CCNP Cisco IP Switched Networks (SWITCH v2.0): Exam Guide and Study Roadmap
Implementing Cisco IP Switched Networks (SWITCH 300-115J) validated switching knowledge and skills for designing, configuring, and verifying complex enterprise switching solutions in an enterprise campus architecture. Its blueprint emphasized Layer 2 technologies, infrastructure security, and infrastructure services, so preparation should prioritize configuration reasoning rather than isolated command memorization. This guide helps candidates decide whether they need a structured lab cycle, a blueprint-led review, or a historical certification reference—and how to turn the available Cisco learning content into a practical study plan.
What the SWITCH exam was designed to validate
The exam focused on the operational decisions behind enterprise switching: how traffic is segmented, carried, protected, monitored, and supported by resilient gateway services. Cisco described successful candidates as able to plan, configure, and verify complex enterprise switching solutions using an enterprise campus architecture.
That objective is broader than recalling the syntax for a VLAN or a spanning-tree command. A candidate needs to recognize the intended campus design, select an appropriate feature, apply it without undermining another control, and verify the resulting behavior. For example, a secure access-layer design may require VLAN and trunk decisions alongside DHCP snooping, IP Source Guard, Dynamic ARP Inspection, and port-security considerations.
Cisco also included secure integration of VLAN and WLAN technologies within the exam content. This makes the subject relevant to engineers who must connect wired switching decisions with wireless access and security requirements rather than treat the switch as an isolated device.
The Cisco exam document identifies the exam as “Implementing Cisco IP Switched Networks (SWITCH 300-115J).” It also states that passing SWITCH 300-115J was required for the historical CCNP Routing and Switching and CCDP certifications. Those historical certification relationships should not be interpreted as current certification-status guidance; candidates making a present-day scheduling decision should consult Cisco’s current certification information separately.
Who should use this guide
This guide suits a candidate who already understands basic IP networking and wants to organize switching study around the official blueprint. It is especially useful for network engineers, administrators, and infrastructure learners who need to connect Layer 2 design, access-layer security, and first-hop redundancy in one troubleshooting model.
It is not a substitute for Cisco’s current exam catalogue or registration information. The supplied official material documents the historical SWITCH 300-115J exam and its v2.0 learning resources, but it does not establish current availability, retirement status, pricing, delivery method, testing language, prerequisites, or a present-day score requirement.
Use the guide in one of two ways. If you are studying the historical exam content, use the blueprint and lab sequence as the core of your plan. If you are considering a current Cisco certification, use the technical themes as background and verify the target exam, path, and scheduling rules through Cisco before committing study time or purchasing resources.
How the blueprint should control your study time
Start with the official domain labels, not with a long list of commands. The blueprint allocated 65% of the exam to Layer 2 technologies, 20% to infrastructure security, and 15% to infrastructure services. Those percentages should guide the order and depth of preparation, while the named topics determine what you actually build and verify in a lab.
Layer 2 technologies represented 65% of the exam and included switch management, Layer 2 protocols, VLANs, trunking, EtherChannel, spanning tree, SPAN/RSPAN, and StackWise. This is the main study block, but it is not eight unrelated chapters: VLAN and trunk design affects spanning tree; EtherChannel affects both physical redundancy and logical topology; management and monitoring determine how you verify the design.
Infrastructure security represented 20% of the exam and included DHCP snooping, IP Source Guard, Dynamic ARP Inspection, port security, private VLANs, storm control, TACACS+, RADIUS, and Cisco IOS AAA. Treat these as a connected control set. A secure configuration is useful only when you understand the traffic assumptions, trusted interfaces, bindings, authentication flow, and failure behavior behind it.
Infrastructure services represented 15% of the exam and covered HSRP, VRRP, and GLBP first-hop redundancy protocols. Study these after the Layer 2 foundation, because gateway redundancy depends on the VLAN path, access design, and forwarding behavior beneath it.
Do not use the percentages as a reason to ignore the smaller domains. A candidate can lose time or miss a design dependency by treating infrastructure security or services as optional. Instead, use the weighting to allocate revision effort: build a strong Layer 2 base, then deliberately reserve focused lab and review sessions for the two remaining domains.
What to learn in the Layer 2 block
Build the Layer 2 block around cause and effect. You should be able to move from a topology requirement to VLAN and trunk configuration, select an EtherChannel and spanning-tree approach, inspect the resulting control-plane state, and explain why the forwarding path is safe and available.
Begin with switch management and Layer 2 protocols. Review the information a switch uses to form relationships, learn paths, and expose operational state. Your notes should pair each feature with its verification evidence: the configuration you intended, the operational state you received, and the symptom that would indicate a mismatch.
Next, combine VLANs and trunking in a small topology. Create multiple broadcast domains, carry them across a trunk, and test both permitted and intentionally excluded VLANs. Then introduce native-VLAN or encapsulation inconsistencies only as troubleshooting exercises. The purpose is not to collect error messages; it is to learn how a mismatch appears in configuration, interface state, and end-to-end reachability.
Study EtherChannel as a design and consistency problem. Practice identifying which member-link properties must agree, how a logical port-channel changes the topology, and how to verify both the bundle and the individual interfaces. A useful exercise is to start with a working bundle, alter one member’s relevant setting, and record the difference between the logical and physical evidence.
Spanning tree deserves a dedicated sequence. Draw the expected root and forwarding paths before configuring them. Then inspect root selection, port roles, states, and blocked links. Test a link or priority change and explain whether the resulting behavior is intentional. Review how redundancy, convergence, and edge-port decisions interact rather than memorizing isolated feature names.
Finally, cover SPAN/RSPAN and StackWise as operational capabilities. For SPAN or RSPAN, identify the source, destination, direction, and transport implications of a monitoring design. For StackWise, focus on the architecture and operational verification relevant to a stacked switching environment. Keep a separate page for commands or outputs that confirm the intended topology.
How to study infrastructure security without memorizing traps
Infrastructure-security preparation is strongest when every control is tied to a threat, a trusted boundary, and a verification step. Make a table with four columns—attack or failure, feature, interface or device assumptions, and evidence of correct operation—and fill it while labbing.
DHCP snooping establishes a foundation for related protections, so study it before IP Source Guard and Dynamic ARP Inspection. Identify which ports should be trusted, what information is learned, and what happens to a legitimate client when the trust model is wrong. Then examine how the resulting binding information supports later controls.
Use IP Source Guard and Dynamic ARP Inspection as separate reasoning exercises. Ask what each feature validates, where its information comes from, and which configuration mistake would block legitimate traffic. A good lab includes both a compliant path and a deliberately inconsistent path, followed by verification and recovery.
Port security, private VLANs, and storm control address different problems. Port security limits or controls endpoint attachment behavior; private VLANs shape communication relationships within a broadcast domain; storm control limits the impact of excessive traffic conditions. Write a one-sentence design objective for each before touching the configuration. This prevents selecting a familiar feature for the wrong requirement.
Authentication and authorization need a similarly explicit model. Compare TACACS+, RADIUS, and Cisco IOS AAA by the role each plays in an administrative access design, then practice the sequence from local device request to remote service and fallback behavior. Do not reduce the topic to protocol acronyms; be able to explain what the device is trying to authenticate, authorize, and account for.
After each security lab, remove one prerequisite and observe the result. For example, test what changes when a trusted interface is not trusted or when an expected binding is absent. Record the symptom, the likely cause, and the least disruptive corrective action. This builds troubleshooting judgment without relying on unauthorized or live exam material.
How to approach HSRP, VRRP, and GLBP
Study first-hop redundancy as a gateway-selection problem. The key question is not merely which protocol is configured, but which device should serve clients, how the standby decision is made, and what evidence proves that failover or load sharing is working as designed.
Build one VLAN with redundant Layer 3 gateways and establish a baseline before introducing failure. Identify the active, standby, or equivalent roles shown by the protocol; verify the virtual gateway behavior from the client perspective; and document the control that influences device preference.
Then compare HSRP, VRRP, and GLBP using the same topology and a consistent set of questions. How is the virtual gateway represented? How are roles selected? What happens when the preferred device or link fails? Does the design provide standby behavior, or does it distribute gateway forwarding? The official blueprint names all three, so your comparison should cover their operational purpose rather than only one preferred implementation.
Include a Layer 2 failure in your exercise, not just a device shutdown. A gateway may remain powered while its path to the switching domain is impaired. This exposes whether tracking, priorities, and topology assumptions have been designed coherently. Verify the result from both the gateway and host viewpoints.
The Cisco lab resource and how to use it
Cisco stated that the CCNP SWITCH v2.0 Learning Labs were developed to prepare learners for the SWITCH exam and used Cisco IOS software labs from Cisco e-learning and authorized training. Cisco described the product as a 50-hour, 180-day product and stated that its curriculum contained 33 exercises aligned with the SWITCH exam learning content.
Those details make the lab resource useful as a possible structured practice path, but they do not by themselves establish that it is currently sold, accessible, or appropriate for a present-day certification target. Confirm current availability and applicability through Cisco before purchasing or scheduling around it.
If you have access to the labs, do not rush through all exercises once. Use a three-pass method. On the first pass, complete the task while identifying the design requirement. On the second, rebuild the topology from a blank starting point and explain each configuration choice. On the third, introduce a controlled fault and verify that you can isolate it without relying on the lab’s expected answer.
If you do not have access, recreate the learning objectives in an authorized IOS lab or simulator where the required features are supported. The aim is repeatable configuration and verification practice, not possession of a particular interface or worksheet.
A practical study roadmap
A useful roadmap moves from topology fundamentals to protective controls, then to gateway resilience, with verification and troubleshooting repeated throughout. Adjust the calendar to your starting knowledge and lab access; the sequence matters more than an arbitrary number of study days.
Phase one: establish the switching baseline. Review switch management, VLANs, trunking, and Layer 2 protocols. Build a small topology with several VLANs and at least one inter-switch connection. For every change, save the intended design, the relevant configuration, the operational verification, and a short explanation of the result.
Phase two: make redundancy visible. Add EtherChannel and spanning tree. Draw the expected forwarding graph before and after each change. Practice root selection, path changes, member consistency, and failure recovery. Include SPAN/RSPAN and StackWise in the review by writing design notes and performing the supported verification tasks, rather than leaving them as reading-only topics.
Phase three: secure the access layer. Work through DHCP snooping first, then IP Source Guard and Dynamic ARP Inspection. Add port security, private VLANs, storm control, and administrative AAA as separate exercises. For each feature, test a valid case, an invalid case, and a recovery case. This is where a feature matrix becomes more useful than a command list.
Phase four: add first-hop services. Configure and compare HSRP, VRRP, and GLBP in a redundant gateway topology. Verify role selection, client gateway behavior, and the effect of a path or device failure. Revisit VLAN and spanning-tree assumptions if the redundancy result is not what the design predicted.
Phase five: integrate the domains. Build a campus-style scenario that includes access VLANs, trunks, an EtherChannel, a spanning-tree root, access security, administrative authentication, and a redundant gateway. Require yourself to produce a short implementation plan, configure it, verify it, and troubleshoot one planted fault. Integration reveals gaps that topic-by-topic drills can hide.
Phase six: conduct readiness review. Use the blueprint headings as a checklist, not as a score prediction. Mark each topic as explain, configure, verify, or troubleshoot. Any item marked only “recognize” needs more lab work. Rebuild the weakest topology from a blank configuration, then perform a timed review using your own notes and authorized practice material.
How to make lab practice produce exam-ready reasoning
Every lab should end with evidence, not just a successful configuration. Write the requirement, the assumptions, the commands or settings applied, the verification output you would expect, and the symptom produced by one controlled fault. This turns practice into a reusable troubleshooting record.
Use topology sketches before command entry. Label VLAN boundaries, trunk links, port-channel members, spanning-tree root placement, trusted security interfaces, and first-hop gateway roles. If you cannot draw the intended forwarding or trust path, configuration is likely to become trial and error.
Separate observation from interpretation. An interface state is an observation; “the trunk is misconfigured” is an interpretation. Record both. Then identify the next check that would distinguish between plausible causes. This habit is valuable for questions that present partial output and ask for the most appropriate action.
Repeat selected labs from a blank state. Copying a working configuration can create the illusion of understanding, especially for AAA dependencies, security bindings, EtherChannel consistency, and spanning-tree behavior. Rebuilding forces you to remember prerequisites and exposes steps you have been performing mechanically.
Keep a compact command-reference sheet, but organize it by question: What is configured? What is operational? What path is selected? What is blocked? What is trusted? What failed over? This is more useful than grouping commands alphabetically because it mirrors the decisions a troubleshooting task requires.
Understanding the documented timing and question range
Cisco specified 30–40 questions for the SWITCH 300-115J exam and a 120-minute time limit. That information supports pacing practice, but it does not tell you how many questions will appear in an individual sitting or how much time any particular item will require.
Use the official range as a planning boundary, not as a promise about current delivery. In a practice session, allocate time for reading topology conditions, checking every option, and flagging questions that depend on a missing assumption. Avoid spending an excessive portion of the session trying to prove one uncertain interpretation.
A practical pacing method is to make an initial decision, mark genuinely uncertain items, and return after completing the rest. Read qualifiers carefully: trusted versus untrusted, local versus remote, active versus standby, intended versus observed, and configuration versus operational state. These distinctions often matter more than a memorized command.
Do not infer a passing score, item format, language, delivery method, or current exam availability from the supplied facts. Confirm those details in the current official Cisco exam information before scheduling.
Common preparation mistakes
The most damaging mistake is studying commands without a design model. A candidate may recognize syntax yet fail to predict the forwarding path, trust relationship, or failover result. Correct this by requiring a topology sketch and verification plan before every substantial lab.
Another mistake is giving Layer 2 all of the attention because it is the largest blueprint domain. Layer 2 technologies represented 65% of the exam, but infrastructure security represented 20% and infrastructure services represented 15%. Study those official domains by name and reserve deliberate practice for each; do not treat the smaller percentages as permission to skip them.
Treating security features as interchangeable also creates avoidable gaps. DHCP snooping, IP Source Guard, Dynamic ARP Inspection, port security, private VLANs, storm control, and AAA solve different problems and rely on different assumptions. Build a comparison table and test what happens when each prerequisite is absent.
A fourth mistake is labbing only the happy path. A working HSRP or EtherChannel configuration proves little if you have not checked role selection, member consistency, path failure, and recovery. Add one controlled fault to every major exercise.
Finally, avoid unauthorized dumps, leaked questions, or memorization claims. They do not replace understanding, may be inaccurate, and do not provide a reliable basis for ethical preparation. Use the official blueprint, authorized training, documented lab work, and your own verification notes instead.
A final readiness check before you schedule
Schedule only after you can explain, configure, verify, and troubleshoot the main blueprint topics without leaning entirely on a step-by-step guide. You should also confirm that the exam you intend to take is the correct current Cisco offering, because the supplied material identifies a historical SWITCH 300-115J exam and does not establish current scheduling status.
Use this checklist as a decision tool: Can you design VLAN and trunk boundaries? Can you diagnose an EtherChannel or spanning-tree inconsistency? Can you explain the trust and binding dependencies of the access-layer security controls? Can you distinguish the roles and behavior of HSRP, VRRP, and GLBP? Can you verify a design from operational evidence rather than configuration alone? Can you integrate these features into an enterprise campus scenario?
If the answer is no for several items, return to targeted labs instead of restarting the entire syllabus. If the answer is yes but performance is inconsistent, focus on fault isolation and timed reading. If the answer is yes across all domains, verify current Cisco requirements and delivery information, then choose a date only when your preparation plan and the official exam information agree.
Conclusion
The strongest preparation path for the SWITCH v2.0 content is blueprint-led and lab-centered: establish Layer 2 behavior, secure the access layer, add first-hop redundancy, and finish with integrated campus scenarios. Use Cisco’s documented topics and learning resources as the evidence base, but verify current certification and scheduling information before making a present-day exam decision. The goal is not to memorize isolated configurations; it is to make defensible switching decisions and prove their operational result.