CCDE Core - Map of Content
Success: Core blueprint complete
All eight Core technology areas (1.0-8.0) are written. Notes are numbered
area.NNin recommended study order (built up the stack). The CCDE Practical's first three scenarios draw from these; the fourth is your AI Infrastructure elective (AI Infrastructure - MOC).
The Core blueprint has eight technology areas. Work through them roughly in number order - each builds on the last.
1.0 Transport technologies
- Physical mediums - fiber and copper
- Ethernet as transport
- Optical transport - CWDM vs DWDM
- WAN and last-mile transport selection
- Transport resiliency, diversity, and migration
2.0 Layer 2 Control Plane
- Layer 2 design fundamentals
- Physical media and Layer 2 convergence
- Spanning Tree - types, tuning, and loop mitigation
- Layer 2 multipath and switch clustering
- Layer 2 multicast - IGMP and MLD snooping
- Layer 2 fault isolation and resiliency
3.0 Layer 3 Control Plane
- Network hierarchy and topologies
- Generic routing and addressing - PBR, NAT, RIB-FIB
- IGP selection - OSPF vs IS-IS vs EIGRP
- BGP in enterprise design
- Route aggregation and summarization
- Redistribution and route manipulation
- Securing routing protocols
- Fast convergence techniques
- Factors affecting convergence
- Metric-based traffic engineering
- Multicast routing design - PIM, RP, MSDP
- IPv6 design and migration
4.0 Data Plane Transport
- Transport protocols overview - TCP, UDP, QUIC
- TCP behavior and the network
- MTU, fragmentation, and PMTUD
- Buffering, microbursts, and congestion signaling
- Load balancing and hashing - ECMP and entropy
- Transport security and encrypted-traffic implications
5.0 Network Virtualization
- MPLS fundamentals
- Segment Routing
- MPLS L3VPN and L2VPN
- Overlays and BGP EVPN
- Tunneling technology selection
- Infrastructure segmentation
- SD-WAN design
- WAN transport architecture selection
- QoS design - models and strategy
- Network management - traditional vs model-driven
- Reference models and migration considerations
6.0 Security
- Security design fundamentals - CIA and defense in depth
- Infrastructure hardening - control, management, and data plane
- AAA and identity - RADIUS, TACACS+, 802.1X
- Network access control and segmentation - NAC, TrustSec, guest and BYOD
- Layer 2 security
- MACsec and secure transport
- Perimeter security - firewalls and IPS-IDS
- Threat detection and mitigation - DDoS, spoofing, MITM
- Zero Trust and ZTNA
7.0 Wireless
- Wireless fundamentals and 802.11 standards
- WLAN architectures
- Controller placement, HA, and tunnel optimization
- Roaming - L2 vs L3 mobility
- RF design - coverage, capacity, high density, voice, location
- Wireless security
8.0 Automation
- Network automation fundamentals - why and the operating model
- Zero-touch provisioning
- Infrastructure as Code - declarative, idempotent, source of truth
- Automation tooling - Ansible vs Terraform and orchestration
- CI-CD pipelines for networks (NetDevOps)
- Telemetry-driven and closed-loop automation
How to read this MOC
Every design note follows one shape: requirement -> constraints -> options -> tradeoffs -> recommendation -> justification -> what-would-change -> validation, with an IPv6 note and spaced-repetition cards. Flagship comparison matrices and decision trees live in _attachments.
See also: AI Infrastructure - MOC (the elective) and Scenario intake checklist.