300-410 cheat sheet
A one-page reference for the Cisco CCNP Enterprise ENARSI (300-410) exam: the format, how the domains are weighted, and the glossary terms for this exam.
Exam at a glance
Vendor
Cisco
Level
Professional
Questions
90
Time
90 min
Mock pass mark
75%
Domains
4
Practice Qs
127
Code
300-410
Domain weightings
How much of the exam each domain covers. Spend your study time in proportion — the heavier the domain, the more questions you'll see.
Key terms
- Administrative Distance
- Administrative Distance (AD) is the trustworthiness ranking a router assigns to a routing source, lower being preferred, used to choose between protocols offering the same prefix. ENARSI covers troubleshooting AD across all routing protocols.
- Route Redistribution
- Route Redistribution injects routes learned by one routing protocol into another, requiring care with metrics, tags, and loop prevention. ENARSI covers troubleshooting redistribution between any routing protocols or sources.
- Route Map
- A Route Map is an ordered set of match/set clauses used to filter and manipulate routes or implement policy-based routing. ENARSI covers troubleshooting route maps (attributes, tagging, filtering) for any routing protocol.
- PBR
- Policy-Based Routing (PBR) forwards packets based on a route map's criteria rather than the destination-based routing table. ENARSI covers configuring and verifying PBR under Layer 3 technologies.
- EIGRP
- EIGRP is Cisco's advanced distance-vector protocol using DUAL for loop-free paths and composite metrics. ENARSI covers troubleshooting EIGRP adjacencies, stuck-in-active, and redistribution.
- OSPF
- OSPF is a link-state IGP that builds a topology database and runs SPF, organized into areas with LSAs. ENARSI covers troubleshooting OSPFv2/v3 adjacencies, path selection, and LSA propagation.
- BGP
- Border Gateway Protocol (BGP) is the path-vector protocol that exchanges routing and reachability between autonomous systems using attributes for best-path selection. ENARSI covers troubleshooting eBGP/iBGP neighbors and path attributes.
- VRF-Lite
- VRF-Lite creates multiple isolated Layer 3 routing tables on a single router without MPLS, keeping customer traffic separated. ENARSI covers configuring and verifying VRF-Lite.
- MPLS L3VPN
- MPLS L3VPN (MPLS Layer 3 VPN) uses VRFs, MP-BGP, and label switching to carry isolated customer routes across a provider MPLS core. ENARSI covers describing MPLS operations and Layer 3 VPN concepts.
- DMVPN
- Dynamic Multipoint VPN (DMVPN) builds on-demand spoke-to-spoke IPsec tunnels using multipoint GRE and NHRP for scalable hub-and-spoke VPNs. ENARSI covers troubleshooting DMVPN under VPN technologies.
- IPsec
- IPsec is the suite that authenticates and encrypts IP traffic, used for site-to-site and remote tunnels including within DMVPN. ENARSI covers IPsec as part of VPN technologies.
- Infrastructure ACL
- An Infrastructure ACL is an access control list that protects the network's core devices and control plane from unwanted traffic. ENARSI covers device and infrastructure security including ACLs and control-plane policing.
- CoPP
- Control Plane Policing (CoPP) rate-limits traffic destined to the router's control plane to protect the CPU from attacks and overload. ENARSI covers CoPP under infrastructure security.
- uRPF
- uRPF (Unicast Reverse Path Forwarding) drops packets whose source address fails a reverse-path check: strict mode requires the source to be reachable via the receiving interface, while loose mode only requires a route to the source via any interface. ENARSI covers uRPF among infrastructure security features.
- IP SLA
- IP SLA generates synthetic probes to measure network performance (latency, jitter, reachability) and can trigger object tracking. ENARSI covers IP SLA and tracking under infrastructure services.