Network+ N10-009 Exam Objectives
The N10-009 exam covers 5 domains split into 25 numbered objectives. You get up to 90 questions in 90 minutes, and you need 720 out of 900 to pass. This page lists every objective in plain English, tells you roughly how many questions each domain is worth, and lets you tick things off as you go — so you always know what's left.
Where the questions actually come from
CompTIA publishes how much of the exam each domain is worth. That's genuinely useful information, because it tells you where your study hours will pay off. Here's what those percentages look like on a 90-question exam:
| Domain | Weight | Questions | Objectives |
|---|---|---|---|
| 1.0 Networking Concepts | 23% | ~21 | 8 |
| 2.0 Network Implementation | 20% | ~18 | 4 |
| 3.0 Network Operations | 19% | ~17 | 5 |
| 4.0 Network Security | 14% | ~12 | 3 |
| 5.0 Network Troubleshooting | 24% | ~22 | 5 |
Two things jump out of that table, and both should shape how you study.
Troubleshooting is the biggest domain — and it only has five objectives. That means each one is worth around four or five questions, far more than a typical objective elsewhere. If you skim Domain 5, you're skimming the most valuable part of the exam.
Domains 1 and 5 together are 47% of your score. That's the exam telling you what it cares about: understanding the fundamentals, and being able to work out why something is broken. Neither one is about memorizing a specific product.
Security being the smallest domain surprises a lot of people. Don't take it as permission to skip it — 12 questions is still bigger than the margin most people pass by.
Keep track as you go
Tick off each objective once you're confident with it. Your progress is saved right here in your browser, so you can close the tab and pick up where you left off. Nothing is sent anywhere and you don't need an account.
1.0 Networking Concepts — 23% · ~21 questions
| Done | Objective | What it covers |
|---|---|---|
| 1.1 | OSI & TCP/IP models — layer functions, encapsulation, PDUs, and which devices and protocols live at each layer. | |
| 1.2 | Appliances, applications & functions — router, switch, firewall, IDS/IPS, load balancer, proxy, NAS, SAN, access point, wireless controller, CDN. | |
| 1.3 | Cloud & virtual networking — NFV, VPC, security groups, internet and NAT gateways, Direct Connect, public/private/hybrid models. | |
| 1.4 | Ports, protocols & traffic types — the port list, TCP vs UDP, and unicast/multicast/anycast/broadcast. Full cheat sheet → | |
| 1.5 | Cabling, media & transceivers — 802.3 and 802.11 standards, single-mode vs multimode fiber, DAC/twinax, coax, and cable speed limits. | |
| 1.6 | Topologies & architectures — mesh, hybrid, star, hub-and-spoke, spine-leaf, point-to-point, three-tier and collapsed core. | |
| 1.7 | IPv4 addressing & subnetting — public/private ranges, APIPA, RFC1918, loopback, VLSM, CIDR, classes A–E. Practice questions → | |
| 1.8 | IPv6 & modern environments — address exhaustion, tunneling, dual stack, NAT64, SDN, SD-WAN, VXLAN, zero-trust architecture, SASE. |
2.0 Network Implementation — 20% · ~18 questions
| Done | Objective | What it covers |
|---|---|---|
| 2.1 | Routing technologies — static vs dynamic, BGP, EIGRP, OSPF, administrative distance, prefix length, metrics and route selection. | |
| 2.2 | Switching technologies — VLANs, SVI, native and voice VLANs, 802.1Q tagging, link aggregation, speed/duplex, STP and MTU. | |
| 2.3 | Wireless networking — channels and widths, non-overlapping channels, 2.4/5/6 GHz bands, band steering, SSID/BSSID/ESSID, mesh. | |
| 2.4 | Physical installation, power & environment — MDF/IDF, rack units, port-side exhaust and intake, patch panels, fiber distribution, UPS and PDU. |
3.0 Network Operations — 19% · ~17 questions
| Done | Objective | What it covers |
|---|---|---|
| 3.1 | Documentation & lifecycle management — physical and logical diagrams, rack diagrams, cable maps, asset inventory, EOL/EOS, patching, change management. | |
| 3.2 | Monitoring & observability — SNMP traps, MIBs, v2c vs v3, community strings, flow data, packet capture and baselines. | |
| 3.3 | Disaster recovery & high availability — RPO, RTO, MTTR, MTBF, cold/warm/hot sites, active-active vs active-passive, tabletop exercises. | |
| 3.4 | Network services — DHCP scopes, reservations, lease times, options, relay and IP helper, exclusions, SLAAC, DNSSEC, DoH. | |
| 3.5 | Network access & management — site-to-site, client-to-site and clientless VPNs, split vs full tunnel, SSH, out-of-band management. |
4.0 Network Security — 14% · ~12 questions
| Done | Objective | What it covers |
|---|---|---|
| 4.1 | Security concepts, IAM & compliance — encryption in transit and at rest, certificates and PKI, MFA, SSO, RADIUS, data locality, PCI DSS, GDPR, segmentation. | |
| 4.2 | Network attacks — DoS and DDoS, VLAN hopping, MAC flooding, ARP poisoning and spoofing, DNS poisoning, rogue devices, social engineering. | |
| 4.3 | Hardening & defense — disabling unused ports and services, changing default passwords, NAC, port security, 802.1X and MAC filtering. |
5.0 Network Troubleshooting — 24% · ~22 questions
| Done | Objective | What it covers |
|---|---|---|
| 5.1 | Troubleshooting methodology — the seven ordered steps, from identifying the problem to documenting findings. Know the order, not just the list. | |
| 5.2 | Cabling & physical interfaces — wrong cable type, SMF vs MMF, Cat 5/6/7/8, STP vs UTP, crosstalk, interference, attenuation, bad transceivers. | |
| 5.3 | Network services — STP loops and root bridge problems, port roles and states, VLAN assignment, ACLs, routing tables, default gateways. | |
| 5.4 | Performance & wireless — congestion, contention, bottlenecks, throughput vs bandwidth, latency, packet loss, jitter, interference and coverage. | |
| 5.5 | Tools & device commands — protocol analyzers, ping, traceroute/tracert, nslookup, dig, tcpdump, netstat, ip/ifconfig/ipconfig. |
What order should you study these in?
The numbers are there for reference, not as a recommended path. If you work straight through from 1.1 to 5.5, you'll reach troubleshooting — the biggest domain — right when you're most worn out. Here's an order that works better:
- Start with 1.1, 1.4 and 1.7. The OSI model, ports, and subnetting are the vocabulary the rest of the exam is written in. Questions in other domains quietly assume you already know them, so learning these first makes everything after feel easier.
- Then Domain 2. Routing, switching and wireless are where those ideas turn into real configuration.
- Then Domain 5. Troubleshooting is the biggest slice, and it builds straight on top of what you just learned — it's hard to fix a VLAN problem before you know what a VLAN is.
- Leave Domains 3 and 4 until last. Operations and security involve more straight memorization, and memorized facts stay fresher when you learn them closer to exam day.
Whatever order you pick, take a full timed practice exam early rather than saving it as a final test. A cold score is uncomfortable, but it shows you where the real gaps are. Without it, most people end up studying the topics they already like.
How the scoring works
You need 720 out of 900 — and that's not the same as needing 80%. The scale doesn't start at zero, and CompTIA adjusts for the fact that some versions of the exam are slightly harder than others. In practice: you can get a fair number of questions wrong and still pass comfortably. What you can't afford is being weak across an entire domain.
You'll also meet performance-based questions, usually at the start. These are hands-on simulations, they're worth more than a regular question, and they eat time. If one has you stuck, flag it and move on. Ten multiple-choice questions you never reached will cost you far more than one imperfect simulation.
Find out where you actually stand
Our free practice exam is weighted exactly like the table above, and it scores you domain by domain — so instead of one number you get a map of what to study next. No account needed, and you can retake it as often as you like.
Take a free Network+ practice exam