N10-009 Network Operations Practice Question
A network administrator receives an automated alert from the network monitoring system indicating that the bandwidth utilization on a specific switch port has exceeded the threshold for the past 10 minutes. According to best practices for network operations, what should the administrator do FIRST?
⚠ Common exam trap
The trap here is that candidates panic and choose 'immediately block the port' (Option A) thinking it's a proactive security measure, but CompTIA Network+ emphasizes that network operations require analysis before action to avoid disrupting legitimate traffic.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Check the monitoring system logs to identify the traffic source and destination.
The first step in responding to a bandwidth utilization alert is to investigate the traffic causing the spike. Checking the monitoring system logs allows the administrator to identify the source and destination of the traffic, which is essential for determining whether the utilization is legitimate (e.g., a backup or large file transfer) or malicious (e.g., a DoS attack). This aligns with the network operations best practice of 'verify before acting' to avoid unnecessary disruptions.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Immediately block the port to prevent potential network congestion from affecting other users.
Why it's wrong here
Immediately blocking a port is an overly aggressive response that carries a significant risk of disrupting legitimate, potentially business-critical traffic. While it might prevent congestion, it does so by potentially isolating a user or device that is performing a necessary function, leading to productivity loss. This action should only be taken if there is clear, confirmed evidence of malicious activity or an uncontrolled network event like a broadcast storm, and even then, it must be a carefully considered step, not an initial reflex. Investigation is paramount to distinguish legitimate high usage from problematic traffic.
When this WOULD be correct
This would be correct if the question stated that the port is experiencing a confirmed security incident, such as a DDoS attack or malware propagation, and immediate isolation is required to protect the network.
- ✓
Check the monitoring system logs to identify the traffic source and destination.
Why this is correct
This is the correct initial diagnostic step. An alert indicates a symptom (high utilization), but not the cause. Logs, such as NetFlow, sFlow, SNMP data, or firewall logs, will reveal which specific devices, applications, or protocols are generating the traffic, their destinations, and the volume. This crucial information allows for targeted troubleshooting or policy adjustments, preventing blind actions and ensuring legitimate traffic isn't disrupted by premature interventions.
- ✗
Reboot the switch to clear any temporary errors that might be causing the alert.
Why it's wrong here
Rebooting a network switch is a drastic measure that will cause a complete outage for all connected devices, immediately disrupting legitimate network services and user productivity. While it might clear some transient software glitches, a bandwidth threshold alert typically indicates sustained traffic, not a temporary error that a simple reboot would resolve. This aggressive action should only be considered as a last resort after extensive diagnostics have failed and the potential impact has been thoroughly assessed.
When this WOULD be correct
If the question described symptoms of a switch malfunction, such as unresponsive management interface, random packet loss, or error counters indicating hardware issues, then rebooting the switch could be an appropriate first troubleshooting step.
- ✗
Increase the bandwidth on the port to accommodate the higher traffic load.
Why it's wrong here
Simply increasing bandwidth without first understanding the root cause of the high utilization is a reactive and potentially wasteful solution. The elevated traffic could be due to a misconfigured application, a broadcast storm, a denial-of-service attack, or an unapproved large file transfer, not necessarily a legitimate need for more capacity. Without proper investigation, you risk masking a deeper problem, incurring unnecessary costs, or simply delaying a more significant issue that requires a different type of intervention.
When this WOULD be correct
When the question states that the port is a critical link for a time-sensitive application and the threshold is set too low for normal operations, and the administrator has already verified that the traffic is legitimate.
Option-by-option analysis
Why each answer is right or wrong
Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The N10-009 exam frequently reuses these exact scenarios with slightly different constraints.
✓Check the monitoring system logs to identify the traffic source and destination.Correct answer▾
Why this is correct
This is the correct initial diagnostic step. An alert indicates a symptom (high utilization), but not the cause. Logs, such as NetFlow, sFlow, SNMP data, or firewall logs, will reveal which specific devices, applications, or protocols are generating the traffic, their destinations, and the volume. This crucial information allows for targeted troubleshooting or policy adjustments, preventing blind actions and ensuring legitimate traffic isn't disrupted by premature interventions.
✗Immediately block the port to prevent potential network congestion from affecting other users.Wrong answer — click to see why▾
Why this is wrong here
Immediately blocking the port is an extreme reaction that disrupts connectivity without first diagnosing the cause. Best practices prioritize investigation over reactive measures to avoid unnecessary downtime.
★ When this WOULD be the correct answer
This would be correct if the question stated that the port is experiencing a confirmed security incident, such as a DDoS attack or malware propagation, and immediate isolation is required to protect the network.
Why candidates choose this
Candidates may think that preventing congestion is urgent and that blocking the port is a quick fix, but they overlook the need for analysis and the potential impact on legitimate traffic.
✗Reboot the switch to clear any temporary errors that might be causing the alert.Wrong answer — click to see why▾
Why this is wrong here
Rebooting the switch is a disruptive action that should not be the first step for a bandwidth utilization alert, as it does not address the root cause and may interrupt legitimate traffic without resolving the issue.
★ When this WOULD be the correct answer
If the question described symptoms of a switch malfunction, such as unresponsive management interface, random packet loss, or error counters indicating hardware issues, then rebooting the switch could be an appropriate first troubleshooting step.
Why candidates choose this
Candidates may default to 'reboot' as a quick fix for any network issue, overlooking that bandwidth alerts typically require traffic analysis rather than device restart.
✗Increase the bandwidth on the port to accommodate the higher traffic load.Wrong answer — click to see why▾
Why this is wrong here
Increasing bandwidth without investigating the cause of the alert does not address the underlying issue and may lead to cost increases or mask a security incident.
★ When this WOULD be the correct answer
When the question states that the port is a critical link for a time-sensitive application and the threshold is set too low for normal operations, and the administrator has already verified that the traffic is legitimate.
Why candidates choose this
Candidates may think that adding bandwidth is a quick fix to resolve performance issues without considering the need for root cause analysis first.
Analysis generated from the official N10-009blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”
Go deeper
Related to this question
Learn chapter
Network Documentation and Diagrams
Key term
Backup
A backup is a copy of computer data taken and stored separately so that the original data can be restored if it is lost, damaged, or corrupted.
Key term
Switch
A switch is a networking device that connects devices on a local area network and uses MAC addresses to forward data only to the intended recipient.
About these practice questions
One of 464 original N10-009 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This N10-009 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the N10-009 exam.