All Exam Questions
Back to All Posts
Networking

CCNA 200-301 Exam Syllabus Breakdown by Domain

August 21, 2026
CCNA 200-301 Exam Syllabus Breakdown by Domain

Understanding the CCNA 200-301 Blueprint

The CCNA 200-301 exam is a single, associate level test that validates your ability to install, configure, operate, and troubleshoot small to medium enterprise networks. Cisco currently runs this exam under blueprint version 1.1, which was refreshed in August 2024 to add generative AI and machine learning awareness, cloud network management concepts, and a stronger emphasis on automation and network programmability compared to earlier versions.

This blueprint remains the active CCNA Exam Objectives through 2026. Cisco has already published a newer CCNA v2.0 blueprint set to take effect in February 2027, restructured around five broader areas with a stronger focus on troubleshooting and operational skills, but candidates preparing right now should continue studying the current v1.1 objectives, since Cisco has explicitly stated there is no need to switch preparation plans yet.

CCNA 200-301 Course Outline: The Six Domains

Here is the complete list of CCNA Test Objectives, organized by domain and official exam weight.

Domain

Weight

Network Fundamentals

20%

Network Access

20%

IP Connectivity

25%

IP Services

10%

Security Fundamentals

15%

Automation and Programmability

10%

Notice that IP Connectivity alone accounts for a quarter of your score, and together with Network Fundamentals and Network Access, these three domains make up 65% of the entire exam. That is where the bulk of your study time should go.

Domain 1: Network Fundamentals (20%)

This domain builds the conceptual foundation everything else depends on, which is why many training programs treat it as an introductory module, similar to a Cisco CCNA Introduction to Networks Syllabus in academic settings.

Key Topics in Network Fundamentals

  • Explaining the role and function of network components like routers, switches, firewalls, and access points

  • Understanding network topology architectures, including two-tier, three-tier, spine-leaf, and cloud based designs

  • Comparing physical interface and cabling types, along with identifying interface and cable issues

  • Understanding IPv4 addressing and subnetting, including calculating subnet masks and identifying valid host ranges

  • Understanding IPv6 addressing, including global unicast, link local, and multicast address types

  • Comparing IPv6 address types and their appropriate use cases

  • Verifying IP parameters for client operating systems, including both IPv4 and IPv6

  • Explaining wireless principles at a foundational level

  • Explaining virtualization fundamentals, including virtual machines and containers

  • Describing switching concepts, including MAC address tables and frame forwarding

Subnetting deserves special attention here, since it consistently trips up first time candidates who understand the theory but have not drilled it enough to calculate quickly and accurately under exam pressure.

Domain 2: Network Access (20%)

This domain shifts from foundational concepts into practical Layer 2 configuration and wireless networking.

Key Topics in Network Access

  • Configuring and verifying VLANs across multiple switches

  • Configuring and verifying interswitch connectivity, including trunking and native VLAN behavior

  • Configuring and verifying Layer 2 discovery protocols

  • Configuring and verifying EtherChannel, including both LACP and static configurations

  • Understanding the purpose of Spanning Tree Protocol and its role in preventing Layer 2 loops

  • Describing Cisco Wireless Architectures and AP modes

  • Describing physical infrastructure connections for wireless access points

  • Describing AP and WLC management access connections

  • Interpreting basic wireless LAN configuration elements, including SSID, WPA, and WPA2

Candidates who come from a purely theoretical background often underestimate how much hands on practice this domain requires, particularly around VLAN and trunking configuration commands.

Domain 3: IP Connectivity (25%)

As the single largest domain on the entire CCNA 200-301 Exam Syllabus, this section deserves the most concentrated study effort of all six.

Key Topics in IP Connectivity

  • Interpreting the components of a routing table, including routing protocol codes, prefixes, and administrative distance

  • Determining how a router makes a forwarding decision by default

  • Configuring and verifying IPv4 and IPv6 static routing

  • Configuring and verifying single area OSPFv2

  • Describing the purpose, functions, and concepts of first hop redundancy protocols

While this domain covers fewer distinct topics than some others, each one goes deep, particularly OSPF configuration and verification, which shows up frequently in scenario based and simulation style exam questions.

Domain 4: IP Services (10%)

This domain covers the services layered on top of basic IP connectivity that keep real networks functional and manageable.

Key Topics in IP Services

  • Configuring and verifying inside source NAT using static and dynamic NAT with overload

  • Configuring and verifying NTP operating in client and server mode

  • Explaining the role of DHCP and DNS within a network

  • Explaining the function of SNMP in network operations

  • Describing the use of syslog features, including facilities and severity levels

  • Configuring and verifying DHCP client and relay

  • Explaining the forwarding per hop behavior concepts related to QoS

  • Configuring network devices for remote access using SSH

  • Describing the capabilities and functions of TFTP and FTP in the network

Though this domain carries a smaller weight, questions here tend to be scenario specific, so understanding when and why you would configure each service matters more than memorizing command syntax alone.

Domain 5: Security Fundamentals (15%)

Security concepts appear woven throughout the exam, but this domain covers the dedicated core security topics directly.

Key Topics in Security Fundamentals

  • Defining key security concepts, including threats, vulnerabilities, exploits, and mitigation techniques

  • Describing security program elements, such as user awareness and physical access control

  • Configuring and verifying device access control using local passwords

  • Configuring and verifying authorization and accounting using AAA

  • Describing wireless security protocols, including WPA, WPA2, and WPA3

  • Configuring and verifying access control lists

  • Configuring Layer 2 security features

  • Comparing authentication, authorization, and accounting concepts

  • Describing wireless security protocols and remote access VPN types

  • Configuring device access control using local passwords

Access control lists deserve particular attention, since they combine networking logic with security decision making, and exam questions frequently test whether you understand both the syntax and the practical placement of ACLs within a network topology.

Domain 6: Automation and Programmability (10%)

The smallest domain by weight, but increasingly relevant as networks shift toward software driven management.

Key Topics in Automation and Programmability

  • Explaining how automation impacts network management

  • Comparing traditional networks with controller based networking

  • Describing controller based and software defined architectures, including separation of control plane and data plane

  • Comparing traditional campus device management with Cisco DNA Center enabled device management

  • Interpreting JSON encoded data

  • Describing characteristics of REST based APIs

  • Understanding basic concepts of configuration management tools, including Puppet, Chef, and Ansible at a conceptual level

This domain is mostly conceptual recognition rather than hands on configuration heavy, making it a manageable finishing point in your study plan once the more technically demanding domains are solid.

How to Prioritize Your Study Time by Domain Weight

Given the weightage distribution across the Latest CCNA Exam Version, here is a sensible way to allocate your preparation hours.

  1. Spend the most concentrated time on IP Connectivity, Network Fundamentals, and Network Access, since together they make up 65% of the exam and cover the technical core of networking itself.

  2. Give Security Fundamentals solid, dedicated attention, particularly ACL configuration and AAA concepts, since 15% is still a meaningful share of your score.

  3. Treat IP Services and Automation and Programmability as important but lighter weight sections, worth thorough understanding but not disproportionate time relative to their combined 20% share.

  4. Build hands on lab practice into every domain rather than treating any single section as purely theoretical, since the CCNA exam consistently rewards practical, applied understanding over memorized definitions.

Conclusion

The CCNA 200-301 Exam Syllabus is built around six domains with clearly defined weights, and understanding that distribution is the single most useful planning tool you have going into your preparation. IP Connectivity, Network Fundamentals, and Network Access together carry the majority of the exam's weight and deserve your most concentrated study time, while Security Fundamentals, IP Services, and Automation and Programmability round out a complete, well prepared candidate profile. Build your study schedule around these weightages, pair every domain with genuine hands on practice, and you will walk into exam day with a realistic, well distributed understanding of exactly what Cisco expects you to know.

Frequently Asked Questions

AllExamQuestions Editorial Team

AllExamQuestions Editorial Team

AllExamQuestions Editorial Team creates high-quality exam preparation content, practice resources, and certification guides to help learners achieve their goals.

Our content is carefully researched, regularly updated, and reviewed for accuracy and relevance.