All practice questions
2237 questions
An IT security administrator needs to implement a full-tunnel remote access VPN solution for traveling employees. The primary constraint is that these employees frequently connect from restrictive public Wi-Fi networks and hotels where firewalls block non-standard outbound ports as well as native IPsec protocols (such as IKE UDP 500/4500 and ESP). The chosen protocol must provide complete network-layer access to internal IP subnets while seamlessly encapsulating traffic over standard HTTPS. Which of the following VPN technologies best fulfills these requirements?
A network administrator is investigating four separate wireless connectivity issues across an enterprise site. Match each observed wireless symptom or telemetry anomaly to its primary root cause.
Click a left item, then click its matching right item
Items
Matches
A network engineer is configuring a remote access Virtual Private Network (VPN) solution using Layer 2 Tunneling Protocol over IPsec (L2TP/IPsec) for corporate users. Which of the following technical characteristics and operational requirements correctly apply to this deployment? (Select TWO.)
Select all that apply
A network engineer is troubleshooting a 75-meter Category 6 (Cat6) unshielded twisted-pair (UTP) link connecting a core switch to a distribution switch. Under load, the interface experiences high frame corruption and periodic link dropping. A basic wiremapper confirms that all eight conductors are pinned correctly according to TIA/EIA-568B with continuous electrical connectivity and no open circuits or shorts. The engineer suspects a structural wire break or severe impedance anomaly located inside the building conduit between floors. Which diagnostic instrument must the engineer use to determine the exact distance along the cable run where the physical defect is located?
An administrator notices that servers mounted in the middle of several server rack rows are experiencing thermal warnings during peak utilization. Environmental monitoring reveals that cool supply air from raised floor vents is mixing directly with hot exhaust air from adjacent equipment rows prior to entering server intake fans. Which physical infrastructure design change should the network administrator implement to prevent this air mixing?
An enterprise network team prepares to update the operating system across central distribution switches to patch a critical security flaw. The lead engineer submits a formal Request for Change (RFC) to the Change Advisory Board (CAB). After evaluating the submission, the CAB rejects the RFC. Which of the following omissions in the RFC is the most likely reason for the board's rejection?
A network engineer troubleshooting a loss of network redundancy on a core switch stack has confirmed that a mismatched VTP domain configuration was the root cause by successfully validating the hypothesis in a staging lab. Following the CompTIA troubleshooting methodology, the engineer is now advancing to the immediate NEXT phase before implementing any modifications on the production network. Which of the following actions should the engineer perform during this phase? (Select TWO.)
Select all that apply
A network technician is troubleshooting a client workstation that cannot connect to a local server by hostname. To determine where the resolution process fails, arrange the name resolution mechanisms in the exact sequence the host operating system attempts them, from FIRST to LAST.
Drag items to arrange them in the correct order
A network technician is troubleshooting poor wireless performance, excessive frame retransmissions, and intermittent connectivity dropouts across an office floor using three access points operating on the 2.4 GHz band. A site survey reveals that adjacent access points are currently assigned to Channel 1, Channel 3, and Channel 5. Which TWO actions should the technician take to resolve the radio frequency interference and stabilize the wireless network?
Select all that apply
A network technician receives reports that workstations on a local subnet are unable to access an internal intranet web server using its hostname `intranet.corp.local`, though connecting directly via IP address works properly. When executing `dig intranet.corp.local` from a workstation, the utility outputs `;; QUESTION SECTION: ;intranet.corp.local. IN A` followed by `;; AUTHORITY SECTION: corp.local. 3600 IN SOA ns1.corp.local. admin.corp.local. (...)` and zero answers in the `ANSWER SECTION`. Which of the following potential root causes and verification steps are valid for troubleshooting this issue? (Select TWO.)
Select all that apply
A network engineer is responding to reports of intermittent application session resets occurring across a hybrid cloud IPsec tunnel following a recent router firmware patch. Place the technician's troubleshooting procedures in the precise order required by the official CompTIA troubleshooting methodology, from the initial action to the final action.
Drag items to arrange them in the correct order
A network security administrator is tasked with baseline hardening for a newly installed Layer 3 enterprise switch before connecting it to the production network. Corporate security compliance mandates that the configuration must mitigate double-tagging VLAN hopping attacks on trunk connections, prevent unauthorized access on unassigned physical ports, and protect administrative sessions from eavesdropping and tampering. Which set of device hardening measures best meets these requirements?
A network administrator is investigating reports that internal workstations are unable to connect to a web application at `payroll.internal.net`. To diagnose the issue, the administrator executes a hostname lookup using `nslookup` on a client machine, which returns the following output:
text
$ nslookup payroll.internal.net
Server: 10.1.1.5
Address: 10.1.1.5#53
Name: payroll.internal.net
Alias: app-server-04.internal.net
*** 10.1.1.5 can't find app-server-04.internal.net: Non-existent domain (NXDOMAIN)
Which of the following represents the primary root cause of this name resolution failure?
A network administrator is designing security controls for an enterprise application that transmits customer records across an untrusted network. The security policy dictates that the solution must prevent unauthorized eavesdropping on the payload content while also ensuring any unauthorized modifications to the data during transit are detected. Which TWO of the following security measures directly address these requirements?
Select all that apply
Match each wireless network symptom described on the left with its primary physical or radio frequency (RF) root cause on the right.
Click a left item, then click its matching right item
Items
Matches
An IT manager is reviewing a proposed wireless network implementation for a corporate office. The security policy mandates individual user accountability through centralized 802.1X RADIUS authentication alongside mandatory Protected Management Frames. The installation team proposes deploying WPA3-Personal with a robust shared passphrase to streamline client onboarding. Which of the following statements best evaluates this proposal against the organization's requirements?
A network technician is troubleshooting a workstation that lost connectivity to the local intranet. The technician established a hypothesis that a recently disabled network port was the cause and conducted tests that confirmed this theory. According to the CompTIA troubleshooting methodology, which of the following actions should the technician take NEXT?
A system administrator notices that log events from the client subnet are not reaching the central Syslog server located at . An extended IPv4 Access Control List (ACL) applied inbound on the router interface serving the client subnet contains the following entries:
access-list 105 permit tcp 10.100.20.0 0.0.0.255 host 192.168.10.50 eq 514
access-list 105 permit udp 10.100.20.0 0.0.0.255 host 192.168.10.50 eq 161
access-list 105 deny ip any any
Which configuration error is preventing the log messages from reaching the Syslog server?
A workstation on a corporate network cannot reach a web server located on a remote subnet. Arrange the following diagnostic steps in the correct logical sequence to systematically isolate whether the connectivity issue stems from local TCP/IP settings, the local default gateway, path routing, or router Access Control Lists (ACLs).
Drag items to arrange them in the correct order
A network administrator is reviewing security logs for remote employees connecting to the corporate network via a client-based Remote Access Virtual Private Network (VPN). The administrator discovers that while remote users can access internal private servers, their web browsing traffic to external internet sites is being routed directly through their local home internet service providers rather than through the corporate firewall and web content filter. Which of the following configuration settings on the VPN concentrator or client profile should the administrator modify to ensure all network traffic from remote clients is routed through the secure tunnel?