Courseiva

CompTIA Network+ N10-009 (N10-009) — Questions 151225

464 questions total · 7pages · All types, answers revealed

Page 2

Page 3 of 7

Page 4
151
MCQmedium

A company is implementing a wireless network and needs to support high-density client environments with minimal interference. Which IEEE 802.11 standard operates in the 5 GHz band and provides the highest throughput among the options?

A.802.11ac
B.802.11n
C.802.11g
D.802.11b
AnswerA

802.11ac is the optimal choice for high-throughput wireless networks because it operates exclusively in the less congested 5 GHz band, supporting wider channels up to 160 MHz. This standard leverages advanced technologies like multi-user MIMO (MU-MIMO) and beamforming to achieve theoretical multi-gigabit speeds, making it ideal for demanding applications requiring significant bandwidth.

Why this answer

802.11ac (Wi-Fi 5) operates exclusively in the 5 GHz band and supports up to 8 spatial streams, 256-QAM modulation, and channel bonding up to 160 MHz, yielding theoretical throughput exceeding 6.9 Gbps. This makes it the highest-throughput option among the listed standards for high-density environments with minimal interference, as the 5 GHz band offers more non-overlapping channels and less co-channel contention than 2.4 GHz.

Exam trap

The trap here is that candidates often confuse 802.11n as the highest-throughput option because it supports both bands and is widely deployed, but they overlook that 802.11ac is strictly 5 GHz and offers significantly higher throughput through wider channels and higher-order modulation.

Why the other options are wrong

B

802.11n operates in both 2.4 GHz and 5 GHz bands but provides lower maximum throughput (up to 600 Mbps) compared to 802.11ac, which can exceed 1 Gbps in the 5 GHz band, making it unsuitable for the highest throughput requirement.

C

802.11g operates in the 2.4 GHz band, not the 5 GHz band, and its maximum throughput is 54 Mbps, which is far lower than 802.11ac's multi-Gbps speeds.

D

802.11b operates in the 2.4 GHz band with a maximum throughput of 11 Mbps, far below the 5 GHz band and high throughput required for high-density environments.

When would these options actually be correct?

B

A question asking for a standard that supports both 2.4 GHz and 5 GHz bands for backward compatibility with older devices, or one that specifies a mixed-band environment without requiring the highest throughput.

C

A question asking for a legacy standard that operates in the 2.4 GHz band and is backward-compatible with 802.11b, with a maximum throughput of 54 Mbps, would make 802.11g the correct answer.

D

A question asking for the oldest 802.11 standard that operates in the 2.4 GHz band and provides basic wireless connectivity for legacy devices.

Why candidates pick the wrong answer

B

Candidates may confuse 802.11n as a high-throughput option because it introduced MIMO and channel bonding, but they overlook that 802.11ac offers significantly higher throughput by using wider channels and more spatial streams.

C

Candidates may confuse 802.11g with 802.11ac because both are 'g' and 'ac' letters, or they might think 'g' is newer than 'n' and thus faster, overlooking the band and throughput specifications.

D

Candidates may confuse 802.11b with 802.11ac due to similar letter naming, or mistakenly think 'b' is a newer standard than it is.

152
MCQhard

An organization uses OSPF as its interior gateway protocol in a multi-area design. After a core router failure, the network takes a long time to reconverge. Which technology can be implemented to improve convergence speed?

A.Use static routes instead of OSPF
B.Increase OSPF hello and dead timers
C.Implement Bidirectional Forwarding Detection (BFD)
D.Configure all routers in a single OSPF area
AnswerC

Bidirectional Forwarding Detection (BFD) is a lightweight, protocol-independent mechanism designed to provide rapid fault detection for forwarding paths between network devices. By establishing a BFD session between OSPF neighbors and sending very frequent, small hello packets (often in milliseconds), BFD can detect link or neighbor failures significantly faster than OSPF's native hello and dead timers. When BFD detects a failure, it immediately notifies OSPF, allowing the routing protocol to quickly re-converge and re-calculate routes in sub-second times, minimizing service disruption.

Why this answer

BFD provides sub-second failure detection by sending rapid, lightweight hello packets independently of OSPF's own hello mechanism. When a core router fails, BFD detects the link down in milliseconds and immediately signals OSPF to trigger reconvergence, drastically reducing the time OSPF would otherwise spend waiting for its own dead timer to expire.

Exam trap

CompTIA often tests the misconception that increasing OSPF timers or using a single area speeds up convergence, when in fact BFD is the correct technology for sub-second failure detection without altering OSPF's own protocol timers.

Why the other options are wrong

A

Static routes lack dynamic adaptation; they cannot improve OSPF convergence speed after a failure because they require manual intervention to update, whereas OSPF reconverges automatically.

B

Increasing OSPF hello and dead timers would slow down failure detection, making convergence even slower, not faster.

When would these options actually be correct?

A

In a small, stable network with no redundancy requirements, where simplicity and predictability are prioritized over dynamic routing, static routes would be correct to minimize routing overhead and control.

B

In a scenario where the network has frequent, transient link flaps causing unnecessary OSPF recalculations, increasing hello and dead timers can reduce instability and improve overall network stability.

Why candidates pick the wrong answer

A

Candidates may think static routes eliminate OSPF's convergence delays entirely, overlooking that static routes do not adapt to failures at all, making convergence irrelevant but causing outages.

B

Candidates may think that longer timers give more time for routes to stabilize, but they overlook that this delays failure detection and extends convergence time.

153
MCQmedium

A network administrator needs to connect two switches located in separate buildings 150 meters apart. The connection must support 10 Gbps speeds. Which cabling type is most appropriate?

A.Cat6a twisted pair
B.Cat7 twisted pair
C.Multi-mode fiber optic
D.Single-mode fiber optic
AnswerC

Multi-mode fiber optic cable, specifically when utilizing the 10GBASE-SR standard, is an excellent choice for this 150-meter link between buildings. This standard supports 10 Gigabit Ethernet speeds over multi-mode fiber up to 300 meters, comfortably accommodating the required distance. Its larger core allows for the use of less expensive LED or VCSEL transceivers, making it a highly cost-effective and performance-appropriate solution for intermediate distances like 150 meters.

Why this answer

Multi-mode fiber optic (MMF) is the most appropriate choice because it supports 10 Gbps speeds over distances up to 300 meters (using OM3 or OM4 fiber) with cost-effective transceivers (e.g., 10GBASE-SR). The 150-meter distance exceeds the 100-meter maximum for twisted-pair copper cabling (Cat6a or Cat7) at 10 Gbps, making fiber the only viable option among the choices.

Exam trap

The trap here is that candidates often assume Cat7 is superior to Cat6a for longer distances, but both are limited to 100 meters for 10GBASE-T, and the question's 150-meter requirement forces the choice to fiber; CompTIA often tests this distance limitation to distinguish copper from fiber solutions.

Why the other options are wrong

A

Cat6a twisted pair has a maximum distance of 100 meters for 10 Gbps, but the buildings are 150 meters apart, exceeding this limit.

B

Cat7 twisted pair has a maximum distance of 100 meters for 10 Gbps, but the buildings are 150 meters apart, exceeding this limit.

D

Single-mode fiber optic is designed for long-distance transmission (typically kilometers), not for a short 150-meter link. Multi-mode fiber is more cost-effective and sufficient for this distance at 10 Gbps.

When would these options actually be correct?

A

A question requiring 10 Gbps over a distance of less than 100 meters, such as connecting switches within the same building or data center, where cost and ease of termination are priorities.

B

A network administrator needs to connect two switches in the same building 50 meters apart at 10 Gbps, and the budget is limited, making Cat7 a cost-effective choice over fiber.

D

Single-mode fiber would be correct for a connection exceeding 550 meters (e.g., 2 km) at 10 Gbps, or for any distance requiring higher bandwidth over longer runs, such as between buildings across a campus.

Why candidates pick the wrong answer

A

Candidates may remember that Cat6a supports 10 Gbps and overlook the distance limitation, assuming it can cover longer runs without considering the 100-meter standard.

B

Candidates may think Cat7 supports higher speeds and longer distances than Cat6a, but they overlook the 100-meter distance limitation for 10 Gbps.

D

Candidates may think single-mode is always superior because it supports higher bandwidth and longer distances, overlooking that multi-mode is more economical and adequate for shorter runs.

154
MCQmedium

A network security analyst notices that the firewall is logging traffic on the external interface that has a source IP address of 10.0.1.5, which is within the internal network range. This is most likely the result of which type of attack?

A.DNS poisoning
B.IP spoofing
C.ARP poisoning
D.VLAN hopping
AnswerB

IP spoofing is the act of creating Internet Protocol (IP) packets with a forged source IP address, making the packet appear to originate from a different host than its actual sender. A firewall logging "IP spoofing" indicates it has detected incoming packets with source IP addresses that do not align with the expected network topology or routing rules, such as an external packet claiming an internal source IP. This technique is often used to bypass network access controls, launch denial-of-service attacks, or hide the attacker's identity.

Why this answer

The firewall is logging traffic on its external interface with a source IP address from the internal RFC 1918 range (10.0.1.5). This indicates the source IP has been forged, because private IP addresses should never appear as source addresses on a public-facing interface. This is the classic signature of an IP spoofing attack, where the attacker modifies the source IP in the packet header to impersonate an internal host.

Exam trap

The trap here is that candidates confuse IP spoofing with ARP poisoning, because both involve address impersonation, but ARP poisoning is a Layer 2 attack confined to the local subnet, whereas IP spoofing can originate from anywhere on the Internet and is visible on the external interface.

Why the other options are wrong

A

DNS poisoning involves corrupting DNS resolution data to redirect traffic, not generating traffic with an internal source IP on an external interface.

D

VLAN hopping attacks involve gaining access to traffic on other VLANs, typically by exploiting trunking protocols or double-tagging. The scenario describes a source IP address from the internal range appearing on the external interface, which is a classic sign of IP spoofing, not VLAN hopping.

When would these options actually be correct?

A

A question describing users being redirected to a malicious website despite typing the correct URL, with DNS logs showing altered records, would point to DNS poisoning.

D

A network analyst notices that a host on VLAN 10 is receiving traffic intended for a host on VLAN 20, even though no routing or firewall rules allow inter-VLAN communication. This would most likely be the result of which type of attack?

Why candidates pick the wrong answer

A

Candidates may confuse any attack involving IP addresses with DNS poisoning, or think that internal IPs on the external interface indicate DNS manipulation.

D

Candidates may confuse the concept of an internal IP appearing externally with VLAN hopping, thinking that the attacker is jumping VLANs to reach the external interface, rather than recognizing it as a spoofed source address.

155
MCQhard

A security analyst has enabled DHCP snooping on all VLANs of the company's switches to mitigate the risk of rogue DHCP servers. After implementation, the analyst discovers that clients are still receiving IP addresses from an unauthorized DHCP server. The unauthorized server is connected to a switch port that is currently configured as a trusted port. What should the analyst do to stop the rogue DHCP server from offering addresses?

A.Enable Dynamic ARP Inspection on the VLAN.
B.Change the port connecting the unauthorized server to an untrusted port.
C.Configure port security on the unauthorized server's port to limit MAC addresses.
D.Increase the rate limit on the unauthorized server's port.
AnswerB

DHCP snooping treats trusted ports as authorized sources of DHCP offers. By making the port untrusted, the switch will drop any DHCP server messages received on that port.

Why this answer

DHCP snooping operates by designating switch ports as either trusted or untrusted. Trusted ports are allowed to send DHCP server messages (OFFER, ACK), while untrusted ports are blocked from sending such messages. Since the rogue server is connected to a trusted port, it can still offer IP addresses.

Changing the port to untrusted will cause the switch to drop all DHCP server messages from that port, stopping the rogue server.

Exam trap

CompTIA often tests the misconception that DHCP snooping alone blocks all rogue servers, but the trap is that it only works if the rogue server's port is correctly classified as untrusted; candidates may forget that a trusted port bypasses all DHCP snooping filtering.

Why the other options are wrong

A

DHCP snooping already filters unauthorized DHCP servers by trusting only specific ports; Dynamic ARP Inspection (DAI) validates ARP packets, not DHCP offers, so it wouldn't stop the rogue DHCP server from assigning IP addresses.

C

Port security limits the number of MAC addresses on a port but does not prevent a rogue DHCP server from offering addresses. The issue is DHCP snooping trust, not MAC flooding.

D

Increasing the rate limit on the unauthorized server's port would allow more DHCP traffic, not block it. The issue is that the port is trusted, so DHCP snooping does not filter DHCP server messages from that port.

When would these options actually be correct?

A

Dynamic ARP Inspection would be correct in a scenario where a rogue device is performing ARP spoofing or man-in-the-middle attacks by sending fake ARP replies, and the goal is to validate ARP packets against the DHCP snooping binding table.

C

Port security would be correct in a scenario where an attacker is performing MAC flooding or a CAM table overflow attack to intercept traffic, and the goal is to restrict the number of MAC addresses per port.

D

This option would be correct in a scenario where a legitimate DHCP server is being overwhelmed by excessive DHCP requests (e.g., due to a DoS attack), and the goal is to protect the server by limiting the rate of incoming DHCP packets.

Why candidates pick the wrong answer

A

Candidates may confuse DHCP snooping with Dynamic ARP Inspection, thinking both are needed to fully secure DHCP, or they might believe DAI can block rogue DHCP servers since it relies on DHCP snooping bindings.

C

Candidates may confuse port security with DHCP snooping, thinking that limiting MAC addresses can block unauthorized servers, but port security does not filter DHCP server messages.

D

Candidates may confuse rate limiting with security controls, thinking that limiting traffic can stop rogue servers, or they may misapply rate limiting as a general mitigation for unauthorized devices.

156
MCQeasy

A user calls the help desk stating that they cannot access any network resources. The technician asks the user to run ipconfig and the output shows an IP address of 169.254.15.20 with a subnet mask of 255.255.0.0. Which of the following is the most likely cause?

A.The DNS server is not responding
B.The DHCP server is unreachable
C.The default gateway is misconfigured
D.There is a duplicate IP address on the network
AnswerB

When a client device fails to locate or communicate with a DHCP server, it cannot obtain a valid IP address, subnet mask, or default gateway from the network. In such scenarios, Windows operating systems automatically fall back to Automatic Private IP Addressing (APIPA), assigning itself an IP address in the 169.254.0.0/16 range. This link-local address prevents the device from communicating with any network resources beyond its immediate segment, directly causing the inability to access 'any' network services.

Why this answer

The IP address 169.254.15.20 with a subnet mask of 255.255.0.0 is an Automatic Private IP Addressing (APIPA) address, which Windows assigns when a DHCP client fails to receive a lease from a DHCP server. Since the user cannot access any network resources, the most likely cause is that the DHCP server is unreachable, preventing the client from obtaining a valid IP address, default gateway, and DNS server settings.

Exam trap

The trap here is that candidates often confuse APIPA with a DNS failure or gateway issue, but APIPA specifically indicates the DHCP process failed, not that other network services are misconfigured.

Why the other options are wrong

A

The IP address 169.254.15.20 is an Automatic Private IP Addressing (APIPA) address, which indicates that the DHCP server was unreachable, not that DNS is failing. DNS issues would not cause the client to self-assign an APIPA address.

C

The IP address 169.254.15.20 is an Automatic Private IP Addressing (APIPA) address, which indicates the client failed to obtain an IP from a DHCP server. A misconfigured default gateway would not cause the client to self-assign an APIPA address; it would still have a valid IP from DHCP.

D

A duplicate IP address typically causes intermittent connectivity or address conflict errors, not a 169.254.x.x APIPA address. The 169.254.x.x address indicates DHCP failure, not a duplicate IP.

When would these options actually be correct?

A

In a scenario where a user can access network resources by IP address but not by hostname, and the client has a valid DHCP-assigned IP address (not APIPA), the most likely cause is a DNS server not responding.

C

A user can access local resources but cannot reach the internet. The ipconfig shows a valid IP, subnet mask, and default gateway. The correct answer would be that the default gateway is misconfigured or unreachable.

D

A user reports intermittent connectivity and an IP address conflict error message. The technician checks the DHCP server logs and finds no issues, but a ping to the user's IP from another workstation succeeds, indicating a duplicate IP address on the network.

Why candidates pick the wrong answer

A

Candidates may confuse general network connectivity issues with DNS problems, or they may think that DNS is required for all network access, not realizing that APIPA specifically points to DHCP failure.

C

Candidates may confuse symptoms of DHCP failure with gateway issues, or think that any network connectivity problem is due to a misconfigured gateway, not recognizing the APIPA address as a clear indicator of DHCP failure.

D

Candidates may confuse symptoms of duplicate IP addresses (conflict errors, connectivity issues) with the APIPA address resulting from DHCP failure, especially if they have experienced duplicate IP scenarios in the past.

157
MCQeasy

Which network topology connects all devices to a central device?

A.Star
B.Mesh
C.Bus
D.Ring
AnswerA

A star topology is characterized by all network devices connecting to a single central device, such as a hub or switch. This central point manages and directs all data traffic between the connected nodes. This design simplifies troubleshooting and fault isolation, as a failure in one device or cable typically does not affect the rest of the network, though the central device itself becomes a single point of failure.

Why this answer

In a star topology, each device connects directly to a central device such as a switch or hub. This central device manages all communication between endpoints, meaning any data sent from one device must pass through the central point before reaching its destination. This design simplifies fault isolation because a single cable failure only affects the connected device, not the entire network.

Exam trap

The trap here is that candidates often confuse a physical star topology with a logical bus topology (e.g., early Ethernet using a hub) and forget that a switch-based star creates a point-to-point logical connection, eliminating the shared medium and collision domain of a bus.

Why the other options are wrong

B

In a mesh topology, each device connects to multiple other devices, not to a single central device. The question specifically asks for a topology where all devices connect to a central device, which is the star topology.

C

In a bus topology, all devices are connected to a single central cable (the bus), not to a central device like a switch or hub. The question specifies a central device, which is characteristic of a star topology.

D

In a ring topology, each device is connected to exactly two other devices, forming a circular data path, not to a central device.

When would these options actually be correct?

B

A mesh topology would be correct for a question like: 'Which network topology provides the highest level of redundancy and fault tolerance by connecting every device to every other device?'

C

A bus topology would be correct for a question like: 'Which topology uses a single backbone cable to connect all devices?' or 'Which topology is simplest and cheapest for small networks with low traffic?'

D

A question asking 'Which topology connects devices in a closed loop where each device has exactly two neighbors?' would make ring the correct answer.

Why candidates pick the wrong answer

B

Candidates may confuse mesh with star because both involve multiple connections, but mesh lacks a central point. They might think 'central' refers to any hub-like structure, but mesh is decentralized.

C

Candidates may confuse 'central cable' with 'central device', or recall that bus topology connects all devices to a common medium, mistakenly thinking that medium is a central device.

D

Candidates may confuse ring with star because both involve a form of centralization in the logical path, but ring lacks a physical central device.

158
MCQmedium

A network administrator is connecting two switches to increase bandwidth and provide redundancy. Which technology should be used to combine multiple physical links into a single logical link?

A.Spanning Tree Protocol
B.Link Aggregation Control Protocol
C.VLAN Trunking Protocol
D.Rapid Spanning Tree Protocol
AnswerB

Link Aggregation Control Protocol (LACP) is a standardized protocol that dynamically bundles multiple physical Ethernet links between two network devices, typically switches, into a single logical channel. This process, known as link aggregation or EtherChannel, significantly increases the available bandwidth and provides crucial fault tolerance. If one of the physical links within the aggregated group fails, traffic automatically redistributes across the remaining active links, ensuring high availability and improved throughput.

Why this answer

Link Aggregation Control Protocol (LACP) is the correct technology because it allows multiple physical Ethernet links to be combined into a single logical link, increasing aggregate bandwidth and providing redundancy. LACP (IEEE 802.3ad) automatically negotiates and manages the bundling of ports between switches, ensuring that traffic is load-balanced across the member links and that the bundle remains operational even if one physical link fails.

Exam trap

The N10-009 exam often tests the misconception that STP or RSTP can be used to increase bandwidth, but the trap here is that STP and RSTP only provide redundancy by blocking ports to prevent loops, not by actively combining links for higher throughput.

Why the other options are wrong

A

Spanning Tree Protocol (STP) prevents loops in redundant networks but does not combine multiple physical links into a single logical link; it blocks redundant paths rather than aggregating bandwidth.

C

VLAN Trunking Protocol (VTP) is used to manage VLAN configurations across switches, not to combine physical links into a single logical link for bandwidth and redundancy.

D

Rapid Spanning Tree Protocol (RSTP) is used to prevent loops in a network topology, not to combine multiple physical links into a single logical link. The question specifically asks for a technology to aggregate links, which is not RSTP's function.

When would these options actually be correct?

A

A question asking which protocol prevents switching loops in a network with redundant paths, or which protocol ensures a loop-free topology in a bridged network, would have STP as the correct answer.

C

A network administrator needs to synchronize VLAN information across multiple switches in a domain, ensuring consistent VLAN databases without manual configuration on each switch.

D

RSTP would be correct in a question asking: 'Which protocol provides faster convergence than STP in a switched network with redundant links?' or 'Which technology prevents bridging loops while offering rapid failover?'

Why candidates pick the wrong answer

A

Candidates confuse STP's role in redundancy with link aggregation, mistakenly thinking STP itself increases bandwidth or combines links, when it actually manages redundancy by disabling duplicate paths.

C

Candidates may confuse 'trunking' (VTP) with link aggregation, as both involve multiple links, but VTP manages VLANs, not link bonding.

D

Candidates may confuse RSTP with link aggregation because both involve multiple links, but RSTP's purpose is loop prevention, not bandwidth aggregation. The word 'rapid' might also mislead candidates into thinking it improves performance.

159
MCQmedium

A network administrator is troubleshooting an intermittent link between two switches connected by single-mode fiber. The interface log shows "Link up / Link down" events multiple times per hour. Which of the following is the most likely cause?

A.Incorrect VLAN configuration on the switch ports
B.Crossed fiber pairs
C.Dirty fiber connectors
D.Duplex mismatch between the switches
AnswerC

Dirty fiber connectors are a very common cause of intermittent link flapping because microscopic dust or oil particles on the ferrule end-face can partially block or scatter the optical signal. This attenuation can cause the received light power to intermittently drop below the receiver's sensitivity threshold, leading to a loss of carrier and subsequent link re-negotiation. Cleaning the connectors with appropriate tools often restores stable link operation by ensuring clear signal transmission.

Why this answer

Dirty fiber connectors cause intermittent signal loss by scattering or absorbing light, which leads to CRC errors and repeated link flaps as the optical transceiver struggles to maintain synchronization. This matches the 'Link up / Link down' pattern seen in the logs, especially on single-mode fiber where precise alignment is critical.

Exam trap

The trap here is that candidates often jump to duplex mismatch or VLAN misconfiguration as common causes of link issues, but the intermittent 'Link up / Link down' pattern specifically points to a physical-layer problem like dirty connectors, not a Layer 2 configuration error.

Why the other options are wrong

A

Incorrect VLAN configuration would cause connectivity issues for specific VLANs, not intermittent link flaps on the physical interface. The log shows physical layer events (link up/down), which are unrelated to VLAN settings.

B

Crossed fiber pairs (e.g., TX/RX swapped) typically cause a complete link failure, not intermittent link flaps. The symptom described is frequent link up/down events, which is more consistent with physical layer issues like dirty connectors rather than a wiring error.

When would these options actually be correct?

A

A question where hosts in the same VLAN cannot communicate across switches, but the physical link is stable and up. The correct answer would be VLAN mismatch or misconfiguration on the trunk ports.

B

This option would be correct in a scenario where two switches are connected via fiber but the link never establishes, or the interface shows 'not connected' despite both ends being up. For example, if a technician accidentally swaps the transmit and receive fibers, the link will not come up at all.

Why candidates pick the wrong answer

A

Candidates often associate any connectivity problem with VLAN misconfiguration, especially when switches are involved, without recognizing that link flaps are a physical layer symptom.

B

Candidates may confuse intermittent link flaps with wiring issues because both involve physical layer problems. The term 'crossed' sounds like a plausible cause for unstable connectivity, leading them to overlook the more specific symptom of intermittent vs. persistent failure.

160
MCQhard

A network administrator scheduled a change window to upgrade the firmware on a core switch. During the upgrade, the switch fails to boot properly. The administrator needs to restore the switch to its previous operational state. Which of the following should the administrator have done before the upgrade to facilitate a successful rollback?

A.Notified all users of the maintenance window.
B.Backed up the current configuration and firmware image.
C.Disconnected all redundant links.
D.Set the switch to boot from an alternative image.
AnswerB

Backing up the current configuration and firmware image is the most critical preparatory step for any network device upgrade. This action creates a complete snapshot of the device's operational state, including all settings, VLANs, routing protocols, and the running operating system software. In the event of an upgrade failure, such as a corrupted firmware flash or an incompatible configuration, these backups provide the exact files needed to revert the switch to its previous, stable working condition, minimizing downtime and service disruption.

Why this answer

Backing up both the current configuration and the firmware image ensures that the administrator can restore the switch to its exact previous operational state if the upgrade fails. Without a backup of the firmware image, the switch may not have a valid bootable image to revert to, even if the configuration is saved. This is a fundamental prerequisite for any firmware upgrade rollback plan.

Exam trap

The trap here is that candidates often confuse 'backing up the configuration' with 'backing up the firmware image,' assuming a configuration backup alone is sufficient for a full rollback, but without the firmware image the switch may have no bootable OS to load.

Why the other options are wrong

A

Notifying users of the maintenance window is a communication best practice but does not provide a technical rollback mechanism for a failed firmware upgrade.

C

Disconnecting redundant links does not facilitate a rollback of the firmware upgrade; it only prevents network loops during the upgrade but does not preserve the previous operational state.

D

Setting the switch to boot from an alternative image does not ensure a rollback to the previous operational state if the new firmware fails; it only changes the boot order. The administrator needs a backup of the current firmware and configuration to restore after a failed upgrade.

When would these options actually be correct?

A

A question asks: 'A network administrator is planning a firmware upgrade on a core switch. Which step should be taken to minimize user impact?' In that context, notifying users of the maintenance window would be correct to set expectations and reduce disruption.

C

When performing maintenance that could cause network instability or loops (e.g., upgrading multiple switches with redundant paths), disconnecting redundant links prevents broadcast storms and ensures a stable environment for the upgrade.

D

This option would be correct in a scenario where the switch has multiple firmware images stored and the administrator wants to test a new image while keeping the ability to revert to the current one by simply changing the boot variable, without needing a separate backup.

Why candidates pick the wrong answer

A

Candidates may confuse general change management procedures (like user notification) with the specific technical steps required to enable a rollback after a failed upgrade.

C

Candidates may think that removing redundancy simplifies the upgrade process and reduces the risk of issues, but it does not address the need to restore the switch to its previous state after a failed boot.

D

Candidates may think that booting from an alternative image is a quick rollback method, confusing it with having a backup image already stored on the device, but they overlook that the alternative image might not be the previous working version.

161
MCQhard

An attacker intercepts communication between two parties and is able to modify the data in transit without either party's knowledge. Which type of attack is this?

A.Man-in-the-middle
B.ARP spoofing
C.DNS poisoning
D.Replay attack
AnswerA

A Man-in-the-Middle (MITM) attack involves an unauthorized third party secretly relaying and potentially altering the communication between two parties who believe they are directly communicating. The attacker positions themselves logically between the endpoints, intercepting all traffic, reading its contents, and then forwarding it, often after modification, to the intended recipient. This allows the attacker to eavesdrop, inject false information, or manipulate data in real-time without detection by the legitimate participants, precisely matching the scenario described.

Why this answer

A man-in-the-middle (MITM) attack occurs when an adversary secretly intercepts and potentially alters the communication between two parties who believe they are directly communicating with each other. The attacker can modify data in transit without either party's knowledge by placing themselves in the logical or physical path of the data flow, often by exploiting weaknesses in authentication or encryption. This matches the scenario described, where the attacker both intercepts and modifies the data.

Exam trap

The N10-009 exam often tests the distinction between the attack type (MITM) and the technique used to achieve it (ARP spoofing, DNS poisoning), so candidates mistakenly select the technique rather than the overarching attack described in the scenario.

Why the other options are wrong

B

ARP spoofing is a technique used to associate an attacker's MAC address with the IP address of a legitimate device, enabling interception of traffic, but it does not inherently involve modifying data in transit. The question specifies modification of data, which is a key characteristic of a man-in-the-middle attack, not ARP spoofing alone.

C

DNS poisoning involves corrupting DNS resolver caches to redirect traffic to malicious sites, but it does not inherently allow real-time modification of data in transit between two parties.

D

A replay attack involves capturing and retransmitting valid data, but it does not allow the attacker to modify data in transit without detection. The question specifies modification, which is a key feature of man-in-the-middle attacks.

When would these options actually be correct?

B

A question that asks: 'An attacker sends forged ARP messages to associate their MAC address with the IP address of a default gateway, causing traffic to be redirected through the attacker's machine. Which type of attack is this?' would make ARP spoofing the correct answer.

C

A question describing an attack where users are redirected to a fake website that mimics a legitimate one, and the attacker captures credentials or serves malware, would make DNS poisoning the correct answer.

D

A replay attack would be correct if the question described an attacker capturing authentication tokens or session data and reusing them to impersonate a user, without any modification of the data.

Why candidates pick the wrong answer

B

Candidates may confuse ARP spoofing with man-in-the-middle because ARP spoofing is often used as a precursor to a man-in-the-middle attack, leading them to incorrectly select it as the primary attack type when the question focuses on data modification.

C

Candidates may confuse DNS poisoning with man-in-the-middle because both can intercept traffic, but they overlook that DNS poisoning redirects traffic rather than modifying data in an existing session.

D

Candidates may confuse replay attacks with man-in-the-middle because both involve intercepting communications, but they overlook that replay attacks do not involve altering the data.

162
MCQmedium

A network technician is configuring a small office network with two subnets: 10.0.1.0/24 and 10.0.2.0/24. Each subnet has its own switch, and both switches are connected to a router with interfaces 10.0.1.1 and 10.0.2.1. Hosts on subnet A can ping the router's interface in their subnet but cannot ping hosts on subnet B. Which of the following is the most likely cause?

A.The router is not configured with a routing protocol.
B.IP routing is disabled on the router.
C.The hosts in subnet A have the wrong default gateway.
D.The switch in subnet A is blocking ICMP traffic.
AnswerB

If IP routing is disabled, the router functions merely as a multi-port switch, preventing it from performing its fundamental Layer 3 role of forwarding packets between different IP subnets. While hosts can reach the router's interface on their local subnet, the router will not process and forward traffic destined for other subnets, effectively isolating them. This directly explains why communication fails beyond the local segment.

Why this answer

The hosts on subnet A can ping their default gateway (10.0.1.1) but cannot reach hosts on subnet B, which indicates that the router is not forwarding packets between the two directly connected subnets. This behavior is characteristic of a router with IP routing disabled, as the router will not perform inter-VLAN or inter-subnet forwarding unless the 'ip routing' command is enabled globally. Without IP routing, the router acts as a host and will only respond to traffic destined for its own interfaces, dropping any packets that require forwarding to another subnet.

Exam trap

The N10-009 exam often tests the distinction between 'routing protocol' and 'IP routing' — candidates mistakenly think a routing protocol is required for directly connected subnets, when in fact the 'ip routing' global command is the fundamental enabler of any Layer 3 forwarding.

Why the other options are wrong

A

The router is directly connected to both subnets (10.0.1.0/24 and 10.0.2.0/24), so it automatically has routes to these networks. A routing protocol is only needed to learn routes to non-directly connected networks, which is not the case here.

C

The hosts can ping the router's interface in their subnet, indicating the default gateway is correctly configured. The issue is inter-subnet routing, not the gateway address.

D

The switch in subnet A is a Layer 2 device and does not block ICMP traffic between subnets; inter-subnet communication requires a router, and the issue is that the router is not forwarding packets because IP routing is disabled.

When would these options actually be correct?

A

In a scenario where the router does not have directly connected interfaces to both subnets (e.g., subnets are behind other routers), and the router needs to dynamically learn routes to reach them, then a routing protocol would be necessary for inter-subnet communication.

C

In a scenario where hosts on subnet A cannot ping the router's interface (10.0.1.1) but can ping other hosts on the same subnet, the most likely cause would be an incorrect default gateway configured on the hosts.

D

In a scenario where hosts on the same subnet cannot ping each other or the local gateway, and the switch is configured with ACLs or port security that blocks ICMP, then the switch blocking ICMP would be the likely cause.

Why candidates pick the wrong answer

A

Candidates often assume that any routing between subnets requires a routing protocol, not realizing that directly connected routes are automatically added and sufficient for communication between directly attached networks.

C

Candidates often assume that connectivity issues between subnets stem from incorrect gateway settings, overlooking that the router's routing capability (IP routing enabled) is required for forwarding between subnets.

D

Candidates may think switches can filter traffic between subnets or that ICMP blocking is a common issue, but switches operate at Layer 2 and do not route between subnets.

163
MCQmedium

A network administrator needs to upgrade the backbone link between two switches to fiber optic to eliminate electromagnetic interference. The distance between the switches is 350 meters. Which transceiver type should be used?

A.1000BASE-SX
B.1000BASE-LX
C.1000BASE-CX
D.1000BASE-T
AnswerA

1000BASE-SX is the optimal choice for upgrading a backbone link to fiber optic over a 350-meter distance. This standard utilizes multi-mode fiber, which is cost-effective for medium-range applications and perfectly supports distances up to 550 meters. Its use of shorter wavelength lasers (850 nm) makes it suitable for the specified requirement, providing reliable gigabit connectivity while effectively avoiding electromagnetic interference.

Why this answer

1000BASE-SX (option A) is correct because it supports distances up to 550 meters over multimode fiber (MMF) at 850 nm wavelength, making it suitable for the 350-meter backbone link. It is designed to eliminate electromagnetic interference (EMI) by using fiber optic cabling, and the distance falls within its maximum reach for common multimode fiber types like OM2 or OM3.

Exam trap

The N10-009 exam often tests the distance limitations of fiber transceivers, and the trap here is that candidates might choose 1000BASE-LX because they assume 'longer distance is always better,' overlooking that 1000BASE-SX is the correct, cost-effective choice for the given 350-meter range over multimode fiber.

Why the other options are wrong

B

1000BASE-LX is designed for single-mode fiber with distances up to 5 km, but the question specifies a distance of 350 meters over multimode fiber, where 1000BASE-SX is the appropriate choice for cost-effective short-range links.

C

1000BASE-CX uses copper twinaxial cable, not fiber optic, and is limited to distances up to 25 meters, far short of the required 350 meters.

D

1000BASE-T uses twisted-pair copper cabling (Cat5e or higher) and is susceptible to electromagnetic interference, which the question explicitly requires eliminating. It also has a maximum distance of 100 meters, far less than the 350 meters needed.

When would these options actually be correct?

B

A network administrator needs to connect two switches 2 km apart using fiber optic cable. Which transceiver type should be used? (1000BASE-LX supports longer distances over single-mode fiber.)

C

This option would be correct for a short-distance, high-speed backbone link within a data center or server room (e.g., connecting switches in the same rack) where low cost and low latency are needed, and fiber is not required.

D

1000BASE-T would be correct if the question asked for a Gigabit Ethernet connection over existing copper infrastructure within 100 meters, without concerns about EMI, such as connecting a server to a switch in the same rack.

Why candidates pick the wrong answer

B

Candidates may confuse LX as a general long-range option without considering the specific distance (350m) and fiber type (multimode) in the question, assuming LX is always better.

C

Candidates may confuse 'CX' with fiber or think it supports longer distances due to the 'C' prefix, or they may overlook the distance limitation and focus only on the need for a backbone link.

D

Candidates may default to 1000BASE-T because it is the most common Gigabit Ethernet standard for copper cabling, and they might overlook the distance and EMI requirements in the question.

164
MCQhard

A network has a single switch with VLANs 10, 20, and 30 configured. The switch is connected to a router that has three subinterfaces, each in a different VLAN. How many broadcast domains are present?

A.1
B.3
C.4
D.5
AnswerB

A broadcast domain is a network segment where all devices can receive each other's broadcast frames. By definition, each Virtual Local Area Network (VLAN) isolates broadcast traffic to its own members, effectively creating a distinct broadcast domain. With VLANs 10, 20, and 30 configured on the switch, there are precisely three separate broadcast domains, as the router's subinterfaces facilitate inter-VLAN routing but do not merge these isolated domains.

Why this answer

Each VLAN is a separate Layer 2 broadcast domain. With VLANs 10, 20, and 30 configured on the switch and a router using subinterfaces to route between them, there are exactly three broadcast domains — one per VLAN. Broadcasts are confined to their VLAN and do not cross VLAN boundaries without a Layer 3 device.

Exam trap

The trap here is that candidates often count the router subinterfaces as separate broadcast domains, not realizing that broadcast domains are strictly Layer 2 constructs and that the router only provides inter-VLAN routing without adding new broadcast domains.

Why the other options are wrong

A

Each VLAN creates a separate broadcast domain. With three VLANs (10, 20, 30) and a router with three subinterfaces, there are three distinct broadcast domains, not one.

C

Each VLAN creates its own broadcast domain, and with three VLANs (10, 20, 30) there are exactly three broadcast domains. Option C (4) is incorrect because there is no fourth broadcast domain; the router subinterfaces do not add additional broadcast domains beyond the VLANs.

When would these options actually be correct?

A

If the question described a single flat network with no VLANs (e.g., all devices on the same switch without VLAN configuration) and no router segmentation, then there would be only one broadcast domain.

C

If the question stated that the switch had four VLANs (e.g., VLANs 10, 20, 30, and 40) and each was connected to a router subinterface, then there would be four broadcast domains, making option C correct.

Why candidates pick the wrong answer

A

Candidates may mistakenly think that a single switch inherently creates one broadcast domain, ignoring that VLANs logically separate broadcast traffic.

C

Candidates might mistakenly count the router subinterfaces as separate broadcast domains or think that the router itself adds an extra broadcast domain, leading them to choose 4 instead of 3.

165
MCQeasy

A network engineer needs to connect two devices that are 150 meters apart with a 10 Gbps link. Which cabling type is most suitable?

A.Cat6a UTP
B.Cat7 STP
C.Single-mode fiber
D.Multimode fiber
AnswerC

Single-mode fiber is the correct choice because it is specifically engineered for transmitting light over very long distances with minimal signal loss and dispersion. Its extremely small core diameter (typically 9 microns) allows only a single path for light to travel, effectively eliminating modal dispersion which limits multimode fiber. This capability enables 10 Gbps speeds to extend for many kilometers, making it exceptionally well-suited and highly reliable for a 150-meter link while providing significant headroom for future speed upgrades.

Why this answer

Single-mode fiber (SMF) is the correct choice because it supports 10 Gbps transmission over distances well beyond 150 meters, typically up to 10 km or more using 10GBASE-LR optics. In contrast, copper cabling like Cat6a or Cat7 is limited to 100 meters for 10GBASE-T, and multimode fiber (MMF) with 10GBASE-SR is limited to about 300-400 meters depending on the fiber grade (e.g., OM3/OM4), but SMF provides the most reliable and future-proof solution for this distance.

Exam trap

The trap here is that candidates often assume multimode fiber is sufficient for any distance under 300 meters, but the exam emphasizes 'most suitable' based on scalability and performance, making single-mode fiber the better choice even for shorter runs when future-proofing is considered.

Why the other options are wrong

A

Cat6a UTP is limited to distances of up to 100 meters for 10 Gbps, so it cannot support a 150-meter link.

B

Cat7 STP is a copper cabling standard that supports up to 10 Gbps but only over distances up to 100 meters. The required 150 meters exceeds this limit, making it unsuitable.

D

Multimode fiber (MMF) typically supports 10 Gbps up to 300-400 meters with OM3/OM4, but 150 meters is well within its range. However, the question asks for the 'most suitable' cabling. Single-mode fiber (SMF) is more suitable for future-proofing and longer distances, and MMF is often used for shorter runs within data centers.

But the key here is that MMF can actually work at 150m for 10 Gbps, so it's not strictly wrong. However, the exam likely expects SMF for any distance over 100m for 10 Gbps, as MMF's reach at 10 Gbps is limited to 300m with OM3, but SMF is more reliable and scalable. Actually, MMF can work, but SMF is better.

The question's correct answer is SMF, so MMF is wrong because it's less suitable for this distance due to higher attenuation and modal dispersion compared to SMF, though it could technically work.

When would these options actually be correct?

A

For a 10 Gbps link over a distance of up to 100 meters in a cost-sensitive environment with existing copper infrastructure, Cat6a UTP would be suitable.

B

A network engineer needs to connect two devices 50 meters apart with a 10 Gbps link in an environment with high electromagnetic interference (EMI). Cat7 STP provides shielding to reduce interference and supports the required speed and distance.

D

A network engineer needs to connect two devices that are 80 meters apart with a 10 Gbps link within a data center. Multimode fiber (OM3 or OM4) is the most cost-effective choice for distances up to 300 meters at 10 Gbps, making it suitable for this scenario.

Why candidates pick the wrong answer

A

Candidates may think Cat6a supports 10 Gbps and overlook the distance limitation, or assume that higher-category copper can exceed standard distance specs.

B

Candidates may think Cat7 STP supports 10 Gbps and assume it can handle longer distances due to its higher category number, overlooking the 100-meter distance limitation for copper cabling.

D

Candidates may think multimode fiber is sufficient for 150 meters because it supports 10 Gbps up to 300 meters with OM3/OM4, overlooking that single-mode fiber is more appropriate for longer distances and future scalability.

166
MCQeasy

A network administrator wants to prevent unauthorized devices from being plugged into switch ports. Only devices with specific MAC addresses should be allowed on each port. Which switch security feature should be enabled?

A.DHCP snooping
B.Dynamic ARP inspection
C.Port security
D.802.1X
AnswerC

Port security is a Layer 2 control mechanism configured on a switch port to restrict which MAC addresses are permitted to send traffic. It can be configured to allow only a specific number of MAC addresses, or even just one, to learn and communicate through that port. If an unauthorized device with a different MAC address attempts to connect, the port can be configured to shut down, restrict traffic, or simply drop packets from the unauthorized MAC, effectively preventing its use. This directly addresses the goal of preventing unauthorized devices from being plugged into a switch.

Why this answer

Port security is the correct feature because it allows the administrator to restrict which MAC addresses can communicate through a switch port. By configuring allowed MAC addresses (sticky or static), any device with an unknown MAC address attempting to send traffic will trigger a security violation (shutdown, restrict, or protect). This directly addresses the requirement to prevent unauthorized devices from being plugged into switch ports.

Exam trap

CompTIA often tests the distinction between port security (MAC-based access control) and 802.1X (authentication-based access control), leading candidates to incorrectly choose 802.1X when the question explicitly mentions 'specific MAC addresses' rather than user credentials or certificates.

Why the other options are wrong

A

DHCP snooping is a security feature that filters untrusted DHCP messages and builds a DHCP snooping binding table, but it does not restrict which devices can be plugged into switch ports based on MAC addresses.

B

Dynamic ARP inspection (DAI) validates ARP packets to prevent ARP spoofing attacks, but it does not restrict which devices can be physically plugged into switch ports based on MAC addresses.

D

802.1X is a port-based network access control protocol that authenticates users or devices before granting network access, but it does not restrict specific MAC addresses per port; it relies on authentication credentials, not a static MAC address list.

When would these options actually be correct?

A

A network administrator wants to prevent rogue DHCP servers from offering IP addresses to clients on a specific VLAN. DHCP snooping should be enabled on the switch to filter DHCP messages and only allow DHCP responses from trusted ports.

B

A network administrator wants to prevent man-in-the-middle attacks by ensuring that only valid ARP responses are accepted on a VLAN. DAI should be enabled to drop ARP packets with invalid IP-to-MAC address bindings.

D

A question asks: 'A company wants to ensure that only authenticated users can connect to the network, using their domain credentials. Which switch security feature should be enabled?' In that scenario, 802.1X would be correct.

Why candidates pick the wrong answer

A

Candidates may confuse DHCP snooping with port security because both involve MAC addresses; DHCP snooping tracks MAC-to-IP bindings, leading to the mistaken belief it can enforce MAC-based port access.

B

Candidates may confuse DAI's use of MAC addresses for validation with port security's MAC address filtering, or think that any feature involving MAC addresses can restrict physical port access.

D

Candidates may confuse MAC-based authentication (which 802.1X can use) with port security's static MAC address filtering, or think 802.1X can enforce MAC address lists when it typically uses RADIUS-based authentication.

167
MCQmedium

A user reports that they cannot access the internal web server by its fully qualified domain name (intranet.company.com). The workstation's IP configuration shows a DNS server of 8.8.8.8, but the internal DNS server is 10.0.0.10. The user can successfully ping the server's IP address (10.0.0.50). What is the MOST likely cause of the issue?

A.A: The workstation is using the wrong DNS server address
B.B: The subnet mask on the workstation is incorrect
C.C: The network cable is faulty
D.D: The default gateway is misconfigured
AnswerA

If the workstation is configured to use an external DNS server (e.g., a public internet DNS resolver), it will be unable to resolve internal hostnames like "internalwebserver.local" because external DNS servers lack records for private network zones. While IP-based connectivity is confirmed by the successful ping to the server's IP address, the failure to access it by hostname indicates a breakdown in the name resolution process specifically for internal resources. This prevents accessing the web server by its friendly name, even though it is physically reachable.

Why this answer

The workstation's DNS server is set to 8.8.8.8 (a public Google DNS server), which cannot resolve the internal domain name 'intranet.company.com' because that zone is only hosted on the internal DNS server at 10.0.0.10. Since the user can ping the server's IP address (10.0.0.50), network connectivity is fine, confirming the issue is name resolution. The most likely cause is that the workstation is using the wrong DNS server address.

Exam trap

The trap here is that candidates often confuse a DNS resolution failure with a network connectivity issue, but the ability to ping the IP address proves the problem is strictly name resolution, not layer 2 or layer 3 problems.

Why the other options are wrong

B

The user can successfully ping the server's IP address (10.0.0.50), which indicates that the network cable is functional and the subnet mask is correct for local communication. An incorrect subnet mask would typically prevent communication with hosts on the same subnet, but pinging the server's IP works, so the subnet mask is not the issue.

C

The user can successfully ping the server's IP address, which rules out a faulty network cable. A faulty cable would cause connectivity issues at the IP level, making pings fail.

D

The user can successfully ping the server's IP address (10.0.0.50), which indicates that the network path is functional. A misconfigured default gateway would prevent communication with external networks, but internal traffic within the same subnet does not require a gateway. Since the server is on the same network (10.0.0.x), the gateway is not needed for this access.

When would these options actually be correct?

B

A user cannot access any network resources, including pinging the default gateway or other hosts on the same subnet. The workstation's IP configuration shows an incorrect subnet mask (e.g., 255.255.255.0 instead of 255.255.0.0), causing the workstation to believe remote hosts are on a different subnet and failing to send traffic to the default gateway.

C

A user cannot access any network resources, and pinging both IP addresses and hostnames fails. The workstation shows a link light but no network activity. In that scenario, a faulty cable would be a likely cause.

D

A user reports they cannot access an external website (e.g., www.example.com) but can ping the internal server by IP. The workstation's default gateway is set to an incorrect address, preventing traffic from leaving the local subnet. In that scenario, a misconfigured default gateway would be the most likely cause.

Why candidates pick the wrong answer

B

Candidates may think that an incorrect subnet mask could cause DNS resolution failures because it affects routing decisions, but in this scenario, the ability to ping the server's IP confirms that layer 3 connectivity is intact, isolating the issue to DNS.

C

Candidates may think any network issue could be due to a physical cable problem, especially when they overlook that successful IP pings confirm Layer 1 and Layer 2 are functioning.

D

Candidates may confuse general network connectivity issues with DNS resolution problems. They might think that if DNS fails, the default gateway could be at fault, but the ability to ping the server's IP proves the gateway is not the issue here.

168
MCQhard

A network engineer is configuring a new wireless LAN for a high-density environment such as a conference hall. The engineer needs to minimize co-channel interference. Which of the following should be configured on the access points?

A.Increase transmit power
B.Decrease transmit power
C.Decrease beacon interval
D.Implement channel bonding
AnswerB

In a high-density wireless environment, decreasing transmit power effectively shrinks the coverage area of each Access Point (AP). This allows for a greater number of APs to be deployed in closer proximity, utilizing non-overlapping channels more efficiently. By reducing the cell size, co-channel interference between adjacent APs operating on the same frequency is minimized, thereby improving overall network capacity and client performance. This strategy is crucial for maximizing spectral efficiency.

Why this answer

In a high-density environment like a conference hall, decreasing transmit power on access points reduces the cell size, which allows for more APs to be placed closer together without their coverage areas overlapping excessively. This minimizes co-channel interference by ensuring that APs on the same channel are physically separated, improving overall throughput and client performance.

Exam trap

The trap here is that candidates mistakenly think increasing transmit power improves performance in dense environments, when in fact it exacerbates co-channel interference by creating larger, overlapping cells.

Why the other options are wrong

A

Increasing transmit power in a high-density environment like a conference hall actually increases co-channel interference because overlapping cells will have stronger signals, worsening contention and reducing overall capacity.

C

Decreasing the beacon interval increases the frequency of beacon transmissions, which adds overhead and can increase co-channel interference, not minimize it.

D

Channel bonding combines adjacent channels to increase throughput, but in a high-density environment like a conference hall, it actually increases co-channel interference by consuming more spectrum and reducing the number of non-overlapping channels available.

When would these options actually be correct?

A

In a scenario where an access point needs to cover a larger area with fewer clients, such as a warehouse or outdoor campus, increasing transmit power can extend range and reduce the number of APs needed, provided co-channel interference is not a primary concern.

C

In a scenario where client devices need faster network discovery or roaming, such as in a high-mobility environment like a warehouse with moving robots, decreasing the beacon interval helps clients find and associate with APs more quickly.

D

In a scenario where the goal is to maximize throughput for a single client or in a low-density environment with minimal interference, channel bonding (e.g., 40 MHz in 2.4 GHz or 80/160 MHz in 5 GHz) can be configured to achieve higher data rates.

Why candidates pick the wrong answer

A

Candidates often assume that higher transmit power always improves performance, not realizing that in dense deployments it exacerbates interference and reduces network efficiency.

C

Candidates may confuse beacon interval with channel utilization, thinking that less frequent beacons reduce interference, or they may incorrectly believe that decreasing the interval reduces channel congestion.

D

Candidates may think that increasing channel width (bonding) improves performance in all situations, not realizing that in dense deployments it exacerbates interference and reduces overall capacity.

169
MCQmedium

A company wants to increase the bandwidth between two switches without upgrading the existing 1 Gbps copper links. Both switches support 802.3ad. Which technology should be implemented?

A.Link aggregation (LACP)
B.VLAN trunking
C.Port mirroring
D.StackWise
AnswerA

Link Aggregation Control Protocol (LACP) is an IEEE 802.3ad standard that dynamically bundles multiple physical Ethernet links into a single logical channel. This process effectively increases the aggregate bandwidth between two network devices by distributing traffic across the bundled links, providing both higher throughput and redundancy. By utilizing existing switch ports, LACP achieves a significant bandwidth increase without requiring an upgrade to higher-speed interfaces.

Why this answer

Link aggregation using LACP (802.3ad) allows multiple 1 Gbps copper links to be combined into a single logical link, increasing bandwidth between the two switches without upgrading the physical interfaces. Since both switches support 802.3ad, they can negotiate and manage the aggregated link dynamically, providing both increased throughput and link redundancy.

Exam trap

The trap here is that candidates often confuse link aggregation with stacking (StackWise) or VLAN trunking, thinking any multi-link technology increases bandwidth, but only LACP/802.3ad properly combines physical links for higher throughput between two switches.

Why the other options are wrong

B

VLAN trunking (802.1Q) is used to carry multiple VLANs over a single link, not to increase bandwidth between switches. It does not combine multiple physical links into one logical link for higher throughput.

C

Port mirroring is used to copy traffic from one port to another for monitoring or analysis, not to increase bandwidth between switches. It does not aggregate links to provide higher throughput.

D

StackWise is a Cisco proprietary technology for stacking multiple switches into a single logical unit, not for increasing bandwidth between two separate switches using existing copper links. It requires specific stacking cables and does not use 802.3ad.

When would these options actually be correct?

B

A company needs to carry traffic from multiple VLANs between two switches over a single physical link. The switches support 802.1Q. Which technology should be implemented?

C

A network administrator needs to capture and analyze traffic passing through a switch port for troubleshooting or security monitoring. Port mirroring would be the correct technology to send a copy of all packets from the source port to a monitoring device connected to another port.

D

A question asks: 'A company wants to combine multiple physical switches into a single logical switch for simplified management and higher forwarding capacity. Which Cisco technology should be used?' In that context, StackWise would be the correct answer.

Why candidates pick the wrong answer

B

Candidates may confuse 'trunking' (VLAN tagging) with 'link aggregation' (port trunking), as both involve combining or managing multiple links, leading to a mix-up of terminology.

C

Candidates may confuse port mirroring with link aggregation because both involve multiple ports, but they serve entirely different purposes—mirroring duplicates traffic, while aggregation combines bandwidth.

D

Candidates may confuse StackWise with link aggregation because both can increase bandwidth, but StackWise is for switch stacking, not for aggregating links between two separate switches.

170
MCQmedium

A network administrator needs to automatically back up the configuration files of all network devices (routers, switches, firewalls) to a central server every night. The administrator requires the transfer to be encrypted to protect sensitive configuration data. Which protocol should the administrator use to retrieve the configuration files?

A.TFTP
B.FTP
C.SCP
D.HTTP
AnswerC

SCP (Secure Copy Protocol) is the correct choice because it leverages the Secure Shell (SSH) protocol to provide robust encryption and authentication for file transfers. This ensures that sensitive configuration files are transmitted securely over the network, protecting them from eavesdropping and unauthorized access during backup operations. Its inherent security features make it ideal for automated, confidential data movement in network environments.

Why this answer

SCP (Secure Copy Protocol) uses SSH for encrypted file transfers, making it ideal for securely retrieving configuration files from network devices to a central server. It ensures both authentication and data encryption, protecting sensitive configuration data during transit.

Exam trap

The N10-009 exam often tests SCP versus TFTP, where candidates mistakenly choose TFTP because it is simpler and commonly used for backups, but they overlook the encryption requirement specified in the question.

Why the other options are wrong

A

TFTP lacks encryption and authentication, making it insecure for transferring sensitive configuration files over a network.

B

FTP transfers data in plaintext, including authentication credentials and configuration files, which violates the requirement for encrypted transfer to protect sensitive data.

D

HTTP does not provide built-in encryption; it transmits data in plaintext, failing the requirement for encrypted transfer of sensitive configuration files.

When would these options actually be correct?

A

A network administrator needs to quickly transfer a small configuration file to a device in a lab environment where security is not a concern, and simplicity and speed are prioritized.

B

A network administrator needs to transfer large firmware files to multiple devices, and the devices only support FTP for file transfer, with encryption provided by a separate VPN tunnel.

D

When the question specifies a need for unencrypted, simple web-based retrieval of configuration files from devices with built-in HTTP servers, and encryption is not required.

Why candidates pick the wrong answer

A

Candidates may associate TFTP with network device configuration backups due to its common use for firmware upgrades and basic file transfers, overlooking its lack of security features.

B

Candidates may associate FTP with file transfers and overlook the encryption requirement, or mistakenly think FTP can be secured with implicit encryption like FTPS.

D

Candidates may assume HTTP can be used over HTTPS for encryption, but the question explicitly states HTTP (not HTTPS), and they might overlook the lack of encryption in HTTP.

171
MCQmedium

Which of the following protocols is used to automatically assign IP addresses to devices on a network and also provides the subnet mask and default gateway?

A.DNS
B.DHCP
C.ARP
D.ICMP
AnswerB

DHCP provides automatic IP configuration including subnet mask and default gateway.

Why this answer

DHCP (Dynamic Host Configuration Protocol) is the correct answer because it is specifically designed to automatically assign IP addresses to devices on a network, along with essential configuration parameters such as the subnet mask and default gateway. When a DHCP client sends a discover message, the DHCP server responds with an offer that includes these details, allowing the client to fully participate in network communication without manual configuration.

Exam trap

The N10-009 exam often tests the distinction between DHCP and DNS, where candidates mistakenly think DNS assigns IP addresses because it 'looks up' information, but DNS only resolves names, not addresses or subnet masks.

Why the other options are wrong

A

DNS resolves domain names to IP addresses, but does not assign IP addresses or provide subnet masks and default gateways.

C

ARP (Address Resolution Protocol) is used to resolve IP addresses to MAC addresses on a local network, not to assign IP addresses or provide subnet masks and default gateways.

D

ICMP is used for network diagnostics and error reporting (e.g., ping, traceroute), not for automatic IP address assignment or providing subnet mask and default gateway.

When would these options actually be correct?

A

A question asking which protocol translates human-readable domain names (like www.example.com) into IP addresses would have DNS as the correct answer.

C

A question asking 'Which protocol maps a known IP address to a MAC address on a local network?' would have ARP as the correct answer.

D

A question asking which protocol is used to test connectivity between devices or to report network errors (e.g., 'Which protocol does the ping command use?') would have ICMP as the correct answer.

Why candidates pick the wrong answer

A

Candidates may confuse DNS with DHCP because both involve IP addresses, but DNS is for name resolution, not automatic assignment.

C

Candidates may confuse ARP with DHCP because both operate at the network layer and are involved in network configuration, but ARP's role is address resolution, not assignment.

D

Candidates may confuse ICMP with DHCP because both are network-layer protocols, or they might think ICMP handles address configuration due to its role in network discovery tools.

172
MCQhard

A security administrator is configuring a firewall to allow remote employees to access the company's internal web server (port 443) from the internet. The web server has an internal IP address of 10.0.0.5. The firewall has a public IP of 203.0.113.10. Which type of firewall rule should be created?

A.A) Port forwarding (DNAT) rule
B.B) Allow rule with source any, destination 10.0.0.5, port 443
C.C) Access control list on the internal interface
D.D) VPN rule to require remote access VPN
AnswerA

Port forwarding, also known as Destination Network Address Translation (DNAT), is the correct solution because it modifies the destination IP address and port of incoming network packets. When an external client sends traffic to the firewall's public IP address on a specific port, the DNAT rule translates this public address and port to the internal private IP address and port of the target server. This allows the remote employees' traffic, destined for the public IP, to be correctly routed to the internal server within the private network, making the service externally accessible.

Why this answer

A port forwarding (DNAT) rule is required because the web server uses a private RFC 1918 IP address (10.0.0.5), which is not routable on the public internet. The firewall must translate the destination IP from its public address (203.0.113.10) to the internal server's private address, allowing inbound traffic on port 443 to reach the correct internal host.

Exam trap

The trap here is that candidates often confuse a simple 'allow' rule with the necessary NAT translation, failing to realize that without DNAT, the firewall has no way to forward the packet to the private IP address of the internal server.

Why the other options are wrong

C

An access control list on the internal interface would only control traffic already inside the network, not allow inbound connections from the internet to the internal web server. The firewall must translate the public IP to the private IP, which DNAT does.

D

The question asks for a firewall rule to allow remote employees to access the internal web server from the internet. A VPN rule is not required for simple port forwarding; it would be an unnecessary complication and not the direct solution for allowing access via port 443.

When would these options actually be correct?

C

This option would be correct if the question asked about controlling outbound traffic from the internal network to the internet, such as restricting which internal users can access external web servers on port 443.

D

A VPN rule would be correct if the scenario required secure, encrypted access to the entire internal network or multiple services, and the organization policy mandated that all remote access must go through a VPN for security compliance.

Why candidates pick the wrong answer

C

Candidates may think ACLs are the standard way to permit traffic, but they overlook that ACLs alone cannot handle the address translation needed for inbound traffic from the internet to a private IP.

D

Candidates may think that remote access always requires a VPN for security, overlooking that a simple DNAT rule with proper firewall policies can securely expose a single service like HTTPS.

173
MCQmedium

A security analyst notices that the DHCP server is responding to a large number of DHCP Discover messages from a single MAC address, but that client never sends a DHCP Request to complete the lease. This pattern repeats continuously. Which type of attack is most likely occurring?

A.ARP poisoning
B.DNS amplification
C.DHCP starvation
D.Rogue DHCP server
AnswerC

The scenario describes a classic DHCP starvation attack. The attacker floods the DHCP server with Discover messages, causing it to exhaust its address pool. Legitimate clients then cannot obtain IP addresses.

Why this answer

The described behavior—a single MAC address sending continuous DHCP Discover messages without completing the lease with a DHCP Request—is the hallmark of a DHCP starvation attack. The attacker exhausts the DHCP server's IP address pool by claiming all available leases, preventing legitimate clients from obtaining IP addresses. This attack targets the DHCP protocol's four-step DORA (Discover, Offer, Request, Acknowledge) process by never completing the handshake.

Exam trap

The trap here is that candidates confuse DHCP starvation with a rogue DHCP server attack, but the key distinction is that starvation exhausts the legitimate server's pool via incomplete handshakes, while a rogue server offers its own IPs to intercept traffic.

Why the other options are wrong

A

ARP poisoning involves manipulating ARP tables to intercept traffic, not flooding DHCP with Discover messages from a single MAC without completing the lease.

B

DNS amplification attacks exploit open DNS resolvers to flood a target with amplified traffic, not DHCP servers or MAC addresses. The question describes DHCP-specific behavior (Discover messages without Request), which is unrelated to DNS.

D

A rogue DHCP server attack involves an unauthorized server offering IP addresses, not a single MAC address repeatedly sending Discover messages without completing the lease. The described pattern of continuous Discover messages from one MAC is characteristic of DHCP starvation, not rogue server.

When would these options actually be correct?

A

A question describing a scenario where an attacker sends forged ARP replies to associate their MAC with the IP of a legitimate device, causing traffic to be misdirected, would make ARP poisoning the correct answer.

B

A question describing a network under a DDoS attack where the attacker sends small queries to open DNS resolvers with a spoofed source IP (the victim), causing large responses to overwhelm the victim. The key clue would be high bandwidth consumption and DNS traffic.

D

A question describing clients receiving incorrect IP configurations (e.g., wrong gateway or DNS) from an unauthorized DHCP server on the network, leading to connectivity issues or man-in-the-middle attacks. The correct answer would be 'Rogue DHCP server'.

Why candidates pick the wrong answer

A

Candidates may confuse DHCP starvation with ARP-based attacks because both involve MAC addresses and network exhaustion, but ARP poisoning targets layer 2 address resolution, not DHCP lease exhaustion.

B

Candidates may confuse 'amplification' with the repeated Discover messages, thinking the DHCP server is being used to amplify traffic, but DHCP starvation is about exhausting IP addresses, not traffic amplification.

D

Candidates may confuse DHCP starvation (exhausting IP pool) with a rogue DHCP server (offering malicious leases), as both involve DHCP abuse. The continuous Discover messages might be misattributed to a rogue server trying to respond, rather than a client flooding to deplete addresses.

174
MCQhard

A switch is connected to a network printer. The switch port is manually configured for 100 Mbps and full duplex. The printer is configured for auto-negotiation. The link is up, but there are many FCS errors on the switch port. What is the most likely cause?

A.Duplex mismatch
B.Bad Ethernet cable
C.Speed mismatch
D.Printer driver issues
AnswerA

The manually-configured full duplex setting forces the link to operate at full duplex, but the printer's auto-negotiation may negotiate half duplex, leading to a duplex mismatch and errors.

Why this answer

The most likely cause is a duplex mismatch. The switch port is manually set to full duplex, while the printer is using auto-negotiation. When one side is manually configured and the other is set to auto-negotiation, the auto-negotiating side fails to detect the manual setting and defaults to half duplex.

This mismatch causes collisions and frame check sequence (FCS) errors on the full-duplex side, as the half-duplex side does not properly handle simultaneous transmission.

Exam trap

CompTIA often tests the misconception that a speed mismatch causes FCS errors, but the trap here is that a speed mismatch prevents the link from coming up, while a duplex mismatch allows the link to be up but with errors.

Why the other options are wrong

B

FCS errors indicate frame corruption at Layer 2, often due to duplex mismatch causing collisions. A bad cable would cause link instability or CRC errors, but the link is up and stable, making cable issues less likely than duplex mismatch.

C

A speed mismatch would prevent the link from coming up entirely, or cause intermittent connectivity, not FCS errors on an active link. The link is up, so speed is negotiated correctly.

D

Printer driver issues would not cause FCS errors on the switch port. FCS errors indicate physical layer problems like collisions or duplex mismatches, not software or driver issues.

When would these options actually be correct?

B

A bad Ethernet cable would be correct if the question described intermittent link drops, excessive CRC errors, or the link not coming up at all, with both sides configured identically for speed and duplex.

C

If the link were down or flapping, and the switch port was set to a different speed (e.g., 1000 Mbps) while the printer auto-negotiated to 100 Mbps, speed mismatch would be the likely cause.

D

A question where a printer intermittently fails to print or prints garbled text, and the network connectivity is fine, would point to printer driver issues as the cause.

Why candidates pick the wrong answer

B

Candidates often default to blaming physical cabling for any errors, not realizing that FCS errors specifically point to duplex mismatch when one side is manually set and the other auto-negotiates.

C

Candidates may confuse speed and duplex negotiation, assuming that any mismatch in link parameters causes FCS errors, but speed mismatch typically prevents link establishment, not frame corruption.

D

Candidates may think that since the printer is involved, driver problems could affect network communication, but FCS errors are purely layer 1/2 issues unrelated to drivers.

175
MCQmedium

A network administrator has completed a scheduled firmware upgrade on a core switch. After verifying successful operation, which document should the administrator update to reflect the new firmware version?

A.Network logical topology diagram
B.Change management log
C.Rack diagram
D.Inventory management system
AnswerB

A change management log is the definitive record for all modifications made to network infrastructure, such as a core switch firmware upgrade. It meticulously documents the date, time, personnel involved, specific changes implemented, and often includes a rollback plan or verification steps. This log is crucial for maintaining network stability, ensuring compliance with organizational policies, and providing an essential audit trail for troubleshooting any post-change issues.

Why this answer

The change management log is the correct document to update because it records all modifications to the network, including firmware upgrades, along with details such as the date, reason, and new version. This log ensures compliance with ITIL change management processes and provides an audit trail for troubleshooting and future changes. Updating it after a successful firmware upgrade is a standard operational procedure to maintain accurate change history.

Exam trap

The N10-009 exam often tests the distinction between documentation types, and the trap here is that candidates confuse the inventory management system (which tracks hardware assets) with the change management log (which tracks operational changes), leading them to choose D instead of B.

Why the other options are wrong

A

The network logical topology diagram shows device connections and IP addressing, not firmware versions. Updating it after a firmware upgrade is not the standard procedure; the change management log is the correct document to record the new firmware version.

C

The rack diagram shows physical placement and cabling of equipment, not firmware versions. Updating it after a firmware upgrade is irrelevant because firmware is a software attribute, not a physical one.

D

The inventory management system tracks hardware assets and their configurations, but after a firmware upgrade, the immediate documentation update required is the change management log, which records the change details, approval, and verification steps.

When would these options actually be correct?

A

A network logical topology diagram would be the correct document to update after adding a new switch or changing network segments, as it reflects the physical or logical layout of the network.

C

When a question asks which document should be updated after physically relocating a device or changing its rack position (e.g., moving a switch from rack A to rack B), the rack diagram would be the correct answer.

D

This option would be correct in a question asking: 'After replacing a failed switch with a new one of the same model, which document should be updated to reflect the new serial number and asset tag?'

Why candidates pick the wrong answer

A

Candidates may think that any change to a device should be reflected in the topology diagram, but firmware versions are typically recorded in change management logs, not topology diagrams.

C

Candidates may confuse 'rack diagram' with a general documentation tool and think it should reflect all changes, including firmware, because they associate diagrams with any network change.

D

Candidates may think firmware version is a configuration detail that should be recorded in the inventory system, but inventory systems typically track hardware specs and asset info, not firmware versions, which are part of change management.

176
MCQmedium

A network administrator wants to centrally monitor the bandwidth utilization on a router's serial interface over time. The monitoring tool needs to periodically poll the router for current interface counters. Which protocol should be used for this polling?

A.SNMP
B.Syslog
C.NetFlow
D.ICMP
AnswerA

SNMP (Simple Network Management Protocol) is the industry-standard protocol for managing and monitoring network devices. It utilizes Management Information Bases (MIBs) to organize device parameters, including interface statistics like bytes in/out and packet counts. A network management station can periodically send SNMP GET requests to a router to retrieve these specific interface counters, enabling the calculation and central monitoring of bandwidth utilization over time on a serial interface.

Why this answer

SNMP (Simple Network Management Protocol) is the correct choice because it is specifically designed for polling network devices to retrieve operational statistics such as interface counters (e.g., ifInOctets, ifOutOctets) from a Management Information Base (MIB). The network administrator can configure an SNMP manager to periodically poll the router's serial interface OIDs, enabling centralized bandwidth utilization monitoring over time.

Exam trap

The N10-009 exam often tests the distinction between polling (SNMP) and push-based reporting (Syslog, NetFlow), and the trap here is that candidates confuse NetFlow's flow export capability with simple interface counter polling, or assume Syslog can be used for periodic data retrieval.

Why the other options are wrong

B

Syslog is used for logging and event messages, not for polling interface counters. It is a push-based protocol, whereas the question requires a pull-based mechanism to periodically poll for bandwidth utilization data.

C

NetFlow is used for traffic flow analysis and accounting, not for polling interface counters like bandwidth utilization. It exports flow data to a collector, whereas the question requires periodic polling of counters, which is SNMP's function.

D

ICMP is used for network diagnostics like ping and traceroute, not for polling interface counters or bandwidth utilization over time.

When would these options actually be correct?

B

Syslog would be correct if the question asked for a protocol to receive unsolicited log messages from network devices, such as error events or security alerts, for central monitoring and alerting.

C

A network administrator wants to analyze traffic patterns and identify top talkers on a router's serial interface over time. The monitoring tool needs to collect detailed flow records (source/destination IP, ports, protocols) for traffic engineering. NetFlow would be the correct protocol.

D

A question asking which protocol is used to test basic connectivity between two hosts, such as verifying if a remote device is reachable, would have ICMP as the correct answer.

Why candidates pick the wrong answer

B

Candidates may confuse Syslog with SNMP because both are used for network monitoring, but Syslog is for event logging, not for polling performance metrics like bandwidth utilization.

C

Candidates may confuse NetFlow's traffic monitoring capability with bandwidth monitoring, assuming it can provide utilization data. They might overlook that NetFlow is flow-based and not designed for polling interface counters like SNMP does.

D

Candidates may confuse ICMP's role in network monitoring (e.g., ping for reachability) with the need to poll interface statistics, assuming ICMP can provide bandwidth data.

177
MCQmedium

A network administrator is designing a Layer 2 network with redundant links between switches. Which protocol should be implemented to prevent loops in the network?

A.STP (Spanning Tree Protocol)
B.OSPF (Open Shortest Path First)
C.VRRP (Virtual Router Redundancy Protocol)
D.LACP (Link Aggregation Control Protocol)
AnswerA

Spanning Tree Protocol (STP) is fundamental for Layer 2 network stability, actively preventing switching loops that arise from redundant physical paths. It achieves this by dynamically placing specific ports into a blocking state, ensuring only one active logical path exists between any two network segments. This process, managed through Bridge Protocol Data Units (BPDUs), creates a loop-free tree topology, eliminating broadcast storms and MAC address table instability while still providing path redundancy in case of a link failure.

Why this answer

STP (Spanning Tree Protocol) is the correct choice because it is specifically designed to prevent Layer 2 loops in networks with redundant links. It achieves this by placing redundant switch ports into a blocking state, creating a loop-free logical topology while maintaining physical redundancy for failover.

Exam trap

The trap here is that candidates often confuse STP with VRRP or OSPF because both involve 'redundancy' and 'loop prevention,' but STP is the only protocol that operates at Layer 2 to prevent switching loops.

Why the other options are wrong

B

OSPF is a Layer 3 routing protocol used to exchange routes between routers, not a Layer 2 loop prevention mechanism. It does not operate at the data link layer and cannot prevent loops in a switched network.

C

VRRP is a First Hop Redundancy Protocol (FHRP) that provides gateway redundancy at Layer 3, not loop prevention at Layer 2. It does not prevent loops in a switched network.

D

LACP is used for link aggregation to combine multiple physical links into a single logical link for increased bandwidth and redundancy, but it does not prevent loops; it actually requires a loop-free topology to function correctly.

When would these options actually be correct?

B

A network administrator is designing a multi-area network with redundant Layer 3 paths between routers. Which protocol should be implemented to ensure loop-free routing and fast convergence?

C

A network administrator is designing a network with multiple routers providing default gateway services. Which protocol should be implemented to ensure high availability of the default gateway?

D

A network administrator needs to increase bandwidth and provide redundancy between two switches by combining multiple physical links into a single logical link. The correct protocol to implement would be LACP.

Why candidates pick the wrong answer

B

Candidates may confuse loop prevention in routing (Layer 3) with loop prevention in switching (Layer 2), or mistakenly think OSPF can handle all types of network loops.

C

Candidates may confuse VRRP's redundancy purpose with loop prevention, or think that any 'redundancy' protocol can handle loops.

D

Candidates may confuse LACP's redundancy feature with loop prevention, thinking that aggregating links automatically eliminates loops, but LACP does not handle loop prevention in a switched network with redundant paths.

178
MCQeasy

Which device is used to connect two different network segments and makes forwarding decisions based on IP addresses?

A.Switch
B.Router
C.Hub
D.Bridge
AnswerB

A router forwards packets based on IP addresses, connecting different networks.

Why this answer

A router is the correct device because it operates at Layer 3 (Network layer) of the OSI model and makes forwarding decisions based on destination IP addresses. It connects two different network segments (subnets) and uses routing tables to determine the best path for packet delivery, often employing protocols like OSPF or BGP.

Exam trap

The N10-009 exam often tests the distinction between Layer 2 and Layer 3 devices, trapping candidates who confuse a switch's MAC-based forwarding with a router's IP-based forwarding, especially when the question mentions 'different network segments'—a switch can segment collision domains but not broadcast domains, while a router segments broadcast domains.

Why the other options are wrong

A

A switch forwards frames based on MAC addresses, not IP addresses, and operates within a single network segment, not between different network segments.

C

A hub operates at Layer 1 (physical) and simply repeats electrical signals to all ports, making no forwarding decisions based on IP addresses.

D

A bridge connects two network segments but makes forwarding decisions based on MAC addresses, not IP addresses, and operates at Layer 2 of the OSI model.

When would these options actually be correct?

A

When the question asks which device connects devices within the same network segment and forwards frames based on MAC addresses, a switch is the correct answer.

C

When the question asks which device connects network segments but operates at Layer 1 and does not perform any filtering or forwarding logic (e.g., 'Which device extends a network by repeating signals without any intelligence?').

D

A bridge would be correct if the question asked: 'Which device connects two network segments and forwards frames based on MAC addresses?' or 'Which Layer 2 device is used to segment a collision domain?'

Why candidates pick the wrong answer

A

Candidates may confuse switches with routers because both are used for connectivity and make forwarding decisions, but they operate at different OSI layers.

C

Candidates may confuse hubs with switches or routers because all are used to connect devices, but they forget that hubs lack any addressing or decision-making capability.

D

Candidates may confuse bridges with routers because both connect network segments, but they forget that bridges operate at Layer 2 using MAC addresses, while routers operate at Layer 3 using IP addresses.

179
MCQhard

A network technician is troubleshooting an issue where Server A can ping Server B by IP address, but Server B cannot ping Server A. Both servers are in the same VLAN and subnet, connected to the same switch. The switch ports are configured identically, and there are no ACLs or firewalls between them. Which of the following is the MOST likely cause?

A.Server A's firewall is blocking incoming ICMP
B.Server B's firewall is blocking outgoing ICMP
C.The cable connecting Server A is faulty
D.There is a duplex mismatch on Server B's switch port
AnswerA

If Server A's firewall is configured to block incoming ICMP echo requests (ping), Server B's ping attempts to Server A will time out. However, if Server A initiates a ping to Server B, the firewall typically permits the outgoing ICMP echo request and allows the corresponding incoming ICMP echo reply, demonstrating full connectivity from Server A's perspective. This creates the observed one-way communication failure where Server B cannot reach Server A via ping, but Server A can reach Server B.

Why this answer

Server A can ping Server B by IP address, meaning ICMP echo requests from Server A reach Server B and echo replies return successfully. However, Server B cannot ping Server A, which indicates that ICMP echo requests from Server B are not reaching Server A or their replies are blocked. Since both servers are in the same VLAN/subnet with no ACLs or firewalls between them, the most likely cause is that Server A's host-based firewall is blocking incoming ICMP (echo requests), preventing Server B's pings from being processed.

This is a classic symptom of a one-way firewall rule that permits outbound ICMP but denies inbound ICMP.

Exam trap

CompTIA often tests the misconception that a firewall blocking outgoing ICMP on Server B would cause the symptom, but the correct reasoning is that the blocking must be on the target server (Server A) for incoming ICMP, creating a one-way ping scenario.

Why the other options are wrong

B

Server B can ping Server A by IP, meaning ICMP traffic from B to A works. If B's firewall blocked outgoing ICMP, B could not send pings to A, contradicting the given success.

C

A faulty cable on Server A would cause both directions of communication to fail, but Server A can ping Server B successfully, indicating the cable is functional.

When would these options actually be correct?

B

In a scenario where Server A cannot ping Server B by IP, but Server B can ping Server A, and both are in the same VLAN/subnet with no ACLs, Server B's firewall blocking outgoing ICMP would explain why A's pings fail while B's succeed.

C

In a scenario where both servers cannot communicate in either direction (e.g., no pings succeed), and physical inspection shows damage or link lights are off, a faulty cable on one server would be the likely cause.

Why candidates pick the wrong answer

B

Candidates may confuse the direction of firewall rules, assuming that if one server cannot ping, the other's firewall must be blocking outgoing traffic, without tracing the actual ICMP flow.

C

Candidates may assume that a one-way communication issue is due to a physical layer problem, overlooking that a cable fault typically affects all traffic on that link.

180
MCQeasy

A security analyst notices that the company's web server is receiving a high volume of TCP SYN packets from a single source IP address, but the server is not completing the three-way handshake. Which type of attack is most likely occurring?

A.A) SYN flood
B.B) Smurf attack
C.C) Ping of death
D.D) ARP poisoning
AnswerA

A SYN flood is a classic Denial-of-Service (DoS) attack that exploits the TCP three-way handshake. The attacker sends a large volume of TCP SYN requests with spoofed source IP addresses to a target server. The server responds with SYN-ACK packets and allocates resources for each half-open connection, awaiting a final ACK that never arrives. This eventually exhausts the server's connection table and prevents legitimate connections from being established.

Why this answer

A SYN flood attack exploits the TCP three-way handshake by sending a high volume of SYN packets from a spoofed or single source IP without completing the handshake. The server allocates resources for each half-open connection, eventually exhausting its connection table and denying service to legitimate users. This matches the scenario where the server receives many SYN packets but never completes the handshake.

Exam trap

CompTIA often tests the distinction between a SYN flood and a Smurf attack by describing a flood of packets from a single source—candidates confuse the ICMP-based Smurf attack with the TCP-based SYN flood because both involve flooding, but the protocol and mechanism are completely different.

Why the other options are wrong

B

A Smurf attack uses ICMP echo requests (pings) to a broadcast address, causing all hosts on the network to reply to a spoofed victim IP, overwhelming it with ICMP replies, not TCP SYN packets.

C

A ping of death attack involves sending oversized or malformed ICMP packets to crash a system, not a high volume of TCP SYN packets that fail to complete the three-way handshake.

D

ARP poisoning manipulates the ARP cache to intercept traffic on a local network, not to flood a web server with TCP SYN packets from a single source.

When would these options actually be correct?

B

A Smurf attack would be correct if the question described a high volume of ICMP echo reply packets (or ping replies) overwhelming a target, or if the attack involved sending ICMP echo requests to a network broadcast address with a spoofed source IP.

C

This option would be correct in a question describing a server crashing or becoming unresponsive after receiving a single oversized ICMP echo request packet, or a series of fragmented ICMP packets that reassemble into a packet larger than 65535 bytes.

D

An exam question describing an attacker sending forged ARP replies to associate their MAC address with the default gateway's IP, causing traffic to be redirected to the attacker, would make ARP poisoning the correct answer.

Why candidates pick the wrong answer

B

Candidates may confuse any high-volume network attack with a Smurf attack, or they might think 'SYN flood' is too obvious and second-guess themselves, choosing a less familiar term.

C

Candidates may confuse any attack that overwhelms a server with 'ping of death' because both involve network flooding, but they fail to distinguish between ICMP-based attacks and TCP SYN floods.

D

Candidates may confuse network-layer attacks (ARP poisoning) with transport-layer attacks (SYN flood) due to a lack of understanding of the TCP/IP model layers.

181
MCQmedium

A network administrator is configuring a trunk link between a switch and a router to support multiple VLANs. The switch's trunk port is set to dot1q encapsulation. Which configuration must match on the router to ensure proper communication?

A.The IP address of the router interface must be in the same subnet as the management VLAN
B.The subinterface encapsulation must match the switch's native VLAN default
C.The native VLAN on the router subinterface must be consistent with the switch's native VLAN
D.The router must be configured with inter-VLAN routing static routes
AnswerC

When configuring an 802.1Q trunk link between a switch and a router, the native VLAN configuration must be identical on both devices. The native VLAN carries untagged frames across the trunk, meaning these frames are not encapsulated with an 802.1Q tag. If the native VLANs differ, frames sent untagged by one device will be interpreted as belonging to a different VLAN by the other, leading to communication failures and potential security vulnerabilities where traffic might be misdirected or dropped.

Why this answer

The native VLAN on the router subinterface must match the switch's native VLAN to ensure untagged frames are handled consistently. On a dot1q trunk, the native VLAN is the only VLAN whose frames are sent untagged; if the router expects a different native VLAN, it will drop or misclassify those frames, breaking communication for that VLAN.

Exam trap

The trap here is that candidates often confuse 'native VLAN' with 'default VLAN' or think the encapsulation type (dot1q) alone is sufficient, overlooking the critical requirement that the native VLAN must be explicitly matched on both sides of the trunk.

Why the other options are wrong

A

The router interface's IP address does not need to match the management VLAN subnet; trunk links carry multiple VLANs, and the router subinterface IPs correspond to their respective VLANs, not the management VLAN.

B

The subinterface encapsulation must match the switch's trunk encapsulation (dot1q), not the native VLAN default. The native VLAN is a separate concept from encapsulation type.

D

Inter-VLAN routing static routes are not required for trunk link communication; the router uses subinterfaces with 802.1Q encapsulation to route between VLANs directly.

When would these options actually be correct?

A

If the question asked about configuring the router interface for management access to the switch (e.g., telnet/SSH), then the router's IP must be in the same subnet as the management VLAN to reach the switch's management IP.

B

If the question asked about ensuring the router subinterface uses the same VLAN ID as the switch's native VLAN for untagged traffic, then matching the native VLAN default would be correct. For example, if the switch's native VLAN is VLAN 1, the router subinterface must also be configured with native VLAN 1.

D

In a scenario where the router is not directly connected to the switch but is reachable via another router, static routes would be needed to direct traffic between VLANs across the network.

Why candidates pick the wrong answer

A

Candidates often confuse management VLAN addressing with general trunk configuration, assuming the router must be on the same subnet as the switch's management interface for any VLAN communication.

B

Candidates may confuse 'encapsulation' with 'native VLAN' because both are configured on subinterfaces and involve VLAN tagging, leading them to think the encapsulation value must match the native VLAN ID.

D

Candidates may confuse the need for routing between VLANs with the specific configuration of a trunk link, assuming static routes are always necessary for inter-VLAN communication.

182
MCQmedium

A network administrator is configuring a new WAN link between two offices using MPLS. Which of the following is a characteristic of MPLS?

A.It uses label switching to forward packets
B.It requires a dedicated point-to-point circuit
C.It operates at Layer 7 of the OSI model
D.It encrypts all data in transit
AnswerA

MPLS fundamentally enhances packet forwarding efficiency by utilizing short, fixed-length labels instead of relying solely on complex IP header lookups. Label Switch Routers (LSRs) within an MPLS domain assign these labels to incoming packets, then swap them at each hop, directing traffic along pre-established Label Switched Paths (LSPs). This label-based forwarding significantly reduces lookup overhead compared to traditional longest-prefix-match IP routing, leading to faster and more predictable data delivery across the WAN.

Why this answer

MPLS (Multiprotocol Label Switching) operates by attaching short, fixed-length labels to packets at the ingress router. These labels are used by intermediate routers (LSRs) to make forwarding decisions based on the label rather than the IP header, which enables faster switching and traffic engineering. This label-swapping mechanism is the defining characteristic of MPLS, distinguishing it from traditional IP routing.

Exam trap

The trap here is that candidates confuse MPLS with a dedicated leased line or assume it provides security features like encryption, when in fact MPLS is a label-switching technology that operates below Layer 3 and above Layer 2.

Why the other options are wrong

B

MPLS does not require a dedicated point-to-point circuit; it can operate over various underlying transport technologies like Ethernet, Frame Relay, or IP networks, using label switching to create virtual paths.

C

MPLS operates at Layer 2.5 (between Layer 2 and Layer 3), not at Layer 7. It uses labels for forwarding, not application-layer processing.

D

MPLS does not inherently encrypt data; it is a label-switching mechanism that operates at Layer 2.5, and encryption (e.g., IPsec) is an optional add-on, not a characteristic of MPLS itself.

When would these options actually be correct?

B

In a question asking about a characteristic of a leased line or dedicated WAN connection (e.g., T1, E1), where the correct answer would be that it requires a dedicated point-to-point circuit.

C

In a question about a device or protocol that inspects or modifies application data, such as 'Which layer does a web application firewall operate at?' or 'Which OSI layer corresponds to application protocols like HTTP?'

D

In a question asking 'Which of the following is a characteristic of IPsec VPNs?' or 'Which technology provides encryption for WAN links?', option D would be correct because IPsec encrypts all data in transit.

Why candidates pick the wrong answer

B

Candidates may confuse MPLS with traditional WAN technologies like leased lines, which do require dedicated circuits, and assume all WAN links are point-to-point.

C

Candidates may confuse MPLS with higher-layer services like encryption or application-aware routing, or mistakenly think 'label switching' involves deep packet inspection at the application layer.

D

Candidates may confuse MPLS with VPN technologies that include encryption, or assume that any secure WAN link must encrypt data, overlooking that MPLS relies on provider network isolation rather than encryption.

183
MCQhard

A security analyst notices that an attacker is sending crafted packets with overlapping IP fragments to a target server, causing the server to crash. Which type of attack is described?

A.Teardrop attack
B.Smurf attack
C.Ping flood
D.SYN flood
AnswerA

The Teardrop attack is a denial-of-service (DoS) attack that exploits vulnerabilities in the reassembly of fragmented IP packets. Attackers send crafted IP fragments with overlapping or oversized offset fields, causing the target system to crash or reboot when it attempts to reconstruct the malformed datagram. This manipulation of IP fragmentation logic prevents proper packet processing and disrupts network services, directly matching the description of an attacker sending crafted packets.

Why this answer

This is a Teardrop attack, which exploits a vulnerability in the IP fragmentation reassembly process. The attacker sends a series of fragmented IP packets with intentionally overlapping fragment offsets, causing the target system to miscalculate the size of the reassembled packet, leading to a buffer overflow and system crash. This attack specifically targets the IP stack's handling of fragment offset fields in the IP header.

Exam trap

CompTIA often tests the distinction between attacks that exploit protocol logic flaws (like Teardrop) versus volumetric or handshake-based attacks, so candidates may confuse Teardrop with a SYN flood because both can cause crashes, but the key difference is that Teardrop targets IP fragmentation, not TCP state exhaustion.

Why the other options are wrong

B

The Smurf attack involves sending ICMP echo requests with a spoofed source IP to a network's broadcast address, causing amplification and flooding the victim, not using overlapping IP fragments to crash a server.

C

A ping flood involves overwhelming a target with ICMP Echo Request packets, not crafted packets with overlapping IP fragments that cause a crash due to reassembly errors.

D

A SYN flood attack involves sending many TCP SYN requests to exhaust server resources, not sending crafted packets with overlapping IP fragments.

When would these options actually be correct?

B

A Smurf attack would be correct if the question described an attacker sending ICMP echo requests to a network broadcast address with a spoofed source IP, causing all hosts to reply to the victim and overwhelming it with traffic.

C

A ping flood would be correct if the question described an attacker sending a high volume of ICMP Echo Request packets to consume bandwidth or CPU resources, potentially causing denial of service.

D

A SYN flood would be correct if the question described an attacker sending a high volume of TCP SYN packets to a server, overwhelming its connection queue and causing denial of service.

Why candidates pick the wrong answer

B

Candidates may confuse any attack that causes a denial of service with the Smurf attack, especially if they recall it involves IP-based flooding, but they miss the specific mechanism of overlapping fragments unique to teardrop.

C

Candidates may confuse any network-based DoS attack with a ping flood, as ping is a common tool and the term 'flood' is broadly associated with overwhelming traffic.

D

Candidates may confuse SYN flood with any attack that causes a server to crash, overlooking the specific mention of overlapping IP fragments which is characteristic of a teardrop attack.

184
MCQhard

A network administrator has configured a switch with four VLANs: VLAN 10, 20, 30, and 99 (native). The switch is connected to a router via an 802.1Q trunk link. The router has subinterfaces for VLANs 10, 20, and 30, each with an IP address. VLAN 99 is used for management and does not have a router subinterface. How many Layer 3 broadcast domains exist in this network?

A.1
B.2
C.3
D.4
AnswerC

Correct. Only VLANs with a router subinterface (10, 20, 30) create Layer 3 broadcast domains. VLAN 99 (native) has no subinterface, so it does not form a Layer 3 domain.

Why this answer

A Layer 3 broadcast domain corresponds to a routed IP subnet. Without a router subinterface, VLAN 99 has no Layer 3 termination, so only VLANs 10, 20, and 30 (with subinterfaces) form separate broadcast domains. Thus, there are 3 Layer 3 broadcast domains.

Exam trap

Candidates often assume every VLAN forms a Layer 3 broadcast domain, but without a router subinterface (or equivalent L3 termination) a VLAN only creates a Layer 2 broadcast domain.

Why the other options are wrong

A

Each VLAN is a separate Layer 3 broadcast domain. With VLANs 10, 20, 30, and 99, there are four broadcast domains, not one.

B

Each VLAN is a separate Layer 3 broadcast domain. VLANs 10, 20, and 30 each have a router subinterface, and VLAN 99 is a native VLAN without a subinterface, but it still constitutes its own broadcast domain because it is a distinct VLAN. Thus, there are 4 broadcast domains, not 2.

When would these options actually be correct?

A

If the switch had no VLANs configured (single flat network) and the router had a single interface with one IP address, there would be one Layer 3 broadcast domain.

B

If the question stated that VLAN 99 is not used and the trunk only carries VLANs 10, 20, and 30, and the router has subinterfaces for only two of them (e.g., VLAN 10 and 20), then there would be 2 Layer 3 broadcast domains (one per subinterface).

Why candidates pick the wrong answer

A

Candidates may think all traffic passes through a single router interface, overlooking that each VLAN creates its own broadcast domain even without a subinterface.

B

Candidates may mistakenly think that only VLANs with router subinterfaces create broadcast domains, ignoring the native VLAN's separate broadcast domain, or they may incorrectly assume the native VLAN is part of another VLAN's domain.

185
MCQeasy

A company is extending its network to a new building located 200 meters away. The link must support 1 Gbps speeds. Which cabling type should be used?

A.Cat5e
B.Cat6
C.Single-mode fiber
D.Coaxial cable
AnswerC

Single-mode fiber is the optimal choice for extending a 1 Gbps network 200 meters. It utilizes a very small core (typically 9 microns) that allows only a single path for light to travel, significantly minimizing modal dispersion. This characteristic enables single-mode fiber to support high bandwidths, such as 1 Gbps, over distances ranging from several kilometers to tens of kilometers, far exceeding the 200-meter requirement with superior reliability.

Why this answer

Single-mode fiber (SMF) is the correct choice because it supports 1 Gbps speeds over distances far exceeding 200 meters, typically up to 5 km or more using 1000BASE-LX optics. Copper cabling like Cat5e and Cat6 is limited to a maximum segment length of 100 meters for 1 Gbps (1000BASE-T), making them unsuitable for this 200-meter link.

Exam trap

The trap here is that candidates often assume Cat6 can exceed 100 meters because it supports higher frequencies (250 MHz vs. 100 MHz for Cat5e), but the 100-meter distance limit for 1000BASE-T is a physical layer standard constraint, not a cable grade limitation.

Why the other options are wrong

A

Cat5e supports 1 Gbps only up to 100 meters; the required distance is 200 meters, exceeding its maximum segment length.

B

Cat6 cabling has a maximum recommended distance of 100 meters for 1 Gbps, but the link requires 200 meters, exceeding this limit.

D

Coaxial cable cannot support 1 Gbps speeds over 200 meters; it is typically limited to lower speeds and shorter distances, and is not suitable for modern high-speed Ethernet.

When would these options actually be correct?

A

A question asking for a cost-effective cabling solution for a 1 Gbps link within 100 meters (e.g., connecting two floors in the same building) would make Cat5e correct.

B

This option would be correct for a link under 100 meters requiring 1 Gbps, such as connecting a server to a switch within the same data center.

D

Coaxial cable would be correct for a question requiring a connection for cable TV or broadband internet (e.g., DOCSIS) over distances up to 500 meters, or for legacy Ethernet (10BASE2/10BASE5) at 10 Mbps.

Why candidates pick the wrong answer

A

Candidates may remember that Cat5e supports 1 Gbps and overlook the distance limitation, assuming it works for any length.

B

Candidates may assume Cat6 is sufficient for 1 Gbps without considering the distance limitation, as it is a common choice for high-speed Ethernet in shorter runs.

D

Candidates may recall coaxial cable being used for networking in the past or for long-distance video transmission, mistakenly believing it can handle gigabit speeds over long runs.

186
MCQmedium

A network engineer configures an 802.1Q trunk between two switches. The trunk is up, but VLAN 10 traffic is not passing. The engineer checks and confirms that VLAN 10 exists on both switches. The show interfaces trunk command displays 'allowed VLANs: none'. What is the most likely cause?

A.The trunk encapsulation is not set to dot1q
B.The native VLAN mismatch
C.The allowed VLAN list is empty
D.VLAN 10 is not created on one of the switches
AnswerC

The explicit output "allowed VLANs: none" directly indicates that the trunk port is currently configured to permit no VLANs to traverse it. Even if VLAN 10 exists on both switches, it cannot pass traffic across this trunk until it is explicitly added to the allowed VLAN list for that interface. This configuration prevents any tagged or untagged traffic from being forwarded over the trunk, effectively isolating the connected network segments.

Why this answer

The 'show interfaces trunk' output showing 'allowed VLANs: none' explicitly indicates that the allowed VLAN list on the trunk has been manually cleared or set to none, which blocks all VLAN traffic including VLAN 10. Even though VLAN 10 exists on both switches, the trunk port's VLAN filter prevents any frames from being forwarded. This is the most direct cause of the issue.

Exam trap

CompTIA often tests the distinction between 'VLAN not created' and 'VLAN not allowed on trunk' — the trap here is that candidates assume VLAN 10 not passing must mean it doesn't exist on one switch, ignoring that the trunk's allowed VLAN list can independently block traffic even when the VLAN is present on both sides.

Why the other options are wrong

A

The trunk is up and the 'show interfaces trunk' output shows 'allowed VLANs: none', which directly indicates an empty allowed VLAN list, not an encapsulation issue. If the encapsulation were wrong, the trunk would not form or would show encapsulation mismatch errors.

D

The question states that VLAN 10 exists on both switches, so this option is factually incorrect based on the given information.

When would these options actually be correct?

A

In a scenario where a trunk fails to form or comes up but does not pass any traffic, and 'show interfaces trunk' does not show 'allowed VLANs: none' but instead shows the trunk is down or not operational, the most likely cause could be an encapsulation mismatch (e.g., one side set to dot1q and the other to ISL).

D

If the question stated that VLAN 10 traffic is not passing and the engineer did not verify VLAN existence, or if the show vlan command showed VLAN 10 missing on one switch, then this would be the correct answer.

Why candidates pick the wrong answer

A

Candidates often confuse trunk configuration issues; they know that 802.1Q encapsulation is required for VLAN tagging, so they assume an encapsulation mismatch is the problem without checking the allowed VLAN list first.

D

Candidates may assume that VLAN traffic issues are often due to missing VLAN definitions, especially when troubleshooting inter-switch connectivity.

187
MCQhard

A security analyst detects a large number of DNS queries for the same domain from multiple internal hosts. The responses contain large payloads. Which type of attack is likely occurring?

A.DNS cache poisoning
B.DNS amplification
C.DNS tunneling
D.DNS zone transfer
AnswerB

DNS amplification is a type of Distributed Denial-of-Service (DDoS) attack where attackers leverage vulnerable open DNS resolvers to flood a target with an overwhelming volume of traffic. The attacker spoofs the victim's IP address as the source for small DNS queries sent to numerous open resolvers. These resolvers then send much larger DNS responses back to the spoofed victim, effectively multiplying the attack's bandwidth and overwhelming the target's network capacity.

Why this answer

DNS amplification is a type of reflection-based DDoS attack where an attacker sends a small query (e.g., ANY or DNSSEC-signed record request) with a spoofed source IP (the victim's address) to an open DNS resolver. The resolver responds with a large payload (often 50–100x larger than the query), flooding the victim's network. The scenario describes many internal hosts making queries to the same domain and receiving large responses, which matches the amplification effect from a compromised or misconfigured internal resolver.

Exam trap

CompTIA often tests the distinction between DNS amplification and DNS cache poisoning by describing 'large payloads' and 'many hosts' — the trap is that candidates confuse the reflection/amplification mechanism with the cache corruption of poisoning, but amplification focuses on traffic volume, not record integrity.

Why the other options are wrong

A

DNS cache poisoning involves corrupting the resolver's cache with false records, not causing large responses to many queries from internal hosts. The large payloads indicate amplification, not cache manipulation.

C

DNS tunneling typically involves encoding data in DNS queries or responses for covert communication, not large payloads from many hosts querying the same domain. The scenario describes many hosts querying the same domain with large responses, which is characteristic of amplification, not tunneling.

D

DNS zone transfer is a mechanism for replicating DNS databases between servers, not an attack that generates many queries with large payloads from internal hosts.

When would these options actually be correct?

A

A question describing a scenario where users are redirected to a malicious site after a DNS resolver returns incorrect IP addresses, with no mention of large response sizes or multiple internal hosts, would make cache poisoning correct.

C

A question describing a single host sending many DNS queries to exfiltrate data or establish a command-and-control channel, where the DNS responses contain encoded data, would make DNS tunneling the correct answer.

D

A question describing an unauthorized attempt to copy the entire DNS zone file from a DNS server to an external host, often using AXFR requests, would make DNS zone transfer the correct answer.

Why candidates pick the wrong answer

A

Candidates may confuse any DNS-based attack with cache poisoning, especially if they recall it as a common threat, without recognizing the specific indicator of large response payloads characteristic of amplification.

C

Candidates may confuse the large payloads in DNS responses with data exfiltration or covert channels, leading them to think of tunneling instead of the amplification attack's reflection and amplification characteristics.

D

Candidates may confuse the term 'zone transfer' with any large-scale DNS data movement, or mistakenly think that large payloads imply data exfiltration via zone transfers.

188
MCQeasy

A company is deploying a new wireless network in a warehouse. The network administrator needs to ensure that clients can seamlessly roam between access points without losing connectivity. Which of the following should be configured?

A.A) Same SSID and security settings on all APs
B.B) Different channels per AP to reduce interference
C.C) WPA2-Enterprise with RADIUS authentication
D.D) Mesh topology for AP interconnection
AnswerA

To enable seamless client roaming across a multi-AP environment like a warehouse, all Access Points (APs) must broadcast the identical Service Set Identifier (SSID). Furthermore, consistent security settings, whether WPA2-Personal with a shared passphrase or WPA2-Enterprise with 802.1X, are crucial. This uniformity allows client devices to perceive the network as a single entity, facilitating rapid re-association with the strongest available AP without requiring manual intervention or re-authentication from the user.

Why this answer

Configuring the same SSID and security settings on all access points (APs) is essential for seamless roaming because clients use the SSID to identify the network and the security credentials to authenticate. When a client moves between APs, it can re-associate without needing to re-authenticate or discover a new network, provided the SSID and security parameters (e.g., PSK or 802.1X configuration) are identical. This ensures a smooth handoff and maintains connectivity during roaming.

Exam trap

The trap here is that candidates often confuse the need for different channels (to avoid interference) with the requirement for seamless roaming, or they assume that enterprise authentication (WPA2-Enterprise) is mandatory for roaming, when in fact the core requirement is simply consistent SSID and security settings across all APs.

Why the other options are wrong

C

WPA2-Enterprise with RADIUS authentication provides strong security but does not directly affect seamless roaming; roaming is primarily enabled by consistent SSID and security settings across APs.

D

While mesh topology can extend coverage, it does not inherently ensure seamless roaming; clients may still experience connectivity loss during handoff if APs are not configured with the same SSID and security settings.

When would these options actually be correct?

C

A company requires centralized authentication for wireless users, with per-user credentials and logging. The question asks for the best authentication method to secure the network and manage user access, making WPA2-Enterprise with RADIUS the correct choice.

D

A company needs to extend wireless coverage to a remote area without running Ethernet cables, and the APs must self-configure and route traffic wirelessly. In this scenario, configuring a mesh topology would be the correct answer.

Why candidates pick the wrong answer

C

Candidates may confuse security features with roaming capabilities, assuming that enterprise authentication inherently supports seamless roaming, or they may overestimate the role of RADIUS in handoff processes.

D

Candidates may confuse mesh topology with seamless roaming because mesh networks can provide continuous coverage, but they overlook that roaming requires consistent SSID and security parameters across APs.

189
MCQmedium

A network engineer is planning a wireless LAN for an open office with 50 users. To maximize performance by using multiple non-overlapping channels, which frequency band should be primarily used?

A.2.4 GHz
B.5 GHz
C.6 GHz
D.900 MHz
AnswerB

For an open office with 50 users, high density and performance are key. The 5 GHz band offers significantly more non-overlapping channels (e.g., 23 in the U.S. for 20 MHz channels) compared to 2.4 GHz. This abundance of channels facilitates robust channel planning, minimizes co-channel interference between access points, and supports higher data rates for numerous concurrent users, making it ideal for high-density WLANs in office environments.

Why this answer

The 5 GHz band is the best choice for maximizing performance in an open office with 50 users because it offers up to 23 non-overlapping channels (using 20 MHz channels) compared to only 3 in the 2.4 GHz band. This allows for better channel reuse, reduced co-channel interference, and higher aggregate throughput in a dense user environment.

Exam trap

The N10-009 exam often tests the misconception that more channels always mean better performance, but the trap here is that candidates may overlook client device compatibility and regulatory availability when considering the 6 GHz band, or they may incorrectly assume the 2.4 GHz band's longer range is beneficial for high-density performance.

Why the other options are wrong

A

The 2.4 GHz band has only three non-overlapping channels (1, 6, 11), limiting performance in high-density environments like an open office with 50 users. The 5 GHz band offers many more non-overlapping channels, reducing co-channel interference.

C

The 6 GHz band (Wi-Fi 6E) offers many non-overlapping channels, but the question asks for the band to be 'primarily used' in an open office with 50 users. While 6 GHz provides high capacity, its shorter range and poorer penetration through obstacles make it less suitable as the primary band for general coverage in an open office compared to 5 GHz, which balances range and channel availability.

D

The 900 MHz band offers very limited non-overlapping channels (typically 1-2) and low data rates, making it unsuitable for maximizing performance in a dense 50-user open office environment.

When would these options actually be correct?

A

A question asking for the best frequency band for maximum range or wall penetration in a large, sparsely populated area (e.g., a warehouse with few users) would make 2.4 GHz correct due to its lower attenuation and better obstacle penetration.

C

A question specifying a high-density environment with many Wi-Fi 6E-capable devices and a need for maximum throughput with minimal interference, where coverage range is less critical (e.g., a conference room or auditorium with devices close to access points).

D

A question asking for the best frequency band for long-range, low-data-rate IoT sensor networks or rural outdoor coverage where wall penetration and distance are prioritized over throughput.

Why candidates pick the wrong answer

A

Candidates may recall that 2.4 GHz has better range and penetration, but overlook that the question emphasizes 'multiple non-overlapping channels' and 'maximize performance' in a dense user environment, where channel availability is critical.

C

Candidates may know that 6 GHz offers the most non-overlapping channels and highest capacity, leading them to choose it without considering the practical limitations of range and device support in a typical open office.

D

Candidates may mistakenly think lower frequency always means better performance due to better range, or confuse 900 MHz with the 900 MHz ISM band used in some legacy or specialized applications.

190
MCQeasy

At which layer of the OSI model does end-to-end communication and data segmentation occur?

A.Session layer
B.Transport layer
C.Network layer
D.Data link layer
AnswerB

The Transport layer is crucial for establishing logical end-to-end communication between specific application processes running on different hosts. It segments data from the Application layer, adding headers that include port numbers to identify these processes. This layer ensures reliable, ordered delivery via TCP, or provides faster, connectionless delivery with UDP, managing flow control and error recovery for the entire communication session between the two endpoints.

Why this answer

The transport layer (Layer 4) is responsible for end-to-end communication between source and destination hosts, as well as data segmentation and reassembly. Protocols such as TCP and UDP operate at this layer, with TCP providing reliable, connection-oriented service by segmenting data into segments and managing flow control and error recovery.

Exam trap

The trap here is that candidates confuse the transport layer's end-to-end communication with the network layer's end-to-end delivery of packets, forgetting that Layer 4 provides logical communication between processes (ports) while Layer 3 provides logical communication between hosts (IP addresses).

Why the other options are wrong

A

The session layer manages sessions (establish, maintain, terminate) but does not handle end-to-end communication or data segmentation; those are transport layer functions.

C

The Network layer (Layer 3) handles routing and logical addressing, not end-to-end communication and data segmentation, which are functions of the Transport layer.

D

The data link layer handles node-to-node communication and framing, not end-to-end communication or data segmentation, which are functions of the transport layer.

When would these options actually be correct?

A

A question asking 'At which OSI layer does dialog control and session management occur?' would make the session layer correct.

C

A question asking 'At which layer does routing and logical addressing occur?' would make the Network layer the correct answer.

D

In a question asking 'At which layer does error detection and correction using MAC addresses occur?' or 'Which layer is responsible for framing and media access control?', the data link layer would be correct.

Why candidates pick the wrong answer

A

Candidates confuse 'session' with 'connection' and think session layer manages end-to-end communication, not realizing that role belongs to the transport layer.

C

Candidates may confuse the Network layer's role in end-to-end delivery of packets with the Transport layer's end-to-end communication, or think segmentation happens at Layer 3 due to packet fragmentation.

D

Candidates may confuse the data link layer's role in local network delivery with end-to-end communication, or they might think segmentation occurs at a lower layer due to packet fragmentation at the network layer.

191
MCQeasy

A network device receives a frame on one port and forwards it out to all other ports. The device does not examine the destination MAC address. Which type of device is being described?

A.Switch
B.Hub
C.Bridge
D.Router
AnswerB

A hub operates at the Physical layer (Layer 1) of the OSI model, functioning as a multi-port repeater. When a hub receives an electrical signal (representing a frame) on one port, it simply regenerates that signal and broadcasts it out to all other connected ports, without inspecting any MAC address information. It has no intelligence to make forwarding decisions, effectively creating a single collision domain where all connected devices share the same bandwidth.

Why this answer

A hub operates at Layer 1 (physical layer) of the OSI model and simply repeats incoming electrical or optical signals out all other ports without any processing of the frame's destination MAC address. This behavior matches the description exactly: the device receives a frame on one port and forwards it out all other ports without examining the MAC address.

Exam trap

The N10-009 exam often tests the distinction between Layer 1 (hub) and Layer 2 (switch/bridge) devices by describing the 'flooding' behavior of a switch when the MAC address is unknown, which can trick candidates into thinking a switch forwards to all ports without examining the MAC address, but a switch always examines the destination MAC address first.

Why the other options are wrong

A

A switch examines the destination MAC address to forward frames only to the appropriate port, not to all ports, unlike the device described.

C

Bridges examine destination MAC addresses to decide whether to forward or filter frames, and they do not flood frames out all ports unless the address is unknown. This question describes a device that forwards all frames out all ports without examining MAC addresses, which is a hub, not a bridge.

D

Routers operate at Layer 3 and examine destination IP addresses to make forwarding decisions, not MAC addresses. They do not forward frames out all ports without inspection.

When would these options actually be correct?

A

This option would be correct if the question described a device that forwards frames based on destination MAC addresses and maintains a MAC address table to filter traffic, such as 'Which device uses MAC addresses to forward frames only to the intended recipient?'

C

A bridge would be the correct answer if the question described a device that uses MAC addresses to segment collision domains and forwards frames only to the appropriate port based on the destination MAC address, or if the question asked about a device that connects two network segments and filters traffic.

D

A router would be the correct answer for a question describing a device that forwards packets based on destination IP address, connects different networks, and uses routing tables to determine the best path.

Why candidates pick the wrong answer

A

Candidates may confuse hubs with switches because both are used to connect multiple devices in a LAN, but they forget that switches intelligently forward frames based on MAC addresses.

C

Candidates may confuse bridges with hubs because both are legacy devices used to connect network segments, but they forget that bridges perform MAC address learning and filtering, whereas hubs simply repeat signals.

D

Candidates may confuse the behavior of a hub with that of a router because both can forward traffic to multiple ports, but they operate at different layers and have distinct forwarding logic.

192
MCQmedium

A network administrator needs to upgrade the firmware on a core switch. According to change management best practices, which step should be performed first?

A.Download the new firmware
B.Create a backup of the current configuration
C.Submit a change request
D.Schedule a maintenance window
AnswerC

Submitting a change request is the foundational first step in any structured change management process for critical infrastructure like a core switch. This formal submission outlines the proposed change, its justification, potential impact, and required resources, allowing stakeholders to review and approve it. This ensures that all modifications are properly vetted, documented, and authorized, minimizing risks to network stability and service continuity before any physical or logical action is taken.

Why this answer

According to change management best practices, the first step in any network change is to submit a change request (option C). This ensures the proposed firmware upgrade is reviewed, approved, and documented before any technical actions are taken, reducing the risk of unplanned outages and providing a rollback plan. Skipping this step violates ITIL/change management frameworks and can lead to unauthorized changes that impact network stability.

Exam trap

The trap here is that candidates often confuse operational best practices with technical steps, assuming that backing up the configuration (option B) is always the first action, but change management mandates that formal authorization precedes any technical work, even backups, to ensure proper governance and audit trails.

Why the other options are wrong

A

In change management best practices, the first step is always to submit a change request for approval before any technical actions like downloading firmware. Downloading firmware without authorization violates the change control process.

D

Scheduling a maintenance window is a later step in the change management process; the first step must be submitting a change request to obtain approval before any actions are taken.

When would these options actually be correct?

A

A network administrator has already received approval for a firmware upgrade and is now executing the plan. The question asks: 'After the change request is approved, what is the next step?' In that context, downloading the new firmware would be the correct first technical action.

D

If the question asked 'After the change request is approved, which step should be performed next?' then scheduling a maintenance window would be correct to minimize disruption.

Why candidates pick the wrong answer

A

Candidates often focus on the technical task of obtaining the firmware and overlook the procedural requirement to get formal approval first, especially when the question emphasizes 'upgrade the firmware' rather than 'change management process'.

D

Candidates often think of the operational need to schedule downtime first, but they overlook that formal approval via a change request is required before any scheduling can occur.

193
MCQmedium

A network administrator is preparing to upgrade the firmware on a critical router. Which document should the administrator consult to understand the steps required to minimize downtime and ensure a successful upgrade?

A.SLA
B.Change management plan
C.Network diagram
D.Baseline performance report
AnswerB

The change management plan documents the process for making changes to the network, including risk assessment, detailed steps, testing, approval, and rollback procedures. It is the appropriate resource to ensure a methodical and safe upgrade.

Why this answer

The change management plan documents the approved procedures, rollback steps, and communication protocols for performing maintenance on critical infrastructure. Consulting this plan ensures the administrator follows the organization's predefined steps to minimize downtime and mitigate risks during the firmware upgrade.

Exam trap

The trap here is that candidates confuse a change management plan with a network diagram or SLA, assuming that knowing the topology or contractual uptime is sufficient to perform a safe upgrade, when in fact the procedural steps and rollback strategy are documented only in the change management plan.

Why the other options are wrong

C

A network diagram shows physical or logical topology but does not provide procedural steps for firmware upgrades or downtime minimization.

D

A baseline performance report documents normal network performance metrics, not the step-by-step upgrade procedures needed to minimize downtime and ensure success.

When would these options actually be correct?

C

When asked which document helps identify potential single points of failure or the physical location of devices before planning a maintenance window, a network diagram would be correct.

D

When a question asks which document to use to compare post-upgrade network performance against pre-upgrade metrics to verify no degradation occurred, the baseline performance report would be correct.

Why candidates pick the wrong answer

C

Candidates may think a network diagram is needed to understand the router's role and connections, but it lacks the step-by-step upgrade procedures and rollback plans found in a change management plan.

D

Candidates may think a baseline report is needed to understand the current state before making changes, but it does not contain upgrade procedures or rollback steps.

194
MCQmedium

A network engineer needs to implement a wireless network in a large open-plan office with high client density. The network must provide the fastest possible speeds and efficient handling of many simultaneous connections. Which IEEE 802.11 standard should be used?

A.802.11ac
B.802.11n
C.802.11ax
D.802.11r
AnswerC

802.11ax, also known as Wi-Fi 6, is the most suitable standard for a large open-plan office due to its optimization for high-density client environments. It significantly improves efficiency and throughput by utilizing Orthogonal Frequency-Division Multiple Access (OFDMA) for simultaneous communication with multiple clients and enhanced Multi-User Multiple-Input Multiple-Output (MU-MIMO) for both uplink and downlink. These features ensure better performance and capacity, even with numerous devices competing for bandwidth and diverse traffic types.

Why this answer

802.11ax (Wi-Fi 6) is the correct choice because it introduces Orthogonal Frequency Division Multiple Access (OFDMA) and MU-MIMO (both uplink and downlink), which significantly improve spectral efficiency and capacity in high-density environments. It also supports 1024-QAM modulation for higher data rates, making it ideal for an open-plan office with many simultaneous connections.

Exam trap

The trap here is that candidates often confuse 802.11ac (Wi-Fi 5) as the fastest standard because of its high single-user throughput, but they overlook that 802.11ax (Wi-Fi 6) is specifically designed for high-density, multi-user scenarios with OFDMA and improved MU-MIMO.

Why the other options are wrong

A

802.11ac operates only on the 5 GHz band and lacks OFDMA and MU-MIMO enhancements for uplink, making it less efficient than 802.11ax for high-density environments with many simultaneous connections.

B

802.11n operates on 2.4 GHz and 5 GHz bands with maximum data rates up to 600 Mbps, but it lacks OFDMA and MU-MIMO, making it inefficient for high-density environments compared to 802.11ax.

D

802.11r focuses on fast roaming (reducing authentication latency during handoffs) and does not improve overall speed or capacity for high-density environments.

When would these options actually be correct?

A

When the question specifies a network upgrade from 802.11n requiring backward compatibility and higher throughput on 5 GHz, but does not require support for 2.4 GHz or the latest efficiency features like OFDMA.

B

A question asking for a standard that provides backward compatibility with older devices (802.11a/b/g) and supports basic MIMO for improved range in a small office or home network with low client density.

D

In a scenario where the network must support seamless, low-latency handoffs for voice or video clients moving between access points, 802.11r (Fast BSS Transition) would be the correct choice.

Why candidates pick the wrong answer

A

Candidates often associate 802.11ac with 'fast speeds' and may overlook that 802.11ax (Wi-Fi 6) is specifically designed for high-density scenarios with better efficiency.

B

Candidates may remember 802.11n as a significant improvement over older standards and assume it is sufficient for modern high-density networks, not realizing that 802.11ax is specifically designed for such scenarios.

D

Candidates may confuse 802.11r with newer standards or think the 'r' stands for 'recent' or 'rapid', leading them to believe it offers speed improvements.

195
MCQhard

A company's public web server is experiencing a flood of TCP SYN packets from multiple external IP addresses. The server's connection table is full, causing new legitimate connections to be dropped. Which of the following mitigation techniques should be implemented to protect the server while still allowing legitimate traffic?

A.Implement SYN cookies on the server.
B.Increase the server's TCP connection backlog.
C.Enable bogon filtering on the perimeter firewall.
D.Deploy an intrusion prevention system (IPS) with signature detection.
AnswerA

SYN cookies are a highly effective defense against SYN floods because they allow the server to defer allocating memory for a new connection until the three-way handshake is fully completed. Instead of storing connection state, the server encodes all necessary information, such as client IP, port, and sequence numbers, into the initial SYN-ACK packet's sequence number. Only upon receiving a valid final ACK, which includes the correct cookie, does the server reconstruct the connection state and allocate resources, effectively preventing its connection table from being exhausted by spoofed or incomplete SYN requests.

Why this answer

SYN cookies allow the server to avoid storing connection state in the TCP backlog until the three-way handshake completes. When the SYN flood fills the connection table, the server encodes the initial sequence number (ISN) with cryptographic information about the connection, enabling it to verify the ACK from a legitimate client without consuming table entries. This technique preserves resources for legitimate traffic while dropping spoofed or incomplete handshakes.

Exam trap

The N10-009 exam often tests the misconception that increasing the TCP backlog (Option B) is a viable defense against SYN floods, but candidates must recognize that backlog tuning only delays exhaustion, whereas SYN cookies provide a stateless, scalable solution.

Why the other options are wrong

B

Increasing the TCP connection backlog only raises the limit of pending connections in the queue, but a SYN flood fills the connection table regardless of backlog size, so the server still exhausts resources and drops legitimate connections.

C

Bogon filtering blocks traffic from invalid or unallocated IP addresses, but the SYN flood is coming from multiple external IPs that may be legitimate (spoofed or real). It does not prevent the connection table from filling up due to half-open connections.

D

An IPS with signature detection can block known attack patterns, but it cannot prevent the connection table from filling up during a SYN flood because the attack traffic still reaches the server and consumes resources before the IPS can act.

When would these options actually be correct?

B

This option would be correct in a scenario where the server is dropping legitimate connections due to a legitimate traffic spike (e.g., flash crowd) and the backlog is set too low, causing new connections to be rejected even though the server has capacity to handle them.

C

A company is receiving traffic from IP addresses that are known to be unallocated or reserved (e.g., private IPs on the internet). Enabling bogon filtering on the perimeter firewall would block this invalid traffic and protect the network.

D

An IPS with signature detection would be correct for blocking application-layer attacks, such as SQL injection or cross-site scripting, where the attack payload is in the data stream and can be matched against signatures.

Why candidates pick the wrong answer

B

Candidates may think that a larger backlog can absorb more SYN packets, misunderstanding that SYN floods exhaust the connection table via half-open connections, not by exceeding the backlog limit.

C

Candidates may think that blocking 'bad' IPs (bogons) is a general defense against any flood, but SYN floods often use spoofed or real distributed IPs that are not necessarily bogons.

D

Candidates may think an IPS can stop any type of attack, including SYN floods, because it is a general-purpose security device, but they overlook that SYN floods exploit TCP handshake mechanics that require endpoint-level mitigation.

196
MCQhard

A network administrator is configuring OSPF on routers in a multi-area network. The administrator wants to ensure that a router in area 1 does not learn external routes (Type 5 LSAs) injected by an ASBR in area 0, but it must still learn inter-area routes (Type 3 LSAs). The administrator wants to reduce the routing table size. Which OSPF area type should be configured for area 1?

A.Stub area
B.Totally stubby area
C.Not-so-stubby-area (NSSA)
D.Normal area
AnswerA

A stub area is designed to reduce the routing table size within an OSPF area by preventing the flooding of Type 5 External LSAs, which represent routes learned from outside the OSPF domain. Instead of individual external routes, the Area Border Router (ABR) connected to a stub area injects a default route (0.0.0.0/0) as a Type 3 LSA. This allows routers within the stub area to reach external destinations while still learning inter-area routes (Type 3 LSAs) from other OSPF areas, thus optimizing resource usage without isolating them from the rest of the OSPF domain.

Why this answer

A stub area blocks Type 5 LSAs (external routes) from entering the area while still allowing Type 3 LSAs (inter-area routes). This meets the requirement of preventing external routes from the ASBR in area 0 from being learned by routers in area 1, while still permitting inter-area routing and reducing the routing table size.

Exam trap

The N10-009 exam often tests the distinction between stub and totally stubby areas, where candidates mistakenly choose totally stubby when they only need to block external routes but still require inter-area routes.

Why the other options are wrong

B

A totally stubby area blocks both Type 5 LSAs (external routes) and Type 3 LSAs (inter-area routes), but the question requires that inter-area routes (Type 3 LSAs) still be learned.

C

An NSSA allows Type 7 LSAs (which are converted to Type 5) and does not block external routes from an ASBR in area 0; it only prevents Type 5 LSAs from other areas while allowing redistribution. The question requires blocking all external routes (Type 5 LSAs) from area 0, which a stub area does by default, but an NSSA does not.

D

A normal area allows all LSA types, including Type 5 external LSAs, so the router in area 1 would still learn external routes, failing the requirement to block them.

When would these options actually be correct?

B

A totally stubby area would be correct when the requirement is to block both external and inter-area routes, allowing only a default route into the area, such as when an area has only one exit point and you want to minimize the routing table as much as possible.

C

A question where an ASBR is inside the NSSA (area 1) and needs to inject external routes into OSPF, but the area must still block Type 5 LSAs from other areas. For example: 'An administrator wants to allow redistribution of external routes from a router within area 1 while preventing Type 5 LSAs from other areas. Which area type?'

D

When the requirement is to allow all OSPF route types (including external routes) and there is no need to reduce routing table size, a normal area is appropriate.

Why candidates pick the wrong answer

B

Candidates may confuse 'stub' with 'totally stubby' and think that blocking external routes automatically implies blocking inter-area routes, or they may overestimate the need to reduce routing table size without carefully reading the requirement to keep inter-area routes.

C

Candidates may confuse NSSA with stub area, thinking NSSA also blocks all external routes, but they remember that NSSA allows some external routes (via Type 7), which seems like a compromise. They might also think the 'not-so-stubby' name implies it is a variation of stub that still blocks external routes, but it actually allows them from within the area.

D

Candidates may default to a normal area because it is the default OSPF area type, without considering the need to filter external routes.

197
MCQmedium

A network administrator needs to analyze bandwidth usage by application and identify top talkers on the network. Which protocol or technology should be used to export detailed traffic flow information from routers and switches to a central collector?

A.NetFlow
B.SNMP
C.ICMP
D.SMTP
AnswerA

NetFlow is a Cisco-developed protocol that collects and exports IP traffic information as "flow records" from network devices. Each flow record details a unique conversation, including source/destination IP addresses, ports, protocol, and byte/packet counts. This granular data allows network administrators to analyze bandwidth usage by specific applications, identify "top talkers" consuming the most resources, and understand traffic patterns for capacity planning and security monitoring. It provides the necessary per-flow visibility to meet the question's requirements.

Why this answer

NetFlow is the correct choice because it is a Cisco-developed protocol designed specifically to export detailed IP traffic flow information—including source/destination IPs, ports, protocols, and byte counts—from routers and switches to a central collector for bandwidth usage analysis and top talker identification. Unlike simpler monitoring tools, NetFlow provides per-flow granularity, enabling administrators to pinpoint which applications and hosts are consuming the most bandwidth.

Exam trap

The N10-009 exam often tests the distinction between SNMP and NetFlow, where candidates mistakenly choose SNMP because they associate it with network monitoring, but SNMP lacks the per-flow granularity needed for top talker and application analysis.

Why the other options are wrong

B

SNMP is used for monitoring and managing network devices by polling or receiving traps, but it does not export detailed traffic flow information like application-level usage or top talkers. NetFlow is specifically designed for that purpose.

C

ICMP is used for network diagnostics (e.g., ping, traceroute) and error reporting, not for exporting detailed traffic flow data like application usage or top talkers.

D

SMTP is used for email transmission, not for exporting network traffic flow data. It cannot provide bandwidth usage by application or identify top talkers.

When would these options actually be correct?

B

SNMP would be correct in a question asking for a protocol to monitor device health metrics (e.g., CPU, memory, interface errors) or to retrieve interface traffic statistics via MIB counters, not for flow-level analysis.

C

A question asking which protocol is used to test connectivity between two hosts or to measure round-trip time (e.g., 'Which protocol does the ping command use?').

D

When the question asks about the protocol used to send email messages between mail servers, SMTP is the correct answer.

Why candidates pick the wrong answer

B

Candidates may confuse SNMP's ability to collect interface traffic statistics (e.g., octets) with the more detailed flow export capability of NetFlow, assuming SNMP can provide application-level data.

C

Candidates may confuse ICMP with network monitoring tools because ping and traceroute are commonly used for basic network troubleshooting, leading them to think ICMP can provide traffic flow details.

D

Candidates might confuse SMTP with a protocol that 'transfers' data, or mistakenly think it can be used for network monitoring because of its role in sending messages.

198
MCQhard

A security engineer is configuring a site-to-site VPN between two branch offices. The requirement is to encrypt all traffic between the two networks using IPsec. Which IPsec mode should be used to encrypt the entire IP packet including the original header?

A.Transport mode
B.Tunnel mode
C.AH only
D.ESP only
AnswerB

Tunnel mode is the correct choice for site-to-site VPNs because it encapsulates the entire original IP packet, including both its header and payload, within a new, outer IP header. This comprehensive encapsulation ensures that the original source and destination IP addresses are hidden from intermediate networks, providing complete confidentiality and network-level anonymity. The new outer header then directs the packet to the VPN gateway at the remote site, making it ideal for connecting entire networks securely.

Why this answer

Tunnel mode is the correct choice because it encrypts the entire original IP packet, including the original header, and then encapsulates it within a new IP header. This is required for site-to-site VPNs where the original source and destination IP addresses must be hidden or protected, and the new header is used for routing between the two VPN gateways.

Exam trap

The N10-009 exam often tests the distinction between Transport and Tunnel modes by asking which mode encrypts the entire packet, and candidates mistakenly choose Transport mode because they confuse 'encrypting the payload' with 'encrypting the entire packet', or they think AH provides encryption.

Why the other options are wrong

A

Transport mode only encrypts the payload of the IP packet, leaving the original IP header intact, so it does not encrypt the entire packet including the header as required.

C

AH only provides authentication and integrity, but does not encrypt the payload or the original header, failing to meet the requirement to encrypt all traffic.

D

ESP only can be used in either transport or tunnel mode, but the question asks for the mode that encrypts the entire IP packet including the original header. ESP alone does not specify the mode; tunnel mode is required for full packet encryption.

When would these options actually be correct?

A

Transport mode would be correct when the VPN is used for end-to-end communication between two hosts (e.g., a client and server) and the requirement is to encrypt only the payload while preserving the original IP header for routing.

C

When the requirement is only to authenticate and ensure integrity of IP packets without encryption, such as in a scenario where data confidentiality is not needed but protection against tampering is required.

D

A question asking: 'Which IPsec protocol provides encryption but not authentication of the IP header?' would make ESP only correct, as AH provides authentication but not encryption.

Why candidates pick the wrong answer

A

Candidates may confuse transport mode with tunnel mode, thinking both encrypt the entire packet, or they may not fully understand that transport mode excludes the header from encryption.

C

Candidates may confuse AH with ESP, or think that AH provides encryption because it is part of IPsec, but AH only offers authentication, not encryption.

D

Candidates may confuse ESP with tunnel mode, thinking ESP inherently encrypts the entire packet, but ESP can operate in transport mode which only encrypts the payload.

199
MCQhard

A network administrator reviews firewall logs and sees thousands of SYN packets coming from various source IP addresses to a single internal web server. No ACK or RST packets are observed from these sources. Which type of attack is most likely occurring?

A.DNS amplification attack
B.SYN flood attack
C.ARP spoofing attack
D.Man-in-the-middle attack
AnswerB

A SYN flood attack exploits the TCP three-way handshake by sending numerous SYN requests to a target server without completing the final ACK. This leaves the server with many half-open connections, rapidly consuming its connection table resources and memory. The firewall logs would precisely reflect this by showing thousands of incoming SYN packets, often from spoofed source IPs, indicating a denial-of-service attempt.

Why this answer

A SYN flood attack exploits the TCP three-way handshake by sending a high volume of SYN packets to a target server without completing the handshake (no ACK or RST). This exhausts the server's connection table resources, preventing legitimate connections. The observed pattern of many SYN packets from various sources with no subsequent ACK or RST is the hallmark of a SYN flood.

Exam trap

The N10-009 exam often tests the distinction between a SYN flood (which targets the TCP handshake) and a DNS amplification attack (which uses UDP reflection), so candidates may confuse the two because both involve high packet volumes and spoofed sources.

Why the other options are wrong

A

A DNS amplification attack uses DNS servers to flood a target with large DNS responses, not SYN packets. The question describes thousands of SYN packets with no ACK or RST, which is characteristic of a SYN flood, not a DNS amplification attack.

C

ARP spoofing attacks involve sending forged ARP messages to link an attacker's MAC address with the IP address of a legitimate device, not flooding a server with SYN packets. The described behavior of thousands of SYN packets without ACK/RST is characteristic of a SYN flood, not ARP spoofing.

D

A man-in-the-middle attack involves intercepting and potentially altering communications between two parties, not sending a flood of SYN packets without completing the handshake. The described behavior of thousands of SYN packets with no ACK or RST is characteristic of a SYN flood, not a MITM attack.

When would these options actually be correct?

A

A DNS amplification attack would be correct if the question described a high volume of large DNS response packets (e.g., from open resolvers) directed at a target, with the source IPs being spoofed DNS servers, and the goal being bandwidth exhaustion.

C

A network administrator notices intermittent connectivity issues and, upon checking ARP tables, finds multiple IP addresses mapped to the same MAC address. Which attack is most likely occurring?

D

A man-in-the-middle attack would be correct in a scenario where an attacker intercepts traffic between a client and server, for example, by ARP spoofing to redirect traffic through the attacker's machine, allowing eavesdropping or data modification. The question would describe suspicious traffic patterns like ARP replies or session hijacking.

Why candidates pick the wrong answer

A

Candidates may confuse 'amplification' with 'flooding' and think any large volume of traffic from many sources is an amplification attack, without recognizing the specific packet type (SYN vs. DNS response).

C

Candidates may confuse network-layer attacks; ARP spoofing is a common attack that can lead to denial of service, but it operates at Layer 2 and does not involve SYN packet floods.

D

Candidates may confuse network-based attacks, thinking that any attack involving spoofed IPs or targeting a server could be a MITM, especially if they associate MITM with intercepting traffic to a web server.

200
MCQmedium

A network technician is troubleshooting a user's inability to access a specific internal web application hosted on a server at 10.10.10.15:8080. The user can ping the server's IP address successfully, but the web browser displays 'connection refused'. The technician verifies that the web application service is running on the server. What is the most likely cause of the issue?

A.The server's firewall is blocking inbound connections to port 8080.
B.The web application is listening on a different port than 8080.
C.The user's web browser is configured to use an incorrect proxy server.
D.The DNS resolution is failing for the server's hostname.
AnswerA

Connection refused often indicates that a firewall is blocking the specific port. Since the server is reachable via ping, the issue is at the port level. Checking the server firewall rules for port 8080 is the next step.

Why this answer

Since the user can ping the server (ICMP success) but receives 'connection refused' on port 8080, and the service is confirmed running, the most likely cause is that the server's firewall is blocking inbound TCP connections to port 8080. A firewall rule can permit ICMP echo requests while denying TCP SYN packets to specific ports, resulting in a successful ping but a TCP RST or no response at the application layer, which manifests as 'connection refused' in the browser.

Exam trap

CompTIA often tests the distinction between ICMP reachability (ping) and TCP port accessibility, trapping candidates into thinking a successful ping means all network connectivity is fine, when in fact firewalls can selectively block specific ports while allowing ICMP.

Why the other options are wrong

B

The technician verified the web application service is running, so it is listening on some port. If it were listening on a different port, the browser would not get 'connection refused' but rather a timeout or no response, unless that port is also blocked. The 'connection refused' error indicates the server actively rejected the connection, which is typical of a firewall blocking the specific port.

C

The user can successfully ping the server, indicating network connectivity and DNS resolution are working. The 'connection refused' error suggests the server is actively rejecting the connection, which points to a firewall blocking port 8080, not a proxy misconfiguration.

D

The user can successfully ping the server's IP address (10.10.10.15), indicating that network connectivity and IP-level communication are working. DNS resolution is not involved because the user is accessing the server by IP address, not by hostname. Therefore, a DNS failure cannot be the cause.

When would these options actually be correct?

B

In a scenario where a user cannot access a web application and the technician finds the service is not listening on the expected port (e.g., configured to port 9090 instead of 8080), the most likely cause is the application listening on a different port. This would result in a 'connection refused' error if no other service is on that port.

C

This option would be correct if the user could not access any external websites, but internal resources were reachable, and the browser was configured with a proxy server that is down or misconfigured for external traffic. For example, a question where a user can access internal sites but not the internet, and the proxy settings are incorrect.

D

A user reports being unable to access a website by its domain name (e.g., www.example.com) but can access it by its IP address. The technician confirms that other users can access the site by domain name. In this scenario, DNS resolution failure for the specific user would be the likely cause.

Why candidates pick the wrong answer

B

Candidates may think that if the service is running, it must be on the expected port, but misconfiguration is common. They overlook that 'connection refused' specifically indicates the port is reachable but no service is listening, which could be due to a different port or firewall, but the firewall is more likely given the service is confirmed running.

C

Candidates may confuse 'connection refused' with proxy-related errors like 'proxy server refusing connection', or they might overthink the issue and assume a proxy is involved even when direct connectivity is confirmed.

D

Candidates may confuse general web access issues with DNS problems, assuming that 'connection refused' could stem from name resolution failure, even though the question explicitly states the user is using an IP address.

201
MCQmedium

A network administrator discovers that client workstations are receiving IP addresses from an unknown device, causing network connectivity issues. Which security feature should be configured on switches to prevent rogue DHCP servers from assigning IP addresses?

A.DHCP snooping
B.Dynamic ARP Inspection
C.Port security
D.BPDU guard
AnswerA

DHCP snooping is a Layer 2 security feature designed to prevent unauthorized DHCP servers from providing IP addresses and configuration to clients. It operates by classifying switch ports as either trusted, where legitimate DHCP server messages are allowed, or untrusted, where incoming DHCP server responses are blocked. This mechanism ensures that only approved DHCP servers can respond to client requests, effectively mitigating the risk of IP address conflicts and network misconfigurations caused by rogue devices.

Why this answer

DHCP snooping is the correct security feature because it acts as a firewall between untrusted hosts and trusted DHCP servers. By configuring ports as trusted (where legitimate DHCP servers are connected) and untrusted (client-facing ports), the switch drops all DHCP server messages (OFFER, ACK, NAK) received on untrusted ports, effectively blocking rogue DHCP servers from assigning IP addresses.

Exam trap

The trap here is that candidates confuse DHCP snooping with Dynamic ARP Inspection (DAI) because both rely on the DHCP snooping binding table, but DAI only validates ARP packets, not DHCP server messages.

Why the other options are wrong

B

Dynamic ARP Inspection (DAI) is used to prevent ARP spoofing attacks by validating ARP packets, not to block rogue DHCP servers. The question specifically asks about preventing unauthorized DHCP server activity, which is addressed by DHCP snooping.

C

Port security limits the number of MAC addresses per switch port but does not inspect DHCP messages or block unauthorized DHCP servers. It cannot prevent rogue DHCP servers from assigning IP addresses.

D

BPDU guard is used to prevent loops by disabling ports that receive Bridge Protocol Data Units (BPDUs) from unauthorized switches, not to block rogue DHCP servers.

When would these options actually be correct?

B

Dynamic ARP Inspection would be the correct answer in a scenario where a network administrator needs to prevent man-in-the-middle attacks caused by an attacker sending fake ARP replies to associate their MAC address with the IP address of a legitimate device (e.g., the default gateway).

C

Port security would be correct in a question about preventing unauthorized devices from connecting to the network by limiting the number of MAC addresses allowed on a port, e.g., 'A network administrator wants to prevent users from connecting personal switches to the network. Which feature should be enabled on switch ports?'

D

A network administrator wants to prevent unauthorized switches from being connected to access ports and causing spanning tree loops. BPDU guard would be the correct feature to configure on switch ports to disable them if a BPDU is received.

Why candidates pick the wrong answer

B

Candidates may confuse DAI with DHCP snooping because both are security features that rely on a trusted database (DHCP snooping binding table) and are often implemented together. They might think DAI can also filter DHCP traffic, but its role is limited to ARP validation.

C

Candidates may confuse port security with DHCP snooping because both are switch security features, and they might think that restricting MAC addresses can block rogue DHCP servers, not realizing that DHCP snooping specifically validates DHCP messages.

D

Candidates may confuse BPDU guard with DHCP snooping because both are security features that protect against unauthorized network devices, but they address different threats.

202
MCQhard

A security analyst receives an alert that an internal user's workstation is sending a high volume of ARP requests for multiple IP addresses on the local subnet. The analyst suspects a man-in-the-middle attack. Which security mechanism is most effective at mitigating this type of attack on a switched network?

A.Port security
B.DHCP snooping
C.Dynamic ARP Inspection
D.MAC address filtering
AnswerC

DAI uses the DHCP snooping binding table to validate ARP packets and block spoofed ARP messages.

Why this answer

Dynamic ARP Inspection (DAI) is the correct answer because it validates ARP packets on a switched network, ensuring that only legitimate ARP replies are forwarded. In a man-in-the-middle attack, an attacker sends spoofed ARP replies to associate their MAC address with the IP address of a legitimate host. DAI intercepts all ARP packets and compares them against a trusted binding table (built by DHCP snooping), dropping any that are invalid, thus preventing ARP spoofing.

Exam trap

The N10-009 exam often tests the distinction between DHCP snooping and DAI, where candidates mistakenly choose DHCP snooping because it builds the binding table, but DAI is the actual mechanism that validates ARP packets to prevent man-in-the-middle attacks.

Why the other options are wrong

A

Port security limits the number of MAC addresses per port but does not inspect ARP packets, so it cannot prevent ARP spoofing or man-in-the-middle attacks.

B

DHCP snooping filters DHCP messages to prevent rogue DHCP servers, but it does not inspect ARP traffic. The attack described involves ARP spoofing, which Dynamic ARP Inspection (DAI) directly mitigates by validating ARP packets against the DHCP snooping binding table.

D

MAC address filtering restricts which MAC addresses can communicate on a port, but it does not prevent ARP spoofing or man-in-the-middle attacks because an attacker can spoof a legitimate MAC address.

When would these options actually be correct?

A

Port security would be correct in a question about preventing unauthorized devices from connecting to a switch port by limiting MAC addresses, such as 'Which feature restricts the number of MAC addresses learned on a port to prevent MAC flooding?'

B

DHCP snooping would be the correct answer if the question described a scenario where a rogue DHCP server is assigning malicious IP configurations to clients, enabling man-in-the-middle attacks via DHCP spoofing.

D

MAC address filtering would be correct in a scenario where the question asks for a mechanism to prevent unauthorized devices from connecting to the network by limiting access based on MAC addresses, such as in a small office with a static device list.

Why candidates pick the wrong answer

A

Candidates may think port security prevents all MAC-based attacks, confusing MAC address limiting with ARP inspection.

B

Candidates may confuse DHCP snooping with ARP inspection because both rely on the same binding table and are often implemented together, leading to the mistaken belief that DHCP snooping alone can prevent ARP-based attacks.

D

Candidates may confuse MAC address filtering with a security measure against ARP attacks, as both involve MAC addresses, but filtering does not validate ARP packets or prevent spoofing.

203
MCQhard

A security analyst observes that a workstation on the network is sending unsolicited ARP replies stating that the workstation's MAC address corresponds to the default gateway IP for all subnets. This behavior is causing other devices to send traffic destined for external networks to the workstation instead of the legitimate gateway. Which type of attack is being performed?

A.A: ARP spoofing
B.B: DHCP starvation
C.C: DNS poisoning
D.D: MAC flooding
AnswerA

ARP spoofing is a Layer 2 attack where an attacker sends forged Address Resolution Protocol (ARP) messages over a local area network. The goal is to associate the attacker's MAC address with the IP address of another host, most commonly the default gateway. By doing this, the attacker intercepts traffic intended for the gateway, effectively positioning themselves as a "man-in-the-middle" between the victim and the actual gateway, allowing for eavesdropping or manipulation of data.

Why this answer

The workstation is sending unsolicited ARP replies that map the default gateway IP to its own MAC address. This poisons the ARP caches of other devices on the network, causing them to forward traffic destined for external networks to the attacker's workstation instead of the legitimate gateway. This is the classic behavior of an ARP spoofing (or ARP poisoning) attack, which exploits the lack of authentication in the ARP protocol (RFC 826).

Exam trap

The trap here is confusing ARP spoofing with MAC flooding, because both involve MAC addresses and network interception, but MAC flooding targets the switch's CAM table to capture traffic, while ARP spoofing targets host ARP caches to redirect traffic to a specific MAC address.

Why the other options are wrong

B

DHCP starvation floods a DHCP server with requests to exhaust its IP address pool, causing denial of service. The question describes unsolicited ARP replies mapping the attacker's MAC to the gateway IP, which is ARP spoofing, not DHCP-related.

C

DNS poisoning involves corrupting DNS resolver caches to redirect domain names to malicious IPs, not manipulating ARP tables with unsolicited replies for the default gateway IP.

D

MAC flooding involves sending many frames with different source MAC addresses to overflow the switch's MAC address table, causing it to fail open and broadcast traffic. The question describes unsolicited ARP replies, not MAC table overflow.

When would these options actually be correct?

B

A DHCP starvation attack would be correct if the question described an attacker sending numerous DHCPDISCOVER messages to exhaust the DHCP server's address pool, preventing legitimate clients from obtaining IP addresses.

C

A question where users report being redirected to a phishing site when typing a legitimate domain name, and the attack is traced to a compromised DNS server or cache poisoning.

D

A security analyst notices that the switch's MAC address table is full and the switch begins flooding unicast traffic to all ports. Which attack is being performed?

Why candidates pick the wrong answer

B

Candidates may confuse DHCP starvation with ARP spoofing because both involve network-layer manipulation and can disrupt traffic flow, but they target different protocols (DHCP vs. ARP).

C

Candidates may confuse 'poisoning' attacks (ARP vs. DNS) and think any redirection of traffic involves DNS, overlooking the Layer 2 ARP mechanism described.

D

Candidates may confuse MAC flooding with ARP spoofing because both involve manipulating network traffic, but MAC flooding targets the switch's forwarding table rather than ARP caches.

204
MCQeasy

A network technician is explaining network segmentation to a junior technician. Which of the following devices increases the number of collision domains but does not increase the number of broadcast domains?

A.Hub
B.Switch
C.Router
D.Repeater
AnswerB

A switch effectively segments a network by creating a dedicated collision domain for each connected port. This means that devices connected to different switch ports can transmit simultaneously without causing collisions, significantly improving network performance and reducing congestion within a local area network. However, a switch operates at Layer 2 and forwards all broadcast frames, so it does not segment broadcast domains.

Why this answer

A switch creates a separate collision domain for each port, so multiple devices can transmit simultaneously without collisions, but it does not segment broadcast domains; all ports remain in the same broadcast domain unless VLANs are configured. This directly matches the question's requirement: increasing collision domains without increasing broadcast domains.

Exam trap

The trap here is that candidates often confuse collision domains with broadcast domains, thinking that a switch reduces both, when in fact it only reduces collision domains while leaving broadcast domains unchanged (unless VLANs are used).

Why the other options are wrong

A

A hub operates at Layer 1 and does not segment collision domains; all ports share a single collision domain, so it does not increase the number of collision domains.

C

A router increases both collision domains and broadcast domains because it separates broadcast domains by default, which is not what the question asks.

D

A repeater operates at Layer 1 and simply regenerates signals, extending the physical reach of a network. It does not segment collision domains; all devices connected via repeaters share the same collision domain, and it does not affect broadcast domains.

When would these options actually be correct?

A

If the question asked which device increases the number of collision domains (without the broadcast domain constraint), a hub would still be incorrect. However, if the question asked which device creates a single collision domain for all connected devices, a hub would be correct.

C

In a question asking 'Which device increases the number of broadcast domains?', a router would be correct as it segments broadcast domains at Layer 3.

D

A repeater would be the correct answer in a question asking: 'Which device extends the maximum cable length of a network segment without segmenting collision or broadcast domains?' or 'Which device regenerates a signal to overcome attenuation?'

Why candidates pick the wrong answer

A

Candidates may mistakenly think that hubs, like switches, create separate collision domains per port, confusing the behavior of hubs with that of switches.

C

Candidates may confuse the roles of routers and switches, thinking routers only affect collision domains, or they may misremember that routers increase collision domains without considering broadcast domains.

D

Candidates may confuse repeaters with switches, thinking that signal regeneration implies segmentation, or they may not fully understand that repeaters operate at Layer 1 and do not create separate collision domains.

205
MCQhard

An organization wants to implement a security solution that uses a cloud-based service to inspect all incoming web traffic for malware and policy violations before it reaches the internal network. This type of solution is known as a:

A.Web application firewall (WAF)
B.Secure web gateway (SWG)
C.Intrusion detection system (IDS)
D.VPN concentrator
AnswerB

A Secure Web Gateway (SWG) is precisely designed to filter and secure web traffic, often delivered as a cloud-based service. It acts as an intermediary proxy, inspecting all outbound and inbound web requests to block malware, enforce acceptable use policies, and prevent data loss. This cloud-native approach provides consistent security for users regardless of their location, making it ideal for distributed workforces and aligning perfectly with the need for a cloud-based security solution.

Why this answer

A Secure Web Gateway (SWG) is a cloud-based security solution that inspects all outbound and inbound web traffic for malware, policy violations, and data loss. It operates at the application layer, typically using proxy-based or API-based inspection to enforce security policies before traffic reaches the internal network. This matches the requirement for a cloud service that inspects incoming web traffic for malware and policy violations.

Exam trap

The trap here is confusing a Secure Web Gateway (SWG) with a Web Application Firewall (WAF), as both deal with web traffic, but SWG focuses on user-to-web traffic inspection and policy enforcement, while WAF protects a specific web server from application-layer attacks.

Why the other options are wrong

A

A WAF inspects and filters HTTP/HTTPS traffic to protect web applications from attacks like SQL injection, but it does not inspect all web traffic for malware and policy violations before reaching the internal network; that is the role of a secure web gateway (SWG).

C

An IDS is a passive monitoring system that detects suspicious activity but does not inspect or block web traffic inline; it cannot enforce policies on incoming web traffic before it reaches the internal network.

D

A VPN concentrator is used to create secure tunnels for remote access or site-to-site connectivity, not to inspect web traffic for malware or policy violations. It does not perform content filtering or threat detection on incoming web traffic.

When would these options actually be correct?

A

A question asking for a solution that protects a specific web application from application-layer attacks (e.g., SQL injection, XSS) by inspecting HTTP/HTTPS requests and responses, typically deployed in front of web servers.

C

A question asking for a solution that monitors network traffic for signs of malicious activity and generates alerts without actively blocking traffic, such as 'An organization wants to detect potential intrusions on its internal network without affecting performance.'

D

An organization needs to provide secure remote access for employees connecting from external networks, requiring encrypted tunnels and authentication. The correct answer would be a VPN concentrator.

Why candidates pick the wrong answer

A

Candidates may confuse WAF with SWG because both deal with web traffic filtering, but WAF focuses on application-layer attacks while SWG enforces broader security policies and malware inspection for all web traffic.

C

Candidates may confuse IDS with SWG because both involve security inspection, but IDS lacks the inline, cloud-based web traffic filtering and policy enforcement capabilities described in the question.

D

Candidates may confuse VPN concentrators with security gateways because both are network security appliances, but VPN concentrators focus on encryption and access, not traffic inspection.

206
MCQhard

Users in a warehouse report that their wireless tablets lose connectivity when moving near large metal racks. The signal strength remains high but throughput drops significantly. What is the most likely cause?

A.Signal attenuation
B.Multipath interference
C.Co-channel interference
D.Insufficient DHCP scope
AnswerB

Metal racks in a warehouse environment are highly reflective surfaces for radio frequency (RF) signals, causing the wireless signal to travel multiple paths to reach the receiver. These reflected signals arrive at slightly different times and phases, interfering with the direct signal. This multipath interference leads to signal cancellation or distortion, resulting in high perceived signal strength but corrupted data and poor throughput. Users experience connectivity loss even when their devices report strong signal.

Why this answer

When wireless signals reflect off large metal surfaces, multiple copies of the signal arrive at the receiver at slightly different times, causing multipath interference. This phase cancellation effect corrupts the signal, forcing the 802.11 MAC layer to retransmit frames, which drastically reduces throughput even though the received signal strength indicator (RSSI) remains high. The metal racks in the warehouse act as reflective surfaces, creating a classic multipath environment.

Exam trap

The trap here is that candidates confuse high signal strength with good signal quality, not realizing that multipath can cause high RSSI but poor throughput due to phase cancellation and retransmissions.

Why the other options are wrong

A

Signal attenuation refers to the reduction of signal strength over distance or through obstacles. In this scenario, signal strength remains high, so attenuation is not the cause; the issue is multipath interference caused by reflections off the metal racks.

C

Co-channel interference occurs when multiple access points use the same frequency channel, causing contention. The described issue is localized near metal racks, not due to overlapping channels, and signal strength remains high, ruling out co-channel interference.

D

Insufficient DHCP scope would cause devices to fail to obtain an IP address, not cause high signal strength with low throughput. The issue here is interference from metal racks, not IP address exhaustion.

When would these options actually be correct?

A

A question where users report low signal strength or complete loss of connectivity when moving behind large metal objects, such as in a factory with thick concrete walls or metal enclosures, would make signal attenuation the correct answer.

C

A question where users in a high-density office experience intermittent connectivity and low throughput despite strong signal, and multiple APs are on the same channel due to poor planning. The correct answer would be co-channel interference.

D

A question where users cannot connect to the network at all, or new devices fail to get an IP address, and the DHCP server shows no available addresses in the pool. For example: 'Users report that after adding 50 new devices, some cannot obtain an IP address. What is the most likely cause?'

Why candidates pick the wrong answer

A

Candidates may associate metal racks with blocking signals, leading them to think of attenuation, but they overlook that the signal strength is still high, which points to multipath rather than attenuation.

C

Candidates may confuse any wireless performance issue with interference, and 'co-channel interference' is a common cause of throughput drops, leading them to select it without considering the specific effect of metal racks causing multipath.

D

Candidates may think that connectivity loss implies an IP address issue, confusing 'loss of connectivity' with 'inability to connect' due to DHCP exhaustion.

207
MCQmedium

A user reports intermittent connectivity issues. The technician runs ping tests and notices that pings to the default gateway sometimes fail and sometimes succeed. While pinging, the technician observes that some replies have high latency. Which tool should the technician use to analyze the path and identify where packets are being delayed?

A.traceroute / tracert
B.nslookup
C.ipconfig
D.arp
AnswerA

Traceroute, or `tracert` on Windows, is the correct tool because it maps the entire network path to a destination by sending packets with progressively increasing Time-To-Live (TTL) values. Each intermediate router decrements the TTL and, when it reaches zero, sends an ICMP Time Exceeded message back to the source, revealing its IP address and the latency to that hop. This hop-by-hop analysis is crucial for pinpointing exactly where intermittent delays or packet loss are occurring along the route, which `ping` alone cannot determine.

Why this answer

Traceroute (tracert on Windows) is the correct tool because it sends packets with incrementing Time-to-Live (TTL) values to map the entire Layer 3 path from source to destination. By measuring the round-trip time (RTT) for each hop, it can pinpoint exactly which router or link is introducing high latency or packet loss, addressing the intermittent connectivity and delayed replies observed in the ping tests.

Exam trap

CompTIA often tests that candidates confuse ping (which only tests end-to-end reachability and latency) with traceroute (which isolates the problematic hop), leading them to overlook traceroute when the question explicitly asks for path analysis.

Why the other options are wrong

B

nslookup is used for DNS queries to resolve domain names to IP addresses, not for analyzing network path or packet delays. It cannot identify where packets are being delayed along a route.

C

ipconfig displays IP configuration settings (e.g., IP address, subnet mask, default gateway) but does not trace network paths or measure latency between hops, so it cannot identify where packets are being delayed.

D

ARP is used to resolve IP addresses to MAC addresses on a local network, not to trace the path or measure latency across multiple hops. It cannot identify where packets are being delayed along a route.

When would these options actually be correct?

B

A user reports that they cannot access a website by its domain name but can access it by IP address. The technician should use nslookup to verify DNS resolution and identify if the DNS server is returning correct records.

C

A user cannot connect to the internet. The technician needs to verify the IP address, subnet mask, and default gateway configuration on the client machine to ensure it is correctly configured for the network.

D

A technician needs to determine if there is a duplicate IP address on the local network causing intermittent connectivity. Running 'arp -a' and checking for multiple MAC addresses for the same IP would be the correct approach.

Why candidates pick the wrong answer

B

Candidates may confuse nslookup as a network troubleshooting tool for connectivity issues, not realizing it is specific to DNS and does not analyze path latency or hop-by-hop delays.

C

Candidates may think ipconfig can diagnose connectivity issues because it shows network settings, but they overlook that it provides only static configuration data, not dynamic path analysis.

D

Candidates may confuse ARP with a tool that can analyze network paths because it deals with network layer addressing, but it only operates on the local link and does not provide hop-by-hop latency information.

208
MCQeasy

A network technician is explaining the OSI model to a junior technician. The technician mentions that the Transport layer is responsible for end-to-end communication and data segmentation. Which protocol operates at the Transport layer?

A.IP
B.TCP
C.Ethernet
D.HTTP
AnswerB

TCP (Transmission Control Protocol) is a core protocol of the Transport layer (Layer 4) of the OSI model. It provides reliable, connection-oriented communication by establishing a three-way handshake before data transfer. TCP ensures data integrity through sequence numbers, acknowledgments, and retransmission of lost segments, also managing flow control and congestion control to optimize data delivery. This makes it suitable for applications requiring guaranteed delivery, such as web browsing and email.

Why this answer

TCP (Transmission Control Protocol) operates at Layer 4 (Transport) of the OSI model, providing reliable, connection-oriented end-to-end communication and data segmentation with sequencing and acknowledgment. It ensures data is delivered error-free and in order, directly fulfilling the described responsibilities.

Exam trap

CompTIA often tests the distinction between TCP and UDP at the Transport layer, but here the trap is that candidates confuse IP (Layer 3) with Transport layer protocols because IP is fundamental to networking, yet it does not perform end-to-end communication or segmentation.

Why the other options are wrong

A

IP operates at the Network layer (Layer 3), not the Transport layer. It handles routing and addressing, not end-to-end communication and data segmentation.

C

Ethernet operates at the Data Link layer (Layer 2) and the Physical layer (Layer 1), not the Transport layer (Layer 4). It handles local network framing and media access, not end-to-end communication or segmentation.

D

HTTP operates at the Application layer (Layer 7) of the OSI model, not the Transport layer. The Transport layer is responsible for end-to-end communication and segmentation, which is handled by protocols like TCP and UDP.

When would these options actually be correct?

A

A question asking 'Which protocol is responsible for logical addressing and routing between networks?' would make IP the correct answer, as it operates at the Network layer.

C

A question asking 'Which protocol operates at the Data Link layer of the OSI model?' would make Ethernet the correct answer, as it defines framing, MAC addressing, and media access control.

D

If the question asked 'Which protocol operates at the Application layer of the OSI model?' or 'Which protocol is used for web traffic?', then HTTP would be the correct answer.

Why candidates pick the wrong answer

A

Candidates often confuse IP with TCP because they are commonly paired (TCP/IP), leading them to mistakenly associate IP with Transport layer functions.

C

Candidates may confuse Ethernet with TCP/IP because both are fundamental to networking, or they might think Ethernet handles data delivery across networks, not realizing it is limited to local segments.

D

Candidates may confuse HTTP with TCP because HTTP relies on TCP for reliable transport, or they might mistakenly think HTTP is a transport protocol due to its common association with network communication.

209
MCQmedium

A network technician runs the command "traceroute 8.8.8.8" from a workstation. The output shows the first hop as the default gateway, the second hop as an internal router, and then a series of asterisks (* * *) before reaching the destination. What does the series of asterisks indicate?

A.The destination is unreachable
B.The intermediate routers are not responding to ICMP time-exceeded messages
C.The TTL expired at the last hop
D.The connection is encrypted
AnswerB

Traceroute works by sending packets with incrementally increasing Time-to-Live (TTL) values. When a router receives a packet with a TTL of 1, it decrements it to 0 and, by protocol, should send an ICMP Time Exceeded message back to the source. Asterisks in traceroute output signify that an intermediate router failed to send this expected ICMP response, often because its firewall is configured to drop such messages or due to rate limiting to prevent denial-of-service attacks, rather than forwarding them. This prevents the traceroute utility from identifying that specific hop.

Why this answer

The series of asterisks indicates that intermediate routers beyond the second hop are not responding with ICMP Time-Exceeded messages when the TTL expires. Traceroute relies on these ICMP responses to identify each hop; if a router is configured to drop ICMP or not send the message, the output shows asterisks for that hop. The destination is still reachable, as the final hop succeeds, so the asterisks do not indicate unreachability.

Exam trap

The N10-009 exam often tests the misconception that asterisks mean the destination is unreachable, but the key is that traceroute still reaches the final hop, so the asterisks only indicate missing ICMP responses from intermediate routers, not a failure to reach the target.

Why the other options are wrong

A

A series of asterisks in traceroute indicates that ICMP time-exceeded messages were not received from intermediate routers, not that the destination is unreachable. The destination (8.8.8.8) is reached, as shown by the final hop completing.

D

Encryption does not affect traceroute's ability to receive ICMP time-exceeded messages; asterisks indicate lack of response, not encryption.

When would these options actually be correct?

A

In a question where traceroute output shows asterisks at the final hop and no response from the destination, option A would be correct. For example: 'A traceroute to a remote server shows asterisks at the last hop and no final reply. What does this indicate?'

D

When a question asks what could cause a traceroute to show asterisks if the path uses encrypted tunnels that drop ICMP packets, or if the destination requires encrypted communication and the traceroute packets are blocked.

Why candidates pick the wrong answer

A

Candidates may assume that asterisks mean a failure to reach the destination, confusing a lack of response from intermediate hops with a complete unreachability of the target.

D

Candidates may confuse encryption with packet filtering or assume that encrypted paths hide intermediate hops, leading them to incorrectly attribute asterisks to encryption.

210
MCQhard

A security analyst is reviewing logs and finds that a single MAC address is rapidly requesting IP addresses from a DHCP server, each time with a different client ID. The DHCP server is exhausting its address pool. Which type of attack is occurring?

A.DHCP starvation attack
B.MAC flooding attack
C.ARP spoofing
D.DNS poisoning
AnswerA

This is exactly the description of a DHCP starvation attack, where the attacker floods the DHCP server with requests to deplete the address pool.

Why this answer

A DHCP starvation attack occurs when an attacker sends numerous DHCP discover messages, each with a unique client ID (chaddr), to exhaust the DHCP server's address pool. This prevents legitimate clients from obtaining IP addresses, as the server believes all leases are assigned. The rapid requests with different client IDs from a single MAC address are a hallmark of this attack.

Exam trap

The trap here is confusing DHCP starvation with MAC flooding, as both involve 'flooding' and MAC addresses, but MAC flooding targets switch CAM tables, not DHCP servers.

Why the other options are wrong

B

MAC flooding attacks target switch MAC address tables by sending many frames with different source MAC addresses, not by exhausting DHCP IP address pools via rapid DHCP requests.

C

ARP spoofing involves sending forged ARP replies to associate an attacker's MAC address with a legitimate IP address, not exhausting DHCP address pools by rapidly requesting IPs with different client IDs.

D

DNS poisoning involves corrupting DNS resolver caches to redirect traffic, not exhausting DHCP address pools via rapid requests with varying client IDs.

When would these options actually be correct?

B

A question describing a switch that stops forwarding traffic correctly after receiving a flood of frames with unique source MAC addresses, causing the CAM table to overflow, would make MAC flooding the correct answer.

C

A question describing an attacker sending fake ARP messages to intercept traffic between two hosts on the same subnet, causing man-in-the-middle attacks or denial of service, would make ARP spoofing the correct answer.

D

A question describing an attacker modifying DNS records to redirect users to a malicious site, or a scenario where users are being sent to incorrect IP addresses due to compromised DNS data.

Why candidates pick the wrong answer

B

Candidates confuse 'MAC address' in the log with MAC flooding, and both attacks involve exhaustion of a network resource, leading to a superficial association.

C

Candidates may confuse DHCP starvation with ARP spoofing because both involve MAC addresses and network layer attacks, but the specific mechanism of exhausting DHCP leases is unique to starvation attacks.

D

Candidates may confuse network-layer attacks, thinking that any attack involving IP address manipulation could be DNS-related, or they may not clearly distinguish between DHCP and DNS functions.

211
MCQeasy

A security auditor is reviewing firewall logs and notices repeated login attempts from a single external IP address to the company's SSH server. Which type of attack is likely occurring?

A.Brute force attack
B.Man-in-the-middle attack
C.ARP poisoning
D.DDoS attack
AnswerA

A brute force attack involves systematically trying numerous combinations of usernames and passwords to gain unauthorized access to a system or service, such as SSH. The firewall logs showing repeated login attempts from a single IP address are a definitive indicator of such an attack, as the attacker is attempting to guess credentials through exhaustive trial and error. This pattern aims to eventually find a valid credential pair rather than exploiting a vulnerability.

Why this answer

Repeated login attempts from a single external IP to an SSH server are characteristic of a brute force attack, where an attacker systematically tries many username/password combinations to gain unauthorized access. SSH (port 22) is a common target because it provides remote shell access, and automated tools like Hydra or Medusa can rapidly test credentials. The firewall logs show multiple failed authentication attempts from the same source, which is the hallmark of this attack type.

Exam trap

The N10-009 exam often tests the distinction between a brute force attack (repeated single-source login attempts) and a DDoS attack (traffic flood from multiple sources), so candidates mistakenly choose DDoS when they see 'repeated attempts' without recognizing the single-source, credential-guessing nature of the activity.

Why the other options are wrong

B

A man-in-the-middle attack involves intercepting communication between two parties, not repeated login attempts from a single external IP to an SSH server.

C

ARP poisoning operates at Layer 2 by corrupting ARP tables to intercept traffic on a local network, whereas the question describes repeated login attempts from a single external IP to an SSH server, which is a Layer 7 authentication attack.

D

A DDoS attack aims to overwhelm a service with traffic from multiple sources, causing denial of service. This scenario describes repeated login attempts from a single IP, which is characteristic of a brute force attack, not a DDoS.

When would these options actually be correct?

B

A question describing an attacker intercepting SSH traffic between a client and server, possibly using ARP spoofing or a rogue access point, to capture credentials or session data.

C

A question describing an attacker on the same subnet sending forged ARP replies to associate the attacker's MAC address with the default gateway's IP, causing traffic to be redirected to the attacker, would make ARP poisoning the correct answer.

D

A DDoS attack would be correct if the question described a flood of traffic from many distributed sources (e.g., botnet) targeting the SSH server, causing service unavailability, rather than repeated login attempts from one IP.

Why candidates pick the wrong answer

B

Candidates may confuse repeated login attempts with an active interception attack, or think SSH brute force involves intercepting authentication traffic.

C

Candidates may confuse network-based attacks like ARP poisoning with brute force attacks, or mistakenly think that repeated login attempts involve intercepting credentials, which is a characteristic of man-in-the-middle attacks, not ARP poisoning.

D

Candidates may confuse repeated attempts with a denial of service, or think that any high volume of traffic from one source qualifies as DDoS, overlooking the distributed nature requirement.

212
MCQhard

A user reports intermittent inability to access websites. When the issue occurs, the user can ping external IP addresses (e.g., 8.8.8.8) but cannot ping domain names like google.com. The user's IP configuration shows a DNS server address of 8.8.8.8. What is the most likely cause?

A.The DNS server is reachable but not responding due to high load.
B.The default gateway is down.
C.The corporate firewall is blocking UDP port 53.
D.The user's machine has a corrupted DNS cache.
AnswerA

Correct. If the DNS server is overloaded, it may drop queries intermittently. The user can still ping the server (ICMP is different from DNS), but DNS queries time out.

Why this answer

The user can ping external IP addresses (e.g., 8.8.8.8) but cannot resolve domain names like google.com, which indicates that IP connectivity is working but DNS resolution is failing. Since the DNS server address is 8.8.8.8 and the user can ping it, the server is reachable; however, intermittent failures suggest the server is overwhelmed and dropping or not responding to queries. This matches the symptom of a reachable but unresponsive DNS server due to high load, where ICMP (ping) succeeds but UDP/53 DNS queries time out.

Exam trap

The trap here is that candidates often assume a reachable server (via ping) means all services are working, but CompTIA Network+ exams test the distinction between ICMP reachability and UDP/TCP service availability, especially for DNS where high load can cause intermittent failures.

Why the other options are wrong

B

If the default gateway were down, the user would not be able to ping external IP addresses like 8.8.8.8, but the user can ping them successfully.

C

The user can ping external IP addresses (8.8.8.8) but not domain names, indicating DNS resolution failure. A firewall blocking UDP port 53 would prevent all DNS queries, making it impossible to ping domain names, but the user's DNS server is 8.8.8.8 (Google's public DNS), which is external. A corporate firewall typically blocks outbound DNS to external servers, but here the issue is intermittent and the DNS server is reachable (since pings to 8.8.8.8 succeed).

D

A corrupted DNS cache would cause consistent resolution failures, not intermittent issues. The user can ping external IPs but not domain names, indicating DNS resolution fails intermittently, which points to a server-side problem rather than a local cache issue.

When would these options actually be correct?

B

A user cannot access any external resources, including pinging external IP addresses, and the default gateway is unreachable from the user's subnet. This would indicate a default gateway failure.

C

In a scenario where a user cannot access any websites and cannot ping any IP addresses or domain names, and network connectivity is otherwise fine, the corporate firewall blocking UDP port 53 would be the likely cause. For example, if the user's DNS server is internal and the firewall blocks all DNS traffic, or if the firewall is misconfigured to drop DNS packets.

D

This option would be correct if the user reported persistent inability to resolve domain names (e.g., always fails to ping google.com) while other network functions work, and flushing the DNS cache resolves the issue. For example, after a malware infection or misconfigured cache entries.

Why candidates pick the wrong answer

B

Candidates may assume that any internet connectivity issue is due to the default gateway, overlooking that successful external pings rule out gateway problems.

C

Candidates may assume that DNS issues are often caused by firewall blocks, especially in corporate environments. They might overlook that the user can ping the DNS server's IP, which suggests the firewall is not blocking all traffic to that server.

D

Candidates may think DNS cache corruption is a common cause of resolution problems, and the intermittent nature might be misinterpreted as cache corruption that sometimes works. They overlook that cache corruption typically causes consistent failures until cleared.

213
MCQeasy

A network monitoring tool uses SNMP to collect data from devices. What is the primary purpose of SNMP traps?

A.To allow a manager to poll devices for current status
B.To enable devices to send unsolicited alerts to the management system
C.To encrypt SNMP communications
D.To provide authentication for SNMP messages
AnswerB

SNMP traps are critical for proactive network monitoring, allowing managed devices (agents) to spontaneously notify a central management system (manager) about significant events or threshold breaches without being explicitly polled. This unsolicited communication mechanism ensures that administrators are immediately alerted to issues like device reboots, interface status changes, or high resource utilization, facilitating rapid response and problem resolution.

Why this answer

SNMP traps are unsolicited messages sent by an SNMP agent to the network management system (NMS) to immediately notify it of a significant event, such as a link failure or high CPU utilization. This push mechanism allows the NMS to react in real time without having to poll the device, reducing bandwidth and processing overhead. The correct answer is B because traps are specifically designed for asynchronous alerting, not for polling, encryption, or authentication.

Exam trap

The N10-009 exam often tests the distinction between traps (unsolicited, unconfirmed) and informs (confirmed), and candidates mistakenly think traps are used for polling or that they inherently provide security features like encryption or authentication.

Why the other options are wrong

A

SNMP traps are unsolicited messages sent by devices to the management system, not responses to polls. Polling for current status is the function of SNMP Get requests, not traps.

C

SNMP traps are unsolicited alerts from devices, not encryption. SNMPv3 provides encryption (via USM), but traps themselves do not encrypt communications.

D

SNMP traps are unsolicited notifications from devices to the management system, not a mechanism for authentication. Authentication is provided by SNMPv3 security features, not by traps.

When would these options actually be correct?

A

This option would be correct for a question like: 'What is the primary purpose of SNMP Get requests?' or 'Which SNMP operation allows a manager to actively request data from a device?'

C

For a question like 'Which SNMP version adds encryption for secure communications?' or 'What feature of SNMPv3 protects message confidentiality?', option C would be correct.

D

A question asking 'What is the purpose of SNMPv3's User-based Security Model (USM)?' would have 'To provide authentication for SNMP messages' as a correct answer, as USM ensures message integrity and authentication.

Why candidates pick the wrong answer

A

Candidates may confuse traps with polling because both are used for monitoring, but traps are event-driven while polling is request-driven.

C

Candidates may confuse traps with security features, or think that traps inherently include encryption because they are used in secure monitoring environments.

D

Candidates may confuse the security features of SNMPv3 (authentication and encryption) with the function of traps, or think that traps inherently include authentication mechanisms.

214
MCQmedium

A network administrator is configuring a new switch to carry traffic for multiple VLANs on a single link to a router. Which IEEE standard is used for VLAN tagging on Ethernet trunks?

A.802.3af
B.802.1D
C.802.1Q
D.802.11ac
AnswerC

IEEE 802.1Q is the industry standard for Virtual Local Area Network (VLAN) tagging on Ethernet networks. It inserts a 4-byte tag into the Ethernet frame header, specifically between the Source Address and Type/Length fields, to carry VLAN identification (VID) information. This tagging allows a single physical link, known as a trunk port, to transport traffic for multiple VLANs, enabling switches to correctly forward frames to their intended VLAN segments. Without 802.1Q, a switch port can typically only belong to a single VLAN.

Why this answer

802.1Q is the IEEE standard that defines VLAN tagging on Ethernet trunks, inserting a 4-byte tag into the Ethernet frame to identify VLAN membership. This allows multiple VLANs to traverse a single link between a switch and a router, enabling inter-VLAN routing without separate physical interfaces.

Exam trap

The N10-009 exam often tests the distinction between 802.1Q (tagging) and 802.1D (STP), leading candidates to confuse VLAN trunking with loop prevention protocols.

Why the other options are wrong

A

802.3af is the IEEE standard for Power over Ethernet (PoE), not for VLAN tagging on Ethernet trunks.

B

802.1D is the IEEE standard for Spanning Tree Protocol (STP), not for VLAN tagging on Ethernet trunks. VLAN tagging is defined by 802.1Q.

D

802.11ac is a wireless networking standard for Wi-Fi, not used for VLAN tagging on Ethernet trunks.

When would these options actually be correct?

A

A question asking which standard provides power to devices like IP cameras or wireless access points over Ethernet cabling would have 802.3af as the correct answer.

B

A question asking 'Which IEEE standard defines the Spanning Tree Protocol for loop prevention in Ethernet networks?' would make 802.1D the correct answer.

D

When asked which IEEE standard supports high-throughput wireless LANs in the 5 GHz band with multi-user MIMO, 802.11ac would be the correct answer.

Why candidates pick the wrong answer

A

Candidates may confuse the 802.3 series with 802.1 standards, or mistakenly think that PoE is related to trunking because both are common switch features.

B

Candidates may confuse 802.1D with 802.1Q due to similar numbering, or mistakenly think that trunking involves spanning tree concepts.

D

Candidates may confuse the 802.11 series (wireless) with 802.1 series (networking/bridging) due to similar numbering, or mistakenly think VLAN tagging applies to wireless links.

215
MCQmedium

A technician is troubleshooting a user's computer that cannot access any network resources. The technician runs ipconfig and sees an IP address of 169.254.18.33 with a subnet mask of 255.255.0.0. The computer is connected to a switch port configured for VLAN 10. The DHCP server is located in a different subnet (VLAN 200) and is reachable via a router. The technician confirms that the switch port is in the correct VLAN and that the cabling is good. Which of the following is the MOST likely cause of the issue?

A.The DHCP server is not authorized in Active Directory
B.The router does not have a DHCP relay (ip helper-address) configured
C.The computer's NIC is faulty
D.The switch port is in the wrong VLAN
AnswerB

Without a DHCP relay configured on the router, DHCP broadcast requests from clients cannot traverse different IP subnets or VLANs to reach a DHCP server located in another segment. The `ip helper-address` command (or equivalent) is essential for the router to convert these broadcasts into unicast packets and forward them to the specified DHCP server. Consequently, the client's DHCP discovery request never reaches the server, leading to a timeout and the assignment of an Automatic Private IP Addressing (APIPA) address.

Why this answer

The 169.254.x.x address is an Automatic Private IP Addressing (APIPA) address, assigned when a DHCP client fails to receive a lease. Since the DHCP server is on VLAN 200 and the client is on VLAN 10, a DHCP relay (ip helper-address) must be configured on the router interface facing VLAN 10 to forward DHCP broadcast requests as unicast to the DHCP server. Without this relay, the DHCP server never receives the client's discover message, causing the client to self-assign an APIPA address.

Exam trap

The trap here is that candidates see a 169.254.x.x address and immediately blame a faulty NIC or DHCP server issue, overlooking the need for a DHCP relay when the server is on a different subnet.

Why the other options are wrong

A

The computer received an APIPA address (169.254.x.x), indicating it failed to get a DHCP lease. DHCP server authorization in Active Directory is irrelevant because the issue is that DHCP requests from VLAN 10 are not reaching the DHCP server in VLAN 200 due to missing relay configuration.

C

A faulty NIC would typically cause no link or intermittent connectivity, but the computer obtained an APIPA address (169.254.x.x), indicating the NIC is functional and can communicate on the local link. The issue is that DHCP requests are not reaching the DHCP server across VLANs.

D

The question states the technician confirmed the switch port is in the correct VLAN (VLAN 10), so the port is not in the wrong VLAN. The IP address 169.254.x.x indicates APIPA, which occurs when DHCP fails, not due to VLAN misconfiguration.

When would these options actually be correct?

A

This would be correct in a scenario where DHCP clients are on the same subnet as the DHCP server, the server is running Windows, and clients receive 'No DHCP server available' errors despite the server being operational. In that case, unauthorized DHCP server in AD would prevent it from leasing addresses.

C

A technician finds a computer with no network connectivity and no IP address (or a 169.254.x.x address) after replacing the NIC. The switch port shows link but the computer cannot obtain an IP address even after static configuration fails. In that scenario, a faulty NIC would be the likely cause.

D

A technician sees a computer with an IP address from a different subnet than expected (e.g., 192.168.1.x instead of 10.0.0.x) and the switch port is configured for a different VLAN than the one the computer is physically connected to. In that case, the wrong VLAN assignment would cause the incorrect IP address.

Why candidates pick the wrong answer

A

Candidates may confuse DHCP server authorization with general DHCP availability issues, especially if they have studied Windows DHCP server deployment and know that unauthorized servers do not respond to requests, but they overlook the cross-subnet relay requirement here.

C

Candidates may think that any network issue could be due to hardware failure, especially when connectivity is completely absent. The APIPA address might be misinterpreted as a symptom of a faulty NIC rather than a DHCP relay problem.

D

Candidates may assume that any network connectivity issue with a VLAN configuration is due to the port being in the wrong VLAN, especially when the problem involves DHCP and subnet mismatches.

216
MCQmedium

After replacing a faulty network cable, a user reports that they can access local resources but not the internet. The technician verifies that the user's IP address is 192.168.1.100 with a subnet mask of 255.255.255.0 and a default gateway of 192.168.1.1. The technician can ping the default gateway successfully. Which of the following should the technician check NEXT?

A.A) DNS configuration
B.B) DHCP server
C.C) Router's firewall ACLs
D.D) Switch port VLAN assignment
AnswerA

If a user can successfully ping the default gateway (an IP address) but cannot access external websites by their domain names, it strongly indicates a DNS resolution failure. DNS (Domain Name System) is responsible for translating human-readable domain names into numerical IP addresses that computers use for routing. Without correct DNS configuration, the client cannot resolve domain names to IP addresses, preventing access to external resources even if underlying network connectivity to the internet gateway exists.

Why this answer

The user can access local resources and successfully ping the default gateway, which confirms that Layer 2 and Layer 3 connectivity to the local network is working. The inability to access the internet while local access works points to a name resolution failure, as the browser relies on DNS to translate domain names to IP addresses. Checking DNS configuration is the logical next step because a misconfigured or missing DNS server would prevent internet access even when IP connectivity is intact.

Exam trap

The trap here is that candidates assume internet access failure must be a gateway or routing issue, but the successful ping to the default gateway proves Layer 3 connectivity is fine, forcing the focus to DNS as the most common cause of 'can't browse but can ping local.'

Why the other options are wrong

B

The user can access local resources and ping the default gateway, indicating DHCP and IP configuration are correct. The issue is internet access, which typically points to DNS resolution, not DHCP.

C

The technician can already ping the default gateway successfully, indicating that the router's firewall ACLs are not blocking traffic at Layer 3. The issue is likely DNS resolution, not firewall rules.

D

The user can access local resources and ping the default gateway, indicating Layer 2 and Layer 3 connectivity within the local subnet. A switch port VLAN misconfiguration would typically prevent local communication or gateway access, not just internet access.

When would these options actually be correct?

B

A technician should check the DHCP server when a user cannot obtain an IP address or receives an incorrect one (e.g., 169.254.x.x), or when multiple users report connectivity issues after a DHCP scope change.

C

A technician finds that a user cannot access any external resources, and pinging the default gateway fails. After verifying the IP configuration is correct, the technician should check the router's firewall ACLs to see if outbound traffic is being blocked.

D

If a user cannot access any network resources (local or internet) after a cable replacement, and other devices on the same switch port work, checking the switch port VLAN assignment would be appropriate to ensure the port is in the correct VLAN.

Why candidates pick the wrong answer

B

Candidates may think the new cable caused a DHCP renewal issue, but the user already has a valid IP and can ping the gateway, so DHCP is not the problem.

C

Candidates may think that since the user can access local resources but not the internet, the router's firewall must be blocking outbound traffic, overlooking that successful gateway ping indicates Layer 3 connectivity.

D

Candidates may think that a VLAN misconfiguration could block internet traffic while allowing local traffic, but VLANs operate at Layer 2 and would affect all traffic through that port, not selectively.

217
MCQmedium

A network administrator is deploying a wireless network in a warehouse environment with many metal racks. Clients using 802.11ac report strong signal strength but very low throughput. What is the most likely cause?

A.Co-channel interference from neighboring access points
B.Multipath interference caused by signal reflections off metal surfaces
C.The encryption method is set to WEP, which limits throughput
D.Too many clients are connected to the same access point
AnswerB

In a warehouse environment, metal racks, shelving, and machinery act as excellent reflectors for wireless signals. This causes radio waves to travel multiple paths to the receiver, arriving at slightly different times and phases. This phenomenon, known as multipath interference, leads to signal distortion, constructive and destructive interference, and increased retransmissions, significantly reducing effective throughput even when the overall signal strength appears strong. While technologies like MIMO (Multiple-Input Multiple-Output) are designed to mitigate multipath, severe reflections in such environments can still overwhelm the system and degrade performance.

Why this answer

In a warehouse with many metal racks, 802.11ac signals reflect off the metal surfaces, creating multiple signal paths that arrive at the receiver at slightly different times. This multipath interference causes phase cancellation and intersymbol interference, which degrades the signal-to-noise ratio and forces the use of lower modulation and coding schemes (MCS), drastically reducing throughput despite strong RSSI.

Exam trap

The trap here is that candidates see 'strong signal strength' and assume the issue is at Layer 2 or higher (co-channel interference, encryption, or client count), but the metal racks create a classic multipath scenario where RSSI is high but SNR is low due to phase cancellation.

Why the other options are wrong

A

Co-channel interference typically causes signal degradation and reduced throughput, but the question states strong signal strength, which is inconsistent with co-channel interference. The low throughput here is due to multipath from metal racks, not neighboring AP interference.

C

WEP encryption is outdated and insecure, but it does not inherently limit throughput; modern 802.11ac clients can still achieve high data rates with WEP. The low throughput in this scenario is due to multipath interference from metal racks, not encryption.

When would these options actually be correct?

A

In a scenario where clients report weak signal strength and high packet loss near channel boundaries, and multiple APs are on the same channel in a dense deployment, co-channel interference would be the likely cause.

C

A question describing a legacy 802.11b/g network where clients experience very low throughput and the configuration uses WEP. In that context, WEP's overhead and inefficiency could be a bottleneck, especially if the network is old and not optimized.

Why candidates pick the wrong answer

A

Candidates may confuse symptoms of multipath (strong signal, low throughput) with co-channel interference, or they may default to interference as a common cause of throughput issues without considering the specific environment.

C

Candidates may recall that WEP is obsolete and associate it with poor performance, but they overlook that 802.11ac is modern and supports stronger encryption without throughput degradation.

218
MCQeasy

A network administrator wants to automate the backup of configuration files from multiple routers and switches. Which protocol is commonly used for this purpose and is supported by most network devices?

A.FTP
B.TFTP
C.SFTP
D.HTTP
AnswerB

TFTP is a lightweight, connectionless protocol operating over UDP port 69, making it exceptionally simple for transferring small files. Its lack of authentication and minimal overhead allows for highly efficient, automated backups of configuration files from numerous network devices without complex setup or user interaction, which is ideal for routine, programmatic tasks.

Why this answer

TFTP (Trivial File Transfer Protocol) is the correct choice because it is a lightweight, connectionless UDP-based protocol (port 69) that is widely supported on network devices like routers and switches for automated configuration backups. Its simplicity and minimal overhead make it ideal for scripting backup operations, even though it lacks security features like authentication or encryption.

Exam trap

The N10-009 exam often tests the distinction between TFTP and FTP/SFTP by emphasizing that TFTP is the simplest and most universally supported protocol for automated backups, even though it lacks security, leading candidates to incorrectly choose SFTP for its encryption without considering device support limitations.

Why the other options are wrong

A

FTP requires authentication and is more complex than needed for automated backups; many network devices do not support FTP server functionality, and it is less commonly used for this purpose compared to TFTP.

C

SFTP is not commonly used for automated backups of network device configurations because it requires SSH, which many older or simpler routers and switches do not support. TFTP is the standard due to its simplicity and widespread device support.

D

HTTP is not commonly used for automated backups of router/switch configurations because it lacks the simplicity and widespread support for device-to-server file transfers that TFTP offers; most network devices do not natively support HTTP for configuration backup.

When would these options actually be correct?

A

When the question specifies a need for secure file transfer with authentication and encryption, or when transferring large files over a reliable network where FTP's error-checking is beneficial.

C

In a scenario where the network devices support SSH and the administrator requires encrypted file transfers for security compliance, SFTP would be the correct choice over TFTP.

D

HTTP would be correct in a scenario where the question specifies backing up configuration files to a web server using a web interface, or when the devices support REST APIs for configuration management over HTTP/HTTPS.

Why candidates pick the wrong answer

A

Candidates may know FTP is a common file transfer protocol and assume it is suitable for network device backups, overlooking that TFTP is simpler and more widely supported for this specific task.

C

Candidates may confuse SFTP with TFTP due to similar names, or assume that SFTP's security features make it a better choice for backups, overlooking that many network devices lack SFTP support.

D

Candidates may confuse HTTP with TFTP due to both being application-layer protocols, or mistakenly think HTTP is commonly used for device backups because of its ubiquity in web services.

219
MCQeasy

A network technician is reviewing the OSI model to understand how data is encapsulated when a web request is sent from a client to a server. At which layer does the web browser's HTTP request data get encapsulated with a TCP segment header?

A.Application layer
B.Presentation layer
C.Session layer
D.Transport layer
AnswerD

The Transport layer (Layer 4) is responsible for end-to-end communication between applications, segmenting data from upper layers and reassembling it at the destination. It adds either a TCP header for reliable, connection-oriented delivery (like for HTTP) or a UDP header for unreliable, connectionless delivery. This header includes source and destination port numbers, enabling multiplexing and demultiplexing of data streams to specific applications.

Why this answer

The Transport layer (Layer 4) is responsible for encapsulating application data with a TCP or UDP segment header. When a web browser sends an HTTP request, the HTTP data is passed down from the Application layer to the Transport layer, where the TCP segment header (including source/destination ports, sequence numbers, and checksum) is added. This encapsulation occurs at Layer 4, not at any higher layer.

Exam trap

The trap here is that candidates often confuse the Application layer (where HTTP data is generated) with the layer where the TCP header is added, mistakenly thinking encapsulation happens at Layer 7 instead of Layer 4.

Why the other options are wrong

A

HTTP operates at the Application layer (Layer 7), but the TCP segment header is added at the Transport layer (Layer 4) during encapsulation. The question specifically asks where the HTTP data gets encapsulated with a TCP segment header, which occurs at the Transport layer, not the Application layer.

B

The Presentation layer (Layer 6) handles data translation, encryption, and compression, not encapsulation with TCP segment headers. TCP segment headers are added at the Transport layer (Layer 4).

C

The Session layer (Layer 5) manages sessions, not encapsulation of data into segments; TCP segment headers are added at the Transport layer (Layer 4).

When would these options actually be correct?

A

This option would be correct if the question asked: 'At which layer does the web browser's HTTP request data originate or get created?' or 'At which layer does the HTTP protocol operate?'

B

A question asking at which layer data encryption (e.g., TLS) occurs during a secure web request would have the Presentation layer as the correct answer, as it handles encryption services.

C

A question asking: 'At which OSI layer does a protocol establish, maintain, and terminate a communication session between two applications?' would make Session layer the correct answer.

Why candidates pick the wrong answer

A

Candidates often confuse the layer where a protocol operates with the layer where its data is encapsulated by the next lower layer. Since HTTP is an application-layer protocol, they mistakenly think the HTTP data is encapsulated at the Application layer.

B

Candidates may confuse the Presentation layer's role in formatting data for the application with the Transport layer's role in segmenting and adding headers, especially when thinking about HTTP data being prepared for transmission.

C

Candidates may confuse the Session layer's role in managing dialogue control with the encapsulation process, or think that HTTP (an application protocol) is directly encapsulated at a higher layer.

220
MCQhard

A company is connecting two buildings that are 300 meters apart. The link must support 10 Gbps. Which combination of cable and transceiver should be used?

A.Cat6a UTP with 10GBASE-T
B.Cat5e UTP with 1000BASE-T
C.Single-mode fiber with 10GBASE-LR
D.Multimode fiber with 10GBASE-SR
AnswerC

10GBASE-LR is specifically designed for long-reach 10 Gigabit Ethernet over single-mode fiber, supporting distances up to 10 kilometers. This makes it an ideal and robust solution for connecting two buildings 300 meters apart, providing ample bandwidth and significant distance headroom. Single-mode fiber minimizes modal dispersion, ensuring signal integrity over extended runs and offering excellent future-proofing.

Why this answer

Single-mode fiber (SMF) with 10GBASE-LR supports 10 Gbps over distances up to 10 km, easily covering the 300-meter requirement. 10GBASE-LR uses 1310 nm laser optics over single-mode fiber, providing low signal loss and high bandwidth for long-reach links.

Exam trap

The trap here is that candidates often assume Cat6a can handle 10 Gbps at any distance, forgetting the 100-meter limitation for twisted-pair copper, or they confuse 10GBASE-LR with 10GBASE-SR, which has a shorter reach on multimode fiber.

Why the other options are wrong

A

Cat6a UTP with 10GBASE-T is limited to 100 meters for 10 Gbps, but the distance is 300 meters, exceeding the maximum reach.

B

Cat5e UTP with 1000BASE-T supports only 1 Gbps, not the required 10 Gbps, and has a maximum distance of 100 meters, insufficient for 300 meters.

D

Multimode fiber with 10GBASE-SR is limited to distances up to 300-400 meters depending on the fiber type (OM3/OM4), but the question specifies a 300-meter link requiring 10 Gbps. While technically possible with OM4, single-mode fiber (10GBASE-LR) is more reliable and standard for this distance, and the correct answer is explicitly single-mode fiber with 10GBASE-LR.

When would these options actually be correct?

A

A question where two buildings are 80 meters apart and require 10 Gbps, with cost as a primary concern, would make Cat6a UTP with 10GBASE-T the correct choice.

B

A question asking for a 1 Gbps link over 100 meters or less, such as connecting two switches within the same building at 1 Gbps, would make Cat5e UTP with 1000BASE-T correct.

D

A question where the distance is less than 300 meters (e.g., 200 meters) and cost is a primary concern, or where the existing infrastructure already uses multimode fiber. For example: 'A company needs to connect two buildings 200 meters apart at 10 Gbps using existing fiber. Which combination should be used?'

Why candidates pick the wrong answer

A

Candidates may mistakenly believe Cat6a supports 10 Gbps over longer distances, or confuse the distance limits of twisted-pair cabling with fiber.

B

Candidates may confuse Cat5e's capability, thinking it supports 10 Gbps over short distances, or overlook the distance limitation and speed requirement.

D

Candidates may confuse the distance limitations of multimode fiber, thinking 10GBASE-SR can reach 300 meters (it can with OM4), and overlook that single-mode fiber is the standard for longer distances and higher reliability. They might also assume multimode is cheaper and sufficient.

221
MCQmedium

A security engineer is configuring port security on a switch to prevent unauthorized devices from connecting. The requirement is that only the first device to connect to a port is allowed, and if a different device connects, the port should be disabled. Which port security violation mode should be configured?

A.Protect
B.Restrict
C.Shutdown
D.Sticky
AnswerC

Shutdown mode is the most stringent port security violation action, immediately disabling the switch port upon detection of an unauthorized MAC address. This action effectively takes the port offline, preventing any further traffic flow and completely blocking unauthorized access attempts. Re-enabling the port typically requires manual intervention by an administrator, making it a highly secure but operationally impactful response that directly prevents unauthorized use.

Why this answer

The 'shutdown' violation mode disables the port entirely when a violation occurs, which meets the requirement that the port be disabled if a different device connects. This is the only mode that physically err-disables the port, preventing any further traffic until manually re-enabled.

Exam trap

The N10-009 exam often tests the distinction that 'shutdown' is the only mode that physically disables the port, while 'restrict' and 'protect' only filter traffic but leave the port administratively up, leading candidates to mistakenly choose 'restrict' because it logs violations.

Why the other options are wrong

A

The Protect mode drops traffic from unauthorized devices but does not disable the port, which contradicts the requirement that the port should be disabled when a different device connects.

B

Restrict mode allows traffic from unauthorized devices but logs the violation and increments a counter; it does not disable the port, which is required by the question's condition that the port be disabled when a different device connects.

D

Sticky is not a violation mode; it is a feature that dynamically learns MAC addresses and adds them to the running configuration. The question asks for a violation mode that disables the port when a different device connects, which is 'shutdown'.

When would these options actually be correct?

A

When the requirement is to silently drop traffic from unauthorized devices without generating alerts or disabling the port, such as in a low-security environment where only traffic filtering is needed.

B

A question where the requirement is to log and alert on unauthorized access attempts without disrupting existing traffic, such as 'A security engineer wants to monitor for unauthorized devices on a port while allowing them to connect for auditing purposes. Which violation mode should be used?'

D

A question asks: 'Which port security feature allows a switch to automatically learn and save MAC addresses to the running configuration to prevent unauthorized devices?' In that case, sticky learning would be the correct answer.

Why candidates pick the wrong answer

A

Candidates may confuse 'protect' with 'shutdown' because both involve preventing unauthorized access, but they overlook that protect does not disable the port.

B

Candidates may confuse 'restrict' with 'shutdown' because both respond to violations, but 'restrict' sounds like it would block access, whereas it actually only logs and allows traffic.

D

Candidates may confuse 'sticky' with a violation mode because it is often used in conjunction with port security to enforce MAC address limits, leading them to think it handles violations.

222
MCQmedium

A user reports that they cannot access the internet. The user's workstation has an IP address of 192.168.1.100/24, with a default gateway of 192.168.1.1. The user can ping the default gateway but cannot ping 8.8.8.8. Other users on the same subnet can ping 8.8.8.8. The technician checks the switch and sees the user's port is up. What should the technician check next?

A.Check the router's routing table for a route to the internet
B.Check the workstation's IP configuration for a misconfigured default gateway or DNS
C.Check the DNS server configuration on the workstation
D.Check the switch port for VLAN misconfiguration
AnswerB

The user can ping the gateway, so the gateway IP (192.168.1.1) is reachable. But if the gateway is not the correct router for internet access, or if the workstation has a local firewall blocking outbound traffic, internet access may fail.

Why this answer

Since the user can ping the default gateway (192.168.1.1) but not 8.8.8.8, while other users on the same subnet can reach 8.8.8.8, the issue is isolated to this workstation. The most likely cause is a misconfigured default gateway (e.g., wrong IP or subnet mask) or DNS settings, as the gateway is reachable but traffic is not being forwarded correctly. Option B directly addresses checking the workstation's IP configuration for these misconfigurations, which is the logical next step after verifying local connectivity.

Exam trap

The trap here is that candidates often jump to checking the router's routing table (Option A) or DNS (Option C) when the symptom is a ping failure to an IP address, but the key clue is that other users on the same subnet are unaffected, isolating the problem to the workstation's configuration.

Why the other options are wrong

A

The user can ping the default gateway but not 8.8.8.8, while other users on the same subnet can. This indicates the router's internet routing is working; the issue is isolated to the workstation, not the router's routing table.

C

The user can ping the default gateway but not 8.8.8.8, indicating the issue is with routing beyond the local network, not DNS. DNS is irrelevant because the test uses an IP address (8.8.8.8), not a hostname.

D

The user can ping the default gateway but not 8.8.8.8, while other users on the same subnet can ping 8.8.8.8. This indicates the issue is isolated to the workstation, not a VLAN misconfiguration on the switch, which would affect all users in that VLAN.

When would these options actually be correct?

A

If all users on the subnet cannot ping 8.8.8.8, but can ping the default gateway, then the router likely lacks a default route to the internet, making checking the routing table the correct next step.

C

A user reports they cannot access a website by name (e.g., www.example.com) but can ping 8.8.8.8. Other users can access the website. The workstation has correct IP and gateway settings.

In this scenario, DNS misconfiguration is the likely cause.

D

A technician finds that all users on a specific switch port cannot access the internet, but other ports work. The switch port is up, but pinging the default gateway fails. In this scenario, checking for VLAN misconfiguration (e.g., port assigned to wrong VLAN) would be the next logical step.

Why candidates pick the wrong answer

A

Candidates may assume internet access failure is always a routing problem, overlooking that the symptom is isolated to one workstation, which points to a local configuration issue.

C

Candidates often confuse internet access issues with DNS problems, especially when the symptom is 'cannot access the internet' without specifying whether it's by name or IP.

D

Candidates may think that since the switch port is up but connectivity is broken, a VLAN mismatch could be the cause, overlooking that the issue is isolated to one workstation and the gateway is reachable.

223
MCQeasy

A network engineer needs to install 15 wireless access points that each require 25W of power. The available switch provides PoE+ (802.3at) with a total power budget of 740W. The engineer also needs to connect 10 IP cameras that each require 12W. Which of the following should the engineer verify before proceeding with the installation?

A.The total power consumption of all devices does not exceed the switch's power budget.
B.The switch supports LLDP-MED for power negotiation.
C.All PoE devices are from the same manufacturer.
D.The cable length does not exceed 150 meters.
AnswerA

This is a critical consideration for any Power over Ethernet (PoE) deployment. Each PoE switch has a finite power budget, representing the maximum total wattage it can supply across all its PoE-enabled ports. If the combined power requirements of all connected Powered Devices (PDs), such as 15 wireless access points each needing 25W (totaling 375W), exceed this budget, the switch will be unable to provide sufficient power to all devices, leading to some devices failing to power on or operate reliably. Therefore, calculating the total power draw and ensuring it is less than or equal to the switch's advertised power budget is a fundamental design requirement.

Why this answer

The total power required is 15 APs × 25W + 10 cameras × 12W = 375W + 120W = 495W, which is well below the switch's 740W PoE+ budget. However, the engineer must verify that the cumulative power draw does not exceed the budget, as exceeding it would cause some ports to be denied power or shut down. This is the fundamental prerequisite for any PoE deployment.

Exam trap

The trap here is that candidates may overlook the simple power budget calculation and instead focus on irrelevant details like manufacturer compatibility or cable length limits, but the core requirement is ensuring the total wattage does not exceed the switch's PoE budget.

Why the other options are wrong

B

The primary concern is whether the total power draw (15 APs × 25W + 10 cameras × 12W = 495W) exceeds the switch's 740W budget. LLDP-MED is used for power negotiation but is not a prerequisite for PoE+ operation; devices can draw power without it.

C

The question is about verifying power budget compliance; manufacturer homogeneity is irrelevant to power delivery and does not affect whether the switch can supply the required wattage.

D

The question asks about verifying power consumption against the switch's power budget, not cable length. The total power required is 15×25W + 10×12W = 495W, which is under the 740W budget, so power is sufficient. Cable length limits (100m for Ethernet) are unrelated to this verification.

When would these options actually be correct?

B

A question where the switch's power budget is sufficient but the engineer needs to ensure proper power allocation and prioritization among devices, such as when connecting IP phones and APs that support LLDP-MED for dynamic power negotiation.

C

In a scenario where the exam asks about ensuring compatibility for advanced features like PoE scheduling or per-port power prioritization that are vendor-specific, verifying all devices are from the same manufacturer would be necessary.

D

This option would be correct if the question were: 'A network engineer needs to install PoE devices 180 meters from the switch. Which of the following should the engineer verify?' In that scenario, the maximum cable length (100m for standard Ethernet) would be a critical constraint.

Why candidates pick the wrong answer

B

Candidates may confuse power negotiation protocols (LLDP-MED) with basic power delivery requirements, thinking that without LLDP-MED the devices cannot draw power correctly, when in fact PoE+ works without it.

C

Candidates may mistakenly think that mixing manufacturers causes power negotiation issues, or they confuse vendor lock-in with fundamental power budget calculations.

D

Candidates may confuse PoE power delivery with cable length limitations, thinking that longer cables reduce power delivery or that PoE has a 150m limit, but standard Ethernet is limited to 100m regardless of PoE.

224
MCQeasy

Which of the following describes the purpose of a default gateway on a host in a TCP/IP network?

A.It translates domain names to IP addresses
B.It assigns IP addresses to devices on the network
C.It forwards traffic from the local network to other networks
D.It filters traffic to prevent unauthorized access
AnswerC

The default gateway is the router that sends packets destined for non-local networks to the appropriate path.

Why this answer

The default gateway is the router interface on the local subnet that a host uses to send packets destined for IP addresses outside its own network. When a host determines that the destination IP is not in its local subnet (via its subnet mask), it forwards the frame to the default gateway's MAC address, which then routes the packet toward the remote network. Without a default gateway, a host can only communicate with devices on the same local broadcast domain.

Exam trap

The trap here is that candidates confuse the default gateway with a DNS server or DHCP server, because all three are often configured on the same router in small networks, but the exam specifically tests the Layer 3 forwarding role of the default gateway.

Why the other options are wrong

A

A default gateway forwards traffic to other networks, not translates domain names to IP addresses; that is the function of DNS.

B

A default gateway forwards traffic to other networks, not assign IP addresses. IP address assignment is typically done by a DHCP server, not a default gateway.

D

A default gateway forwards traffic to other networks, not filters it. Traffic filtering to prevent unauthorized access is the function of a firewall, not a default gateway.

When would these options actually be correct?

A

In a question asking 'Which service translates domain names to IP addresses?', option A would be correct, as DNS performs this function.

B

In a question asking 'Which network service dynamically assigns IP addresses to devices on a network?', the correct answer would be 'DHCP server' or a similar option describing IP address assignment.

D

This option would be correct in a question asking: 'Which of the following describes the purpose of a firewall on a host in a TCP/IP network?'

Why candidates pick the wrong answer

A

Candidates may confuse the default gateway with DNS because both involve network connectivity and are often configured together, leading to a mix-up of their roles.

B

Candidates may confuse the default gateway with a DHCP server because both are common network services, and the gateway often runs a DHCP server in small networks.

D

Candidates may confuse the default gateway with a firewall because both are involved in network traffic control and security, leading them to think the gateway filters traffic.

225
MCQmedium

A company is deploying a new wireless network for employee devices and wants to use the most secure encryption method currently available for WPA2/3. Which encryption standard should be used?

A.WEP
B.TKIP
C.AES
D.DES
AnswerC

AES (Advanced Encryption Standard) is the current industry standard for strong symmetric-key encryption, adopted by the U.S. government and widely used globally. It provides robust confidentiality and integrity for wireless networks, forming the cryptographic backbone of modern Wi-Fi security protocols like WPA2 and WPA3. Its strength against known attacks makes it the recommended choice for securing sensitive employee data in new deployments.

Why this answer

AES (Advanced Encryption Standard) is the most secure encryption method available for WPA2 and WPA3. WPA2 mandates AES-CCMP, and WPA3 uses AES-GCMP, both of which are based on the AES block cipher, providing strong confidentiality and integrity. This makes AES the correct choice for the highest security in modern Wi-Fi deployments.

Exam trap

The N10-009 exam often tests the misconception that TKIP is acceptable for WPA2 security, but the trap is that WPA2 mandates AES-CCMP for certification, and TKIP is only a backward-compatible option that should never be used in a secure deployment.

Why the other options are wrong

A

WEP is an outdated encryption standard with known vulnerabilities, easily cracked, and is not considered secure for modern WPA2/3 networks.

B

TKIP is an older encryption protocol used with WPA, but it is not considered secure for WPA2/3. WPA2 and WPA3 require AES (CCMP) for strong encryption; TKIP is deprecated due to vulnerabilities.

D

DES is an outdated symmetric encryption algorithm used primarily for data at rest, not for wireless network encryption. WPA2/3 uses AES (Advanced Encryption Standard) as the most secure encryption method, not DES.

When would these options actually be correct?

A

A question asking about legacy wireless security for older devices that only support WEP, or a scenario where maximum compatibility with very old hardware is required despite low security.

B

TKIP would be correct in a question asking for backward compatibility with legacy devices that do not support AES, or in a scenario describing a mixed-mode WPA/WPA2 network where TKIP is used as a fallback for older clients.

D

DES would be correct if the question asked about legacy encryption standards for securing data at rest, such as in a scenario involving older systems that require DES for compatibility with legacy hardware or software.

Why candidates pick the wrong answer

A

Candidates may confuse WEP with WPA or think it is still acceptable because it was once the standard, or they may misremember the acronym as a valid encryption method.

B

Candidates may confuse TKIP as a secure option because it was part of the original WPA standard and is still supported in some configurations, but they overlook that AES is mandatory for WPA2/3 security.

D

Candidates may confuse DES with AES due to similar acronyms or mistakenly think DES is a wireless encryption standard because it is a well-known encryption algorithm, even though it is not used in Wi-Fi security.

Page 2

Page 3 of 7

Page 4

All pages