Definitions

Every term from the course in one searchable list.

566 terms
Domain 1 — Networking Concepts 55
anycast
Network traffic routed to whichever of several devices sharing the same address is nearest or best able to respond.
Ports, Protocols & Traffic Types · Domain 1
APIPA
Automatic Private IP Addressing — a self-assigned address in the 169.254.0.0/16 range that a device uses when it can't reach a DHCP server.
IP Addressing · Domain 1
binary
A number system using only two digits, 0 and 1, which is how computers represent and process data at the lowest level.
IP Addressing · Domain 1
bit
A single binary digit, either 0 or 1 — the smallest unit of digital information.
IP Addressing · Domain 1
block size
The number of addresses in each subnet, equal to 256 minus the mask's value in the interesting octet (also called the magic number).
Subnetting · Domain 1
borrowed bits
Host bits that have been reassigned to the network portion of an address, in order to create additional, smaller subnets.
Subnetting · Domain 1
broadcast
Network traffic sent from one sender to every device on the local network segment.
Ports, Protocols & Traffic Types · Domain 1
broadcast address
The last address in a subnet's range, which delivers to every device on that subnet at once and can never be assigned to an individual host.
Subnetting · Domain 1
CIDR
Classless Inter-Domain Routing — the slash notation (like /24) used as shorthand for a subnet mask's number of network bits.
IP Addressing · Domain 1
community cloud
Cloud infrastructure shared by several organizations with common needs or regulations, splitting the cost among themselves.
Cloud Concepts & Connectivity · Domain 1
DHCP
Dynamic Host Configuration Protocol — automatically assigns IP addresses and network settings to devices, using UDP ports 67 and 68.
Ports, Protocols & Traffic Types · Domain 1
direct connect
A dedicated, private physical connection from an organization's network straight to a cloud provider, bypassing the public internet.
Cloud Concepts & Connectivity · Domain 1
DNS
Domain Name System — the service that translates human-friendly domain names into IP addresses.
Ports, Protocols & Traffic Types · Domain 1
dynamic IP
An IP address automatically assigned by a DHCP server, which can change over time as leases renew.
IP Addressing · Domain 1
elasticity
The ability to automatically and quickly increase or decrease the resources assigned to a workload based on real-time demand.
Cloud Concepts & Connectivity · Domain 1
FTP
File Transfer Protocol — an unencrypted protocol for transferring files, using TCP ports 20 (data) and 21 (control).
Ports, Protocols & Traffic Types · Domain 1
HTTP
Hypertext Transfer Protocol — the unencrypted protocol used to load web pages, running on TCP port 80.
Ports, Protocols & Traffic Types · Domain 1
HTTPS
HTTP Secure — the encrypted version of HTTP, using TLS to protect web traffic, running on TCP port 443.
Ports, Protocols & Traffic Types · Domain 1
hybrid cloud
A cloud deployment that combines private (or on-premises) infrastructure with public cloud infrastructure, working together.
Cloud Concepts & Connectivity · Domain 1
IaaS
Infrastructure as a Service — a cloud model where the provider manages hardware, storage, and networking, while the customer manages the operating system and everything above it.
Cloud Concepts & Connectivity · Domain 1
IP address
A numerical address that uniquely identifies a device on a network, used to deliver data to the right destination.
IP Addressing · Domain 1
IPv4
Internet Protocol version 4 — the 32-bit addressing scheme, written in dotted decimal, that most networks are built on.
IP Addressing · Domain 1
IPv6
Internet Protocol version 6 — the 128-bit addressing scheme, written in colon-separated hexadecimal, designed to solve IPv4 address exhaustion.
IP Addressing · Domain 1
Layer 2
The Data Link layer of the OSI model — handles MAC addressing and framing on the local network segment.
Networking Appliances & Functions · Domain 1
LDAP
Lightweight Directory Access Protocol — used to look up and manage directory information, such as user accounts, on TCP port 389.
Ports, Protocols & Traffic Types · Domain 1
loopback
A special address (127.0.0.1, within the 127.0.0.0/8 block) that always refers back to the device itself, used to test its own network stack.
IP Addressing · Domain 1
MAC address
A hardware address burned into a network interface card by its manufacturer, used to identify a device at Layer 2.
Networking Appliances & Functions · Domain 1
magic number
The block size used in the fast subnetting shortcut — 256 minus the subnet mask's value in the interesting octet.
Subnetting · Domain 1
multicast
Network traffic sent from one sender to a specific group of interested receivers.
Ports, Protocols & Traffic Types · Domain 1
network address
The first address in a subnet's range, which identifies the subnet itself and can never be assigned to an individual host — also called the subnet ID.
Subnetting · Domain 1
octet
One of the four 8-bit sections of an IPv4 address, each represented as a decimal number from 0 to 255.
IP Addressing · Domain 1
PaaS
Platform as a Service — a cloud model where the provider manages hardware and the operating system, and the customer only manages their application and its data.
Cloud Concepts & Connectivity · Domain 1
port security
A managed-switch feature that restricts which devices, often by MAC address, are allowed to connect to a given switch port.
Networking Appliances & Functions · Domain 1
prefix length
The number after the slash in CIDR notation (like the 24 in /24), stating how many bits of the address are network bits.
Subnetting · Domain 1
private cloud
Cloud infrastructure dedicated entirely to a single organization, not shared with other customers.
Cloud Concepts & Connectivity · Domain 1
private IP
An IP address from one of the RFC 1918 ranges, reserved for use inside private networks and never routed directly on the public internet.
IP Addressing · Domain 1
public cloud
Cloud infrastructure owned and operated by a third-party provider and shared across many different customers.
Cloud Concepts & Connectivity · Domain 1
public IP
An IP address that is globally unique and routable across the public internet.
IP Addressing · Domain 1
RDP
Remote Desktop Protocol — provides remote access to a full graphical desktop, running on TCP port 3389.
Ports, Protocols & Traffic Types · Domain 1
SaaS
Software as a Service — a cloud model where the provider manages everything, including the application itself; the customer simply uses the finished software.
Cloud Concepts & Connectivity · Domain 1
scalability
The general ability of a system to grow and handle increased load, whether by scaling up or scaling out.
Cloud Concepts & Connectivity · Domain 1
SFTP
SSH File Transfer Protocol — a secure, encrypted way to transfer files that runs over an SSH connection on TCP port 22.
Ports, Protocols & Traffic Types · Domain 1
SNMP
Simple Network Management Protocol — used to monitor and manage network devices, using UDP ports 161 and 162.
Ports, Protocols & Traffic Types · Domain 1
SSH
Secure Shell — an encrypted protocol for remote command-line access, running on TCP port 22.
Ports, Protocols & Traffic Types · Domain 1
static IP
A manually configured IP address that stays fixed and doesn't change on its own.
IP Addressing · Domain 1
subnet
A logically segmented portion of a larger network, created by dividing up a range of IP addresses.
Subnetting · Domain 1
subnet mask
A 32-bit value that marks which bits of an IP address are the network portion and which are the host portion.
IP Addressing · Domain 1
Subnetting
The process of dividing one larger network into several smaller networks, each with its own range of addresses.
Subnetting · Domain 1
TCP
Transmission Control Protocol — a connection-oriented Transport-layer protocol that guarantees reliable, ordered delivery through acknowledgments and retransmission.
Ports, Protocols & Traffic Types · Domain 1
Telnet
An unencrypted protocol for remote command-line access, running on TCP port 23 — largely obsolete in favor of SSH.
Ports, Protocols & Traffic Types · Domain 1
UDP
User Datagram Protocol — a connectionless Transport-layer protocol that sends data quickly with no guarantee of delivery or ordering.
Ports, Protocols & Traffic Types · Domain 1
unicast
Network traffic sent from one sender to exactly one specific receiver.
Ports, Protocols & Traffic Types · Domain 1
VLAN
Virtual LAN — a way to logically separate devices into different network segments on the same physical switch, without needing separate hardware.
Networking Appliances & Functions · Domain 1
VPC
Virtual Private Cloud — a logically isolated, private section of a public cloud provider's infrastructure, reserved for one customer.
Cloud Concepts & Connectivity · Domain 1
VPN
Virtual Private Network — an encrypted tunnel that lets a device or network securely connect to another network over the public internet.
Cloud Concepts & Connectivity · Domain 1
Domain 2 — Network Implementation 102
802.1Q
The IEEE standard that defines how VLAN tags are inserted into an Ethernet frame so a trunk link can carry traffic for multiple VLANs.
Routing & Switching · Domain 2
802.1X
A port-based authentication standard that requires a client to authenticate through a central server before it's allowed onto the network — the basis for WPA2/WPA3-Enterprise.
Wireless Networking · Domain 2
administrative distance
A trustworthiness ranking (0–255) a router uses to choose between routes to the same destination learned from different sources — lower always wins.
Routing & Switching · Domain 2
AES
Advanced Encryption Standard — the strong encryption algorithm that protects data on WPA2 and WPA3 wireless networks.
Wireless Networking · Domain 2
ARP
Address Resolution Protocol — resolves a known IP address into the MAC address needed to actually deliver a frame on the local network.
Routing & Switching · Domain 2
attenuation
The gradual weakening of a signal as it travels farther down a cable — the reason every cable type has a maximum usable distance before the signal becomes too weak to read reliably.
Physical Installations & Cabling · Domain 2
autonomous AP
A standalone access point that holds its own configuration and manages itself, without depending on a central controller — practical for a handful of APs.
Wireless Networking · Domain 2
autonomous system
A large network or group of networks under one organization's administrative control, such as an ISP, that shares a single routing policy — BGP is the protocol that routes between them.
Routing & Switching · Domain 2
backbone cabling
The cabling that connects distribution points to each other, such as an MDF to an IDF, forming the main pathways of a structured cabling system.
Physical Installations & Cabling · Domain 2
band
A range of radio frequencies a wireless technology transmits on — Wi-Fi uses the 2.4 GHz, 5 GHz, and (with Wi-Fi 6E) 6 GHz bands, each with a different range-versus-speed tradeoff.
Wireless Networking · Domain 2
BASE-T
Shorthand used in Ethernet standard names (like 1000BASE-T) meaning the standard runs baseband signaling over twisted-pair copper cable.
Physical Installations & Cabling · Domain 2
BGP
Border Gateway Protocol — the path-vector protocol that routes traffic between autonomous systems across the internet itself.
Routing & Switching · Domain 2
broadcast domain
The set of devices that receive a broadcast sent by any one device in the group — routers (and VLANs) separate broadcast domains; switches alone do not.
Routing & Switching · Domain 2
BSS
Basic Service Set — a single access point plus every wireless client connected to it, forming one coverage cell.
Wireless Networking · Domain 2
BSSID
Basic Service Set Identifier — the MAC address of the specific access point radio serving a BSS, used to tell multiple APs sharing the same SSID apart.
Wireless Networking · Domain 2
bus
A topology where every device connects to a single shared backbone cable, capped at each end with a terminator — largely obsolete in modern networks.
Network Topologies & Architectures · Domain 2
CCMP
Counter Mode with Cipher Block Chaining Message Authentication Code Protocol — the encryption protocol that uses AES to secure WPA2/WPA3 traffic and confirm it wasn't tampered with.
Wireless Networking · Domain 2
channel
A narrower slice of frequency within a wireless band that an access point transmits on — splitting a band into channels lets nearby networks avoid fully overlapping each other.
Wireless Networking · Domain 2
channel bonding
Combining two or more adjacent Wi-Fi channels into one wider channel to increase throughput, at the cost of leaving fewer separate non-overlapping channels available nearby.
Wireless Networking · Domain 2
collapsed core
A two-tier network design that combines the core and distribution layers into a single tier, sitting above the access layer — common in smaller networks that don't need a separate core.
Network Topologies & Architectures · Domain 2
collision domain
The set of devices that could cause a collision if they transmitted at the same time — every switch port is its own collision domain, but an old hub's whole segment is one.
Routing & Switching · Domain 2
controller-based AP
An access point (sometimes called a lightweight AP) that depends on a wireless LAN controller for its configuration and management, rather than holding its own settings — the practical choice for large deployments with many APs.
Wireless Networking · Domain 2
crossover cable
A twisted-pair cable wired with T568A on one end and T568B on the other, historically used to connect two similar devices directly together — largely unnecessary today since most modern ports detect and adjust automatically.
Physical Installations & Cabling · Domain 2
crosstalk
Unwanted signal leaking from one wire pair into a neighboring pair inside the same cable, which can corrupt data — twisting each pair of wires is what keeps crosstalk low.
Physical Installations & Cabling · Domain 2
default gateway
The router interface a device sends traffic to whenever the destination isn't on its own local network — a device's exit door to everywhere else.
Routing & Switching · Domain 2
demarc
Demarcation point — the exact spot where a service provider's responsibility for a connection ends and the customer's own equipment and wiring begins.
Physical Installations & Cabling · Domain 2
directional antenna
An antenna that focuses signal into one specific direction for longer range or a narrower coverage area, at the cost of coverage everywhere else.
Wireless Networking · Domain 2
distance-vector
A routing protocol approach where routers share their entire routing table with directly connected neighbors and pick paths mainly by hop count.
Routing & Switching · Domain 2
dynamic routing
A method where routers automatically learn routes and adjust to network changes by exchanging information with each other using a routing protocol.
Routing & Switching · Domain 2
east-west traffic
Network traffic that flows between devices within the same data center or network tier, such as server-to-server traffic.
Network Topologies & Architectures · Domain 2
EIGRP
Enhanced Interior Gateway Routing Protocol — a Cisco-developed advanced distance-vector protocol that converges quickly and supports multiple metrics.
Routing & Switching · Domain 2
EMI
Electromagnetic Interference — unwanted electrical noise from nearby sources (like motors, fluorescent lights, or power lines) that can corrupt signals traveling over copper cable.
Physical Installations & Cabling · Domain 2
ESS
Extended Service Set — two or more BSSs (access points) sharing the same SSID and wired network, letting a client roam between them without disconnecting.
Wireless Networking · Domain 2
exit interface
The specific interface a router sends a packet out of on its way toward the next hop.
Routing & Switching · Domain 2
F-type connector
A screw-on connector used to terminate coaxial cable, commonly seen on cable internet modems and cable TV connections.
Physical Installations & Cabling · Domain 2
flooding
What a switch does when it doesn't yet know which port leads to a frame's destination MAC address (or the destination is a broadcast) — sending the frame out every port except the one it arrived on.
Routing & Switching · Domain 2
horizontal cabling
The cabling that runs from an IDF or MDF out to individual work areas, such as a wall jack at a desk.
Physical Installations & Cabling · Domain 2
hybrid topology
A topology that combines two or more different topology types, such as several star networks linked together — most real-world networks are hybrid.
Network Topologies & Architectures · Domain 2
IDF
Intermediate Distribution Frame — a secondary wiring closet (often one per floor) that connects back to the MDF and distributes cabling out to nearby work areas.
Physical Installations & Cabling · Domain 2
LC
Lucent Connector — a small, common fiber optic connector, popular in tight spaces because two of them fit into roughly the same space as one older-style SC connector.
Physical Installations & Cabling · Domain 2
link-state
A routing protocol approach where every router builds a complete map of the network's topology and calculates the best path itself, rather than trusting a neighbor's summary.
Routing & Switching · Domain 2
longest prefix match
The rule a router uses to pick between multiple matching routes to the same destination — the route with the most specific (longest) prefix always wins.
Routing & Switching · Domain 2
LTE
Long-Term Evolution — the technology standard commonly marketed as 4G, offering much faster data speeds and lower latency than 3G.
Wireless Networking · Domain 2
MAC address table
A table a switch builds and maintains, mapping which MAC address was learned on which port, so it knows exactly where to forward each frame.
Routing & Switching · Domain 2
MDF
Main Distribution Frame — the central wiring point for an entire building or site, where outside connections and the building's core network equipment come together.
Physical Installations & Cabling · Domain 2
media converter
A device that converts a signal from one media type to another, such as copper to fiber, so two otherwise incompatible types of cabling can connect to the same network.
Physical Installations & Cabling · Domain 2
mesh topology
A topology where devices connect directly to multiple other devices for redundancy — a full mesh connects every device to every other device, while a partial mesh connects only some.
Network Topologies & Architectures · Domain 2
metric
The value a routing protocol uses to measure how good a route is, such as hop count or bandwidth-based cost, so it can pick the best path when more than one route is available.
Routing & Switching · Domain 2
MIMO
Multiple Input, Multiple Output — using multiple antennas at both the access point and client to send and receive several data streams at once, boosting throughput.
Wireless Networking · Domain 2
MMF
Multimode Fiber — fiber optic cable with a wider core that lets light travel down multiple paths at once, cheaper than single-mode but limited to shorter distances.
Physical Installations & Cabling · Domain 2
MU-MIMO
Multi-User MIMO — extends MIMO so an access point can use its multiple antennas to serve several different clients at the same time, instead of one client at a time.
Wireless Networking · Domain 2
next hop
The next router along the path toward a destination network — the immediate next stop for a packet, not necessarily its final destination.
Routing & Switching · Domain 2
north-south traffic
Network traffic that flows into or out of a data center or network, typically between a client and a server.
Network Topologies & Architectures · Domain 2
OFDMA
Orthogonal Frequency-Division Multiple Access — a Wi-Fi 6 feature that splits a channel into smaller resource units so an access point can serve several clients' small transmissions simultaneously.
Wireless Networking · Domain 2
omnidirectional antenna
An antenna that radiates signal roughly equally in every direction, used to cover an open area surrounding the access point.
Wireless Networking · Domain 2
OSPF
Open Shortest Path First — an open-standard link-state routing protocol that calculates the fastest path using a cost metric based on bandwidth.
Routing & Switching · Domain 2
patch panel
A panel of fixed ports, usually mounted in a rack, where permanent wall cabling is terminated so it can be connected to networking equipment with short, easily swapped patch cables.
Physical Installations & Cabling · Domain 2
path-vector
A routing protocol category, used by BGP, that chooses paths based on policy and the list of autonomous systems a route has passed through, rather than a simple metric like hop count.
Routing & Switching · Domain 2
plenum
A fire-rating for cable jacketing, required in the open spaces used for air circulation (like above a drop ceiling or under a raised floor) — plenum cable is coated to resist burning and release less toxic smoke.
Physical Installations & Cabling · Domain 2
PoE
Power over Ethernet — delivering electrical power to a device over the same twisted-pair cable that carries its network data, so it doesn't need a separate power outlet.
Physical Installations & Cabling · Domain 2
PoE+
An enhanced Power over Ethernet standard delivering more power than the original PoE, enough for higher-draw devices like pan-tilt-zoom cameras.
Physical Installations & Cabling · Domain 2
PoE++
The most powerful Power over Ethernet standard, delivering enough power for demanding devices like laptops or some access points that need more than PoE+ can supply.
Physical Installations & Cabling · Domain 2
point-to-point
A topology consisting of a single dedicated link directly connecting exactly two devices, with nothing else sharing that connection.
Network Topologies & Architectures · Domain 2
PSK
Pre-Shared Key — a single shared password configured on the access point and on every client, used in WPA2/WPA3-Personal mode.
Wireless Networking · Domain 2
QSFP
Quad Small Form-factor Pluggable — a transceiver module standard built for very high-speed links (40 Gbps and beyond) by combining four channels in one module.
Physical Installations & Cabling · Domain 2
rack unit
A standard unit of vertical space in an equipment rack, abbreviated U — one rack unit equals 1.75 inches, and equipment height is described by how many U it takes up.
Physical Installations & Cabling · Domain 2
RADIUS
Remote Authentication Dial-In User Service — a protocol that provides centralized authentication, authorization, and accounting (AAA); commonly used for Wi-Fi/802.1X and remote access. Uses UDP and encrypts only the password.
Wireless Networking · Domain 2
ring
A topology where each device connects to exactly two neighbors, forming a closed loop that data travels around.
Network Topologies & Architectures · Domain 2
RIP
Routing Information Protocol — a simple, legacy distance-vector routing protocol limited to a maximum of 15 hops.
Routing & Switching · Domain 2
riser
A fire-rating for cable jacketing used when cable runs vertically between floors, such as inside a wall shaft — less strict than plenum-rated cable, since it isn't run through open air-handling spaces.
Physical Installations & Cabling · Domain 2
RJ45
The standard 8-pin connector used to terminate twisted-pair copper cable, plugging into the Ethernet port on a computer, switch, or router.
Physical Installations & Cabling · Domain 2
roaming
A wireless client moving from one access point to another within the same ESS while staying connected to the network, ideally without a noticeable interruption.
Wireless Networking · Domain 2
router
A device that connects separate networks together and forwards packets based on destination IP address.
Routing & Switching · Domain 2
routing table
A list a router keeps of known destination networks, the next hop toward each one, the exit interface to use, and how that route was learned.
Routing & Switching · Domain 2
RSSI
Received Signal Strength Indicator — a measurement of how strong a wireless signal is at the receiving device, usually a negative dBm value where closer to zero means a stronger signal.
Wireless Networking · Domain 2
SC
Subscriber Connector — a fiber optic connector that locks in with a simple push-pull motion, larger than an LC connector.
Physical Installations & Cabling · Domain 2
SFP
Small Form-factor Pluggable — a transceiver module standard, commonly used for Gigabit fiber or copper links.
Physical Installations & Cabling · Domain 2
SFP+
An enhanced version of SFP supporting higher speeds, commonly used for 10 Gigabit fiber or copper links.
Physical Installations & Cabling · Domain 2
SMF
Single-Mode Fiber — fiber optic cable with a very narrow core that sends light straight down a single path, supporting the longest distances with the least signal loss.
Physical Installations & Cabling · Domain 2
spine-leaf
A two-tier data center architecture where every leaf switch connects to every spine switch, giving any two devices a short, predictable, non-blocking path between them.
Network Topologies & Architectures · Domain 2
SSID
Service Set Identifier — the human-readable network name a wireless network broadcasts, like the name you pick from a list of available Wi-Fi networks.
Wireless Networking · Domain 2
ST
Straight Tip — an older fiber optic connector that locks in with a twist, like a small bayonet-mount camera lens.
Physical Installations & Cabling · Domain 2
star topology
A topology where every device connects with its own cable to one central device, like a switch or hub — the most common physical topology in modern networks.
Network Topologies & Architectures · Domain 2
static route
A route manually entered by an administrator, which never changes unless someone edits it — reliable and predictable, but doesn't adapt on its own.
Routing & Switching · Domain 2
STP
Shielded Twisted Pair — twisted-pair copper cable with an added metal foil or braid shielding layer around the wires, giving extra protection against interference in noisy environments.
Physical Installations & Cabling · Domain 2
straight-through cable
A twisted-pair cable wired with the same standard (T568A or T568B) on both ends — the normal cable type for connecting dissimilar devices, like a PC to a switch.
Physical Installations & Cabling · Domain 2
switch
A device that connects devices within a local network and forwards frames based on destination MAC address.
Routing & Switching · Domain 2
T568A
One of two standard wiring orders for terminating twisted-pair cable into an RJ45 connector, defining which colored wire goes into which pin.
Physical Installations & Cabling · Domain 2
T568B
The more commonly used of two standard wiring orders for terminating twisted-pair cable into an RJ45 connector — most premade patch cables use this order on both ends.
Physical Installations & Cabling · Domain 2
three-tier architecture
A hierarchical network design with three layers — core, distribution, and access — each with a distinct role in moving traffic through the network.
Network Topologies & Architectures · Domain 2
topology
The arrangement of devices and connections in a network — physical topology describes the actual cabling and device placement, while logical topology describes how data actually flows, and the two can differ.
Network Topologies & Architectures · Domain 2
transceiver
A small module that plugs into a switch or router port to transmit and receive signals over a specific type of media, such as fiber — short for "transmitter/receiver."
Physical Installations & Cabling · Domain 2
trunk
A switch link configured to carry traffic for multiple VLANs at once, tagging each frame with its VLAN ID so the receiving switch knows which VLAN it belongs to.
Routing & Switching · Domain 2
UTP
Unshielded Twisted Pair — ordinary twisted-pair copper cable with no extra shielding layer around the wires, relying on the twists themselves to resist interference.
Physical Installations & Cabling · Domain 2
WAN
Wide Area Network — a network connection that spans a large geographic area, linking separate sites or networks together, often over a link leased from a service provider.
Routing & Switching · Domain 2
Wi-Fi 4
The marketing name for the 802.11n standard — works on both 2.4 GHz and 5 GHz, introduced MIMO, and reaches theoretical speeds up to about 600 Mbps.
Wireless Networking · Domain 2
Wi-Fi 5
The marketing name for the 802.11ac standard — 5 GHz only, with wider channels and MU-MIMO that push theoretical speeds into the multi-gigabit range.
Wireless Networking · Domain 2
Wi-Fi 6
The marketing name for the 802.11ax standard — runs on 2.4 GHz and 5 GHz, adding OFDMA and uplink MU-MIMO for much better performance when many devices share one network.
Wireless Networking · Domain 2
Wi-Fi 6E
An extension of Wi-Fi 6 that adds access to the 6 GHz band, opening up a wide slice of spectrum that's free of older devices and much less congested.
Wireless Networking · Domain 2
WLC
Wireless LAN Controller — a central device that manages many access points at once, pushing consistent configuration, security settings, and channel plans to each one.
Wireless Networking · Domain 2
WPA2
Wi-Fi Protected Access 2 — the wireless security standard that replaced WEP and the original WPA, using AES/CCMP encryption to protect traffic.
Wireless Networking · Domain 2
WPA3
Wi-Fi Protected Access 3 — the current wireless security standard, adding stronger encryption and protections (like forward secrecy) beyond what WPA2 offers.
Wireless Networking · Domain 2
Domain 3 — Network Operations 138
3-2-1 rule
A backup guideline: keep at least 3 copies of your data, on 2 different types of media, with 1 copy stored off-site.
Disaster Recovery & High Availability · Domain 3
A record
A DNS record type that maps a domain name to an IPv4 address.
IPv4/IPv6 Network Services · Domain 3
AAAA record
A DNS record type that maps a domain name to an IPv6 address.
IPv4/IPv6 Network Services · Domain 3
active-active
A redundancy design where two or more devices all handle traffic at the same time, sharing the load.
Disaster Recovery & High Availability · Domain 3
active-passive
A redundancy design where one device handles all the traffic while an idle standby waits to take over if it fails.
Disaster Recovery & High Availability · Domain 3
anomaly detection
The practice of comparing current network behavior against a known baseline to identify activity that falls outside what's normal or expected.
Network Monitoring · Domain 3
API
Application Programming Interface — a defined way for software to send requests to a device or service and get structured responses back, with no human clicking or typing involved.
Access & Management Methods · Domain 3
assessment
An evaluation of a network's current state — performance, security, or capacity — used to identify problems or plan future changes.
Organizational Processes & Documentation · Domain 3
asset inventory
A maintained record of every piece of equipment an organization owns — what it is, where it is, and identifying details like a serial number or asset tag — used to track hardware over its lifetime.
Organizational Processes & Documentation · Domain 3
audit
A formal review checking whether a network's actual configuration and practices comply with required standards, policies, or regulations.
Organizational Processes & Documentation · Domain 3
AUP
Acceptable Use Policy — a document defining what an organization does and doesn't allow when using its network, devices, or internet access.
Organizational Processes & Documentation · Domain 3
authoritative
Describes a DNS server that holds the official records for a specific domain and can answer directly about it.
IPv4/IPv6 Network Services · Domain 3
baseline
A documented snapshot of a network's normal, expected configuration or performance, used as the reference point for spotting unauthorized changes or unusual behavior later.
Organizational Processes & Documentation · Domain 3
bastion host
A hardened system deliberately exposed as the single controlled entry point into a protected network — a jump box is a common example.
Access & Management Methods · Domain 3
BYOD
Bring Your Own Device — a policy allowing employees to use their own personal phones, laptops, or tablets to access an organization's network and resources.
Organizational Processes & Documentation · Domain 3
change management
A formal process for proposing, reviewing, approving, and documenting any change to a network before it's made, so changes are deliberate and reversible rather than ad hoc.
Organizational Processes & Documentation · Domain 3
CLI
Command-Line Interface — a text-based way of managing a device by typing commands, such as over SSH or a console connection.
Access & Management Methods · Domain 3
client-to-site
A VPN type where an individual device runs VPN software to connect on demand into a company network — also called a remote-access VPN.
Access & Management Methods · Domain 3
clientless VPN
A VPN reached through an ordinary web browser over TLS, with no VPN software installed on the user’s device.
Access & Management Methods · Domain 3
cloud site
A disaster recovery environment hosted by a cloud provider, often paying for full capacity only when it’s actually used.
Disaster Recovery & High Availability · Domain 3
clustering
Grouping several servers or devices (nodes) so they work together as one system, with the other nodes taking over if one fails.
Disaster Recovery & High Availability · Domain 3
CNAME record
A DNS record type that points one domain name to another domain name, instead of straight to an address.
IPv4/IPv6 Network Services · Domain 3
cold site
A disaster recovery site with space, power, and cooling but no equipment ready — the cheapest, but it takes days to bring online.
Disaster Recovery & High Availability · Domain 3
community string
A shared, password-like value that authenticates SNMP communication between a manager and an agent in SNMP versions 1 and 2c — sent in plain text, which is a well-known weakness.
Network Monitoring · Domain 3
config backup
A saved copy of a device's current configuration, kept so that configuration can be restored quickly if the device fails or a change goes wrong.
Organizational Processes & Documentation · Domain 3
configuration management
The practice of tracking, controlling, and recording a network's device configurations over time, so every setting in use is known, intentional, and reversible.
Organizational Processes & Documentation · Domain 3
console port
A physical port on a network device that gives direct, local command-line access over a cable, without using the network at all.
Access & Management Methods · Domain 3
decommissioning
The formal process of permanently removing a device from service — including securely wiping its data, physically removing it, and updating documentation — rather than simply unplugging it.
Organizational Processes & Documentation · Domain 3
DHCP relay
A feature that forwards DHCP broadcasts from a subnet with no local DHCP server over to a server on a different subnet.
IPv4/IPv6 Network Services · Domain 3
DHCPv6
The IPv6 version of DHCP, used to assign addresses and settings to devices in a stateful way, much like DHCP does for IPv4.
IPv4/IPv6 Network Services · Domain 3
differential backup
A backup that copies all data changed since the last full backup — it grows each day, but a restore needs only the last full backup plus the latest differential.
Disaster Recovery & High Availability · Domain 3
disaster recovery
The planning and processes for restoring systems, data, and operations after a major failure or disaster.
Disaster Recovery & High Availability · Domain 3
diverse paths
Separate network connections that don’t share the same physical route or provider, so one break can’t take down both.
Disaster Recovery & High Availability · Domain 3
DORA
The four-step process a device uses to get an address from a DHCP server: Discover, Offer, Request, Acknowledge.
IPv4/IPv6 Network Services · Domain 3
environmental sensor
A sensor that monitors physical conditions around network equipment, such as temperature or humidity, to catch problems (like a failing air conditioner) before they cause hardware damage.
Network Monitoring · Domain 3
EOL
End-of-Life — the point at which a manufacturer stops selling and developing new features for a product, even though existing units may still receive support for a while longer.
Organizational Processes & Documentation · Domain 3
EOS
End-of-Support — the point at which a manufacturer stops providing updates, patches, or support for a product entirely, even for units still in active use.
Organizational Processes & Documentation · Domain 3
EUI-64
A method for building the host portion of an IPv6 address out of a device's own 48-bit MAC address, expanded to 64 bits.
IPv4/IPv6 Network Services · Domain 3
exclusion
An address or range inside a DHCP scope that's deliberately left out, so the server never assigns it.
IPv4/IPv6 Network Services · Domain 3
failover
The automatic switch to a standby device or system when the active one fails.
Disaster Recovery & High Availability · Domain 3
FHRP
First Hop Redundancy Protocol — a family of protocols (like VRRP and HSRP) that lets routers share a virtual IP address as a redundant default gateway.
Disaster Recovery & High Availability · Domain 3
floor plan
A diagram of a building's physical layout — walls, rooms, and hallways — marked up with where network equipment and wall jacks actually sit within that space.
Organizational Processes & Documentation · Domain 3
forward lookup
A DNS query that resolves a domain name into its IP address — the everyday kind of lookup.
IPv4/IPv6 Network Services · Domain 3
full backup
A backup that copies all of the selected data every time — the slowest to create, but the fastest and simplest to restore from.
Disaster Recovery & High Availability · Domain 3
full tunnel
A VPN setup where all of a client’s traffic, including internet-bound traffic, is sent through the encrypted tunnel to the company network first.
Access & Management Methods · Domain 3
generator
An engine-driven power source that supplies electricity during long outages — slow to start, so a UPS covers the gap.
Disaster Recovery & High Availability · Domain 3
geographic redundancy
Placing sites far enough apart that a single regional event, like an earthquake or storm, can’t take out both.
Disaster Recovery & High Availability · Domain 3
golden config
A saved, verified-working configuration for a device, used as the trusted starting point when configuring or restoring similar devices — also called a known-good configuration.
Organizational Processes & Documentation · Domain 3
GUI
Graphical User Interface — a point-and-click management interface, such as a device’s built-in web page, as opposed to typing commands.
Access & Management Methods · Domain 3
heartbeat
A regular signal that cluster nodes or redundant routers send to each other to confirm they’re still alive; missing heartbeats trigger failover.
Disaster Recovery & High Availability · Domain 3
high availability
Designing a network or service with redundancy so it keeps running with minimal downtime even when components fail.
Disaster Recovery & High Availability · Domain 3
hot site
A fully equipped disaster recovery site running with near-real-time copies of the data — the most expensive, but it recovers in minutes or less.
Disaster Recovery & High Availability · Domain 3
HSRP
Hot Standby Router Protocol — Cisco’s proprietary FHRP, with an active router answering for the shared virtual IP and a standby router ready to take over.
Disaster Recovery & High Availability · Domain 3
HVAC
Heating, Ventilation, and Air Conditioning — the systems that keep equipment rooms at safe temperatures.
Disaster Recovery & High Availability · Domain 3
in-band management
Managing a device over the same production network that carries normal user traffic — convenient, but it fails if that network goes down.
Access & Management Methods · Domain 3
incremental backup
A backup that copies only the data changed since the last backup of any type — quick and small, but a restore needs the last full backup plus every incremental after it.
Disaster Recovery & High Availability · Domain 3
interface errors
Frames or packets a network interface sent or received with problems, such as corruption or an invalid size — often called discards when the interface drops them outright, both signaling a physical or configuration issue.
Network Monitoring · Domain 3
IP helper
A router command that enables DHCP relay, telling the router exactly where to forward DHCP broadcasts it receives.
IPv4/IPv6 Network Services · Domain 3
IPAM
IP Address Management — a system, often software, for tracking which IP addresses are assigned, available, or reserved across a network, so nothing gets duplicated or lost track of.
Organizational Processes & Documentation · Domain 3
IPFIX
IP Flow Information Export — an open standard for exporting flow data, based on NetFlow, designed to work consistently across equipment from different vendors.
Network Monitoring · Domain 3
IPsec
Internet Protocol Security — a suite of protocols that encrypts and authenticates traffic at Layer 3, commonly used to build site-to-site VPNs.
Access & Management Methods · Domain 3
ISP
Internet Service Provider — the company that supplies a network’s connection to the internet.
Disaster Recovery & High Availability · Domain 3
jitter
The variation in latency over time — even when average delay is low, inconsistent delay (jitter) can badly disrupt real-time traffic like voice or video calls.
Network Monitoring · Domain 3
JSON
JavaScript Object Notation — a lightweight, human-readable text format for structured data, and the most common way REST APIs return their responses.
Access & Management Methods · Domain 3
jump box
A hardened, heavily monitored server that administrators connect to first, then use as a stepping stone to reach devices in a secure segment. Also called a jump host.
Access & Management Methods · Domain 3
LACP
Link Aggregation Control Protocol — the standard protocol that automatically negotiates and manages a link aggregation bundle between two devices.
Disaster Recovery & High Availability · Domain 3
latency
The time it takes for data to travel from a source to a destination, usually measured in milliseconds — high latency means a noticeable delay.
Network Monitoring · Domain 3
lease
The length of time a DHCP-assigned address stays valid before a device must renew it or give it up.
IPv4/IPv6 Network Services · Domain 3
link aggregation
Bundling several physical links between devices into one logical link, for more total bandwidth and redundancy if a link fails.
Disaster Recovery & High Availability · Domain 3
link-local
An IPv6 address every interface gets automatically, valid only on its own local segment and never routed beyond it.
IPv4/IPv6 Network Services · Domain 3
load balancer
A device that distributes incoming client requests across multiple servers so no single server gets overwhelmed.
Disaster Recovery & High Availability · Domain 3
load balancing
Spreading traffic or requests across several servers or links so none is overwhelmed, which improves both performance and availability.
Disaster Recovery & High Availability · Domain 3
log collector
A centralized server that receives and stores log messages, often sent via syslog, from many devices across a network, making them searchable in one place.
Network Monitoring · Domain 3
logical diagram
A network diagram showing how data logically flows — IP addressing, subnets, VLANs, and traffic paths — independent of the actual physical wiring or device placement.
Organizational Processes & Documentation · Domain 3
management port
A dedicated network port on a device, separate from its normal data ports, reserved for out-of-band management traffic.
Access & Management Methods · Domain 3
MIB
Management Information Base — a structured, hierarchical directory of every value an SNMP agent can report on a device, like a menu of everything that device is willing to share.
Network Monitoring · Domain 3
MOU
Memorandum of Understanding — a document where two parties state their intent to work together, outlining a shared understanding without the binding formality of a full contract.
Organizational Processes & Documentation · Domain 3
MTBF
Mean Time Between Failures — the average time a component runs before it fails, used as a measure of reliability; higher is better.
Disaster Recovery & High Availability · Domain 3
MTTR
Mean Time To Repair — the average time it takes to fix a failed component and return it to service; lower is better.
Disaster Recovery & High Availability · Domain 3
MX record
A DNS record type that specifies which mail server handles email for a domain.
IPv4/IPv6 Network Services · Domain 3
NDA
Non-Disclosure Agreement — a contract where the signing parties agree not to share confidential information they're exposed to.
Organizational Processes & Documentation · Domain 3
NDP
Neighbor Discovery Protocol — the IPv6 equivalent of ARP, used to find neighboring MAC addresses and detect local routers.
IPv4/IPv6 Network Services · Domain 3
NetFlow
A Cisco-developed protocol for exporting flow data — summarized records of who talked to whom, over what protocol, and how much traffic passed between them — without capturing every packet's full contents.
Network Monitoring · Domain 3
NIC
Network Interface Card — the hardware in a device that connects it to a network.
Disaster Recovery & High Availability · Domain 3
NIC teaming
Combining two or more of a server’s network interface cards so they act as one logical connection, for failover and added bandwidth.
Disaster Recovery & High Availability · Domain 3
node
One server or device that is a member of a cluster.
Disaster Recovery & High Availability · Domain 3
NS record
A DNS record type that specifies which name servers are authoritative for a domain.
IPv4/IPv6 Network Services · Domain 3
NTP
Network Time Protocol — synchronizes device clocks across a network to a common, accurate time source.
IPv4/IPv6 Network Services · Domain 3
off-site backup
A copy of data stored in a different physical location from the original, such as a remote facility or cloud storage, so a site disaster can’t destroy it.
Disaster Recovery & High Availability · Domain 3
OID
Object Identifier — the specific numeric address within a MIB that points to one exact piece of data, like a precise item number on that menu.
Network Monitoring · Domain 3
out-of-band management
Managing a device over a separate, dedicated path that doesn’t depend on the production network, so it still works during an outage.
Access & Management Methods · Domain 3
packet capture
Recording the complete contents of network packets as they cross a link, giving the deepest level of visibility into traffic — down to the exact bytes exchanged.
Network Monitoring · Domain 3
packet loss
Packets that never arrive at their destination at all, usually due to congestion, errors, or a failing link — even a small percentage can seriously degrade real-time traffic.
Network Monitoring · Domain 3
physical diagram
A network diagram showing what's actually wired to what in the real world — devices, cable runs, and ports — the layout you'd need to trace a cable or find a specific switch.
Organizational Processes & Documentation · Domain 3
plaintext
Data sent without encryption, so anyone who captures it on the network can read it exactly as-is — including usernames and passwords.
Access & Management Methods · Domain 3
polling
The act of an SNMP manager periodically asking each agent for its current values, rather than waiting for the agent to report in on its own.
Network Monitoring · Domain 3
pool
The specific range of addresses within a DHCP scope that's actually available to assign to clients.
IPv4/IPv6 Network Services · Domain 3
protocol analyzer
A tool used to capture and inspect packet captures in detail, decoding each protocol layer so a person can read exactly what's being sent.
Network Monitoring · Domain 3
PSU
Power Supply Unit — the component that converts incoming power into what a device needs; a device with dual PSUs keeps running if one fails.
Disaster Recovery & High Availability · Domain 3
PTR record
A DNS record type used for reverse lookups, mapping an address back to a domain name.
IPv4/IPv6 Network Services · Domain 3
rack diagram
A diagram showing exactly which piece of equipment sits in which rack unit of a specific rack, so anyone can find a device without having to search for it in person.
Organizational Processes & Documentation · Domain 3
recursive
Describes a DNS server that takes on the full job of resolving a query on a client's behalf, chasing referrals itself.
IPv4/IPv6 Network Services · Domain 3
redundancy
Having duplicate components, links, or systems so that one failure doesn’t stop the service.
Disaster Recovery & High Availability · Domain 3
reservation
A specific address within a DHCP scope permanently set aside for one device, identified by its MAC address.
IPv4/IPv6 Network Services · Domain 3
REST
Representational State Transfer — a popular API style that uses ordinary HTTP/HTTPS requests (GET, POST, PUT/PATCH, DELETE) against URLs to read and change data.
Access & Management Methods · Domain 3
reverse lookup
A DNS query that resolves an IP address back into a domain name, using a PTR record.
IPv4/IPv6 Network Services · Domain 3
rollback plan
A documented plan for undoing a change and returning to the previous known-good state if that change causes unexpected problems.
Organizational Processes & Documentation · Domain 3
RPO
Recovery Point Objective — the maximum amount of data loss a business can accept, measured as how far back in time the last good copy of the data may be.
Disaster Recovery & High Availability · Domain 3
RTO
Recovery Time Objective — the maximum amount of time a service can be down after a failure before the impact on the business becomes unacceptable.
Disaster Recovery & High Availability · Domain 3
scope
The overall DHCP configuration for one subnet — the address range it hands out, plus settings like lease time and default gateway.
IPv4/IPv6 Network Services · Domain 3
sFlow
An open, vendor-neutral standard for exporting sampled flow data, similar in purpose to NetFlow but based on statistically sampling packets rather than tracking every flow completely.
Network Monitoring · Domain 3
SIEM
Security Information and Event Management — a system that aggregates and correlates logs and events from many different sources across a network, generating alerts when it spots something suspicious.
Network Monitoring · Domain 3
single point of failure
Any single component whose failure would bring down an entire service because nothing else can take over its job.
Disaster Recovery & High Availability · Domain 3
site survey
A physical inspection of a location, often done before installing a wireless network, to assess coverage needs, interference sources, and where equipment should go.
Organizational Processes & Documentation · Domain 3
site-to-site
A VPN type that permanently links two whole networks (such as a branch office and headquarters) through VPN gateways, so users at either site never have to connect manually.
Access & Management Methods · Domain 3
SLA
Service-Level Agreement — a contract that defines the minimum level of service a provider guarantees, such as uptime or response time, and what happens if they fail to meet it.
Organizational Processes & Documentation · Domain 3
SLAAC
Stateless Address Autoconfiguration — lets an IPv6 device build its own address from router advertisements, without a DHCP server.
IPv4/IPv6 Network Services · Domain 3
snapshot
A point-in-time capture of a system, virtual machine, or storage volume that can be rolled back to almost instantly — useful before changes, but not a replacement for a real backup.
Disaster Recovery & High Availability · Domain 3
SOA record
A DNS record type holding administrative details about a zone, like its primary server and refresh timers.
IPv4/IPv6 Network Services · Domain 3
SOW
Statement of Work — a document defining the specific work to be done for a project, including deliverables, timeline, and cost, usually tied to a contract.
Organizational Processes & Documentation · Domain 3
split tunnel
A VPN setup where only traffic bound for the company network goes through the tunnel, while everything else goes straight out the client’s own internet connection.
Access & Management Methods · Domain 3
SSL
Secure Sockets Layer — the older, now-deprecated predecessor of TLS; the name lingers in terms like “SSL VPN.”
Access & Management Methods · Domain 3
stratum
A number showing how many steps an NTP time source sits from a reference clock — stratum 0 is the reference itself.
IPv4/IPv6 Network Services · Domain 3
syslog
A standard protocol and message format for sending log messages from network devices to a central logging server, so records from many devices can be reviewed in one place.
Network Monitoring · Domain 3
terminal emulator
Software on a computer that connects to a device’s console port (or other command-line session) and displays its text interface — PuTTY and Tera Term are common examples.
Access & Management Methods · Domain 3
throughput
The actual amount of data successfully transferred over a connection in a given time, which can be lower than a link's theoretical maximum bandwidth.
Network Monitoring · Domain 3
TLS
Transport Layer Security — the modern protocol that encrypts traffic between two endpoints, used by HTTPS and by so-called SSL VPNs.
Access & Management Methods · Domain 3
transport mode
An IPsec mode that encrypts only the payload of each packet and leaves the original IP header intact — typical for direct host-to-host protection.
Access & Management Methods · Domain 3
trap
An unsolicited message an SNMP agent sends to the manager immediately when something notable happens, rather than waiting to be asked.
Network Monitoring · Domain 3
tunnel mode
An IPsec mode that encrypts the entire original packet and wraps it in a new IP header — typical for gateway-to-gateway (site-to-site) VPNs.
Access & Management Methods · Domain 3
TXT record
A DNS record type that holds arbitrary text, often used to verify domain ownership or publish mail policies.
IPv4/IPv6 Network Services · Domain 3
UPS
Uninterruptible Power Supply — a battery-backed unit that takes over instantly when utility power fails, giving short runtime for a clean shutdown or until a generator starts.
Disaster Recovery & High Availability · Domain 3
uptime
The amount of time a device or service has been continuously running and available, often expressed as a percentage — also called availability.
Network Monitoring · Domain 3
version control
A system for tracking every saved change to a configuration or document over time, so you can see what changed, when, and revert to an earlier version if needed.
Organizational Processes & Documentation · Domain 3
virtual IP
A shared IP address held by whichever router in an FHRP group is currently active, so hosts can use it as a default gateway that survives a router failure.
Disaster Recovery & High Availability · Domain 3
VRRP
Virtual Router Redundancy Protocol — an open-standard FHRP where one master router answers for a shared virtual IP and backup routers take over if it fails.
Disaster Recovery & High Availability · Domain 3
warm site
A disaster recovery site with some equipment already installed that still needs setup and a recent data restore — moderate cost, recovering in hours to about a day.
Disaster Recovery & High Availability · Domain 3
wiring diagram
A diagram tracing individual cable runs — which port on a patch panel connects to which port on a switch or wall jack — also called a cable diagram.
Organizational Processes & Documentation · Domain 3
Domain 4 — Network Security 166
2FA
Two-Factor Authentication — multifactor authentication that uses exactly two different factors.
Security Fundamentals · Domain 4
AAA
Authentication, Authorization, and Accounting — the framework for verifying who you are, deciding what you may do, and recording what you did.
Security Fundamentals · Domain 4
access control vestibule
A small entry space with two interlocking doors that can’t be open at once, used to stop tailgating — also called a mantrap.
Security Fundamentals · Domain 4
account lockout
A security setting that temporarily disables an account after too many failed login attempts, limiting password guessing.
Network Attacks · Domain 4
accounting
Recording what a user did and when, such as logins and commands — the “what did you do?” part of AAA, used for auditing.
Security Fundamentals · Domain 4
ACL
Access Control List — an ordered list of permit and deny rules that a router, switch, or firewall uses to filter traffic; the first matching rule wins.
Defense Techniques & Solutions · Domain 4
air gap
A physical separation with no network connection at all between a system and other networks — the strongest form of isolation.
Defense Techniques & Solutions · Domain 4
amplification
A technique where a small request triggers a much larger response, so the attacker multiplies the volume of a flood — often combined with reflection using DNS or NTP servers.
Network Attacks · Domain 4
anomaly-based
A detection method that learns what normal behavior looks like and flags deviations from it — able to catch new attacks, but prone to more false positives.
Defense Techniques & Solutions · Domain 4
ARP poisoning
An attack that sends forged ARP replies so devices map the wrong MAC address to an IP address (often the gateway’s), redirecting local traffic through the attacker — also called ARP spoofing.
Network Attacks · Domain 4
asset disposal
The safe retirement of old equipment, including wiping or destroying the data, configurations, and keys it holds.
Security Fundamentals · Domain 4
asset tag
A label attached to a piece of equipment that identifies it so it can be tracked in an inventory.
Security Fundamentals · Domain 4
asymmetric encryption
Encryption that uses a linked pair of keys, a public key and a private key — slower, but it solves the problem of sharing keys (RSA is a common example).
Security Fundamentals · Domain 4
attack surface
The total number of ways an attacker could get into or attack a system — every open port, service, and account.
Defense Techniques & Solutions · Domain 4
authentication
Verifying who someone or something is — the “who are you?” part of AAA, such as a username and password.
Security Fundamentals · Domain 4
authentication factor
A category of proof of identity: something you know, something you have, something you are, and sometimes somewhere you are or something you do.
Security Fundamentals · Domain 4
authenticator
In 802.1X, the switch or access point that controls the port and relays the client’s credentials to the authentication server.
Defense Techniques & Solutions · Domain 4
authorization
Deciding what an authenticated user is allowed to access or do — the “what may you do?” part of AAA.
Security Fundamentals · Domain 4
availability
Making sure systems and data are accessible to authorized users whenever they’re needed — protected by redundancy, backups, and DDoS protection.
Security Fundamentals · Domain 4
backhauling
Sending branch or remote users’ traffic back to a central data center for inspection before it goes on to the internet or cloud, which adds delay.
Zero Trust & SASE · Domain 4
badge reader
A device at a door that reads an employee’s ID card or badge to decide whether to let them in, and logs who entered.
Security Fundamentals · Domain 4
biometrics
Authentication based on a physical characteristic of the person, such as a fingerprint, face, or iris.
Security Fundamentals · Domain 4
botnet
A large group of compromised devices (bots or zombies) that an attacker controls remotely, often used to launch DDoS attacks.
Network Attacks · Domain 4
BPDU
Bridge Protocol Data Unit — the messages switches exchange in Spanning Tree Protocol to elect a root bridge and prevent loops.
Network Attacks · Domain 4
BPDU guard
A switch feature that shuts down an access port if it receives BPDUs, blocking rogue switches from joining the Spanning Tree.
Network Attacks · Domain 4
brute force
A password attack that automatically tries every possible combination of characters until one works.
Network Attacks · Domain 4
CAM table
Content Addressable Memory table — the switch’s MAC address table, which maps MAC addresses to ports and has a limited size.
Network Attacks · Domain 4
captive portal
A web page that guests must sign in to or accept terms on before they’re allowed to use a network.
Defense Techniques & Solutions · Domain 4
CASB
Cloud Access Security Broker — a control point between users and cloud services that gives visibility into cloud app use and enforces security policy, such as access control and data loss prevention.
Zero Trust & SASE · Domain 4
castle-and-moat
Another name for the perimeter security model: a strong wall and moat at the edge, and free movement for anyone who gets inside.
Zero Trust & SASE · Domain 4
certificate authority
A trusted organization that issues digital certificates and vouches that a public key belongs to its stated owner.
Security Fundamentals · Domain 4
CIA
Confidentiality, Integrity, and Availability — the three core goals of information security, and the model used to judge what a security control protects.
Security Fundamentals · Domain 4
ciphertext
Data that has been encrypted and is unreadable without the correct key.
Security Fundamentals · Domain 4
command and control
Command and Control (C2) — the server or channel an attacker uses to send instructions to the devices in a botnet.
Network Attacks · Domain 4
conditional access
A policy that grants, limits, blocks, or adds proof requirements for access based on conditions such as the user’s identity, device health, location, and risk level.
Zero Trust & SASE · Domain 4
confidentiality
Keeping data private so that only authorized people can see it — protected by controls like encryption and access controls.
Security Fundamentals · Domain 4
content filtering
Blocking or allowing web content by category, URL, domain, or file type, to enforce acceptable use and reduce exposure to malicious sites.
Defense Techniques & Solutions · Domain 4
continuous verification
Re-checking identity, device health, and context throughout a session, not only at login, so access can be limited or revoked if conditions change.
Zero Trust & SASE · Domain 4
control plane
The part of a system that makes decisions and sets up how traffic is handled, without carrying user data — in zero trust, the policy engine and policy administrator.
Zero Trust & SASE · Domain 4
credential stuffing
An attack that takes username and password pairs leaked in one breach and tries them on other sites, exploiting password reuse.
Network Attacks · Domain 4
cross-site scripting
An attack that injects malicious script into a web page so it runs in other users’ browsers — often shortened to XSS.
Defense Techniques & Solutions · Domain 4
data plane
The part of a system that carries the actual user traffic — in zero trust, the path from the user through the policy enforcement point to the resource.
Zero Trust & SASE · Domain 4
DDoS
Distributed Denial of Service — a denial-of-service attack launched from many sources at once, usually a botnet, which makes it harder to block.
Network Attacks · Domain 4
deauthentication attack
An attack that sends forged management frames to disconnect wireless clients from an access point, used for denial of service or to push users toward an evil twin.
Network Attacks · Domain 4
deep packet inspection
Examining the contents of packets, not just their headers, so a device can identify applications and detect threats.
Defense Techniques & Solutions · Domain 4
default credentials
The manufacturer’s preset username and password on a new device, which are widely known and must be changed.
Defense Techniques & Solutions · Domain 4
defense in depth
Protecting assets with multiple layers of different security controls, so that if one fails, others still protect them.
Security Fundamentals · Domain 4
DHCP snooping
A switch feature that only allows DHCP server replies from trusted ports, blocking rogue DHCP servers.
Network Attacks · Domain 4
dictionary attack
A password attack that tries words and common passwords from a wordlist instead of every possible combination.
Network Attacks · Domain 4
digital certificate
An electronic document that ties a public key to an identity, such as a website, and is signed by a certificate authority.
Security Fundamentals · Domain 4
digital signature
A hash of a message signed with a sender’s private key, which anyone can verify with the public key to prove who sent it and that it wasn’t altered.
Security Fundamentals · Domain 4
DLP
Data Loss Prevention — controls that detect and block sensitive data, such as customer records or card numbers, from leaving the organization.
Zero Trust & SASE · Domain 4
DMZ
Demilitarized Zone — a buffer network holding public-facing servers between the internet and the internal network; now often called a screened subnet.
Defense Techniques & Solutions · Domain 4
DNS poisoning
An attack that plants false records in a DNS server’s cache, or forges a response, so a real domain name resolves to the attacker’s IP address — also called DNS spoofing.
Network Attacks · Domain 4
DNSSEC
DNS Security Extensions — a set of protections that digitally sign DNS records so resolvers can verify they’re authentic and unaltered.
Network Attacks · Domain 4
DoS
Denial of Service — an attack that overwhelms a system or network so legitimate users can no longer use it; it targets availability.
Network Attacks · Domain 4
DTP
Dynamic Trunking Protocol — a Cisco protocol that automatically negotiates trunk links between switches; attackers abuse it for switch spoofing.
Network Attacks · Domain 4
dumpster diving
Searching through trash for discarded documents, drives, or notes that contain sensitive information.
Network Attacks · Domain 4
dynamic ARP inspection
A switch feature that checks ARP messages against trusted address bindings and drops forged ones, defending against ARP poisoning.
Network Attacks · Domain 4
encryption
Scrambling readable data into unreadable ciphertext using an algorithm and a key, so only someone with the right key can read it.
Security Fundamentals · Domain 4
encryption key
A secret value used by an encryption algorithm to scramble and unscramble data.
Security Fundamentals · Domain 4
evil twin
A malicious wireless access point that copies the name (SSID) of a legitimate network so users connect to it, letting the attacker capture their traffic and credentials.
Network Attacks · Domain 4
exploit
A specific tool, piece of code, or technique that takes advantage of a vulnerability.
Security Fundamentals · Domain 4
false negative
A real attack that a security tool fails to detect or alert on.
Defense Techniques & Solutions · Domain 4
false positive
An alert that flags harmless, legitimate activity as an attack.
Defense Techniques & Solutions · Domain 4
firewall
A device or service that allows or blocks network traffic based on a defined set of rules.
Defense Techniques & Solutions · Domain 4
forward proxy
A proxy that sits in front of clients and handles their outbound requests to the internet — used for filtering, logging, and caching.
Defense Techniques & Solutions · Domain 4
FWaaS
Firewall as a Service — a firewall delivered from the cloud instead of a hardware appliance at each site, filtering traffic for offices and remote users.
Zero Trust & SASE · Domain 4
guest network
An isolated network for visitors that usually offers internet access only, with no access to internal resources.
Defense Techniques & Solutions · Domain 4
hardening
Securing a device by reducing its attack surface — disabling unused ports and services, changing default credentials, and applying patches.
Defense Techniques & Solutions · Domain 4
hashing
Running data through a one-way function to produce a fixed-length fingerprint (a hash) — it can’t be reversed, and it’s used to check integrity.
Security Fundamentals · Domain 4
honeynet
A network of honeypots that imitates a real network to lure and study attackers.
Defense Techniques & Solutions · Domain 4
honeypot
A decoy system built to look like a valuable target so attackers go after it, giving defenders an early warning and a way to study their techniques.
Defense Techniques & Solutions · Domain 4
identity provider
IdP — a service that stores user identities, authenticates them, and vouches for them to applications.
Zero Trust & SASE · Domain 4
IDS
Intrusion Detection System — monitors traffic for suspicious activity and generates alerts, without directly blocking it.
Defense Techniques & Solutions · Domain 4
implicit deny
The invisible final rule in an ACL or firewall policy that blocks any traffic no earlier rule allowed.
Defense Techniques & Solutions · Domain 4
implicit trust
Trust granted automatically because of where a user or device is — such as inside the office network — instead of because it was verified.
Zero Trust & SASE · Domain 4
inline
Placed directly in the path of network traffic, so all traffic passes through the device — unlike a device that only sees a copy.
Defense Techniques & Solutions · Domain 4
integrity
Keeping data accurate and unaltered, so any unauthorized change is prevented or detected — protected by controls like hashing and digital signatures.
Security Fundamentals · Domain 4
IP spoofing
Forging the source IP address in packets to hide the sender’s identity or impersonate another host — the basis of reflection attacks.
Network Attacks · Domain 4
IPS
Intrusion Prevention System — sits inline with live traffic and can actively block suspicious traffic in real time.
Defense Techniques & Solutions · Domain 4
lateral movement
An attacker’s movement from one compromised system to others inside a network, looking for more valuable targets.
Zero Trust & SASE · Domain 4
least functionality
Configuring a device to provide only the functions it needs and nothing more, so there’s less to attack.
Defense Techniques & Solutions · Domain 4
least privilege
Giving every user, account, and system only the minimum access needed to do its job — and nothing more.
Security Fundamentals · Domain 4
MAC flooding
An attack that floods a switch with frames from fake source MAC addresses to overflow its CAM table, making it forward traffic out every port like a hub.
Network Attacks · Domain 4
MAC spoofing
Changing or cloning a device’s MAC address to impersonate another device or bypass MAC filtering.
Network Attacks · Domain 4
malware
Any software designed to harm a system, steal data, or gain unauthorized access.
Network Attacks · Domain 4
MD5
Message Digest 5 — an older hashing algorithm that is now considered weak and unsuitable for security purposes.
Security Fundamentals · Domain 4
MFA
Multifactor Authentication — requiring two or more different types of proof of identity, such as a password plus a fingerprint.
Security Fundamentals · Domain 4
microsegmentation
Dividing a network into very small, granular zones — down to a single workload or application — with policy controlling the traffic between them, to limit lateral movement.
Zero Trust & SASE · Domain 4
motion detection
A sensor system that raises an alert when it detects movement in an area that should be empty.
Security Fundamentals · Domain 4
MPLS
Multiprotocol Label Switching — a carrier-provided private WAN service that forwards traffic using labels; reliable, but usually more costly than broadband.
Zero Trust & SASE · Domain 4
NAC
Network Access Control — decides whether a device or user may join the network, and what it may reach, based on identity and health checks.
Defense Techniques & Solutions · Domain 4
native VLAN
The VLAN whose traffic crosses a trunk without an 802.1Q tag — the weakness that double-tagging attacks exploit.
Network Attacks · Domain 4
network segmentation
Dividing a network into smaller zones and controlling the traffic allowed between them, which limits how far an attack can spread.
Defense Techniques & Solutions · Domain 4
network tap
A hardware device placed on a link that copies the traffic passing through it to a monitoring device, without sitting in the traffic’s path.
Defense Techniques & Solutions · Domain 4
NGFW
Next-Generation Firewall — adds deep, application-aware inspection beyond basic IP address and port filtering.
Defense Techniques & Solutions · Domain 4
on-path attack
An attack where the attacker secretly positions themselves between two parties to intercept, read, or alter their communication — formerly called a man-in-the-middle (MITM) attack.
Network Attacks · Domain 4
on-path browser attack
A variant where malware inside the victim’s own web browser changes what the user sees or alters transactions as they’re sent — also called man-in-the-browser.
Network Attacks · Domain 4
password spraying
An attack that tries one or a few very common passwords against many different accounts, staying under account lockout limits.
Network Attacks · Domain 4
patch
A software or firmware update that fixes a known vulnerability or bug.
Defense Techniques & Solutions · Domain 4
perimeter security
A security model that defends the edge of the network, mainly with firewalls, and trusts users and devices once they are inside — also called the castle-and-moat model.
Zero Trust & SASE · Domain 4
phishing
A fraudulent message, usually an email with a link or attachment, sent to many people to trick them into revealing information or installing malware.
Network Attacks · Domain 4
piggybacking
Gaining entry to a secured area because an authorized person knowingly lets you in, such as by holding the door — unlike tailgating, where they don’t know.
Network Attacks · Domain 4
PKI
Public Key Infrastructure — the system of certificate authorities, policies, and processes that issues, manages, and verifies digital certificates.
Security Fundamentals · Domain 4
point of presence
PoP — a cloud provider’s regional location where user traffic is processed and secured close to the user.
Zero Trust & SASE · Domain 4
policy administrator
The zero trust component that carries out the policy engine’s decision by setting up or tearing down the connection, and telling the enforcement point what to allow.
Zero Trust & SASE · Domain 4
policy enforcement point
PEP — the zero trust component that sits in the path of the traffic and allows, monitors, and ends the connection between a user or device and a resource.
Zero Trust & SASE · Domain 4
policy engine
The zero trust component that decides whether to grant, deny, or revoke access, by weighing each request against policy and signals such as identity, device health, and risk.
Zero Trust & SASE · Domain 4
port mirroring
A switch feature that copies the traffic from one or more ports to another port, so a monitoring device such as an IDS can inspect it.
Defense Techniques & Solutions · Domain 4
posture assessment
A NAC check of a device’s health — such as OS patches, antivirus, and firewall status — before or after it is allowed onto the network.
Defense Techniques & Solutions · Domain 4
pretexting
Using an invented scenario or false identity to gain a victim’s trust and get information or access.
Network Attacks · Domain 4
private key
The secret half of an asymmetric key pair, kept only by its owner — it decrypts data sent to them or creates their digital signature.
Security Fundamentals · Domain 4
proxy
A server that forwards requests on behalf of a client, sitting between the client and its destination.
Defense Techniques & Solutions · Domain 4
public key
One half of an asymmetric key pair, which can be shared openly — it encrypts data for its owner or verifies the owner’s digital signature.
Security Fundamentals · Domain 4
quarantine network
A restricted network where devices that fail a NAC health check are placed, able to reach only what they need to fix the problem.
Defense Techniques & Solutions · Domain 4
ransomware
Malware that encrypts a victim’s data (or locks their system) and demands payment for the key.
Network Attacks · Domain 4
rate limiting
Capping how many requests or how much traffic a source can send in a set time, which reduces the effect of floods and password guessing.
Defense Techniques & Solutions · Domain 4
RBAC
Role-Based Access Control — granting permissions according to a user’s job role instead of assigning them one by one.
Zero Trust & SASE · Domain 4
reflection
A technique where an attacker forges the victim’s IP address as the source of requests sent to third-party servers, so all the replies go to the victim and the attacker stays hidden.
Network Attacks · Domain 4
reverse proxy
A proxy that sits in front of servers and handles inbound requests from the internet — hiding the servers and often balancing load or handling TLS.
Defense Techniques & Solutions · Domain 4
risk
The likelihood that a threat will exploit a vulnerability, combined with the damage it would cause if it did.
Security Fundamentals · Domain 4
rogue access point
A wireless access point connected to a network without authorization, creating an unsecured back door — it might be malicious or just an employee’s personal device.
Network Attacks · Domain 4
rogue DHCP server
An unauthorized DHCP server on the network that hands out false settings, such as the attacker’s default gateway or DNS server.
Network Attacks · Domain 4
root bridge
The switch elected as the central reference point of a Spanning Tree topology, chosen by the lowest bridge priority.
Network Attacks · Domain 4
root guard
A switch feature that blocks a port from accepting a switch that tries to become the root bridge, keeping the root where the administrator placed it.
Defense Techniques & Solutions · Domain 4
RSA
A widely used asymmetric encryption algorithm, common for key exchange and digital signatures.
Security Fundamentals · Domain 4
SASE
Secure Access Service Edge (pronounced “sassy”) — a cloud-delivered service that combines SD-WAN networking with security services such as SWG, CASB, ZTNA, and FWaaS.
Zero Trust & SASE · Domain 4
screened subnet
The modern name for a DMZ — a subnet for public-facing servers whose traffic is screened by firewall rules, keeping them separate from the internal network.
Defense Techniques & Solutions · Domain 4
SD-WAN
Software-Defined Wide Area Network — WAN connectivity managed by central software that steers traffic across multiple links, such as broadband, cellular, and MPLS, by application and link quality.
Zero Trust & SASE · Domain 4
separation of duties
Splitting a sensitive task among more than one person so no single person can complete it alone, which prevents fraud and errors.
Security Fundamentals · Domain 4
session hijacking
Taking over a user’s active, already-authenticated session, usually by stealing or guessing the session token, without needing the password.
Network Attacks · Domain 4
session token
A value, often stored in a cookie, that a website uses to recognize a logged-in user across requests.
Network Attacks · Domain 4
SHA
Secure Hash Algorithm — a family of hashing algorithms; SHA-1 is deprecated, and SHA-2 (such as SHA-256) is widely used.
Security Fundamentals · Domain 4
shadow IT
Cloud apps and services that employees use without the IT department’s knowledge or approval.
Zero Trust & SASE · Domain 4
shoulder surfing
Watching someone enter a password or PIN, or read a screen, from over their shoulder.
Network Attacks · Domain 4
signature-based
A detection method that matches traffic against known attack patterns — accurate for known threats, but blind to new ones.
Defense Techniques & Solutions · Domain 4
smishing
SMS phishing — social engineering carried out through text messages.
Network Attacks · Domain 4
social engineering
Manipulating people, instead of technology, into giving up information or access.
Network Attacks · Domain 4
spear phishing
Phishing aimed at a specific person or group, personalized with details like their name, role, or coworkers to look convincing.
Network Attacks · Domain 4
SQL injection
An attack that inserts database commands into a web form or URL so the application runs them, letting the attacker read or change data.
Defense Techniques & Solutions · Domain 4
SSE
Security Service Edge — the security half of SASE: cloud-delivered security services such as SWG, CASB, and ZTNA (often FWaaS), without the SD-WAN networking part.
Zero Trust & SASE · Domain 4
SSO
Single Sign-On — signing in once with one set of credentials to reach many applications, without signing in to each separately.
Zero Trust & SASE · Domain 4
stateful
A firewall that tracks the state of connections in a state table, so it automatically allows return traffic for connections that inside devices started and drops packets that don’t belong to a known connection.
Defense Techniques & Solutions · Domain 4
stateless
A firewall or filter that examines each packet on its own, by header details like IP address, port, and protocol, with no memory of earlier packets.
Defense Techniques & Solutions · Domain 4
STP manipulation
An attack that sends crafted BPDUs to win the root bridge election in Spanning Tree, letting the attacker redirect or disrupt traffic.
Network Attacks · Domain 4
supplicant
In 802.1X, the client device that requests access and must prove its identity.
Defense Techniques & Solutions · Domain 4
SWG
Secure Web Gateway — a service between users and the internet that filters web traffic, blocks malicious sites and downloads, and enforces acceptable use.
Zero Trust & SASE · Domain 4
symmetric encryption
Encryption that uses the same single secret key to encrypt and decrypt — fast, but the key has to be shared safely (AES is a common example).
Security Fundamentals · Domain 4
SYN flood
A DoS attack that sends a huge number of TCP connection requests (SYN packets) and never completes the handshake, tying up the server with half-open connections.
Network Attacks · Domain 4
TACACS+
Terminal Access Controller Access-Control System Plus — a Cisco-developed AAA protocol that keeps authentication, authorization, and accounting separate, used mainly for device administration (TCP port 49).
Security Fundamentals · Domain 4
tailgating
When an unauthorized person follows an authorized one through a secured door without using their own credentials.
Security Fundamentals · Domain 4
tamper detection
A feature or seal that shows when a device or its enclosure has been opened or altered.
Security Fundamentals · Domain 4
threat
Anything that could cause harm to a system or its data, such as an attacker, malware, or a natural disaster.
Security Fundamentals · Domain 4
TLS inspection
Decrypting HTTPS traffic so security tools can examine it for threats, then re-encrypting it before it continues.
Zero Trust & SASE · Domain 4
trojan
Malware disguised as legitimate or desirable software; it doesn’t self-replicate and relies on tricking the user into installing it.
Network Attacks · Domain 4
virus
Malware that attaches itself to a legitimate file or program and spreads when a user runs that file.
Network Attacks · Domain 4
vishing
Voice phishing — social engineering carried out over a phone call.
Network Attacks · Domain 4
VLAN hopping
An attack that lets an attacker reach VLANs they shouldn’t, using switch spoofing (trunk negotiation) or double tagging.
Network Attacks · Domain 4
vulnerability
A weakness in a system, process, or configuration that a threat could take advantage of, such as unpatched software or a default password.
Security Fundamentals · Domain 4
WAF
Web Application Firewall — a firewall that inspects HTTP and HTTPS requests to protect a web application from attacks like SQL injection and cross-site scripting.
Defense Techniques & Solutions · Domain 4
whaling
Spear phishing aimed at senior executives or other high-value targets.
Network Attacks · Domain 4
worm
Self-replicating malware that spreads across networks on its own, without any user action, often by exploiting vulnerabilities.
Network Attacks · Domain 4
zero trust
A security model that never trusts any user, device, or connection by default and verifies every access request — identity, device health, and context — no matter where it comes from: “never trust, always verify.”
Security Fundamentals · Domain 4
zero-day
A vulnerability the software’s vendor doesn’t know about yet, so no patch exists — attackers get to use it with zero days of warning for defenders.
Security Fundamentals · Domain 4
ZTNA
Zero Trust Network Access — a service that connects a verified user to specific applications, not the whole network, after checking identity, device health, and context.
Zero Trust & SASE · Domain 4
Domain 5 — Network Troubleshooting 100
110 block
A wiring block where wires from many cables are punched down, often behind patch panels.
Troubleshooting Tools · Domain 5
arp
A command that shows or edits a computer’s ARP cache, the table of IP-address-to-MAC-address matches it has learned on the local network.
Troubleshooting Tools · Domain 5
asymmetric routing
When traffic to a destination and the replies back take different paths; often harmless, but a stateful firewall that sees only one direction may drop the traffic.
Connectivity & Performance Issues · Domain 5
auto-MDIX
Automatic Medium-Dependent Interface Crossover — a port feature that detects the transmit and receive pairs and swaps them automatically, so straight-through and crossover cables both work.
Cabling & Physical Issues · Domain 5
auto-negotiation
A process where two connected ports exchange their capabilities and agree on the best speed and duplex setting they both support.
Cabling & Physical Issues · Domain 5
bad port
A switch or device port that has failed physically or electrically, so no link comes up even with a known-good cable and device.
Cabling & Physical Issues · Domain 5
bandwidth
The maximum amount of data a link can carry per second, such as 1 Gbps; think of it as the size of the pipe, not how much actually flows.
Connectivity & Performance Issues · Domain 5
bend radius
The tightest curve a cable can be bent without damage; bending it tighter can break copper conductors or fiber and increases signal loss.
Cabling & Physical Issues · Domain 5
bottleneck
The slowest or most overloaded point on a path, which limits the speed of the whole path.
Connectivity & Performance Issues · Domain 5
bottom-to-top
A troubleshooting approach that starts at the OSI Physical layer (1) and works up toward the Application layer (7); useful when hardware or cabling is suspected.
The Troubleshooting Methodology · Domain 5
cable tester
A tool that checks a copper cable’s wiring for opens, shorts, and miswires.
Cabling & Physical Issues · Domain 5
congestion
Too much traffic for a link or device to carry at once, so packets queue up, causing delay, jitter, and dropped packets.
Connectivity & Performance Issues · Domain 5
CRC error
Cyclic Redundancy Check error — a frame that arrived corrupted, caught by a failed check value; rising CRC errors suggest a physical problem or a duplex mismatch.
Cabling & Physical Issues · Domain 5
crimper
A tool that presses an RJ45 connector onto the end of a cable.
Troubleshooting Tools · Domain 5
dBm
Decibel-milliwatts — a unit of power level; on fiber it expresses how much light is received, and for Wi-Fi it expresses signal strength (closer to zero is stronger).
Troubleshooting Tools · Domain 5
DHCP scope
The range of IP addresses a DHCP server is set up to hand out on one subnet, along with settings such as the default gateway, DNS server, and lease time.
Connectivity & Performance Issues · Domain 5
DHCP scope exhaustion
When every address in a DHCP scope’s pool is already leased, so new devices can’t get an address and fall back to APIPA.
Connectivity & Performance Issues · Domain 5
dig
Domain Information Groper — a Linux and macOS command that queries a DNS server and shows a detailed answer, including the status, the record’s TTL, and the server that replied.
Troubleshooting Tools · Domain 5
divide and conquer
A troubleshooting approach that starts at a middle OSI layer, often Layer 3 with a ping, then moves up or down depending on the result.
The Troubleshooting Methodology · Domain 5
DNS cache
A temporary store of recent DNS answers kept on a device or DNS server; a cached answer can be stale until it expires or is flushed.
Connectivity & Performance Issues · Domain 5
DNS server
The server a device asks to turn a name into an IP address; the device’s settings must point to a correct, reachable one.
Connectivity & Performance Issues · Domain 5
documentation
The written record of a problem and its resolution — symptoms, cause, actions taken, and outcome — so others can learn from it.
The Troubleshooting Methodology · Domain 5
duplex
Whether a link can send and receive at the same time (full duplex) or only one direction at a time (half duplex).
Cabling & Physical Issues · Domain 5
duplex mismatch
A configuration problem where one end of a link is full duplex and the other half duplex — the link stays up, but performance is poor, with late collisions and CRC errors.
Cabling & Physical Issues · Domain 5
duplicate the problem
Reproducing the problem yourself, if possible, to confirm it is real and to see exactly when it happens.
The Troubleshooting Methodology · Domain 5
escalate
To hand a problem to someone with more expertise, authority, or access — such as a senior technician, another team, or a vendor.
The Troubleshooting Methodology · Domain 5
fiber polarity
The correct pairing of fiber strands so each end’s transmit fiber connects to the other end’s receive fiber; reversed polarity means no link.
Cabling & Physical Issues · Domain 5
full duplex
A link mode where a device can send and receive at the same time, so collisions don’t occur.
Cabling & Physical Issues · Domain 5
half duplex
A link mode where a device can either send or receive, but not both at once, so it takes turns and collisions are possible.
Cabling & Physical Issues · Domain 5
hop
One router crossing on the path to a destination; each hop lowers a packet’s TTL by 1.
Connectivity & Performance Issues · Domain 5
hostname command
A command that prints the name of the computer you’re working on.
Troubleshooting Tools · Domain 5
ICMP
Internet Control Message Protocol — the protocol behind ping and messages such as “TTL expired” and “destination unreachable”; some firewalls block it.
Connectivity & Performance Issues · Domain 5
ifconfig
The older Linux and macOS command that shows a network interface’s IP address, subnet mask, MAC address, and error counters; on many modern Linux systems the ip command replaces it.
Troubleshooting Tools · Domain 5
ip command
The modern Linux command for viewing and managing interfaces, addresses, and routes, such as ip addr and ip route.
Troubleshooting Tools · Domain 5
IP conflict
Two devices on the same network using the same IP address, which causes intermittent connectivity and often an “IP address conflict” warning.
Connectivity & Performance Issues · Domain 5
ipconfig
A Windows command that shows a device’s IP address, subnet mask, default gateway, and DNS servers, and can release, renew, or flush them.
Connectivity & Performance Issues · Domain 5
keystone jack
A small snap-in socket, usually an RJ45 jack, held by a wall plate or patch panel; wires are punched down into it.
Troubleshooting Tools · Domain 5
knowledge base
A searchable collection of documented problems and solutions that technicians can use to fix repeat issues faster.
The Troubleshooting Methodology · Domain 5
late collisions
Collisions detected after the first 64 bytes of a frame have been sent; on a modern switched link they usually point to a duplex mismatch (or an overlong cable).
Cabling & Physical Issues · Domain 5
lessons learned
What the team learned from resolving a problem: what worked, what didn’t, and how to prevent or fix it faster next time.
The Troubleshooting Methodology · Domain 5
light meter
A tool (also called an optical power meter) that measures how much light reaches the end of a fiber link, in dBm, to check signal strength and total loss.
Troubleshooting Tools · Domain 5
link light
The LED on a port that shows whether a link is established, and often its speed or activity; a dark link light usually means no link.
Cabling & Physical Issues · Domain 5
loopback address
127.0.0.1 (::1 in IPv6) — an address that always points back at the device itself; pinging it tests the device’s own TCP/IP stack without using the network.
Connectivity & Performance Issues · Domain 5
loopback plug
A plug that sends a port’s transmit signal straight back to its own receive, used to test whether the port or network interface works.
Cabling & Physical Issues · Domain 5
maintenance window
A scheduled period, often outside business hours, set aside for changes that could interrupt service.
The Troubleshooting Methodology · Domain 5
multimeter
A tool that measures electrical voltage, current, and resistance, and can check the continuity of a wire.
Troubleshooting Tools · Domain 5
netcat
A command-line tool (nc) that opens TCP or UDP connections, often used to test whether a port is open, as in nc -zv host 443.
Troubleshooting Tools · Domain 5
netstat
A command that shows a computer’s active network connections, listening ports, and their states, such as LISTENING, ESTABLISHED, and TIME_WAIT.
Troubleshooting Tools · Domain 5
NEXT
Near-End Crosstalk — crosstalk measured at the same end of a cable where the signal is transmitted, where that signal is strongest and leaks the most into neighboring pairs.
Cabling & Physical Issues · Domain 5
nmap
Network Mapper — a scanner that finds live hosts on a network and the open, closed, and filtered ports on them; use it only on networks you’re authorized to test.
Troubleshooting Tools · Domain 5
nslookup
A command-line tool that asks a DNS server to resolve a name and shows which server answered and what address it returned, used to confirm a DNS problem.
Connectivity & Performance Issues · Domain 5
NXDOMAIN
A DNS reply meaning the name does not exist; nslookup shows it as “Non-existent domain.”
Troubleshooting Tools · Domain 5
open circuit
A cable fault where a wire is broken, so there is no connection on that pin — usually causing no link or missing pairs.
Cabling & Physical Issues · Domain 5
optical attenuator
An inline device that reduces the strength of light on a fiber link, protecting a receiver from a transmitter that is too strong.
Cabling & Physical Issues · Domain 5
OSI model
Open Systems Interconnection model — a seven-layer framework (Physical, Data Link, Network, Transport, Session, Presentation, Application) used to describe network communication and to organize troubleshooting by layer.
The Troubleshooting Methodology · Domain 5
OTDR
Optical Time-Domain Reflectometer — the fiber version of a TDR, showing the location of breaks, bends, splices, and loss along a fiber link.
Cabling & Physical Issues · Domain 5
patch cable
A short, flexible cable used to connect a device to a wall jack or patch panel, or one piece of equipment to another.
Cabling & Physical Issues · Domain 5
ping
A basic test that sends a small message to an address and waits for a reply, showing whether the address is reachable and how long the round trip takes.
Connectivity & Performance Issues · Domain 5
pinout
The arrangement that says which wire connects to which pin of a connector, such as T568A or T568B for an RJ45 plug.
Cabling & Physical Issues · Domain 5
plan of action
The steps you will take to fix a confirmed problem, worked out before making any change, including what the fix could affect and how to undo it.
The Troubleshooting Methodology · Domain 5
PoE budget
The total power a PoE switch can supply across all its ports together; if devices need more than the budget, some lose power or fail to start.
Cabling & Physical Issues · Domain 5
port scanner
A tool that probes a host to find which TCP and UDP ports have a service listening, used for auditing and for checking firewall rules.
Troubleshooting Tools · Domain 5
potential effects
What else a fix could disrupt, such as other users, other services, or downtime — identified while planning, before the change is made.
The Troubleshooting Methodology · Domain 5
preventive measures
Actions taken to stop a problem from happening again, such as applying patches, replacing failing hardware, or adding monitoring.
The Troubleshooting Methodology · Domain 5
probable cause
The most likely reason for a problem based on the evidence gathered — a theory to be tested, not a confirmed fact.
The Troubleshooting Methodology · Domain 5
punchdown tool
A tool that seats wires into the slots of a patch panel, keystone jack, or 110 block and trims the excess; it builds connections and doesn’t test them.
Troubleshooting Tools · Domain 5
QoS
Quality of Service — settings that give priority to important or time-sensitive traffic, such as voice, when a link is busy.
Connectivity & Performance Issues · Domain 5
question the obvious
Checking the simple, common causes first — cable plugged in, device powered on, correct network — before assuming something complex.
The Troubleshooting Methodology · Domain 5
retransmission
Sending data again because the original was lost or corrupted; many retransmissions slow a transfer.
Connectivity & Performance Issues · Domain 5
round-trip time
How long a packet takes to reach a destination and for the reply to come back, in milliseconds; the “time=” value in a ping result.
Connectivity & Performance Issues · Domain 5
route command
A command that shows and edits a host’s own routing table, such as route print on Windows or route -n on Linux.
Troubleshooting Tools · Domain 5
routing loop
A fault where routers’ routes point at each other, so packets circle between them until their TTL runs out.
Connectivity & Performance Issues · Domain 5
SERVFAIL
A DNS reply meaning the server was reached but failed to resolve the name; nslookup shows it as “Server failed.”
Troubleshooting Tools · Domain 5
shielding
A metal foil or braid layer around a cable’s wires, as in STP, that blocks outside electrical noise; it works only when properly grounded.
Cabling & Physical Issues · Domain 5
short circuit
A cable fault where two conductors touch when they shouldn’t, so the signal shorts out — usually causing errors or no link.
Cabling & Physical Issues · Domain 5
signal degradation
Any weakening or corruption of a signal on its way to the receiver, including attenuation, crosstalk, and interference.
Cabling & Physical Issues · Domain 5
spectrum analyzer
A tool that shows all radio-frequency energy across a band, so it can reveal non-Wi-Fi interference such as microwave ovens, cordless phones, and Bluetooth devices.
Troubleshooting Tools · Domain 5
speed mismatch
Two ends of a link that can’t agree on a speed — for example, fixed to different speeds so there is no link, or negotiation falling back to a lower speed than expected.
Cabling & Physical Issues · Domain 5
split pair
A wiring error where wires connect correctly pin to pin but are taken from the wrong twisted pairs, causing heavy crosstalk; a basic continuity test can miss it.
Cabling & Physical Issues · Domain 5
stale DNS record
A DNS record that is out of date, such as one still pointing to a server’s old IP address, so the name leads to the wrong place.
Connectivity & Performance Issues · Domain 5
symptom
An observable sign that something is wrong, such as slow pages, no connectivity, or an unlit link light — as opposed to the cause behind it.
The Troubleshooting Methodology · Domain 5
TCP/IP stack
The software on a device that handles IP addressing and network communication; if it is damaged, even the loopback address fails.
Connectivity & Performance Issues · Domain 5
tcpdump
A command-line packet capture tool for Linux and macOS that prints one line per packet and can filter by host or port.
Troubleshooting Tools · Domain 5
TDR
Time-Domain Reflectometer — a tool that sends a pulse down a copper cable and times the reflection to find the distance to a break or short.
Cabling & Physical Issues · Domain 5
termination
Attaching a connector to the end of a cable; poor termination — untwisted pairs, wrong wire order, or a loose crimp — is a common cause of faults.
Cabling & Physical Issues · Domain 5
theory of probable cause
An educated guess about what is causing the problem, based on the symptoms and evidence, that you test before acting on it.
The Troubleshooting Methodology · Domain 5
ticket
A record in a tracking system that follows a problem from report to resolution, holding its details, actions taken, and outcome.
The Troubleshooting Methodology · Domain 5
tone generator
The half of a toner probe kit that plugs into a cable and sends a tone down it, so the probe can find the cable’s other end.
Troubleshooting Tools · Domain 5
toner probe
A handheld probe that picks up the tone sent along a cable by a tone generator, used to trace a cable through walls and bundles to find its other end.
Cabling & Physical Issues · Domain 5
top-to-bottom
A troubleshooting approach that starts at the OSI Application layer (7) and works down toward the Physical layer (1); useful when the symptom looks like an application problem.
The Troubleshooting Methodology · Domain 5
traceroute
A tool that lists each router a packet passes on the way to a destination, used to find where a path breaks, slows down, or loops.
Connectivity & Performance Issues · Domain 5
tracert
The Windows command that lists each router (hop) between your PC and a destination, with three round-trip times per hop; the Linux and macOS version is traceroute.
Troubleshooting Tools · Domain 5
troubleshooting methodology
A structured, repeatable set of steps for finding and fixing a problem, so you don’t guess or skip ahead — CompTIA’s version has seven steps.
The Troubleshooting Methodology · Domain 5
TTL
Time To Live — a counter in every IP packet that drops by 1 at each router and discards the packet at 0, which stops routing loops; not the same as a DNS record’s TTL, which is how long an answer may be cached.
Connectivity & Performance Issues · Domain 5
TX/RX
Transmit and receive — the pair a device sends on (TX) and the pair it listens on (RX); a link works only when each end’s TX connects to the other end’s RX.
Cabling & Physical Issues · Domain 5
verify full system functionality
Confirming that the original problem is gone and that related services and users still work, and not just that one symptom has stopped.
The Troubleshooting Methodology · Domain 5
VoIP
Voice over IP — phone calls carried as packets over a data network; very sensitive to latency, jitter, and packet loss.
Connectivity & Performance Issues · Domain 5
wavelength
The color of light used on a fiber link, measured in nanometers (nm); the transceivers at both ends must use matching wavelengths.
Cabling & Physical Issues · Domain 5
Wi-Fi analyzer
A program or app that scans for wireless networks and shows each one’s channel and signal strength, used to find crowded channels and weak spots.
Troubleshooting Tools · Domain 5
Wireshark
A widely used graphical protocol analyzer that captures traffic or opens saved captures and decodes each protocol layer.
Troubleshooting Tools · Domain 5
Other terms 5
AP
Access Point — a device that bridges wireless clients onto a wired network, acting much like a switch port for Wi-Fi devices.
encapsulation
The process of wrapping data with a layer-specific header (and, at Layer 2, a trailer) as it moves down the OSI stack.
frame
A unit of data at Layer 2, containing MAC addressing and a trailer used for error detection.
packet
A small chunk of data, plus addressing information, used to transmit data across a network at Layer 3.
PDU
Protocol Data Unit — the general term for a unit of data at a given OSI layer (for example, a frame at Layer 2 or a packet at Layer 3).