Quick reference

Free cheat sheets

Printable quick references, no account and no email required. Every sheet lists what is inside it before you open it, so you know whether it is worth printing.

AZ-104220-1202SC-300

PowerShell for Administrators

PowerShell is regular in a way that makes it guessable: every cmdlet is a verb and a noun. Learning the verbs and the discovery cmdlets is worth more than memorising any particular command.

What is in it

  • Discovery, which replaces memorising5
  • Windows administration11
  • Azure and Entra ID9
  • Pipeline and structure7
32entriesOpen cheat sheet →

AZ-900CLF-C02SY0-701

Cloud Service and Deployment Models

The service model decides where the line falls between what the provider manages and what you do. Exam questions almost always test that line rather than the definitions.

What is in it

  • Who manages what8
  • Examples5
  • Deployment models5
  • Cloud economics7
25entriesOpen cheat sheet →

AZ-104AZ-700AZ-500

Azure Networking

Most Azure networking questions are one of two shapes: why is this traffic blocked, or which connectivity option fits these requirements. The NSG rule table answers the first and the connectivity table answers the second.

What is in it

  • Core objects9
  • NSG rule evaluation8
  • Connectivity options6
  • Load balancing4
27entriesOpen cheat sheet →

AZ-104AZ-500SC-300

Azure Governance and RBAC

Two systems are easy to confuse and both appear in the same questions. RBAC controls who may do something. Policy controls what may exist. A question that says a compliant user cannot create a resource is usually a policy question.

What is in it

  • Built-in roles8
  • Scope and inheritance7
  • RBAC against Policy4
  • Locks and cost controls7
26entriesOpen cheat sheet →

AZ-900AZ-104

AZ-900 Azure Services Map

Azure Fundamentals rewards recognizing which service solves which problem. This maps the AZ-900 core services to their categories.

What is in it

  • Compute & containers6
  • Storage & networking6
  • Management & governance7
19entriesOpen cheat sheet →

AZ-104AZ-900

AZ-104 Azure CLI and PowerShell Reference

The Azure CLI and Azure PowerShell commands AZ-104 asks you to read and pick between, plus the resource types those commands create. Written for the Azure Administrator exam and useful revision after AZ-900.

What is in it

  • Azure CLI essentials15
  • Azure PowerShell equivalents14
  • Core resource types15
  • Storage services, tiers and redundancy13
  • Built-in RBAC roles9
  • Governance: policy, locks and tags10
76entriesOpen cheat sheet →

SC-300SC-900

Microsoft Entra ID Concepts

The Entra ID vocabulary SC-300 and SC-900 test, from tenant objects to Conditional Access controls and governance features. SC-900 candidates need the first three tables; SC-300 needs all seven.

What is in it

  • Identity fundamentals11
  • Users, groups and devices14
  • Authentication methods12
  • Conditional Access building blocks13
  • Application access and SSO11
  • Identity governance9
  • Entra ID admin roles12
82entriesOpen cheat sheet →

SAA-C03ANS-C01SOA-C03

AWS VPC and Networking

The security group against network ACL table is the single most tested comparison in AWS networking, because the stateful and stateless difference explains most blocked-traffic scenarios.

What is in it

  • Security groups against network ACLs6
  • VPC components10
  • Connecting outside the VPC6
  • Route 53 routing policies7
29entriesOpen cheat sheet →

CLF-C02SAA-C03SCS-C03

AWS IAM and Security

Two things carry most AWS security questions: what the shared responsibility model puts on your side of the line, and how IAM resolves a request when several policies apply. The evaluation table is the one that decides exam answers.

What is in it

  • Policy evaluation, in order6
  • IAM building blocks9
  • Shared responsibility6
  • Security services12
33entriesOpen cheat sheet →

CLF-C02SAA-C03SOA-C03

AWS Storage and Compute

Storage questions give you an access pattern and ask for the cheapest class that meets it. Compute questions give you a workload shape and ask for the cheapest purchasing model. Both are lookup problems once the tables are memorised.

What is in it

  • S3 storage classes7
  • EBS volume types5
  • EC2 purchasing options6
  • Storage service selection7
25entriesOpen cheat sheet →

CLF-C02SAA-C03

AWS Cloud Practitioner Service Comparison

CLF-C02 lives on 'which service would you use for X?' questions. This is the core service vocabulary, grouped by category.

What is in it

  • Compute & storage7
  • Database & networking7
  • Security, identity & management8
22entriesOpen cheat sheet →

220-1201220-1202

Mobile Devices and Printers

Two A+ Core 1 topics that are pure recall. The laser imaging process is asked in order almost every exam cycle, and the fault table is the shape most printer questions take.

What is in it

  • The laser imaging process, in order7
  • Printer types6
  • Printer faults8
  • Mobile connectors and sync8
29entriesOpen cheat sheet →

220-1201XK0-005KCNA

Virtualisation and Containers

The comparison that gets tested is what a container shares with the host and what a virtual machine does not. Everything else follows from that one difference.

What is in it

  • Virtual machines against containers8
  • Hypervisor types4
  • Docker commands9
  • Virtualisation terms8
29entriesOpen cheat sheet →

220-1201SY0-701XK0-005

Backup, RAID and Recovery

RAID levels and backup types both come down to a trade between speed, capacity and how much you can lose. The tables state each one so a scenario can be matched to it.

What is in it

  • RAID levels5
  • Backup types5
  • Backup strategy6
  • Recovery sites4
20entriesOpen cheat sheet →

220-1202N10-009220-1201

Troubleshooting Methodology

CompTIA tests the order directly. A question gives you a scenario mid-way through and asks what to do next, and the answer is whichever step comes next in this list, not whichever action would fix it fastest.

What is in it

  • The six steps, in order6
  • Network troubleshooting commands11
  • Working out where the fault is7
24entriesOpen cheat sheet →

N10-009SY0-701220-1201

DNS Record Types

DNS appears in networking questions as a record type and in security questions as email authentication. Both sets are here, because SPF, DKIM and DMARC are all TXT records and the exam expects you to know what each one asserts.

What is in it

  • Record types10
  • Email authentication6
  • Resolution order and terms8
24entriesOpen cheat sheet →

CS0-003PT0-003SY0-701

MITRE ATT&CK Tactics

ATT&CK organises what attackers do into tactics, which are goals, and techniques, which are the ways of reaching them. Exam questions give you an observed behaviour and ask which tactic it belongs to.

What is in it

  • Enterprise tactics, in rough order14
  • Cyber Kill Chain, and how it differs7
  • Related models5
26entriesOpen cheat sheet →

CS0-003PT0-003SY0-701

Security Tools

Exam questions describe a task and ask which tool does it. The grouping below is by task rather than by name, because that is how the question arrives.

What is in it

  • Which tool for which job12
  • Nmap flags worth knowing10
  • Wireshark and tcpdump filters8
30entriesOpen cheat sheet →

CS0-003SC-200SY0-701

Log Analysis and Event IDs

Analysis questions hand you a log line and ask what happened. Knowing which event ID means what, and which file to look in, is most of the work.

What is in it

  • Windows security event IDs13
  • Windows logon types9
  • Linux log locations9
  • Investigation questions to ask of a log7
38entriesOpen cheat sheet →

SY0-701CISSPCS0-003

Risk Management Formulas

The quantitative formulas are the only maths on Security+ and they appear most years. The worked example runs one scenario through every formula so the relationships are visible.

What is in it

  • The formulas6
  • Worked example7
  • Risk treatment5
  • Continuity metrics6
24entriesOpen cheat sheet →

XK0-005EX200CKA

Linux Command Reference

The commands that come up in exam scenarios, grouped by what you are trying to do. The permissions table is the one worth memorising, because octal notation appears in questions that are not otherwise about permissions.

What is in it

  • Files and directories10
  • Permissions and ownership8
  • Octal permissions8
  • Processes, services and networking11
37entriesOpen cheat sheet →

N10-009200-301SY0-701

OSI and TCP/IP Models

Layer questions are usually device questions or troubleshooting questions in disguise. Knowing which layer a device operates at tells you what it can and cannot see, which is what the question is really asking.

What is in it

  • The seven layers7
  • Device to layer10
  • TCP/IP model mapping4
  • TCP against UDP6
27entriesOpen cheat sheet →

N10-009220-1201200-301

Cabling, Connectors and Standards

Distance and speed are what these questions turn on. A scenario gives you a run length and a required speed, and the answer is whichever standard covers both.

What is in it

  • Copper Ethernet standards8
  • Fibre standards6
  • Connectors9
  • T568A and T568B pinout8
31entriesOpen cheat sheet →

N10-009220-1201SY0-701

Wireless Standards and Security

Two things get tested: which 802.11 standard fits a speed and band requirement, and which security protocol to use. The channel table matters because non-overlapping channels are a recurring troubleshooting answer.

What is in it

  • 802.11 standards8
  • Bands and channels7
  • Wireless security8
23entriesOpen cheat sheet →

SY0-701CISSPSC-300

Access Control Models

Four models, and exam questions separate them by one question: who decides who gets in. The authentication factor tables underneath are the other half, because multifactor questions turn on whether two factors are actually different types.

What is in it

  • The models6
  • Authentication factors5
  • Multifactor: what counts6
  • AAA and biometric measures9
26entriesOpen cheat sheet →

SY0-701CS0-003SC-200

Incident Response and Forensics

Order is what these questions test. The phases run in one sequence, evidence is collected most volatile first, and getting either backwards is the wrong answer even when every individual step is right.

What is in it

  • The six phases, in order6
  • Order of volatility7
  • Evidence handling8
  • Exercise types5
26entriesOpen cheat sheet →

SY0-701CISSPSC-900

Frameworks and Regulations

Questions here turn on which document applies to the situation described. A framework is voluntary guidance, a regulation carries legal force, and an audit report is evidence about a third party.

What is in it

  • Frameworks12
  • Regulations and standards8
  • Audit reports and agreements10
30entriesOpen cheat sheet →

SY0-701CS0-003SC-900

Security+ Acronyms

CompTIA publishes an acronym list with the SY0-701 objectives and then writes questions that use the short form without expanding it. These are grouped by subject rather than alphabetically, because that is how they come up.

What is in it

  • Identity and access12
  • Cryptography12
  • Network defence and operations12
  • Risk, governance and continuity12
48entriesOpen cheat sheet →

SY0-701CS0-003PT0-003

Attack Types

Exam questions rarely name an attack. They describe one and ask what it was. Each row here carries the detail that separates it from the attack next to it, which is the part the question turns on.

What is in it

  • Social engineering14
  • Malware12
  • Network attacks13
  • Application and password attacks13
52entriesOpen cheat sheet →

SY0-701SC-900CISSP

Cryptography Basics

What each algorithm is for, and which of the three properties it gives you. Most cryptography questions are answered by knowing whether the scenario needs confidentiality, integrity, or authenticity.

What is in it

  • What each property needs6
  • Symmetric algorithms6
  • Asymmetric and hashing9
  • PKI components12
33entriesOpen cheat sheet →

SY0-701N10-009220-1201

Common Ports & Protocols

The well-known ports you must recognize for CompTIA Network+, Security+, and A+. Insecure protocols are paired with their encrypted replacements, a favorite exam theme.

What is in it

  • Well-known ports21
  • Insecure → secure protocol pairs6
27entriesOpen cheat sheet →

220-1201

A+ Hardware Quick Reference

The hardware facts A+ Core 1 (220-1201) loves to test: memory and storage generations, RAID levels, connectors, and the imaging process order.

What is in it

  • Storage interfaces (fastest → slowest)5
  • RAID levels5
  • Laser imaging process (in order)7
17entriesOpen cheat sheet →

220-1202

A+ Command Line Reference

The command line tools A+ Core 2 (220-1202) expects you to recognize on sight, with the switches that get tested. Windows commands first, then the Linux and macOS commands from objective 1.9.

What is in it

  • Windows network commands15
  • Windows file and disk commands15
  • Windows system and policy commands12
  • Linux and macOS file commands13
  • Linux and macOS system commands13
  • chmod permission values12
80entriesOpen cheat sheet →

220-1202

Windows Troubleshooting Reference

Symptom to cause to first action, for the Windows problems A+ Core 2 (220-1202) puts in front of you. Covers boot failures, the repair tools, malware removal order, and the security settings on objective 2.2.

What is in it

  • Boot and startup symptoms8
  • Recovery and repair tools10
  • Run box and .msc shortcuts15
  • Malware removal procedure, in order7
  • Application and performance symptoms10
  • Windows OS security settings10
60entriesOpen cheat sheet →

200-301N10-009350-401

IPv6 Addressing

IPv6 questions are usually recognition rather than calculation: which type of address is this, and what is the shortened form. Both tables below answer that directly.

What is in it

  • Address types9
  • Shortening rules5
  • Structure and configuration8
  • Transition mechanisms4
26entriesOpen cheat sheet →

200-301N10-009350-401

Routing Protocols

A router picks the longest prefix match first, then the lowest administrative distance, then the lowest metric. Most routing questions are that sequence applied to a table.

What is in it

  • Route selection, in order4
  • Administrative distance11
  • Protocol comparison5
  • OSPF essentials7
27entriesOpen cheat sheet →

200-301N10-009350-401

Switching, VLANs and Spanning Tree

Switching questions come in two shapes: a configuration that does not work, and a topology asking which port blocks. The command tables answer the first and the spanning tree tables answer the second.

What is in it

  • VLAN and trunk commands10
  • Spanning tree port states5
  • Spanning tree roles and election8
  • EtherChannel and port security9
32entriesOpen cheat sheet →

200-301N10-009

CCNA Subnetting Reference

Subnetting under time pressure is the CCNA skill. Memorize this table and the block-size trick, and subnet questions become seconds, not minutes.

What is in it

  • CIDR / mask / host reference10
  • Fast method5
  • Private address ranges (RFC 1918)4
19entriesOpen cheat sheet →

CISSPSY0-701

CISSP Domains

CISSP is a management exam written for someone who thinks like a risk owner rather than an engineer. The weightings decide where study time goes, and the models table covers the recognition questions.

What is in it

  • The eight domains8
  • Security models6
  • Terms the exam expects10
24entriesOpen cheat sheet →

CKACKADKCNA

kubectl and Kubernetes Objects

The CKA and CKAD are performance exams under a clock, so speed matters more than breadth. These are the commands that come up, plus the order to debug a pod that will not start.

What is in it

  • Everyday commands10
  • Speed under a clock6
  • Core objects12
  • Pod not starting: debug order6
34entriesOpen cheat sheet →

Nothing here asks for an email. Open a sheet, print it, and the paper carries its title and the page it came from, so it still says what it is a week later on your desk.