All practice questions

2237 questions

Question 1101Question

A network administrator prepares a Request for Change (RFC) to perform a major firmware upgrade on the primary core switches of a enterprise network. The submitted RFC includes the technical rationale, a comprehensive risk impact analysis, results from pre-deployment sandbox testing, and a designated maintenance window schedule. During the Change Advisory Board (CAB) review, the committee defers approval due to an omitted required section. Which of the following critical elements was missing from the submitted RFC?

Show answer & explanation

Answer: A formal rollback plan defining specific trigger thresholds and step-by-step procedures to revert to the previous stable state if validation fails

Answer

A formal rollback plan defining specific trigger thresholds and step-by-step procedures to revert to the previous stable state if validation fails
In standardized configuration and change management workflows, every Request for Change (RFC) must contain an explicit rollback plan prior to Change Advisory Board (CAB) approval. This ensures engineers can quickly and safely revert the network device to its baseline configuration if post-implementation testing fails.

Step-by-Step Solution

1
Analyze the components present in the RFC submission
The submission includes rationale, risk assessment, sandbox test results, and maintenance window scheduling.
Identifying existing RFC components highlights what mandatory change management phase is missing.
2
Evaluate standard CompTIA and ITIL change management guidelines for RFC completion
A mandatory requirement for any infrastructure RFC is a fully defined, pre-tested rollback procedure with explicit triggers.
CAB approval requires assurance that the network can quickly revert to a baseline state without prolonged outage if the implementation encounters errors.

Key Concept

Standard Request for Change (RFC) Mandatory Components and Rollback Planning
Estimated Time:1m 15s
Question 1102Question

Match each out-of-band management operational requirement on the left with the most appropriate hardware management technology on the right.

Click a left item, then click its matching right item

Items

Emergency administrative CLI access to network routers during a complete failure of the primary terrestrial WAN connection
Direct BIOS-level graphical keyboard, video, and mouse control with virtual media mounting for an un-responsive bare-metal host
Remote execution of hard power-cycles on individual equipment outlets during system kernel lockups
Centralized aggregation of multiple asynchronous RS-232 serial console connections within a datacenter rack

Matches

Show answer & explanation

Answer

Emergency WAN access pairs with Out-of-Band Cellular Gateway; BIOS-level video and peripheral control pairs with Hardware IP-KVM Switch; Remote outlet power-cycling pairs with Switched Smart Power Distribution Unit (PDU); RS-232 serial console aggregation pairs with Terminal Server / Console Server.
Out-of-band technologies target distinct physical management planes: Cellular Gateways restore network pathways during landline outages; IP-KVM switches digitize hardware video and USB inputs prior to OS load; Switched PDUs control AC electrical outlets; and Terminal Servers centralize low-level serial CLI connections.

Step-by-Step Solution

1
Analyze the access requirement type for each operational scenario
Identify whether the task involves secondary WAN connectivity, graphical host/BIOS management, AC power control, or multi-device serial console consolidation.
Out-of-band mechanisms provide dedicated hardware channels depending on which layer of host or network access has failed.
2
Evaluate transport independence for primary circuit outages
Match cellular gateways to primary WAN link failures, as cellular networks supply a completely isolated path independent of wired ISP infrastructure.
In-band remote access relies on functional production routing, whereas out-of-band cellular pathways bypass standard WAN infrastructure.
3
Differentiate peripheral, serial CLI, and power interface technologies
Assign IP-KVM switches for graphical KVM frame capture, terminal servers for RS-232 CLI console consolidation, and switched PDUs for electrical outlet rebooting.
KVM devices handle video/peripherals, terminal servers handle text-based serial communications, and smart PDUs manage electrical current.

Key Concept

Remote Access and Out-of-Band Management Solutions
Question 1103Question

A network facility security officer is auditing physical defense mechanisms and environmental protection systems across an enterprise data center. Match each physical security or environmental vulnerability scenario on the left with the corresponding technical control on the right that provides appropriate mitigation.

Click a left item, then click its matching right item

Items

Risk of side-channel electromagnetic eavesdropping on sensitive wireless operations from outside the physical building boundary.
Risk of thermal shock, electrical shorting, and equipment destruction during fire suppression inside high-density server racks.
Risk of single-corded network switches experiencing unexpected power loss upon primary circuit branch failure.
Risk of undetected fluid accumulation beneath raised access flooring due to cooling pipe condensation or HVAC drain pan overflow.

Matches

Show answer & explanation

Answer

Electromagnetic eavesdropping matches with Faraday cage / RF shielding enclosure; thermal shock and equipment destruction from fire matches with Clean-agent gaseous fire suppression system; single-corded power failure matches with Rack-mounted Automatic Transfer Switch (ATS); and undetected sub-floor fluid accumulation matches with Conductive liquid-detection sensing cable array.
Each risk factor requires a targeted physical or environmental control: RF shielding blocks electromagnetic leakage; clean-agent gases put out electrical fires cleanly; automatic transfer switches grant dual-feed resilience to single-corded network hardware; and liquid-detection cables spot hidden sub-floor leaks.

Step-by-Step Solution

1
Analyze the electromagnetic emissions scenario.
Identified electromagnetic leakage outside building boundaries as an RF security threat (TEMPEST).
Faraday cages and metallic mesh/enclosures block electromagnetic signals and RF propagation.
2
Analyze fire protection requirements for energized electronics.
Determined that water sprinklers cause shorts and chemical powders damage equipment.
Clean-agent gaseous systems extinguish fires without liquid residue or electrical conductivity.
3
Evaluate power redundancy for single-corded hardware.
Selected a mechanism that allows legacy single-cord hardware to connect to dual utility feeds.
Rack-mounted ATS units draw from dual circuits and rapidly switch feeds if primary power fails.
4
Identify early warning systems for fluid leaks under raised floors.
Selected sub-floor moisture sensing arrays.
Conductive sensing cables placed under raised floors detect localized moisture immediately upon contact.

Key Concept

Physical and Environmental Controls Integration
Question 1104Question

Match each enterprise high-availability mechanism or protocol on the left with its correct operational description on the right.

Click a left item, then click its matching right item

Items

VRRP (Virtual Router Redundancy Protocol)
LACP (Link Aggregation Control Protocol)
CARP (Common Address Redundancy Protocol)
MPIO (Multipath I/O)

Matches

Show answer & explanation

Answer

VRRP pairs with the open-standard Layer 3 virtual IP default gateway failover protocol; LACP pairs with IEEE 802.1AX Layer 2 physical link aggregation; CARP pairs with shared IP host/firewall cluster redundancy; MPIO pairs with storage area network redundant physical pathing.
Each mechanism matches its exact function: VRRP provides standard open Layer 3 virtual default gateway redundancy; LACP aggregates Layer 2 Ethernet links into a logical interface; CARP handles shared IP addresses for host and firewall clusters; and MPIO provides redundant physical connectivity to storage array targets.

Step-by-Step Solution

1
Categorize each mechanism by its primary layer and operational scope in high-availability design.
VRRP and CARP function as Layer 3/cluster IP sharing mechanisms; LACP functions as a Layer 2 link bundler; MPIO functions at the storage adapter level.
Identifying the target OSI layer or system component simplifies matching terms with operational descriptions.
2
Distinguish between Layer 3 gateway failover protocols and host-level IP sharing mechanisms.
VRRP matches the open-standard virtual default gateway protocol, whereas CARP matches shared IP clustering across security appliances.
VRRP is specifically designed for gateway routers, while CARP is commonly used in BSD-based firewall cluster deployments.
3
Differentiate interface aggregation from storage path redundancy.
LACP matches IEEE link bundling, and MPIO matches multi-path storage controller connection management.
LACP handles network switch interfaces, while MPIO handles SAN and host interface adapter paths.

Key Concept

High Availability and Redundancy Protocols across Network Layers and Storage
Question 1105Question

An infrastructure manager is auditing the environmental and life-safety controls of a newly built core network distribution facility. The server room relies on a total-flooding clean-agent gaseous fire suppression system to protect high-density switches and fiber interconnects. During a simulated system test, concern is raised regarding structural room integrity and agent containment when the high-pressure gas discharges. Which HVAC and airflow control procedure must be implemented upon fire suppression activation to ensure maximum suppression effectiveness while preventing structural damage?

Show answer & explanation

Answer: Automatically actuate motorized dampers to seal HVAC supply and return ducts while opening dedicated pressure relief vents to manage displacement pressure.

Answer

Automatically actuate motorized dampers to seal HVAC supply and return ducts while opening dedicated pressure relief vents to manage displacement pressure.
Clean-agent gaseous fire suppression systems function by rapidly discharging gas into an enclosed space to achieve a specific chemical concentration. Automatically closing HVAC supply and return dampers prevents the agent from diluting or escaping into neighboring zones. Concurrently, opening dedicated pressure relief vents dissipates the sudden rise in room pressure during discharge, safeguarding the structural integrity of walls and ceiling enclosures.

Step-by-Step Solution

1
Analyze total-flooding clean-agent fire suppression operational requirements.
Gaseous agents (such as FM-200 or Novec 1230) require an enclosed room to maintain minimum design concentration for suppressing fire without oxygen depletion or equipment corrosion.
Air leakage through open ductwork dilutes the suppression agent.
2
Evaluate pressure dynamics during rapid gas discharge.
Discharging high-pressure gaseous agents within seconds creates a positive pressure wave that can damage drywalls, ceiling tiles, and doors if unvented.
Pressure relief vents calibrated for over-pressure release protect room integrity without permitting continuous ambient airflow.
3
Determine correct HVAC damper and vent control sequence.
Motorized fire/smoke dampers on main HVAC ducts must instantly close upon discharge signal, while dedicated pressure relief vents open temporarily to release peak pressure.
This sequence ensures structural safety while keeping suppression agent concentration contained.

Key Concept

Clean-Agent Fire Suppression and Environmental HVAC Interlocks
Estimated Time:2m 0s
Question 1106Question

An organization needs to grant remote workers secure access to corporate web applications from unmanaged personal devices. Corporate policy prohibits installing dedicated VPN software or administrative agents on these personal endpoints while requiring full encryption for all remote web traffic. Which protocol and transport layer configuration must be permitted on the perimeter firewall to support this clientless remote access design?

Show answer & explanation

Answer: SSL/TLS operating over TCP port 443

Answer

SSL/TLS operating over TCP port 443 is the correct choice because clientless SSL VPN portals leverage standard web browsers using HTTPS without requiring endpoint client installation.
Clientless SSL/TLS VPN portals permit users to establish encrypted remote sessions to internal web applications directly through a standard web browser. Because web browsers natively handle TLS encryption over TCP port 443, no client software installation is required on the user's personal device.

Step-by-Step Solution

1
Analyze the endpoint restriction requirements
Unmanaged personal endpoints cannot have third-party VPN client software installed.
The requirement specifies a clientless solution for remote web application access.
2
Identify the protocol compatible with clientless browser access
SSL/TLS (HTTPS) provides secure browser-based portal sessions.
Standard web browsers natively support SSL/TLS encryption without additional software.
3
Determine the transport protocol and port number
SSL/TLS for web traffic operates over TCP port 443.
Perimeter firewalls must allow TCP port 443 for HTTPS/SSL VPN portal traffic.

Key Concept

Clientless SSL/TLS Remote Access VPN
Question 1107Question

During a scheduled high-availability failover test, a network administrator powers down Core Router A, which participates in a Virtual Router Redundancy Protocol (VRRP) group with Core Router B. Core Router A has a physical IP address of 10.1.10.2, Core Router B has a physical IP address of 10.1.10.3, and the VRRP virtual IP (VIP) is 10.1.10.1. Immediately following the shutdown, several workstations lose connection to remote networks. Troubleshooting reveals that these workstations have their default gateway statically configured as 10.1.10.2. What is the root cause of the connectivity failure?

Show answer & explanation

Answer: The workstations were configured with the primary router's physical interface IP address rather than the VRRP virtual IP address.

Answer

The workstations were configured with the primary router's physical interface IP address rather than the VRRP virtual IP address.
For First Hop Redundancy Protocols (FHRP) such as VRRP or HSRP to function properly, host devices must use the Virtual IP (VIP) as their default gateway. When hosts are configured with the physical interface IP of a specific router, high-availability mechanism is bypassed. Powering down that physical router breaks outbound routing for those hosts because the standby router only intercepts traffic addressed to the VIP.

Step-by-Step Solution

1
Analyze host default gateway configuration in relation to the VRRP setup.
Workstations have their default gateway set to 10.1.10.2, which is the physical IP address of Core Router A.
First Hop Redundancy Protocols (FHRPs) like VRRP require hosts to point to a shared Virtual IP (10.1.10.1) so that traffic is dynamically handled by whichever router holds the master role.
2
Evaluate traffic behavior when Core Router A is powered down.
Packets sent directly to 10.1.10.2 are dropped because the underlying physical interface is offline.
Core Router B only responds to packets destined for the VRRP VIP (10.1.10.1) and the VRRP virtual MAC address, not to packets sent to Core Router A's physical IP address.
3
Determine the required resolution.
Update the workstation network configuration so the default gateway points to the VRRP VIP (10.1.10.1).
This enables seamless failover to Core Router B whenever Core Router A becomes unavailable.

Key Concept

FHRP Virtual Gateway IP Configuration
Estimated Time:1m 30s
Question 1108Question

A network security administrator is configuring centralized access control for managing enterprise switch and router CLI sessions. The security policy mandates two key capabilities: full packet payload encryption for all authorization traffic, and granular per-command authorization for administrative roles. Which of the following operational characteristics of TACACS+ satisfy these requirements when compared to RADIUS? (Select TWO.)

Select all that apply

Show answer & explanation

Answer: TACACS+ encrypts the entire body of the packet, whereas RADIUS encrypts only the password field.; TACACS+ separates authentication, authorization, and accounting into distinct functions, enabling individual command authorization.

Answer

TACACS+ encrypts the entire body of the packet, whereas RADIUS encrypts only the password field, and TACACS+ separates authentication, authorization, and accounting into distinct functions, enabling individual command authorization.
TACACS+ encrypts the entire packet payload following its standard header and decouples the AAA pillars into independent services. Decoupling authentication from authorization allows TACACS+ to perform real-time, per-command authorization checks for administrative CLI sessions.

Step-by-Step Solution

1
Evaluate the encryption boundary of each protocol.
TACACS+ encrypts the entire packet body following the header, whereas RADIUS encrypts only the user password field within Access-Request packets.
Protecting management commands and authorization responses across the network requires full payload encryption.
2
Evaluate how AAA functions are handled.
TACACS+ separates AAA into independent services, allowing the network access server to validate each command executed by an administrator against the AAA server.
RADIUS binds authentication and authorization together, which prevents granular per-command restriction during an established session.

Key Concept

AAA Framework protocol characteristics (TACACS+ vs RADIUS)
Question 1109Question

A network security administrator is transitioning a segment from a stateful firewall to a router utilizing stateless extended IPv4 Access Control Lists (ACLs). The administrator configures an inbound ACL on the interface connecting internal monitoring workstations (172.16.10.0/24172.16.10.0/24) to allow diagnostic queries to a remote Syslog server (10.20.30.5010.20.30.50) using UDP port 514514. After applying the ACL, technicians report that while outbound query packets are sent successfully, return diagnostic responses from the Syslog server are blocked. Which statement accurately explains why this communication failure occurs?

Show answer & explanation

Answer: Stateless ACLs inspect packets individually without maintaining session state tables, meaning return traffic from the Syslog server is blocked unless explicitly permitted by a return ACL rule.

Answer

Stateless ACLs inspect packets individually without maintaining session state tables, meaning return traffic from the Syslog server is blocked unless explicitly permitted by a return ACL rule.
Stateful firewalls maintain connection tracking tables that dynamically permit return traffic associated with established sessions. In contrast, stateless router ACLs evaluate every packet independently. When replacing a stateful firewall with stateless ACLs, an explicit rule must be created to allow response packets traveling in the reverse direction, as they will otherwise be blocked by the implicit deny statement.

Step-by-Step Solution

1
Differentiate between stateful firewall operation and stateless ACL processing.
Stateful firewalls track connection states (e.g., TCP handshakes, active UDP pseudo-sessions) in a state table, automatically allowing reverse return flows for permitted outbound connections. Stateless ACLs process every packet independently against configured rules without context of prior packets.
Understanding the fundamental operational difference between stateful firewalls and stateless router ACLs is essential for network access troubleshooting.
2
Analyze the directional packet flow for UDP communication.
Outbound packet flow: Source 172.16.10.0/24172.16.10.0/24 \rightarrow Destination 10.20.30.50:51410.20.30.50:514 (Permitted by inbound ACL).
Return packet flow: Source 10.20.30.50:51410.20.30.50:514 \rightarrow Destination 172.16.10.0/24172.16.10.0/24 (No explicit permit rule; hit by implicit deny).
Because UDP is connectionless and the ACL is stateless, return packets are evaluated independently against the interface rules.
3
Identify the required configuration modification to restore bi-directional communication.
An explicit return rule must be configured on the appropriate interface to permit traffic originating from 10.20.30.5010.20.30.50 with source UDP port 514514 back to the 172.16.10.0/24172.16.10.0/24 subnet.
Without a state table or an explicit return permit rule, return packets encounter the implicit deny all statement at the end of the stateless ACL.

Key Concept

Stateful Firewalls vs. Stateless Access Control Lists (ACLs)
Estimated Time:2m 0s
Question 1110Question

An organization deploys a client-based IPsec VPN solution for remote system administrators. During initial deployment testing, users connecting from home networks behind Network Address Translation (NAT) devices experience immediate packet drops when using IPsec with Authentication Header (AH). However, changing the VPN configuration to use Encapsulating Security Payload (ESP) resolves the issue and allows full connectivity. Which of the following best explains why the AH configuration failed in this scenario?

Show answer & explanation

Answer: Authentication Header includes the outer IP header in its Integrity Check Value calculation, causing cryptographic validation failure when NAT modifies the IP address.

Answer

Authentication Header (AH) includes the outer IP header in its ICV integrity calculation, causing packet drops when a NAT router modifies the source/destination IP address.
The correct answer identifies that IPsec Authentication Header (AH) includes the outer IP header in its integrity hash calculation. When a NAT router translates the IP address, the header modification invalidates the cryptographic checksum, causing the recipient IPsec endpoint to drop the packet. Switching to Encapsulating Security Payload (ESP) avoids this because ESP does not include the outer IP header in its ICV.

Step-by-Step Solution

1
Analyze the functional difference between IPsec Authentication Header (AH) and Encapsulating Security Payload (ESP).
AH provides integrity and authentication for the entire IP packet (including outer IP headers), whereas ESP provides confidentiality and integrity primarily for the payload.
Understanding which packet header fields are covered by cryptographic integrity checks is necessary to evaluate NAT compatibility.
2
Evaluate the effect of Network Address Translation (NAT) on IP headers.
NAT alters IP header fields by modifying the source or destination IP addresses.
Routers performing NAT must mutate packet headers to route traffic between private and public IP address spaces.
3
Correlate NAT modifications with AH integrity verification.
Because AH calculates its Integrity Check Value (ICV) over immutable and mutable IP header fields, changing the IP address breaks the ICV validation at the receiving gateway.
The receiver recalculates the ICV upon arrival; since NAT changed the header, the calculated hash does not match the transmitted hash, leading to dropped packets unless ESP with NAT-Traversal (NAT-T) is utilized.

Key Concept

IPsec AH vs ESP NAT Incompatibility
Question 1111Question

A network security engineer is performing a physical security audit of a high-density transaction processing facility. The audit reveals three distinct vulnerabilities: confidential packet data is leaking via unintended electromagnetic emissions from server chassis, unauthorized employees are frequently tailgating through access doors during shift changes, and intruders could potentially bypass door access controls by crawling through the hollow space above the suspended drop ceiling. Which of the following combinations of physical security measures directly mitigates all three identified vulnerabilities?

Show answer & explanation

Answer: Erecting slab-to-slab barrier walls extending from the true floor to the structural ceiling, deploying an anti-tailgating man-trap with interlocking doors, and housing sensitive server clusters within a Faraday enclosure.

Answer

Erecting slab-to-slab barrier walls extending from the true floor to the structural ceiling, deploying an anti-tailgating man-trap with interlocking doors, and housing sensitive server clusters within a Faraday enclosure.
The solution prescribing slab-to-slab walls, an anti-tailgating man-trap, and a Faraday enclosure directly mitigates all three security vulnerabilities. Slab-to-slab walls extend past suspended drop ceilings up to the solid structural deck, preventing intruders from climbing over locked access doors. A man-trap uses interlocking doors to physically enforce one-person entry, eliminating tailgating during high-traffic shift changes. A Faraday enclosure blocks electromagnetic emissions from radiating outside the server room, neutralizing eavesdropping risks.

Step-by-Step Solution

1
Analyze Vulnerability 1 (Electromagnetic Data Leakage)
Identified the need for electromagnetic shielding (Faraday enclosure or TEMPEST shielding) to block unintended RF emissions from active computing hardware.
Unshielded high-speed data buses and network hardware radiate electromagnetic signals that can be captured externally by specialized eavesdropping gear.
2
Analyze Vulnerability 2 (Tailgating during shift changes)
Identified the requirement for a man-trap (security vestibule) equipped with presence sensors and interlocking doors.
Standard single-door access points allow unauthorized individuals to follow authorized personnel during a door unlock cycle, whereas man-traps physically restrict access to one validated person at a time.
3
Analyze Vulnerability 3 (Drop-ceiling interstitial intrusion)
Identified the need for slab-to-slab physical partition walls extending from the structural subfloor to the upper concrete ceiling slab.
Suspended drop ceilings leave open plenum space above interior walls, allowing intruders to climb over locked doors unless true structural barrier walls are installed.
4
Synthesize Physical Safeguards
Selected the combination featuring slab-to-slab walls, anti-tailgating man-traps, and Faraday enclosures.
This specific combination provides target-specific physical and environmental countermeasures for all three audited vulnerabilities.

Key Concept

Physical Access Controls, Perimeter Security Barriers, and RF/EM Shielding
Estimated Time:2m 0s
Question 1112Question

During a security assessment of an enterprise LAN segment, a network technician observes that host traffic intended for the default gateway at IP address 192.168.10.1192.168.10.1 is being redirected through an unauthorized laptop at 192.168.10.88192.168.10.88. Packet inspection reveals that host machines are continuously receiving unsolicited frame updates mapping 192.168.10.1192.168.10.1 to MAC address `00:11:22:AA:BB:CC`, which belongs to the laptop. Which network attack type is taking place, and what is its primary vector?

Show answer & explanation

Answer: ARP poisoning, which exploits the lack of authentication in ARP responses to update host ARP caches with forged IP-to-MAC address mappings.

Answer

ARP poisoning, which exploits the lack of authentication in ARP responses to update host ARP caches with forged IP-to-MAC address mappings.
The correct answer identifies ARP poisoning. ARP is a stateless Layer 2 protocol that maps IPv4 addresses to MAC addresses. Because ARP lacks authentication, hosts accept unsolicited ARP responses, allowing an attacker to broadcast forged ARP replies that associate their own MAC address with the IP address of the legitimate default gateway.

Step-by-Step Solution

1
Analyze the observed network symptom
Unsolicited frames map default gateway IP 192.168.10.1192.168.10.1 to an unauthorized host's MAC address `00:11:22:AA:BB:CC`.
This indicates targeted Layer 2 address cache tampering rather than domain name resolution or volumetric flooding.
2
Identify the protocol and vulnerability involved
Address Resolution Protocol (ARP) is inherently stateless and unauthenticated, accepting gratuitous ARP replies without validation.
Because hosts accept these responses, their local ARP tables are updated with spoofed bindings.
3
Determine the specific attack classification
The attack is ARP poisoning (or ARP spoofing), facilitating an On-Path (Man-in-the-Middle) scenario.
Traffic destined for external networks passes to the attacker's MAC address first before being forwarded.

Key Concept

ARP Poisoning and Spoofing Vectors
Question 1113Question

A network manager is reviewing a proposed upgrade plan for a corporate wireless network. The organization requires per-user authentication tied to Active Directory so that individual access can be revoked immediately upon employee termination. A technician suggests deploying WPA3-Personal with a complex 32-character passphrase to avoid configuring an 802.1X RADIUS infrastructure. Which of the following best explains why this recommendation fails to meet the organization's security requirements?

Show answer & explanation

Answer: Pre-shared key deployment uses a single shared secret, preventing unique user identification and requiring passphrase rotation across all client devices when offboarding a single employee.

Answer

Pre-shared key deployment uses a single shared secret, preventing unique user identification and requiring passphrase rotation across all client devices when offboarding a single employee.
WPA3-Personal uses Simultaneous Authentication of Equals (SAE) with a shared password. While SAE provides forward secrecy and protection against offline dictionary attacks, it still relies on a single shared secret across devices. Consequently, it cannot authenticate individual user accounts against Active Directory or allow an administrator to revoke access for a departing employee without changing the passphrase on every device across the enterprise. Achieving per-user authentication requires WPA3-Enterprise with 802.1X/RADIUS.

Step-by-Step Solution

1
Identify the organization's core access control requirements.
The requirement specifies per-user authentication tied to Active Directory with selective revocation capability.
Enterprise access control demands individual accountability via 802.1X authentication.
2
Evaluate the mechanism of WPA3-Personal.
WPA3-Personal uses Simultaneous Authentication of Equals (SAE) based on a common Pre-Shared Key (PSK).
Because everyone uses the same passphrase, individual users cannot be identified or individually disabled at the RADIUS level.
3
Compare WPA3-Personal against WPA3-Enterprise.
WPA3-Enterprise integrates with an 802.1X RADIUS server and Active Directory, meeting all requirements, whereas WPA3-Personal does not.
WPA3-Personal cannot satisfy requirements for individual user auditability or single-user credential revocation.

Key Concept

WPA3-Personal vs. WPA3-Enterprise Authentication Requirements
Question 1114Question

A network administrator is overseeing the construction of a new network closet situated directly adjacent to a light manufacturing area that produces significant airborne dust and debris. Which environmental control should be configured for the network closet's HVAC system to prevent dust from entering the room when personnel open the entry door?

Show answer & explanation

Answer: Maintain positive air pressure inside the network closet relative to adjacent spaces.

Answer

Maintaining positive air pressure inside the network closet relative to surrounding areas ensures air flows outward when doors open, preventing airborne dust and debris from entering.
Maintaining positive air pressure inside a network closet creates a higher atmospheric pressure within the room compared to adjacent spaces. When the door to the closet is opened, air naturally flows outward into the hallway or manufacturing area, effectively creating an air barrier that prevents airborne dust and debris from entering sensitive network equipment areas.

Step-by-Step Solution

1
Analyze the environmental threat described in the scenario.
The primary threat is airborne dust and particulate intrusion from the adjacent manufacturing floor whenever the door opens.
Dust accumulation on network devices can impair cooling fans, cause overheating, and lead to component failure.
2
Evaluate HVAC airflow pressure differential options.
Positive air pressure keeps internal pressure higher than external pressure, forcing clean air outward through doorways and gaps.
Negative pressure would draw unfiltered air and dust inward into the equipment space.
3
Select the appropriate environmental control mechanism.
Configuring HVAC systems for positive air pressure mitigates particulate contamination while preserving proper equipment operating conditions.
Positive pressure directly addresses the risk without introducing unwanted moisture or liquid hazards.

Key Concept

HVAC Air Pressure Differentials and Environmental Contamination Control
Question 1115Question

A network technician is configuring remote administrative access on a newly installed network switch. Which protocol should be enabled to ensure that command-line interface (CLI) sessions and authentication credentials are encrypted across the network?

Show answer & explanation

Answer: SSH

Answer

SSH should be enabled because it provides encrypted shell sessions and secure password transmission for device management.
SSH (Secure Shell) operates on TCP port 22 and uses cryptographic methods to encrypt all management traffic, preventing unauthorized eavesdropping and credential theft during remote administration sessions.

Step-by-Step Solution

1
Identify the primary requirement for device hardening
The requirement is to secure remote interactive CLI management access using encryption.
Unencrypted administrative protocols allow attackers to capture login credentials using network sniffing tools.
2
Evaluate protocol security capabilities
SSH provides strong encryption for administrative sessions over TCP port 22.
Replacing legacy cleartext protocols such as Telnet with SSH is a baseline network device hardening best practice.

Key Concept

Management Plane Hardening via Encrypted Protocols
Estimated Time:45s
Question 1116Question

A security analyst is auditing a wireless network transition from WPA2-Personal to WPA3-Personal across several satellite offices. The goal is to support modern WPA3 security enhancements while maintaining temporary backward compatibility for legacy WPA2 devices. Which TWO of the following configuration settings or protocols are required to properly achieve this deployment? (Select TWO)

Select all that apply

Show answer & explanation

Answer: Enable WPA3 Transition Mode to allow legacy WPA2-PSK clients and WPA3 SAE clients to connect to the same SSID.; Set Protected Management Frames (PMF) to required or capable to safeguard management traffic against spoofing.

Answer

The correct requirements are enabling WPA3 Transition Mode for dual-protocol support and configuring Protected Management Frames (PMF) to secure wireless management frames.
Deploying WPA3-Personal in an environment with legacy clients requires WPA3 Transition Mode so that WPA2-PSK clients and WPA3-SAE clients can connect to the same wireless network. Additionally, Protected Management Frames (PMF / IEEE 802.11w) must be enabled because PMF is a required security baseline under the WPA3 standard to stop frame spoofing attacks.

Step-by-Step Solution

1
Determine the mechanism for supporting legacy WPA2-Personal devices alongside WPA3-Personal devices.
Identify WPA3 Transition Mode as the standard feature allowing WPA2-PSK and WPA3-SAE clients on a single SSID.
Transition mode provides a seamless migration path without requiring separate SSIDs for legacy and modern clients.
2
Identify mandatory WPA3 security controls for frame integrity.
Select Protected Management Frames (PMF / IEEE 802.11w).
WPA3 standards mandate PMF to prevent common wireless attacks such as rogue deauthentication frame injection.
3
Evaluate authentication and authorization protocols in the wrong options.
Exclude RADIUS and TACACS+ options for this Personal (PSK/SAE) deployment scenario.
WPA3-Personal does not rely on centralized 802.1X RADIUS servers or TACACS+ administration systems.

Key Concept

WPA3-Personal (SAE), Transition Mode, and Mandatory PMF
Estimated Time:1m 30s
Question 1117Question

A network security analyst is investigating logs from multiple enterprise security incidents across the network infrastructure. Match each observed attack symptom and mechanism to its corresponding network attack vector.

Click a left item, then click its matching right item

Items

An unauthorized frame with nested 802.1Q headers is sent over an access port configured on the switch's native VLAN, causing the outer tag to be stripped at the first switch and the frame forwarded to a restricted VLAN.
Small UDP request packets with spoofed target source IP addresses are transmitted to open network time infrastructure using commands like monlist, resulting in massive response payloads targeting the victim.
An adversary on the local network path intercepts initial unencrypted HTTP requests, dynamically replacing secure HTTPS links with plain HTTP equivalents to intercept credentials in cleartext.
Spoofed 802.11 management frames containing disassociation control codes are broadcast to force connected wireless clients off an authorized access point.

Matches

Show answer & explanation

Answer

The correct pairings are: 1) Nested 802.1Q headers on a native VLAN corresponds to VLAN Hopping (Double Tagging); 2) Spoofed UDP requests using monlist commands correspond to an NTP Amplification Attack; 3) Intercepting HTTP/HTTPS redirects to downgrade connection security corresponds to SSL/TLS Stripping; 4) Spoofed 802.11 disassociation management frames correspond to a Wireless Deauthentication Attack.
Each attack vector maps directly to its underlying technical exploit method: nested 802.1Q headers exploit switch native VLAN parsing (VLAN Hopping), monlist query responses reflect high-volume traffic (NTP Amplification), modifying HTTP location headers prevents encryption (SSL Stripping), and spoofing 802.11 management frames forces wireless disassociation (Deauthentication).

Step-by-Step Solution

1
Analyze Incident 1 (Nested 802.1Q headers on native VLAN)
Identify that two 802.1Q tags allow traffic to jump from the native VLAN across trunk lines without passing through a router.
This structural behavior specifically defines double-tagging VLAN hopping.
2
Analyze Incident 2 (Spoofed UDP requests with monlist to time servers)
Recognize that monlist returns a large list of historical IP addresses over UDP (port 123) with a spoofed victim IP address.
This is a classic reflection/amplification attack targeting Network Time Protocol (NTP) services.
3
Analyze Incident 3 (Interception and modification of HTTPS links to plain HTTP)
Determine that modifying web headers to prevent TLS handshake upgrades strips transport layer security.
This technique is known as SSL/TLS stripping or protocol downgrade attack.
4
Analyze Incident 4 (Spoofed 802.11 management disassociation frames)
Determine that unauthenticated wireless management frames cause clients to disconnect.
This describes a wireless deauthentication attack aimed at denial of service or forcing clients onto a rogue access point.

Key Concept

Common Network Attack Vectors and Mechanisms
Question 1118Question

Match each wireless network symptom or issue to its corresponding root cause or scenario description.

Click a left item, then click its matching right item

Items

Captive Portal Redirection Failure
Signal Attenuation due to Absorption
Co-Channel Interference
Multipath Distortion

Matches

Show answer & explanation

Answer

Captive Portal Redirection Failure matches the web browser credential prompt issue; Signal Attenuation due to Absorption matches RSSI drop behind concrete walls; Co-Channel Interference matches multiple APs competing on Channel 6; Multipath Distortion matches RF signals reflecting off metal surfaces causing phase cancellation.
Each wireless symptom maps directly to its underlying physical or logical cause based on 802.11 standards and RF behavior.

Step-by-Step Solution

1
Analyze the scenario regarding web browser prompts and IP connectivity.
Identify that failure to open an authentication splash page after receiving an IP address on a public network is characteristic of a captive portal redirection failure.
Captive portals intercept web traffic to authenticate users before granting external network access.
2
Analyze the physical barrier symptom involving concrete walls and signal degradation.
Identify that dense materials absorbing RF energy cause signal attenuation.
Solid construction materials such as concrete absorb radio signals, reducing RSSI.
3
Evaluate the channel configuration symptom involving multiple APs on Channel 6.
Determine that APs sharing the same channel in the same physical space cause co-channel interference.
802.11 devices use CSMA/CA, so sharing a channel forces devices to wait for airtime.
4
Evaluate the signal reflection symptom in the warehouse environment.
Identify that RF signals reflecting off metal and arriving out of phase cause multipath distortion.
Bouncing signals create phase differences that cancel out or corrupt incoming RF frames.

Key Concept

Wireless Connectivity and Signal Troubleshooting
Question 1119Question

A network technician needs to establish direct administrative access to a network switch whose network interfaces are completely unreachable due to a network link failure. Which connection method provides dedicated out-of-band management to the command-line interface without relying on active network IP connectivity?

Show answer & explanation

Answer: Connecting a terminal emulator on a laptop directly to the switch console port using a serial console cable

Answer

Connecting a terminal emulator on a laptop directly to the switch console port using a serial console cable
Connecting directly to the physical console port using a serial console cable provides true out-of-band management. This connection operates independently of the switch's network interfaces, IP configuration, or network link state, allowing administrative CLI access even during a major network outage.

Step-by-Step Solution

1
Identify the management requirement
The network interfaces are unreachable, meaning in-band network protocols cannot function.
In-band protocols depend on operational IP interfaces, network links, and routing infrastructure.
2
Evaluate management channels
Direct console port connection provides out-of-band (OOB) management capabilities.
The serial console port connects directly to the device's control plane hardware independently of network interface status.

Key Concept

Out-of-Band Management vs. In-Band Management
Question 1120Question

A network security engineer is establishing a hardened configuration baseline for a core switch cluster to mitigate internal eavesdropping and unauthorized access risks. A security audit highlights that device telemetry monitoring traffic exposes system OIDs and interface statistics in cleartext across the network, while unassigned access ports and default trunking settings present physical and logical intrusion risks. Which set of device hardening configurations correctly addresses all of these identified vulnerabilities according to industry best practices?

Show answer & explanation

Answer: Implement SNMPv3 with the authPriv security level specifying SHA for authentication and AES for encryption, disable all unassigned physical switch ports while assigning them to an unused blackhole VLAN, and change the 802.1Q native VLAN from default VLAN 1 to an unused VLAN ID.

Answer

Implement SNMPv3 with the authPriv security level specifying SHA for authentication and AES for encryption, disable all unassigned physical switch ports while assigning them to an unused blackhole VLAN, and change the 802.1Q native VLAN from default VLAN 1 to an unused VLAN ID.
The correct response comprehensively addresses all management plane and Layer 2 hardening requirements. Configuring SNMPv3 with authPriv guarantees both origin authentication and packet confidentiality using SHA and AES encryption, preventing cleartext telemetry interception. Administratively disabling unused ports and assigning them to an isolated blackhole VLAN prevents unauthorized local physical access. Finally, changing the 802.1Q native VLAN from default VLAN 1 to an unused, dedicated VLAN ID prevents VLAN hopping exploits.

Step-by-Step Solution

1
Evaluate management protocol security levels for SNMP monitoring telemetry.
SNMPv3 using the authPriv security level is required to provide both cryptographic authentication (SHA) and privacy via payload encryption (AES).
SNMPv1/v2c transmit community strings in cleartext, and SNMPv3 authNoPriv only authenticates without encrypting the monitored data payload.
2
Assess physical switch port hardening for unassigned access ports.
Unused switch ports must be administratively shut down (`shutdown`) and assigned to a non-routed, inactive VLAN (blackhole VLAN).
Leaving unused ports active in default VLAN 1 allows unauthorized devices to gain immediate Layer 2 access upon physical connection.
3
Analyze trunk line security and native VLAN isolation best practices.
The 802.1Q native VLAN must be changed from default VLAN 1 to an unused VLAN ID that carries no active user or management traffic.
Default VLAN 1 is a well-known target for VLAN hopping attacks (such as double-tagging), and isolating untagged trunk frames prevents unauthorized Layer 2 traversal.

Key Concept

Management Plane and Layer 2 Switch Hardening Best Practices
Estimated Time:2m 0s
PreviousPage 56 / 112Next
All practice questions — CompTIA Network+ | Examkin