CloudNetX CNX-001 Exam Objectives: All Four Domains Broken Down
The efficient way to prepare is to follow the weighting rather than your comfort zone. CompTIA CloudNetX (CNX-001) tells you exactly where the points are, and this article walks through all four domains, what each covers in practice, and how to prioritize your time.
For exam mechanics, see the format guide. For the whole path, the complete CloudNetX guide ties it together.
The weighting at a glance
| Domain | Weight |
|---|---|
| 1.0 Network Architecture Design | 31% |
| 2.0 Network Security | 28% |
| 3.0 Network Operations, Monitoring, and Performance | 16% |
| 4.0 Network Troubleshooting | 25% |
Design and Security are 59% together — that's the identity of this credential. Operations is the smallest at 16%, which surprises people until you remember CloudNetX is for the people who design networks, not the ones who run them day to day. Troubleshooting at 25% is architect-level: diagnosing across hybrid boundaries.
Because the exam is pass/fail with no scaled score, you can't bank on a strong domain covering a weak one. Aim for real competence across all four.
Domain 1: Network Architecture Design (31%)
The largest domain, and the heart of the credential: translating business, technical, and regulatory requirements into resilient hybrid designs.
Core concepts you're expected to have cold, not relearn: the OSI model, IPv4/IPv6, subnetting, CIDR and VLSM, NAT/PAT and port forwarding, DHCP, NTP, DNS (including DNSSEC, DoT, DoH), TCP/UDP, and authentication protocols (802.1X, RADIUS, TACACS+, LDAP).
Architectures and topologies: mesh, star, hub-and-spoke, spine-and-leaf, and point-to-point; trusted, untrusted, and screened subnets; north-south versus east-west traffic flows; segmentation with VLAN, VXLAN, and GENEVE; and production versus non-production separation.
Hybrid connectivity — the modern core: MPLS, SD-WAN, cellular, satellite, dark fibre, DIA, and metro links; public cloud connections (Direct Connect, ExpressRoute, SDCI); VPNs (site-to-site, point-to-site, split tunnelling, WireGuard); bastion hosts with SSH/RDP; and cloud-native constructs — PaaS private endpoints, transit gateways, VPC peering, and private link.
Availability solutions: global and local load balancing (round-robin, least-connection, weighted), VIPs, active-active versus active-passive HA, link aggregation, autoscaling, regions and availability zones, CDNs, fault and update domains, and device/path redundancy.
Campus and physical: evaluating power, environmental factors, and physical access controls. Wireless technologies including the capabilities of BLE, NFC, RFID, and IoT devices in a network environment.
The framing throughout is given these requirements, select the appropriate design — not configure this device.
Domain 2: Network Security (28%)
Close behind Design, and inseparable from it at architect level.
Threats and mitigations: identifying threats, addressing vulnerabilities, applying mitigations. Security technologies: firewalls, encryption protocols, and network access control (NAC). Access controls: firewall rules, security groups, and URL filtering.
Zero Trust is a first-class topic, not a bullet point: implementing zero trust network access (ZTNA), secure access service edge (SASE), microsegmentation, and cloud access security brokers (CASB). CompTIA's objective wording is explicit — analyze requirements to apply the appropriate Zero Trust architecture principles to secure a network.
IAM solutions: single sign-on (SSO), multifactor authentication (MFA), public key infrastructure (PKI), and privileged access management. Wireless security: encryption, authentication, and wireless isolation.
If you're also pursuing SecurityX, you'll find real overlap here — the two Xpert credentials reinforce each other.
Domain 3: Network Operations, Monitoring, and Performance (16%)
The smallest domain, but don't dismiss it — it's where architect designs meet operational reality.
Operations management: managing risk, ensuring continuity, and optimizing service delivery. Monitoring tools: metrics, dashboards, logging, and alerting for performance. Automation of routine tasks and maintaining reliable network environments across on-prem and cloud sits here too — including capturing infrastructure as code and proving idempotence.
At 16%, this is efficient to study relative to its weight, and it connects directly to the troubleshooting domain: you can't diagnose what you don't observe.
Domain 4: Network Troubleshooting (25%)
Bigger than most people expect, and genuinely hard — because it's hybrid troubleshooting.
It covers diagnosing and resolving connectivity, performance, access, and security issues across on-premises and cloud. The difficulty isn't any single tool; it's that the fault could be anywhere: a local firewall, a cloud network security group, a route table, a peering connection, a DNS record, or the link between environments.
This is exactly what the PBQs test — the format guide describes a representative one. The skill is narrowing the fault domain methodically rather than guessing. It draws on all three other domains, so study it throughout rather than saving it for last.
How to sequence your study
Study time should follow weight, and your background should shape the order:
- Design (31%) and Security (28%) get the majority of your hours — that's 59% of the exam.
- Troubleshooting (25%) should be woven throughout, since it builds on everything else.
- Operations (16%) is efficient to cover and reinforces troubleshooting.
If you come from a traditional enterprise networking background, front-load cloud connectivity (Direct Connect/ExpressRoute, transit gateways, private endpoints, VPC peering) and Zero Trust/SASE — that's where experienced engineers most often have gaps. If you come from cloud, shore up the classic campus, wireless, and routing fundamentals. The study plan lays out a schedule.
Because CNX-001 is design-and-diagnosis oriented with demanding PBQs, applied practice mapped to the objectives is the efficient path.
Practice against the objectives: CompTIA CloudNetX CertMaster Labs (CNX-001) give applied, objective-aligned exercises. For learning content and hands-on practice integrated in one environment, CertMaster Perform (CNX-001) combines them. As an Authorized CompTIA Partner, these are the official versions.
FAQ
Which domain is most important? Network Architecture Design at 31%, with Network Security at 28% close behind. Together they're 59% of the exam.
Why is Operations only 16%? Because CloudNetX is for people who design networks rather than operate them. Operations matters, but design and security judgment is what's being validated.
How hard is the Troubleshooting domain? Harder than it looks at 25%. It's hybrid troubleshooting — the fault could be on-prem, in a cloud security group, in a route table, or in the connectivity between them.
How much Zero Trust do I need? A lot. ZTNA, SASE, microsegmentation, and CASB are implementation-level topics in the Security domain, not definitions.
Do I need to know subnetting and the OSI model at this level? Yes — they're assumed foundations in Domain 1. The exam builds design questions on top of them rather than testing them directly.
Does CloudNetX overlap with SecurityX? Meaningfully, in Zero Trust and security architecture. Many architects find one makes the other easier.
0 comments