All practice questions

2237 questions

Question 1221Question

An IT security administrator needs to implement a full-tunnel remote access VPN solution for traveling employees. The primary constraint is that these employees frequently connect from restrictive public Wi-Fi networks and hotels where firewalls block non-standard outbound ports as well as native IPsec protocols (such as IKE UDP 500/4500 and ESP). The chosen protocol must provide complete network-layer access to internal IP subnets while seamlessly encapsulating traffic over standard HTTPS. Which of the following VPN technologies best fulfills these requirements?

Show answer & explanation

Answer: Secure Socket Tunneling Protocol (SSTP)

Answer

Secure Socket Tunneling Protocol (SSTP) is the optimal choice because it tunnels network traffic over TCP port 443 using SSL/TLS encryption, allowing full network access while passing through restrictive firewalls.
Secure Socket Tunneling Protocol (SSTP) transports PPP tunneling traffic over a standard SSL/TLS session using TCP port 443. Because TCP port 443 is universally enabled on firewalls for outbound HTTPS traffic, SSTP provides reliable full-tunnel network connectivity even from highly restrictive network environments.

Step-by-Step Solution

1
Analyze the technical requirements and network environment constraints.
The requirement demands full network-layer IP routing that can pass through strict firewalls blocking native IPsec protocols (IKE/ESP) and non-standard UDP ports.
Public networks and hotel firewalls frequently restrict outbound traffic to standard web ports like TCP 80 and TCP 443.
2
Evaluate candidate protocols based on OSI layer encapsulation and transport port usage.
Secure Socket Tunneling Protocol (SSTP) encapsulates PPP frames within an SSL/TLS session over TCP port 443.
Because TCP port 443 is used for secure web browsing (HTTPS), firewalls almost universally allow it.
3
Differentiate SSTP from clientless SSL/TLS access.
SSTP acts as a full-tunnel network-level client solution, unlike clientless browser portals which only proxy specific application connections.
Full network access requires tunneling Layer 3 packets across the secure transport session.

Key Concept

Secure Socket Tunneling Protocol (SSTP) Firewall Traversal
Question 1222Question

A network administrator is investigating four separate wireless connectivity issues across an enterprise site. Match each observed wireless symptom or telemetry anomaly to its primary root cause.

Click a left item, then click its matching right item

Items

High frame retransmissions occur when legacy 802.11b802.11\text{b} clients at the facility perimeter transmit simultaneously with newer 802.11n802.11\text{n} clients operating closer to the access point.
Signal strength drops significantly from 62 dBm-62\text{ dBm} to 84 dBm-84\text{ dBm} immediately after interior drywall partitions are replaced with reinforced cinder block walls.
Access points operating on 5 GHz5\text{ GHz} channel 100 near a coastal harbor experience periodic, sudden 60-second transmission silences and channel changes.
Clients experience high frame corruption and packet loss inside a metallic storage room despite maintaining a strong received signal strength indicator (RSSI) of 52 dBm-52\text{ dBm}.

Matches

Show answer & explanation

Answer

1 matches Hidden node problem; 2 matches RF Absorption; 3 matches Dynamic Frequency Selection (DFS) clearing event; 4 matches Multipath delay spread.
Each observed wireless symptom directly corresponds to a specific physical propagation phenomenon or protocol-level behavior: collisions between distant stations stem from the hidden node problem; signal loss through masonry walls is caused by RF absorption; radar detection on 5 GHz UNII-2 channels triggers DFS channel changes; and signal reflections in metal-heavy spaces create multipath delay spread.

Step-by-Step Solution

1
Analyze collision issues between legacy and modern clients at differing distances.
Identify that clients out of RF range of each other transmit simultaneously, causing frame corruption at the access point.
This behavior defines the hidden node problem, which can be mitigated using Request to Send / Clear to Send (RTS/CTS) mechanisms.
2
Assess the impact of structural changes on signal propagation metrics.
Determine that high-density masonry absorbs RF energy, sharply decreasing signal power (RSSI).
RF absorption by dense materials reduces signal intensity and coverage area.
3
Evaluate intermittent outages occurring specifically on 5 GHz UNII-2 channels near radar sources.
Recognize mandatory 60-second channel availability check silences associated with DFS radar detection.
802.11 standards require APs on DFS channels to yield priority to primary radar signals.
4
Diagnose high packet corruption occurring in highly reflective environments with high RSSI.
Identify multipath delay spread, where reflected signals cause inter-symbol interference.
Strong RSSI measures overall power but does not guarantee signal phase alignment or quality.

Key Concept

RF environmental propagation phenomena and 802.11 protocol troubleshooting
Question 1223Question

A network engineer is configuring a remote access Virtual Private Network (VPN) solution using Layer 2 Tunneling Protocol over IPsec (L2TP/IPsec) for corporate users. Which of the following technical characteristics and operational requirements correctly apply to this deployment? (Select TWO.)

Select all that apply

Show answer & explanation

Answer: L2TP relies on the IPsec Encapsulating Security Payload (ESP) protocol to provide payload confidentiality and encryption.; The initial Internet Key Exchange (IKE) negotiation phase operates over UDP port 500.

Answer

L2TP relies on IPsec ESP for encryption, and the initial IKE key exchange negotiation phase operates over UDP port 500.
L2TP provides multi-protocol tunneling mechanisms but relies on IPsec ESP to encrypt packet contents. Furthermore, IPsec uses IKE over UDP port 500 to establish the initial security associations necessary for secure communication.

Step-by-Step Solution

1
Analyze the encryption architecture of L2TP/IPsec.
Identify that L2TP handles Layer 2 frame tunneling but relies on IPsec (specifically ESP) for encryption and integrity.
L2TP lacks built-in cryptographic mechanisms.
2
Analyze the port requirements for IPsec phase 1 negotiation.
Confirm that IKE uses UDP port 500 for authentication and key exchange.
UDP port 500 is the standard port for establishing IKE Security Associations.
3
Evaluate distractor protocols and transport modes.
Reject the statements asserting TCP port 443 usage for native L2TP encryption and TCP port 1701 for encapsulation.
L2TP uses UDP port 1701 for tunneling, lacks native encryption, and TCP port 443 is used by SSTP/SSL VPNs.

Key Concept

L2TP/IPsec VPN Protocol Requirements and Port Usage
Question 1224Question

A network engineer is troubleshooting a 75-meter Category 6 (Cat6) unshielded twisted-pair (UTP) link connecting a core switch to a distribution switch. Under load, the interface experiences high frame corruption and periodic link dropping. A basic wiremapper confirms that all eight conductors are pinned correctly according to TIA/EIA-568B with continuous electrical connectivity and no open circuits or shorts. The engineer suspects a structural wire break or severe impedance anomaly located inside the building conduit between floors. Which diagnostic instrument must the engineer use to determine the exact distance along the cable run where the physical defect is located?

Show answer & explanation

Answer: A Time-Domain Reflectometer (TDR), because it sends electrical pulses along the conductors and calculates distance to anomalies based on signal reflection timing.

Answer

A Time-Domain Reflectometer (TDR), because it sends electrical pulses along the conductors and calculates distance to anomalies based on signal reflection timing.
The option specifying a Time-Domain Reflectometer (TDR) is correct because TDR instruments transmit high-frequency electrical pulses down copper conductors. When the pulse encounters an impedance change, break, or crushed section, part of the signal reflects back to the device. By measuring the elapsed time and reflection signature, the TDR calculates the precise distance to the fault along the cable run.

Step-by-Step Solution

1
Analyze physical layer troubleshooting requirements
Identified that simple end-to-end pinout continuity is confirmed, indicating the fault is an internal conductor anomaly along the length of the run.
Basic continuity wiremappers confirm pin mapping but cannot measure distance to impedance faults or internal physical damage.
2
Evaluate diagnostic tool capabilities for copper media
Determined that a Time-Domain Reflectometer (TDR) injects signal pulses and records reflections caused by impedance mismatches or breaks.
TDR technology converts signal reflection delay into precise linear distance along metallic conductors.
3
Select the correct instrument based on physical media and scenario
Selected the TDR instrument over toning tools, continuity testers, and optical meters.
TDR is specifically designed to locate hidden physical cable breaks and impedance anomalies in copper UTP runs.

Key Concept

Copper Cable Fault Diagnostics using Time-Domain Reflectometry (TDR)
Question 1225Question

An administrator notices that servers mounted in the middle of several server rack rows are experiencing thermal warnings during peak utilization. Environmental monitoring reveals that cool supply air from raised floor vents is mixing directly with hot exhaust air from adjacent equipment rows prior to entering server intake fans. Which physical infrastructure design change should the network administrator implement to prevent this air mixing?

Show answer & explanation

Answer: Reorient the equipment racks into alternating rows so server intakes face intake aisles and exhausts face exhaust aisles to create hot and cold aisles.

Answer

Reorient the equipment racks into alternating rows so server intakes face intake aisles and exhausts face exhaust aisles to create hot and cold aisles.
Arranging rack equipment into alternating hot and cold aisles physically isolates cold intake streams from hot exhaust air streams. Cold supply air enters the cold aisles to feed server intake fans, while rear server exhausts discharge heat into dedicated hot aisles for collection by environmental return ducts.

Step-by-Step Solution

1
Analyze environmental telemetry and airflow paths
Identified that cool supply air mixes with warm exhaust air before reaching server equipment intakes.
Uniform rack orientation without containment allows hot exhaust air to loop back into intake streams.
2
Select the standard physical layout design for data center thermal management
Arrange rack rows so fronts face fronts (cold aisles) and backs face backs (hot aisles).
Hot and cold aisle containment physically separates intake air from exhaust air, maximizing HVAC cooling efficiency.

Key Concept

Hot Aisle and Cold Aisle Environmental Containment
Question 1226Question

An enterprise network team prepares to update the operating system across central distribution switches to patch a critical security flaw. The lead engineer submits a formal Request for Change (RFC) to the Change Advisory Board (CAB). After evaluating the submission, the CAB rejects the RFC. Which of the following omissions in the RFC is the most likely reason for the board's rejection?

Show answer & explanation

Answer: The RFC did not contain a validated rollback procedure and specific performance metrics for triggering a change reversion.

Answer

The RFC did not contain a validated rollback procedure and specific performance metrics for triggering a change reversion.
The correct answer highlights the necessity of a fully documented rollback plan and clear abort triggers within an RFC. A primary responsibility of the Change Advisory Board is risk management; any RFC lacking a clear, tested backout strategy for reverting to a functional baseline upon failure will be rejected.

Step-by-Step Solution

1
Analyze the core requirements of a Change Advisory Board (CAB) review for a Request for Change (RFC).
Identify that CAB approval requires comprehensive risk mitigation, including impact analysis, maintenance window scheduling, testing validation, and backout strategies.
CAB governance focuses on ensuring system stability and minimizing unmitigated operational risk.
2
Evaluate the missing element that presents the greatest risk during a core distribution switch upgrade.
The absence of a defined rollback plan leaves the network without a recovery strategy if the software update causes unforeseen instability or outage.
Without clear backout steps and trigger metrics, recovery from a failed change would be unstructured and prolonged.

Key Concept

Request for Change (RFC) Requirements and Rollback Planning
Question 1227Question

A network engineer troubleshooting a loss of network redundancy on a core switch stack has confirmed that a mismatched VTP domain configuration was the root cause by successfully validating the hypothesis in a staging lab. Following the CompTIA troubleshooting methodology, the engineer is now advancing to the immediate NEXT phase before implementing any modifications on the production network. Which of the following actions should the engineer perform during this phase? (Select TWO.)

Select all that apply

Show answer & explanation

Answer: Outline a step-by-step implementation plan detailing the exact configuration commands needed to align the VTP domain settings.; Evaluate the risk of potential service disruption to downstream trunk links and identify necessary change control approvals.

Answer

The engineer must outline a step-by-step implementation plan detailing the configuration changes and evaluate the risk of potential service disruption while identifying change control approvals.
According to the CompTIA troubleshooting methodology, after testing a theory and confirming the root cause (Step 3), the technician must proceed to Step 4: 'Establish a plan of action to resolve the problem and identify potential effects'. Developing a clear step-by-step implementation plan and identifying potential risks or side effects on production traffic directly satisfy the requirements of Step 4.

Step-by-Step Solution

1
Identify the current phase completed in the CompTIA troubleshooting methodology.
The engineer confirmed the root cause in a lab, which completes Step 3: 'Test the theory to determine cause'.
Determining which phase was completed establishes where the technician is in the overall sequence.
2
Determine the immediate next sequential step in the methodology.
The next phase is Step 4: 'Establish a plan of action to resolve the problem and identify potential effects'.
CompTIA requires establishing a formal plan and assessing side effects prior to implementing any production changes.
3
Select the activities that correspond strictly to Step 4.
Formulating a step-by-step implementation plan and evaluating side effects / change control requirements belong to Step 4.
Implementation tasks, verification, and final documentation belong to subsequent steps in the methodology.

Key Concept

CompTIA 7-Step Troubleshooting Methodology Sequence
Question 1228Question

A network technician is troubleshooting a client workstation that cannot connect to a local server by hostname. To determine where the resolution process fails, arrange the name resolution mechanisms in the exact sequence the host operating system attempts them, from FIRST to LAST.

Drag items to arrange them in the correct order

Show answer & explanation

Answer

The host operating system resolves names sequentially by checking the local DNS resolver cache and HOSTS file first, sending a query to the primary DNS server second, querying the secondary DNS server third, and broadcasting an LLMNR or NetBIOS query on the local subnet last.
The correct order follows standard operating system host resolution behavior: inspecting local memory resources (DNS cache and HOSTS file) first, followed by configured unicast DNS servers (primary then secondary), and resorting to local subnet link-local resolution (LLMNR/NetBIOS) last.

Step-by-Step Solution

1
Check local memory and configuration files
The OS reads the local DNS cache and HOSTS file.
Local lookup is instant and prevents unnecessary network requests.
2
Contact the preferred unicast DNS server
A DNS request is sent over UDP/TCP port 53 to the primary DNS server.
Unicast DNS is the primary network name resolution service.
3
Contact the alternate unicast DNS server
The request is resent to the secondary DNS server after a timeout from the primary.
Secondary DNS servers provide redundant resolution capability.
4
Perform link-local multicast/broadcast resolution
The host broadcasts LLMNR or NetBIOS Name Service packets on the local subnet.
Link-local resolution serves as a final fallback for peer-to-peer name resolution on the local LAN segment.

Key Concept

Operating System Name Resolution Order
Question 1229Question

A network technician is troubleshooting poor wireless performance, excessive frame retransmissions, and intermittent connectivity dropouts across an office floor using three access points operating on the 2.4 GHz band. A site survey reveals that adjacent access points are currently assigned to Channel 1, Channel 3, and Channel 5. Which TWO actions should the technician take to resolve the radio frequency interference and stabilize the wireless network?

Select all that apply

Show answer & explanation

Answer: Reconfigure the access points to operate on non-overlapping channels 1, 6, and 11.; Adjust and reduce the transmission power levels on adjacent access points to limit cell coverage overlap.

Answer

The technician should reconfigure access point channel assignments to use non-overlapping channels (1, 6, and 11) and adjust transmission power levels to limit cell coverage overlap.
Reconfiguring the wireless access points to use channels 1, 6, and 11 eliminates adjacent-channel interference because these three channels have sufficient frequency separation. Decreasing transmission power resizes the coverage cells, minimizing co-channel interference and facilitating effective client roaming.

Step-by-Step Solution

1
Analyze current 2.4 GHz channel assignments.
Channels 1, 3, and 5 share overlapping frequencies, resulting in adjacent-channel interference.
Each 2.4 GHz channel is 20 MHz wide with center frequencies spaced only 5 MHz apart.
2
Reassign access point channels.
Using channels 1, 6, and 11 provides at least 25 MHz of separation between center frequencies.
Channels 1, 6, and 11 are the only standard non-overlapping 20 MHz channel combination in the 2.4 GHz band.
3
Tune access point transmission power.
Lowering transmit power reduces the coverage boundary of each AP cell.
Excessive cell overlap leads to co-channel interference and causes clients to remain connected to distant APs.

Key Concept

2.4 GHz Channel Overlap and RF Cell Tuning
Question 1230Question

A network technician receives reports that workstations on a local subnet are unable to access an internal intranet web server using its hostname `intranet.corp.local`, though connecting directly via IP address works properly. When executing `dig intranet.corp.local` from a workstation, the utility outputs `;; QUESTION SECTION: ;intranet.corp.local. IN A` followed by `;; AUTHORITY SECTION: corp.local. 3600 IN SOA ns1.corp.local. admin.corp.local. (...)` and zero answers in the `ANSWER SECTION`. Which of the following potential root causes and verification steps are valid for troubleshooting this issue? (Select TWO.)

Select all that apply

Show answer & explanation

Answer: An A record for intranet.corp.local is missing or incorrectly named on the authoritative DNS server.; Using an authoritative lookup tool to query the primary name server directly will confirm whether the record exists on the zone file.

Answer

The valid root cause is that the requested host record is missing or misspelled in the authoritative zone file, and a valid troubleshooting step is to query the authoritative name server directly to confirm record presence.
Receiving an SOA record in the AUTHORITY section without records in the ANSWER section indicates that the DNS server is authoritative for the domain zone, but no A/AAAA entry exists for the queried hostname. Directly querying the primary DNS server specified in the SOA record allows an administrator to inspect the authoritative record status without cached interference.

Step-by-Step Solution

1
Analyze the provided `dig` output status and response sections.
The query succeeded without an error code like NXDOMAIN, but returned zero answer records while citing the zone SOA in the authority section.
This output pattern confirms the server is authoritative for `corp.local`, but no resource record exists for `intranet.corp.local`.
2
Evaluate potential host configuration and record causes.
Identified missing or misspelled A record in the zone configuration as the primary root cause.
When a domain zone exists but a specific record is missing, the server responds with NOERROR and an empty ANSWER section.
3
Select the proper verification methodology.
Directly querying the primary name server specified in the SOA record confirms if the zone file itself lacks the entry.
Targeting the authoritative server isolates zone misconfigurations from intermediate caching or forwarding anomalies.

Key Concept

DNS Lookup Output Interpretation & Record Verification
Question 1231Question

A network engineer is responding to reports of intermittent application session resets occurring across a hybrid cloud IPsec tunnel following a recent router firmware patch. Place the technician's troubleshooting procedures in the precise order required by the official CompTIA troubleshooting methodology, from the initial action to the final action.

Drag items to arrange them in the correct order

Show answer & explanation

Answer

The correct sequential order of the troubleshooting process is: 1. Review logs, interview users, and duplicate the failure; 2. Formulate a hypothesis regarding DF bit enforcement and MTU mismatch; 3. Perform ping tests with the DF bit set to test the hypothesis; 4. Submit change management details, identify potential impacts, and apply MSS clamping; 5. Verify transaction stability under full system load and configure monitoring thresholds; 6. Log findings, parameters, and documentation in the ticketing system repository.
The correct sequence strictly adheres to the official CompTIA 6-step troubleshooting workflow: (1) Identify the problem by gathering symptoms and duplicating the issue; (2) Establish a theory of probable cause by analyzing header overhead and packet constraints; (3) Test the theory using DF bit ping sweeps; (4) Formulate a change management plan of action, evaluate side effects, and implement MSS clamping; (5) Verify full functionality under real workloads and apply preventive monitoring; (6) Document the root cause and configuration details in the enterprise repository.

Step-by-Step Solution

1
Identify the problem by interviewing users, reviewing error logs, and replicating the issue.
Establishes clear symptoms, baseline conditions, and scope of the failure.
CompTIA methodology strictly mandates gathering information and establishing symptoms before making assumptions or forming hypotheses.
2
Establish a theory of probable cause by evaluating physical, transport, and network layer parameters.
Develops a plausible hypothesis (MTU/DF bit mismatch across IPsec tunnel).
A theory must be established before conducting targeted diagnostic tests.
3
Test the theory using diagnostic utilities (ping with DF bit set).
Confirms or denies the root cause of the problem.
Testing validates the theory without prematurely implementing untested production modifications.
4
Establish a plan of action to resolve the issue, evaluate potential side effects, and implement the solution.
Applies the resolution (MSS clamping configuration) safely through change control procedures.
Remediation planning and impact analysis must precede implementation to prevent unintended outages.
5
Verify full system functionality and implement preventive measures.
Ensures the system operates correctly end-to-end and guards against future recurrence.
Confirmation of overall system health must occur before final sign-off and ticket closure.
6
Document findings, actions, and outcomes.
Updates organizational knowledge bases and incident history records.
Documentation provides reference material for future network incidents and completes the methodology.

Key Concept

CompTIA 6-Step Network Troubleshooting Methodology Sequential Flow
Question 1232Question

A network security administrator is tasked with baseline hardening for a newly installed Layer 3 enterprise switch before connecting it to the production network. Corporate security compliance mandates that the configuration must mitigate double-tagging VLAN hopping attacks on trunk connections, prevent unauthorized access on unassigned physical ports, and protect administrative sessions from eavesdropping and tampering. Which set of device hardening measures best meets these requirements?

Show answer & explanation

Answer: Change the native VLAN on all 802.1Q trunk links to an unused non-default VLAN ID, disable Dynamic Trunking Protocol (DTP) on trunk ports, shut down all unused physical switch ports and reassign them to an isolated blackhole VLAN, and enforce SSHv2 alongside SNMPv3 with authPriv for remote management.

Answer

Change the native VLAN on all 802.1Q trunk links to an unused non-default VLAN ID, disable Dynamic Trunking Protocol (DTP) on trunk ports, shut down all unused physical switch ports and reassign them to an isolated blackhole VLAN, and enforce SSHv2 alongside SNMPv3 with authPriv for remote management.
The correct response combines comprehensive Layer 2 and management plane hardening controls. Native VLAN reassignment to a dedicated, unused VLAN ID combined with disabling DTP prevents VLAN hopping via double-tagging and unauthorized trunk formation. Moving unused ports to a non-routed blackhole VLAN while disabling them prevents physical rogue access. Enforcing SSHv2 and SNMPv3 configured with authPriv guarantees both cryptographic authentication and strong payload encryption for remote management.

Step-by-Step Solution

1
Analyze layer 2 trunk hardening requirements.
Default VLAN 1 should never be used as the native VLAN on 802.1Q trunks because untagged frames could enable double-tagging attacks. Reassigning the native VLAN to a dummy/unused VLAN ID and explicitly disabling DTP prevents malicious trunk negotiation.
Eliminates potential VLAN hopping and untagged frame leakage vulnerabilities across trunk interfaces.
2
Analyze physical switch port security requirements.
Unused interfaces should be administratively disabled (`shutdown`) and assigned to an isolated blackhole VLAN that is not routed anywhere on the network.
Prevents unauthorized physical access to the internal network by plugging into inactive Ethernet ports.
3
Analyze management plane security requirements.
Legacy cleartext management protocols (Telnet, HTTP, SNMPv1/v2c) must be replaced with secure, encrypted alternatives (SSHv2, HTTPS, SNMPv3 with authentication and privacy/encryption).
Ensures administrative credentials and network monitoring telemetry are protected against eavesdropping and man-in-the-middle attacks.

Key Concept

Switch Baseline Hardening & Management Plane Security
Question 1233Question

A network administrator is investigating reports that internal workstations are unable to connect to a web application at `payroll.internal.net`. To diagnose the issue, the administrator executes a hostname lookup using `nslookup` on a client machine, which returns the following output:

text
$ nslookup payroll.internal.net
Server: 10.1.1.5
Address: 10.1.1.5#53

Name: payroll.internal.net
Alias: app-server-04.internal.net

*** 10.1.1.5 can't find app-server-04.internal.net: Non-existent domain (NXDOMAIN)

Which of the following represents the primary root cause of this name resolution failure?

Show answer & explanation

Answer: The CNAME record for `payroll.internal.net` points to a canonical target (`app-server-04.internal.net`) that lacks a corresponding A or AAAA record in DNS.

Answer

The CNAME record for `payroll.internal.net` points to a canonical target (`app-server-04.internal.net`) that lacks a corresponding A or AAAA record in DNS.
A CNAME (Canonical Name) record acts as an alias pointing to another domain name rather than directly to an IP address. When a client requests `payroll.internal.net`, the DNS server resolves `payroll.internal.net` to `app-server-04.internal.net` and then attempts to resolve `app-server-04.internal.net` to an IP address. Because `app-server-04.internal.net` does not have a valid A/AAAA host record in the zone, the DNS server returns an NXDOMAIN error for the target, causing the entire resolution attempt to fail.

Step-by-Step Solution

1
Analyze the `nslookup` command output.
The lookup successfully resolved `payroll.internal.net` to its alias target `app-server-04.internal.net`.
This confirms that the CNAME entry for `payroll.internal.net` exists and is functional.
2
Examine the second stage of the DNS resolution chain.
The DNS server returned `Non-existent domain (NXDOMAIN)` when attempting to resolve `app-server-04.internal.net`.
Resolving a CNAME record requires a valid A (IPv4) or AAAA (IPv6) record for the destination canonical hostname. Without an A/AAAA record for `app-server-04.internal.net`, final IP address resolution cannot complete.
3
Identify the corrective action required to fix the issue.
Create an A record for `app-server-04.internal.net` mapping to the server's correct IP address.
Adding the missing host record will allow future CNAME chain resolution to complete successfully.

Key Concept

DNS CNAME Record Resolution and Chaining Dependencies
Estimated Time:2m 0s
Question 1234Question

A network administrator is designing security controls for an enterprise application that transmits customer records across an untrusted network. The security policy dictates that the solution must prevent unauthorized eavesdropping on the payload content while also ensuring any unauthorized modifications to the data during transit are detected. Which TWO of the following security measures directly address these requirements?

Select all that apply

Show answer & explanation

Answer: Encrypting the data payload using Transport Layer Security (TLS); Appending a Hash-based Message Authentication Code (HMAC) to the transmitted data

Answer

The correct measures are encrypting the payload using Transport Layer Security (TLS) to enforce confidentiality, and appending a Hash-based Message Authentication Code (HMAC) to enforce message integrity.
The scenario requires addressing two pillars of the CIA Triad: Confidentiality (preventing unauthorized viewing) and Integrity (detecting unauthorized modification). Encrypting the payload with Transport Layer Security (TLS) satisfies confidentiality by scrambling data in transit. Using a Hash-based Message Authentication Code (HMAC) satisfies integrity by calculating a cryptographic checksum that reveals any tampering during transmission.

Step-by-Step Solution

1
Identify the required CIA Triad pillars specified in the scenario
Preventing unauthorized eavesdropping maps to Confidentiality; detecting unauthorized modifications during transit maps to Integrity.
Security controls must align specifically with the targeted security goals of confidentiality and integrity.
2
Evaluate cryptographic controls that enforce Confidentiality
Transport Layer Security (TLS) encrypts session traffic, making intercepted payloads unreadable to unauthorized parties.
Encryption is the primary mechanism for maintaining data confidentiality in transit.
3
Evaluate cryptographic controls that enforce Integrity
HMAC calculates a cryptographic digest using a shared key, allowing the receiver to verify that data was not tampered with.
Hashing mechanisms (like HMAC) ensure message integrity by detecting modifications.

Key Concept

CIA Triad (Confidentiality and Integrity Controls for Data in Transit)
Question 1235Question

Match each wireless network symptom described on the left with its primary physical or radio frequency (RF) root cause on the right.

Click a left item, then click its matching right item

Items

High frame retransmission rates and latency near metal warehouse racks despite strong RSSI measurements.
Intermittent 2.4 GHz Wi-Fi connection drops in an office area adjacent to a breakroom during lunch hours.
A sudden, drastic drop in signal strength (dBm) immediately after entering a room surrounded by reinforced concrete.
Severe throughput degradation on two nearby access points assigned to 2.4 GHz channels 2 and 3.

Matches

Show answer & explanation

Answer

High frame retransmissions near metal racks match RF reflection and multipath distortion. Intermittent drops near breakrooms match non-802.11 2.4 GHz interference. Signal drops behind reinforced concrete match RF attenuation. Performance drops on channels 2 and 3 match adjacent-channel interference.
Each symptom directly corresponds to a fundamental RF behavior: metal causes reflection and multipath delay spread; active microwave ovens create non-802.11 2.4 GHz interference; reinforced concrete causes high RF attenuation; and selecting channels 2 and 3 violates non-overlapping 2.4 GHz channel design (1, 6, 11), producing adjacent-channel interference.

Step-by-Step Solution

1
Analyze the metal warehouse rack scenario
Strong RSSI combined with high frame retransmissions indicates signal reflections bouncing off metal surfaces, causing multipath delay spread.
Metal is a known reflector of RF signals.
2
Analyze the breakroom Wi-Fi drops
Periodic disruption correlated with lunch hours points to microwave oven usage radiating noise in the 2.4 GHz band.
Microwaves operate in the 2.4 GHz ISM band and interfere with 802.11b/g/n signals.
3
Analyze the reinforced concrete scenario
Concrete absorbs RF energy, causing severe attenuation and lower dBm readings.
High-density physical barriers attenuate wireless signal strength.
4
Analyze the channel 2 and 3 configuration
Channels 2 and 3 overlap substantially with each other, generating destructive adjacent-channel interference.
Standard 2.4 GHz deployments require non-overlapping channels (1, 6, and 11) to avoid spectral overlap.

Key Concept

Identifying wireless RF degradation mechanisms and channel allocation rules.
Question 1236Question

An IT manager is reviewing a proposed wireless network implementation for a corporate office. The security policy mandates individual user accountability through centralized 802.1X RADIUS authentication alongside mandatory Protected Management Frames. The installation team proposes deploying WPA3-Personal with a robust shared passphrase to streamline client onboarding. Which of the following statements best evaluates this proposal against the organization's requirements?

Show answer & explanation

Answer: The proposal fails to meet requirements because WPA3-Personal uses Simultaneous Authentication of Equals (SAE) with a shared passphrase rather than individual 802.1X user authentication.

Answer

The proposal fails to meet requirements because WPA3-Personal uses Simultaneous Authentication of Equals (SAE) with a shared passphrase rather than individual 802.1X user authentication.
WPA3-Personal is designed for home and small office networks using Simultaneous Authentication of Equals (SAE) with a pre-shared passphrase. Because all clients share the same key, it cannot provide individual user accountability or integrate with 802.1X RADIUS authentication servers. Meeting the requirement for central user authentication requires WPA3-Enterprise.

Step-by-Step Solution

1
Identify the organization's key wireless security requirement
The requirement specifies centralized 802.1X RADIUS authentication for individual user accountability.
Enterprise security environments require unique credentials per user mapped to a central identity provider via RADIUS.
2
Evaluate the capabilities of the proposed WPA3-Personal standard
WPA3-Personal uses Simultaneous Authentication of Equals (SAE) with a shared password across devices.
SAE provides strong key exchange for pre-shared key environments but does not support EAP/802.1X RADIUS authentication.
3
Determine the correct standard and conclusion
The team must deploy WPA3-Enterprise instead of WPA3-Personal.
WPA3-Enterprise is required to integrate 802.1X RADIUS authentication for unique user account identity verification.

Key Concept

WPA3-Personal vs. WPA3-Enterprise Authentication Requirements
Question 1237Question

A network technician is troubleshooting a workstation that lost connectivity to the local intranet. The technician established a hypothesis that a recently disabled network port was the cause and conducted tests that confirmed this theory. According to the CompTIA troubleshooting methodology, which of the following actions should the technician take NEXT?

Show answer & explanation

Answer: Establish a plan of action to resolve the problem and identify potential effects.

Answer

Establish a plan of action to resolve the problem and identify potential effects.
According to the CompTIA 7-step troubleshooting methodology, once a theory of probable cause has been tested and confirmed (Step 3), the technician must establish a plan of action to resolve the issue and identify any potential effects (Step 4) before implementing the fix.

Step-by-Step Solution

1
Determine the current phase in the CompTIA Troubleshooting Methodology.
The technician has completed Step 2 (Establish a theory) and Step 3 (Test the theory to determine cause).
The scenario states that testing confirmed the established theory.
2
Identify the immediate next step in the official 7-step sequence.
Step 4 is 'Establish a plan of action to resolve the problem and identify potential effects'.
After confirming the cause, the technician must plan the fix and consider any potential impacts before executing the resolution.

Key Concept

CompTIA Troubleshooting Methodology Order
Question 1238Question

A system administrator notices that log events from the client subnet 10.100.20.0/2410.100.20.0/24 are not reaching the central Syslog server located at 192.168.10.50192.168.10.50. An extended IPv4 Access Control List (ACL) applied inbound on the router interface serving the client subnet contains the following entries:

access-list 105 permit tcp 10.100.20.0 0.0.0.255 host 192.168.10.50 eq 514
access-list 105 permit udp 10.100.20.0 0.0.0.255 host 192.168.10.50 eq 161
access-list 105 deny ip any any

Which configuration error is preventing the log messages from reaching the Syslog server?

Show answer & explanation

Answer: The ACL rule permits TCP traffic on port 514, but standard Syslog operates over UDP port 514, causing the log packets to be matched and dropped by the deny rule.

Answer

The ACL rule permits TCP traffic on port 514, but standard Syslog operates over UDP port 514, causing the log packets to be matched and dropped by the deny rule.
Standard Syslog generates event messaging over UDP port 514. The configured Access Control List explicitly specifies `tcp` for port 514 in the first rule. Because TCP and UDP are distinct transport-layer protocols, incoming UDP Syslog datagrams fail to match the first rule, fail to match the SNMP rule (UDP 161), and are ultimately discarded by the final deny statement.

Step-by-Step Solution

1
Identify the transport protocol and port used by standard Syslog.
Standard Syslog operates over UDP using port 514.
Syslog default message transmission relies on connectionless UDP datagram delivery to port 514.
2
Evaluate the configured ACL rules against incoming Syslog packets.
The first entry permits `tcp ... eq 514` which fails to match UDP packets. The second entry permits `udp ... eq 161` (SNMP).
Because protocol type matching requires exact protocol match (TCP vs UDP), UDP 514 packets bypass rules 1 and 2.
3
Determine packet disposition after passing unmatched rules.
The packet hits `deny ip any any` and is dropped.
ACLs process rules sequentially until a match occurs; unmatched packets reach explicit or implicit deny statements.

Key Concept

Syslog Protocol & Transport ACL Matching
Question 1239Question

A workstation on a corporate network cannot reach a web server located on a remote subnet. Arrange the following diagnostic steps in the correct logical sequence to systematically isolate whether the connectivity issue stems from local TCP/IP settings, the local default gateway, path routing, or router Access Control Lists (ACLs).

Drag items to arrange them in the correct order

Show answer & explanation

Answer

The correct sequence begins with testing the local TCP/IP stack (127.0.0.1127.0.0.1), followed by pinging the default gateway, executing a traceroute to locate the failing hop, and finally inspecting the router table and ACL entries at the failure point.
Structured network troubleshooting progresses from inside to outside: verifying the local host TCP/IP stack first, testing the local default gateway second, running path tracing to pinpoint intermediate failure hops third, and examining router configuration state (routes and ACLs) at the point of failure last.

Step-by-Step Solution

1
Ping the loopback address (127.0.0.1127.0.0.1).
Confirms the host network driver and protocol stack are operational.
Eliminates local host software corruption before testing physical/network link reachability.
2
Ping the default gateway IP address.
Verifies local subnet connectivity and gateway IP configuration.
Determines whether the issue is restricted to the local broadcast domain or gateway reachability.
3
Run traceroute to the target destination address.
Identifies the exact gateway hop where path forwarding stops.
Isolates the network boundary between functional intermediate routers and the failing node.
4
Check routing tables and ACL rules on the failing hop router.
Reveals missing routes or filtering rules blocking destination traffic.
Provides the root cause configuration detail required to restore network traffic flow.

Key Concept

Standard Network Troubleshooting Flow for Gateway, Routing, and ACL Faults
Question 1240Question

A network administrator is reviewing security logs for remote employees connecting to the corporate network via a client-based Remote Access Virtual Private Network (VPN). The administrator discovers that while remote users can access internal private servers, their web browsing traffic to external internet sites is being routed directly through their local home internet service providers rather than through the corporate firewall and web content filter. Which of the following configuration settings on the VPN concentrator or client profile should the administrator modify to ensure all network traffic from remote clients is routed through the secure tunnel?

Show answer & explanation

Answer: Disable split tunneling and enforce a full-tunnel VPN configuration.

Answer

Disable split tunneling and enforce a full-tunnel VPN configuration.
Split tunneling allows a remote user's device to route internet-bound traffic directly through their local network while only routing corporate-bound traffic through the VPN. Disabling split tunneling and implementing a full-tunnel VPN configuration modifies the client's routing table so that all network traffic—regardless of destination—is encapsulated and forwarded to the corporate VPN gateway for processing and security inspection.

Step-by-Step Solution

1
Analyze the observed network behavior.
Internal corporate traffic enters the VPN tunnel, while external internet traffic bypasses the tunnel and exits directly via the remote user's local interface.
This behavior describes split tunneling, where only specific corporate subnets are directed into the VPN tunnel, leaving all other destination traffic on the default local default gateway.
2
Identify the security requirement.
All client traffic must be routed to the corporate network so central security policies (firewalling, web filtering, DLP) can be applied.
Full tunneling redirects the client's default route into the VPN tunnel, sending all outbound IP packets to the VPN gateway.
3
Select the correct profile configuration.
Disabling split tunneling (enforcing full-tunnel mode) forces all traffic through the corporate gateway.
Full tunneling ensures zero traffic bypasses security inspection, meeting the requirement.

Key Concept

Split Tunneling vs. Full Tunneling VPN Configurations
PreviousPage 62 / 112Next
All practice questions — CompTIA Network+ | Examkin