🇺🇸 Cisco Certified Network Associate (CCNA) · flashcards

Cisco Certified Network Associate (CCNA) Network Access Flashcards

80 question-and-answer cards covering Network Access as it is examined in Cisco Certified Network Associate (CCNA). 24 of them are printed below, taken from across the deck — no signup, no paywall on the preview.

80Cards in deck
24Free preview
17Syllabus topics
~146Chars per answer
FreePrice

24 sample cards from the Network Access deck

Sampled from the end of the deck, so these are different cards from the ones shown on the syllabus page.

  1. What are CDP's default timers?

    Advertisements sent every 60 seconds; holdtime (how long info is kept) is 180 seconds.

  2. What commands display detailed CDP neighbor information including IP and IOS version?

    show cdp neighbors detail (or show cdp entry *).

  3. How do you disable CDP globally versus on a single interface?

    Globally: 'no cdp run'. Per interface: 'no cdp enable' under the interface.

  4. What is LLDP and how does it differ from CDP?

    Link Layer Discovery Protocol (IEEE 802.1AB) is the vendor-neutral, open-standard equivalent of CDP for discovering neighbors in multivendor networks; CDP is Cisco-proprietary.

  5. What are LLDP's default timers and how is it enabled?

    Advertisements every 30 seconds, holdtime 120 seconds. Enabled globally with 'lldp run' (LLDP is disabled by default on Cisco devices).

  6. In CDP/LLDP output, what does the 'Local Intrfce' versus 'Port ID' column represent?

    Local Intrfce is the port on your local device; Port ID is the neighbor's port connected to that local interface.

  7. What is a Wireless LAN Controller (WLC)?

    A central device that manages, configures, and controls multiple lightweight access points, handling functions like RF management, security, and roaming in a centralized (split-MAC) architecture.

  8. What is the difference between an autonomous AP and a lightweight AP?

    An autonomous AP is standalone with a full local configuration; a lightweight AP relies on a WLC for configuration and control, using the split-MAC architecture.

  9. What protocol do lightweight APs use to communicate with a WLC, and what does it tunnel?

    CAPWAP (Control And Provisioning of Wireless Access Points); it uses a control tunnel (UDP 5246) and a data tunnel (UDP 5247) between AP and WLC.

  10. In the split-MAC architecture, which MAC-layer functions stay on the AP versus move to the WLC?

    Real-time functions (beacons, ACKs, encryption, frame transmission) stay on the AP; management functions (authentication, association, security policy, RF management) move to the WLC.

  11. List common Cisco lightweight AP operating modes.

    Local (default), FlexConnect (local switching when WLC link is down), Monitor, Sniffer, Rogue Detector, Bridge/Mesh, SE-Connect, and Flex+Bridge.

  12. What does FlexConnect mode allow an AP to do?

    Switch client data traffic locally at the branch and continue operating even if the WAN link to the WLC fails, instead of tunneling all traffic back to the controller.

  13. What are the main WLC interface types used for management and traffic?

    Management interface (in-band management/AP communication), Virtual interface (client auth/DHCP relay, e.g., 1.1.1.1), Service port (out-of-band management), and Dynamic interfaces (mapped to WLANs/VLANs).

  14. How do administrators typically access a WLC for management?

    Via HTTPS GUI to the management or service-port IP, SSH/Telnet CLI, or the console port; the management interface handles in-band access while the service port provides out-of-band access.

  15. On a WLC, what is a 'dynamic interface' and why is it important?

    A logical interface mapped to a VLAN that connects a WLAN to the wired network; client traffic for a WLAN egresses through its associated dynamic interface's VLAN.

  16. What three components are bound together when creating a WLAN on a WLC?

    The SSID (and profile name), a WLAN ID, and an interface/interface group (VLAN) that carries the WLAN's traffic, plus the security policy.

  17. In the WLC GUI, under which main tab do you create and configure WLANs?

    The WLANs tab (WLANs > Create New), where you set the SSID, interface mapping, and security settings.

  18. What is the difference between an SSID and a WLAN?

    The SSID is the wireless network name broadcast to clients; a WLAN is the full logical configuration on the WLC (SSID + VLAN interface + security/QoS policies) that delivers that network.

  19. What are the main Layer 2 wireless security options from weakest to strongest?

    Open (none) and WEP (deprecated/insecure), then WPA, WPA2, and WPA3 — with WPA2/WPA3 using AES-CCMP encryption being the recommended choices.

  20. Compare WPA2-Personal and WPA2-Enterprise authentication.

    WPA2-Personal (PSK) uses a shared pre-shared key for all users; WPA2-Enterprise (802.1X) authenticates each user individually against a RADIUS/AAA server with unique credentials.

  21. What encryption and integrity method does WPA2 use?

    AES encryption with CCMP (Counter Mode with CBC-MAC Protocol) for confidentiality and integrity, replacing WPA's weaker TKIP.

  22. What is 802.1X and what three roles does it define?

    An IEEE port-based access control framework for authentication. Roles: Supplicant (client), Authenticator (AP/WLC), and Authentication Server (RADIUS).

  23. Why is WEP considered insecure and unsuitable for modern WLANs?

    WEP uses the weak RC4 cipher with short, reusable initialization vectors (IVs), allowing the key to be cracked quickly; it is deprecated and should never be used.

  24. When configuring Layer 2 security for a WLAN in the WLC GUI, where do you set WPA2/PSK?

    Under WLANs > (the WLAN) > Security > Layer 2 tab, where you choose WPA+WPA2, enable WPA2 Policy/AES, and set either PSK or 802.1X (AAA server).

What this deck covers

The Network Access deck follows the Cisco Certified Network Associate (CCNA) Network Access syllabus — 5 chapters and 17 topics — so questions land on material that is genuinely examinable rather than trivia around it. That works out to roughly 16.0 cards per chapter.

Answers are written to be recallable, not just readable — averaging about 146 characters, which is long enough to carry the reasoning and short enough to say out loud.

A deck like this earns its keep on the second and third pass. Read the syllabus first so you know the shape of the subject, then use the cards to find the specific facts that have not stuck.

Network Access flashcards FAQ

How many Network Access flashcards are in this Cisco Certified Network Associate (CCNA) deck?

80 cards. This page previews 24 of them, sampled evenly across the deck so you can judge the difficulty before installing anything.

Are these Cisco Certified Network Associate (CCNA) flashcards free?

Yes. The preview here is free to read with no signup, and the full 80-card deck is free inside the Examius app.

What do the Network Access cards cover?

They follow the Cisco Certified Network Associate (CCNA) Network Access syllabus — 5 chapters and 17 topics — so the questions track what is actually examinable.

How should I use these flashcards?

Read the syllabus first so you know the shape of the subject, then drill the deck. Examius schedules each card with spaced repetition, so cards you keep missing come back sooner and ones you know drift further apart.