Courseiva

CCNA Networking Questions

22 of 97 questions · Page 2/2 · Networking topic · Answers revealed

76
MCQeasy

A junior administrator needs to verify that the host can resolve the name db.internal.example.com to an IPv4 address before deploying a database client. The system uses systemd-resolved. Which command queries the configured resolver and displays the answer without relying on the local nsswitch.conf ordering?

A.dig db.internal.example.com
B.host db.internal.example.com
C.getent hosts db.internal.example.com
D.resolvectl query db.internal.example.com
AnswerD

resolvectl query sends the name to systemd-resolved and reports the answer along with which link and DNS server provided it. This directly exercises the resolver configured on the system, bypassing nsswitch.conf ordering, and is the correct tool on systemd-resolved hosts. It also shows whether the answer came from cache, DNS, or another source, which is valuable for troubleshooting.

Why this answer

resolvectl query is the native client for systemd-resolved. It sends the query through the resolver daemon, showing the answer, the link used, and the DNS server that responded. This isolates DNS resolution from nsswitch.conf sources like /etc/hosts, which is exactly what is needed to confirm the configured resolver can resolve the name.

Exam trap

The trap here is assuming that any lookup tool tests the configured resolver, when tools like getent and host actually follow nsswitch.conf and may return /etc/hosts entries instead.

77
MCQmedium

A server must resolve internal hostnames using a DNS server at 10.0.0.53 before falling back to public resolvers. The administrator edits /etc/systemd/resolved.conf and sets DNS=10.0.0.53 and FallbackDNS=8.8.8.8. After restarting systemd-resolved, queries for internal names still fail. Which additional step is most likely required?

A.Ensure /etc/resolv.conf is a symlink to /run/systemd/resolve/stub-resolv.conf or /run/systemd/resolve/resolv.conf.
B.Add the search domain to /etc/hosts so internal names resolve locally.
C.Run resolvectl flush-caches to clear stale entries.
D.Set DNSSEC=no in resolved.conf because DNSSEC validation is blocking internal responses.
AnswerA

systemd-resolved only serves queries through its stub listener if /etc/resolv.conf points to the stub resolver file. If it still points to a static file or a different target, applications bypass systemd-resolved and the configured DNS servers are never used. Correcting the symlink makes the configuration effective.

Why this answer

systemd-resolved reads DNS server settings from resolved.conf, but applications reach it through /etc/resolv.conf. If that file is not symlinked to the stub or full resolv.conf generated by systemd-resolved, the configured servers are ignored. Recreating the symlink ensures queries go through systemd-resolved and reach 10.0.0.53.

Exam trap

The trap here is assuming that editing resolved.conf is sufficient, when the /etc/resolv.conf symlink determines whether systemd-resolved is actually used.

78
MCQeasy

An administrator needs to view the current IPv4 addresses, link state, and interface names on a Linux server without making any changes. Which command provides this information in a single invocation?

A.ip addr show
B.ifconfig -a
C.ss -tuln
D.ip route show
AnswerA

ip addr show displays all interfaces with their link state and assigned IPv4 and IPv6 addresses. It is the standard, non-disruptive command to inspect current addressing and interface status, exactly matching the requirement to view addresses and link state without modifying configuration.

Why this answer

The ip command from iproute2 is the current standard for network configuration and inspection. ip addr show lists every interface with its operational state, MAC address, and assigned IPv4/IPv6 addresses, which is precisely the information requested. The other commands either show unrelated data or belong to deprecated tooling.

Exam trap

The trap here is reaching for the deprecated ifconfig -a out of habit instead of the current ip addr show.

79
MCQmedium

A server needs to forward packets between two networks: 10.0.1.0/24 on eth0 and 10.0.2.0/24 on eth1. Which sysctl parameter must be enabled?

A.net.ipv4.conf.all.rp_filter = 1
B.net.ipv4.ip_forward = 1
C.net.ipv4.conf.all.accept_source_route = 1
D.net.ipv4.conf.all.send_redirects = 0
AnswerB

Setting net.ipv4.ip_forward to 1 enables the kernel to route packets between interfaces rather than dropping them, which is exactly what forwarding between eth0's 10.0.1.0/24 and eth1's 10.0.2.0/24 requires. Without it, the server cannot act as a router.

Why this answer

Enabling `net.ipv4.ip_forward = 1` allows the Linux kernel to forward IP packets between network interfaces, which is required for a server to route traffic between the 10.0.1.0/24 and 10.0.2.0/24 subnets. Without this parameter, the kernel drops any packet not destined for the local system, preventing inter-network communication.

Exam trap

The trap here is that candidates often confuse security-related sysctl parameters (like rp_filter or send_redirects) with the actual forwarding control, or mistakenly think that enabling source route acceptance is needed for routing between subnets.

How to eliminate wrong answers

Option A is wrong because `net.ipv4.conf.all.rp_filter = 1` enables reverse path filtering, which helps prevent IP spoofing by dropping packets that arrive on an interface that is not the best route back to the source; it does not enable packet forwarding. Option C is wrong because `net.ipv4.conf.all.accept_source_route = 1` allows the system to process IPv4 source-routed packets, a security risk that is unrelated to forwarding between networks. Option D is wrong because `net.ipv4.conf.all.send_redirects = 0` disables the sending of ICMP redirect messages, which is a security hardening measure but does not enable or disable packet forwarding.

80
MCQhard

A Linux server is configured with two network interfaces: eth0 (192.168.1.10/24) and eth1 (10.0.0.10/24). The default route is via 192.168.1.1. A network administrator wants to ensure that traffic to the 10.0.0.0/24 network uses eth1 and that the source address for that traffic is 10.0.0.10. Which command will achieve this?

A.ip route add 10.0.0.0/24 via 10.0.0.1 dev eth1
B.ip route add 10.0.0.0/24 dev eth1
C.ip route add 10.0.0.0/24 dev eth1 src 10.0.0.10
D.ip route add default via 10.0.0.1 dev eth1
AnswerC

This command adds a route for the 10.0.0.0/24 network directly via eth1 and specifies the source address 10.0.0.10. It ensures that packets to that network are sent out eth1 with the correct source IP, meeting the administrator's requirement without needing a gateway.

Why this answer

To direct traffic for a specific directly attached network out a particular interface and use a specific source address, the ip route add command with the dev and src options is used. This ensures packets to 10.0.0.0/24 leave via eth1 with source 10.0.0.10, fulfilling the requirement without affecting other traffic.

Exam trap

The trap here is forgetting to specify the source address or incorrectly using a gateway for a directly attached network.

81
Drag & Dropmedium

Order the steps to configure a static IP address on a CentOS/RHEL 7 system using ifcfg files.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

Static IP configuration requires editing the ifcfg file, restarting network, and verification.

82
MCQeasy

A technician needs to view the current IPv4 addresses, netmasks, and interface states for all network interfaces on a Linux server. Which command displays this information in a structured, modern format?

A.netstat -rn
B.ss -tuln
C.ifconfig -a
D.ip addr show
AnswerD

The ip addr show command (or its shorthand ip a) displays IPv4 and IPv6 addresses, netmasks in CIDR notation, and interface operational states for all interfaces. It is part of the iproute2 suite and is the modern replacement for ifconfig. It provides exactly the structured output needed to inspect addressing and link status.

Why this answer

The ip addr show command is the standard modern tool for displaying interface addresses, netmasks, and states. It is part of iproute2 and provides both IPv4 and IPv6 details in a structured format. The other commands either show routing tables, socket statistics, or rely on deprecated tools that do not present the requested information in the required format.

Exam trap

The trap here is reaching for ifconfig out of habit, even though it is deprecated and does not show CIDR netmasks or IPv6 by default.

83
Multi-Selecteasy

A system administrator needs to check the firewall rules on a Linux server using firewalld. Which two commands can be used to list the current rules? (Choose two.)

Select 2 answers
A.systemctl status firewalld
B.iptables -S
C.iptables -L
D.firewall-cmd --list-all-zones
E.firewall-cmd --list-all
AnswersD, E

Correct. This command displays the firewall rules for all zones configured in firewalld, including services, ports, and rules per zone.

Why this answer

`firewall-cmd --list-all-zones` displays the firewall rules for all zones configured in firewalld, showing services, ports, and rules per zone. Option E is correct because `firewall-cmd --list-all` lists the rules for the default zone, providing a concise view of active firewall configuration. Both commands are native to firewalld and directly query its runtime and permanent rules via D-Bus.

Exam trap

The trap here is that candidates confuse legacy iptables commands with firewalld's native tools, assuming `iptables -L` or `-S` are equivalent to listing firewalld rules, when in fact they bypass firewalld's zone abstraction and may not reflect the current dynamic configuration.

84
Multi-Selecthard

Which THREE files or directories are commonly used to configure network interfaces on a RHEL/CentOS system?

Select 3 answers
A./etc/rc.d/rc.local
B./etc/resolv.conf
C./etc/sysconfig/network
D./etc/sysconfig/network-scripts/
E./etc/nsswitch.conf
AnswersB, C, D

This file configures DNS resolver settings.

Why this answer

/etc/resolv.conf is the primary configuration file for DNS resolver settings on RHEL/CentOS systems. It specifies the nameserver IP addresses, search domains, and resolver options used by the system's glibc resolver library to perform DNS lookups. Without this file, domain name resolution will fail, making it essential for network interface configuration.

Exam trap

The trap here is that candidates often confuse /etc/resolv.conf as a static configuration file, but on modern systems it is frequently auto-generated by NetworkManager or dhclient, leading to the misconception that it is not a 'commonly used' configuration file for network interfaces.

85
MCQhard

Given the network interface configuration in the exhibit, which command should be run to apply the configuration without rebooting?

A.systemctl restart network
B.ifup eth0
C.ifconfig eth0 down && ifconfig eth0 up
D.ip link set eth0 up
AnswerB

Brings up the interface with the configuration in ifcfg-eth0.

Why this answer

The `ifup eth0` command reads the configuration file for the eth0 interface (typically `/etc/sysconfig/network-scripts/ifcfg-eth0` on RHEL/CentOS) and applies the settings (IP address, netmask, gateway, etc.) without requiring a system reboot. This is the standard way to activate a network interface with its configured parameters on Linux systems using the legacy network scripts.

Exam trap

The trap here is that candidates confuse bringing an interface up with applying its configuration, assuming that `ip link set eth0 up` or toggling `ifconfig` will also restore IP settings, when in fact those commands only affect the link state and do not read the persistent configuration file.

How to eliminate wrong answers

Option A is wrong because `systemctl restart network` restarts the entire network service, which can disrupt all active connections and is unnecessary for applying a single interface's configuration; it also may not be available on systems using NetworkManager. Option C is wrong because `ifconfig eth0 down && ifconfig eth0 up` only toggles the interface link state without reading the configuration file, so it will not apply any new settings (e.g., a changed IP address) and may leave the interface with stale parameters. Option D is wrong because `ip link set eth0 up` only brings the interface administratively up at Layer 2, but does not assign any IP address or apply Layer 3 configuration from the interface's config file.

86
MCQmedium

A Linux server uses NetworkManager and has a wired connection profile named 'Wired connection 1'. The administrator needs to set a static IPv4 address 10.20.30.40/24 with gateway 10.20.30.1, and ensure the change persists across reboots. Which sequence of commands accomplishes this?

A.nmcli dev modify eth0 ipv4.addresses 10.20.30.40/24 ipv4.gateway 10.20.30.1 ipv4.method manual
B.nmcli con mod 'Wired connection 1' ipv4.addresses 10.20.30.40/24 ipv4.gateway 10.20.30.1 ipv4.method manual && nmcli con up 'Wired connection 1'
C.ip addr add 10.20.30.40/24 dev eth0 && ip route add default via 10.20.30.1
D.nmcli con add type ethernet con-name 'Wired connection 1' ifname eth0 ip4 10.20.30.40/24 gw4 10.20.30.1
AnswerB

This is correct because 'nmcli con mod' modifies the persistent connection profile, setting the static address, gateway, and method to manual, and 'nmcli con up' reactivates the profile to apply the changes immediately. NetworkManager stores the configuration in its connection files, so the settings survive reboots.

Why this answer

The correct approach uses 'nmcli con mod' to alter the existing connection profile's IPv4 settings and set the method to manual, then brings the connection up to apply the changes. This persists the static address and gateway in NetworkManager's configuration, satisfying the reboot requirement. Lower-level ip commands are temporary and do not modify profiles, while creating a duplicate profile or using an invalid command would not achieve the goal.

Exam trap

The trap here is assuming that ip addr and ip route commands persist across reboots or that 'nmcli dev modify' is a valid way to change persistent settings.

87
Multi-Selecthard

An administrator is troubleshooting DNS resolution and wants to query the SOA record for a domain. Which three commands can be used? (Choose three.)

Select 3 answers
A.nslookup -type=soa example.com
B.host -t SOA example.com
C.dig example.com SOA
D.nmcli dev show
E.getent hosts example.com
AnswersA, B, C

nslookup can query SOA records.

Why this answer

The `nslookup -type=soa` command queries the DNS for the Start of Authority (SOA) record of a domain. The `-type=soa` flag explicitly sets the query type to SOA, which returns authoritative information about the zone, including the primary name server and administrator email.

Exam trap

The trap here is that candidates may confuse `getent hosts` with DNS lookup tools, not realizing it bypasses DNS resolution and only checks local name resolution sources.

88
MCQmedium

A server has two NICs bonded in mode 1 (active-backup). If the active NIC fails, what occurs?

A.Both NICs continue to pass traffic simultaneously
B.Traffic automatically switches to the backup NIC with minimal interruption
C.The bond interface goes down until an administrator intervenes
D.The system disables the bond and uses a single NIC
AnswerB

Mode 1 active-backup bonding keeps the backup NIC passive until the active link fails. Failover detection then moves the MAC and traffic to the backup interface, maintaining connectivity with only brief interruption, satisfying the redundancy requirement.

Why this answer

In bonding mode 1 (active-backup), only one NIC is active at a time while the other remains in standby. When the active NIC fails, the bonding driver automatically fails over to the backup NIC by reassigning the MAC address and IP to the backup interface, typically within a few milliseconds. This ensures minimal interruption to network traffic without requiring manual intervention.

Exam trap

The trap here is that candidates often confuse active-backup (mode 1) with balance-rr (mode 0) or assume that both NICs must be active for redundancy, leading them to incorrectly select Option A.

How to eliminate wrong answers

Option A is wrong because in active-backup mode, only one NIC passes traffic at any given time; both NICs never pass traffic simultaneously. Option C is wrong because the bond interface does not go down; the failover is automatic and does not require administrator intervention. Option D is wrong because the bond interface remains operational and continues to use the backup NIC; the system does not disable the bond or revert to a single un-bonded NIC.

89
MCQmedium

A Linux server has a single network interface ens3. You need to assign the static address 10.10.10.5/24 with gateway 10.10.10.1 using NetworkManager. The connection profile is named 'static-ens3'. Which command correctly applies the IPv4 address, disables DHCP, and sets the gateway, all in one step?

A.nmcli con mod static-ens3 ipv4.addresses 10.10.10.5/24 ipv4.gateway 10.10.10.1 ipv4.method manual
B.nmcli con mod static-ens3 ipv4.addresses 10.10.10.5/24 ipv4.gateway 10.10.10.1 ipv4.method auto
C.nmcli con up static-ens3 ipv4.addresses 10.10.10.5/24 ipv4.gateway 10.10.10.1 ipv4.method manual
D.nmcli con add type ethernet ifname ens3 ipv4.addresses 10.10.10.5/24 ipv4.gateway 10.10.10.1 ipv4.method manual
AnswerA

This nmcli command modifies the existing connection profile named static-ens3, setting the IPv4 address, gateway, and switching the method to manual. It is the correct and idiomatic way to configure a static address with NetworkManager. After this command, you would need to bring the connection up (or reactivate it) for the changes to take effect.

Why this answer

The correct command uses 'nmcli con mod' to modify the existing connection profile named static-ens3. It sets the IPv4 address, gateway, and changes the method to manual, which disables DHCP. This is the standard way to apply a static configuration with NetworkManager.

After modification, the connection must be reactivated for the changes to take effect.

Exam trap

The trap here is confusing 'nmcli con mod' (modify existing profile) with 'nmcli con add' (create new profile) or 'nmcli con up' (activate profile), and forgetting that 'ipv4.method manual' is required to disable DHCP.

90
MCQeasy

A junior administrator must temporarily assign the address 172.16.5.20/24 to interface eth1 on a running server so that a migration can be tested, and the change must not survive a reboot. Which command accomplishes this?

A.ip addr add 172.16.5.20/24 dev eth1
B.ip link set eth1 up && ip route add 172.16.5.20/24 dev eth1
C.ifconfig eth1 172.16.5.20 netmask 255.255.255.0
D.nmcli con mod eth1 ipv4.addresses 172.16.5.20/24 && nmcli con up eth1
AnswerA

The ip addr add command assigns the address to the interface immediately in the running kernel. Because it only modifies runtime state and does not write any configuration file, the address disappears on reboot, which matches the requirement for a temporary change during migration testing.

Why this answer

Temporary address changes are made directly in the kernel with the iproute2 ip addr add command. This affects the running system only and is lost on reboot, which is exactly what the migration test requires. Persistent configuration tools such as NetworkManager profiles or network configuration files would write the change to disk and reapply it at boot.

Exam trap

The trap here is choosing a NetworkManager or configuration-file method, which makes the address persistent and therefore violates the explicit requirement that the change not survive a reboot.

91
Multi-Selecthard

A Linux server is configured as a router with IP forwarding enabled. It has two interfaces: eth0 (203.0.113.5/24) and eth1 (192.168.1.1/24). Clients on 192.168.1.0/24 need to reach the internet via eth0. The administrator has set up NAT using iptables with the rule: iptables -t nat -A POSTROUTING -o eth0 -j MASQUERADE. However, clients cannot access external websites. Which two actions should the administrator take to resolve the issue? (Choose two.)

Select 2 answers
A.Add a SNAT rule instead of MASQUERADE for better performance.
B.Disable the firewall on the clients to allow outbound connections.
C.Verify that IP forwarding is enabled by checking the value of net.ipv4.ip_forward.
D.Ensure that the FORWARD chain policy is ACCEPT or add rules to allow forwarding from eth1 to eth0.
E.Configure a default route on the router pointing to the ISP gateway.
AnswersC, D

NAT alone does not enable routing. The kernel must have IP forwarding enabled, typically via sysctl net.ipv4.ip_forward=1. If this is disabled, packets from the internal network will not be forwarded to the external interface, causing the connectivity failure described.

Why this answer

For a Linux router to forward traffic between interfaces, IP forwarding must be enabled, and the FORWARD chain must permit the traffic. Even with MASQUERADE configured, if either condition is not met, packets will be dropped. The administrator should verify net.ipv4.ip_forward and ensure FORWARD rules allow traffic from the internal to external interface.

Exam trap

The trap here is focusing solely on NAT configuration while overlooking the need for IP forwarding and FORWARD chain rules.

92
Matchingmedium

Match each systemd unit type to its purpose.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Manages a daemon or service

Interprocess communication socket

Schedules and activates other units

Controls mount points

Groups units for synchronization

Why these pairings

Correct matches: service manages processes, socket handles socket activation, timer schedules events, target groups units. Common confusion: mixing socket and timer responsibilities is typical.

93
Multi-Selecteasy

Which TWO commands can be used to resolve a hostname to an IP address?

Select 2 answers
A.host
B.traceroute
C.ping
D.nslookup
E.ifconfig
AnswersA, D

This is a DNS lookup utility.

Why this answer

The `host` command is a simple DNS lookup utility that queries DNS servers to resolve a hostname to an IP address. It directly performs forward DNS resolution using the system's configured resolvers and returns the A or AAAA record for the given name.

Exam trap

The trap here is that candidates often think `ping` is a valid name resolution tool because it can accept a hostname and display the resolved IP in its output, but `ping` relies on the system resolver and does not perform its own DNS query—it only displays the IP after the system has already resolved it, making it a connectivity test, not a resolution command.

94
Multi-Selecteasy

Which TWO commands can be used to display listening TCP ports on a Linux system?

Select 2 answers
A.ss -tln
B.netstat -tln
C.nmap -sT localhost
D.iptables -L
E.lsof -i TCP
AnswersA, B

ss -tln lists listening TCP ports (t for TCP, l for listening, n for numeric).

Why this answer

The `ss -tln` command displays listening TCP sockets by using the `-t` flag for TCP, `-l` for listening sockets, and `-n` to show numeric addresses and ports without resolving service names. It reads socket information directly from the kernel's netlink interface, making it the modern replacement for netstat on Linux systems.

Exam trap

The trap here is that candidates often assume `lsof -i TCP` shows only listening ports, but without the `-sTCP:LISTEN` filter it displays all TCP sockets, including established connections, making it incorrect for the specific requirement of listing only listening TCP ports.

95
MCQmedium

A Linux server has a DNS resolver configuration in /etc/resolv.conf. You need to add a new DNS server at 8.8.8.8 and ensure it is used before the existing server. Which line should you add to the top of /etc/resolv.conf?

A.dns 8.8.8.8
B.nameserver 8.8.8.8:53
C.search 8.8.8.8
D.nameserver 8.8.8.8
AnswerD

The 'nameserver' directive specifies a DNS server. Placing 'nameserver 8.8.8.8' at the top of /etc/resolv.conf makes it the first server queried. The resolver tries nameservers in the order they appear, so this ensures it is used before the existing server. This is the correct syntax and placement.

Why this answer

The correct line is 'nameserver 8.8.8.8'. The resolver reads nameserver entries in order, so placing it at the top makes it the first server used. The other options use invalid keywords or syntax that would not be recognized by the resolver.

Exam trap

The trap here is using incorrect keywords such as 'dns' or adding a port number to the nameserver IP, which are invalid in /etc/resolv.conf.

96
MCQeasy

An administrator wants to ensure that a service is listening on TCP port 8080 and accessible from remote hosts. Which command will confirm that the service is listening on the correct interface?

A.iptables -L
B.netstat -i
C.ss -tlnp
D.ip addr
AnswerC

The ss -tlnp command lists TCP listening sockets with numeric ports and the owning process, showing which interface each service binds to. This confirms whether the service listens on port 8080 and is reachable remotely, satisfying the stem's verification requirement.

Why this answer

The `ss -tlnp` command displays listening (`-l`) TCP (`-t`) sockets with numeric addresses (`-n`) and the associated process (`-p`), which directly confirms that a service is bound to TCP port 8080 on a specific interface (e.g., 0.0.0.0:8080 or 192.168.1.10:8080). This ensures the service is listening on the correct interface and is reachable from remote hosts.

Exam trap

The trap here is that candidates confuse commands that show network configuration or firewall rules with those that show actual listening sockets, leading them to pick `iptables -L` or `ip addr` instead of `ss -tlnp`.

How to eliminate wrong answers

Option A is wrong because `iptables -L` lists firewall rules, not listening sockets; it cannot confirm whether a service is listening on a specific port or interface. Option B is wrong because `netstat -i` displays interface statistics (packets, errors, etc.), not listening sockets or port bindings. Option D is wrong because `ip addr` shows IP addresses assigned to network interfaces, not the listening state of services or TCP ports.

97
MCQhard

A Linux router has two interfaces: eth0 (203.0.113.10/24) connected to the internet and eth1 (10.10.0.1/24) connected to an internal network. Internal clients can ping the router's eth1 address but cannot reach external websites. IP forwarding is enabled, and no firewall rules are present. Which command will allow the internal clients to reach the internet by masquerading their traffic?

A.iptables -t nat -A POSTROUTING -o eth1 -j MASQUERADE
B.iptables -t nat -A PREROUTING -i eth1 -j MASQUERADE
C.iptables -t nat -A POSTROUTING -o eth0 -j MASQUERADE
D.iptables -A FORWARD -i eth1 -o eth0 -j ACCEPT
AnswerC

This rule adds a source NAT (masquerade) rule to the POSTROUTING chain for packets leaving via eth0. It rewrites the source address of internal packets to the router's external IP, allowing return traffic to be routed back. This is the standard way to provide internet access for a private subnet when the external address is dynamic or when using a single public IP.

Why this answer

For internal clients to reach the internet through a router, their private source addresses must be translated to the router's public address. This is done with a MASQUERADE rule in the nat table's POSTROUTING chain, applied to packets leaving the external interface. The other options either use the wrong chain, only permit forwarding without translation, or masquerade in the wrong direction.

Exam trap

The trap here is placing MASQUERADE in PREROUTING or on the internal interface, confusing the direction of source NAT.

← PreviousPage 2 of 2 · 97 questions total

Ready to test yourself?

Try a timed practice session using only Networking questions.