CompTIA Network+ (N10-009) Exam-Day Cheat Sheet
High-yield OSI layer mappings, critical service ports, IPv4 CIDR subnetting matrices, 802.11 Wi-Fi standards, cabling specifications, and the CompTIA 7-step troubleshooting methodology for last-minute cramming.
๐ Quick Summary / Core Test Principles:N10-009 Quick Rules: OSI: Physical (bits), Data Link (frames/MAC), Network (packets/IP), Transport (segments/TCP/UDP), Session, Presentation, Application; TCP Ports: 20/21 FTP, 22 SSH, 23 Telnet, 25 SMTP, 53 DNS, 80 HTTP, 110 POP3, 143 IMAP, 443 HTTPS, 3389 RDP; UDP Ports: 53 DNS, 67/68 DHCP, 69 TFTP, 123 NTP, 161/162 SNMP, 514 Syslog; Subnetting: /24=254, /25=126, /26=62, /27=30, /28=14, /29=6, /30=2; Wi-Fi: 802.11a (5GHz/54M), 802.11b (2.4GHz/11M), 802.11g (2.4GHz/54M), 802.11n (2.4+5GHz/600M), 802.11ac (5GHz/6.9G), 802.11ax (2.4+5+6GHz/9.6G); Cabling: 100m max for copper; Troubleshooting: 1. Identify -> 2. Establish theory -> 3. Test theory -> 4. Plan action -> 5. Implement -> 6. Verify & Prevent -> 7. Document!
Core Architecture
1. OSI 7-Layer Architecture, PDUs & Device Matrix
| Layer | PDU | Core Functionality | Representative Protocols | Hardware / Devices |
|---|---|---|---|---|
| Layer 7: Application | Data | User-facing network interfaces and application service communication. | HTTP, HTTPS, DNS, DHCP, SSH, SNMP, SMTP | Application Layer Gateways, NGFWs, Proxies |
| Layer 6: Presentation | Data | Data formatting, character encoding, compression, and encryption/decryption. | TLS/SSL, ASCII, JPEG, GIF, MPEG | Software encryption/compression engines |
| Layer 5: Session | Data | Establishes, manages, coordinates, and terminates dialog sessions between endpoints. | NetBIOS, RPC, SOCKS, SIP | Session managers, SIP gateways |
| Layer 4: Transport | Segment (TCP) / Datagram (UDP) | End-to-end communication, port addressing, flow control, and error recovery. | TCP (connection-oriented, reliable), UDP (connectionless, low-latency) | Layer 4 Load Balancers, Stateful Firewalls |
| Layer 3: Network | Packet | Logical IP addressing, path determination across subnets, and packet routing. | IPv4, IPv6, ICMP, IPsec, OSPF, BGP, RIP | Routers, Layer 3 Multilayer Switches |
| Layer 2: Data Link | Frame | Physical MAC addressing, media access control (MAC), and error detection (FCS/CRC). | Ethernet (802.3), Wi-Fi (802.11), 802.1Q VLANs, ARP, STP | Layer 2 Switches, Bridges, Wireless APs, NICs |
| Layer 1: Physical | Bits | Physical electrical, optical, or radio transmission of unstructured raw bitstreams. | 10GBASE-T, 1000BASE-SX, T568A/B, DSL | Hubs, Repeaters, Cables, Fiber Transceivers |
๐ก Pro Tip:Remember top-down encapsulation: Data -> Segment -> Packet -> Frame -> Bits (Don't Spill Peanutbutter For Breakfast).
Port Memorization
2. High-Yield Network Ports & Protocols Quick-Ref
| Port Number | Protocol / Acronym | Transport | Standard Operational Purpose | Security Consideration |
|---|---|---|---|---|
| 20 / 21 | FTP (File Transfer Protocol) | TCP | File transfer (Port 20 data, Port 21 control) | Plaintext credentials; replace with SFTP or FTPS |
| 22 | SSH / SFTP | TCP | Encrypted CLI remote management and secure file transfer | Standard secure management replacement for Telnet |
| 23 | Telnet | TCP | Unencrypted remote command-line terminal access | Strictly prohibited in production; cleartext credentials |
| 25 | SMTP (Simple Mail Transfer Protocol) | TCP | Server-to-server email forwarding | Legacy unencrypted; client submission uses port 587 |
| 53 | DNS (Domain Name System) | UDP & TCP | Hostname resolution to IP addresses (UDP), Zone transfers (TCP) | DNSSEC prevents cache poisoning |
| 67 / 68 | DHCP (Dynamic Host Configuration) | UDP | Automatic IP addressing (Server 67, Client 68) | Protect with DHCP Snooping on untrusted switch ports |
| 69 | TFTP (Trivial File Transfer Protocol) | UDP | Bootstrap and firmware transfer without authentication | No security, used only on isolated management VLANs |
| 80 | HTTP (Hypertext Transfer Protocol) | TCP | Unencrypted World Wide Web browsing | Cleartext; modern networks enforce HTTPS redirects |
| 110 | POP3 (Post Office Protocol v3) | TCP | Email retrieval downloading messages to local client | Unencrypted; use POP3S on port 995 |
| 123 | NTP (Network Time Protocol) | UDP | Clock synchronization across network devices and servers | Crucial for cryptographic certificates and log correlation |
| 143 | IMAP (Internet Message Access Protocol) | TCP | Synchronized email folder access across multiple devices | Unencrypted; use IMAPS on port 993 |
| 161 / 162 | SNMP (Simple Network Management Protocol) | UDP | Network monitoring (161 polling queries, 162 traps) | SNMPv1/v2c use cleartext community strings; use SNMPv3 AuthPriv |
| 389 | LDAP (Lightweight Directory Access Protocol) | TCP | Centralized user and directory queries (Active Directory) | Unencrypted; replace with LDAPS on port 636 |
| 443 | HTTPS (HTTP Secure) | TCP | Encrypted web communications using TLS | Standard web encryption standard |
| 445 | SMB (Server Message Block) | TCP | Windows network file sharing and network printers | Do not expose to public WANs; vulnerable to worms |
| 587 | SMTP Submission | TCP | Authenticated, encrypted email submission with STARTTLS | Modern client-to-server outbound email submission |
| 636 | LDAPS (LDAP over SSL/TLS) | TCP | Encrypted directory authentication using TLS certificates | Secure replacement for LDAP port 389 |
| 993 | IMAPS (IMAP over SSL/TLS) | TCP | Encrypted multi-device email synchronization | Standard secure mobile/desktop email retrieval |
| 995 | POP3S (POP3 over SSL/TLS) | TCP | Encrypted email download | Secure legacy email retrieval |
| 3389 | RDP (Remote Desktop Protocol) | TCP | Microsoft graphical remote desktop administration | Should be protected behind VPN or remote gateway |
๐ก Pro Tip:Common exam trap: DNS uses UDP 53 for standard lookups, but switches to TCP 53 for zone transfers or responses over 512 bytes!
Subnetting Math
3. IPv4 Subnetting & CIDR Quick Calculation Table
| CIDR Prefix | Dotted-Decimal Subnet Mask | Block Size (Increment) | Total IP Addresses | Usable Host Addresses |
|---|---|---|---|---|
| /24 | 255.255.255.0 | 256 | 256 | 254 (2^8 - 2) |
| /25 | 255.255.255.128 | 128 | 128 | 126 (2^7 - 2) |
| /26 | 255.255.255.192 | 64 | 64 | 62 (2^6 - 2) |
| /27 | 255.255.255.224 | 32 | 32 | 30 (2^5 - 2) |
| /28 | 255.255.255.240 | 16 | 16 | 14 (2^4 - 2) |
| /29 | 255.255.255.248 | 8 | 8 | 6 (2^3 - 2) |
| /30 | 255.255.255.252 | 4 | 4 | 2 (2^2 - 2) (Point-to-point link) |
| /31 | 255.255.255.254 | 2 | 2 | 2 (RFC 3021 point-to-point without broadcast) |
| /32 | 255.255.255.255 | 1 | 1 | 1 (Single host / loopback interface) |
๐ก Pro Tip:To find block size quickly: Subtract the non-255 octet from 256 (e.g. for /27 with mask .224: 256 - 224 = 32). Network IDs increment by that number!
Wireless Matrix
4. IEEE 802.11 Wireless Standards Evolution
| Standard | Common Industry Name | Frequency Bands | Maximum Theoretical Data Rate | Key Architectural Innovations |
|---|---|---|---|---|
| 802.11b | Wi-Fi 1 (Legacy) | 2.4 GHz | 11 Mbps | DSSS modulation, 3 non-overlapping channels (1, 6, 11) |
| 802.11a | Wi-Fi 2 (Legacy) | 5 GHz | 54 Mbps | OFDM modulation, avoided 2.4 GHz interference, short range |
| 802.11g | Wi-Fi 3 (Legacy) | 2.4 GHz | 54 Mbps | OFDM in 2.4 GHz band, backward compatible with 802.11b |
| 802.11n | Wi-Fi 4 | 2.4 GHz & 5 GHz | 600 Mbps | MIMO (up to 4 spatial streams), 40 MHz channel bonding |
| 802.11ac | Wi-Fi 5 | 5 GHz only | 6.93 Gbps | MU-MIMO (downlink only), 80 & 160 MHz channel bonding, 256-QAM |
| 802.11ax | Wi-Fi 6 & 6E | 2.4 GHz, 5 GHz & 6 GHz | 9.6 Gbps | OFDMA (Resource Units), bidirectional MU-MIMO, 1024-QAM, BSS Coloring, TWT |
| 802.11be | Wi-Fi 7 | 2.4 GHz, 5 GHz & 6 GHz | 46 Gbps | 320 MHz channels, 4096-QAM, Multi-Link Operation (MLO) |
๐ก Pro Tip:Wi-Fi 6E is NOT a new protocol; it is 802.11ax operating in the pristine, wide 6 GHz band (up to 1,200 MHz of clean spectrum)!
Media Standards
5. Copper & Fiber Cabling Specifications
| Cable Category / Type | Maximum Data Rate | Maximum Certified Distance | Bandwidth Frequency | Primary Deployment Use Case |
|---|---|---|---|---|
| Cat 5e (UTP/STP) | 1 Gbps (1000BASE-T) | 100 meters (328 ft) | 100 MHz | Standard legacy horizontal desktop patching |
| Cat 6 (UTP/STP) | 10 Gbps (10GBASE-T) | 55 meters (10G) / 100 meters (1G) | 250 MHz | Modern commercial horizontal runs; 10G in small offices |
| Cat 6a (Augmented) | 10 Gbps (10GBASE-T) | 100 meters (328 ft) | 500 MHz | Full 100m 10G enterprise data center and backbone cabling |
| Cat 7 (Shielded S/FTP) | 10 Gbps / 40 Gbps | 100 meters (10G) / 50 meters (40G) | 600 MHz | Strictly shielded industrial and high-EMI environments |
| Cat 8 (Shielded S/FTP) | 25 Gbps / 40 Gbps | 30 meters (98 ft) | 2000 MHz (2 GHz) | Top-of-Rack (ToR) data center switch-to-server interconnects |
| OS2 Single-Mode Fiber | 10G / 40G / 100G / 400G | Up to 40 km (25 miles) | 1310 nm & 1550 nm laser | Campus and long-distance WAN backbones (9 ยตm core) |
| OM4 Multimode Fiber | 10G / 40G / 100G | Up to 400 meters (10G) / 150m (40G) | 850 nm VCSEL/LED | Intra-building riser runs and data center short reaches (50 ยตm core) |
๐ก Pro Tip:Cat 6 can only do 10G up to 55 meters; if a question specifies 10G at 90+ meters, the answer MUST be Cat 6a!
Methodology Sequence
6. CompTIA 7-Step Troubleshooting Methodology
| Step Number | Phase Name | Mandatory Technician Actions | Exam Trap to Avoid |
|---|---|---|---|
| Step 1 | Identify the problem | Gather information, duplicate problem if possible, question users, identify symptoms, determine if anything has changed. | Never jump to theories before gathering symptoms and checking what changed! |
| Step 2 | Establish a theory of probable cause | Question the obvious, consider multiple approaches (top-to-bottom, bottom-to-top, divide-and-conquer). | Do not implement solutions during this step; only formulate hypotheses. |
| Step 3 | Test the theory to determine cause | If theory is confirmed, proceed to Step 4. If theory is disproved, establish a new theory or escalate. | Do not execute permanent production fixes in Step 3; only test the hypothesis. |
| Step 4 | Establish a plan of action | Design the exact solution and identify potential unintended side effects on network operations. | Never apply a major configuration without considering side effects and downtime. |
| Step 5 | Implement the solution or escalate | Execute the corrective action or escalate to higher-tier engineering if beyond authority. | Always follow change management windows when implementing. |
| Step 6 | Verify full system functionality | Test user applications, inspect port error counters, and implement preventive measures. | A ticket is NOT resolved until verified with the user and error counters remain zero. |
| Step 7 | Document findings, actions, and outcomes | Log complete post-mortem, update network topology diagrams, and write knowledge base entries. | CompTIA strictly mandates documentation as the mandatory final step. |
๐ก Pro Tip:CompTIA exams heavily test troubleshooting order: 1) Identify -> 2) Theory -> 3) Test Theory -> 4) Plan of Action -> 5) Implement -> 6) Verify -> 7) Document.