Exact 50-question practice allocation
Architecture and virtualization foundations
Weeks 1–2: build the diagrams and decision vocabulary that every later configuration depends on.
- Compare two-tier, three-tier, routed-access, on-premises and cloud-managed designs.
- Trace SD-Access management, LISP control, VXLAN data and TrustSec policy planes.
- Identify edge, control, border and intermediate roles and their failure effects.
- Compare SD-WAN centralized policy with distributed edge forwarding.
- Design QoS trust boundaries, classification, marking and bounded priority treatment.
- Use VRFs for routing separation and distinguish them from device virtualization.
- Trace GRE and VXLAN encapsulation over an IP underlay and account for MTU.
- Complete Architecture and Virtualization questions 1–7 and 26–31.
Infrastructure: forwarding, convergence and services
Weeks 3–5: operate enterprise Layer 2, dual-stack routing, multicast, QoS, and wireless as connected systems.
- Practice STP root design, PortFast, BPDU Guard, Root Guard and loop diagnosis.
- Build EtherChannels and identify member inconsistencies.
- Implement IPv4/IPv6 gateways, neighbor discovery and first-hop protections.
- Troubleshoot OSPF adjacency and path selection; explain EIGRP feasibility.
- Apply BGP Local Preference, AS_PATH and bounded route policy.
- Design redistribution with filters, tags, metrics, return paths and loop tests.
- Trace PIM sparse-mode joins, RP registration, RPF and multicast state.
- Correlate wireless RF, association, authentication, DHCP and roaming evidence.
Assurance and structured troubleshooting
Week 6: prove what the network is doing with sources chosen for the question.
- Use SPAN for targeted packets and Flexible NetFlow for conversation summaries.
- Use syslog, SNMP or modeled telemetry for state and event context.
- Build active IP SLA measurements for reachability, latency, jitter or loss.
- Synchronize time and retain source plus ingestion timestamps.
- Distinguish configuration intent, control-plane state, forwarding state and user experience.
- Show stale or missing telemetry as degraded coverage.
- Follow scope, evidence, hypothesis, test, narrow repair and regression steps.
- Complete assurance questions and preserve one failure timeline from Project 1.
Identity, segmentation and infrastructure security
Weeks 7–8: secure access and device operation without losing required control traffic.
- Master AAA authentication, authorization, accounting and ERROR-versus-FAIL fallback.
- Write ordered standard and extended ACLs with explicit dependency testing.
- Protect infrastructure addresses and control-plane capacity.
- Use SSH, trusted time, secured telemetry and restricted management sources.
- Design 802.1X/EAP with carefully bounded MAB exceptions.
- Use VRFs for macro-segmentation and SGTs for identity-oriented micro-segmentation.
- Differentiate MACsec link protection from IPsec routed-path protection.
- Assess rogue wireless evidence before taking disruptive containment action.
Automation, AI, projects and exam readiness
Weeks 9–10+: convert knowledge into repeatable, reviewable operation.
- Parse and validate JSON and XML without assuming keys or types.
- Understand YANG hierarchy, constraints, actions and notifications.
- Discover NETCONF/RESTCONF capabilities before changing state.
- Build deterministic, idempotent deltas with retries, timeouts and post-checks.
- Use AI for bounded explanation and recommendation, never as unrestricted authority.
- Complete all three projects with failure, rollback, security, cost and cleanup evidence.
- Answer all 50 original questions and review all 40 nonduplicate cards.
- Recheck official topics and schedule only when every domain can be explained from evidence.
Three deep projects
All learning surfaces
Exact domain allocation, detailed explanations and Cisco references.40 flashcards
Architecture through automation and AI.3 projects
Architecture, steps, validation, security, cost, cleanup and evidence.Substantial study guide
Domain reasoning, lab strategy and official sources.Roadmap catalog
Explore adjacent Cisco and cloud paths.Editorial policy
Originality, sourcing and exam integrity.
Official Cisco sources
Frequently asked questions
What is the current ENCOR exam version and duration?
Cisco lists 350-401 ENCOR v1.2 as a 120-minute exam. Always verify the official page before scheduling.
Which formats can appear?
Cisco says to expect performance-based, multiple-choice, and drag-and-drop formats. The practice bank uses scenario and ordering questions to prepare the underlying skills without reproducing live items.
How are the 50 questions allocated?
Architecture 8, Virtualization 5, Infrastructure 15, Network Assurance 5, Security 10, and Automation and Artificial Intelligence 7.
Does Cisco publish a fixed live question count or passing score?
This roadmap does not claim one. The number 50 applies only to PrepKloud's original practice bank. Consult Cisco and its testing provider for current published logistics.
Which certification paths use ENCOR?
Cisco states that passing earns Cisco Certified Specialist – Enterprise Core and can satisfy the core exam requirement for relevant CCNP Enterprise and CCIE Enterprise certifications. Verify the current certification pages for pathway rules.
Are these materials exam dumps?
No. They are independently written educational scenarios grounded in public objectives and official Cisco documentation, with no live, recalled, leaked or proprietary questions.
Build professional core skill
Study the blueprint, explain every distractor, and complete all three projects with evidence and cleanup.
Start questionsReview cardsOpen projectsRead guide