocking state until they are needed.

On the examA sudden broadcast storm after someone adds a redundant cable between switches means STP is off or misconfigured. Root bridge election uses the lowest bridge ID.

TACACS+Terminal Access Controller Access-Control System PlusD4

An AAA protocol developed by Cisco for administering network devices. It runs over TCP port 49, encrypts the entire payload, and separates authentication, authorization and accounting so individual commands can be authorized.

On the examChoose TACACS+ when admins logging into routers and switches need per-command authorization and full encryption. TCP and separated AAA are the clues over RADIUS.

Don’t confuse with RADIUS

TCPTransmission Control ProtocolD1

A connection-oriented Layer 4 protocol that sets up sessions with a three-way handshake, numbers segments, acknowledges delivery and retransmits lost data so the application receives a complete, ordered stream.

On the examReliability, SYN/SYN-ACK/ACK, sequencing and acknowledgments point to TCP. Protocols like HTTPS, SSH and SMTP run on TCP; ask whether guaranteed delivery matters.

Don’t confuse with UDP

Toner ProbeTone generator and probeD5

A two-piece tool: the generator puts an audible signal on a cable at one end, and the probe detects it at the other end to identify which cable or patch panel port it is.

On the examFinding which unlabeled cable in a bundle or patch panel goes to a specific office is a toner probe job. Cable testers verify wiring; they do not locate cables.

traceroutetracert on WindowsD5

A command that reveals each router hop on the path to a destination by sending packets with increasing TTL values and recording the replies from each hop that expires them.

On the examUse traceroute when ping fails and you need to find where along the path traffic stops or delay jumps. tracert is the Windows command name.

Troubleshooting MethodologyCompTIA seven-step processD5

CompTIA's ordered process: identify the problem, establish a theory, test the theory, plan and identify effects, implement or escalate, verify full functionality and add preventive measures, then document findings and lessons learned.

On the examQuestions ask what to do next. Question users and duplicate the issue come first; documentation always comes last. Implementing a fix before testing the theory is wrong.

UDPUser Datagram ProtocolD1

A connectionless Layer 4 protocol that sends datagrams without a handshake, acknowledgments or retransmission. It has low overhead, making it suited to real-time traffic and simple query-response services.

On the examDNS queries, DHCP, TFTP, SNMP, syslog and VoIP media use UDP. Scenarios stressing speed over guaranteed delivery, or streaming voice and video, point to UDP.

Don’t confuse with TCP

VLANVirtual Local Area NetworkD2

A logical Layer 2 segment created on a switch so ports in different VLANs are in separate broadcast domains, even on the same hardware. Traffic between VLANs must be routed.

On the examSegmenting departments, voice phones or IoT devices on shared switches points to VLANs. Hosts in different VLANs that cannot talk need a router or Layer 3 switch with SVIs.

Don’t confuse with VXLAN

VLAN HoppingD4

An attack that lets a host send traffic into a VLAN it should not reach, either by pretending to be a switch to form a trunk or by double tagging frames using the native VLAN.

On the examMitigations to pick: disable automatic trunk negotiation, set access ports statically, and change the native VLAN to an unused one. Double tagging is the keyword.

Don’t confuse with Native VLAN

VXLANVirtual Extensible LAND1

An overlay that wraps Layer 2 Ethernet frames inside UDP packets so they can cross a Layer 3 network. Its 24-bit identifier allows about 16 million segments, versus 4,094 usable VLANs.

On the examData center or cloud scenarios needing to stretch Layer 2 across a routed fabric, or more segments than VLANs allow, point to VXLAN. It is new to N10-009.

Don’t confuse with VLAN

Well-Known PortsPorts 0-1023D1

The port range reserved for common services, such as SSH on 22, DNS on 53 and HTTPS on 443; registered ports such as RDP on 3389 sit above it. Ports identify which application on a host receives traffic.

On the examMemorize the objectives' port table. Questions give a port and ask for the service, or ask which port a firewall ACL must open, such as 636 for LDAPS or 5060 for SIP.

WPA3Wi-Fi Protected Access 3D2

The current Wi-Fi security standard. WPA3-Personal replaces the pre-shared key handshake with SAE, which resists offline password guessing, and WPA3-Enterprise offers a stronger 192-bit mode.

On the examPick WPA3 when asked for the most secure wireless option. Personal uses a passphrase via SAE; Enterprise adds 802.1X and RADIUS for individual user credentials.

Terms the exam loves to confuse

These six pairs produce most of the wrong answers we see on Network+ practice questions. Learn the one clue that separates each.

TCPConnection-oriented transport with a handshake, sequencing, acknowledgments and retransmission of lost segments for guaranteed ordered delivery.

UDPConnectionless transport that fires off datagrams with no handshake or acknowledgment, trading reliability for low overhead and speed.

The tellIf the scenario stresses guaranteed delivery or mentions a handshake, pick TCP; if it stresses real-time voice, video or simple queries, pick UDP.

Administrative DistanceA trust ranking for route sources, lower is better, used to choose between routes to the exact same prefix.

Longest Prefix MatchThe first rule in route selection: the most specific matching route, the one with the longest mask, wins.

The tellDifferent prefix lengths? Longest prefix wins, full stop. Same prefix from different protocols? Then administrative distance decides.

RPOThe maximum data loss the business accepts, measured backward in time from the outage; it sets backup frequency.

RTOThe maximum downtime the business accepts before the service must be running again; it sets recovery site and HA choices.

The tellPoint equals data, time equals downtime. If the requirement is about lost transactions, it is RPO; about being back online, RTO.

RADIUSOpen AAA protocol over UDP that encrypts only the password and combines authentication with authorization, used for user network access.

TACACS+Cisco-developed AAA protocol over TCP 49 that encrypts the whole payload and separates AAA functions for device administration.

The tellEnd users joining Wi-Fi or VPN points to RADIUS; admins needing per-command authorization on routers and switches points to TACACS+.

Evil TwinAn attacker AP broadcasting the same SSID as a legitimate network to trick users into connecting to it.

Rogue Access PointAny unauthorized AP connected to the network, often plugged in by an employee, that bypasses security controls.

The tellImpersonating the real network name means evil twin. An unapproved device plugged into the wired network, whatever its name, is a rogue AP.

JitterVariation in packet delay over time that makes real-time audio and video choppy even when average delay is low.

LatencyThe travel time for a packet from source to destination, often measured as round-trip time in milliseconds.

The tellChoppy or robotic voice with acceptable ping means jitter; uniformly slow responses or long round-trip times mean latency.

Acronym quick-scan

CompTIA prints a multi-page acronym list at the end of the official N10-009 objectives and advises candidates to know them all; CompTIA does not headline a count. Below are 85 of the ones that show up most in questions.

  • AAAAuthentication, Authorization, and Accounting
  • ACLAccess Control List
  • AHAuthentication Header
  • APAccess Point
  • APIPAAutomatic Private IP Addressing
  • ARPAddress Resolution Protocol
  • BGPBorder Gateway Protocol
  • BNCBayonet Neill-Concelman
  • BSSIDBasic Service Set Identifier
  • BYODBring Your Own Device
  • CDNContent Delivery Network
  • CDPCisco Discovery Protocol
  • CIDRClassless Inter-Domain Routing
  • CNAMECanonical Name
  • CRCCyclic Redundancy Check
  • DACDirect Attach Copper
  • DDoSDistributed Denial-of-Service
  • DHCPDynamic Host Configuration Protocol
  • DNSDomain Name System
  • DNSSECDomain Name System Security Extensions
  • DoHDNS over HTTPS
  • DoTDNS over TLS
  • EAPExtensible Authentication Protocol
  • EIGRPEnhanced Interior Gateway Routing Protocol
  • EOLEnd of Life
  • EOSEnd of Support
  • ESPEncapsulating Security Payload
  • FHRPFirst Hop Redundancy Protocol
  • FTPFile Transfer Protocol
  • GDPRGeneral Data Protection Regulation
  • GREGeneric Routing Encapsulation
  • HTTPSHypertext Transfer Protocol Secure
  • IaaSInfrastructure as a Service
  • IaCInfrastructure as Code
  • ICMPInternet Control Message Protocol
  • ICSIndustrial Control System
  • IDFIntermediate Distribution Frame
  • IDSIntrusion Detection System
  • IKEInternet Key Exchange
  • IoTInternet of Things
  • IPAMIP Address Management
  • IPSIntrusion Prevention System
  • IPsecInternet Protocol Security
  • LACPLink Aggregation Control Protocol
  • LDAPLightweight Directory Access Protocol
  • LDAPSLightweight Directory Access Protocol over SSL
  • LLDPLink Layer Discovery Protocol
  • MACMedia Access Control
  • MDFMain Distribution Frame
  • MFAMultifactor Authentication
  • MIBManagement Information Base
  • MTBFMean Time Between Failures
  • MTTRMean Time to Repair
  • MTUMaximum Transmission Unit
  • NACNetwork Access Control
  • NATNetwork Address Translation
  • NFVNetwork Functions Virtualization
  • NTPNetwork Time Protocol
  • OSPFOpen Shortest Path First
  • PATPort Address Translation
  • PDUPower Distribution Unit
  • PKIPublic Key Infrastructure
  • PoEPower over Ethernet
  • PTPPrecision Time Protocol
  • QoSQuality of Service
  • QSFPQuad Small Form-factor Pluggable
  • RADIUSRemote Authentication Dial-In User Service
  • RDPRemote Desktop Protocol
  • RPORecovery Point Objective
  • RTORecovery Time Objective
  • SASESecure Access Service Edge
  • SCADASupervisory Control and Data Acquisition
  • SD-WANSoftware-Defined Wide Area Network
  • SDNSoftware-Defined Networking
  • SFPSmall Form-factor Pluggable
  • SIEMSecurity Information and Event Management
  • SIPSession Initiation Protocol
  • SLAACStateless Address Autoconfiguration
  • SNMPSimple Network Management Protocol
  • SSESecurity Service Edge
  • SSIDService Set Identifier
  • STPSpanning Tree Protocol (also Shielded Twisted Pair)
  • SVISwitch Virtual Interface
  • VXLANVirtual Extensible Local Area Network
  • ZTAZero Trust Architecture

How to make the terms stick

Reading this page once will not survive a 90-question scenario exam; use these three steps.

  1. Build the port and layer grid firstDraw a table with protocol, port, TCP or UDP, and OSI layer, then fill it from memory daily until it is automatic. Many recall and firewall questions lean on exactly that grid.
  2. Learn look-alikes as pairsStudy RPO with RTO, RADIUS with TACACS+, and evil twin with rogue AP together. For each pair write the single deciding clue, because CompTIA almost always puts the twin in the answer options.
  3. Tie every term to a symptomFor troubleshooting terms, practice in reverse: read a symptom such as 169.254 addresses, rising CRC counters or choppy calls, and name the cause and the tool. Domain 5 is the largest at 24 percent.

Knowing the word is not the same as answering the question

Knowing a definition is not the same as spotting it inside a four-line scenario. Practice questions make you apply these terms under time pressure, the way N10-009 does.

App StoreGoogle PlayFree practice testNetwork+ exam page

FAQ

How many acronyms are on the Network+ N10-009 exam?

CompTIA includes a multi-page acronym list at the end of the N10-009 exam objectives and recommends a working knowledge of all of them, but it does not advertise an exact count. Not every acronym appears on every exam form. Focus first on protocols, ports, routing and wireless terms, and the DR metrics, since those show up most often in scenario questions.

Do I need to memorize every Network+ acronym?

You need to recognize them, not recite textbook definitions. Questions rarely ask what an acronym stands for; they describe a situation and expect you to pick the right protocol, attack or tool. Know the expansion well enough to reason about the purpose, and spend extra time on look-alikes like RPO and RTO or SSID and BSSID.

What new terms did N10-009 add compared with N10-008?

N10-009 puts more weight on modern and cloud networking. Newer objective terms include SASE and SSE, VXLAN, infrastructure as code, zero trust architecture, and cloud networking concepts such as VPCs and network security groups. N10-008 retired in December 2024, so study materials built only for it can miss these topics.

Which Network+ domain has the most terms to learn?

Networking Concepts, at 23 percent, has the densest vocabulary: the OSI model, ports and protocols, IPv4 subnetting, IPv6 and newer architectures. Network Troubleshooting is the largest domain at 24 percent, but it mostly tests applying terms from the other domains to symptoms, commands and tools.

Sources

Scope and domain names on this page come from CompTIA’s published exam objectives; definitions are ours, written for exam prep:

Checked September 30, 2026. Exam objectives are revised on the vendor’s schedule — if a term here is not in the current objectives, the objectives win.