learn/CompTIA Network+

Start here

What the CompTIA Network+ exam is, why the subject is worth certifying when every other exam assumes it, how these lessons are built, how to get something to practise on when you cannot buy a switch, and what is in the track.

Start here·Intro·8 min read·updated ·network-plusnetworkingorientation

What you will be able to do

  • Decide whether this exam is the right one for you to sit
  • Say where your study time should go, from the published domain weights
  • Work through a topic the way it was designed to be worked through
  • Get a network you can break, without owning any network hardware
  • Find the study plan, the coverage report, and the practice sets

This page teaches no networking. It covers what the exam is, where your time should go, how these lessons are built, and how to get a network you can break when you do not own any network hardware. The networking starts on the next page.

What the CompTIA Network+ exam is

A vendor-neutral certification covering the design, implementation, operation and troubleshooting of networks. Vendor-neutral is doing real work in that sentence. The exam names a routing protocol without naming whose implementation, and asks about a switch command family without committing to one vendor’s syntax, because it is testing whether you understand the mechanism rather than whether you have memorised a menu.

Code N10-009, also labelled V9
Launched 20 June 2024
Questions Maximum of 90, multiple-choice and performance-based
Time 90 minutes
Passing score 720 on a scale of 100 to 900
Languages English, German, Japanese, Portuguese, Spanish
Valid for Three years, renewable with 30 CEUs

The scale is not a percentage. 720 out of 900 is not 80 percent, because the scale starts at 100, and CompTIA does not publish how raw answers map onto it. Any tool showing you a scaled score, this site included, is approximating.

CompTIA gives two different answers on experience, and it is worth knowing both before you decide you are not ready. The objectives document asks for “A minimum of 9–12 months of experience in the IT networking field” and stops there. The certification page asks for A+ as well, phrased as “CompTIA A+ certification, with 9 to 12 months of hands-on experience in a junior network administrator or network support technician role”. Neither is a gate. Nobody checks, and this track is written for somebody at zero.

Where your time should go

Five domains, sorted by weight rather than by number, because that ordering is the one that should decide what you study.

Domain Weight
5.0 Network Troubleshooting 24%
1.0 Networking Concepts 23%
2.0 Network Implementation 20%
3.0 Network Operations 19%
4.0 Network Security 14%

Troubleshooting is the largest domain on this exam. Not joint largest. Larger than concepts, and ten points larger than security. Nearly every book and course on the market opens with the OSI model and closes with a troubleshooting chapter that reads like an afterthought, which is exactly backwards from where the marks are. This track gives troubleshooting sixteen topics and puts the diagnostic thinking into the earlier topics too.

The security domain is the other surprise, in the other direction. Fourteen percent, three objectives. If you have come from Security+ or you work in security, the temptation is to spend your evenings there. Resist it.

Performance-based questions, and one piece of good news

PBQs drop you into a simulated tool and score what you leave behind. They are why hands-on time matters more than reading time.

The good news is specific to this exam. CompTIA delivers PBQs either as simulations or inside a virtual environment, and Network+ uses simulations only. That means you can skip a hard one and come back to it, and CompTIA says your work is saved as you go and when you move to another item. The advice you will read elsewhere about being unable to leave a PBQ applies to the virtual kind, which this exam does not use.

Partial credit may be given, and scoring anticipates more than one valid approach. “May” is CompTIA’s word and it is worth keeping: partial credit exists, and how it is apportioned is not published.

Why bother certifying this

Every other certification you might sit assumes it. Security+ talks about segmentation and expects you to know what a broadcast domain is. Cloud exams talk about a virtual private cloud and expect subnetting to be reflex. Linux+ has you configure an interface and read a routing table in the middle of a system administration exam. Networking is the layer underneath the thing you actually want to do, and it is the one people skip and then quietly work around for years.

There is a second reason, which is what this track is organised around. Most networking problems are not solved by knowing more facts. They are solved by being able to say what a network is currently doing, as opposed to what somebody believes it is doing, and then proving it. That skill transfers to every job that touches infrastructure, and it happens to be exactly what a 24 percent troubleshooting domain is testing.

How to work through these lessons

Every topic has the same shape, so once you have read two you know where to look in the third.

Section What it is for
Before you read A question you cannot yet answer. Attempt it anyway.
Some words you will need The vocabulary the rest of the topic assumes
What breaks without this The consequence of not knowing it
Predict Captured output hidden behind a question. Answer first, then open.
If you already work on networks Depth for readers who have done this before. Safe to skip.
Across platforms The same task on a switch, on Linux, and on Windows
Prove it The evidence: a command to run, arithmetic to do, or a named clause in a standard to go and read
What trips people up The failures you will hit, with the real error text
Work it through A scenario reasoned out on the page
Try it Optional, and it does not need hardware
Check yourself Retrieval questions, for next week rather than now
References Every source, with the date it was checked

Troubleshooting topics carry two more. For the exam is the compressed version worth taking into the test centre, and Where this sits places the topic against the objectives.

Three habits make the difference between reading this and learning it.

Attempt the Before you read prompt. Getting it wrong is not a failure mode, it is the mechanism. An answer you guessed at and missed sticks better than one you were handed, and that is a measured effect rather than encouragement.

Commit before you open a Predict block. Some output is hidden behind a question on purpose. Decide on your answer first. Output you have already been shown teaches you very little, and reading it feels productive, which is the problem.

Answer last week’s Check yourself questions from memory before you reread anything. This is the step people skip and the one carrying most of the benefit. Rereading feels like progress because the words come easily the second time. That feeling is fluency, not knowledge, and it is the most reliable way to walk into an exam confident and underprepared.

Where the output comes from

Every block of command output in this track is one of two things, and the page always says which.

Captured means it was produced by running the command on a real network built out of Linux network namespaces, and pasted in unedited. The routers route, the switches learn MAC addresses and run spanning tree, and when a topic shows you a blocked port it is because the protocol blocked it.

Sourced means it came from a standard or from vendor documentation, with the document named. About a third of this exam is cabling, connectors, radio, physical installation and process, and none of that can be captured honestly by software. Those topics say so instead of dressing up a hand-written block as a transcript.

A block is one or the other. Nothing here is typed into a code fence from memory.

The three things alongside the topics

What it is for
Study plan Topics across weeks, each week’s reading returning the following week. Start here if you have a date booked.
Objective coverage Every objective, which topics cover it, how many questions target it. This is where you find gaps, including gaps in this site.
Full practice exam Weighted to the real domain percentages and timed. It appears once the question banks exist; the coverage report is the honest picture until then.

Practice sets cover one domain at a time. They are good for finding a weak area and deliberately not much use for anything else: a set where every question comes from the same domain never makes you choose an approach, so it flatters you.

Getting something to practise on

Here is the awkward part of studying for this exam. You cannot buy the lab. A managed switch, a router, an access point and the cabling to join them is real money and a cupboard you do not have, and the exam expects you to have touched all of it.

Two useful things follow from that.

The first is that most of what the exam tests about switching and routing is reproducible in software, on any Linux machine, for free. Network namespaces give you isolated hosts; virtual Ethernet pairs are the cables between them; a Linux bridge is a switch that genuinely learns MAC addresses, filters VLANs and runs spanning tree. That is how the captured output in this track is made, and the topologies are committed alongside it so you can run the same thing. You need a Linux virtual machine and nothing else.

The second is that the parts you cannot reproduce are also the parts that are cheapest to learn from documentation. A connector is a shape. A cable category is a table of distances and speeds. You do not need to hold an LC connector to answer a question about one, and pretending otherwise would just be an excuse to put off starting.

If you want a graphical network simulator on top of that:

What it is, and the catch
GNS3 Free and open source. It emulates the topology; you supply the device images, so the genuinely free path is open-source routers rather than vendor ones.
Cisco Packet Tracer Free to Networking Academy students, instructors and alumni, which means enrolling in a free course to get it. Apple Silicon support is not something I can confirm from Cisco’s own pages, so check before you plan around it.
subnetipv4.com Not a simulator. Unlimited subnetting problems with worked solutions, which is the one skill on this exam that only volume fixes.

Subnetting deserves that last row. It is arithmetic under time pressure, and no amount of reading substitutes for having done a hundred of them. This track teaches why the arithmetic works and gives you the method. Getting fast is repetition, and somebody else already built the tool for that.

References

Domain weightings and exam details are CompTIA’s published figures. The objectives document itself is copyright CompTIA and is not reproduced here.

Every topic in this track

Generated from the collection, so it cannot fall behind what is actually written. 83 topics so far.

  1. Start hereWhat the CompTIA Network+ exam is, why the subject is worth certifying when every other exam assumes it, how these lessons are built, how to get something to practise on when you cannot buy a switch, and what is in the track.Intro
  2. What a network actually isA cable between two computers does not make a network. What else has to be true, why one machine needs two different addresses, and the arithmetic that decides whether your neighbour is reachable at all.Intro·1.1
  3. MACs, IPs and portsA MAC address, an IP address and a port number identify the same machine at the same moment, and they are not competing answers. What each one is for, how all three travel inside one frame, and which of them survives a trip through a router.Intro·1.1, 1.4
  4. The OSI modelThe OSI model names the parts of a system you have already seen working. What each layer adds, why encapsulation is the mechanism behind it, which model the protocols on your machine actually follow, and the two layers nothing you will meet implements separately.Intro·1.1
  5. The boxes on a networkRouters, switches, firewalls, load balancers, proxies and the rest, sorted by the one question that actually separates them: how far into a frame does this thing read before it acts.Intro·1.2
  6. IPv4 addresses and the maskAn IPv4 address is 32 bits and the mask is a line drawn through them. Where that line falls decides which addresses are neighbours, which two you cannot give to anything, and why the obvious answer to how many machines fit is wrong twice.Intro·1.7
  7. Subnetting by handSplitting a network is the other half of subnetting, and it works in the opposite direction from reading one. Borrowing bits, why a requirement for six networks gets you eight, how to turn a machine count into a prefix, and laying the ranges out with nothing overlapping.Working knowledge·1.7
  8. Address classes, private ranges and APIPASome IPv4 ranges are special and knowing which is worth more than it looks. The classes and why they are obsolete but still examinable, the three private ranges, loopback, and what a 169.254 address is actually reporting.Intro·1.7
  9. IPv6 addressingIPv4 ran dry in February 2011 and the internet carried on, which is the fact worth explaining. What 128 bits buys, how to read and shorten a hex address, the link-local address your machine configured without being asked, and the three ways networks run both protocols at once.Working knowledge·1.8
  10. TCP, UDP and the handshakeTCP sets up a connection, numbers everything, and resends what goes missing. UDP does none of that on purpose. The handshake packet by packet, what retransmission actually costs, the state that lingers after a close, and why a video call chooses the protocol that gives up.Intro·1.4
  11. Ports and the protocols that use themA firewall rule says 443 and nobody explains what that means. The ports this exam expects you to know, a way to learn them that is not brute repetition, the plaintext and encrypted pairs, and the uncomfortable fact that a port number guarantees nothing at all.Intro·1.4
  12. Copper cablingTwisted pair looks the same whatever is printed on the jacket. Why the pairs are twisted at all, what a category number actually promises and why it is not a speed, when shielding helps and when it makes things worse, and the rating on the jacket that has nothing to do with data.Intro·1.5
  13. Fibre and transceiversSingle mode and multimode look identical and are not interchangeable. What actually differs inside the glass, how the OM and OS numbers name it, the connectors and the transceiver form factors, and why a mismatched optic gives you a link that comes up and then fails.Working knowledge·1.5
  14. Physical installationsWhere cabling terminates and why the hierarchy exists, what a rack unit is, which way the air is supposed to travel and what happens when one switch disagrees, sizing power from the load, and the room conditions that decide whether any of it keeps running.Working knowledge·2.4
  15. How a switch learnsA switch is told nothing and works out where everything is by watching. How the forwarding table fills, what happens to a frame whose destination it has not learned yet, why entries expire, and what all of that means for anyone with a packet capture running.Working knowledge·2.2
  16. Unicast, multicast, anycast and broadcastOne packet and four different answers to who gets it. What each delivery type means on the wire, where the boundary of a broadcast actually sits, how multicast avoids sending the same thing twice, and the one that puts a single address in several countries at once.Working knowledge·1.4
  17. VLANsOne switch, two companies, and traffic that must never mix. What a VLAN separates and what it deliberately does not, why a VLAN is exactly a broadcast domain, and the demonstration that separates VLAN membership from subnet membership once and for all.Working knowledge·2.2
  18. Trunking and 802.1Q taggingOne cable between two switches carrying eight VLANs. Where the tag sits in the frame, the four bytes it costs, what the native VLAN is and why it causes arguments, and what happens when the two ends of a trunk disagree about any of it.Working knowledge·2.2
  19. Interface configuration and link aggregationSpeed and duplex, what auto-negotiation does when only one end is playing, why a duplex mismatch produces a slow link rather than a broken one, and what bonding two cables together actually buys you, which is not what most people expect.Working knowledge·2.2
  20. Spanning treeTwo switches, two cables between them, and the whole network stops. Why a layer 2 loop is fatal rather than merely wasteful, how the root bridge is elected, what the port states mean, and what running the protocol costs you.Working knowledge·2.2, 5.3
  21. MTU and jumbo framesSmall requests work and large ones hang forever. What the MTU is, what fragmentation costs, how path MTU discovery is supposed to find the answer, and why blocking one kind of ICMP turns a working network into one that fails only for big packets.Working knowledge·2.2
  22. The routing table and static routesA packet arrives for a network this machine is not on. The routing table is the list of decisions that answers what happens next: connected routes nobody typed, static routes somebody did, longest prefix match, and the default route as the answer of last resort.Working knowledge·2.1
  23. Dynamic routing protocolsForty routers and a link that failed at three in the morning. Why dynamic routing exists, what distinguishes the three protocols this exam names, what an adjacency is, and what convergence looks like when you watch a network repair itself.Working knowledge·2.1
  24. Route selectionTwo routes to the same place and only one goes in the table. The order the three tiebreaks are applied in, why prefix length beats everything including a much better metric, and what administrative distance is actually comparing.Working knowledge·2.1
  25. VLSM and planning an address spaceSix subnets of wildly different sizes and one /22 to fit them in. Allocating largest first and why the order is not a preference, what summarisation buys and what it costs you if you allocate badly, and how to leave room to grow without wasting the space.Working knowledge·1.7
  26. NAT and PATFifty machines behind one public address and everything works. What is actually being rewritten, the table that keeps the conversations apart, why incoming connections are the hard direction, and the reasons NAT is not the security control people believe it is.Working knowledge·2.1
  27. FHRP, virtual IPs and subinterfacesThe default gateway is a single point of failure that every machine on the network is configured to use. First hop redundancy as a concept, the virtual address two routers share, and the subinterfaces that let one physical link carry several networks.Working knowledge·2.1
  28. Topologies and architecturesThe shapes networks are built in, why the data centre abandoned the one every textbook teaches, and what north-south and east-west actually describe. Star, mesh, hub and spoke, three-tier and spine and leaf, with the arithmetic that decides between them.Intro·1.6
  29. SDN, SD-WAN and VXLANTwo hundred branch offices and one policy change. What separating the control plane from the data plane actually buys, what SD-WAN does that a router does not, and VXLAN as layer 2 carried over layer 3 with the byte cost that comes with it.Working knowledge·1.8
  30. Wireless and cellular mediaA radio link is a shared medium with no cable, and almost everything confusing about wireless follows from that one fact. What 802.11 is as a family, why the air is half duplex, and where cellular and satellite genuinely belong.Intro·1.5
  31. Wireless channels and frequenciesTwelve access points in one office and everything is slow. The three bands and what each trades, why only three channels fit in 2.4 GHz, what channel width actually buys, and the regulatory limits that decide what you are allowed to transmit.Working knowledge·2.3
  32. SSIDs, network types and access pointsThe same network name in every room and your laptop moving between them. What SSID, BSSID and ESSID each actually name, why roaming is the client's decision and not yours, the four network types, and what a controller changes.Working knowledge·2.3
  33. Wireless security and authenticationThe password is on a whiteboard and forty people know it. What WPA3 changed and why it mattered, the operational difference between a shared key and per-user identity, what enterprise authentication actually involves, and why two protocols this subject is famous for are absent from the exam.Working knowledge·2.3
  34. Security vocabulary and the CIA triadFive words everybody uses and half of them mean something else. Risk, vulnerability, threat and exploit as four distinct things, why availability is a security property rather than an operations one, and what the triad is for.Intro·4.1
  35. Encryption, certificates and PKIThe padlock proves less than people think. Symmetric and asymmetric in one page, what a certificate actually binds and who vouches for it, and the chain of trust demonstrated by breaking it.Working knowledge·4.1
  36. Identity and access managementThe contractor left in March and the account still works. Authentication against authorisation as two separate questions, what multifactor actually requires, the four authentication services the exam names, and why RADIUS and TACACS+ are not interchangeable.Working knowledge·4.1
  37. Network documentation and diagramsThe person who built it left in 2019. Physical against logical drawings, why layer 2 is the diagram nobody has, what an asset inventory needs beyond a list of boxes, and what makes documentation survive contact with change.Working knowledge·3.1
  38. Lifecycle, change and configuration managementThe switch stopped getting firmware updates two years ago and nothing changed on the day it happened. End of life against end of support, what change management is protecting, and why a backup config nobody has restored is not a backup.Working knowledge·3.1
  39. SNMPA protocol from 1988 that most networks still run, and the two ways it delivers information. Polling against traps, what an object identifier actually is, and why the community string in a version 2c poll is not a password.Working knowledge·3.2
  40. Flow data, capture and port mirroringCounters tell you how much. Flow data tells you who. Packet capture tells you what, at a price you cannot pay for long. Plus where a mirror sits, what that means it cannot show you, and the half of a conversation people lose without noticing.Working knowledge·3.2
  41. Baselines, alerting and monitoring solutionsWhy a number on its own is not evidence of anything, what a threshold does to a metric that has a daily shape, and the two ways a counter lies to the system reading it.Working knowledge·3.2
  42. Disaster recoveryTwo objectives measured from the same moment in opposite directions, three kinds of standby site that differ only in what is already switched on, and the failover step nobody has ever run with users on it.Working knowledge·3.3
  43. DHCPFour messages, two of them shouted by a machine with no address. Plus what a reservation is not, the three deadlines inside a lease, and the one field that lets a server hand out addresses on a subnet it has never seen.Working knowledge·3.4
  44. IPv6 address assignment and SLAACHow a host ends up with three IPv6 addresses nobody configured, the two flag bits in a router advertisement that decide whether DHCPv6 is involved at all, and what happens when two machines claim the same address.Working knowledge·3.4
  45. How DNS resolution worksThe walk from the root down, drawn and then captured on a lab with its own root server. Plus the one flag that separates an answer from a copy of an answer, and why a change you made this morning is still invisible this afternoon.Working knowledge·3.4
  46. What happens when you open a web pageOne capture of one page load, from the first frame to the last, with every step named and tied to its layer. Nine things happen in twelve milliseconds and any one of them failing produces the same sentence from the user.Intro·1.1, 1.4
  47. DNS records and zonesA record type is a question type, which is why moving a website and moving the mail are separate jobs. Plus the five numbers in the SOA, what a zone actually is, and the one place a CNAME is not allowed.Working knowledge·3.4
  48. DNS securityA signed answer proves the zone owner wrote it and hides nothing. An encrypted one hides the question and proves nothing about the answer. Both, demonstrated on a lab that signs its own zone and then breaks it.Working knowledge·3.4
  49. Time protocolsStratum counts hops rather than quality, a clock that is wrong makes a perfectly good certificate look forged, and the fault presents as a security problem on exactly one machine.Working knowledge·3.4
  50. IP protocols and tunnellingThe field in the IP header that says what the payload is, and what happens when the answer is another packet. GRE and IPSec captured from the middle, where one of them shows you everything.Working knowledge·1.4
  51. VPNsWhere the tunnel ends decides everything else. Site to site against client to site, clientless access, and why split tunnel is an argument about policy rather than a setting.Working knowledge·3.5
  52. Managing devices remotelyFour ways in, and the one that still works when the network does not. Plus a jump box that refuses to route, and a device locked out by a single command sent over the connection it broke.Working knowledge·3.5
  53. Physical security and deceptionCameras, locks and badge readers as network controls rather than building ones, why the most effective attack on a data centre needs no exploit at all, and what a honeypot is actually for, which is not catching anybody.Intro·4.1
  54. Compliance and auditsWhy a payment standard and a data protection regulation reach all the way down to how you wire a network, what data locality actually constrains, and why an audit asks you to prove a control works rather than that it exists.Working knowledge·4.1
  55. Access lists, filtering and security zonesThe rule is in the list and traffic still gets through. How a list is evaluated, why order decides everything, what the implicit deny at the bottom is doing, and what a trusted zone actually means once you stop assuming it.Working knowledge·4.3
  56. Network segmentationA vending machine on the same network as the payment system. What segmentation actually enforces, which devices need a segment of their own, and why a guest network is a segmentation decision rather than a wireless one.Working knowledge·4.1
  57. Layer 2 attacksEverything still works and somebody is reading all of it. MAC flooding that turns a switch back into a hub, ARP poisoning that puts an attacker in the middle, and VLAN hopping that crosses a boundary the tagging was supposed to hold, each one captured.Working knowledge·4.2
  58. Attacks on services and peopleThe network is fine and the company has been compromised. Denial of service and the amplification that makes it cheap, the rogue services that answer before the real one does, the evil twin, and the human techniques that are on a network exam for a reason.Working knowledge·4.2
  59. Device hardening and network access controlA switch in a meeting room with sixteen live ports. The cheap controls that close most of the door, why MAC filtering is a speed bump you can watch an attacker step over, and 802.1X, where a port passes nothing but the authentication until the authentication succeeds.Working knowledge·4.3
  60. Cloud concepts and connectivityThe server is in a building you will never visit. Service and deployment models without the marketing, what a virtual private cloud actually is, why a security group is not a firewall appliance, and the two ways to connect your network to a cloud.Working knowledge·1.3
  61. Zero trust, SASE and infrastructure as codeThe old model trusted anything already inside the building. Zero trust checks every request wherever it comes from, SASE moves the controls to where the users are, and infrastructure as code makes the network a repository you can catch drifting from its source.Working knowledge·1.8
  62. The troubleshooting methodologyEverything is broken and you have to start somewhere. CompTIA's seven steps in order, what each one is actually guarding against, why testing the theory can send you back a step, and why the step everyone skips is the one that pays next time.Working knowledge·5.1
  63. Ping, traceroute and what they provePing fails and the server is serving traffic perfectly. What an echo actually tests and what it does not, how traceroute finds each hop by letting a packet die there, why loss at a hop is not loss to the end, and why a failed test proves far less than a successful one.Working knowledge·5.5
  64. Connection and interface toolsSomething is listening on a port and nobody knows what. Listing listening sockets and reading the address each is bound to, seeing who is connected right now, the interface tools on each platform and which name goes with which, and the neighbour table.Working knowledge·5.5
  65. Name resolution toolsThe name resolves on your machine and not on theirs. Querying a specific server instead of the default one, reading an answer section, telling an authoritative answer from a cached copy by one flag, and doing forward and reverse lookups with the tool the exam names.Working knowledge·5.5
  66. Narrowing a fault by layerFifteen candidates, two machines, and one afternoon. Top-down, bottom-up and divide-and-conquer as three named ways to search the stack, why the discriminating test is the only real unit of progress, and why one test in the middle beats ten in a row.Working knowledge·5.1
  67. Cable faults and signal problemsThe link works at 100 Mb and refuses to negotiate 1000. Which faults a continuity tester finds and which it cannot see, why attenuation, crosstalk and interference each leave a different fingerprint, and why the speed a link settles at is the cheapest diagnostic you own.Working knowledge·5.2
  68. Interface counters and port statusThe interface is up and the counters are climbing. Why an error and a drop are different sentences about a frame, what each counter narrows the fault to, why a number is worthless until you read it twice, and how to tell a port that was switched off from one with nothing on the end of it.Working knowledge·5.2
  69. PoE and transceiver problemsSix cameras, one switch, and the sixth one keeps rebooting. Why a power budget is a total rather than a per-port limit, what happens when an injector and a device disagree about the standard, and how a switch tells you a fibre link is dim rather than broken.Working knowledge·5.2
  70. Switching faults, loops and VLANsThe network is saturated and no host is sending anything. What one extra cable does to a switched network in a second, why the root bridge election decides every path in the network, and why a VLAN fault looks exactly like a broken host.Deep dive·5.3
  71. Routing and default gateway faultsLocal traffic is perfect and nothing leaves the building. How the error message tells you how far the packet got, why a missing route and a wrong gateway fail differently, and why traffic taking a path nobody expected is usually one line somebody left behind.Deep dive·5.3
  72. Addressing faultsTwo machines, one address, and connectivity that comes and goes. Why a duplicate address produces intermittent failure rather than an error, why a wrong mask fails one way down the wire and looks like broken hardware, and why an empty DHCP pool looks identical to four other faults from the client.Deep dive·5.3
  73. Wireless performance and roamingFull signal strength, and the connection keeps dropping. Why airtime rather than bandwidth is what a cell shares, why one distant laptop slows a whole room, how a coverage gap and a capacity problem produce identical complaints with opposite fixes, and the channel change nobody made.Deep dive·5.4
  74. Packet capture and protocol analysisThe two teams disagree and the packets settle it. The two decisions to make before you start a capture, why a reset and a silence mean opposite things, how two captures at two points name the device that is dropping traffic, and what a capture of nothing still proves.Deep dive·5.5
  75. Discovery tools and device commandsYou inherit a network and no documentation. Finding what is on a segment and what it is running, getting the devices to describe each other so a diagram builds itself, the four questions a device command answers, and why scanning is a permission question before it is a technical one.Working knowledge·5.5
  76. Bandwidth, congestion and bottlenecksThe link is at 40 percent and everything is slow. Why a five minute average hides a link that was completely full, why contention shares a link rather than slowing it, and why one bulk transfer punishes every other user on the path.Deep dive·5.4
  77. Latency, jitter and packet lossThe call breaks up and the file transfer is fine. Why a packet that arrives late is a packet that is lost when something is waiting for it, why one percent loss costs a TCP transfer most of its speed, and why the same path can be excellent and unusable at the same time.Deep dive·5.4
  78. Quality of serviceThe call breaks up every afternoon and the link is not full for the other twenty-three hours. What a marking is, where the queue that acts on it lives, the difference between shaping and policing, and why your marks stop meaning anything the moment traffic leaves your estate.Working knowledge
  79. Wi-Fi generations and the number on the boxThe exam names no 802.11 letter, so this track never did either. Which amendment each marketing generation maps to, what actually changed at each step, how to take apart the throughput figure on a datasheet, and why the generation that matters is the one your clients have.Working knowledge
  80. How the internet is glued togetherYour router knows how to reach a server in Tokyo and nobody told it. Autonomous systems, the three relationships every network has with its neighbours, why an announcement is a claim rather than a fact, and what the signing system built to check those claims does and does not cover.Working knowledge
  81. Reading the standardsEvery page of this track ends in a list of documents and one of its three forms of evidence is to go and read a named clause. Which document is current, what its status actually means, why MUST and SHOULD are the two most expensive words in networking, and how to get at the ones behind a paywall.Working knowledge
  82. The hour after it breaksTopic 61 gives you a method for finding a fault. This is everything happening around you while you use it: who runs the incident, what to say when you do not know yet, when escalating is the right call, and why a postmortem that names a person has found nothing.Working knowledge
  83. How big networks actually breakThree of the largest failures of recent years, read as faults rather than as news. A backbone that withdrew itself from the internet, a DNS record that automation emptied, and a filter deleted during a tidy-up. All three organisations employ excellent engineers, and none of the causes are exotic.Working knowledge