ITCertFoundryTechnical training system
16-WEEK CCNP ENCOR 350-401 PLAN

A structured route from CCNA-level fluency to ENCOR readiness.

Weighted toward the blueprint's own domain weights — Infrastructure (30%) and Security (20%) get proportionally more weeks than Virtualization or Network Assurance (10% each). Plan for 12–16 focused hours each week. Progress is based on demonstrated mastery, not simply reaching Sunday.

16 weeks 12–16 hours weekly 80%+ mastery gates 2 full exams
WEEKLY OPERATING RHYTHM

Use the same repeatable learning cycle every week.

Days 1–2: Learn

Read the assigned lessons, and explain each concept's enterprise use case aloud without copying the lesson's own wording.

Days 3–4: Build

Work the assigned lab(s) in Cisco Modeling Labs. Verify each layer with real show commands before adding the next feature.

Day 5: Break

Work each lab's break/fix step deliberately. Predict the symptom, gather evidence, diagnose the cause, then check your reasoning.

Day 6: Retrieve

Answer the week's check-on-learning and question-bank questions without notes. Review why every wrong option is wrong.

Day 7: Recover

Use light review or rest. If the mastery gate was missed, use this as a targeted catch-up day before the next week begins.

THE ROADMAP

Sixteen weeks, each ending with proof.

WEEK 1LEARN

Architecture I — Campus Design and High Availability

Objectives: 1.1–1.4

Know and explain

  • Two-tier, three-tier, fabric, and cloud design tradeoffs
  • Device/link redundancy, FHRP concepts, and SSO
  • SD-WAN control plane and data plane elements
  • SD-WAN's real benefits and real limitations, not just marketing claims

Hands-on proof

Work the encor-two-tier-fhrp-campus lab: build a collapsed-core campus with HSRP, then fail the active router and prove the standby takes over correctly.

Question target: 20 mixed Architecture questions

Advance when: Explain why a two-tier design was chosen over three-tier for a given scenario, and score 80% on Architecture 1.1–1.4 questions.
WEEK 2BUILD

Architecture II — SD-Access, Interoperability, and QoS

Objectives: 1.5–1.7 + domain review

Know and explain

  • SD-Access control plane and data plane elements
  • Traditional campus interoperability with SD-Access
  • Basic QoS concepts: classification, marking, queuing, policing vs. shaping

Hands-on proof

Work through the SD-WAN and SD-Access guided activities, then the QoS config-interpretation lab — read real policy-map output and predict its effect before checking.

Question target: Architecture domain review (all of 1.1–1.7)

Advance when: Score 80% across the full Architecture domain before moving on — this is 15% of the real exam.
WEEK 3LEARN

Virtualization — Hypervisors, VRF, Tunnels, and Overlays

Objectives: 2.1–2.8

Know and explain

  • Type 1 vs. Type 2 hypervisors, and vSwitch/vNIC concepts
  • VRF-Lite configuration and verification
  • GRE tunneling and IPsec site-to-site VPN concepts
  • LISP and VXLAN — what problem each one actually solves

Hands-on proof

Complete the VRF-Lite lab, the GRE tunnel lab, and the IPsec/VTI lab back to back — by the end you should be able to explain why GRE alone isn't secure and what IPsec adds.

Question target: 20 Virtualization questions

Advance when: Score 80% on Virtualization, and correctly explain the difference between VRF-Lite's routing isolation and a VLAN's Layer 2 isolation.
WEEK 4BUILD

Infrastructure I — Layer 2 Troubleshooting

Objectives: 3.1–3.4

Know and explain

  • 802.1Q trunking, native VLAN, and DTP troubleshooting
  • EtherChannel troubleshooting: LACP and PAgP
  • RSTP and Multiple Spanning Tree Protocol configuration
  • Root Guard and BPDU Guard — and the real difference between them

Hands-on proof

Work the Enterprise Campus capstone's break/fix step: diagnose a rogue-switch root-inconsistent event and correctly distinguish it from a BPDU Guard err-disable.

Question target: 20 Layer 2 questions

Advance when: Score 80%, and correctly diagnose a native VLAN mismatch from show-command evidence alone, not from re-reading the configuration.
WEEK 5LEARN

Infrastructure II — EIGRP, OSPF Fundamentals, and Multiarea

Objectives: 3.5–3.8

Know and explain

  • EIGRP vs. OSPF operation, metrics, and convergence behavior
  • OSPF path selection, load balancing, and area types
  • Multiarea OSPFv2/OSPFv3 configuration, including virtual links and route filtering
  • OSPF adjacencies, passive interfaces, network types, and summarization

Hands-on proof

Work the multiarea OSPF lab in full, including the virtual-link scenario — don't skip it, it's the single most commonly under-practiced Infrastructure skill.

Question target: 25 OSPF-focused questions

Advance when: Score 80%, and diagnose a stuck adjacency from 'show ip ospf neighbor' output without guessing.
WEEK 6BUILD

Infrastructure III — eBGP and Policy Routing

Objectives: 3.9–3.11

Know and explain

  • Directly connected eBGP peering configuration
  • BGP neighbor establishment, path attributes, and best-path selection
  • Policy-Based Routing configuration and use cases

Hands-on proof

Work the eBGP peering lab and the PBR lab. In the PBR lab specifically, predict which traffic takes the policy-routed path before you apply the policy-map.

Question target: 20 BGP/PBR questions

Advance when: Score 80%, and correctly walk through BGP's best-path selection order for a given set of candidate routes.
WEEK 7LEARN

Infrastructure IV — NTP/PTP, NAT/PAT, HSRP/VRRP

Objectives: 3.12–3.14 + domain review

Know and explain

  • NTP and PTP configuration in client and server mode
  • NAT and PAT configuration and verification
  • HSRP and VRRP — configuration, tracking, and failover behavior

Hands-on proof

Work the NTP/PTP lab, the NAT/PAT lab, and the HSRP/VRRP lab. Re-run the HSRP tracking scenario and verify your decrement math actually crosses the peer's priority.

Question target: Infrastructure Routing domain review (3.5–3.14)

Advance when: Score 80% across all of 3.5–3.14 before moving to multicast — this sub-domain alone is a large share of Infrastructure's 30% weight.
WEEK 8BUILD

Infrastructure V — Multicast

Objectives: 3.15–3.20 + full Infrastructure review

Know and explain

  • Reverse Path Forwarding checks
  • PIM Sparse Mode operation and configuration
  • IGMPv2 vs. IGMPv3, and Source-Specific Multicast
  • Bidirectional PIM and MSDP between PIM domains

Hands-on proof

Work every multicast lab in the domain, then review 3.1–3.20 together — Infrastructure is 30% of the real exam, so this domain review matters more than any single week before it.

Question target: Full Infrastructure domain review (3.1–3.20)

Advance when: Score 80% across the ENTIRE Infrastructure domain. Do not proceed with a shaky Infrastructure score — it's too large a share of the exam to carry forward.
WEEK 9LEARN

Network Assurance — Monitoring, Telemetry, and API Basics

Objectives: 4.1–4.8

Know and explain

  • Ping, traceroute, and conditional vs. unconditional debugs
  • SNMP, syslog severity levels, and common config issues
  • Flexible NetFlow, SPAN/RSPAN/ERSPAN, and IP SLA
  • Cisco Catalyst Center workflows, and NETCONF/RESTCONF at the Describe level

Hands-on proof

Work the NetFlow lab, the SPAN/RSPAN/ERSPAN lab, and the IP SLA lab. Use the NETCONF/RESTCONF lab to get comfortable reading a GET response before Automation week goes further.

Question target: 20 Network Assurance questions

Advance when: Score 80%, and correctly choose SPAN vs. RSPAN vs. ERSPAN for three different topology scenarios.
WEEK 10BUILD

Security I — Device Access, AAA, and ACLs

Objectives: 5.1–5.4

Know and explain

  • Device access control: console, VTY, local-user authentication
  • AAA for device and network access, method lists and fallback
  • Local vs. TACACS+ vs. RADIUS — when each one fits
  • Standard and extended ACLs for management and data-plane traffic

Hands-on proof

Work the device-access/AAA lab in full, including the break/fix step where the local fallback is removed — feel what a real lockout looks like before it happens on a real device.

Question target: 20 Security questions

Advance when: Score 80%, and correctly explain why a method list needs a local fallback even when TACACS+ is normally reliable.
WEEK 11LEARN

Security II — CoPP through MACsec

Objectives: 5.5–5.11 + domain review

Know and explain

  • Control Plane Policing to protect the route processor
  • REST API authentication and authorization security
  • Threat-defense architecture, endpoint security, and NGFW deployment modes
  • TrustSec/SGT and MACsec — hop-by-hop vs. end-to-end encryption scope

Hands-on proof

Work the ACL/CoPP lab and the Secure Enterprise Core capstone's break/fix step — practice telling an ACL-layer failure apart from an AAA-layer failure using connection behavior alone, not guesswork.

Question target: Full Security domain review (5.1–5.11)

Advance when: Score 80% across the entire Security domain — 20% of the real exam, the second-largest domain after Infrastructure.
WEEK 12BUILD

Automation & AI I — Python, JSON, YANG, and REST Codes

Objectives: 6.1–6.6

Know and explain

  • Reading and troubleshooting basic Python scripts
  • Constructing valid JSON, and the exact syntax mistakes that break it
  • YANG data modeling principles and why they matter for automation
  • Catalyst Center and SD-WAN Manager API structure
  • Interpreting HTTP/REST response codes and JSON payloads

Hands-on proof

Work the Python/JSON lab and the HTTP/REST codes lab. Deliberately break your own JSON with a trailing comma and a single-quoted key, and watch exactly how the parser reacts to each.

Question target: 20 Automation questions

Advance when: Score 80%, and correctly distinguish a 401 from a 403 from a 500 for three different scenarios without hesitating.
WEEK 13LEARN

Automation & AI II — RESTCONF/NETCONF, EEM, and AI in Operations

Objectives: 6.7–6.12 + domain review

Know and explain

  • Constructing a RESTCONF request to configure a device — PATCH vs. PUT
  • Constructing a NETCONF edit-config operation and the candidate/commit model
  • EEM applets for event-driven remediation
  • Agent-based vs. agentless orchestration
  • AI-assisted operations use cases, and the real risks of AI-driven changes

Hands-on proof

Work the RESTCONF/NETCONF configuration lab and the EEM applet lab. In the RESTCONF lab, deliberately use PUT where PATCH was correct and watch what it wipes out.

Question target: Full Automation & AI domain review (6.1–6.12)

Advance when: Score 80% across the entire Automation & AI domain, and explain why PUT and PATCH are not interchangeable even though both can technically update a resource.
WEEK 14CAPSTONE

Capstones — Everything Together

Objectives: All six domains, cumulative

Know and explain

  • There's no new content this week — this is where isolated skills either connect into real judgment or don't
  • Review any objective a capstone exposes as shaky before moving on

Hands-on proof

Complete all four capstones: Enterprise Campus, Enterprise WAN, Secure Enterprise Core, and Automated Network Operations. Do not read ahead in a capstone's walkthrough before attempting the step yourself.

Question target: None assigned — the capstones themselves are this week's assessment

Advance when: All four capstones completed, with every break/fix step correctly diagnosed before checking the lesson's answer.
WEEK 15EXAM

Simulation Exam A + Remediation

Objectives: All domains

Know and explain

  • Targeted review driven entirely by your Exam A domain breakdown, not by what feels unfinished

Hands-on proof

Take ENCOR Simulation Exam A under real, timed, forward-only conditions. Then spend the rest of the week remediating specifically the domains where you scored weakest.

Question target: ENCOR Simulation Exam A (67–68 questions, 120 minutes)

Advance when: Review every missed question's explanation. Do not move to Exam B until you understand why each correct answer was correct, not just that it was.
WEEK 16EXAM

Simulation Exam B + Final Readiness Check

Objectives: All domains

Know and explain

  • Final pass over anything still below your target score after Exam A's remediation

Hands-on proof

Take ENCOR Simulation Exam B under real, timed, forward-only conditions.

Question target: ENCOR Simulation Exam B (67–68 questions, 120 minutes)

Advance when: Do not schedule the real 350-401 exam until both simulation forms are consistently at or above your target score, with no single domain badly lagging the rest.
READINESS RULES

Protect the plan from false confidence.

Use closed-note checks

Recognition is easier than recall. If you need the lesson open, the skill is not exam-ready yet.

Track weaknesses by objective

“Routing” is too broad. Record the exact failure: BGP best-path, OSPF virtual link, PBR ordering, or something else specific.

Remediate before retesting

Explain the rule, rebuild the scenario, and answer new questions. Repeating the same question can measure memory instead of mastery.

Simulate honestly

Use one question at a time, no backtracking, no notes, and the full 120-minute timer for each timed simulation exam.

IF YOU FALL BEHIND

Adjust scope, not the mastery standard.

Use the next Day 7 and the first half of Week 16 as recovery space. Move your exam date if necessary. Do not compress labs, capstones, or remediation simply to preserve the calendar — Infrastructure and Security alone are half the real exam.

Start the CCNP ENCOR course →