How to Master One of the Hardest Parts of the Cisco CCNP Enterprise Exam: Infrastructure
Ask CCNP Enterprise candidates which part of the ENCOR 350-401 exam worries them most, and many will say Infrastructure. It’s the largest domain at 30%, and it’s packed with protocols, each with its own states, timers, defaults, and tie-breakers. Questions often show a configuration or show command output and ask what’s wrong, so memorizing definitions isn’t enough.
The good news: Infrastructure is also the most learnable domain. The protocols follow clear rules, and once you understand those rules, the questions become predictable. We’ll walk you through what the domain covers, the concepts that matter most, the traps that catch people, and how to practice.
What Does Infrastructure Cover on ENCOR v1.2?
In the ENCOR 350-401 v1.2 exam topics, Infrastructure is worth 30% of the exam and has three sections:
- 3.1 Layer 2: Troubleshoot 802.1Q trunking and EtherChannels; configure and verify RSTP, MST, and enhancements such as root guard and BPDU guard.
- 3.2 Layer 3: Compare EIGRP and OSPF; configure multi-area OSPFv2/v3 with summarization and filtering; configure eBGP between directly connected neighbors; describe policy-based routing.
- 3.3 IP Services: Interpret NTP and PTP configurations; configure NAT/PAT; configure HSRP and VRRP; describe multicast (RPF check, PIM-SM, IGMPv2/v3, SSM, bidir, and MSDP).
Wireless was part of this domain in v1.1 but was removed in v1.2 (effective March 19, 2026). If your study materials include wireless chapters, you can skip them for ENCOR.
Why Is Infrastructure So Hard?
- Volume. It spans more than a dozen protocols, each with its own behavior.
- Verbs matter. Many items say “troubleshoot” or “configure and verify,” so you must read real configurations and output.
- Defaults are testable. Whether preemption is on by default or what a default priority is can decide a question.
- No going back. Cisco exams don’t let you revisit questions, so you can’t count on a later item to jog your memory.
Core Infrastructure Concepts to Know Cold
Trunking and EtherChannel
Dynamic Trunking Protocol (DTP) negotiates trunks. A port set to dynamic desirable actively tries to form a trunk, while dynamic auto only responds. Two dynamic auto ports never form a trunk; they stay access ports. Trunks also need matching native VLANs and allowed VLAN lists to work cleanly.
For EtherChannel, know the modes:
- LACP (IEEE 802.3ad): active and passive. Active-active or active-passive forms a channel; passive-passive does not.
- PAgP (Cisco proprietary): desirable and auto. Desirable-desirable or desirable-auto forms a channel; auto-auto does not.
- On: forces a channel with no negotiation. It only works if the other side is also set to on.
Member ports must also match on speed, duplex, trunk/access mode, and VLAN settings.
Spanning Tree: RSTP and MST
Rapid Spanning Tree (802.1w) uses port roles of root, designated, alternate, and backup, and port states of discarding, learning, and forwarding. The root bridge is the switch with the lowest bridge ID (priority first, then MAC address). The default priority is 32768, configurable in increments of 4096.
Multiple Spanning Tree (MST, 802.1s) maps many VLANs to a small number of instances. Switches must match region name, revision number, and VLAN-to-instance mapping to be in the same region.
Know the enhancements: BPDU guard err-disables a PortFast port that receives a BPDU, while root guard puts a port into a root-inconsistent state if it receives a superior BPDU, protecting your chosen root placement.
OSPF vs. EIGRP
OSPF is a link-state protocol that uses cost based on bandwidth and supports only equal-cost load balancing. EIGRP is an advanced distance vector protocol that uses a composite metric (bandwidth and delay by default) and supports unequal-cost load balancing with the variance command. Default administrative distances are worth memorizing: eBGP 20, internal EIGRP 90, OSPF 110, and iBGP 200.
For OSPF, two routers must match on area ID, subnet and mask, hello and dead timers, authentication, and stub area flags to become neighbors. They also need matching MTUs to reach the FULL state. Know the area types: standard, stub (blocks external Type 5 LSAs), totally stubby (also blocks inter-area Type 3 LSAs except a default route), and NSSA (allows external routes as Type 7 LSAs). Summarization happens at the ABR (area range) or ASBR (summary-address).
eBGP
eBGP peers are in different autonomous systems and, by default, must be directly connected (TTL of 1). Neighbor states progress through Idle, Connect, Active, OpenSent, OpenConfirm, and Established. A neighbor stuck in Active usually means the TCP session on port 179 isn’t completing, often because of a wrong neighbor address or AS number.
The best path selection order on Cisco routers begins with: highest weight, highest local preference, locally originated, shortest AS path, lowest origin type, lowest MED, and eBGP over iBGP. Knowing that weight is Cisco-specific and local to the router, while local preference is shared within the AS, answers many questions.
IP Services
- HSRP vs. VRRP: Both default to priority 100. HSRP (Cisco) uses active/standby roles and has preemption off by default. VRRP (open standard) uses master/backup roles and has preemption on by default.
- NAT terms: Inside local is the private address of an internal host; inside global is the public address that represents it. PAT (overload) maps many inside hosts to one address using port numbers.
- NTP: Lower stratum means closer to the reference clock. PTP provides more precise timing for applications that need it.
- Multicast: IGMP runs between hosts and routers; PIM runs between routers. PIM-SM uses a rendezvous point (RP) for the shared tree. SSM uses IGMPv3 and the 232.0.0.0/8 range, with no RP needed. The RPF check prevents loops by accepting multicast only on the interface the router would use to reach the source.
- Policy-based routing: A route map applied to an ingress interface can override the routing table, for example, setting a next hop for traffic from a specific subnet.
Common Infrastructure Traps on ENCOR
- Mixing EtherChannel protocols. LACP active on one side and PAgP desirable on the other will not form a channel.
- Assuming higher priority always wins in HSRP. Without preempt, a higher-priority router that comes up later stays in standby.
- Forgetting MTU in OSPF. Neighbors that form but get stuck in EXSTART/EXCHANGE usually point to an MTU mismatch, not a timer or area problem.
- Confusing weight and local preference. Both prefer higher values, but only local preference is shared with iBGP peers.
- Mixing up BPDU guard and root guard. One protects edge ports from any BPDU; the other protects root placement from superior BPDUs.
- Studying removed topics. Time spent on wireless RF or WLC configuration doesn’t help on v1.2.
Sample Scenarios: How to Reason Through Infrastructure Questions
Scenario 1: OSPF Neighbors That Won’t Go FULL
Consider a question showing two routers on the same subnet in area 0. show ip ospf neighbor lists each router, but the state stays at EXSTART. The options include mismatched hello timers, mismatched area IDs, an MTU mismatch, and a duplicate router ID.
Start by eliminating what can’t be true. A hello timer or area mismatch would stop the routers from seeing each other as neighbors at all, so they wouldn’t reach EXSTART. EXSTART and EXCHANGE are where routers swap database description packets, and mismatched MTUs cause those packets to be rejected. The best answer is the MTU mismatch, fixed by matching interface MTUs (or, less ideally, ip ospf mtu-ignore).
Scenario 2: The Router That Should Be Active
Now picture two distribution switches running HSRP for VLAN 10. Switch A has priority 110 and Switch B has the default. After a reload, Switch A comes back up, but Switch B remains active. Why?
Switch A has the higher priority, so the question is really about defaults. HSRP preemption is disabled by default, so a higher-priority router won’t take over from an active peer unless standby 10 preempt is configured. If the same scenario used VRRP, Switch A would take over, since VRRP preempts by default.
How Infrastructure Connects to Other ENCOR Domains
- Architecture: FHRPs and EtherChannel are the building blocks of the high availability designs in domain 1.
- Virtualization: VRFs, GRE tunnels, and SD-Access’s LISP and VXLAN all ride on the routing you learn here.
- Network Assurance: Debugs, IP SLA, and NetFlow are how you verify and troubleshoot Infrastructure problems.
- Security: ACLs, CoPP, and BPDU guard protect the control plane and switching fabric.
- Automation: EEM applets and RESTCONF often automate the same configurations you practice here.
A Focused Plan to Master Infrastructure
- Build a small lab. Four routers and three switches in Cisco Modeling Labs or a similar tool cover nearly every Infrastructure topic.
- Break things on purpose. Change an MTU, remove preempt, or mismatch EtherChannel modes, then watch the show output. This is how you learn to recognize problems on the exam.
- Make a defaults sheet. List priorities, timers, administrative distances, and preemption behavior, and review it weekly.
- Practice by subject, then mix. In Pocket Prep, use Build Your Own Quiz to focus on Infrastructure until you can explain every answer. Review Missed Questions regularly, and check Weakest Subject to confirm this domain is improving.
- Finish with timed mixed sets. Infrastructure concepts show up in other domains, so mixed practice shows whether you can spot them without a label.
Start Preparing for the CCNP Enterprise Exam With Pocket Prep
Pocket Prep’s Cisco CCNP Enterprise practice questions include 850 questions aligned to ENCOR v1.2, with plenty of Infrastructure scenarios, and each one comes with a detailed explanation. Use Build Your Own Quiz to drill Layer 2, Layer 3, and IP services, then test yourself on the full-length mock exam. Keep at it, and the largest domain on ENCOR can become your strongest.