Courseiva

CompTIA Network+ N10-009 (N10-009) — Questions 451–472

472 questions total · 7pages · All types, answers revealed

Page 6

Page 7 of 7

451
MCQeasy

An organization wants to centrally manage and monitor network devices from a single interface. The solution should support auto-discovery, configuration management, and performance monitoring. Which type of system should be deployed?

A.AAA server
B.Network Management System (NMS)
C.SIEM
D.DHCP server
AnswerB

A Network Management System (NMS) is purpose-built for comprehensive, centralized oversight and control of network infrastructure. It utilizes protocols like SNMP to discover devices, monitor their performance metrics (e.g., CPU, memory, bandwidth), manage configurations, and detect faults across routers, switches, and firewalls. This enables administrators to proactively identify issues, apply updates, and ensure optimal network health from a single console, directly addressing the need for central management and monitoring.

Why this answer

A Network Management System (NMS) is the correct choice because it provides a centralized interface for auto-discovery (e.g., via SNMP or CDP/LLDP), configuration management (e.g., using NETCONF or CLI scripting), and performance monitoring (e.g., polling SNMP MIBs or streaming telemetry). This directly matches the requirement for a single-pane-of-glass solution for network device lifecycle management.

Exam trap

CompTIA often tests the distinction between an NMS and a SIEM, where candidates mistakenly choose SIEM because they think 'monitoring' includes security event monitoring, but the question explicitly asks for auto-discovery and configuration management, which are core NMS functions, not SIEM capabilities.

Why the other options are wrong

A

An AAA server handles authentication, authorization, and accounting for network access, not centralized management, auto-discovery, configuration management, or performance monitoring of network devices.

C

A SIEM (Security Information and Event Management) system focuses on security event collection, correlation, and alerting, not on network device auto-discovery, configuration management, or performance monitoring.

D

A DHCP server assigns IP addresses and network configuration parameters to clients; it does not provide centralized management, monitoring, auto-discovery, or configuration management of network devices.

When would these options actually be correct?

A

A question asking for a system to control user access to network resources, enforce policies, and log access attempts for compliance would make an AAA server the correct answer.

C

An organization needs to collect, analyze, and correlate security logs from multiple sources (e.g., firewalls, servers, applications) to detect and respond to security incidents in real time. Which system should be deployed?

D

An organization needs to automatically assign IP addresses to devices on a subnet and ensure that network configuration (e.g., default gateway, DNS) is consistently applied without manual intervention.

Why candidates pick the wrong answer

A

Candidates may confuse AAA's centralized control of network access with centralized management of devices, or think AAA includes device monitoring features.

C

Candidates may confuse SIEM with NMS because both involve monitoring and centralized management, but SIEM is security-focused while NMS handles network infrastructure.

D

Candidates may confuse DHCP's role in network configuration with broader network management capabilities, or think that DHCP's auto-assignment feature is similar to auto-discovery.

452
MCQhard

A network engineer is troubleshooting intermittent packet loss on a 10 km single-mode fiber link between two buildings. The link lights are on, but the interface shows a high number of CRC errors. The engineer has cleaned the fiber connectors and replaced the patch cables. What should the engineer check NEXT?

A.Check the transmit/receive optical power levels
B.Check the duplex settings on both ends
C.Verify the cable length is within specifications
D.Adjust the Spanning Tree Protocol priority
AnswerA

Intermittent packet loss on fiber links, especially over distance, often points to physical layer issues. Checking transmit (Tx) and receive (Rx) optical power levels with an optical power meter is crucial. If Rx power is too low (below receiver sensitivity) or too high (saturating the receiver), it can lead to bit errors, which manifest as CRC errors and subsequent packet retransmissions or drops, causing intermittent loss. This verifies the optical link budget and ensures signal integrity.

Why this answer

CRC errors on a single-mode fiber link typically indicate physical-layer issues such as excessive attenuation or dispersion. Since cleaning connectors and replacing patch cables did not resolve the problem, the next logical step is to measure the optical power levels at both the transmitter and receiver using an optical power meter. This will confirm whether the received signal is within the acceptable range (e.g., -3 dBm to -20 dBm for 10GBASE-LR) and identify if a damaged transceiver or a splice loss is causing the errors.

Exam trap

The trap here is that candidates often jump to duplex mismatch or cable length issues because those are common in copper troubleshooting, but on long-haul single-mode fiber, optical power levels are the primary suspect when CRC errors persist after cleaning and patching.

Why the other options are wrong

B

CRC errors on a fiber link with link lights on typically indicate signal degradation or physical layer issues, not duplex mismatches, which usually cause frame check sequence errors or late collisions on copper links, not on single-mode fiber.

C

The question states the link is 10 km, which is within the typical range for single-mode fiber (up to 40 km or more). CRC errors are more likely due to signal degradation or dirty connectors, not cable length.

When would these options actually be correct?

B

When troubleshooting intermittent connectivity or performance issues on a copper Ethernet link (e.g., Cat5e) where link lights are on but there are errors, checking duplex settings is the next step after verifying cables, as mismatched duplex can cause high error rates.

C

If the question described a link exceeding the maximum distance for the fiber type (e.g., 100 km on single-mode without repeaters) or if the cable was installed with excessive bends or splices causing attenuation, then verifying cable length or loss budget would be the next step.

Why candidates pick the wrong answer

B

Candidates often associate CRC errors with duplex mismatches from common Ethernet troubleshooting scenarios, but they overlook that fiber links are almost always full-duplex and duplex mismatch is rare on modern fiber interfaces.

C

Candidates may confuse CRC errors with distance-related issues like signal attenuation, assuming that exceeding the cable length specification causes bit errors, but in this scenario the length is standard and the problem points to optical power issues.

453
MCQeasy

A network administrator needs to remotely manage multiple routers and switches. The management traffic must be encrypted. Which protocol should be used for the remote terminal sessions?

A.Telnet
B.SSH
C.SNMP
D.HTTP
AnswerB

SSH (Secure Shell) is the industry-standard protocol for secure remote command-line access to network devices. It establishes an encrypted tunnel over TCP port 22, protecting all management traffic, including authentication credentials and commands, from eavesdropping and tampering. This robust encryption and strong authentication make SSH the preferred choice for securely managing multiple routers and switches from a remote location, ensuring confidentiality and integrity.

Why this answer

SSH (Secure Shell) encrypts all traffic, including authentication credentials and session data, making it the correct choice for securely managing routers and switches over a network. Telnet transmits everything in plaintext, while SNMP and HTTP lack the interactive encrypted terminal session required for remote CLI management.

Exam trap

CompTIA often tests the distinction between Telnet and SSH by presenting a scenario that requires encryption, hoping candidates overlook that Telnet offers no security and default to it because of its simplicity or familiarity.

Why the other options are wrong

A

Telnet transmits data, including credentials, in plaintext, so it does not provide encryption for remote terminal sessions, which is required by the question.

C

SNMP is used for network monitoring and management of device configurations, not for establishing remote terminal sessions. It does not provide an interactive command-line interface for routers and switches.

D

HTTP is not encrypted and is used for web traffic, not for remote terminal sessions to manage routers and switches.

When would these options actually be correct?

A

In a scenario where the question specifies a legacy network with no security requirements or asks for a protocol that does not require encryption, Telnet would be correct for remote terminal access.

C

A question asking for a protocol to collect performance metrics or monitor device status from multiple routers and switches, especially when encrypted communication is required (SNMPv3).

D

When the question asks for a protocol to access a web-based management interface on a network device without encryption requirements, HTTP would be correct.

Why candidates pick the wrong answer

A

Candidates often confuse Telnet with SSH because both provide remote terminal access, and they may overlook the encryption requirement or assume Telnet can be secured with other measures.

C

Candidates may confuse SNMP's role in network management with remote terminal access, or think that because SNMP can manage devices, it can also be used for interactive sessions.

D

Candidates may confuse HTTP with HTTPS or think that web-based management is equivalent to terminal sessions, overlooking the encryption requirement.

454
MCQhard

A security analyst detects that an attacker is sending forged ARP replies to associate the attacker's MAC address with the IP address of the default gateway. What is this attack called?

A.ARP poisoning
B.MAC flooding
C.DHCP snooping
D.DNS spoofing
AnswerA

ARP poisoning, also known as ARP spoofing, is a man-in-the-middle attack where an attacker sends forged ARP (Address Resolution Protocol) messages over a local area network. By sending false ARP replies, the attacker associates their own MAC address with the IP address of another host, such as the default gateway. This causes the victim's traffic, intended for the gateway, to be incorrectly forwarded to the attacker's machine, allowing interception or modification.

Why this answer

ARP poisoning (also known as ARP spoofing) is the correct answer because the attacker sends forged ARP replies to associate their MAC address with the IP address of the default gateway. This causes the victim's switch to update its ARP cache with the attacker's MAC for the gateway's IP, enabling man-in-the-middle attacks where the attacker intercepts traffic destined for the gateway.

Exam trap

The N10-009 exam often tests the distinction between ARP poisoning (which targets the ARP cache) and MAC flooding (which targets the switch's CAM table), leading candidates to confuse the two because both involve MAC addresses and network attacks.

Why the other options are wrong

B

MAC flooding involves sending many frames with different source MAC addresses to overflow the switch's CAM table, not forging ARP replies to associate a MAC with a gateway IP.

C

DHCP snooping is a security feature that filters untrusted DHCP messages to prevent rogue DHCP servers, not a method for forging ARP replies to associate a MAC with a gateway IP.

D

DNS spoofing involves corrupting DNS resolution to redirect traffic to malicious sites, not forging ARP replies to associate a MAC address with a gateway IP.

When would these options actually be correct?

B

A question describing an attack where an attacker sends a flood of packets with random source MAC addresses to force a switch into hub mode, allowing traffic sniffing, would have MAC flooding as the correct answer.

C

A question describing an attack where a rogue DHCP server assigns false IP configurations to clients, causing traffic interception, would have DHCP snooping as the correct answer (e.g., 'What attack is mitigated by DHCP snooping?').

D

A question describing an attacker intercepting DNS queries and returning fake IP addresses to redirect users to a phishing site would make DNS spoofing the correct answer.

Why candidates pick the wrong answer

B

Candidates may confuse ARP poisoning with MAC flooding because both attacks manipulate MAC address tables and are used for man-in-the-middle or traffic interception purposes.

C

Candidates may confuse DHCP snooping with ARP poisoning because both involve manipulating network mappings (IP-MAC) and are often covered together in security training.

D

Candidates may confuse network-layer attacks, thinking 'spoofing' in DNS spoofing is similar to ARP spoofing, or they may misremember the specific attack vector for ARP poisoning.

455
MCQhard

A network administrator wants to ensure that SNMP traffic between the network monitoring server and managed devices is encrypted and provides authentication of the data origin. Which version of SNMP should be implemented?

A.A: SNMPv1
B.B: SNMPv2c
C.C: SNMPv3
D.D: SNMPv2
AnswerC

SNMPv3 is the only version that incorporates robust security features, including strong authentication and encryption, which are crucial for protecting sensitive network management traffic. It utilizes the User-based Security Model (USM) for message authentication and privacy (encryption), ensuring data integrity and confidentiality. This prevents unauthorized access to network device information and protects against tampering, making it the standard for secure network management.

Why this answer

SNMPv3 is the correct choice because it provides both encryption (via the AuthPriv security level) and data origin authentication (via the AuthNoPriv or AuthPriv levels). Unlike earlier versions, SNMPv3 includes a security model that ensures confidentiality, integrity, and authentication, meeting the administrator's requirements.

Exam trap

The trap here is that candidates often confuse SNMPv2c's improved efficiency and bulk retrieval (e.g., GetBulk) with security enhancements, but SNMPv2c still lacks encryption and authentication, making SNMPv3 the only viable option for secure SNMP traffic.

Why the other options are wrong

A

SNMPv1 does not support encryption or authentication; it uses community strings in plaintext, so it cannot provide the required security for data origin authentication and encryption.

B

SNMPv2c uses community strings for authentication, which are transmitted in plaintext, and does not provide encryption or data origin authentication, failing the question's requirements.

D

SNMPv2 (and SNMPv2c) lacks encryption and authentication; it only uses community strings in plaintext, which does not meet the requirement for encrypted and authenticated data origin.

When would these options actually be correct?

A

A question asking for the simplest SNMP version that is widely supported for basic monitoring in a trusted, isolated network where security is not a concern, and only read-only access is needed.

B

A question asking for the simplest SNMP version that supports bulk retrieval of MIB data (e.g., GETBULK) and uses community-based authentication, without requiring encryption or strong authentication.

D

A question that asks for a version that supports bulk retrieval of MIB data (GetBulk) or improved error handling, without requiring security features, would make SNMPv2 the correct answer.

Why candidates pick the wrong answer

A

Candidates may confuse SNMPv1 with being 'secure enough' for basic monitoring, or they may not realize that SNMPv1 lacks any security features beyond a plaintext community string.

B

Candidates may confuse SNMPv2c's community strings as providing some form of authentication, or they may recall that SNMPv2c is widely used and mistakenly think it supports encryption.

D

Candidates may confuse SNMPv2 with SNMPv3, thinking that 'v2' implies improved security, or they may recall that SNMPv2 introduced some enhancements but overlook that security was not addressed until v3.

456
MCQmedium

A security auditor discovers that an unauthorized switch has been connected to an access port in the wiring closet. The rogue switch caused a network loop and disrupted connectivity. Which security feature, if enabled on the access port, would have prevented this by disabling the port when a BPDU is received?

A.BPDU guard
B.Root guard
C.Loop guard
D.UDLD
AnswerA

BPDU guard is a critical Spanning Tree Protocol (STP) security feature designed to protect the integrity of the STP domain by preventing unauthorized devices from influencing the network topology. When enabled on an access port, it immediately places the port into an error-disabled state upon receiving any Bridge Protocol Data Unit (BPDU). This action effectively shuts down the port, isolating the unauthorized switch and preventing it from injecting BPDUs that could disrupt the STP topology or create network loops.

Why this answer

BPDU guard is the correct answer because it is specifically designed to protect against rogue switch connections on access ports. When enabled, if a port receives any Bridge Protocol Data Unit (BPDU), it immediately places the port into an errdisable state, effectively disabling it and preventing a potential network loop. This directly addresses the scenario where an unauthorized switch connected to an access port caused a loop.

Exam trap

CompTIA often tests the distinction between BPDU guard and Root guard, where candidates mistakenly choose Root guard thinking it prevents loops, but Root guard only protects the root bridge election and does not disable a port upon BPDU reception.

Why the other options are wrong

B

Root guard is used to enforce the root bridge position in a spanning-tree topology, not to disable ports upon receiving BPDUs. It does not prevent unauthorized switches from causing loops by disabling the port.

C

Loop guard is designed to prevent alternate or root ports from becoming designated ports in the absence of BPDUs, not to disable a port upon receiving a BPDU. It does not protect against rogue switches sending BPDUs.

D

UDLD (Unidirectional Link Detection) detects unidirectional links but does not disable a port upon receiving BPDUs; it is not designed to prevent rogue switches or loops caused by BPDU reception.

When would these options actually be correct?

B

Root guard would be correct in a scenario where an administrator wants to ensure that a specific switch remains the root bridge and prevent any other switch from becoming root by sending superior BPDUs. For example, on a port connected to a customer switch, root guard would disable the port if a superior BPDU is received.

C

A question describing a scenario where a unidirectional link failure causes a loop, and the solution must prevent a port from transitioning to forwarding state when BPDUs stop arriving (e.g., due to a faulty cable).

D

UDLD would be correct in a scenario where a network administrator needs to detect and disable ports that are only transmitting in one direction, preventing issues like routing loops or STP failures due to unidirectional links.

Why candidates pick the wrong answer

B

Candidates may confuse root guard with BPDU guard because both involve BPDUs and port disabling, but root guard focuses on maintaining root bridge status rather than preventing unauthorized switches.

C

Candidates may confuse loop guard with BPDU guard because both deal with loops and BPDUs, but loop guard addresses missing BPDUs rather than unexpected BPDUs.

D

Candidates may confuse UDLD with BPDU guard because both involve loop prevention, but UDLD focuses on unidirectional links rather than unauthorized BPDU reception.

457
MCQmedium

A technician is troubleshooting an intermittent connectivity issue between two switches connected by a fiber optic cable. The link status shows up/down flapping. The technician checks the optical power levels and finds they are within acceptable range. Which of the following is the most likely cause?

A.Dirty fiber connectors
B.Duplex mismatch
C.Speed mismatch
D.VLAN mismatch
AnswerA

Contamination on fiber end faces, such as dust or oil, can cause significant and intermittent signal degradation. These microscopic particles can partially block or scatter the light signal, leading to increased attenuation or back reflection that disrupts communication. The intermittent nature arises because the contamination might shift, vibrate, or only partially obscure the core, causing periods of good signal followed by periods of poor or lost signal, resulting in link flaps. Even if average power readings appear acceptable, the transient nature of the obstruction can cause connectivity to drop.

Why this answer

Intermittent link flapping with acceptable optical power levels strongly indicates a physical-layer issue that is not related to signal strength. Dirty fiber connectors cause intermittent signal degradation due to scattering and absorption of light, leading to CRC errors and link flaps even when average power appears normal. Cleaning the connectors is the standard first step in such scenarios.

Exam trap

The trap here is that candidates see 'acceptable optical power levels' and assume the physical layer is fine, overlooking that intermittent physical contamination can cause flapping without dropping the average power below threshold.

Why the other options are wrong

B

Duplex mismatch typically causes constant errors or complete link failure, not intermittent flapping. The symptoms here (up/down flapping with acceptable optical power) point to a physical layer issue like dirty connectors, not a duplex configuration problem.

C

Speed mismatch typically causes a link to not come up at all or to flap continuously, but the question states optical power levels are within range, and the issue is intermittent. Speed mismatch would usually be constant, not intermittent, and is less common on fiber links with auto-negotiation.

D

A VLAN mismatch would cause connectivity issues but typically results in a stable link state (up/up) with no communication, not intermittent flapping of the link status. The link flapping indicates a physical layer problem, not a layer 2 configuration issue.

When would these options actually be correct?

B

A technician reports that a link is up but has a high number of CRC errors and slow performance. After checking, both switches are set to different duplex modes (one half, one full). In that scenario, duplex mismatch is the most likely cause.

C

A technician connects two switches and the link fails to establish. The switches have different fixed speed capabilities (e.g., one is 100 Mbps and the other is 1 Gbps) and auto-negotiation is disabled. In this scenario, speed mismatch is the most likely cause.

D

A VLAN mismatch would be correct in a scenario where two switches are connected and the link is up/up, but devices on the same VLAN cannot communicate across the link, or there is no traffic passing despite a stable link.

Why candidates pick the wrong answer

B

Candidates may confuse intermittent flapping with duplex mismatch because both can cause connectivity issues, but they overlook that duplex mismatch usually results in persistent errors rather than link state changes.

C

Candidates may confuse symptoms of speed mismatch (link flapping) with those of dirty connectors, or they may overgeneralize that any flapping is due to speed/duplex issues without considering the intermittent nature and acceptable power levels.

D

Candidates may confuse VLAN mismatch with other misconfigurations that cause intermittent issues, or they might think that VLAN mismatch can cause link flapping due to spanning tree or other protocols reacting to the misconfiguration.

458
MCQhard

Users in a remote office are experiencing slow file transfers to the data center. The network technician runs a traceroute and discovers high latency on a specific hop. The technician pings that hop and gets replies with varying latency. The technician also checks the interface error counters on the router at that hop and finds no errors. What is the most likely cause?

A.Duplex mismatch
B.Incorrect MTU
C.Route flapping
D.CPU overload on the router
AnswerD

When a router's CPU is overloaded, it struggles to process packets efficiently, leading to increased queue depths for incoming traffic. This results in significant packet processing delays and variable latency, directly impacting file transfer speeds without necessarily generating interface errors like discards or input errors. The router simply cannot keep up with the forwarding, routing table lookups, and other management plane tasks.

Why this answer

High latency with varying values (jitter) combined with clean interface error counters points to a router that is overwhelmed by processing demands. When a router's CPU is overloaded, it queues packets for processing, introducing variable delays even though the physical layer shows no errors. This matches the symptom of a specific hop showing latency spikes without CRC or framing errors.

Exam trap

The trap here is that candidates see 'no errors' on the interface and assume the problem must be at a higher layer, but CompTIA often tests that CPU overload can cause latency without any interface errors, misleading those who think clean counters always mean a healthy router.

Why the other options are wrong

A

Duplex mismatch typically causes CRC errors and frame check sequence failures, which would appear in interface error counters. Since the technician checked and found no errors, duplex mismatch is unlikely.

B

Incorrect MTU typically causes packet fragmentation or drops, not varying latency with no interface errors. The symptoms of high and varying latency without errors point to CPU overload, not MTU issues.

C

Route flapping typically causes intermittent connectivity and routing table instability, not consistently high latency with varying ping responses and no interface errors.

When would these options actually be correct?

A

A question describes intermittent connectivity or slow performance between two directly connected devices, and the interface error counters show CRC errors or runts. In that scenario, duplex mismatch is a common cause.

B

Incorrect MTU would be correct if users report that large file transfers fail or are slow, while small transfers work fine, and the traceroute shows no response or 'fragmentation needed' messages at a specific hop, with no latency variation.

C

A question describes intermittent connectivity to a remote site, with traceroute showing the route changing between different paths and the route appearing and disappearing in the routing table. The correct answer would be route flapping.

Why candidates pick the wrong answer

A

Candidates often associate high latency with layer 1 or 2 issues like duplex mismatch, but they overlook that duplex mismatch usually produces visible errors on the interface counters.

B

Candidates may confuse MTU issues with latency problems because both can affect file transfer performance, and MTU misconfiguration is a common cause of network slowdowns in remote office scenarios.

C

Candidates may associate any routing issue with 'flapping' and confuse high latency with route instability, especially when traceroute shows a problematic hop.

459
MCQeasy

At which OSI layer does a router primarily operate to make forwarding decisions based on IP addresses?

A.Layer 1 (Physical)
B.Layer 2 (Data Link)
C.Layer 3 (Network)
D.Layer 4 (Transport)
AnswerC

A router's primary function is to forward data packets between different network segments or subnets. This crucial operation relies on examining the destination logical IP address contained within the packet header, which is a function of the OSI Layer 3, the Network layer. Routers use routing tables to determine the optimal path for these packets, making intelligent forwarding decisions based on network topology and reachability, fundamentally operating at this layer to connect disparate networks.

Why this answer

A router primarily operates at Layer 3 (Network) of the OSI model because it uses logical IP addresses (e.g., IPv4 or IPv6) to make forwarding decisions. The router examines the destination IP address in the packet header, performs a longest-prefix match against its routing table, and determines the next-hop interface. This layer is responsible for end-to-end delivery and path selection across multiple networks.

Exam trap

CompTIA often tests the misconception that routers operate at Layer 2 because they forward frames, but the key distinction is that routers make forwarding decisions based on Layer 3 IP addresses, not Layer 2 MAC addresses.

Why the other options are wrong

A

Routers use IP addresses to make forwarding decisions, which operate at Layer 3 (Network). Layer 1 is the physical medium (cables, signals) and does not involve IP addresses.

B

A router makes forwarding decisions based on IP addresses, which are Layer 3 (Network layer) addresses. Layer 2 (Data Link layer) uses MAC addresses for forwarding within a local network, not IP addresses.

D

Routers make forwarding decisions based on IP addresses, which operate at Layer 3 (Network). Layer 4 (Transport) handles end-to-end communication and port numbers, not IP routing.

When would these options actually be correct?

A

A question asking 'At which OSI layer do hubs and repeaters operate?' would have Layer 1 as the correct answer, as these devices simply regenerate signals without addressing.

B

This option would be correct for a question like: 'At which OSI layer does a switch primarily operate to make forwarding decisions based on MAC addresses?' In that context, Layer 2 is the correct answer.

D

A question asking which OSI layer handles segmentation, flow control, and error recovery (e.g., TCP/UDP) would have Layer 4 as the correct answer.

Why candidates pick the wrong answer

A

Candidates may confuse the physical transmission of data (Layer 1) with the routing function, or think that routers deal with physical connections.

B

Candidates may confuse routers with switches, as both forward traffic, or they may think that IP addresses are handled at Layer 2 because they associate IP with Ethernet frames.

D

Candidates may confuse the router's use of IP addresses with higher-layer functions like port-based filtering, or mistakenly think routers inspect transport-layer headers for forwarding decisions.

460
MCQhard

A network administrator needs to automate the backup of router configuration files to a remote server over the internet. The backup must be encrypted and authenticated. Which protocol should the administrator use in the automated script?

A.TFTP
B.FTP
C.SCP
D.HTTP
AnswerC

SCP (Secure Copy Protocol) is the most appropriate choice because it leverages SSH (Secure Shell) for both data encryption and strong authentication. This ensures that router configuration files are transferred securely over an untrusted network, protecting sensitive data from eavesdropping and tampering. Its widespread support on network devices makes it ideal for automated, script-based backups to a remote server.

Why this answer

SCP (Secure Copy Protocol) is the correct choice because it provides both encryption and authentication by operating over SSH (Secure Shell), which encrypts the entire session and verifies the server's identity using public-key cryptography. This makes it suitable for automating secure backups of router configuration files to a remote server over the internet, as it supports scripting with tools like expect or SSH keys without interactive password prompts.

Exam trap

The N10-009 exam often tests the distinction between secure and insecure file transfer protocols, and the trap here is that candidates may confuse FTP with SFTP or FTPS, assuming FTP itself provides encryption, or they may choose TFTP because it is commonly used for router backups in lab environments, forgetting that the question specifies 'over the internet' and requires encryption and authentication.

Why the other options are wrong

A

TFTP lacks encryption and authentication, making it unsuitable for secure backups over the internet.

B

FTP transmits data in plaintext, including authentication credentials, and does not provide encryption or authentication for the backup files, failing the security requirements.

D

HTTP does not provide encryption or authentication by default; it transmits data in plaintext, making it unsuitable for secure backup of router configurations over the internet.

When would these options actually be correct?

A

A network administrator needs to quickly transfer a router configuration file to a local TFTP server on the same LAN segment, with no security requirements.

B

An administrator needs to transfer files within a trusted local network where security is not a concern, and the devices support FTP for simple file transfers without encryption overhead.

D

A question asking for a protocol to transfer configuration files within a secure internal network where encryption is not required, or when using HTTPS (HTTP over SSL/TLS) for secure web-based management interfaces.

Why candidates pick the wrong answer

A

Candidates may associate TFTP with router configuration backup due to its simplicity and common use in local network environments, overlooking the security requirements for internet-based transfers.

B

Candidates may associate FTP with file transfer automation and overlook its lack of encryption, assuming it is sufficient for remote backups over the internet.

D

Candidates may confuse HTTP with HTTPS, assuming it provides security, or think that web-based management is sufficient for automated backups without considering encryption requirements.

461
MCQmedium

A network administrator is installing cable in a plenum space (an area used for air circulation, such as above a drop ceiling). Which cable type is required by most building codes for such an installation?

A.PVC-jacketed cable
B.Riser-rated cable
C.Plenum-rated cable
D.Low Smoke Zero Halogen (LSZH) cable
AnswerC

Plenum-rated cables are specifically engineered with advanced fire-retardant materials, such as fluorinated polymers like FEP or PVDF, which exhibit extremely low smoke production and flame spread characteristics when exposed to fire. This critical design ensures that in the event of a fire, the cable will not contribute significantly to the rapid distribution of smoke or flames through a building's air-handling systems. Adherence to stringent standards like NFPA 90A and UL 910 is mandatory for these cables to be installed in plenum spaces, protecting occupants and preventing widespread damage.

Why this answer

Plenum-rated cable is required by most building codes (e.g., NFPA 70, National Electrical Code) for installation in plenum spaces because it is constructed with fire-retardant materials, such as FEP or PFA, that produce minimal smoke and are self-extinguishing. This prevents toxic fumes and flames from spreading through air-handling areas, ensuring safety in case of a fire. Standard PVC-jacketed cable would release hazardous smoke and support flame propagation, making it illegal in plenum spaces.

Exam trap

The trap here is that candidates often confuse 'plenum-rated' with 'riser-rated' or 'LSZH', assuming any low-smoke cable suffices, but the exam specifically tests that only CMP meets the fire and smoke spread requirements for plenum spaces as defined by the NEC.

Why the other options are wrong

A

PVC-jacketed cable is not allowed in plenum spaces because it produces toxic smoke and supports flame propagation, violating building codes that require low-smoke, fire-resistant materials.

B

Riser-rated cable is designed for vertical runs between floors, not for plenum spaces where air circulates. Building codes require plenum-rated cable in plenums due to its low smoke and flame spread properties.

D

LSZH cable is designed to emit low smoke and no halogens when burned, but it is not specifically rated for plenum spaces; plenum-rated cable is required by building codes for air-handling spaces due to its fire-resistant and low-smoke properties.

When would these options actually be correct?

A

PVC-jacketed cable would be correct for a question about general-purpose horizontal cabling in non-plenum areas (e.g., within walls or conduit) where cost is a primary concern and fire codes are less strict.

B

A question asking which cable type is required for vertical cable runs between floors in a building (e.g., in elevator shafts or riser closets) would have riser-rated cable as the correct answer.

D

In a scenario where the cable is installed in a non-plenum, confined space (e.g., inside a metal conduit or in a residential area) and the primary concern is reducing toxic gas emissions during a fire, LSZH cable would be the correct choice.

Why candidates pick the wrong answer

A

Candidates may assume PVC is standard for all indoor cabling and overlook the special fire and smoke requirements of plenum spaces.

B

Candidates may confuse 'riser' with 'plenum' or assume that any fire-resistant cable is acceptable in plenums, not realizing that plenum spaces have stricter requirements.

D

Candidates may confuse LSZH with plenum-rated cable because both are associated with fire safety and low smoke, but they are governed by different standards and applications.

462
MCQmedium

A technician is troubleshooting a wireless network that experiences intermittent disconnections. A spectrum analysis shows channel utilization consistently above 80% on the 2.4 GHz band. Which of the following is the most likely cause?

A.Too many access points are configured on the same or overlapping channels
B.Access point output power is too high
C.Microwave ovens are interfering with the wireless signal
D.Client devices have weak signal strength
AnswerA

When multiple access points operate on the same or overlapping Wi-Fi channels within close proximity, they create co-channel interference. This forces devices to contend more frequently for airtime, leading to increased retransmissions and a higher perceived channel utilization. The result is reduced effective throughput and intermittent connectivity issues for clients as they struggle to communicate reliably amidst the signal collisions.

Why this answer

A is correct because consistently high channel utilization above 80% on the 2.4 GHz band indicates co-channel or adjacent-channel interference, typically caused by too many access points (APs) operating on the same or overlapping channels (e.g., channels 1, 6, and 11 are non-overlapping in 802.11b/g/n). This leads to excessive contention, increased retransmissions, and intermittent disconnections as stations wait for clear channel access via CSMA/CA.

Exam trap

The trap here is that candidates often attribute high channel utilization solely to non-Wi-Fi interference (like microwaves) or power settings, but the exam expects you to recognize that persistent >80% utilization in the 2.4 GHz band is almost always due to overlapping APs on the same or adjacent channels, not transient interference sources.

Why the other options are wrong

B

High output power can cause co-channel interference and cell overlap, but the question states channel utilization is above 80%, which points to congestion from too many APs on the same or overlapping channels, not power levels.

C

Intermittent disconnections with high channel utilization are more likely caused by co-channel interference from too many access points on the same or overlapping channels, not by microwave ovens, which typically cause non-Wi-Fi interference that is constant rather than intermittent.

D

Weak signal strength causes low throughput or disconnections at the client, but the question states channel utilization is consistently above 80% on the 2.4 GHz band, indicating congestion from many devices or access points, not weak signal.

When would these options actually be correct?

B

In a scenario where clients experience disconnections but channel utilization is low, and a site survey shows excessive signal overlap and high RSSI from neighboring APs, then output power being too high is the likely cause.

C

A technician reports periodic, severe signal degradation on the 2.4 GHz band during lunch hours. A spectrum analyzer shows non-Wi-Fi interference spikes. In this scenario, microwave ovens are the most likely cause.

D

A technician is troubleshooting a wireless network where users in a specific area report frequent disconnections. A site survey shows low RSSI values for client devices in that area. In this scenario, weak signal strength would be the most likely cause.

Why candidates pick the wrong answer

B

Candidates may confuse symptoms of high channel utilization with those of excessive power, or they may recall that high power can cause interference and assume it leads to high utilization.

C

Candidates know that microwave ovens operate in the 2.4 GHz band and can cause interference, so they may jump to this familiar cause without considering that the high channel utilization points to Wi-Fi congestion rather than external interference.

D

Candidates may associate intermittent disconnections with weak signal, overlooking that the given high channel utilization points to congestion rather than signal strength issues.

463
MCQeasy

A network administrator needs to ensure that in the event of a switch failure, the switch can be replaced and brought online with minimal downtime. Which of the following tasks should the administrator perform regularly?

A.Perform a firmware upgrade on all switches
B.Back up the configuration files of all switches
C.Monitor the switch's CPU utilization
D.Create a network performance baseline
AnswerB

Backing up configuration files involves saving the operational settings, such as VLAN assignments, port security, routing protocols, and access control lists, from the switch's NVRAM to an external server (e.g., TFTP, SCP). In the event of a hardware failure, these saved configurations can be rapidly deployed onto a new or repaired switch, minimizing downtime and ensuring the network segment returns to its intended operational state without manual reconfiguration. This is a direct and efficient method for disaster recovery concerning switch settings.

Why this answer

Regularly backing up the configuration files of all switches ensures that when a failed switch is replaced, the exact configuration can be restored quickly, minimizing downtime. This is a core best practice in network operations because a replacement switch typically ships with factory defaults and requires the original configuration to resume normal operations. Without a recent backup, the administrator would have to reconfigure the switch manually, leading to extended outage and potential human error.

Exam trap

CompTIA often tests the distinction between proactive maintenance tasks (like firmware upgrades or monitoring) and disaster recovery tasks (like configuration backups), leading candidates to choose firmware upgrades because they associate 'minimizing downtime' with keeping software current, when in fact the backup directly enables rapid replacement.

Why the other options are wrong

A

Performing a firmware upgrade does not directly address the goal of restoring a failed switch with minimal downtime; it is a proactive maintenance task unrelated to rapid replacement.

C

Monitoring CPU utilization helps identify performance issues but does not prepare for switch replacement or reduce downtime after a failure; it is a proactive monitoring task, not a recovery task.

When would these options actually be correct?

A

A question asking 'Which task ensures switches have the latest security patches and feature updates?' would make firmware upgrades the correct answer.

C

A question asking 'Which task helps identify potential switch overload before it causes network issues?' would make monitoring CPU utilization correct, as it detects high usage that could lead to performance degradation.

Why candidates pick the wrong answer

A

Candidates may think keeping firmware current is essential for reliability, but it does not speed up recovery after a failure.

C

Candidates may think that monitoring CPU utilization is part of regular maintenance that indirectly aids recovery, but they overlook that the question specifically focuses on minimizing downtime after a failure, not preventing it.

464
MCQmedium

A network administrator is configuring Quality of Service (QoS) on a router to prioritize voice traffic. Which of the following fields should be used to mark packets for classification and prioritization?

A.Source IP address
B.DSCP
C.Source port number
D.MAC address
AnswerB

DSCP (Differentiated Services Code Point) is a 6-bit field within the Type of Service (ToS) byte of the IPv4 header, or the Traffic Class field in IPv6. Routers use DSCP values to classify and mark packets, assigning them to specific per-hop behaviors (PHBs) such as expedited forwarding (EF) for voice or assured forwarding (AF) for critical data. This marking enables consistent end-to-end QoS prioritization across diverse network devices, ensuring that high-priority traffic receives preferential treatment regardless of its origin or destination.

Why this answer

DSCP (Differentiated Services Code Point) is the correct field because it is a 6-bit value in the IP header used to mark packets for QoS classification and prioritization, as defined in RFC 2474. Voice traffic typically uses DSCP EF (Expedited Forwarding, value 46) to ensure low latency and jitter, making it the standard choice for QoS marking on routers.

Exam trap

The trap here is that candidates confuse classification (using source IP, port, or MAC to identify traffic) with marking (setting a QoS field like DSCP or CoS), leading them to choose a valid classification method instead of the actual marking field required by the question.

Why the other options are wrong

A

QoS marking for classification and prioritization uses Layer 3 fields like DSCP or IP Precedence, not the source IP address. The source IP identifies the sender but does not carry QoS priority information.

C

Source port number is a transport-layer field used for identifying applications, but QoS marking for voice traffic is typically done at Layer 3 using DSCP (e.g., EF for voice), not by source port.

D

MAC addresses operate at Layer 2 and are not used for QoS marking in IP networks; QoS classification and prioritization rely on Layer 3 fields like DSCP or IP precedence.

When would these options actually be correct?

A

If the question asked about filtering traffic from a specific host for QoS policing or shaping, the source IP address would be used to match packets from that host. For example, 'Which field is used to identify traffic from a particular subnet for bandwidth limiting?'

C

In a scenario where a firewall or router must prioritize traffic based on application type without relying on DSCP markings, source port number can be used to classify voice traffic (e.g., UDP port 5060 for SIP).

D

In a Layer 2 QoS scenario, such as configuring Class of Service (CoS) on a switch to prioritize traffic based on MAC addresses or VLAN tags, MAC address could be used for classification.

Why candidates pick the wrong answer

A

Candidates may think that since IP addresses are used in ACLs for traffic classification, they can also be used for QoS marking, but marking requires a dedicated field like DSCP, not the source IP itself.

C

Candidates may think source port numbers are used for QoS classification because they associate specific ports with voice protocols (e.g., SIP, RTP), but DSCP is the standard method for packet marking in QoS.

D

Candidates may confuse Layer 2 QoS mechanisms (like CoS) with Layer 3 QoS (DSCP), or think MAC addresses can be used for traffic prioritization because they are unique identifiers.

465
MCQeasy

Which protocol is used to resolve a known IP address to a corresponding MAC address on a local network?

A.ARP
B.DNS
C.DHCP
D.ICMP
AnswerA

ARP (Address Resolution Protocol) is a Layer 2 protocol responsible for mapping a known Layer 3 IPv4 address to its corresponding Layer 2 MAC (Media Access Control) address within the same local network segment. When a device needs to send data to another host on the same local network and only knows the destination's IP address, it uses ARP to discover the necessary MAC address for direct frame delivery. This process is fundamental for local network communication.

Why this answer

ARP (Address Resolution Protocol) is used to resolve a known IP address to its corresponding MAC address on a local network. When a host needs to send a frame to another host on the same subnet, it broadcasts an ARP request containing the target IP; the host with that IP responds with its MAC address, which is then cached for future use.

Exam trap

The trap here is confusing ARP with DNS, as both involve 'resolution,' but DNS resolves names to IPs (Layer 3) while ARP resolves IPs to MACs (Layer 2), and candidates often forget ARP operates only within a local broadcast domain.

Why the other options are wrong

B

DNS resolves domain names to IP addresses, not IP addresses to MAC addresses. The question specifically asks for mapping an IP address to a MAC address on a local network, which is ARP's function.

C

DHCP is used to dynamically assign IP addresses and other network configuration parameters to devices, not to resolve IP addresses to MAC addresses. The resolution of IP to MAC addresses on a local network is performed by ARP.

D

ICMP is used for network diagnostics (e.g., ping, traceroute) and error reporting, not for resolving IP addresses to MAC addresses. The Address Resolution Protocol (ARP) is the correct protocol for this purpose.

When would these options actually be correct?

B

DNS would be correct if the question asked: 'Which protocol is used to resolve a fully qualified domain name (e.g., www.example.com) to an IP address?' or 'Which protocol translates human-readable domain names into numerical IP addresses?'

C

A question asking 'Which protocol automatically assigns IP addresses to devices on a network?' would have DHCP as the correct answer. Also, 'Which protocol provides IP configuration including subnet mask and default gateway?' would be answered with DHCP.

D

ICMP would be correct for a question like: 'Which protocol is used to test reachability and measure round-trip time to a remote host?' or 'Which protocol is used by the ping command?'

Why candidates pick the wrong answer

B

Candidates often confuse 'resolution' tasks, assuming DNS handles all address resolution, or they misread the question as resolving a name to an IP rather than an IP to a MAC.

C

Candidates may confuse DHCP with ARP because both operate at the network layer and involve IP addresses, but they serve different purposes. The similarity in acronyms (both four-letter protocols) can also cause confusion.

D

Candidates may confuse ICMP with ARP because both operate at the network layer and are involved in local network communication, or they may mistakenly think ICMP handles address resolution due to its role in network diagnostics.

466
MCQeasy

A network technician needs to connect two switches to support multiple VLANs between them. The technician wants to use a single link to carry traffic for all VLANs. Which protocol should be used to tag frames with VLAN information?

A.802.1Q
B.802.1X
C.802.11
D.802.3
AnswerA

IEEE 802.1Q is the industry standard for Virtual Local Area Network (VLAN) tagging, essential for enabling multiple VLANs to traverse a single physical link, known as a trunk port, between switches. It inserts a 4-byte tag into the Ethernet frame header, identifying the VLAN to which the frame belongs. This allows switches to properly forward traffic to the correct VLAN segment on the receiving end, effectively segmenting network traffic while utilizing shared physical infrastructure.

Why this answer

802.1Q is the IEEE standard for VLAN tagging, which inserts a 4-byte tag into the Ethernet frame header to identify the VLAN membership of the frame. This allows a single trunk link between two switches to carry traffic for multiple VLANs by tagging each frame with its corresponding VLAN ID (1-4094).

Exam trap

The trap here is that candidates often confuse 802.1Q (VLAN tagging) with 802.1X (port authentication) because of the similar numbering, or they assume 802.3 handles VLANs since it is the base Ethernet standard.

Why the other options are wrong

B

802.1X is a port-based network access control protocol used for authentication, not for tagging frames with VLAN information. It does not provide VLAN tagging capabilities.

C

802.11 is a wireless networking standard (Wi-Fi), not a protocol for tagging VLAN frames on Ethernet links between switches.

D

802.3 is an Ethernet standard that defines physical and data link layer specifications, but it does not include VLAN tagging. VLAN tagging is accomplished by 802.1Q, which inserts a VLAN tag into the Ethernet frame.

When would these options actually be correct?

B

A network technician needs to implement secure access control on a switch port to authenticate devices before granting network access. Which protocol should be used?

C

When a question asks which standard defines wireless LAN communication, such as 'Which IEEE standard is used for Wi-Fi networks?'

D

A question asking which standard defines the basic frame format for Ethernet networks, such as 'Which IEEE standard specifies the frame format for wired Ethernet?' would have 802.3 as the correct answer.

Why candidates pick the wrong answer

B

Candidates may confuse 802.1X with 802.1Q due to similar numbering, or mistakenly think that access control involves VLAN tagging.

C

Candidates may confuse 802.11 with 802.1Q due to similar numbering, or mistakenly think VLAN tagging applies to wireless frames.

D

Candidates may confuse 802.3 with 802.1Q because both are IEEE standards related to Ethernet, and they might think that the base Ethernet standard includes VLAN tagging.

467
MCQeasy

Which of the following best describes the primary function of the transport layer in the OSI model?

A.Routing packets across networks
B.Providing end-to-end communication and data flow control
C.Encoding data into electrical signals
D.Determining the best path for data transmission
AnswerB

The transport layer, specifically Layer 4 of the OSI model, is responsible for establishing and maintaining logical end-to-end connections between applications running on different hosts. It manages data segmentation into smaller units, reassembly at the destination, and implements robust flow control mechanisms, such as windowing, to prevent network congestion and ensure that a sender does not overwhelm a receiver. Furthermore, protocols like TCP provide reliable data transfer through acknowledgments and retransmissions, guaranteeing data integrity and ordered delivery.

Why this answer

The transport layer (Layer 4) is responsible for end-to-end communication between hosts, including segmentation, reassembly, and flow control. Protocols like TCP use windowing and acknowledgments to manage data flow, ensuring reliable delivery. This distinguishes it from lower layers that handle routing or physical signaling.

Exam trap

CompTIA often tests the confusion between the transport layer's end-to-end delivery and the network layer's path determination, leading candidates to incorrectly select routing-related options like A or D.

Why the other options are wrong

A

Routing packets across networks is a function of the network layer (Layer 3), not the transport layer (Layer 4). The transport layer provides end-to-end communication and flow control.

C

Encoding data into electrical signals is a function of the physical layer, not the transport layer. The transport layer handles end-to-end communication and flow control, not signal encoding.

D

Determining the best path for data transmission is a function of the network layer (Layer 3), not the transport layer (Layer 4). The transport layer focuses on end-to-end communication and flow control.

When would these options actually be correct?

A

This option would be correct for a question asking: 'Which of the following best describes the primary function of the network layer in the OSI model?'

C

This option would be correct for a question like: 'Which OSI layer is responsible for converting data into bits for transmission over a physical medium?' In that context, the physical layer's encoding function is the answer.

D

This option would be correct for a question like: 'Which OSI layer is responsible for routing and path determination?' In that context, the network layer performs this function.

Why candidates pick the wrong answer

A

Candidates often confuse the transport layer with the network layer because both deal with data delivery, and 'routing' is a common networking term that seems related to 'transport'.

C

Candidates may confuse the transport layer with lower layers, especially if they think of 'transport' as moving data across the wire, which involves signal encoding.

D

Candidates often confuse the transport layer's role in managing data segments with the network layer's path selection, especially since both involve end-to-end delivery concepts.

468
MCQeasy

A network administrator is creating a standard operating procedure for firmware upgrades. Which step should be performed FIRST according to best practices?

A.Schedule the upgrade during a maintenance window
B.Back up the current configuration
C.Test the firmware in a lab environment
D.Notify users of the planned outage
AnswerC

Testing the firmware in a lab environment is the critical initial step in any robust firmware upgrade standard operating procedure. This isolated, non-production setting allows engineers to thoroughly evaluate the new firmware for compatibility issues, performance regressions, and potential bugs without risking the stability or availability of live production systems. Identifying and mitigating these issues early prevents costly downtime and service interruptions.

Why this answer

According to best practices for firmware upgrades, the first step should always be to test the new firmware in a non-production lab environment that mirrors the production setup. This validates compatibility, identifies potential bugs, and ensures the upgrade process works without risking network downtime or data loss. Only after successful lab testing should you proceed to backup the current configuration and schedule the upgrade during a maintenance window.

Exam trap

The N10-009 exam often tests the misconception that backing up the configuration is the first step, but best practices dictate that testing in a lab environment takes precedence to avoid deploying untested firmware that could render the device inoperable.

Why the other options are wrong

A

Scheduling the upgrade during a maintenance window is important but should not be the first step; the firmware must first be tested in a lab to ensure compatibility and stability before any scheduling or user notification.

B

Backing up the current configuration is important but should occur after testing the firmware in a lab environment, as testing ensures the firmware is stable and compatible before any changes are made to production systems.

D

Notifying users of a planned outage is important but should occur after the firmware has been tested and validated in a lab environment to ensure the upgrade is safe and necessary.

When would these options actually be correct?

A

If the question asked 'After testing the firmware in a lab and backing up configurations, what is the next step in the upgrade process?' then scheduling during a maintenance window would be the correct answer.

B

In a scenario where the firmware has already been tested and approved, and the question asks for the next step before applying the upgrade to production, backing up the current configuration would be the correct answer.

D

In a scenario where the firmware upgrade has already been tested and approved, and the question asks for the step to perform just before the actual upgrade, notifying users of the planned outage would be the correct answer.

Why candidates pick the wrong answer

A

Candidates often think of operational planning first, overlooking that validation of the firmware itself is a prerequisite to any scheduling or communication steps.

B

Candidates often prioritize data preservation and mistakenly think backing up is the first step in any change process, overlooking the critical need to validate the firmware first to avoid corrupting backups with untested code.

D

Candidates may think that user notification is a critical first step to minimize disruption, overlooking the prerequisite of testing to prevent potential issues.

469
MCQhard

Users in a remote branch office report that they cannot access the company's cloud-based applications. The network administrator notices that the edge router's WAN interface is up but the branch's default route points to a next-hop IP that is unreachable. The administrator can ping the ISP's gateway IP from the router. What is the most likely cause?

A.The routing protocol is not redistributing the default route
B.The static default route has an incorrect next-hop IP
C.The WAN interface is administratively down
D.The firewall is blocking traffic to the cloud
AnswerB

If the next-hop IP in the static route is incorrect or the interface is down, traffic cannot be forwarded even though the WAN interface is up and the ISP gateway is reachable via another path.

Why this answer

The scenario describes a static default route configured with a next-hop IP that is unreachable. The WAN interface is up and the ISP gateway is reachable (as confirmed by the ping), but the router cannot forward traffic to the cloud because the static route points to an incorrect next-hop address. This is a classic static route misconfiguration where the next-hop IP does not match the ISP gateway or is not in the directly connected subnet.

Exam trap

CompTIA often tests the distinction between a WAN interface being up and the default route's next-hop being reachable; candidates mistakenly assume that if the interface is up and the ISP gateway is pingable, the default route must be correct, but the next-hop IP configured in the static route could be a different, unreachable address.

Why the other options are wrong

A

The question states that the default route points to an unreachable next-hop IP, and the administrator can ping the ISP's gateway. This indicates a static route misconfiguration, not a redistribution issue. Redistribution would only matter if a dynamic routing protocol were involved, but the problem is with a static default route.

C

The WAN interface is up (as stated), so it is not administratively down. An administratively down interface would show as 'down' or 'disabled', not 'up'.

D

The firewall blocking traffic to the cloud would not cause the router to have an unreachable next-hop IP for the default route; it would instead prevent traffic from passing through the firewall, but the router would still have a valid route.

When would these options actually be correct?

A

In a scenario where OSPF or EIGRP is used and the default route is not being advertised into the routing domain, causing remote routers to lack a default route. For example, a router has a static default route but redistribution from static into OSPF is missing, so other routers don't learn it.

C

A question where the edge router's WAN interface is down or disabled (e.g., 'interface status shows administratively down') and users cannot access remote resources, with no other routing issues mentioned.

D

In a scenario where users cannot access cloud applications, the router has a valid default route, and pinging the ISP gateway succeeds, but traffic is still blocked, the firewall could be the cause if it is dropping traffic to the cloud IPs.

Why candidates pick the wrong answer

A

Candidates may confuse a missing default route with a redistribution problem, especially if they've studied dynamic routing protocols. They might assume the default route should be learned via a routing protocol rather than being statically configured.

C

Candidates may confuse 'interface up' with 'interface operational' and assume a down interface is the cause, or they may overlook the explicit statement that the interface is up.

D

Candidates may think that any connectivity issue to cloud applications must be due to a firewall blocking traffic, overlooking that the problem is actually a routing issue indicated by the unreachable next-hop.

470
MCQmedium

A network administrator is preparing documentation for a new branch office. The administrator needs a diagram that shows the logical relationships between network devices and how VLANs are trunked over inter-switch links. Which type of document should be created?

A.Network baseline
B.Wiring diagram
C.Physical topology diagram
D.Logical topology diagram
AnswerD

This diagram is crucial for understanding how data flows and how network segments are logically interconnected. It specifically illustrates logical connections, IP addressing schemes, VLAN IDs, subnet masks, routing protocols, and the configuration of trunk links between switches, which are essential for multi-VLAN environments. For a new branch office, this diagram provides the necessary blueprint for configuring network devices to support various services and user groups.

Why this answer

A logical topology diagram is the correct choice because it illustrates how devices communicate across the network, including VLAN assignments and trunk links (e.g., 802.1Q tagging) between switches. This diagram abstracts physical locations to show Layer 2 and Layer 3 relationships, such as which VLANs traverse which inter-switch links, making it ideal for documenting VLAN trunking and logical connectivity.

Exam trap

The trap here is that candidates confuse 'physical topology' with 'logical topology,' assuming that a physical diagram can show VLAN trunking, but physical diagrams only depict hardware connections, not the logical VLAN paths or trunking relationships.

Why the other options are wrong

A

A network baseline documents performance metrics over time, not the logical relationships between devices or VLAN trunking.

B

A wiring diagram shows physical cable paths and connector pinouts, not logical relationships like VLAN trunking between switches.

C

A physical topology diagram shows the physical layout and connections of cables and devices, not logical relationships like VLAN trunking between switches.

When would these options actually be correct?

A

When a question asks for a document that records normal network performance metrics (e.g., bandwidth utilization, latency) to compare against future anomalies, a network baseline is correct.

B

A wiring diagram would be correct if the question asked for a document detailing cable runs, patch panel connections, or physical wire routing for a new office installation.

C

When the question asks for a diagram that shows the physical location of devices, cable runs, and port connections for installation or troubleshooting physical connectivity.

Why candidates pick the wrong answer

A

Candidates may confuse 'baseline' with 'diagram' or think that documenting VLANs requires a baseline of traffic patterns.

B

Candidates may confuse 'wiring' with 'inter-switch links' and think a wiring diagram includes VLAN trunk information, but wiring diagrams focus on physical cabling, not logical data flow.

C

Candidates may confuse physical topology with logical topology, thinking that inter-switch links are physical connections, but the question specifically asks for logical relationships and VLAN trunking.

471
MCQeasy

A network administrator is troubleshooting a connectivity issue and suspects the problem is related to the physical cabling. At which layer of the OSI model should the administrator begin their investigation?

A.Transport layer
B.Data Link layer
C.Physical layer
D.Network layer
AnswerC

The Physical layer (Layer 1) is fundamentally responsible for the raw bit stream transmission over the physical medium, defining the electrical, mechanical, and procedural specifications for transmitting data signals. Therefore, issues such as faulty cables, damaged connectors, incorrect cable types, or signal degradation due to attenuation or electromagnetic interference directly manifest as problems at this foundational layer, preventing any higher-layer communication from occurring reliably or at all.

Why this answer

The Physical layer (Layer 1) is the correct starting point because the administrator suspects the problem is related to physical cabling. The Physical layer defines the electrical, mechanical, and procedural specifications for transmitting raw bits over a physical medium, such as copper or fiber optic cables. Troubleshooting at this layer involves checking for cable faults, signal degradation, or improper termination before moving up the OSI stack.

Exam trap

The trap here is that candidates often jump to the Data Link layer (Layer 2) because they associate 'connectivity issues' with MAC addresses or switching, forgetting that physical cabling faults must be ruled out first at Layer 1.

Why the other options are wrong

A

The question specifies a physical cabling issue, which is a Layer 1 (Physical layer) problem. The Transport layer (Layer 4) deals with end-to-end communication and data segmentation, not physical media.

B

The Data Link layer (Layer 2) handles framing, MAC addressing, and error detection, but not the physical cabling itself. The question specifically states the issue is related to physical cabling, which is Layer 1.

D

The Network layer (Layer 3) handles logical addressing and routing, not physical cabling issues. The administrator suspects a physical cabling problem, which is a Layer 1 concern.

When would these options actually be correct?

A

A question about troubleshooting a connectivity issue where the problem is suspected to be related to port numbers, session multiplexing, or reliable data delivery (e.g., TCP vs UDP issues) would make the Transport layer the correct starting point.

B

A question asking where to investigate issues with MAC address conflicts, frame errors, or switch port configuration (e.g., duplex mismatch) would make the Data Link layer the correct starting point.

D

This option would be correct if the question asked about troubleshooting a routing issue, such as incorrect IP configuration or a routing table problem, where the investigation should start at the Network layer.

Why candidates pick the wrong answer

A

Candidates may confuse the OSI layers and think that all connectivity issues start at higher layers, or they may recall that the Transport layer is involved in end-to-end connectivity, but they overlook the specific mention of physical cabling.

B

Candidates may confuse the Data Link layer with physical cabling because it deals with network interfaces and media access control, or they might think troubleshooting always starts at Layer 2.

D

Candidates may confuse the Network layer with physical connectivity because they associate 'network' with all networking hardware, or they may think IP addressing is involved in cable troubleshooting.

472
MCQmedium

A user reports that they can access the internet but cannot access the company's internal web application at https://intranet.company.local. The technician can ping the server's IP address (192.168.10.50) successfully from the user's workstation. However, when the technician runs 'nslookup intranet.company.local', it returns 'Non-existent domain'. What is the most likely cause?

A.The web server is not running on port 443.
B.The client's DNS server does not have a record for the internal domain.
C.A firewall is blocking traffic to the internal web server.
D.The hostname is misspelled in the browser.
AnswerB

This is the correct answer because an 'NXDOMAIN' (Non-existent domain) response from `nslookup` explicitly indicates that the DNS server queried could not find a corresponding A or CNAME record for the internal hostname. Since external internet access works, the client's DNS server is functional for public lookups but lacks the necessary zone information or conditional forwarders to resolve internal company domain names, preventing any connection attempts to internal resources.

Why this answer

The user can access the internet and ping the server's IP address, which confirms Layer 3 connectivity and that the web server is reachable. However, 'nslookup intranet.company.local' returns 'Non-existent domain', indicating that the DNS server used by the client does not have an A or CNAME record for that internal hostname. Since the browser relies on DNS resolution to translate the FQDN to an IP address, the failure to resolve the name prevents the web application from loading, even though the server itself is online and reachable.

Exam trap

CompTIA often tests the distinction between connectivity (ping) and name resolution (nslookup), trapping candidates who assume that successful ping to an IP means the web application should work, ignoring that DNS failure prevents the browser from even initiating the HTTP request.

Why the other options are wrong

A

The user can access the internet but not the internal web app, and nslookup returns 'Non-existent domain', indicating a DNS resolution failure. The web server being down on port 443 would not cause a DNS lookup to fail; it would cause a connection timeout or refusal after successful resolution.

C

The technician can ping the server's IP address successfully, indicating that network connectivity and firewall rules are not blocking traffic to the server. The issue is DNS resolution, not firewall filtering.

D

The user can access the internet and ping the server IP, but nslookup returns 'Non-existent domain', indicating a DNS resolution failure, not a browser misspelling. A misspelling would still result in a DNS query, not a 'Non-existent domain' error.

When would these options actually be correct?

A

A user reports being unable to access an internal HTTPS website, but nslookup resolves the hostname correctly. The technician can ping the server IP, and telnet to port 443 fails. In this scenario, the web server not running on port 443 would be the correct answer.

C

A user cannot access an internal web application, and pinging the server's IP address fails. A firewall rule blocking the specific port (e.g., 443) would be the likely cause, especially if other services on the server are reachable.

D

In a scenario where a user reports being unable to access a website, but nslookup resolves correctly and the server is reachable, the most likely cause could be a typo in the browser's address bar. For example, if the user typed 'intranet.company,local' instead of 'intranet.company.local'.

Why candidates pick the wrong answer

A

Candidates may think that since HTTPS uses port 443, a port issue is a common cause of web access problems, and they overlook the DNS failure evidence provided in the question.

C

Candidates often assume that any connectivity issue to a web server is due to a firewall, overlooking that successful ping to the IP proves basic network access is allowed.

D

Candidates may assume that a simple typo is the easiest explanation for a web access issue, overlooking the DNS error message that clearly indicates the hostname cannot be resolved at all.

Page 6

Page 7 of 7

All pages