All practice questions

2237 questions

Question 1181Question

A network engineer is investigating intermittent packet loss and TCP session resets across a newly deployed hybrid cloud IPsec VPN tunnel connecting a corporate data center to an AWS VPC. After executing packet captures, the engineer confirms the hypothesis: transit packets exceeding the path MTU are being dropped because the DF (Don't Fragment) bit is set and ICMP Type 3 Code 4 messages are blocked by an upstream firewall. According to the CompTIA troubleshooting methodology, which TWO of the following actions should the engineer perform NEXT?

Select all that apply

Show answer & explanation

Answer: Develop a structured implementation strategy to adjust MSS clamping and allow required ICMP control traffic.; Analyze the potential operational impacts and adverse effects of applying interface MTU modifications on active production sessions.

Answer

The technician should develop a structured implementation strategy to adjust MSS clamping and analyze the potential operational impacts of the changes on production sessions.
In the CompTIA troubleshooting methodology, once a theory of probable cause has been tested and confirmed (Step 3), the network professional must proceed to Step 4: Establish a plan of action to resolve the problem and identify potential effects. Developing a structured implementation plan (adjusting MSS clamping and ICMP rules) and evaluating potential operational side effects on live production sessions are both essential components of this specific step.

Step-by-Step Solution

1
Determine current phase in CompTIA methodology
The engineer confirmed the theory through diagnostic testing (Step 3: Test the theory to determine cause).
Identifying the current position in the sequence determines which step comes next.
2
Identify the immediate next phase in the methodology
The next phase is Step 4: Establish a plan of action to resolve the problem and identify potential effects.
CompTIA guidelines dictate that once cause is proven, remediation planning and risk assessment must occur before implementation or verification.
3
Evaluate candidate actions against Step 4 requirements
Formulating the deployment plan (MSS clamping adjustments) and assessing potential operational impacts directly fulfill Step 4.
Planning actions without considering side effects or skipping to final verification/documentation violates official procedural order.

Key Concept

CompTIA Troubleshooting Methodology Step Progression (Test Theory → Plan of Action)
Question 1182Question

A network technician is investigating a report that a client computer cannot access internal corporate resources using hostnames. Place the following troubleshooting steps in the correct logical sequence to systematically isolate and resolve the name resolution issue, from basic stack verification to cache remediation.

Drag items to arrange them in the correct order

Show answer & explanation

Answer

The correct logical sequence for troubleshooting DNS name resolution issues is: 1) Ping loopback address (127.0.0.1), 2) Run ipconfig /all to check DNS server configurations, 3) Ping primary DNS server IP, 4) Execute nslookup targeting hostname, 5) Run ipconfig /flushdns.
The standard network troubleshooting methodology progresses from local hardware/stack verification up to higher-level service queries and cache remediation. Verifying the loopback adapter establishes local TCP/IP operational status. Checking network configuration via `ipconfig /all` identifies target DNS server IP addresses. Pinging the DNS server tests Layer 3 reachability. Using `nslookup` isolates Application layer (DNS port 53) functionality. Finally, clearing the client resolver cache with `ipconfig /flushdns` resolves stale mapping issues on the workstation.

Step-by-Step Solution

1
Verify local TCP/IP stack operation.
Pinging 127.0.0.1127.0.0.1 confirms local protocol stack integrity.
Eliminates local OS networking software corruption before evaluating network settings.
2
Inspect client network parameters.
`ipconfig /all` displays client IP settings and primary/secondary DNS server IP addresses.
Determines whether the client is configured with correct DNS server IP addresses.
3
Verify network path to the DNS server.
Pinging the DNS server IP verifies ICMP connectivity and default gateway routing.
Ensures physical link and routing to the DNS server are operational.
4
Test DNS application protocol.
`nslookup` directly queries the DNS server over port 53 to check if records are properly retrieved.
Isolates application-layer DNS server functionality from local OS caching behavior.
5
Remediate local resolution cache.
`ipconfig /flushdns` purges stale or incorrect records stored in the client cache.
Clears bad cached entries after confirming the authoritative DNS server holds correct records.

Key Concept

Systematic OSI Bottom-Up / Layered Network Troubleshooting for Name Resolution
Estimated Time:1m 30s
Question 1183Question

A network administrator is auditing the organization's wireless security baseline. Match each wireless security standard on the left with its corresponding primary encryption protocol or cryptographic suite on the right.

Click a left item, then click its matching right item

Items

WEP (Wired Equivalent Privacy)
WPA (Wi-Fi Protected Access)
WPA2 (Wi-Fi Protected Access 2)
WPA3 (Wi-Fi Protected Access 3)

Matches

Show answer & explanation

Answer

WEP matches RC4 with a 24-bit IV; WPA matches TKIP with RC4; WPA2 matches CCMP with AES; WPA3 matches GCMP-128 with AES and SAE.
Each wireless security generation relies on a distinct cryptographic suite: legacy WEP uses RC4 with a 24-bit IV, WPA uses TKIP wrapper around RC4, WPA2 standardizes AES-CCMP, and WPA3 mandates AES-GCMP along with SAE authentication.

Step-by-Step Solution

1
Analyze WEP requirements
WEP relies on RC4 with a short 24-bit IV.
This is the original 802.11 security mechanism.
2
Analyze WPA requirements
WPA introduces TKIP to encapsulate RC4 and add Michael MIC.
It served as an interim fix for WEP devices.
3
Analyze WPA2 requirements
WPA2 mandates CCMP utilizing AES.
Provides robust confidentiality and integrity under 802.11i.
4
Analyze WPA3 requirements
WPA3 utilizes GCMP-128/256 with SAE.
Represents the modern Wi-Fi security standard replacing PSK and upgrading ciphers.

Key Concept

Wireless Security Standards and Encryption Protocols
Estimated Time:1m 30s
Question 1184Question

A network administrator is troubleshooting persistent wireless connectivity dropouts and high frame retransmission rates in a newly renovated office building. Diagnostic scans reveal that 5 GHz5\text{ GHz} access points are operating on 80 MHz80\text{ MHz} channel widths spanning Dynamic Frequency Selection (DFS) channels, while office partition walls contain foil-backed insulation and heavy metal mesh. Client devices experience sudden 25 dBm25\text{ dBm} signal drops when stepping behind partitions, alongside temporary disconnections whenever access point logs record radar detection events. Which of the following root causes are contributing to these wireless performance issues? (Select TWO.)

Select all that apply

Show answer & explanation

Answer: Severe signal attenuation and absorption caused by metallic building materials within office partitions; Service interruptions caused by mandatory channel changes when access points detect radar on DFS frequencies

Answer

The primary root causes are severe RF signal attenuation caused by metallic wall materials and mandatory channel switches triggered by DFS radar detection events.
High-density metallic obstacles (foil insulation and metal mesh) heavily absorb and reflect high-frequency 5 GHz5\text{ GHz} signals, causing sharp drop-offs in signal strength. Simultaneously, 5 GHz5\text{ GHz} access points configured on Dynamic Frequency Selection (DFS) channels are legally mandated to clear the channel immediately upon detecting radar signals, causing temporary disconnections while the AP shifts to an alternate channel.

Step-by-Step Solution

1
Analyze physical obstacle impact on RF propagation
Identify that metal mesh and foil-backed insulation act as electromagnetic shields, causing dramatic signal attenuation (25 dBm25\text{ dBm} drops) and coverage dead zones.
Dense metallic materials reflect and absorb RF energy at high frequencies such as 5 GHz5\text{ GHz} much more severely than standard drywall.
2
Analyze spectrum usage and log events
Correlate access point radar detection logs with client disconnections on DFS channels.
Regulatory requirements force 802.11 devices operating on DFS spectrum to immediately mute transmissions and switch channels upon detecting radar, causing temporary client dropouts.
3
Rule out non-applicable frequency and protocol misconfigurations
Confirm 2.4 GHz channel overlap and DHCP APIPA fallbacks do not match the 5 GHz5\text{ GHz} scenario and diagnostic logs.
The system operates on 5 GHz5\text{ GHz} DFS channels with established Layer 2/3 connections prior to physical attenuation or channel vacation.

Key Concept

Wireless Signal Attenuation & Dynamic Frequency Selection (DFS) Radar Clearing
Estimated Time:2m 0s
Question 1185Question

A network administrator is troubleshooting an issue where remote access VPN users cannot resolve names for specific corporate subdomains. Standard DNS queries for small records complete successfully, but queries that return large payload responses fail. The technician executes the following command on an affected client workstation:

$ nslookup -vc large-record.corp.internal 10.100.1.2
Server: dns1.corp.internal
Address: 10.100.1.2

DNS request timed out.
timeout was 2 seconds.
*** Request to dns1.corp.internal timed out

Which of the following is the most likely root cause of this failure?

Show answer & explanation

Answer: An intermediate firewall along the VPN path is blocking TCP port 53 traffic required for truncated DNS responses.

Answer

An intermediate firewall along the VPN path is blocking TCP port 53 traffic required for truncated DNS responses.
DNS primarily operates over UDP port 53 for standard short queries. However, when a response payload exceeds the maximum UDP packet size, or when using command flags like `-vc` in `nslookup` (which forces Virtual Circuit / TCP mode), DNS relies on TCP port 53. If an intermediate firewall permits UDP port 53 but blocks TCP port 53, normal small queries succeed while large responses or forced TCP queries time out.

Step-by-Step Solution

1
Analyze the nslookup command syntax and flags.
The `-vc` flag explicitly forces nslookup to establish a Virtual Circuit connection using TCP instead of UDP.
Understanding tool flags isolates whether the failure is specific to TCP transport.
2
Evaluate the command output error message.
The output indicates `DNS request timed out`, meaning the client sent a TCP segment to 10.100.1.2:53 but received no response (SYN dropped or blocked).
Connection timeouts on specific protocol transports typically point to network filtering or firewall rules.
3
Correlate TCP behavior with large DNS responses.
DNS queries that exceed the UDP payload size limit set the Truncation (TC) flag, prompting clients to retry over TCP port 53.
If TCP port 53 is blocked by a network firewall, any large DNS response or forced TCP query (-vc) will fail with a timeout.

Key Concept

DNS Transport Protocols (UDP vs TCP Port 53)
Estimated Time:2m 0s
Question 1186Question

A tier-2 Security Operations Center (SOC) analyst is analyzing threat intelligence logs and network packet captures from a recent enterprise security incident. Match each observed technical attack metric or anomalous protocol behavior to its corresponding network attack classification.

Click a left item, then click its matching right item

Items

Rapid injection of frames containing randomized source physical addresses to saturate switch memory tables and force traffic onto all active ports.
Transmission of continuous TCP connection requests with spoofed return addresses to saturate embryonic socket queues without sending final ACK packets.
Emission of high-power electromagnetic noise across specific wireless spectrum channels to lower the signal-to-noise ratio and drop client connections.
Operation of an unauthorized wireless base station configured with a duplicated Service Set Identifier (SSID) to intercept client traffic.

Matches

Show answer & explanation

Answer

The correct pairings match MAC Address Flooding with saturating switch memory via randomized source addresses; TCP SYN Flood with filling embryonic connection queues using unacknowledged SYN packets; RF Jamming with emitting high-power noise to lower wireless SNR; and Evil Twin Access Point with deploying an unauthorized base station using a duplicated SSID.
Each attack vector targets specific network layers and operational characteristics: MAC address flooding targets Layer 2 switch CAM tables by exhausting memory entries; TCP SYN flooding targets Layer 4 TCP connection state queues by leaving handshakes incomplete; RF jamming targets Layer 1 physical wireless channels by suppressing signal-to-noise ratios; and Evil Twin attacks target Layer 2 802.11 association procedures by impersonating valid network SSIDs.

Step-by-Step Solution

1
Analyze the Layer 2 switch memory table anomaly.
Identify that flooding randomized source MAC addresses exhausts the Content Addressable Memory (CAM) table, defining MAC Address Flooding.
Switches store learned MAC addresses in CAM tables; when full, the switch falls back to fail-open mode, broadcasting unicast frames to all ports.
2
Analyze the Layer 4 transport layer connection queue saturation.
Identify that continuous unacknowledged SYN packets fill embryonic connection queues, defining a TCP SYN Flood.
The TCP three-way handshake requires a final ACK to complete connection state; withholding ACKs leaves sockets stuck in the SYN_RECEIVED state until resources are exhausted.
3
Analyze the physical wireless spectrum interference anomaly.
Identify that emitting high-power radio noise to lower signal-to-noise ratio corresponds to Radio Frequency (RF) Jamming.
Wireless communication relies on an acceptable signal-to-noise ratio (SNR); high-power interference overwhelms legitimate radio signals, causing denial of service.
4
Analyze the rogue wireless access point impersonation vector.
Identify that deploying a rogue base station with a duplicate corporate SSID corresponds to an Evil Twin attack.
Wireless client devices automatically probe and connect to known SSIDs offering strong signal levels, enabling man-in-the-middle interception.

Key Concept

Identifying Network Attack Types and Operational Vectors across OSI Layers
Question 1187Question

A network technician is preparing a newly unboxed switch for deployment on a corporate network. Place the following administrative device hardening steps in the correct chronological order from first to last.

Drag items to arrange them in the correct order

Show answer & explanation

Answer

The correct sequence begins with establishing an out-of-band serial console connection, followed by updating default administrative passwords, configuring SSH while disabling Telnet, and concluding with applying management Access Control Lists and shutting down unused ports.
Device hardening follows a logical sequence: first connecting directly via an out-of-band console cable, changing default passwords to secure administrative access, enabling encrypted SSH management while turning off unencrypted Telnet, and finally restricting network access with management ACLs and shutting down unused physical ports.

Step-by-Step Solution

1
Establish out-of-band console access
Direct command-line interface access is established locally.
Initial setup must be performed out-of-band before remote access services or IP network interfaces exist.
2
Change default administrative credentials
Factory default usernames and passwords are removed and secured.
Default account credentials leave the switch vulnerable to unauthorized login if remote management is enabled.
3
Configure SSH and disable Telnet
Remote administrative communications are encrypted and unencrypted Telnet access is disabled.
Secure remote access requires crypto key generation and active user credentials before remote login can occur.
4
Apply management ACLs and disable unused ports
Unused physical ports are disabled and remote management is restricted to authorized subnets.
Restricting IP management access and turning off unused ports completes the baseline hardening phase.

Key Concept

Chronological Baseline Hardening Sequence for Network Switches
Estimated Time:1m 0s
Question 1188Question

A desktop technician is troubleshooting a client system that cannot connect to an internal web application hosted at `payroll.internal`. The application server was recently migrated to a new IP address (10.0.5.9010.0.5.90), and the authoritative DNS zone was updated accordingly. However, when attempting to open the application on the client workstation, network traffic is still sent to the decommissioned IP address (10.0.5.1210.0.5.12). The technician executes `ipconfig /displaydns` on the client system and receives the following command output snippet:

Record Name . . . . . : payroll.internal
Record Type . . . . . : 1
Time To Live . . . . . : 86400
Data Length . . . . . : 4
Section . . . . . . . : Answer
A (Host) Record . . . : 10.0.5.12

Which of the following identifies the root cause of this failure and the correct remediation action to take on the client workstation?

Show answer & explanation

Answer: The client workstation is retaining a stale mapping in its local DNS resolver cache due to a high Time To Live value; running `ipconfig /flushdns` will clear the outdated entry.

Answer

The client workstation holds an outdated mapping in its local DNS cache owing to a high Time To Live setting; executing `ipconfig /flushdns` on the client resolves the issue.
The correct answer correctly identifies that `ipconfig /displaydns` displays entries currently held in the client system's local resolver cache. Because the TTL (Time To Live) was configured for 86,400 seconds (24 hours), the client operating system reuses the cached IP address (10.0.5.1210.0.5.12) instead of querying the DNS server for the newly updated record (10.0.5.9010.0.5.90). Running `ipconfig /flushdns` clears this local cache and forces a new DNS lookup.

Step-by-Step Solution

1
Analyze the command output from `ipconfig /displaydns`.
The local DNS cache contains an A record (Record Type 1) mapping `payroll.internal` to 10.0.5.1210.0.5.12 with 86,40086,400 seconds remaining on its TTL.
When a host queries a domain name, the operating system checks its local resolver cache before querying external DNS servers. A cached entry prevents new network requests from hitting the server.
2
Compare the cached entry to the actual updated infrastructure state.
The server was updated on the DNS server to 10.0.5.9010.0.5.90, but the client is still using the cached 10.0.5.1210.0.5.12 address.
Because the TTL was set high (86,40086,400 seconds or 24 hours), the client will not automatically query DNS until the cache entry expires.
3
Determine the appropriate command to invalidate the local cache.
Executing `ipconfig /flushdns` purges all entries in the Windows DNS resolver cache.
Flushing the cache forces the next application lookup to send a fresh request to the network's DNS server, obtaining the new IP address.

Key Concept

Local DNS Resolver Cache and TTL Behavior
Estimated Time:1m 30s
Question 1189Question

A network security engineer is tasked with hardening the management plane of a newly installed enterprise edge router to ensure administrative traffic and network telemetry are fully protected against unauthorized access and packet inspection. Which set of configuration actions represents the best practice for hardening the device?

Show answer & explanation

Answer: Implement SNMPv3 with authPriv for encrypted telemetry, disable Telnet and HTTP daemons in favor of SSH and HTTPS, and reassign the native VLAN on 802.1Q trunks from VLAN 1 to an unused VLAN ID.

Answer

Implement SNMPv3 with authPriv for encrypted telemetry, disable Telnet and HTTP daemons in favor of SSH and HTTPS, and reassign the native VLAN on 802.1Q trunks from VLAN 1 to an unused VLAN ID.
The correct configuration establishes a complete hardening baseline by encrypting management traffic (SSH and HTTPS), securing telemetry with strong authentication and payload encryption (SNMPv3 authPriv), and isolating trunking vulnerabilities by reassigning the untagged native VLAN away from default VLAN 1.

Step-by-Step Solution

1
Analyze administrative transport protocol security
Identify plaintext daemons (Telnet, HTTP) and replace them with encrypted protocols (SSH, HTTPS).
Plaintext management protocols transmit credentials and session data unencrypted across the network.
2
Select the appropriate SNMP version and security mode
Configure SNMPv3 with the authPriv security level.
authPriv provides both HMAC-based authentication and symmetric encryption for SNMP telemetry payloads.
3
Review Layer 2 trunk baseline hardening requirements
Change the default 802.1Q native VLAN away from VLAN 1 to a dedicated, unused VLAN ID.
Using default VLAN 1 for untagged trunk traffic exposes the switch infrastructure to double-tagging (VLAN hopping) vectors.

Key Concept

Network Device Baseline Hardening
Question 1190Question

A network security administrator is deploying a core Layer 3 router into an enterprise environment. To establish secure administrative remote access, the administrator must configure the management plane from the local console port before exposing the device to the network. In what chronological order should the administrator perform the following hardening steps to correctly enable encrypted remote management?

Drag items to arrange them in the correct order

Show answer & explanation

Answer

The correct sequence for hardening remote management plane access is: 1) Configure a unique system hostname and IP domain name on the router, 2) Generate persistent RSA asymmetric encryption key pairs, 3) Configure local administrative user credentials and enforce SSH transport on the VTY lines while disabling cleartext protocols, 4) Apply an inbound access control list (ACL) to the VTY lines to restrict management access exclusively to authorized administration subnets.
Establishing secure administrative remote access on network hardware follows a strict dependency chain: the device identity (hostname and domain name) must exist first so that RSA host keys can be generated. Once keys exist, the SSH daemon can be enabled on VTY lines and Telnet disabled. Finally, access control lists are applied to the VTY lines to restrict inbound management traffic strictly to authorized management subnets.

Step-by-Step Solution

1
Define the system identity by assigning a hostname and domain name.
The device forms its Fully Qualified Domain Name (FQDN), which is required by key generation utilities.
Cryptographic key generation algorithms fail or use default temporary parameters if the device lacks a domain identity.
2
Execute the crypto key generation command to build asymmetric RSA host keys.
The router creates and stores public/private key pairs used for SSH transport encryption.
SSH protocol daemons cannot initialize or negotiate secure sessions without pre-generated host keys.
3
Configure local AAA/user authentication and set VTY line transport input to SSH only.
Unencrypted Telnet management access is disabled, and remote connections require encrypted SSH authentication.
Restricting transport lines to SSH ensures credentials and session data are protected against eavesdropping.
4
Create and bind an inbound IPv4/IPv6 ACL to the VTY lines.
Remote management attempts from unauthorized IP addresses or subnets are dropped at the interface level.
Restricting source IP addresses adds defense-in-depth, mitigating brute-force and unauthorized access attempts against the management plane.

Key Concept

Management Plane Hardening & SSH Infrastructure Deployment Sequence
Estimated Time:2m 0s
Question 1191Question

A network operations team is preparing to implement a major infrastructure modification involving the deployment of new interior routing protocol parameters across core enterprise routers. To ensure compliance with IT governance standards, what is the correct chronological sequence of steps the team must follow throughout the standard change management lifecycle?

Drag items to arrange them in the correct order

Show answer & explanation

Answer

The correct sequence for standard IT change management is: 1) Draft the RFC including risk analysis and rollback plans, 2) Submit the RFC for CAB review and approval, 3) Perform pre-implementation lab validation and schedule the maintenance window, 4) Execute the change during the maintenance window and perform post-change verification, and 5) Update baseline documentation and conduct a post-implementation review.
Standard ITIL and enterprise change management practices require defining scope and rollback procedures in an RFC prior to obtaining formal CAB authorization. Once approved, changes are validated in a sandbox and scheduled during a low-impact maintenance window. Following execution and verification in production, configuration baselines must be updated and a post-implementation review conducted to finalize the change.

Step-by-Step Solution

1
Initiate the change request by drafting the formal RFC.
Defines change scope, potential impact, implementation steps, and mandatory rollback procedures.
Clear documentation of scope and rollback steps is necessary before any review or testing can occur.
2
Submit the RFC to the Change Advisory Board (CAB).
Obtain formal authorization and assessment from business and technical stakeholders.
CAB approval ensures business continuity and prevents uncoordinated or conflicting production changes.
3
Conduct sandbox validation and schedule the maintenance window.
Verifies configuration syntax in lab conditions and minimizes user impact by selecting low-traffic operational windows.
Pre-deployment testing ensures implementation readiness prior to modifying live infrastructure.
4
Deploy configuration changes and execute verification testing.
Applies changes on production equipment during the approved window and confirms service functionality.
Immediate post-change testing confirms whether the change succeeded or if immediate rollback is triggered.
5
Update configuration baselines and complete the Post-Implementation Review (PIR).
Maintains accurate inventory/configuration records and documents lessons learned to close the change ticket.
Documentation and PIR ensure configuration management database (CMDB) accuracy and operational traceability.

Key Concept

Standard Change Management Lifecycle Phases
Estimated Time:1m 30s
Question 1192Question

A network security administrator is aligning enterprise operational controls with fundamental security principles. Match each security mechanism or operational scenario to the core CIA Triad or security concept it primarily enforces.

Click a left item, then click its matching right item

Items

Encrypting web application session tokens in transit using TLS 1.3
Generating and validating SHA-256 checksums for software installation packages
Deploying redundant fault-tolerant SAN storage arrays across dual power feeds
Requiring asymmetric digital signatures on electronic contract documents

Matches

Show answer & explanation

Answer

Encrypting web application session tokens maps to Confidentiality; SHA-256 checksum validation maps to Integrity; Redundant SAN storage and dual power feeds map to Availability; Asymmetric digital signatures map to Non-repudiation.
Each mechanism aligns directly with its fundamental security goal: TLS encryption safeguards confidentiality against interception; SHA-256 hashing preserves integrity by verifying data unalterability; redundant hardware ensures availability via continuous service; digital signatures establish non-repudiation by mathematically binding signers to data.

Step-by-Step Solution

1
Analyze encrypting web application session tokens
Identified goal as preventing eavesdropping and unauthorized inspection
Protecting data from unauthorized disclosure is the definition of Confidentiality.
2
Analyze SHA-256 checksum validation
Identified goal as verifying data hasn't been altered or corrupted
Ensuring data accuracy and preventing unauthorized tampering is the core purpose of Integrity.
3
Analyze redundant SAN storage and dual power feeds
Identified goal as maintaining operational uptime and preventing single points of failure
Guaranteeing reliable access to data and systems for authorized users defines Availability.
4
Analyze asymmetric digital signatures on contract documents
Identified goal as proving document origin and authenticity without denial
Providing cryptographic proof of source identity so an entity cannot deny an action satisfies Non-repudiation.

Key Concept

CIA Triad & Core Security Concepts
Question 1193Question

A network administrator is retrofitting an unmonitored Intermediate Distribution Frame (IDF) closet located directly beneath an active plumbing line in a satellite office. Facilities management raised concerns regarding potential unauthorized physical opening of the network enclosures during off-hours cleaning, as well as the risk of water condensation or plumbing leaks causing hardware damage.

Which TWO of the following physical and environmental controls should the network administrator deploy to directly mitigate these specific threats?

Select all that apply

Show answer & explanation

Answer: Chassis intrusion sensors integrated with automated alerting systems; Spot or rope liquid detection sensors placed beneath the pipe route and rack base

Answer

The administrator should deploy chassis intrusion sensors to detect unauthorized cabinet access and liquid detection sensors to monitor for water leaks or condensation.
Deploying chassis intrusion sensors directly addresses unauthorized physical opening of network rack enclosures by generating security alerts when cabinet doors are opened. Deploying liquid detection sensors beneath overhead plumbing routes and near rack bases provides early warning of water leaks or moisture accumulation before physical equipment damage occurs.

Step-by-Step Solution

1
Analyze the physical security threat in the scenario
Identified threat: Unauthorized opening or physical tampering of network equipment enclosures during off-hours.
Chassis intrusion switches/sensors monitor cabinet doors and send instant notifications if opened without permission.
2
Analyze the environmental threat in the scenario
Identified threat: Water condensation or liquid intrusion from overhead plumbing.
Liquid detection rope or spot sensors installed near overhead pipes or cabinet drip pans alert administrators immediately upon contact with conductive fluid.
3
Evaluate and eliminate non-matching security controls
Faraday cages, clean-agent suppression systems, and aisle containment address electromagnetic interference, fire suppression, and airflow management respectively, not physical intrusion or pipe leakage.
Controls must directly align with the specific threat vectors described in the scenario.

Key Concept

Physical Security Controls and Environmental Measures
Question 1194Question

A network security administrator is configuring a newly deployed wireless network for corporate headquarters. The organization's compliance policy specifies that every user must authenticate individually using their RADIUS credentials and that all management frames must be protected against spoofing attacks. Which of the following wireless security configurations fulfills these requirements?

Show answer & explanation

Answer: WPA3-Enterprise using 802.1X authentication

Answer

WPA3-Enterprise using 802.1X authentication is the correct choice because it integrates with RADIUS for individual identity verification while enforcing Protected Management Frames.
WPA3-Enterprise implements 802.1X/EAP authentication to validate users individually against a RADIUS infrastructure. Additionally, WPA3 mandates Protected Management Frames (PMF) to guard against eavesdropping and frame forge attacks.

Step-by-Step Solution

1
Analyze authentication requirements
Individual user authentication via RADIUS requires an Enterprise mode (802.1X) rather than Personal/Pre-Shared Key (PSK/SAE) modes.
Enterprise modes decouple access control to centralized authentication servers (RADIUS/AAA).
2
Evaluate protection of management frames
WPA3 security standards mandate Protected Management Frames (PMF/802.11w) by default.
PMF prevents malicious actors from spoofing management frames such as deauthentication or disassociation frames.
3
Select the matching configuration
WPA3-Enterprise meets both RADIUS authentication and mandatory PMF criteria.
It satisfies corporate policy for credential auditing and management frame security.

Key Concept

Wireless Security Standards and Enterprise Authentication (802.1X vs SAE and PMF requirements)
Question 1195Question

A network technician is resolving high packet retransmission rates caused by adjacent-channel interference on a 2.4 GHz wireless deployment. The current access points were incorrectly configured using overlapping frequencies. Which TWO of the following channels should the technician assign to ensure non-overlapping 2.4 GHz operation? (Select TWO.)

Select all that apply

Show answer & explanation

Answer: Channel 1; Channel 6

Answer

Channel 1 and Channel 6 are standard non-overlapping channels in the 2.4 GHz spectrum.
In 2.4 GHz Wi-Fi deployments, 20 MHz channels require a 25 MHz center-frequency separation to operate without interference. Channel 1 and Channel 6 (along with Channel 11) fulfill this requirement and provide clean, non-overlapping coverage.

Step-by-Step Solution

1
Identify the 2.4 GHz channel width and total available spectrum
Standard 802.11 2.4 GHz channels use a 20 MHz channel width with 5 MHz spacing between center frequencies.
Channels must be spaced at least 25 MHz apart between center frequencies to prevent spectral overlap.
2
Select the standard non-overlapping channel set
Channels 1, 6, and 11 do not share overlapping frequency ranges.
Choosing Channel 1 and Channel 6 eliminates adjacent-channel interference between neighboring access points.

Key Concept

2.4 GHz Non-Overlapping Channels
Estimated Time:45s
Question 1196Question

A network architect is diagnosing severe performance degradation, high frame retransmission rates, and intermittent disconnections in a newly renovated logistics warehouse. An RF spectrum analyzer and site survey reveal two primary findings: (1) several 2.4 GHz access points (APs) are statically assigned to channels 1, 3, 7, and 11, and (2) high-power directional antennas mounted near metal support beams are creating significant delay spread at ground level. Which of the following statements accurately identify an underlying RF issue or a correct remediation step for this scenario? (Select TWO.)

Select all that apply

Show answer & explanation

Answer: The APs operating on channels 3 and 7 induce adjacent-channel interference (ACI), which should be mitigated by reconfiguring all 2.4 GHz radios to use only non-overlapping channels 1, 6, and 11.; The signal reflections off metallic beams cause multipath distortion, which can be mitigated by adjusting AP placement, selecting appropriate antenna patterns, or enabling antenna diversity.

Answer

The correct statements identify that assigning channels 3 and 7 causes adjacent-channel interference (which requires reassigning radios to non-overlapping channels 1, 6, and 11) and that reflection off metal beams causes multipath distortion (which requires adjusting placement, antenna patterns, or utilizing antenna diversity).
The option addressing channel configuration is correct because using channels 3 and 7 in 2.4 GHz Wi-Fi introduces adjacent-channel interference; using only non-overlapping channels 1, 6, and 11 resolves this. The option addressing metal reflection is correct because metal structures create multipath signals and delay spread, which are mitigated by adjusting AP antenna positioning, diversity, or radiation patterns.

Step-by-Step Solution

1
Analyze the 2.4 GHz channel assignment findings.
Channels 1, 3, 7, and 11 overlap in frequency space. Channels 3 and 7 overlap partially with channels 1, 6, and 11, creating destructive adjacent-channel interference (ACI).
In the 2.4 GHz ISM band, each 20 MHz channel spaced 5 MHz apart overlaps with adjacent channels unless restricted to channels 1, 6, and 11 in North America/standard deployments.
2
Analyze the RF propagation issue near metallic beams.
Metallic surfaces reflect RF signals, causing multiple out-of-phase copies of the signal to reach the receiver at varying time intervals (delay spread), leading to multipath distortion.
High delay spread degrades signal quality (SNR) and causes symbols to overlap, resulting in corrupt frames and retransmissions.
3
Evaluate mitigation techniques for both findings.
Reassigning APs to non-overlapping channels 1, 6, and 11 resolves ACI. Adjusting AP placement, utilizing MIMO/antenna diversity, or optimizing directional coverage resolves multipath distortion.
These physical-layer RF remedies directly resolve the root causes revealed by the spectrum analyzer and site survey.

Key Concept

Wireless RF Interference and Multipath Propagation Troubleshooting
Estimated Time:2m 0s
Question 1197Question

An enterprise systems administrator discovers that an attacker gained access to a database server and modified audit log files to erase evidence of unauthorized database queries. The administrator needs to select a security control that specifically ensures log files cannot be altered or tampered with without detection. Which of the following core security controls best maintains this specific pillar of the CIA triad?

Show answer & explanation

Answer: Implementing cryptographic hashing and digital signatures for generated log files

Answer

Implementing cryptographic hashing and digital signatures for generated log files directly preserves data integrity, ensuring any modification or deletion of log entries is immediately detectable.
Generating cryptographic hashes and applying digital signatures ensures data integrity. Any unauthorized modification to audit logs changes the calculated hash value, making alterations immediately detectable.

Step-by-Step Solution

1
Analyze the threat scenario described in the stem.
The compromise involved unauthorized modification of log files, which directly violates the Integrity pillar of the CIA triad.
Integrity guarantees that data remains accurate, complete, and untampered with throughout its lifecycle.
2
Evaluate potential technical controls against the target security principle.
Cryptographic hashing algorithms generate a unique digest of data; if a log file is altered, the recalculated hash value will fail validation.
Hashing and digital signatures are the primary technical controls used to ensure data integrity and non-repudiation.

Key Concept

CIA Triad Integrity Controls
Question 1198Question

A network operations team is upgrading their device management infrastructure to implement centralized command-level access control on enterprise routers. They select TACACS+ over RADIUS to fulfill this security requirement. Which technical capability of TACACS+ directly supports restricting specific administrative commands on a per-user basis?

Show answer & explanation

Answer: The strict separation of authentication and authorization processes, paired with full packet payload encryption over TCP

Answer

The strict separation of authentication and authorization processes, paired with full packet payload encryption over TCP
TACACS+ decouples authentication, authorization, and accounting functions within the AAA framework. This separation allows network access devices to send individual authorization requests to the TACACS+ server for each CLI command an administrator attempts to execute. Additionally, TACACS+ operates over TCP port 49 and encrypts the entire packet payload, providing comprehensive security for administrative device management.

Step-by-Step Solution

1
Analyze the requirement for per-command administrative authorization
Determine that granular command-level authorization requires decoupling authentication from authorization in the AAA architecture.
When authentication and authorization are combined, authorization happens once at login rather than dynamically per CLI command.
2
Compare RADIUS and TACACS+ AAA architecture features
TACACS+ decouples AAA components, allowing independent authorization requests for every CLI command entered by an administrator. RADIUS combines authentication and authorization.
Decoupled architecture in TACACS+ enables dynamic per-command authorization.
3
Evaluate protocol transport and encryption specifications
TACACS+ uses TCP port 49 and encrypts the entire body of the packet, whereas RADIUS uses UDP (ports 1812/1813) and encrypts only the password field.
Full payload encryption provides maximum confidentiality for sensitive administrative session traffic.

Key Concept

AAA Protocol Differentiation (RADIUS vs TACACS+)
Estimated Time:1m 30s
Question 1199Question

During a scheduled maintenance window, a senior administrator applies a new security configuration baseline to a core enterprise gateway. Immediately after applying the change, automated monitoring indicates that key database servers have lost network reachability due to an unintended blocking rule. Which of the following is the immediate next step the administrator should take according to standard change management procedures?

Show answer & explanation

Answer: Execute the documented rollback plan to return the core gateway to its pre-change functional baseline configuration.

Answer

The immediate next step is to execute the documented rollback plan to return the core gateway to its pre-change functional baseline configuration.
Executing the documented rollback plan is the required response when a change fails post-implementation testing. Reverting to the pre-change configuration baseline restores production service immediately without introducing unvetted configuration drift.

Step-by-Step Solution

1
Assess post-implementation validation results
Identified unexpected loss of database server reachability caused by the newly applied baseline configuration.
Post-implementation testing confirms that the change failed validation criteria.
2
Determine appropriate lifecycle procedure
Recognize that service outage triggers the predefined rollback conditions specified in the Request for Change (RFC).
Standard change management procedures require reverting failed changes immediately to minimize operational downtime.
3
Initiate rollback execution
Revert device configuration to the verified baseline taken prior to the maintenance window.
Restores full network connectivity and service baseline functionality before conducting root-cause analysis in a non-production environment.

Key Concept

Rollback Execution Trigger and Change Management Lifecycle
Estimated Time:1m 30s
Question 1200Question

A network technician is troubleshooting a client workstation that cannot connect to an internal server named `appserver.corp.local`. When the technician checks the local client cache using `ipconfig /displaydns`, the following output is returned:

text Record Name . . . . . : appserver.corp.local Record Type . . . . . : 1 Time To Live . . . . : 480 Data Length . . . . . : 4 Section . . . . . . . : Answer A (Host) Record . . . : 10.0.1.50

The system administrator notes that `appserver.corp.local` was recently migrated to IP address `10.0.1.150`. Which TWO of the following solutions will address the stale resolution issue on this workstation? (Select TWO.)

Select all that apply

Show answer & explanation

Answer: Run the `ipconfig /flushdns` command on the workstation to purge the local DNS resolver cache.; Allow the record's Time to Live (TTL) timer to expire naturally before making subsequent connection requests.

Answer

Running `ipconfig /flushdns` to immediately clear the local DNS resolver cache and allowing the Time to Live (TTL) period to expire naturally are the two valid methods to resolve the stale record issue.
When a host IP address changes on the server side, workstations that have recently resolved the old IP address store that mapping in their local DNS resolver cache until the TTL expires. Running `ipconfig /flushdns` forcibly purges the cache immediately so the next request queries the server for the new IP address (`10.0.1.150`). Alternatively, waiting for the remaining TTL timer to count down to zero will cause the client to purge the entry naturally.

Step-by-Step Solution

1
Analyze the `ipconfig /displaydns` output
The output reveals a cached A record mapping `appserver.corp.local` to an outdated IP address (`10.0.1.50`) with 480 seconds remaining on its TTL.
The client system relies on locally cached entries before querying upstream DNS servers.
2
Identify immediate cache remediation
Executing `ipconfig /flushdns` clears all cached host entries from memory immediately.
Clearing the cache forces the OS DNS resolver to send a new query to the DNS server, receiving the updated IP (`10.0.1.150`).
3
Identify passive cache remediation
Waiting out the 480-second TTL countdown automatically invalidates the stale record.
Once TTL reaches zero, the workstation discards the cached entry and queries the server for a fresh record.

Key Concept

DNS Client Cache and TTL Management
PreviousPage 60 / 112Next
All practice questions — CompTIA Network+ | Examkin