Courseiva
← Back to CompTIA Network+ N10-009 questions

Scenario-based practice

Hard Difficulty Questions

Practise CompTIA Network+ N10-009 practice questions — original exam-style scenarios covering every exam domain, with detailed explanations, wrong-answer analysis, and common exam traps.

20
scenario questions
N10-009
exam code
CompTIA
vendor

Scenario guide

How to approach hard difficulty questions

These are the questions most candidates get wrong. They require connecting multiple concepts, reading tricky output, or knowing edge-case behaviour that isn't on most study cards. Practising them trains you to operate under uncertainty — a necessary skill on the real exam.

Quick answer

Hard Difficulty Questions questions test whether you can apply the concept in context, not just recognise a definition.

How the topic appears in realistic exam-style scenarios.

Which detail in the question changes the correct answer.

How to eliminate plausible but wrong options.

How to connect the question back to the wider exam objective.

Related practice questions

Related N10-009 topic practice pages

Scenario questions usually connect to one or more exam topics. Use these links to review the underlying concepts behind the scenario.

Practice set

Practice scenarios

Question 1hardmultiple choice
Full question →

A security analyst is reviewing firewall logs and sees many incoming packets with a source IP address that matches the internal IP range of the company (10.0.0.0/8) arriving on the external interface. Which type of attack is likely being attempted?

Question 2hardmultiple choice
Review the full OSPF breakdown →

An organization uses OSPF as its interior gateway protocol in a multi-area design. After a core router failure, the network takes a long time to reconverge. Which technology can be implemented to improve convergence speed?

Question 3hardmultiple choice
Read the full VPN explanation →

An organization's security policy requires that all remote access VPN connections use two-factor authentication and that the VPN clients are compliant with the latest patch levels before gaining network access. Which technology combination provides these capabilities?

Question 4hardmultiple choice
Read the full VPN explanation →

A security engineer is configuring a site-to-site VPN between two branch offices. The requirement is to encrypt all traffic between the two networks using IPsec. Which IPsec mode should be used to encrypt the entire IP packet including the original header?

Question 5hardmultiple choice
Review the full subnetting walkthrough →

A security analyst receives an alert that an internal user's workstation is sending a high volume of ARP requests for multiple IP addresses on the local subnet. The analyst suspects a man-in-the-middle attack. Which security mechanism is most effective at mitigating this type of attack on a switched network?

Question 6hardmultiple choice
Full question →

A network administrator reviews firewall logs and sees thousands of SYN packets coming from various source IP addresses to a single internal web server. No ACK or RST packets are observed from these sources. Which type of attack is most likely occurring?

Question 7hardmultiple choice
Read the full DHCP explanation →

A security analyst is reviewing logs and finds that a single MAC address is rapidly requesting IP addresses from a DHCP server, each time with a different client ID. The DHCP server is exhausting its address pool. Which type of attack is occurring?

Question 8hardmultiple choice
Open the full VLAN trunking answer →

A network administrator has configured a switch with four VLANs: VLAN 10, 20, 30, and 99 (native). The switch is connected to a router via an 802.1Q trunk link. The router has subinterfaces for VLANs 10, 20, and 30, each with an IP address. VLAN 99 is used for management and does not have a router subinterface. How many Layer 3 broadcast domains exist in this network?

Question 9hardmultiple choice
Open the full VLAN trunking answer →

Users in VLAN 10 cannot obtain IP addresses from the DHCP server located in VLAN 20. The router interface for VLAN 10 has an ip helper-address 192.168.20.5 command configured, and users can ping the DHCP server IP (192.168.20.5) from the router. However, users receive APIPA addresses. What is the most likely cause?

Question 10hardmultiple choice
Full question →

A security analyst observes that an internal server is sending a large volume of TCP SYN packets to various external IP addresses, but never completing the three-way handshake. This behavior is indicative of which type of attack?

Question 11hardmultiple choice
Full question →

A company's public web server is experiencing a flood of TCP SYN packets from multiple external IP addresses. The server's connection table is full, causing new legitimate connections to be dropped. Which of the following mitigation techniques should be implemented to protect the server while still allowing legitimate traffic?

Question 12hardmultiple choice
Study the full IPv6 explanation →

A network engineer is designing a new IPv6 addressing scheme. The company has been assigned a /48 prefix and needs to support up to 250 subnets. Which subnet size should be used to minimize waste while meeting the requirement?

A network administrator configures a router to send syslog messages to a central log server. The administrator can ping the server from the router, but the server is not receiving any logs. What is the most likely cause?

Question 14hardmultiple choice
Full question →

A network administrator is configuring a monitoring system to collect metrics from network devices. The administrator needs to ensure that the monitoring system can automatically discover the devices and obtain detailed information about their configuration and status, such as interface descriptions and software versions. Which protocol is best suited for this purpose?

Question 15hardmultiple choice
Review the full OSPF breakdown →

Two routers are configured with OSPF in the same area, but they do not form an adjacency. Router A shows OSPF state EXSTART, and Router B shows state EXSTART. Which of the following is the most likely cause?

Question 16hardmultiple choice
Review the full OSPF breakdown →

A network engineer configures OSPF on two routers with a primary link (1 Gbps) and a backup link (100 Mbps). The engineer expects traffic to always use the primary link unless it fails, but the router is sending traffic over the backup link. What is the most likely cause?

Question 17hardmultiple choice
Open the full VLAN trunking answer →

A network engineer is troubleshooting intermittent call drops on a VoIP deployment. The network uses separate VLANs for voice (VLAN 20) and data (VLAN 10). Switch ports connecting the IP phones are configured with the correct voice VLAN. Which of the following is the MOST likely cause to check NEXT?

Question 18hardmultiple choice
Full question →

A network administrator scheduled a change window to upgrade the firmware on a core switch. During the upgrade, the switch fails to boot properly. The administrator needs to restore the switch to its previous operational state. Which of the following should the administrator have done before the upgrade to facilitate a successful rollback?

Question 19hardmultiple choice
Open the full VLAN trunking answer →

A network technician is troubleshooting an issue where Server A can ping Server B by IP address, but Server B cannot ping Server A. Both servers are in the same VLAN and subnet, connected to the same switch. The switch ports are configured identically, and there are no ACLs or firewalls between them. Which of the following is the MOST likely cause?

Question 20hardmultiple choice
Full question →

A company is implementing 802.1X port-based authentication on its wired network to control access. The network uses Active Directory for user accounts. Which type of server must be deployed to authenticate clients connecting to the switch ports?

These N10-009 practice questions are part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style N10-009 questions with detailed explanations, topic-based practice, mock exams, readiness tracking, and study analytics.