How to use CCNA flashcards properly

CCNA flashcards work best when each card tests one decision, command, value or protocol behaviour. They are less useful when a card contains an entire configuration or a vague prompt such as “Explain routing”. The aim is to recall the specific fact quickly, then apply it to a scenario.

The CCNA Certification Exam is a timed, computer-based exam with multiple-choice and multiple-response questions, drag-and-drop tasks, and simulation or lab-style questions. It covers networking fundamentals, IP connectivity and services, security fundamentals, automation and programmability, and common operational tasks. Many questions require you to interpret an output, select the next step or correct a configuration.

That means a useful deck should contain more than definitions. It should include:

  • subnetting calculations and usable address ranges;
  • route-selection rules and CLI interpretation;
  • VLAN, trunking, STP and EtherChannel behaviour;
  • common IPv4 and IPv6 services;
  • security configuration intent;
  • verification commands and troubleshooting evidence.

The deck below is designed to be studied, not read passively. For each card, answer before opening the back. Grade yourself on the quality of the answer, not on whether the topic looks familiar. “Good” means you recalled the answer accurately without prompting. “Hard” means you reached the answer but needed time or made a minor error. “Again” means the answer was missing or materially wrong.

The first card is shown face-up in this deck. Work through the remaining cards one at a time, reveal the answer, and assign a grade immediately.

A CCNA deck on this topic ends up looking like this:

Cards — CCNA — Core networking decisions18 due

What is the network address of 192.168.10.77/26?

192.168.10.64. A /26 has blocks of 64 addresses: .0, .64, .128 and .192. The usable host range is 192.168.10.65–192.168.10.126.

All 18 cards
What is the network address of 192.168.10.77/26?192.168.10.64. A /26 has blocks of 64 addresses: .0, .64, .128 and .192. The usable host range is 192.168.10.65–192.168.10.126.
What is the broadcast address for 10.20.8.0/21?10.20.15.255. A /21 has a block size of 8 in the third octet, so 10.20.8.0 covers third-octet values 8–15.
Which IPv4 route is preferred when two routes match the destination?The route with the longest prefix length is preferred. For example, a /27 is preferred over a /24 because it is more specific.
What administrative distance is used by a directly connected route?0. Directly connected routes have the lowest possible administrative distance.
What is the purpose of the default gateway on an IPv4 host?It is the router address the host uses to send traffic for destinations outside its local subnet.
What does 802.1Q tagging identify on a trunk link?The VLAN associated with an Ethernet frame. The native VLAN is sent untagged by default on an 802.1Q trunk.
Which VLAN carries a switch's untagged management traffic when configured as the native VLAN?The native VLAN. Both ends of a trunk should use the same native VLAN where possible to avoid a native-VLAN mismatch.
What does Spanning Tree Protocol prevent?Layer 2 forwarding loops. STP places redundant paths into a blocking or alternate state so that only a loop-free forwarding topology remains.
What is the purpose of PortFast on an access port?It allows an end-host port to move to forwarding quickly instead of waiting through normal STP transitional states. It should not be used on a link to another switch.
What does BPDU Guard do on a PortFast-enabled port?It protects the edge port by placing it into an err-disabled state if a BPDU is received. This helps prevent an unauthorised switch from influencing STP.
What is the difference between an access port and a trunk port?An access port carries traffic for one VLAN, normally untagged. A trunk carries traffic for multiple VLANs using VLAN tags, except for the native VLAN's default behaviour.
What does DHCP offer to a client besides an IPv4 address?It can provide options such as the subnet mask, default gateway and DNS server. The exact options depend on the DHCP configuration.
What is the purpose of the OSPF router ID?It uniquely identifies an OSPF router within the OSPF domain and is used in neighbour relationships and the link-state database.
What is the first address in the usable host range of 172.16.40.0/28?172.16.40.1. The subnet contains .0–.15; .0 is the network address and .15 is the broadcast address.
What does ‘deny’ at the end of an IPv4 standard ACL mean if no explicit permit matches?An implicit deny means the packet is dropped if it has not matched an earlier permit statement.
Where should an extended ACL generally be placed?Close to the source of the traffic being filtered, because an extended ACL can match details such as source, destination and protocol and can stop unwanted traffic early.
What does the command show ip interface brief help you check?It summarises interface IP addresses and their status and protocol state, helping identify interfaces that are administratively down or not operational.
What is the security risk of using Telnet to manage a network device?Telnet sends the session, including credentials, without encryption. SSH is the appropriate secure management protocol when configured and supported.
A focused CCNA flashcard deck covering addressing, switching, routing, services and security.

That is a MySummaries deck, filled with CCNA material. Yours is written from your own notes. Start free

This is a deliberately mixed deck. If every card were a definition, it would not prepare you for output interpretation or configuration questions. The cards also use different levels of recall: some require a number, some require a rule, and some require you to distinguish two similar technologies.

The core facts behind the deck

Do not try to memorise all networking details at the same time. First reduce the board to the facts that cause the most downstream decisions. For CCNA revision, subnet boundaries, longest-prefix matching, VLAN behaviour, basic STP protection, and verification commands are a sensible starting core.

Use the core as a short pre-session check. If you cannot state one of these accurately, repair that gap before adding more cards. A card should then test the fact in a slightly different form, such as calculating a boundary rather than repeating the definition of a prefix length.

The Must-not-miss core for this deck is:

Must not miss coreCCNA — Core networking decisions
Subnetting: /26 blocks by 64, /28 blocks by 16, and /21 blocks by 8 in the third octet when the mask is 255.255.248.0
Routing: longest prefix match is considered before administrative distance; directly connected routes have AD 0
Switching: access ports carry one VLAN; trunks carry multiple VLANs; 802.1Q identifies the VLAN and the native VLAN is untagged by default
STP and edge security: PortFast is for end-host ports; BPDU Guard places a PortFast port into err-disabled state when a BPDU arrives
Verification and security: use show ip interface brief for interface state, prefer SSH to Telnet, and remember the implicit deny at the end of an ACL
The compact CCNA core from which the longer flashcard deck was cut.

The core is not a replacement for practice. It is a filter for deciding what deserves repeated recall. Once the core is reliable, spend more time on scenario cards: “Which route wins?”, “What output would confirm the diagnosis?” and “What is the safest next configuration step?”

A study routine for this CCNA deck

Use the deck in short, consistent sessions rather than reading every answer in one sitting.

First pass: establish accuracy

Study 8–10 cards. Say the answer aloud or type it before revealing the back. For a subnetting card, include the block size and range. For a command card, say what evidence it provides and what it does not prove. This prevents partial recall from being graded as correct.

Second pass: apply a constraint

Turn a fact into a small decision. For example, after recalling that a trunk carries multiple VLANs, ask what you would check if one VLAN worked and another did not. A useful sequence is to check VLAN existence, trunk status, allowed VLANs, native-VLAN consistency, and the endpoint or SVI configuration.

For routing, do not jump straight to a protocol explanation. First compare the destination against the routing table, apply longest-prefix matching, then consider administrative distance and metric where relevant. The route that looks most familiar is not necessarily the route the device will select.

Third pass: practise operational language

CCNA questions often reward precise terminology. Say “the interface is administratively down” rather than simply “the port is broken” when the output supports that conclusion. Say “the packet matched the implicit deny” rather than “the ACL did not work” when no permit statement matched.

Include verification and rollback in configuration recall. A strong answer does not stop at the command. It states what should change, which show command will confirm the result, and what should be checked if the result is unexpected.

Grade by retrieval quality

Use these practical rules:

  • Again: you could not produce the value, rule or command intent;
  • Hard: you answered with hesitation, omitted an important condition, or confused a closely related concept;
  • Good: the answer was accurate and complete without help;
  • Easy: the answer was immediate and you could apply it to a short scenario.

An “Easy” grade should not mean that the topic is permanently learned. It means the interval can be longer. A card involving a subnet calculation may still need regular review even after several easy recalls because a small arithmetic error can change the result.

Turn repeated misses into remediation

When the same card is missed twice, stop simply repeating it. Identify the cause. If 192.168.10.77/26 is difficult, the problem may be block-size calculation rather than the address itself. Create a short repair card such as “What are the /26 boundaries in the last octet?” Then return to the original scenario card.

Configuration misses need the same treatment. If you remember that BPDU Guard protects an edge port but forget what happens when a BPDU arrives, split the fact into behaviour and purpose. If you confuse PortFast with BPDU Guard, make a comparison card that asks what each feature does and where it belongs.

A remediation card waiting after repeated misses looks like this:

Remediation tray

You lost this card twice: a router has routes for 10.10.0.0/16 and 10.10.20.0/24. Which route is selected for 10.10.20.15, and why?

Add cardDismiss
A remediation card waiting after the same CCNA routing error was missed twice.

The answer is the /24 route because it is the longer, more specific prefix. Notice that the remediation question tests the decision rule in a new address range. That is more useful than copying the original answer three times.

How MySummaries helps

MySummaries lets you build a revision board from your own CCNA notes, configuration exercises and lab outputs, then turn the board into cards such as this deck. Cards due for review can be mixed with written mock exams and troubleshooting prompts, so recall is followed by application. Review the platform here: MySummaries.