Cisco CCNA 200-301 v2.0 Exam Blueprint

Check Cisco CCNA v2.0 domain weights, task depth and exam-version dates, then map the official scope to independent practice.

Upcoming exam: v2.0 testing starts February 3, 2027. Testing earlier? Use CCNA v1.1 .

Official v2.0 structure

Cisco’s 200-301 v2.0 topic document specifies a 120-minute exam with five weighted domains. Testing begins February 3, 2027. The document does not state a fixed number of questions; our public 100-question set is an editorial practice length.

DomainWeightPreparation focus
Network Infrastructure and Connectivity25%Physical faults, virtualization, IPv4/IPv6, wireless, host connectivity and DHCPv4
Switching and Network Access25%VLANs, trunks, LACP, SVIs, PoE, discovery, diagnostic tools and Rapid PVST+
IP Routing20%FIB decisions, IPv4/IPv6 static routing, single-area OSPFv2/OSPFv3 and FHRP status
Network Services and Security20%AAA, secure transfer, NAT/PAT, DNS, IPsec, IPv4 ACLs and Layer 2 protections
AI, Network Operations, and Management10%Agentic AI, prompts, management approaches, SNMP, Ansible and syslog

What the detailed objectives add

  • Connectivity: physical and wireless troubleshooting, host connectivity checks, and DHCPv4 server, client and relay troubleshooting.
  • Access: switched and routed links, LACP, SVI configuration, PoE checks, packet capture and Rapid PVST+ protection behavior.
  • Routing: routing-table decisions, static IPv4/IPv6 routes and single-area OSPFv2/OSPFv3. Neighbor authentication is excluded from the stated OSPF configuration objective. HSRP and VRRP appear in operational-status interpretation.
  • Services and security: local users and AAA clients, SFTP/SCP, NAT/PAT on IOS XE, named DNS record types, IPsec, IPv4 ACLs, DHCP snooping, DAI, storm control, RA guard and port security.
  • Operations: agentic AI and prompt components, management approaches, SNMP, Ansible command execution and syslog interpretation.

These are study pointers paraphrased from Cisco’s detailed document. Read the full official objective and its verb before deciding how deeply to practise.

Translate scope into operational study tasks

The following preparation map is editorial guidance built around the official domains. It emphasizes the evidence a learner should be able to interpret or produce. It does not predict particular live exam questions or replace Cisco’s complete topic document.

Infrastructure and connectivity: begin with the affected endpoint

Use actual host configuration, interface evidence and the stated topology to decide where the failure begins. A wrong mask can change whether the host ARPs locally; an absent DHCP relay can prevent an address exchange even when a statically configured host reaches the server. A strong wireless signal does not establish a successful security exchange or working DNS.

Review virtualization roles alongside physical and IP connectivity. When diagnosing counters or signal information, distinguish a supported conclusion from a plausible cause needing another check.

Useful study artifact: a client-to-server dependency map with one controlled physical, addressing or DHCP fault and the evidence that isolates it. Include an IPv6 case rather than assuming IPv4 success validates both stacks.

Switching and access: verify the configured path

Build and inspect VLANs, trunks, routed interfaces, SVIs and LACP where your lab supports them. Incorporate a phone, AP or virtualized-host context so port configuration follows the endpoint requirement. Compare CDP/LLDP observations with the network drawing; documentation can be the incorrect input.

Work with Rapid PVST+ configuration and protection features. Interpret an alternate path or inconsistent state in terms of the intended root and trust boundary. A protection action can be correct even when it interrupts an unexpected attachment.

Useful study artifact: a topology with expected and observed VLAN carriage, root/port roles, channel membership and endpoint power/connectivity. Confirm the service after restoring the intended state.

IP routing: keep control and forwarding evidence separate

Determine the most specific matching installed route, then check the next hop and reverse path. Practise default, host, network and floating static routes for IPv4 and IPv6. A backup configuration is only meaningful when you understand which failure causes the preferred route to disappear.

Configure single-area OSPFv2 for IPv4 and OSPFv3 for IPv6 using your image’s supported syntax. Verify neighbors and advertised prefixes separately. For first-hop redundancy, interpret virtual addresses and roles together with the gateway actually configured on the client.

Useful study artifact: a dual-stack route/neighbor record and a source-specific test that exposes a missing return route. Include an HSRP or VRRP status exercise where a healthy protocol state does not automatically mean every client is correctly configured.

Services and security: restore service while retaining policy

Use named DNS record types to diagnose the specific name-to-service dependency. Inspect NAT/PAT through translations and packet direction. Treat management AAA and secure file transfer as operational tasks with particular endpoints and permissions.

For IPv4 ACLs and Layer 2 protections, document both the permitted behavior and the traffic or attachment that should remain prohibited. An overly broad fix is not correct simply because one positive test succeeds. Distinguish DHCP snooping, ARP validation, router-advertisement protection and source-MAC limits by what they inspect.

Useful study artifact: an acceptance-test table with one allowed flow, two prohibited flows and the relevant management-access check, accompanied by the smallest justified configuration change.

AI and operations: evaluate incomplete evidence honestly

An AI assistant can summarize output or propose a diagnosis, but its statements need to be checked against supplied facts. Practise choosing a prompt with the relevant sanitized evidence, constraints and output structure. Identify unsupported assumptions and requests that exceed the intended scope.

Use a scoped Ansible collection task and reconcile its inventory with per-device results. Read syslog and SNMP evidence in context. Successful command execution on one device does not validate another device that was unreachable, and a message’s severity alone does not establish the incident’s cause.

Useful study artifact: a short review separating observed facts, hypotheses, missing evidence and verification steps. The scenario guide includes both a proposed ACL repair and an automation-result exercise.

What changes for someone moving from v1.1?

The foundations remain useful, but a version change requires more than changing the title on a study set. Compare the depth of the tasks you can perform. OSPFv3, operational FHRP interpretation, broader DHCP troubleshooting, configuration of additional protection features and explicit AI/automation work need their own practice.

Some concepts already appeared in v1.1. AI is not entirely new to CCNA; the upcoming version makes operational evaluation more explicit. Similarly, a familiar service name does not imply identical task depth. Read each verb before deciding whether recognition, output interpretation or configuration is required.

Use the six-stage plan to retain demonstrated fundamentals and target the gaps. Do not restart every familiar topic from zero, and do not assume a good score on a v1.1 set establishes readiness for all v2.0 tasks.

Choose the right preparation method

SkillEvidence of useful practice
DiagnoseA hypothesis narrowed by a check that distinguishes plausible causes
ConfigureAn intended state produced on a supported platform
InterpretA conclusion tied to the exact output field, route or topology fact
VerifyA recovery test from the affected path, with restrictions still satisfied
Evaluate an AI recommendationA comparison of the proposal with facts, constraints and unanswered questions

The Cheat Sheet is a recall aid; it cannot replace these activities. Written questions, labs and official documentation contribute different evidence of readiness.

How the public set is organized

The sample allocates 25, 25, 20, 20 and 10 questions to the five domains. It uses single-answer configuration, output and troubleshooting scenarios from the available practice bank. This is not an official item-format distribution or a substitute for labs.

For a v1.1 appointment, use the current six-domain blueprint . Both versions share networking foundations, but their weights and named tasks are different. Recheck Cisco’s official guidance before booking or changing your appointment.

Scope checked September 13, 2026 against Cisco’s v2.0 exam topics and Cisco’s version-transition announcement .