300-410 cheat sheet

A one-page reference for the Cisco CCNP Enterprise ENARSI (300-410) exam: the format, how the domains are weighted, and the glossary terms for this exam.

Exam at a glance

Vendor
Cisco
Level
Professional
Questions
90
Time
90 min
Mock pass mark
75%
Domains
4
Practice Qs
127
Code
300-410

Domain weightings

How much of the exam each domain covers. Spend your study time in proportion — the heavier the domain, the more questions you'll see.

Key terms

Administrative Distance
Administrative Distance (AD) is the trustworthiness ranking a router assigns to a routing source, lower being preferred, used to choose between protocols offering the same prefix. ENARSI covers troubleshooting AD across all routing protocols.
Route Redistribution
Route Redistribution injects routes learned by one routing protocol into another, requiring care with metrics, tags, and loop prevention. ENARSI covers troubleshooting redistribution between any routing protocols or sources.
Route Map
A Route Map is an ordered set of match/set clauses used to filter and manipulate routes or implement policy-based routing. ENARSI covers troubleshooting route maps (attributes, tagging, filtering) for any routing protocol.
PBR
Policy-Based Routing (PBR) forwards packets based on a route map's criteria rather than the destination-based routing table. ENARSI covers configuring and verifying PBR under Layer 3 technologies.
EIGRP
EIGRP is Cisco's advanced distance-vector protocol using DUAL for loop-free paths and composite metrics. ENARSI covers troubleshooting EIGRP adjacencies, stuck-in-active, and redistribution.
OSPF
OSPF is a link-state IGP that builds a topology database and runs SPF, organized into areas with LSAs. ENARSI covers troubleshooting OSPFv2/v3 adjacencies, path selection, and LSA propagation.
BGP
Border Gateway Protocol (BGP) is the path-vector protocol that exchanges routing and reachability between autonomous systems using attributes for best-path selection. ENARSI covers troubleshooting eBGP/iBGP neighbors and path attributes.
VRF-Lite
VRF-Lite creates multiple isolated Layer 3 routing tables on a single router without MPLS, keeping customer traffic separated. ENARSI covers configuring and verifying VRF-Lite.
MPLS L3VPN
MPLS L3VPN (MPLS Layer 3 VPN) uses VRFs, MP-BGP, and label switching to carry isolated customer routes across a provider MPLS core. ENARSI covers describing MPLS operations and Layer 3 VPN concepts.
DMVPN
Dynamic Multipoint VPN (DMVPN) builds on-demand spoke-to-spoke IPsec tunnels using multipoint GRE and NHRP for scalable hub-and-spoke VPNs. ENARSI covers troubleshooting DMVPN under VPN technologies.
IPsec
IPsec is the suite that authenticates and encrypts IP traffic, used for site-to-site and remote tunnels including within DMVPN. ENARSI covers IPsec as part of VPN technologies.
Infrastructure ACL
An Infrastructure ACL is an access control list that protects the network's core devices and control plane from unwanted traffic. ENARSI covers device and infrastructure security including ACLs and control-plane policing.
CoPP
Control Plane Policing (CoPP) rate-limits traffic destined to the router's control plane to protect the CPU from attacks and overload. ENARSI covers CoPP under infrastructure security.
uRPF
uRPF (Unicast Reverse Path Forwarding) drops packets whose source address fails a reverse-path check: strict mode requires the source to be reachable via the receiving interface, while loose mode only requires a route to the source via any interface. ENARSI covers uRPF among infrastructure security features.
IP SLA
IP SLA generates synthetic probes to measure network performance (latency, jitter, reachability) and can trigger object tracking. ENARSI covers IP SLA and tracking under infrastructure services.