All practice questions
2237 questions
A network administrator is investigating intermittent VoIP audio degradation across an enterprise WAN link connecting two branch offices. Telephony logs indicate elevated packet loss and jitter during peak operational hours. Corporate security policy dictates that all infrastructure monitoring must utilize encrypted payload data and cryptographic authentication to prevent packet interception on intermediate links. Additionally, the administrator must gather interface bandwidth utilization baselines alongside granular protocol flow analysis to isolate the source of network congestion. Which of the following protocol and security level combinations correctly fulfills both operational and security requirements?
A network administrator is preparing to apply a major firmware update to enterprise distribution switches following a vendor security advisory. Which TWO of the following actions should the administrator perform during the pre-deployment and staging phase to verify software integrity and minimize operational risk?
Select all that apply
An enterprise network architect is designing a comprehensive monitoring strategy for a multi-site WAN deployment. The solution must provide secure, continuous device health monitoring, granular flow visibility for bandwidth utilization analysis, and ensure compliance with strict zero-trust cryptographic requirements. Which of the following technical configurations and protocols should the architect deploy to satisfy these operational requirements? (Select TWO).
Select all that apply
A network security team observes severe throughput degradation and dropped legitimate traffic on an inline Network Intrusion Prevention System (NIPS) during peak hours. The NIPS performs deep packet inspection and signature matching on unencrypted perimeter traffic. Concurrently, an audit reveals that internal attackers are transmitting malicious encrypted payloads across TLS sessions that bypass the NIPS undetected. Which of the following architectural modifications best addresses the processing bottleneck while providing threat visibility into the encrypted traffic?
An IT department deploys Virtual Router Redundancy Protocol (VRRP) across two edge routers, Router-1 (Primary, physical IP ) and Router-2 (Backup, physical IP ), to provide default gateway redundancy for a LAN. The virtual router is assigned the Virtual IP (VIP) address . During a planned failover test, Router-1 is powered down. Although Router-2 correctly assumes the active VRRP Master role, all client workstations on the LAN immediately lose access to external networks. Which of the following host misconfigurations is the most likely cause of this service disruption?
A network security administrator is configuring a centralized logging and monitoring architecture across enterprise core switches. The corporate compliance policy mandates that event logs are delivered reliably with connection-oriented transport and encrypted in transit, and that SNMP polling must provide both cryptographic user authentication and payload encryption. Which of the following protocol and port configurations must the administrator implement to meet these requirements? (Select TWO.)
Select all that apply
A network administrator is designing a high-availability infrastructure for a mission-critical application server cluster. The design must provide Layer 2 link bandwidth aggregation with failure protection between switches, as well as Layer 3 active-standby gateway redundancy for host workstations on the local subnet. Which TWO of the following protocols or configurations should be deployed to satisfy these requirements?
Select all that apply
A network administrator is preparing to modify the interface configurations on a primary distribution switch during a scheduled maintenance window. Which of the following steps should be completed BEFORE applying any configuration updates to ensure the switch can be rapidly restored if the change causes an unexpected outage?
A network security administrator configures a passive Network Intrusion Detection System (NIDS) connected to a switch port mirroring session. While the system successfully logs alert notifications for unauthorized port scans, it does not stop the scanning traffic from reaching internal hosts. Which architectural characteristic explains why the NIDS cannot directly drop these attack packets?
A network administrator configures a First Hop Redundancy Protocol (FHRP) across two routers to ensure continuous network availability for clients on a local subnet. To enable seamless automated failover if the primary router fails, which address must be specified as the default gateway on the client workstations?
An enterprise network operations team must urgently remediate a newly published zero-day vulnerability affecting the routing protocol daemon across core Layer 3 switches. Which of the following procedures should the engineering team execute during the emergency maintenance window to preserve high availability and maintain change management compliance? (Select TWO.)
Select all that apply
An enterprise network engineering team is preparing a formal Request for Change (RFC) to modify core switch configurations and re-architect VLAN trunking across multiple datacenters. To adhere strictly to enterprise configuration and change management standards, which of the following components MUST be included within the submitted RFC prior to presenting it to the Change Advisory Board (CAB) for evaluation? (Select TWO.)
Select all that apply
A network administrator is scheduling a critical vendor-issued software update for an organization's central network monitoring server. Before deploying the software update into the live environment, the administrator needs to ensure that the patch will not disrupt existing monitoring services or introduce system instability. Which of the following represents the most appropriate initial step in the patch management lifecycle to safely mitigate this risk?
Match each AAA framework component or access control concept on the left to its corresponding operational description on the right.
Click a left item, then click its matching right item
Items
Matches
An enterprise security team is deploying 802.1X port-based network access control across corporate network switches. In this architecture, the edge switch serves as the authenticator and relays Extensible Authentication Protocol (EAP) messages between the client host and a centralized authentication server. Which protocol is primarily utilized between the switch and the authentication server to transport these encapsulated EAP packets?
Match each core security principle of the CIA triad to its primary operational objective.
Click a left item, then click its matching right item
Items
Matches
During an unpredicted core link failure, a lead network engineer executed an approved Emergency Change (ECAB) by manually applying temporary static routing overrides directly on live edge routers to restore connectivity. Three hours later, an automated configuration management pipeline executed its scheduled compliance audit and synchronized the routers against the central version-controlled repository, inadvertently wiping out the manual emergency modifications and restoring the outage. Which of the following procedures should have been completed immediately following the emergency implementation to permanently prevent this configuration drift?
Match each wireless security standard on the left with its primary encryption algorithm or cipher suite on the right.
Click a left item, then click its matching right item
Items
Matches
Match each high-availability concept or protocol on the left with its correct operational description on the right.
Click a left item, then click its matching right item
Items
Matches
A healthcare organization experiences an outage on its web-based patient portal after a misconfigured network backup script fails to clear temporary files, causing the primary storage volume to fill completely and crashing the service. Although all patient records remained securely encrypted at rest and no data was accessed or altered by unauthorized parties, clinical staff were unable to access critical patient records for three hours. Which pillar of the CIA triad was directly compromised in this incident?