All practice questions
2237 questions
A network engineer is investigating intermittent packet loss and TCP session resets across a newly deployed hybrid cloud IPsec VPN tunnel connecting a corporate data center to an AWS VPC. After executing packet captures, the engineer confirms the hypothesis: transit packets exceeding the path MTU are being dropped because the DF (Don't Fragment) bit is set and ICMP Type 3 Code 4 messages are blocked by an upstream firewall. According to the CompTIA troubleshooting methodology, which TWO of the following actions should the engineer perform NEXT?
Select all that apply
A network technician is investigating a report that a client computer cannot access internal corporate resources using hostnames. Place the following troubleshooting steps in the correct logical sequence to systematically isolate and resolve the name resolution issue, from basic stack verification to cache remediation.
Drag items to arrange them in the correct order
A network administrator is auditing the organization's wireless security baseline. Match each wireless security standard on the left with its corresponding primary encryption protocol or cryptographic suite on the right.
Click a left item, then click its matching right item
Items
Matches
A network administrator is troubleshooting persistent wireless connectivity dropouts and high frame retransmission rates in a newly renovated office building. Diagnostic scans reveal that access points are operating on channel widths spanning Dynamic Frequency Selection (DFS) channels, while office partition walls contain foil-backed insulation and heavy metal mesh. Client devices experience sudden signal drops when stepping behind partitions, alongside temporary disconnections whenever access point logs record radar detection events. Which of the following root causes are contributing to these wireless performance issues? (Select TWO.)
Select all that apply
A network administrator is troubleshooting an issue where remote access VPN users cannot resolve names for specific corporate subdomains. Standard DNS queries for small records complete successfully, but queries that return large payload responses fail. The technician executes the following command on an affected client workstation:
$ nslookup -vc large-record.corp.internal 10.100.1.2
Server: dns1.corp.internal
Address: 10.100.1.2
DNS request timed out.
timeout was 2 seconds.
*** Request to dns1.corp.internal timed out
Which of the following is the most likely root cause of this failure?
A tier-2 Security Operations Center (SOC) analyst is analyzing threat intelligence logs and network packet captures from a recent enterprise security incident. Match each observed technical attack metric or anomalous protocol behavior to its corresponding network attack classification.
Click a left item, then click its matching right item
Items
Matches
A network technician is preparing a newly unboxed switch for deployment on a corporate network. Place the following administrative device hardening steps in the correct chronological order from first to last.
Drag items to arrange them in the correct order
A desktop technician is troubleshooting a client system that cannot connect to an internal web application hosted at `payroll.internal`. The application server was recently migrated to a new IP address (), and the authoritative DNS zone was updated accordingly. However, when attempting to open the application on the client workstation, network traffic is still sent to the decommissioned IP address (). The technician executes `ipconfig /displaydns` on the client system and receives the following command output snippet:
Record Name . . . . . : payroll.internal
Record Type . . . . . : 1
Time To Live . . . . . : 86400
Data Length . . . . . : 4
Section . . . . . . . : Answer
A (Host) Record . . . : 10.0.5.12
Which of the following identifies the root cause of this failure and the correct remediation action to take on the client workstation?
A network security engineer is tasked with hardening the management plane of a newly installed enterprise edge router to ensure administrative traffic and network telemetry are fully protected against unauthorized access and packet inspection. Which set of configuration actions represents the best practice for hardening the device?
A network security administrator is deploying a core Layer 3 router into an enterprise environment. To establish secure administrative remote access, the administrator must configure the management plane from the local console port before exposing the device to the network. In what chronological order should the administrator perform the following hardening steps to correctly enable encrypted remote management?
Drag items to arrange them in the correct order
A network operations team is preparing to implement a major infrastructure modification involving the deployment of new interior routing protocol parameters across core enterprise routers. To ensure compliance with IT governance standards, what is the correct chronological sequence of steps the team must follow throughout the standard change management lifecycle?
Drag items to arrange them in the correct order
A network security administrator is aligning enterprise operational controls with fundamental security principles. Match each security mechanism or operational scenario to the core CIA Triad or security concept it primarily enforces.
Click a left item, then click its matching right item
Items
Matches
A network administrator is retrofitting an unmonitored Intermediate Distribution Frame (IDF) closet located directly beneath an active plumbing line in a satellite office. Facilities management raised concerns regarding potential unauthorized physical opening of the network enclosures during off-hours cleaning, as well as the risk of water condensation or plumbing leaks causing hardware damage.
Which TWO of the following physical and environmental controls should the network administrator deploy to directly mitigate these specific threats?
Select all that apply
A network security administrator is configuring a newly deployed wireless network for corporate headquarters. The organization's compliance policy specifies that every user must authenticate individually using their RADIUS credentials and that all management frames must be protected against spoofing attacks. Which of the following wireless security configurations fulfills these requirements?
A network technician is resolving high packet retransmission rates caused by adjacent-channel interference on a 2.4 GHz wireless deployment. The current access points were incorrectly configured using overlapping frequencies. Which TWO of the following channels should the technician assign to ensure non-overlapping 2.4 GHz operation? (Select TWO.)
Select all that apply
A network architect is diagnosing severe performance degradation, high frame retransmission rates, and intermittent disconnections in a newly renovated logistics warehouse. An RF spectrum analyzer and site survey reveal two primary findings: (1) several 2.4 GHz access points (APs) are statically assigned to channels 1, 3, 7, and 11, and (2) high-power directional antennas mounted near metal support beams are creating significant delay spread at ground level. Which of the following statements accurately identify an underlying RF issue or a correct remediation step for this scenario? (Select TWO.)
Select all that apply
An enterprise systems administrator discovers that an attacker gained access to a database server and modified audit log files to erase evidence of unauthorized database queries. The administrator needs to select a security control that specifically ensures log files cannot be altered or tampered with without detection. Which of the following core security controls best maintains this specific pillar of the CIA triad?
A network operations team is upgrading their device management infrastructure to implement centralized command-level access control on enterprise routers. They select TACACS+ over RADIUS to fulfill this security requirement. Which technical capability of TACACS+ directly supports restricting specific administrative commands on a per-user basis?
During a scheduled maintenance window, a senior administrator applies a new security configuration baseline to a core enterprise gateway. Immediately after applying the change, automated monitoring indicates that key database servers have lost network reachability due to an unintended blocking rule. Which of the following is the immediate next step the administrator should take according to standard change management procedures?
A network technician is troubleshooting a client workstation that cannot connect to an internal server named `appserver.corp.local`. When the technician checks the local client cache using `ipconfig /displaydns`, the following output is returned:
text Record Name . . . . . : appserver.corp.local Record Type . . . . . : 1 Time To Live . . . . : 480 Data Length . . . . . : 4 Section . . . . . . . : Answer A (Host) Record . . . : 10.0.1.50
The system administrator notes that `appserver.corp.local` was recently migrated to IP address `10.0.1.150`. Which TWO of the following solutions will address the stale resolution issue on this workstation? (Select TWO.)
Select all that apply