Sitonce
Country: US
Show exams for United States Hong Kong
Sign in

CCNA Exam Domains and Topics

Updated 9 min read
Key takeaway

The current CCNA 200-301 v1.1 blueprint has six domains: Network Fundamentals (20%), Network Access (20%), IP Connectivity (25%), IP Services (10%), Security Fundamentals (15%), and Automation and Programmability (10%).

  • These percentages show relative topic emphasis, not an exact question count.
  • Cisco lists v1.1 through February 2, 2027; v2.0 begins February 3.
On this page10 sections
  1. Current CCNA blueprint at a glance
  2. Network Fundamentals: build the mental model
  3. Network Access: VLANs and wireless
  4. IP Connectivity: route selection and reachability
  5. IP Services: support host and network operation
  6. Security Fundamentals: protect devices and access
  7. Automation and Programmability: manage at scale
  8. Combine domains in one troubleshooting case
  9. Allocate study by weights and personal gaps
  10. Version boundary

Current CCNA blueprint at a glance

Cisco's current CCNA 200-301 v1.1 exam topics are organized into six domains. The weights help candidates allocate preparation and show why routing and switching deserve substantial practice. They are blueprint percentages, not a promise of a fixed number of questions on every exam form. Cisco does not publish a fixed item count, so do not multiply an assumed count copied from an old site by these weights and call it an official allocation.

DomainWeightStudy focus
Network Fundamentals20%Media, devices, architectures, TCP/UDP, IPv4/IPv6, switching behavior, and virtualization.
Network Access20%VLANs, trunks, EtherChannel, spanning tree, and wireless fundamentals.
IP Connectivity25%Routing tables, static routing, longest-prefix match, and single-area OSPF concepts.
IP Services10%DHCP, DNS, NAT, NTP, SNMP, syslog, QoS, and secure remote access.
Security Fundamentals15%Device access, ACLs, Layer 2 protection, WLAN security, VPN concepts, and AAA.
Automation and Programmability10%Controller-based networking, APIs, data formats, and automation tools.

Network Fundamentals: build the mental model

Fundamentals supplies the vocabulary for later configuration work. Candidates should compare common network architectures and device roles, interpret physical interfaces and media, and understand how hosts and switches forward traffic. The topic list includes common media, topologies, IPv4 and IPv6 addressing, and basic virtualization and cloud concepts.

Addressing is especially important. Given an IPv4 prefix, identify the network, usable host range, and broadcast address. Determine whether two endpoints share a subnet and whether a configured default gateway is reachable locally. For IPv6, read compressed notation and distinguish address categories. TCP and UDP also matter because application behavior depends on transport characteristics: TCP provides connection-oriented delivery and recovery features, while UDP sends datagrams without the same connection setup.

Switches learn source MAC addresses and use their forwarding table to send known unicast frames. Unknown unicast and broadcast traffic is flooded within the VLAN. This behavior helps explain why a Layer 2 loop is dangerous and why VLAN segmentation matters. Learn what a switch does before memorizing commands that configure it.

Network Access: VLANs and wireless

Know how an access port assigned to a VLAN differs from an 802.1Q trunk that carries multiple VLANs. Trunk allowed lists, native VLAN configuration, and mismatches can affect connectivity. Voice VLANs can carry voice and data traffic on an access edge while maintaining logical separation.

EtherChannel combines physical links into a logical connection and can use LACP for negotiation. Spanning Tree Protocol builds a loop-free topology by selecting a root bridge and controlling redundant paths. Understand root selection and common edge safeguards such as PortFast and BPDU Guard. A troubleshooting sequence should inspect VLAN membership and trunk status before changing routing.

Wireless topics include access points, controllers, WLAN components, security mechanisms, and basic configuration interpretation. Identify how a client joins an SSID, which authentication and encryption settings protect it, and what central management contributes. A wireless issue can originate in radio or authentication rather than routing.

IP Connectivity: route selection and reachability

IP Connectivity is the largest domain at 25%. Candidates should interpret routing tables, configure static routes for IPv4 and IPv6, and understand single-area OSPF concepts. A route has a destination prefix and a way to reach it, often through a next hop or outgoing interface. If the next hop cannot be reached, a configured route may not forward traffic as intended.

Longest-prefix match means the most specific matching route is selected. If a table contains a default route and a more-specific route for the destination, the more-specific route wins. Route source, metric, administrative distance, and interface state may explain which entry is active. Work from destination address through table lookup to next hop rather than memorizing isolated output.

OSPF supports dynamic route exchange. At the associate level, understand the purpose of a neighbor relationship, the role of a router ID, and how mismatched settings can prevent adjacency. Keep preparation within the published task scope rather than turning it into an advanced multi-area design course.

IP Services: support host and network operation

IP Services covers configuration, naming, translation, timing, monitoring, and prioritization. DHCP assigns host settings; DNS maps names to addresses; NAT translates address information; NTP synchronizes clocks. SNMP supports monitoring and syslog centralizes messages. QoS prioritizes selected traffic under congestion. SSH provides secure remote management.

A client without a valid address may have a DHCP scope or relay issue. A host that can ping an IP but cannot reach a domain name may have a DNS issue. A private address that needs access to an external destination may require NAT. Identify which service performs the missing step, inspect its configuration or logs, and make a bounded correction.

Security Fundamentals: protect devices and access

Security objectives include threat awareness, device hardening, administrative access, passwords and secrets, ACLs, Layer 2 safeguards, WLAN security, VPN concepts, and AAA. Learn the reason for each control. An ACL evaluates ordered entries and has an implicit deny at the end; placement and direction affect traffic. Strong management access and AAA support accountability. Layer 2 controls reduce attacks such as rogue DHCP behavior or address spoofing.

For a filtering scenario, identify source, destination, protocol, direction, and interface before writing a rule. A correct permit statement in the wrong direction may not solve the problem. A broad permit can restore reachability but expose services. Practice reading rules, predicting which packet matches first, and explaining what is denied by default.

Automation and Programmability: manage at scale

The 10% automation domain reflects controller-based networks, APIs, and structured data. Distinguish device-by-device management from controller-based approaches. Know the difference between an underlay that transports traffic and an overlay that provides logical connectivity over it. Understand basic API requests and JSON's key-value structure.

Tools such as Ansible and Terraform automate repeatable configuration or infrastructure workflows. At this level, recognize why automation improves consistency and reduces repetitive manual work, and interpret a small data object or controller workflow. The objective is foundational understanding, not advanced programming or building a controller.

Combine domains in one troubleshooting case

Suppose a laptop in VLAN 30 receives an address but cannot reach a server in another subnet. Confirm its address, prefix, and gateway under Fundamentals. Verify the access VLAN and trunk carrying VLAN 30 under Network Access. Check the gateway route and remote route under IP Connectivity. If the route exists but traffic still fails, inspect ACLs under Security. DHCP, DNS, and logs under IP Services can isolate configuration or name-resolution issues.

This layered approach prevents unnecessary changes. Adding a static route may not help if a trunk drops the VLAN. Opening an ACL may not help if the host has the wrong mask. Real networks do not label a fault with one blueprint domain; candidates must connect topics.

Allocate study by weights and personal gaps

If you have 20 hours for domain review, a proportional starting plan is about 4 hours for Fundamentals, 4 for Access, 5 for Connectivity, 2 for Services, 3 for Security, and 2 for Automation. Adjust based on diagnostic results. Someone who already works in routing may spend more time on wireless or security. The official percentages are not an obligation to study a fixed number of hours.

  1. Save the official topic list for the exact version you plan to take.
  2. Mark each task as explain, configure, or troubleshoot, then rate your confidence.
  3. Use a simulator for configuration and written reasoning for routes, addressing, protocols, and automation.
  4. Practice across domains and explain distractors, especially for ACL and route problems.
  5. Reassess with fresh practice and change allocation based on recurring errors.

The weights describe relative emphasis, not a guaranteed count. If a third-party resource has a different split, use Cisco's current exam topics as the source of truth for coverage. A resource may group subjects differently, but every official task should map to some lesson or exercise.

Version boundary

Cisco lists February 2, 2027 as the last date to test v1.1 and February 3 as the first date for v2.0. This page describes the current v1.1 map. Candidates testing on v2.0 should use its replacement topic list when Cisco publishes it, rather than assuming names, weights, or task statements remain unchanged.

Build cross-domain practice that starts with a user report and ends with a verified fix. Suppose a host has an address but cannot reach an application. Validate the address and mask, check the local VLAN and trunk, inspect the gateway and route table, then check DNS or ACLs depending on the symptom. This single exercise touches Fundamentals, Network Access, Connectivity, Services, and Security. The exercise should be small enough to explain each step and should not turn into an unstructured network redesign.

The automation domain can be studied without becoming a software engineer. Read a small JSON structure, recognize an API request and response, and understand why a controller can apply similar policy to many devices. Focus on the relationship between data and configuration: structured input is parsed into a repeatable change. A candidate should know the purpose of tools such as Ansible and Terraform, but the official associate-level task list does not require writing a complex automation platform.

Build cross-domain practice that starts with a user report and ends with a verified fix. Suppose a host has an address but cannot reach an application. Validate address and mask, check local VLAN and trunk, inspect gateway and route table, then check DNS or ACLs depending on the symptom. This case touches Fundamentals, Network Access, Connectivity, Services, and Security. Keep it small enough to explain each step rather than redesigning the network.

The automation domain can be studied without becoming a software engineer. Read a small JSON structure, recognize an API request and response, and understand why a controller can apply similar policy to many devices. Focus on the relationship between data and configuration: structured input is parsed into a repeatable change. Candidates should know the purpose of tools such as Ansible and Terraform without needing to build an advanced automation platform.

A candidate should not treat the domains as six isolated silos. A VLAN can be configured correctly but blocked by spanning tree; a route can be correct but unusable because the next hop is unavailable; a service can work but expose management access. The official weights help with coverage, but real troubleshooting follows evidence across layers.

Common questions

What are the current CCNA domain weights?

Network Fundamentals 20%, Network Access 20%, IP Connectivity 25%, IP Services 10%, Security Fundamentals 15%, Automation and Programmability 10%.

What is the largest domain?

IP Connectivity at 25%.

Are percentages exact question counts?

No. They express relative blueprint emphasis.