Courseiva

CCNA Networking Questions

7 questions · Networking · All types, answers revealed

1
MCQhard

A company has a network with multiple VLANs. Users on VLAN 10 need to access a server on VLAN 20, but they cannot. The technician verifies that the switch ports are correctly assigned and the server is reachable from other VLANs. Which of the following is the MOST likely cause?

A.The router or Layer 3 switch is not configured to route between VLAN 10 and VLAN 20.
B.The default gateway on VLAN 10 is misconfigured.
C.The subnet mask on the server is incorrect.
D.The DNS server is not resolving the server's hostname for VLAN 10 clients.
AnswerA

Inter-VLAN routing must be explicitly configured on a router or Layer 3 switch. If routing between VLAN 10 and VLAN 20 is not enabled, traffic cannot pass between them. The fact that other VLANs can reach the server suggests that routing works for those VLANs but not for VLAN 10. This is the most likely cause.

Why this answer

Inter-VLAN routing requires explicit configuration on a Layer 3 device. If VLAN 10 cannot reach VLAN 20 while other VLANs can, the routing between those specific VLANs is likely missing or misconfigured. This is the most probable cause given the symptoms.

Other options would cause broader connectivity issues.

Exam trap

The trap here is assuming a DNS or server configuration issue when the problem is isolated to one VLAN's ability to reach another, which points to inter-VLAN routing or ACLs.

2
MCQmedium

A technician is configuring a small office wireless router for a client. The client wants the network to be as secure as possible while still allowing employees to connect easily with a pre-shared key. The router supports WPA2, WPA3, WPA, and WEP. Which security protocol should the technician select?

A.WPA2-PSK with AES
B.WPA-PSK with TKIP
C.WPA3-Personal
D.WEP with 128-bit key
AnswerC

WPA3-Personal is the most secure option among those listed and is supported by the router. It uses SAE (Simultaneous Authentication of Equals) to provide forward secrecy and resistance to offline dictionary attacks, which WPA2-PSK lacks. It still allows easy connection with a pre-shared key, satisfying the client's requirement. Therefore, it is the best choice.

Why this answer

WPA3-Personal provides the strongest security among the listed protocols by using SAE, which enhances protection against offline dictionary attacks and adds forward secrecy. It still supports a pre-shared key for easy employee connectivity. WPA2 is secure but less robust, while WPA and WEP are deprecated and vulnerable.

Thus, WPA3-Personal is the correct choice for maximum security with a pre-shared key.

Exam trap

The trap here is assuming that WPA2 is always the most secure option, overlooking that WPA3 is now widely supported and offers significant security improvements.

3
MCQmedium

A small business wants to add a guest wireless network that allows visitors to access the internet but prevents them from reaching internal company resources. The existing network uses a single wireless router with a default configuration. Which of the following should a technician implement?

A.Change the default SSID and disable SSID broadcast to hide the guest network.
B.Set up MAC filtering to allow only known guest devices on the wireless network.
C.Configure a separate guest SSID and enable client isolation or a guest VLAN on the wireless router.
D.Enable WPA3-Personal on the guest SSID and place it on the same VLAN as the corporate network.
AnswerC

Creating a separate guest SSID with client isolation or a dedicated guest VLAN prevents guests from accessing internal company resources while still providing internet access. This is the standard method for guest network segmentation on a small business router. It meets both security and connectivity requirements without additional hardware.

Why this answer

A separate guest SSID with client isolation or a guest VLAN isolates guest traffic from the internal network, preventing access to company resources while allowing internet access. This is the most effective and standard solution for the scenario. Other options either do not provide isolation or only add superficial security.

Exam trap

The trap here is assuming that encryption or hiding the SSID provides isolation, when in fact only network segmentation (guest VLAN or client isolation) prevents access to internal resources.

4
MCQeasy

A user reports that their workstation cannot connect to any network resources. The technician notices the network cable is plugged into the wall jack and the NIC, but the link light is off. Which of the following should the technician check FIRST?

A.The IP address configuration on the workstation.
B.The firewall rules on the workstation.
C.The DNS server settings in the operating system.
D.The patch cable and wall jack for physical damage or loose connection.
AnswerD

The link light being off indicates a physical layer issue. The first step is to verify the cable is securely connected and undamaged, and that the wall jack is active. This is the most likely cause and the quickest to check. Reseating or replacing the cable often resolves the problem.

Why this answer

The link light off indicates a physical layer problem. The first step is always to check the physical connection: cable, wall jack, and NIC port. This is the most efficient troubleshooting step and aligns with the bottom-up troubleshooting methodology.

Other options are higher-layer issues that would not cause the link light to be off.

Exam trap

The trap here is jumping to logical configuration issues like IP or DNS when the physical link light is off, which clearly points to a Layer 1 problem.

5
MCQeasy

A user reports that they cannot access any websites by typing domain names, but they can access websites by entering IP addresses directly. The technician suspects a DNS issue. Which command should the technician use first to verify the DNS server settings on the user's Windows 10 computer?

A.ipconfig /all
B.ping
C.netstat -an
D.nslookup
AnswerA

ipconfig /all displays the full TCP/IP configuration for all adapters, including the DNS servers that are configured. This allows the technician to verify whether the correct DNS server addresses are assigned via DHCP or manually. Since the user can access sites by IP but not by name, checking DNS settings is the logical first step, making this command appropriate.

Why this answer

The ipconfig /all command shows the complete IP configuration, including DNS server addresses, which are essential to verify when name resolution fails. Since the user can reach sites by IP, the problem likely lies with DNS settings or the DNS server itself. Checking the configured DNS servers is the first step before testing resolution with tools like nslookup or ping.

Exam trap

The trap here is choosing nslookup because it directly relates to DNS, but the question asks to verify DNS server settings, which ipconfig /all provides.

6
Multi-Selectmedium

A technician is configuring a wireless access point for a small office. The office needs to support both older laptops that only support 2.4 GHz and newer devices that support 5 GHz. The technician wants to ensure optimal performance and compatibility. Which two of the following should the technician configure? (Choose two.)

Select 2 answers
A.Disable SSID broadcast on both bands to improve security.
B.Set the 2.4 GHz band to use channel 1, 6, or 11.
C.Set the access point to use WEP encryption for backward compatibility.
D.Configure the 5 GHz band to use channel 36 at 80 MHz width.
E.Enable both 2.4 GHz and 5 GHz bands on the access point.
AnswersB, E

In the 2.4 GHz spectrum, channels 1, 6, and 11 are the only non-overlapping channels. Using one of these minimizes interference from neighboring networks. This is a best practice for 2.4 GHz Wi-Fi deployment. It ensures stable performance for older devices.

Why this answer

Enabling both 2.4 GHz and 5 GHz bands ensures compatibility with older and newer devices. Setting the 2.4 GHz band to channel 1, 6, or 11 minimizes interference. These two steps provide the best balance of compatibility and performance for a mixed-device office.

Other options either reduce security or are not required.

Exam trap

The trap here is thinking that wider channels or disabling SSID broadcast are necessary for performance, when in fact they can cause problems; the key is dual-band support and non-overlapping 2.4 GHz channels.

7
MCQmedium

A technician is troubleshooting a workstation that can access local network resources but cannot reach any websites on the internet. The technician runs ipconfig and sees the IP address, subnet mask, and default gateway are correct. Which of the following should the technician check NEXT?

A.The physical cable connection to the wall jack.
B.The DHCP lease expiration time.
C.The DNS server settings.
D.The MAC address of the NIC.
AnswerC

If the workstation can reach local resources but not internet websites, the issue is likely name resolution. The IP configuration is correct, so the next step is to verify DNS server settings. Incorrect DNS would prevent resolving domain names to IP addresses, causing web access to fail while local resources (accessed by IP or local name) still work.

Why this answer

When local resources are accessible but internet websites are not, and IP configuration is correct, the most likely cause is DNS resolution failure. The technician should verify the DNS server settings. Other options are either irrelevant or would cause broader connectivity loss.

Exam trap

The trap here is assuming a physical or IP configuration problem when the symptom of local access but no internet access strongly points to DNS or default gateway issues; since the gateway is correct, DNS is the next logical check.

Ready to test yourself?

Try a timed practice session using only Networking questions.