Labour Day Special - Limited Time 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: top65certs

CompTIA N10-008 Dumps

Page: 1 / 61
Total 849 questions

CompTIA Network+ Certification Exam Questions and Answers

Question 1

Which of the following routing technologies uses a successor and a feasible successor?

Options:

A.

IS-IS

B.

OSPF

C.

BGP

D.

EIGRP

Question 2

A new computer that was connected to the network reported an error of an identical IP address with another computer. Both computers were configured for SLAAC. Which of the following is causing the error?

Options:

A.

Rogue DHCP server

B.

Duplicate MAC addresses

C.

Incorrect router advertisement

D.

Wrong VLAN assignment

Question 3

Which of the following types of connections would need to be set up to provide access from the internal network to an external network so multiple satellite offices can communicate securely using various ports and protocols?

Options:

A.

Client-to-site VPN

B.

Clientless VPN

C.

RDP

D.

Site-to-site VPN

E.

SSH

Question 4

Which of the following attacks, if successful, would provide a malicious user who is connected to an isolated guest network access to the corporate network?

Options:

A.

VLAN hopping

B.

On-path attack

C.

IP spoofing

D.

Evil twin

Question 5

A technician is troubleshooting servers with high CPU usage. While trying to connect, the technician needs to open a port for remote access. Which of the following ports should the

technician open?

Options:

A.

443

B.

3321

C.

8080

D.

5900

Question 6

A network technician receives a support ticket concerning multiple users who are unable access the company's shared drive. The switch interface that the shared drive Is connected to is displaying die following:

Which of the following is MOST likely the Issue?

Options:

A.

The switchport Is shut down

B.

The cable Is not plugged In.

C.

The loopoack Is not set

D.

The bandwidth configuration is incorrect.

Question 7

A network administrator is configuring a firewall to allow for a new cloud-based email server. The company standard is to use SMTP to route email traffic. Which of the following ports, by default, should be reserved for this purpose?

Options:

A.

23

B.

25

C.

53

D.

110

Question 8

A bank installed a new smart TV to stream online video services, but the smart TV was not able to connect to the branch Wi-Fi. The next day. a technician was able to connect the TV to the Wi-Fi, but a bank laptop lost network access at the same time. Which of the following is the MOST likely cause?

Options:

A.

DHCP scope exhaustion

B.

AP configuration reset

C.

Hidden SSID

D.

Channel overlap

Question 9

A sales team at a company uses a SaaS solution primarily for videoconferencing and a CRM application that connects to a database server in the corporate data center. Which of the following VPN solutions would allow secure, remote access for sales staff to the CRM application without impacting videoconferencing traffic?

Options:

A.

Clientless

B.

Site-to-site

C.

Split tunnel

D.

Full tunnel

Question 10

A technician is troubleshooting a connectivity issue with an end user. The end user can access local network shares and intranet pages but is unable to access the internet or remote resources. Which of the following needs to be reconfigured?

Options:

A.

The IP address

B.

The subnet mask

C.

The gateway address

D.

The DNS servers

Question 11

A network administrator is configuring logging on an edge switch. The requirements are to log each time a switch port goes up or down. Which of the following logging levels will provide this information?

Options:

A.

Warnings

B.

Notifications

C.

Alert

D.

Errors

Question 12

A network technician 13 troubleshooting a specific port on a switch. Which of the following commands should the technician use to see the port configuration?

Options:

A.

show route

B.

show Interface

C.

show arp

D.

show port

Question 13

To find the best subnet mask that meets the requirement of six usable IP addresses, we need to calculate the number of host bits and the number of host addresses for each option. The number of host bits is the number of 0s in the binary representation of the subnet mask, and the number of host addresses is 2^host bits - 2 (the -2 is to exclude the network address and the broadcast address). The option that has the smallest number of host addresses that is greater than or equal to six is the best choice. Here are the calculations for each option:

Options:

A.

255.255.255.128

Binary: 11111111.11111111.11111111.10000000

Host bits: 7

Host addresses: 2^7 - 2 = 126 - 2 = 124

This option has too many host addresses for the requirement.

B.

255.255.255.192

Binary: 11111111.11111111.11111111.11000000

Host bits: 6

Host addresses: 2^6 - 2 = 64 - 2 = 62

This option also has too many host addresses for the requirement.

C.

255.255.255.224

Binary: 11111111.11111111.11111111.11100000

Host bits: 5

Host addresses: 2^5 - 2 = 32 - 2 = 30

This option has the smallest number of host addresses that is greater than or equal to six, so this is the best choice.

D.

255.255.255.240

Binary: 11111111.11111111.11111111.11110000

Host bits: 4

Host addresses: 2^4 - 2 = 16 - 2 = 14

This option has fewer host addresses than the requirement, so this is not a valid choice.

Question 14

Which of the following would be used to enforce and schedule critical updates with supervisory approval and include backup plans in case of failure?

Options:

A.

Business continuity plan

B.

Onboarding and offboarding policies

C.

Acceptable use policy

D.

System life cycle

E.

Change management

Question 15

An engineer needs to restrict the database servers that are in the same subnet from communicating with each other. The database servers will still need to communicate with the application servers in a different subnet. In some cases, the database servers will be clustered, and the servers will need to communicate with other cluster members. Which of the following technologies will be BEST to use to implement this filtering without creating rules?

Options:

A.

Private VLANs

B.

Access control lists

C.

Firewalls

D.

Control plane policing

Question 16

Which of the following can be used to centrally manage credentials for various types of administrative privileges on configured network devices?

Options:

A.

SSO

B.

TACACS+

C.

Zero Trust

D.

Separation of duties

E.

Multifactor authentication

Question 17

A network device needs to discover a server that can provide it with an IPv4 address. Which of the following does the device need to send the request to?

Options:

A.

Default gateway

B.

Broadcast address

C.

Unicast address

D.

Link local address

Question 18

Which of the following bandwidth management techniques uses buffers al the client side to prevent TCP retransmissions from occurring when the ISP starts to drop packets of specific types that exceed the agreed traffic rate?

Options:

A.

Traffic shaping

B.

Traffic policing

C.

Traffic marking

D.

Traffic prioritization

Question 19

Which of the following would be BEST suited for use at the access layer in a three-tier architecture system?

Options:

A.

Router

B.

Multilayer switch

C.

Layer 2 switch

D.

Access point

Question 20

A technician is consolidating a topology with multiple SSlDs into one unique SSiD deployment. Which of the following features will be possible after this new configuration?

Options:

A.

Seamless roaming

B.

Basic service set

C.

WPA

D.

MU-MIMO

Question 21

Users al a company will require more bandwidth on their wireless laptops because of a migration to the cloud. The company's current infrastructure contains four 802.11n access points, which are creating a bottleneck. Hardware upgrades are not an option. Which of the following configurations will provide a solution?

Options:

A.

Increasing RSSi

B.

MIMO

C.

Channel bonding

D.

Reconfiguring SSID

Question 22

A device is connected to a managed Layer 3 network switch. The MAC address of the device is known, but the static IP address assigned to the device is not. Which of the following features of a Layer 3 network switch should be used to determine the IPv4 address of the device?

Options:

A.

MAC table

B.

Neighbor Discovery Protocol

C.

ARP table

D.

IPConfig

E.

ACL table

Question 23

A business purchased redundant internet connectivity from two separate ISPs. Which of the following is the business MOST likely implementing?

Options:

A.

NIC teaming

B.

Hot site

C.

Multipathing

D.

Load balancing

Question 24

Network connectivity in an extensive forest reserve was achieved using fiber optics. A network fault was detected, and now the repair team needs to check the integrity of the fiber cable. Which of me following actions can reduce repair time?

Options:

A.

Using a tone generator and wire map to determine the fault location

B.

Using a multimeter to locate the fault point

C.

Using an OTDR In one end of the optic cable to get the liber length information

D.

Using a spectrum analyzer and comparing the current wavelength with a working baseline

Question 25

A network administrator is investigating a network event that is causing all communication to stop. The network administrator is unable to use SSH to connect to the switch but is able to gain access using the serial console port. While monitoring port statistics, the administrator sees the following:

Which of the following is MOST likely causing the network outage?

Options:

A.

Duplicate IP address

B.

High collisions

C.

Asynchronous route

D.

Switch loop

Question 26

A help desk technician is concerned that a client's network cable issues may be causing intermittent connectivity. Which of the following would help the technician determine if this is the issue?

Options:

A.

Run the show interface command on the switch

B.

Run the tracerouute command on the server

C.

Run iperf on the technician's desktop

D.

Ping the client's computer from the router

E.

Run a port scanner on the client's IP address

Question 27

A global company has acquired a local company. The companies are geographically separate. The IP address ranges for the two companies are as follows:

· Global company: 10.0.0.0/16

· Local company: 10.0.0.0/24

Which of the following can the network engineer do to quickly connect the two companies?

Options:

A.

Assign static routing to advertise the local company's network.

B.

Assign an overlapping IP address range to both companies.

C.

Assign a new IP address range to the local company.

D.

Assign a NAT range to the local company.

Question 28

Which of the following cloud components can filter inbound and outbound traffic between cloud resources?

Options:

A.

NAT gateways

B.

Service endpoints

C.

Network security groups

D.

Virtual private cloud

Question 29

A Wi-Fi network was recently deployed in a new, multilevel budding. Several issues are now being reported related to latency and drops in coverage. Which of the following is the FIRST step to troubleshoot the issues?

Options:

A.

Perform a site survey.

B.

Review the AP placement

C.

Monitor channel utilization.

D.

Test cable attenuation.

Question 30

A technician is investigating why a PC cannot reach a file server with the IP address 192.168.8.129. Given the following TCP/IP network configuration:

Which of the following configurations on the PC is incorrect?

Options:

A.

Subnet mask

B.

IPv4 address

C.

Default gateway

D.

IPv6 address

Question 31

Which of the following is the most accurate NTP time source that is capable of being accessed across a network connection?

Options:

A.

Stratum 0 device

B.

Stratum 1 device

C.

Stratum 7 device

D.

Stratum 16 device

Question 32

A network administrator wants to know which systems on the network are at risk of a known vulnerability. Which of the following should the administrator reference?

Options:

A.

SLA

B.

Patch management policy

C.

NDA

D.

Site survey report

E.

CVE

Question 33

A network technician is attempting to harden a commercial switch that was recently purchased. Which of the following hardening techniques best mitigates the use of publicly available information?

Options:

A.

Changing the default password

B.

Blocking inbound SSH connections

C.

Removing the gateway from the network configuration

D.

Restricting physical access to the switch

Question 34

A technician is setting up DNS records on local servers for the company's cloud DNS to enable access by hostname. Which of the following records should be used?

Options:

A.

A

B.

MX

C.

CNAME

D.

NS

Question 35

An administrator needs to connect two laptops directly to each other using 802.11ac but does not have an AP available. Which of the following describes this configuration?

Options:

A.

Basic service set

B.

Extended service set

C.

Independent basic service set

D.

MU-MIMO

Question 36

Which of the following ports is a secure protocol?

Options:

A.

20

B.

23

C.

443

D.

445

Question 37

A company is considering shifting its business to the cloud. The management team is concerned at the availability of the third-party cloud service. Which of the following should the management team consult to determine the promised availability of the cloud provider?

Options:

A.

Memorandum of understanding

B.

Business continuity plan

C.

Disaster recovery plan

D.

Service-level agreement

Question 38

Which of the following is conducted frequently to maintain an updated list of a system's weaknesses?

Options:

A.

Penetration test

B.

Posture assessment

C.

Risk assessment

D.

Vulnerability scan

Question 39

A PC and a network server have no network connectivity, and a help desk technician is attempting to resolve the issue. The technician plans to run a constant ping command from a Windows workstation while testing various possible reasons for the connectivity issue. Which of the following should the technician use?

Options:

A.

ping —w

B.

ping -i

C.

ping —s

D.

ping —t

Question 40

A technician is trying to determine whether an LACP bundle is fully operational. Which of the following commands will the technician MOST likely use?

Options:

A.

show interface

B.

show config

C.

how route

D.

show arp

Question 41

A technician is troubleshooting network connectivity from a wall jack. Readings from a multimeter indicate extremely low ohmic values instead of the rated impedance from the switchport. Which of the following is the MOST likely cause of this issue?

Options:

A.

Incorrect transceivers

B.

Faulty LED

C.

Short circuit

D.

Upgraded OS version on switch

Question 42

Which of the following compromises internet-connected devices and makes them vulnerable to becoming part of a botnet? (Select TWO)

Options:

A.

Deauthentication attack

B.

Malware infection

C.

IP spoofing

D.

Firmware corruption

E.

Use of default credentials

F.

Dictionary attack

Question 43

The Chief Executive Officer of a company wants to ensure business operations are not disrupted in the event of a disaster. The solution must have fully redundant equipment, real-time synchronization, and zero data loss. Which Of the following should be prepared?

Options:

A.

Cloud site

B.

Warm site

C.

Hot site

D.

Cold site

Question 44

A technician needs to set up a wireless connection that utilizes MIMO on non-overlapping channels. Which of the following would be the best choice?

Options:

A.

802.11a

B.

802.11b

C.

802.11g

D.

802.11n

Question 45

A network engineer needs to change an entire subnet of SLAAC-configured workstation addresses. Which of the following methods would be the best for the engineer to use?

Options:

A.

Change the address prefix in ARP in order for the workstations to retrieve their new addresses.

B.

Change the address prefix in a router in order for the router to advertise the new prefix with an ND.

C.

Change the address prefix scope in a DHCP server in order for the workstations to retrieve their new addresses.

D.

Change the workstations' address prefix manually because an automated method does not exist.

Question 46

A software developer changed positions within a company and is now a sales engineer. The security team discovered that the former software developer had been modifying code to

implement small features requested by customers. Which of the following would be the best thing for the security administrator to implement to prevent this from happening?

Options:

A.

A software patching policy

B.

A role-based access control policy

C.

Firewalls on the software development servers

D.

Longer and more complex password requirements

Question 47

A technician is assisting a user who cannot connect to a website. The technician attempts to ping the default gateway and DNS server of the workstation. According to troubleshooting methodology, this is an example of:

Options:

A.

a divide-and-conquer approach.

B.

a bottom-up approach.

C.

a top-to-bottom approach.

D.

implementing a solution.

Question 48

A computer engineer needs to ensure that only a specific workstation can connect to port 1 on a switch. Which of the following features should the engineer configure on the switch interface?

Options:

A.

Port tagging

B.

Port security

C.

Port mirroring

D.

Port aggregation

Question 49

Which of the following protocols would enable a company to upgrade its internet connection by acquiring its own public IP prefixes and autonomous system number?

Options:

A.

EIGRP

B.

BGP

C.

IPv6

D.

MPLS

Question 50

Which of the following fouling protocols is generally used by major ISPs for handing large-scale internet traffic?

Options:

A.

RIP

B.

EIGRP

C.

OSPF

D.

BGP

Question 51

An online gaming company needs a cloud solution that will allow for more virtual resources to be deployed when tournaments are held. The number of users who access the service

increases during tournaments. The company also needs the resources to return to baseline levels once the resources are not needed in order to reduce cost. Which of the following

cloud concepts would provide the best solution?

Options:

A.

Scalability

B.

Hybrid

C.

Multitenancy

D.

Elasticity

Question 52

Which of the following routing protocols uses bandwidth and delay as the primary metrics to calculate the best path?

Options:

A.

EIGRP

B.

RIP

C.

OSPF

D.

BGP

Question 53

A company ranis out a largo event space and includes wireless internet access for each tenant. Tenants reserve a two-hour window from the company each week, which includes a tenant-specific SSID However, all users share the company's network hardware.

The network support team is receiving complaints from tenants that some users are unable to connect to the wireless network Upon investigation, the support teams discovers a pattern indicating that after a tenant with a particularly large attendance ends its sessions, tenants throughout the day are unable to connect.

The following settings are common lo all network configurations:

Which of the following actions would MOST likely reduce this Issue? (Select TWO).

Options:

A.

Change to WPA encryption

B.

Change the DNS server to 10.1.10.1.

C.

Change the default gateway to 10.0.0.1.

D.

Change the DHCP scope end to 10.1.10.250

E.

Disable AP isolation

F.

Change the subnet mask lo 255.255.255.192.

G.

Reduce the DHCP lease time to four hours.

Question 54

A network technician is attempting to increase throughput by configuring link port aggregation between a Gigabit Ethernet distribution switch and a Fast Ethernet access switch. Which of the following is the BEST choice concerning speed and duplex for all interfaces that are participating in the link aggregation?

Options:

A.

Half duplex and 1GB speed

B.

Full duplex and 1GB speed

C.

Half duplex and 10OMB speed

D.

Full duplex and 100MB speed

Question 55

A customer calls the help desk to report that users are unable to access any network resources_ The issue started earlier in the day when an employee rearranged the wiring closet A technician goes to the site but does not observe any obvious damage. The statistics output on the switch indicates high CPI-J usage, and all the lights on the switch are blinking rapidly in unison_ Which of the following is the most likely explanation for these symptoms?

Options:

A.

The switch was rebooted and set to run in safe mode.

B.

The line between the switch and the upstream router was removed

C.

A cable was looped and created a broadcast storm.

D.

A Cat 6 cable from the modem to the router was replaced with Cat 5e.

Question 56

An engineer is using a tool to run an ICMP sweep of a network to find devices that are online. When reviewing the results, the engineer notices a number of workstations that are currently verified as being online are not listed in the report.

The tool was configured to scan using the following information:

Network address: 172.28.16.0

CIDR: /22

The engineer collected the following information from the client workstation:

IP address: 172.28.17.206

Subnet mask: 255.255.252.0

Which of the following MOST likely explains why the tool is failing to detect some workstations?

Options:

A.

The scanned network range is incorrect.

B.

The subnet mask on the client is misconfigured.

C.

The workstation has a firewall enabled.

D.

The tool is unable to scan remote networks.

Question 57

A company joins a bank's financial network and establishes a connection to the clearinghouse servers in the range 192 168.124.0/27. An IT technician then realizes the range exists within the VM pool at the data center. Which of the following is the BEST way for the technician to connect to the bank's servers?

Options:

A.

NAT

B.

PAT

C.

CIDR

D.

SLAAC

Question 58

A user from a remote office is reporting slow file transfers. Which of the following tools will an engineer MOST likely use to get detailed measurement data?

Options:

A.

Packet capture

B.

IPerf

C.

SIEM log review

D.

Internet speed test

Question 59

A firewall administrator observes log entries of traffic being allowed to a web server on port 80 and port 443. The policy for this server is to only allow

traffic on port 443. The firewall administrator needs to investigate how this change occurred to prevent a reoccurrence. Which of the following should

the firewall administrator do next?

Options:

A.

Consult the firewall audit logs.

B.

Change the policy to allow port 80.

C.

Remove the server object from the firewall policy.

D.

Check the network baseline.

Question 60

At which of the following OSI model layers does a MAC filter list for a wireless infrastructure operate?

Options:

A.

Physical

B.

Network

C.

Session

D.

Data link

Question 61

A customer needs to distribute Ethernet to multiple computers in an office. The customer would like to use non-proprietary standards. Which of the following blocks does the technician need to install?

Options:

A.

110

B.

66

C.

Bix

D.

Krone

Question 62

An organization recently connected a new computer to the LAN. The user is unable to ping the default gateway. Which of the following is the most likely cause?

Options:

A.

The DHCP server is not available.

B.

An RFC1918 address is being used

C.

The VLAN is incorrect.

D.

A static IP is assigned.

Question 63

Which of the following should be used to associate an IPv6 address with a domain name?

Options:

A.

AAAA

B.

A

C.

SOA

D.

TXT

Question 64

Which of the following would be the MOST cost-effective recovery solution for a company's lower-priority applications?

Options:

A.

Warm site

B.

Cloud site

C.

Hot site

D.

Cold site

Question 65

A desktop support department has observed slow wireless speeds for a new line of laptops using the organization's standard image. No other devices have experienced the same issue. Which of the following should the network administrator recommend troubleshooting FIRST to resolve this issue?

Options:

A.

Increasing wireless signal power

B.

Installing a new WAP

C.

Changing the protocol associated to the SSID

D.

Updating the device wireless drivers

Question 66

A company's publicly accessible servers are connected to a switch between the company's ISP-connected router and the firewall in front of the company network. The firewall is stateful, and the router is running an ACL. Which of the following best describes the area between the router and the firewall?

Options:

A.

Untrusted zone

B.

Screened subnet

C.

Trusted zone

D.

Private VLAN

Question 67

A network client is trying to connect to the wrong TCP port. Which of the following responses would the client MOST likely receive?

Options:

A.

RST

B.

FIN

C.

ICMP Time Exceeded

D.

Redirect

Question 68

All packets arriving at an interface need to be fully analyzed. Which of me following features should be used to enable monitoring of the packets?

Options:

A.

LACP

B.

Flow control

C.

Port mirroring

D.

NetFlow exporter

Question 69

A network administrator needs to configure a server to use the most accurate NTP reference available. Which of the following NTP devices should the administrator select?

Options:

A.

Stratum 1

B.

Stratum 2

C.

Stratum 3

D.

Stratum 4

Question 70

Which of the following would be the MOST likely attack used to bypass an access control vestibule?

Options:

A.

Tailgating

B.

Phishing

C.

Evil twin

D.

Brute-force

Question 71

Which of the following is the best way to remotely monitor who is accessing a secure data center?

Options:

A.

Access control vestibule

B.

Cameras

C.

Employee training

D.

Biometrics

Question 72

A technician is troubleshooting a client's report about poor wireless performance. Using a client monitor, the technician notes the following information:

Which of the following is most likely the cause of the issue?

Options:

A.

Channel overlap

B.

Poor signal

C.

Incorrect power settings

D.

Wrong antenna type

Question 73

A technician is installing the Wi-Fi infrastructure for legacy industrial machinery at a warehouse. The equipment only supports 802.11a and 802.11b standards. Speed of transmission is the top business requirement. Which of the following is the correct maximum speed for this scenario?

Options:

A.

11Mbps

B.

54Mbps

C.

128Mbps

D.

144Mbps

Question 74

A network administrator is looking for a solution to extend Layer 2 capabilities and replicate backups between sites. Which of the following is the best solution?

Options:

A.

Security Service Edge

B.

Data center interconnect

C.

Infrastructure as code

D.

Zero trust architecture

Question 75

Which of the following is the DNS feature that controls how long a lookup is stored in cache on a server?

Options:

A.

CNAME

B.

TTL

C.

SOA

D.

SRV

Question 76

A network technician is deploying multiple switches for a new office. The switches are separately managed and need to be cabled in to support dual firewalls in a HA setup. Which of the following should the technician enable to support proper stability of the network switches?

Options:

A.

NTP

B.

CDMA

C.

STP

D.

LACP

E.

802.1Q

Question 77

A technician is investigating an intermittent connectivity issue that occurs when specific WAPs are turned on. The technician checks into the issue further and finds the WAPs that are having issues share channel five. Which of the following is most likely causing the issue?

Options:

A.

Polarization

B.

Interference

C.

Incorrect channel

D.

Low power levels

Question 78

Which of the following can be used to validate domain ownership by verifying the presence of pre-agreed content contained in a DNS record?

Options:

A.

SOA

B.

SRV

C.

AAA

D.

TXT

Question 79

A technician discovered that some information on the local database server was changed during a tile transfer to a remote server. Which of the following should concern the technician the MOST?

Options:

A.

Confidentiality

B.

Integrity

C.

DDoS

D.

On-path attack

Question 80

A security engineer is trying to determine whether an internal server was accessed by hosts on the internet. The internal server was shut down during the investigation Which of the following will the engineer review to determine whether the internal server had an unauthorized access attempt?

Options:

A.

The server's syslog

B.

The NetFlow statistics

C.

The firewall logs

D.

The audit logs on the core switch

Question 81

A technician wants to assign addresses to PCs on a subnet that uses IPv4 and IPv6. The DHCP server only supports IPv4. Which of the following can the technician use to assign IPv6 addresses without DHCP?

Options:

A.

SLAAC

B.

APIPA

C.

MAC reservation

D.

IPv4 to IPv6 tunnel

Question 82

An engineer needs to verity the external record tor SMTP traffic. The engineer logged in to the server and entered the nslookup command. Which of the following commands should the engineer send before entering the DNS name?

Options:

A.

set type=A

B.

is -d company-mail.com

C.

set domain=company.mail.com

D.

set querytype=Mx

Question 83

A network administrator needs to change where the outside DNS records are hosted. Which of the following records should the administrator change at the

registrar to accomplish this task?

Options:

A.

NS

B.

SOA

C.

PTR

D.

CNAME

Question 84

A network administrator is planning to implement device monitoring to enhance network visibility. The security team requires that the solution provides authentication and encryption.

Which of the following meets these requirements?

Options:

A.

SIEM

B.

Syslog

C.

NetFlow

D.

SNMPv3

Question 85

Which of the following would be used when connecting devices that have different physical characteristics?

Options:

A.

A proxy server

B.

An industrial control system

C.

A load balancer

D.

A media converter

Question 86

A network technician is installing new software on a Windows-based server in a different geographical location. Which of the following would be BEST for the technician to use to perform this task?

Options:

A.

RDP

B.

SSH

C.

FTP

D.

DNS

Question 87

A technician is troubleshooting a network switch that seems to stop responding to requests intermittently whenever the logging level is set for debugging. Which of the following metrics should the technician check to begin troubleshooting the issue?

Options:

A.

Audit logs

B.

CPU utilization

C.

CRC errors

D.

Jitter

Question 88

Which of the following is used to track and document various types of known vulnerabilities?

Options:

A.

CVE

B.

Penetration testing

C.

Zero-day

D.

SIEM

E.

Least privilege

Question 89

A user reports being unable to access network resources after making some changes in the office. Which of the following should a network technician do FIRST?

Options:

A.

Check the system’s IP address

B.

Do a ping test against the servers

C.

Reseat the cables into the back of the PC

D.

Ask what changes were made

Question 90

A user tries to ping 192.168.1.100 from the command prompt on the 192.168.2.101 network but gets the following response: U.U.U.U. Which of the following needs to be configured for these networks to reach each other?

Options:

A.

Network address translation

B.

Default gateway

C.

Loopback

D.

Routing protocol

Question 91

Which of the following is used to prioritize Internet usage per application and per user on the network?

Options:

A.

Bandwidth management

B.

Load balance routing

C.

Border Gateway Protocol

D.

Administrative distance

Question 92

An administrator is writing a script to periodically log the IPv6 and MAC addresses of all the devices on a network segment. Which of the following switch features will MOST likely be used to assist with this task?

Options:

A.

Spanning Tree Protocol

B.

Neighbor Discovery Protocol

C.

Link Aggregation Control Protocol

D.

Address Resolution Protocol

Question 93

A network technician is reviewing the interface counters on a router interface. The technician is attempting to confirm a cable issue. Given the following information:

Which of the following metrics confirms there is a cabling issue?

Options:

A.

Last cleared

B.

Number of packets output

C.

CRCs

D.

Giants

E.

Multicasts

Question 94

Which of the following devices would be used to manage a corporate WLAN?

Options:

A.

A wireless NAS

B.

A wireless bridge

C.

A wireless router

D.

A wireless controller

Question 95

A network administrator needs to query the NSs for a remote application. Which of the following commands would BEST help the administrator accomplish this task?

Options:

A.

dig

B.

arp

C.

show interface

D.

hostname

Question 96

A network administrator is implementing OSPF on all of a company’s network devices. Which of the following will MOST likely replace all the company’s hubs?

Options:

A.

A Layer 3 switch

B.

A proxy server

C.

A NGFW

D.

A WLAN controller

Question 97

Given the following information:

Which of the following command-line tools would generate this output?

Options:

A.

netstat

B.

arp

C.

dig

D.

tracert

Question 98

A technician is installing multiple UPS units in a major retail store. The technician is required to keep track of all changes to new and old equipment. Which of the following will allow the technician to record these changes?

Options:

A.

Asset tags

B.

A smart locker

C.

An access control vestibule

D.

A camera

Question 99

You are tasked with verifying the following requirements are met in order to ensure network security.

Requirements:

Datacenter

Ensure network is subnetted to allow all devices to communicate properly while minimizing address space usage

Provide a dedicated server to resolve IP addresses and hostnames correctly and handle port 53 traffic

Building A

Ensure network is subnetted to allow all devices to communicate properly while minimizing address space usage

Provide devices to support 5 additional different office users

Add an additional mobile user

Replace the Telnet server with a more secure solution

Screened subnet

Ensure network is subnetted to allow all devices to communicate properly while minimizing address space usage

Provide a server to handle external 80/443 traffic

Provide a server to handle port 20/21 traffic

INSTRUCTIONS

Drag and drop objects onto the appropriate locations. Objects can be used multiple times and not all placeholders need to be filled.

Available objects are located in both the Servers and Devices tabs of the Drag & Drop menu.

If at any time you would like to bring back the initial state of the simulation, please click the Reset All button.

Options:

Question 100

Which of the following technologies provides a failover mechanism for the default gateway?

Options:

A.

FHRP

B.

LACP

C.

OSPF

D.

STP

Question 101

Which of the following routing protocols is used to exchange route information between public autonomous systems?

Options:

A.

OSPF

B.

BGP

C.

EGRIP

D.

RIP

Question 102

A network administrator is configuring a load balancer for two systems. Which of the following must the administrator configure to ensure connectivity during a failover?

Options:

A.

VIP

B.

NAT

C.

APIPA

D.

IPv6 tunneling

E.

Broadcast IP

Question 103

According to troubleshooting methodology, which of the following should the technician do NEXT after determining the most likely probable cause of an issue?

Options:

A.

Establish a plan of action to resolve the issue and identify potential effects

B.

Verify full system functionality and, if applicable, implement preventive measures

C.

Implement the solution or escalate as necessary

D.

Test the theory to determine the cause

Question 104

A network administrator is designing a new datacenter in a different region that will need to communicate to the old datacenter with a secure connection. Which of the following access methods would provide the BEST security for this new datacenter?

Options:

A.

Virtual network computing

B.

Secure Socket Shell

C.

In-band connection

D.

Site-to-site VPN

Question 105

An IT organization needs to optimize speeds for global content distribution and wants to reduce latency in high-density user locations. Which of the following technologies BEST meets the organization’s requirements?

Options:

A.

Load balancing

B.

Geofencing

C.

Public cloud

D.

Content delivery network

E.

Infrastructure as a service

Question 106

Which of the following factors should be considered when evaluating a firewall to protect a datacenter’s east-west traffic?

Options:

A.

Replication traffic between an on-premises server and a remote backup facility

B.

Traffic between VMs running on different hosts

C.

Concurrent connections generated by Internet DDoS attacks

D.

VPN traffic from remote offices to the datacenter’s VMs

Question 107

Which of the following TCP ports is used by the Windows OS for file sharing?

Options:

A.

53

B.

389

C.

445

D.

1433

Question 108

The network administrator is informed that a user’s email password is frequently hacked by brute-force programs. Which of the following policies should the network administrator implements to BEST mitigate this issue? (Choose two.)

Options:

A.

Captive portal

B.

Two-factor authentication

C.

Complex passwords

D.

Geofencing

E.

Role-based access

F.

Explicit deny

Question 109

An IT director is setting up new disaster and HA policies for a company. Limited downtime is critical to operations. To meet corporate requirements, the director set up two different datacenters across the country that will stay current on data and applications. In the event of an outage, the company can immediately switch from one datacenter to another. Which of the following does this BEST describe?

Options:

A.

A warm site

B.

Data mirroring

C.

Multipathing

D.

Load balancing

E.

A hot site

Question 110

Wireless users are reporting intermittent internet connectivity. Connectivity is restored when the users disconnect and reconnect, utilizing the web authentication process each time. The network administrator can see the devices connected to the APs at all times. Which of the following steps will MOST likely determine the cause of the issue?

Options:

A.

Verify the session time-out configuration on the captive portal settings

B.

Check for encryption protocol mismatch on the client’s wireless settings

C.

Confirm that a valid passphrase is being used during the web authentication

D.

Investigate for a client’s disassociation caused by an evil twin AP

Question 111

A fiber link connecting two campus networks is broken. Which of the following tools should an engineer use to detect the exact break point of the fiber link?

Options:

A.

OTDR

B.

Tone generator

C.

Fusion splicer

D.

Cable tester

E.

PoE injector

Question 112

Which of the following would be BEST to use to detect a MAC spoofing attack?

Options:

A.

Internet Control Message Protocol

B.

Reverse Address Resolution Protocol

C.

Dynamic Host Configuration Protocol

D.

Internet Message Access Protocol

Question 113

Branch users are experiencing issues with videoconferencing. Which of the following will the company MOST likely configure to improve performance for these applications?

Options:

A.

Link Aggregation Control Protocol

B.

Dynamic routing

C.

Quality of service

D.

Network load balancer

E.

Static IP addresses

Question 114

A company built a new building at its headquarters location. The new building is connected to the company’s LAN via fiber-optic cable. Multiple users in the new building are unable to access the company’s intranet site via their web browser, but they are able to access internet sites. Which of the following describes how the network administrator can resolve this issue?

Options:

A.

Correct the DNS server entries in the DHCP scope

B.

Correct the external firewall gateway address

C.

Correct the NTP server settings on the clients

D.

Correct a TFTP Issue on the company’s server

Question 115

A network administrator is installing a wireless network at a client’s office. Which of the following IEEE 802.11 standards would be BEST to use for multiple simultaneous client access?

Options:

A.

CDMA

B.

CSMA/CD

C.

CSMA/CA

D.

GSM

Question 116

A network technician needs to ensure outside users are unable to telnet into any of the servers at the datacenter. Which of the following ports should be blocked when checking firewall configuration?

Options:

A.

22

B.

23

C.

80

D.

3389

E.

8080

Question 117

Which of the following provides redundancy on a file server to ensure the server is still connected to a LAN even in the event of a port failure on a switch?

Options:

A.

NIC teaming

B.

Load balancer

C.

RAID array

D.

PDUs

Question 118

A network administrator discovers that users in an adjacent building are connecting to the company’s guest wireless network to download inappropriate material. Which of the following can the administrator do to MOST easily mitigate this issue?

Options:

A.

Reduce the wireless power levels

B.

Adjust the wireless channels

C.

Enable wireless client isolation

D.

Enable wireless port security

Question 119

After the A record of a public website was updated, some visitors were unable to access the website. Which of the following should be adjusted to address the issue?

Options:

A.

TTL

B.

MX

C.

TXT

D.

SOA

Question 120

A technician is searching for a device that is connected to the network and has the device’s physical network address. Which of the following should the technician review on the switch to locate the device’s network port?

Options:

A.

IP route table

B.

VLAN tag

C.

MAC table

D.

QoS tag

Question 121

Which of the following would need to be configured to ensure a device with a specific MAC address is always assigned the same IP address from DHCP?

Options:

A.

Scope options

B.

Reservation

C.

Dynamic assignment

D.

Exclusion

E.

Static assignment

Question 122

A network device is configured to send critical events to a syslog server; however, the following alerts are not being received:

Severity 5 LINK-UPDOWN: Interface 1/1, changed state to down

Severity 5 LINK-UPDOWN: Interface 1/3, changed state to down

Which of the following describes the reason why the events are not being received?

Options:

A.

The network device is not configured to log that level to the syslog server

B.

The network device was down and could not send the event

C.

The syslog server is not compatible with the network device

D.

The syslog server did not have the correct MIB loaded to receive the message

Question 123

Which of the following transceiver types can support up to 40Gbps?

Options:

A.

SFP+

B.

QSFP+

C.

QSFP

D.

SFP

Question 124

Which of the following BEST describes a network appliance that warns of unapproved devices that are accessing the network?

Options:

A.

Firewall

B.

AP

C.

Proxy server

D.

IDS

Question 125

A technician is connecting multiple switches to create a large network for a new office. The switches are unmanaged Layer 2 switches with multiple connections between each pair. The network is experiencing an extreme amount of latency. Which of the following is MOST likely occurring?

Options:

A.

Ethernet collisions

B.

A DDoS attack

C.

A broadcast storm

D.

Routing loops

Question 126

A network technician is manually configuring the network settings for a new device and is told the network block is 192.168.0.0/20. Which of the following subnets should the technician use?

Options:

A.

255.255.128.0

B.

255.255.192.0

C.

255.255.240.0

D.

255.255.248.0

Question 127

A network engineer is investigating reports of poor network performance. Upon reviewing a report, the engineer finds that jitter at the office is greater than 10ms on the only WAN connection available. Which of the following would be MOST affected by this statistic?

Options:

A.

A VoIP sales call with a customer

B.

An in-office video call with a coworker

C.

Routing table from the ISP

D.

Firewall CPU processing time

Question 128

A network is experiencing a number of CRC errors during normal network communication. At which of the following layers of the OSI model will the administrator MOST likely start to troubleshoot?

Options:

A.

Layer 1

B.

Layer 2

C.

Layer 3

D.

Layer 4

E.

Layer 5

F.

Layer 6

G.

Layer 7

Question 129

The following configuration is applied to a DHCP server connected to a VPN concentrator:

There are 300 non-concurrent sales representatives who log in for one hour a day to upload reports, and 252 of these representatives are able to connect to the VPN without any Issues. The remaining sales representatives cannot connect to the VPN over the course of the day. Which of the following can be done to resolve the issue without utilizing additional resources?

Options:

A.

Decrease the lease duration

B.

Reboot the DHCP server

C.

Install a new VPN concentrator

D.

Configure a new router

Question 130

SIMULATION

You have been tasked with setting up a wireless network in an office. The network will consist of 3 Access Points and a single switch. The network must meet the following parameters:

The SSIDs need to be configured as CorpNet with a key of S3cr3t!

The wireless signals should not interfere with each other

The subnet the Access Points and switch are on should only support 30 devices maximum

The Access Points should be configured to only support TKIP clients at a maximum speed

INSTRUCTONS

Click on the wireless devices and review their information and adjust the settings of the access points to meet the given requirements.

If at any time you would like to bring back the initial state of the simulation, please click the Reset All button.

Options:

Question 131

The management team needs to ensure unnecessary modifications to the corporate network are not permitted and version control is maintained. Which of the following documents would BEST support this?

Options:

A.

An incident response plan

B.

A business continuity plan

C.

A change management policy

D.

An acceptable use policy

Question 132

A network engineer performs the following tasks to increase server bandwidth:

Connects two network cables from the server to a switch stack

Configure LACP on the switchports

Verifies the correct configurations on the switch interfaces

Which of the following needs to be configured on the server?

Options:

A.

Load balancing

B.

Multipathing

C.

NIC teaming

D.

Clustering

Question 133

A technician is configuring a network switch to be used in a publicly accessible location. Which of the following should the technician configure on the switch to prevent unintended connections?

Options:

A.

DHCP snooping

B.

Geofencing

C.

Port security

D.

Secure SNMP

Question 134

A technician is troubleshooting a wireless connectivity issue in a small office located in a high-rise building. Several APs are mounted in this office. The users report that the network connections frequently disconnect and reconnect throughout the day. Which of the following is the MOST likely cause of this issue?

Options:

A.

The AP association time is set too low

B.

EIRP needs to be boosted

C.

Channel overlap is occurring

D.

The RSSI is misreported

Question 135

Client devices cannot enter a network, and the network administrator determines the DHCP scope is exhausted. The administrator wants to avoid creating a new DHCP pool. Which of the following can the administrator perform to resolve the issue?

Options:

A.

Install load balancers

B.

Install more switches

C.

Decrease the number of VLANs

D.

Reduce the lease time

Question 136

A systems administrator needs to improve WiFi performance in a densely populated office tower and use the latest standard. There is a mix of devices that use 2.4 GHz and 5 GHz. Which of the following should the systems administrator select to meet this requirement?

Options:

A.

802.11ac

B.

802.11ax

C.

802.11g

D.

802.11n

Question 137

A network administrator redesigned the positioning of the APs to create adjacent areas of wireless coverage. After project validation, some users still report poor connectivity when their devices maintain an association to a distanced AP. Which of the following should the network administrator check FIRST?

Options:

A.

Validate the roaming settings on the APs and WLAN clients

B.

Verify that the AP antenna type is correct for the new layout

C.

Check to see if MU-MIMO was properly activated on the APs

D.

Deactivate the 2.4GHz band on the APS

Question 138

Which of the following can be used to centrally manage credentials for various types of administrative privileges on configured network devices?

Options:

A.

SSO

B.

TACACS+

C.

Zero Trust

D.

Separation of duties

E.

Multifactor authentication

Question 139

Which of the following is MOST likely to generate significant East-West traffic in a datacenter?

Options:

A.

A backup of a large video presentation to cloud storage for archival purposes

B.

A duplication of a hosted virtual server to another physical server for redundancy

C.

A download of navigation data to a portable device for offline access

D.

A query from an IoT device to a cloud-hosted server for a firmware update

Question 140

A technician wants to deploy a new wireless network that comprises 30 WAPs installed throughout a three-story office building. All the APs will broadcast the same SSID for client access. Which of the following BEST describes this deployment?

Options:

A.

Extended service set

B.

Basic service set

C.

Unified service set

D.

Independent basic service set

Question 141

A branch of a company recently switched to a new ISP. The network engineer was given a new IP range to assign. The ISP assigned 196.26.4.0/26, and the branch gateway router now has the following configurations on the interface that peers to the ISP:

The network engineer observes that all users have lost Internet connectivity. Which of the following describes the issue?

Options:

A.

The incorrect subnet mask was configured

B.

The incorrect gateway was configured

C.

The incorrect IP address was configured

D.

The incorrect interface was configured

Question 142

Several WIFI users are reporting the inability to connect to the network. WLAN users on the guest network are able to access all network resources without any performance issues. The following table summarizes the findings after a site survey of the area in question:

Which of the following should a wireless technician do NEXT to troubleshoot this issue?

Options:

A.

Reconfigure the channels to reduce overlap

B.

Replace the omni antennas with directional antennas

C.

Update the SSIDs on all the APs

D.

Decrease power in AP 3 and AP 4

Question 143

An attacker is attempting to find the password to a network by inputting common words and phrases in plaintext to the password prompt. Which of the following attack types BEST describes this action?

Options:

A.

Pass-the-hash attack

B.

Rainbow table attack

C.

Brute-force attack

D.

Dictionary attack

Question 144

Which of the following ports is commonly used by VoIP phones?

Options:

A.

20

B.

143

C.

445

D.

5060

Question 145

Which of the following DNS records works as an alias to another record?

Options:

A.

AAAA

B.

CNAME

C.

MX

D.

SOA

Question 146

Access to a datacenter should be individually recorded by a card reader even when multiple employees enter the facility at the same time. Which of the following allows the enforcement of this policy?

Options:

A.

Motion detection

B.

Access control vestibules

C.

Smart lockers

D.

Cameras

Question 147

A network administrator walks into a datacenter and notices an unknown person is following closely. The administrator stops and directs the person to the security desk. Which of the following attacks did the network administrator prevent?

Options:

A.

Evil twin

B.

Tailgating

C.

Piggybacking

D.

Shoulder surfing

Question 148

An engineer is configuring redundant network links between switches. Which of the following should the engineer enable to prevent network stability issues?

Options:

A.

802.1Q

B.

STP

C.

Flow control

D.

CSMA/CD

Question 149

Which of the following systems would MOST likely be found in a screened subnet?

Options:

A.

RADIUS

B.

FTP

C.

SQL

D.

LDAP

Question 150

Which of the following is the LARGEST MTU for a standard Ethernet frame?

Options:

A.

1452

B.

1492

C.

1500

D.

2304

Question 151

An engineer notices some late collisions on a half-duplex link. The engineer verifies that the devices on both ends of the connection are configured for half duplex. Which of the following is the MOST likely cause of this issue?

Options:

A.

The link is improperly terminated

B.

One of the devices is misconfigured

C.

The cable length is excessive

D.

One of the devices has a hardware issue

Question 152

At which of the following OSI model layers would a technician find an IP header?

Options:

A.

Layer 1

B.

Layer 2

C.

Layer 3

D.

Layer 4

Question 153

A network engineer configured new firewalls with the correct configuration to be deployed to each remote branch. Unneeded services were disabled, and all firewall rules were applied successfully. Which of the following should the network engineer perform NEXT to ensure all the firewalls are hardened successfully?

Options:

A.

Ensure an implicit permit rule is enabled

B.

Configure the log settings on the firewalls to the central syslog server

C.

Update the firewalls with current firmware and software

D.

Use the same complex passwords on all firewalls

Question 154

Which of the following would MOST likely be used to review previous upgrades to a system?

Options:

A.

Business continuity plan

B.

Change management

C.

System life cycle

D.

Standard operating procedures

Question 155

A technician needs to configure a Linux computer for network monitoring. The technician has the following information:

Linux computer details:

Switch mirror port details:

After connecting the Linux computer to the mirror port on the switch, which of the following commands should the technician run on the Linux computer?

Options:

A.

ifconfig ecth0 promisc

B.

ifconfig eth1 up

C.

ifconfig eth0 10.1.2.3

D.

ifconfig eth1 hw ether A1:B2:C3:D4:E5:F6

Question 156

A store owner would like to have secure wireless access available for both business equipment and patron use. Which of the following features should be configured to allow different wireless access through the same equipment?

Options:

A.

MIMO

B.

TKIP

C.

LTE

D.

SSID

Question 157

A new cabling certification is being requested every time a network technician rebuilds one end of a Cat 6 (vendor-certified) cable to create a crossover connection that is used to connect switches. Which of the following would address this issue by allowing the use of the original cable?

Options:

A.

CSMA/CD

B.

LACP

C.

PoE+

D.

MDIX

Question 158

A client recently added 100 users who are using VMs. All users have since reported slow or unresponsive desktops. Reports show minimal network congestion, zero packet loss, and acceptable packet delay. Which of the following metrics will MOST accurately show the underlying performance issues? (Choose two.)

Options:

A.

CPU usage

B.

Memory

C.

Temperature

D.

Bandwidth

E.

Latency

F.

Jitter

Question 159

Which of the following is the physical topology for an Ethernet LAN?

Options:

A.

Bus

B.

Ring

C.

Mesh

D.

Star

Question 160

Which of the following types of devices can provide content filtering and threat protection, and manage multiple IPSec site-to-site connections?

Options:

A.

Layer 3 switch

B.

VPN headend

C.

Next-generation firewall

D.

Proxy server

E.

Intrusion prevention

Question 161

A technician is assisting a user who cannot connect to a network resource. The technician first checks for a link light. According to troubleshooting methodology, this is an example of:

Options:

A.

using a bottom-to-top approach.

B.

establishing a plan of action.

C.

documenting a finding.

D.

questioning the obvious.

Question 162

A website administrator is concerned the company’s static website could be defaced by hacktivists or used as a pivot point to attack internal systems. Which of the following should a network security administrator recommend to assist with detecting these activities?

Options:

A.

Implement file integrity monitoring.

B.

Change the default credentials.

C.

Use SSL encryption.

D.

Update the web-server software.

Question 163

Which of the following connector types would have the MOST flexibility?

Options:

A.

SFP

B.

BNC

C.

LC

D.

RJ45

Question 164

A technician is deploying a new switch model and would like to add it to the existing network monitoring software. The technician wants to know what metrics can be gathered from a given switch. Which of the following should the technician utilize for the switch?

Options:

A.

MIB

B.

Trap

C.

Syslog

D.

Audit log

Question 165

A company hired a technician to find all the devices connected within a network. Which of the following software tools would BEST assist the technician in completing this task?

Options:

A.

IP scanner

B.

Terminal emulator

C.

NetFlow analyzer

D.

Port scanner

Question 166

A technician is installing a new fiber connection to a network device in a datacenter. The connection from the device to the switch also traverses a patch panel connection. The chain of connections is in the following order:

Device

LC/LC patch cable

Patch panel

Cross-connect fiber cable

Patch panel

LC/LC patch cable

Switch

The connection is not working. The technician has changed both patch cables with known working patch cables. The device had been tested and was working properly before being installed. Which of the following is the MOST likely cause of the issue?

Options:

A.

TX/RX is reversed

B.

An incorrect cable was used

C.

The device failed during installation

D.

Attenuation is occurring

Question 167

A workstation is configured with the following network details:

Software on the workstation needs to send a query to the local subnet broadcast address. To which of the following addresses should the software be configured to send the query?

Options:

A.

10.1.2.0

B.

10.1.2.1

C.

10.1.2.23

D.

10.1.2.255

E.

10.1.2.31

Question 168

Within the realm of network security, Zero Trust:

Options:

A.

prevents attackers from moving laterally through a system.

B.

allows a server to communicate with outside networks without a firewall.

C.

block malicious software that is too new to be found in virus definitions.

D.

stops infected files from being downloaded via websites.

Question 169

A technician is writing documentation regarding a company’s server farm. The technician needs to confirm the server name for all Linux servers. Which of the following commands should the technician run?

Options:

A.

ipconfig

B.

nslookup

C.

arp

D.

route

Question 170

A technician receives feedback that some users are experiencing high amounts of jitter while using the wireless network. While troubleshooting the network, the technician uses the ping command with the IP address of the default gateway and verifies large variations in latency. The technician thinks the issue may be interference from other networks and non-802.11 devices. Which of the following tools should the technician use to troubleshoot the issue?

Options:

A.

NetFlow analyzer

B.

Bandwidth analyzer

C.

Protocol analyzer

D.

Spectrum analyzer

Question 171

A lab environment hosts Internet-facing web servers and other experimental machines, which technicians use for various tasks A technician installs software on one of the web servers to allow communication to the company's file server, but it is unable to connect to it Other machines in the building are able to retrieve files from the file server. Which of the following is the MOST likely reason the web server cannot retrieve the files, and what should be done to resolve the problem?

Options:

A.

The lab environment's IDS is blocking the network traffic 1 he technician can whitelist the new application in the IDS

B.

The lab environment is located in the DM2, and traffic to the LAN zone is denied by default. The technician can move the computer to another zone or request an exception from the administrator.

C.

The lab environment has lost connectivity to the company router, and the switch needs to be rebooted. The technician can get the key to the wiring closet and manually restart the switch

D.

The lab environment is currently set up with hubs instead of switches, and the requests are getting bounced back The technician can submit a request for upgraded equipment to management.

Question 172

Which of the following attacks encrypts user data and requires a proper backup implementation to recover?

Options:

A.

DDoS

B.

Phishing

C.

Ransomware

D.

MAC spoofing

Question 173

A network technician is configuring a new firewall for a company with the necessary access requirements to be allowed through the firewall. Which of the following would normally be applied as the LAST rule in the firewall?

Options:

A.

Secure SNMP

B.

Port security

C.

Implicit deny

D.

DHCP snooping

Question 174

Which of the following security devices would be BEST to use to provide mechanical access control to the MDF/IDF?

Options:

A.

A smart card

B.

A key fob

C.

An employee badge

D.

A door lock

Question 175

Which of the following policies is MOST commonly used for guest captive portals?

Options:

A.

AUP

B.

DLP

C.

BYOD

D.

NDA

Question 176

Which of the following is a system that is installed directly on a server's hardware and abstracts the hardware from any guest machines?

Options:

A.

Storage array

B.

Type 1 hypervisor

C.

Virtual machine

D.

Guest QS

Question 177

A business is using the local cable company to provide Internet access. Which of the following types of cabling will the cable company MOST likely use from the demarcation point back to the central office?

Options:

A.

Multimode

B.

Cat 5e

C.

RG-6

D.

Cat 6

E.

100BASE-T

Question 178

A network technician is investigating an issue with a desktop that is not connecting to the network. The desktop was connecting successfully the previous day, and no changes were made to the environment. The technician locates the switchport where the device is connected and observes the LED status light on the switchport is not lit even though the desktop is turned on Other devices that arc plugged into the switch are connecting to the network successfully Which of the following is MOST likely the cause of the desktop not connecting?

Options:

A.

Transceiver mismatch

B.

VLAN mismatch

C.

Port security

D.

Damaged cable

E.

Duplex mismatch

Question 179

A user is having difficulty with video conferencing and is looking for assistance. Which of the following would BEST improve performance?

Options:

A.

Packet shaping

B.

Quality of service

C.

Port mirroring

D.

Load balancing

Question 180

A network administrator is setting up several loT devices on a new VLAN and wants to accomplish the following

1. Reduce manual configuration on each system

2. Assign a specific IP address to each system

3. Allow devices to move to different switchports on the same VLAN

Which of the following should the network administrator do to accomplish these requirements?

Options:

A.

Set up a reservation for each device

B.

Configure a static IP on each device

C.

Implement private VLANs for each device

D.

Use DHCP exclusions to address each device

Question 181

A technician is connecting DSL for a new customer. After installing and connecting the on-premises equipment, the technician verifies DSL synchronization. When connecting to a workstation, however, the link LEDs on the workstation and modem do not light up. Which of the following should the technician perform during troubleshooting?

Options:

A.

Identify the switching loops between the modem and the workstation.

B.

Check for asymmetrical routing on the modem.

C.

Look for a rogue DHCP server on the network.

D.

Replace the cable connecting the modem and the workstation.

Question 182

A wireless network was installed in a warehouse for employees to scan crates with a wireless handheld scanner. The wireless network was placed in the corner of the building near the ceiling for maximum coverage However users in the offices adjacent lo the warehouse have noticed a large amount of signal overlap from the new network Additionally warehouse employees report difficulty connecting to the wireless network from the other side of the building; however they have no issues when Ihey are near the antenna Which of the following is MOST likely the cause?

Options:

A.

The wireless signal is being refracted by the warehouse's windows

B.

The antenna's power level was set too high and is overlapping

C.

An omnidirectional antenna was used instead of a unidirectional antenna

D.

The wireless access points are using channels from the 5GHz spectrum

Question 183

Which of the following is used to provide networking capability for VMs at Layer 2 of the OSI model?

Options:

A.

VPN

B.

VRRP

C.

vSwitch

D.

VIP

Question 184

A network field technician is installing and configuring a secure wireless network. The technician performs a site survey. Which of the following documents would MOST likely be created as a result of the site survey?

Options:

A.

Physical diagram

B.

Heat map

C.

Asset list

D.

Device map

Question 185

Which of the following would be used to expedite MX record updates to authoritative NSs?

Options:

A.

UDP forwarding

B.

DNS caching

C.

Recursive lookup

D.

Time to live

Question 186

Which of the following protocols will a security appliance that is correlating network events from multiple devices MOST likely rely on to receive event messages?

Options:

A.

Syslog

B.

Session Initiation Protocol

C.

Secure File Transfer Protocol

D.

Server Message Block

Question 187

A network administrator is configuring a database server and would like to ensure the database engine is listening on a certain port. Which of the following commands should the administrator use to accomplish this goal?

Options:

A.

nslookup

B.

netstat -a

C.

ipconfig /a

D.

arp -a

Question 188

A network administrator has been directed to present the network alerts from the past week to the company's executive staff. Which of the following will provide the BEST collection and presentation of this data?

Options:

A.

A port scan printout

B.

A consolidated report of various network devices

C.

A report from the SIEM tool

D.

A report from a vulnerability scan done yesterday

Question 189

Which of the following services can provide data storage, hardware options, and scalability to a third-party company that cannot afford new devices?

Options:

A.

SaaS

B.

IaaS

C.

PaaS

D.

DaaS

Question 190

An ARP request is broadcasted and sends the following request.

''Who is 192.168.1.200? Tell 192.168.1.55''

At which of the following layers of the OSI model does this request operate?

Options:

A.

Application

B.

Data link

C.

Transport

D.

Network

E.

Session

Question 191

A user recently made changes to a PC that caused it to be unable to access websites by both FQDN and IP Local resources, such as the file server remain accessible. Which of the following settings did the user MOST likely misconfigure?

Options:

A.

Static IP

B.

Default gateway

C.

DNS entries

D.

Local host file

Question 192

A company wants to implement a large number of WAPs throughout its building and allow users to be able to move around the building without dropping their connections Which of the following pieces of equipment would be able to handle this requirement?

Options:

A.

A VPN concentrator

B.

A load balancer

C.

A wireless controller

D.

A RADIUS server

Question 193

A network technician is reviewing an upcoming project's requirements to implement laaS. Which of the following should the technician consider?

Options:

A.

Software installation processes

B.

Type of database to be installed

C.

Operating system maintenance

D.

Server hardware requirements

Question 194

Given the following output:

Which of the following attacks is this MOST likely an example of?

Options:

A.

ARP poisoning

B.

VLAN hopping

C.

Rogue access point

D.

Amplified DoS

Question 195

A network technician has multimode fiber optic cable available in an existing IDF. Which of the following Ethernet standards should the technician use to connect the network switch to the existing fiber?

Options:

A.

10GBaseT

B.

1000BaseT

C.

1000BaseSX

D.

1000BaseLX

Question 196

Which of the following protocol types describes secure communication on port 443?

Options:

A.

ICMP

B.

UDP

C.

TCP

D.

IP

Question 197

There are two managed legacy switches running that cannot be replaced or upgraded. These switches do not support cryptographic functions, but they are password protected. Which of the following should a network administrator configure to BEST prevent unauthorized access?

Options:

A.

Enable a management access list

B.

Disable access to unnecessary services.

C.

Configure a stronger password for access

D.

Disable access to remote management

E.

Use an out-of-band access method.

Question 198

A network administrator is downloading a large patch that will be uploaded to several enterprise switches simultaneously during the day's upgrade cycle. Which of the following should the administrator do to help ensure the upgrade process will be less likely to cause problems with the switches?

Options:

A.

Confirm the patch's MD5 hash prior to the upgrade

B.

Schedule the switches to reboot after an appropriate amount of time.

C.

Download each switch's current configuration before the upgrade

D.

Utilize FTP rather than TFTP to upload the patch

Question 199

A network technician was troubleshooting an issue for a user who was being directed to cloned websites that were stealing credentials. The URLs were correct for the websites but an incorrect IP address was revealed when the technician used ping on the user's PC After checking the is setting, the technician found the DNS server address was incorrect Which of the following describes the issue?

Options:

A.

Rogue DHCP server

B.

Misconfigured HSRP

C.

DNS poisoning

D.

Exhausted IP scope

Question 200

A technician is deploying a low-density wireless network and is contending with multiple types of building materials. Which of the following wireless frequencies would allow for the LEAST signal attenuation?

Options:

A.

2.4GHz

B.

5GHz

C.

850MHz

D.

900MHZ

Question 201

A technician is troubleshooting a workstation's network connectivity and wants to confirm which switchport corresponds to the wall jack the PC is using Which of the following concepts would BEST help the technician?

Options:

A.

Consistent labeling

B.

Change management

C.

Standard work instructions

D.

Inventory management

E.

Network baseline

Question 202

A company is being acquired by a large corporation. As part of the acquisition process, the company's address should now redirect clients to the corporate organization page. Which of the following DNS records needs to be created?

Options:

A.

SOA

B.

NS

C.

CNAME

D.

TXT

Question 203

A technician wants to install a WAP in the center of a room that provides service in a radius surrounding a radio. Which of the following antenna types should the AP utilize?

Options:

A.

Omni

B.

Directional

C.

Yagi

D.

Parabolic

Question 204

Which of the following OSI model layers is where conversations between applications are established, coordinated, and terminated?

Options:

A.

Session

B.

Physical

C.

Presentation

D.

Data link

Question 205

During the security audit of a financial firm the Chief Executive Officer (CEO) questions why there are three employees who perform very distinct functions on the server. There is an administrator for creating users another for assigning the users lo groups and a third who is the only administrator to perform file rights assignment Which of the following mitigation techniques is being applied'

Options:

A.

Privileged user accounts

B.

Role separation

C.

Container administration

D.

Job rotation

Question 206

Two remote offices need to be connected securely over an untrustworthy MAN. Each office needs to access network shares at the other site. Which of the following will BEST provide this functionality?

Options:

A.

Client-to-site VPN

B.

Third-party VPN service

C.

Site-to-site VPN

D.

Split-tunnel VPN

Question 207

A network administrator is reviewing interface errors on a switch. Which of the following indicates that a switchport is receiving packets in excess of the configured MTU?

Options:

A.

CRC errors

B.

Giants

C.

Runts

D.

Flooding

Question 208

A small, family-run business uses a single SOHO router to provide Internet and WiFi to its employees At the start of a new week, employees come in and find their usual WiFi network is no longer available, and there is a new wireless network to which they cannot connect. Given that information, which of the following should have been done to avoid this situation'

Options:

A.

The device firmware should have been kept current.

B.

Unsecure protocols should have been disabled.

C.

Parental controls should have been enabled

D.

The default credentials should have been changed

Question 209

A network technician needs to correlate security events to analyze a suspected intrusion. Which of the following should the technician use?

Options:

A.

SNMP

B.

Log review

C.

Vulnerability scanning

D.

SIEM

Question 210

A Chief Information Officer (CIO) wants to improve the availability of a company's SQL database Which of the following technologies should be utilized to achieve maximum availability?

Options:

A.

Clustering

B.

Port aggregation

C.

NIC teaming

D.

Snapshots

Question 211

A network administrator decided to use SLAAC in an extensive IPv6 deployment to alleviate IP address management. The devices were properly connected into the LAN but autoconfiguration of the IP address did not occur as expected. Which of the following should the network administrator verify?

Options:

A.

The network gateway is configured to send router advertisements.

B.

A DHCP server is present on the same broadcast domain as the clients.

C.

The devices support dual stack on the network layer.

D.

The local gateway supports anycast routing.

Question 212

A network technician is installing an analog desk phone for a new receptionist After running a new phone line, the technician now needs to cnmp on a new connector. Which of the following connectors would MOST likely be used in this case?

Options:

A.

DB9

B.

RJ11

C.

RJ45

D.

DB25

Question 213

Which of the following uses the destination IP address to forward packets?

Options:

A.

A bridge

B.

A Layer 2 switch

C.

A router

D.

A repeater

Question 214

A firewall administrator is implementing a rule that directs HTTP traffic to an internal server listening on a non-standard socket Which of the following types of rules is the administrator implementing?

Options:

A.

NAT

B.

PAT

C.

STP

D.

SNAT

E.

ARP

Question 215

A network requirement calls for segmenting departments into different networks. The campus network is set up with users of each department in multiple buildings. Which of the following should be configured to keep the design simple and efficient?

Options:

A.

MDIX

B.

Jumbo frames

C.

Port tagging

D.

Flow control

Question 216

An IT technician suspects a break in one of the uplinks that provides connectivity to the core switch. Which of the following command-line tools should the technician use to determine where the incident is occurring?

Options:

A.

nslookup

B.

show config

C.

netstat

D.

show interface

E.

show counters

Question 217

A network technician is investigating an IP phone that does not register in the VoIP system Although it received an IP address, it did not receive the necessary DHCP options The information that is needed for the registration is distributes by the OHCP scope All other IP phones are working properly. Which of the following does the technician need to verify?

Options:

A.

VLAN mismatch

B.

Transceiver mismatch

C.

Latency

D.

DHCP exhaustion

Question 218

A network administrator is required to ensure that auditors have read-only access to the system logs, while systems administrators have read and write access to the system logs, and operators have no access to the system logs. The network administrator has configured security groups for each of these functional categories. Which of the following security capabilities will allow the network administrator to maintain these permissions with the LEAST administrative effort?

Options:

A.

Mandatory access control

B.

User-based permissions

C.

Role-based access

D.

Least privilege

Question 219

A network administrator wants to improve the security of the management console on the company's switches and ensure configuration changes made can be correlated to the administrator who conformed them Which of the following should the network administrator implement?

Options:

A.

Port security

B.

Local authentication

C.

TACACS+

D.

Access control list

Question 220

A technician is implementing a new wireless network to serve guests at a local office. The network needs to provide Internet access but disallow associated stations from communicating with each other. Which of the following would BEST accomplish this requirement?

Options:

A.

Wireless client isolation

B.

Port security

C.

Device geofencing

D.

DHCP snooping

Question 221

An IDS was installed behind the edge firewall after a network was breached. The network was then breached again even though the IDS logged the attack. Which of the following should be used in place of these devices to prevent future attacks?

Options:

A.

A network tap

B.

A proxy server

C.

A UTM appliance

D.

A content filter

Question 222

A network administrator wants to analyze attacks directed toward the company's network. Which of the following must the network administrator implement to assist in this goal?

Options:

A.

A honeypot

B.

Network segmentation

C.

Antivirus

D.

A screened subnet

Question 223

A technician is troubleshooting a previously encountered issue. Which of the following should the technician reference to find what solution was implemented to resolve the issue?

Options:

A.

Standard operating procedures

B.

Configuration baseline documents

C.

Work instructions

D.

Change management documentation

Question 224

A client moving into a new office wants the IP network set up to accommodate 412 network-connected devices that are all on the same subnet. The subnet needs to be as small as possible. Which of the following subnet masks should be used to achieve the required result?

Options:

A.

255.255.0.0

B.

255.255.252.0

C.

255.255.254.0

D.

255.255.255.0

Question 225

A company that uses VoIP telephones is experiencing intermittent issues with one-way audio and dropped conversations The manufacturer says the system will work if ping times are less than 50ms. The company has recorded the following ping times:

Which of the following is MOST likely causing the issue?

Options:

A.

Attenuation

B.

Latency

C.

VLAN mismatch

D.

Jitter

Question 226

A network administrator is talking to different vendors about acquiring technology to support a new project for a large company. Which of the following documents will MOST likely need to be signed before information about the project is shared?

Options:

A.

BYOD policy

B.

NDA

C.

SLA

D.

MOU

Question 227

A network administrator needs to implement an HDMI over IP solution. Which of the following will the network administrator MOST likely use to ensure smooth video delivery?

Options:

A.

Link aggregation control

B.

Port tagging

C.

Jumbo frames

D.

Media access control

Question 228

A company requires a disaster recovery site to have equipment ready to go in the event of a disaster at its main datacenter. The company does not have the budget to mirror all the live data to the disaster recovery site. Which of the following concepts should the company select?

Options:

A.

Cold site

B.

Hot site

C.

Warm site

D.

Cloud site

Question 229

Which of the following is MOST commonly used to address CVEs on network equipment and/or operating systems?

Options:

A.

Vulnerability assessment

B.

Factory reset

C.

Firmware update

D.

Screened subnet

Question 230

A user reports a weak signal when walking 20ft (61 m) away from the WAP in one direction, but a strong signal when walking 20ft in the opposite direction The technician has reviewed the configuration and confirmed the channel type is correct There is no jitter or latency on the connection Which of the following would be the MOST likely cause of the issue?

Options:

A.

Antenna type

B.

Power levels

C.

Frequency

D.

Encryption type

Question 231

A city has hired a new employee who needs to be able to work when traveling at home and at the municipal sourcing of a neighboring city that snares services. The employee is issued a laptop, and a technician needs to train the employee on the appropriate solutions for secure access to the network from all the possible locations On which of the following solutions would the technician MOST likely train the employee?

Options:

A.

Site-to-site VPNs between the two city locations and client-to-site software on the employee's laptop tor all other remote access

B.

Client-to-site VPNs between the travel locations and site-to-site software on the employee's laptop for all other remote access

C.

Client-to-site VPNs between the two city locations and site-to-site software on the employee's laptop for all other remote access

D.

Site-to-site VPNs between the home and city locations and site-to-site software on the employee's laptop for all other remote access

Question 232

Which of the following technologies allows traffic to be sent through two different ISPs to increase performance?

Options:

A.

Fault tolerance

B.

Quality of service

C.

Load balancing

D.

Port aggregation

Question 233

An organization with one core and five distribution switches is transitioning from a star to a full-mesh topology Which of the following is the number of additional network connections needed?

Options:

A.

5

B.

7

C.

10

D.

15

Question 234

A corporation has a critical system that would cause unrecoverable damage to the brand if it was taken offline. Which of the following disaster recovery solutions should the corporation implement?

Options:

A.

Full backups

B.

Load balancing

C.

Hot site

D.

Snapshots

Question 235

A local firm has hired a consulting company to clean up its IT infrastructure. The consulting company notices remote printing is accomplished by port forwarding via publicly accessible IPs through the firm's firewall Which of the following would be the MOST appropriate way to enable secure remote printing?

Options:

A.

SSH

B.

VPN

C.

Telnet

D.

SSL

Question 236

An organization wants to implement a method of centrally managing logins to network services. Which of the following protocols should the organization use to allow for authentication, authorization and auditing?

Options:

A.

MS-CHAP

B.

RADIUS

C.

LDAPS

D.

RSTP

Question 237

A customer wants to segregate the traffic between guests on a hypervisor. Which of the following does a technician need to configure to meet the requirement?

Options:

A.

Virtual switches

B.

OSPF routing

C.

Load balancers

D.

NIC teaming

E.

Fibre Channel

Question 238

A network technician is investigating an issue with handheld devices in a warehouse. Devices have not been connecting to the nearest APs, but they have been connecting to an AP on the far side of the warehouse. Which of the following is the MOST likely cause of this issue?

Options:

A.

The nearest APs are configured for 802.11g.

B.

An incorrect channel assignment is on the nearest APs.

C.

The power level is too high for the AP on the far side.

D.

Interference exists around the AP on the far side.

Question 239

A SaaS provider has decided to leave an unpatched VM available via a public DMZ port. With which of the following concepts is this technique MOST closely associated?

Options:

A.

Insider threat

B.

War driving

C.

Evil twin

D.

Honeypot

Question 240

A systems administrator is running a VoIP network and is experiencing jitter and high latency. Which of the following would BEST help the administrator determine the cause of these issues?

Options:

A.

Enabling RADIUS on the network

B.

Configuring SNMP traps on the network

C.

Implementing LDAP on the network

D.

Establishing NTP on the network

Question 241

The following instructions were published about the proper network configuration for a videoconferencing device:

"Configure a valid static RFC1918 address for your network. Check the option to use a connection over NAT."

Which of the following is a valid IP address configuration for the device?

Options:

A.

FE80::1

B.

100.64.0.1

C.

169.254.1.2

D.

172.19.0.2

E.

224.0.0.12

Question 242

A network engineer is designing a new secure wireless network. The engineer has been given the following requirements:

1 Must not use plaintext passwords

2 Must be certificate based

3. Must be vendor neutral

Which of the following methods should the engineer select?

Options:

A.

TWP-RC4

B.

CCMP-AES

C.

EAP-TLS

D.

WPA2

Question 243

A network technician is observing the behavior of an unmanaged switch when a new device is added to the network and transmits data. Which of the following BEST describes how the switch processes this information?

Options:

A.

The data is flooded out of every port. including the one on which it came in.

B.

The data is flooded out of every port but only in the VLAN where it is located.

C.

The data is flooded out of every port, except the one on which it came in

D.

The data is flooded out of every port, excluding the VLAN where it is located

Page: 1 / 61
Total 849 questions