All practice questions

2237 questions

Question 1721Question

Match each IEEE 802.11 wireless standard with its defining operational frequency and key technical capability.

Click a left item, then click its matching right item

Items

IEEE 802.11b
IEEE 802.11a
IEEE 802.11n
IEEE 802.11ac

Matches

Show answer & explanation

Answer

IEEE 802.11b matches 2.4 GHz / 11 Mbps DSSS; IEEE 802.11a matches 5 GHz / 54 Mbps OFDM; IEEE 802.11n matches dual-band operation with MIMO; IEEE 802.11ac matches 5 GHz operation with MU-MIMO and 160 MHz channel bonding.
Each standard is accurately matched to its specified frequency band, modulation/stream capabilities, and theoretical speed limits: 802.11b (2.4 GHz, 11 Mbps), 802.11a (5 GHz, 54 Mbps), 802.11n (2.4/5 GHz dual-band with MIMO), and 802.11ac (5 GHz with MU-MIMO and up to 160 MHz channels).

Step-by-Step Solution

1
Identify legacy single-band standards
IEEE 802.11b is matched with 2.4 GHz / 11 Mbps, while IEEE 802.11a is matched with 5 GHz / 54 Mbps.
802.11b and 802.11a were the original legacy wireless standards established for 2.4 GHz and 5 GHz bands respectively.
2
Identify high-throughput dual-band standard
IEEE 802.11n is paired with dual-band operation and MIMO capability.
802.11n was the first Wi-Fi standard designed to operate in both 2.4 GHz and 5 GHz frequency bands simultaneously while introducing MIMO antenna streams.
3
Identify Very High Throughput 5 GHz standard
IEEE 802.11ac is paired with 5 GHz MU-MIMO and 160 MHz channel bonding.
802.11ac focused exclusively on enhancing 5 GHz performance using wider channels and multi-user MIMO technology.

Key Concept

Wireless IEEE 802.11 Standards and Operational Frequencies
Question 1722Question

An organization needs to connect 150 internal workstations on the 172.16.10.0/24172.16.10.0/24 private subnet to external web services simultaneously. The Internet Service Provider (ISP) has allocated only a single public IPv4 address (198.51.100.25198.51.100.25) to the perimeter router's WAN interface. Which address translation method must be configured on the router to meet these requirements by mapping multiple private IP addresses to unique source port numbers on the shared public IP address?

Show answer & explanation

Answer: Port Address Translation (PAT / NAT Overload)

Answer

Port Address Translation (PAT / NAT Overload) must be configured on the router.
Port Address Translation (PAT), also referred to as NAT Overload, is designed specifically for scenarios where multiple internal hosts with private IPv4 addresses must share one or a few public IPv4 addresses. PAT achieves this by translating both the Layer 3 IP address and the Layer 4 TCP/UDP port numbers. Each outbound session from an internal workstation receives a unique ephemeral source port tied to the single public IP address (198.51.100.25198.51.100.25), allowing the router's translation table to correctly forward returning traffic to the originating host.

Step-by-Step Solution

1
Analyze internal host counts and external public IPv4 address availability
150 private hosts (172.16.10.0/24172.16.10.0/24) require internet access, but only one public IPv4 address (198.51.100.25198.51.100.25) is provided.
Because the ratio of internal hosts to external IP addresses is many-to-one, 1:1 mapping techniques cannot be used.
2
Evaluate mapping requirements at OSI Layer 3 and Layer 4
Multiplexing multiple private IP addresses over a single public IP address requires tracking connections using unique Layer 4 source port numbers (TCP/UDP).
Layer 4 port tracking allows the router to differentiate returning traffic for each of the 150 internal workstations.
3
Identify the standard technology used for many-to-one address translation
Port Address Translation (PAT), also known as NAT Overload, matches this exact functional capability.
PAT translates the private IP and original source port into the public IP and a unique allocated source port.

Key Concept

Port Address Translation (PAT / NAT Overload)
Question 1723Question

A system administrator is preparing to deploy several new 2U hypervisor hosts and a high-density storage array into an existing server room enclosure. Before unboxing the hardware, the administrator needs to inspect a document that details physical rack unit space allocations, power distribution unit (PDU) port assignments, and device dimensions within the enclosure. Which of the following network documentation types should the administrator consult?

Show answer & explanation

Answer: Rack elevation diagram

Answer

Rack elevation diagram
A rack elevation diagram provides an accurate scale drawing showing the vertical positioning (in Rack Units or U) of servers, switches, patch panels, and power distribution units within an equipment rack. This makes it the essential document for planning equipment installations and physical layout inside server enclosures.

Step-by-Step Solution

1
Analyze the administrator's requirement
The scenario calls for reviewing physical space allocations, equipment heights (in rack units), and cabinet PDU port locations.
Identifying the specific attributes required (physical rack footprint vs protocol layout) isolates the appropriate documentation type.
2
Evaluate documentation types against the physical cabinet requirement
Rack elevation diagrams provide a 2D front/rear view of server enclosures detailing unit height positions and physical layout.
This visual layout prevents physical mounting collisions and ensures planned power/space utilization is verified before installation.

Key Concept

Rack Elevation Diagrams and Physical Documentation
Estimated Time:1m 0s
Question 1724Question

A network administrator is deploying three neighboring wireless access points within an office floor plan operating on the 2.4 GHz frequency band. To minimize co-channel and adjacent-channel interference, which set of channels should be assigned to these access points?

Show answer & explanation

Answer: Channels 1, 6, and 11

Answer

Channels 1, 6, and 11
In 2.4 GHz wireless networks, channels 1, 6, and 11 are the three standard non-overlapping channels. Because each channel requires 20 MHz of bandwidth and channel centers are spaced 5 MHz apart, a separation of 5 channel numbers (25 MHz center-to-center spacing) is required to eliminate adjacent-channel interference.

Step-by-Step Solution

1
Identify the operating band and channel bandwidth
The network operates on the 2.4 GHz band where 20 MHz wide channels are spaced 5 MHz apart.
Understanding the channel spacing of 2.4 GHz is necessary to calculate channel overlap.
2
Select non-overlapping channels
Channels 1, 6, and 11 have 25 MHz separation between their center frequencies, ensuring zero channel overlap.
Using non-overlapping channels prevents adjacent-channel interference across neighboring coverage cells.

Key Concept

2.4 GHz Non-Overlapping Channels
Question 1725Question

A network engineer is configuring a multi-access point wireless deployment operating in the 2.4 GHz band for an enterprise office in North America. To optimize spectrum utilization, prevent adjacent-channel interference (ACI), and effectively manage co-channel interference (CCI) across adjacent coverage cells, which of the following deployment strategies should be implemented? (Select TWO.)

Select all that apply

Show answer & explanation

Answer: Restrict 2.4 GHz channel assignments strictly to non-overlapping channels 1, 6, and 11 across neighboring access points.; Lower the transmission power levels on the 2.4 GHz radios of adjacent access points.

Answer

The engineer should restrict 2.4 GHz radio assignments strictly to non-overlapping channels 1, 6, and 11 across neighboring access points, and lower transmission power levels on the 2.4 GHz radios to shrink coverage cells and mitigate co-channel interference.
Restricting 2.4 GHz radio assignments strictly to non-overlapping channels 1, 6, and 11 ensures that neighboring cells do not cause adjacent-channel interference (ACI). Furthermore, lowering the transmission power on 2.4 GHz radios reduces the coverage radius of each cell, preventing co-channel interference (CCI) between access points that reuse the same channel across a multi-AP facility.

Step-by-Step Solution

1
Analyze 2.4 GHz spectrum boundaries and channel width parameters.
Recognize that 2.4 GHz Wi-Fi channels are 20 MHz wide but separated by only 5 MHz center frequencies. Non-overlapping deployment in North America requires a minimum 25 MHz separation, which leaves only channels 1, 6, and 11.
Deploying overlapping channels causes adjacent-channel interference, preventing access points from decoding frame preambles cleanly.
2
Evaluate cell sizing and channel reuse strategy.
Determine that reducing radio transmission power shrinks cell boundaries.
Smaller cells prevent distant access points sharing the same non-overlapping channel from contending for the medium, directly reducing co-channel interference (CCI).

Key Concept

Wireless 2.4 GHz Channel Planning and Power Management
Estimated Time:2m 0s
Question 1726Question

Three switches—S1, S2, and S3—are connected in a triangular physical topology using standard IEEE 802.1D Spanning Tree Protocol (STP):

- S1 has a Bridge Priority of 4096 and MAC address 00:11:22:33:44:55.
- S2 has a Bridge Priority of 32768 and MAC address 00:AA:BB:CC:DD:EE.
- S3 has a Bridge Priority of 32768 and MAC address 00:AA:BB:CC:DD:FF.

Link speeds and default STP path costs are configured as follows:
- The link between S1 and S2 is 1 Gbps (STP Cost = 4).
- The link between S2 and S3 is 1 Gbps (STP Cost = 4).
- The link between S1 and S3 is 100 Mbps (STP Cost = 19).

Based on STP operations, which TWO of the following statements accurately describe port role determinations and traffic paths in this network?

Select all that apply

Show answer & explanation

Answer: Switch S3 selects its interface connected to Switch S2 as its Root Port because the cumulative path cost to the Root Bridge via S2 is 8, which is lower than the direct path cost of 19.; Switch S2's interface on the link connecting S2 and S3 assumes the Designated Port role because Switch S2 advertises a lower Root Path Cost to the segment than Switch S3.

Answer

The two correct statements are that Switch S3 selects its interface connected to Switch S2 as its Root Port (due to a lower cumulative path cost of 8 versus 19), and that Switch S2's interface on the link to Switch S3 becomes the Designated Port (because S2 has a lower advertised root path cost than S3).
In standard IEEE 802.1D STP, non-root switches elect their Root Port based on the lowest cumulative root path cost to the Root Bridge. Switch S1 is the Root Bridge due to its priority of 4096. Switch S3 evaluates two paths to S1: the direct 100 Mbps link with a cost of 19, and the path through Switch S2 (1 Gbps + 1 Gbps) with a cumulative cost of 4 + 4 = 8. Because 8 is less than 19, S3 selects its interface toward S2 as its Root Port. Furthermore, for the segment connecting S2 and S3, S2 advertises a Root Path Cost of 4 while S3 advertises a Root Path Cost of 8. Since S2 advertises a lower root path cost, S2's interface on that segment is elected as the Designated Port.

Step-by-Step Solution

1
Determine the Root Bridge
Switch S1 is elected Root Bridge because it has the lowest Bridge Priority (4096 < 32768). All active ports on S1 become Designated Ports in the Forwarding state.
STP elects the bridge with the lowest Bridge ID (Priority + MAC) as the Root Bridge.
2
Calculate Root Path Costs for Switch S2 and Switch S3
S2 direct path cost to S1 = 4. S3 path cost via S1 (direct 100 Mbps) = 19; S3 path cost via S2 (1 Gbps + 1 Gbps) = 4 + 4 = 8.
Root path cost is cumulative, adding incoming port path costs along the shortest path back to the Root Bridge.
3
Assign Root Ports for non-root switches
S2's port to S1 becomes S2's Root Port (cost 4). S3's port to S2 becomes S3's Root Port (cost 8 < 19).
Each non-root switch chooses one port with the lowest cumulative root path cost as its Root Port.
4
Determine Designated Port on the S2-S3 segment and remaining port roles
S2 advertises cost 4, S3 advertises cost 8. S2 wins the segment, so S2's port on the S2-S3 link is Designated. S3's port connected directly to S1 goes into Blocking state (non-designated).
The switch advertising the lower root path cost onto a shared segment wins the Designated Port role.

Key Concept

STP Root Port & Designated Port Path Cost Calculations
Question 1727Question

Match each Network Address Translation (NAT) term on the left with its correct operational description or mapping behavior on the right.

Click a left item, then click its matching right item

Items

Inside Local Address
Inside Global Address
Port Address Translation (PAT)
Static NAT

Matches

Show answer & explanation

Answer

Inside Local Address matches the private IPv4 address assigned to an internal host. Inside Global Address matches the public IPv4 address representing an internal host externally. Port Address Translation (PAT) matches mapping multiple private IP addresses to a single public IP address using unique port numbers. Static NAT matches a fixed 1-to-1 mapping between a private IP address and a public IP address.
Inside Local is the private address assigned to an internal host. Inside Global is the public address that represents an internal host externally. Port Address Translation (PAT) maps multiple private IP addresses to a single public address using Layer 4 port numbers. Static NAT establishes a fixed 1-to-1 translation between a private IP address and a public IP address.

Step-by-Step Solution

1
Identify the internal addressing terms used in Cisco and standard networking terminology.
'Inside Local' represents the actual address assigned to a device on the internal network (private IP), whereas 'Inside Global' represents how that same device appears to external networks (public IP).
Understanding the four NAT address types (Inside Local, Inside Global, Outside Local, Outside Global) is essential for proper routing and address translation configuration.
2
Analyze translation mechanisms for scaling and hosting.
Static NAT provides a static, permanent 1-to-1 mapping suited for inbound accessibility (servers), while PAT uses Layer 4 port identifiers to multiplex multiple private hosts onto one public IP address.
Differentiating between 1-to-1 static NAT and many-to-1 dynamic PAT (Overload) ensures efficient IPv4 pool usage based on enterprise requirements.

Key Concept

NAT Terminology and Address Translation Types
Question 1728Question

A network specialist is establishing remote out-of-band access for a core router stationed at a remote datacenter. The solution must allow administrators to access the router's CLI interface to troubleshoot system failures even if the primary WAN interface and local network operating system crash. Which of the following implementations best meets these requirements?

Show answer & explanation

Answer: Connecting a cellular-enabled terminal console server directly to the router's serial console port.

Answer

Connecting a cellular-enabled terminal console server directly to the router's serial console port provides dedicated out-of-band management independent of primary network links.
Out-of-band management provides a distinct physical or logical pathway—such as a cellular modem paired with a console server attached to the router's RS-232 serial console port—enabling command-line access even when primary WAN links or local interface drivers are unavailable.

Step-by-Step Solution

1
Identify the operational constraint and access requirement.
The solution requires access during total WAN failure and network OS crashes.
In-band solutions (like SSH or SNMP over primary Ethernet interfaces) rely on active network interfaces and running OS stacks, which fail during major link or system outages.
2
Evaluate alternative management channels.
Out-of-band (OOB) management using a dedicated cellular modem and console server bypasses the production network.
Connecting directly to the serial console port allows low-level CLI access regardless of internal IP interface status.

Key Concept

Out-of-Band (OOB) Management
Question 1729Question

A network administrator is performing a post-implementation audit following a data center refresh. The project involved mounting new modular switches into equipment enclosures, re-allocating server rack unit (UU) space, and establishing new VLAN subnets with associated gateway interfaces across multiple switches. The administrator needs to update the core network documentation to accurately record both the physical enclosure layouts and the Layer 3 IP routing and VLAN structures. Which of the following documentation artifacts should the administrator update to fulfill these specific requirements? (Select TWO).

Select all that apply

Show answer & explanation

Answer: Rack elevation diagram; Logical network topology diagram

Answer

The administrator must update the rack elevation diagram to document physical rack space utilization and equipment placement, and the logical network topology diagram to document VLAN IDs, IP subnetting, and Layer 3 interfaces.
Updating both the rack elevation diagram and the logical topology diagram fulfills all specified audit requirements. The rack elevation diagram documents physical hardware positioning, height allocations (UU), and enclosure placement. The logical topology diagram documents non-physical relationships, including VLAN segment IDs, IP subnetting schemes, and Layer 3 gateway relationships.

Step-by-Step Solution

1
Identify the physical documentation requirement in the scenario.
The requirement specifies recording physical enclosure equipment placement and rack unit (UU) space utilization.
Rack elevation diagrams specifically show the vertical positioning and unit spacing of hardware components inside server racks.
2
Identify the logical documentation requirement in the scenario.
The requirement specifies recording IP subnetting, VLAN boundaries, and gateway routing interfaces.
Logical network topology diagrams describe data paths, IP address allocations, VLAN configurations, and routing relationships independent of physical cabling layouts.

Key Concept

Distinguishing between physical rack diagrams and logical topology diagrams in network documentation
Question 1730Question

A network engineer is configuring Neighbor Discovery protocol settings on an enterprise VLAN. A server interface has been assigned the IPv6 global unicast address 2001:db8:1111:2222:4567:89ab:cdef:12342001:\text{db8}:1111:2222:4567:89\text{ab}:\text{cdef}:1234. Which solicited-node multicast address will the server interface automatically join to enable Layer 2 address resolution?

Show answer & explanation

Answer: ff02::1:ffef:1234

Answer

The server interface will automatically join the solicited-node multicast address ff02::1:ffef:1234.
The correct answer combines the mandatory solicited-node multicast prefix ff02::1:ff00:0/104 with the last 24 bits (6 hexadecimal characters) of the server's unicast address cdef:1234, yielding ff02::1:ffef:1234.

Step-by-Step Solution

1
Identify the standard IPv6 solicited-node multicast prefix
The predefined prefix for all solicited-node multicast addresses is ff02::1:ff00:0/104ff02::1:ff00:0/104.
Solicited-node multicast addresses are required by Neighbor Discovery Protocol (NDP) to replace broadcast ARP in IPv6 networks.
2
Extract the low-order 24 bits from the assigned IPv6 address
The final 32 bits of 2001:db8:1111:2222:4567:89ab:cdef:12342001:\text{db8}:1111:2222:4567:89\text{ab}:\text{cdef}:1234 are cdef:1234\text{cdef}:1234. Taking the last 24 bits (6 hex digits) yields ef1234ef1234.
Solicited-node address construction strictly appends the last 24 bits of the host unicast/anycast address to the prefix.
3
Combine the prefix and extracted 24 bits
Appending ef1234ef1234 to ff02::1:ff00:0/104ff02::1:ff00:0/104 gives ff02::1:ffef:1234ff02::1:ffef:1234.
This creates a unique multicast group mapped to the specific network interface for efficient Neighbor Solicitation processing.

Key Concept

IPv6 Solicited-Node Multicast Address Generation
Estimated Time:1m 30s
Question 1731Question

A network administrator needs to perform a complete system restoration following a server failure on Thursday morning. The backup schedule performs a full backup every Sunday night and cumulative backups of all data changed since Sunday on each subsequent night. To restore the server, the administrator restores Sunday's full backup followed immediately by Wednesday night's backup. Which type of backup was restored alongside the full backup?

Show answer & explanation

Answer: Differential backup

Answer

Differential backup
A differential backup captures all data that has changed since the most recent full backup. Because each differential backup accumulates all changes made since the full backup, a full system restore requires only two items: the baseline full backup and the single most recent differential backup file.

Step-by-Step Solution

1
Analyze the restoration process described in the scenario.
The administrator restored the initial full backup from Sunday and only one subsequent file from Wednesday night.
Determining the number of backup sets required for recovery differentiates differential backups from incremental backups.
2
Apply backup strategy definitions.
Because Wednesday's file contained all cumulative changes since Sunday, restoring Sunday's full backup plus Wednesday's file completes recovery. This defines a differential backup strategy.
An incremental backup strategy would have required restoring Monday, Tuesday, and Wednesday backups in sequential order.

Key Concept

Differential vs. Incremental Backup Restoration Strategies
Question 1732Question

A network operations team is updating its disaster recovery plan documentation. How should the team arrange the following recovery site solutions in order from shortest Recovery Time Objective (RTO) to longest Recovery Time Objective (RTO)?

Drag items to arrange them in the correct order

Show answer & explanation

Answer

The correct order from shortest to longest RTO is: Hot site with active-active server cluster, followed by Warm site with pre-installed network hardware, and finally Cold site with physical facility only.
A hot site has live data and equipment ready for immediate takeover, providing the shortest RTO. A warm site has infrastructure staged but requires backup data to be restored, resulting in a moderate RTO. A cold site provides only basic environmental controls and space, requiring full hardware provisioning and setup, which results in the longest RTO.

Step-by-Step Solution

1
Determine which site model provides immediate operational readiness.
A hot site maintains active hardware and synchronized data, yielding the shortest RTO.
Near-instantaneous failover minimizes downtime.
2
Determine which site model has hardware installed but requires operational restoration.
A warm site has network equipment ready, but requires data restoration, making its RTO moderate.
Restoring data takes hours rather than minutes.
3
Determine which site model lacks operational networking equipment.
A cold site requires bringing in equipment, cabling, and configuring systems, leading to the longest RTO.
Full hardware setup and configuration takes days or weeks.

Key Concept

Disaster Recovery Site Selection and Recovery Time Objective (RTO)
Question 1733Question

A network administrator has just completed testing a theory and confirmed that an incorrect Maximum Transmission Unit (MTU) setting on an edge router interface is causing packet fragmentation and dropping encrypted site-to-site IPsec VPN traffic. Following the CompTIA troubleshooting methodology, the administrator is now preparing to transition to the phase of establishing a plan of action and implementing the solution. Which of the following specific tasks should be performed during this phase? (Select TWO.)

Select all that apply

Show answer & explanation

Answer: Assess potential side effects and impacts on downstream network services before applying configuration modifications.; Draft a step-by-step implementation procedure alongside a roll-back contingency plan in case issues arise during execution.

Answer

The technician must assess potential side effects on downstream network services and draft a detailed step-by-step implementation plan with rollback contingency steps.
According to the CompTIA troubleshooting methodology, after a theory is confirmed in Step 3, the technician proceeds to Step 4: 'Establish a plan of action to resolve the problem and implement the solution.' This step explicitly requires identifying potential effects on existing systems, designing a clear step-by-step implementation procedure, and formulating a rollback contingency plan.

Step-by-Step Solution

1
Identify current phase in CompTIA Troubleshooting Methodology
The technician has confirmed the theory (Step 3 complete) and is entering Step 4: Establish a plan of action to resolve the problem and implement the solution.
Once a theory of probable cause is verified, the technician moves to planning and implementation.
2
Differentiate tasks belonging strictly to Step 4 from subsequent steps
Step 4 encompasses identifying potential side effects, creating an action plan, writing rollback procedures, and executing the solution.
Proper change management requires risk analysis and rollback plans before implementation.
3
Select valid Step 4 actions
Assessing impact on downstream services and creating step-by-step rollout and fallback procedures belong in Step 4.
System testing (Step 5) and documentation logging (Step 6) occur later in the troubleshooting process.

Key Concept

CompTIA Troubleshooting Methodology - Plan of Action & Implementation
Question 1734Question

A network administrator partitions the IPv4 block 192.168.50.0/24192.168.50.0/24 into subnets with a /27/27 prefix length. Which of the following IP addresses represent valid usable host addresses within the third subnet block? (Select TWO.)

Select all that apply

Show answer & explanation

Answer: 192.168.50.67192.168.50.67; 192.168.50.90192.168.50.90

Answer

The valid usable host addresses for the third /27/27 subnet are 192.168.50.67192.168.50.67 and 192.168.50.90192.168.50.90.
For the allocated block 192.168.50.0/24192.168.50.0/24, partitioning with a /27/27 subnet mask creates blocks of 32 IP addresses. The third subnet spans from 192.168.50.64192.168.50.64 to 192.168.50.95192.168.50.95. Subtracting the network ID (192.168.50.64192.168.50.64) and broadcast address (192.168.50.95192.168.50.95) yields the valid host IP range 192.168.50.65192.168.50.65 through 192.168.50.94192.168.50.94. Therefore, 192.168.50.67192.168.50.67 and 192.168.50.90192.168.50.90 are correct valid host IP assignments.

Step-by-Step Solution

1
Determine the block size for a /27/27 subnet mask.
A /27/27 mask gives 3227=532 - 27 = 5 host bits. Block size =25=32= 2^5 = 32 addresses.
Calculating block size establishes the boundary boundaries for consecutive subnets.
2
Calculate network ranges for the first three subnets starting from 192.168.50.0192.168.50.0.
Subnet 1: 192.168.50.0192.168.50.31192.168.50.0 - 192.168.50.31, Subnet 2: 192.168.50.32192.168.50.63192.168.50.32 - 192.168.50.63, Subnet 3: 192.168.50.64192.168.50.95192.168.50.64 - 192.168.50.95.
Identifying the third subnet boundaries isolates the specific address range being evaluated.
3
Determine the usable host IP address range for the third subnet.
Network ID: 192.168.50.64192.168.50.64, Broadcast Address: 192.168.50.95192.168.50.95, Usable Range: 192.168.50.65192.168.50.65 to 192.168.50.94192.168.50.94.
Usable host addresses exclude the first address (Network ID) and last address (Broadcast) of the block.
4
Compare given choices against the usable host IP address range.
192.168.50.67192.168.50.67 and 192.168.50.90192.168.50.90 fall within 192.168.50.65192.168.50.94192.168.50.65 - 192.168.50.94, whereas 192.168.50.64192.168.50.64 and 192.168.50.95192.168.50.95 are network/broadcast addresses.
Confirms which addresses can actually be statically assigned to network host interfaces.

Key Concept

IPv4 Subnet Boundaries & Usable Host Ranges
Question 1735Question

Four switches are deployed in a single LAN segment running IEEE 802.1D Spanning Tree Protocol (STP). The bridge configuration settings for each switch are as follows:

- Switch-1: Bridge Priority = 3276832768, MAC Address = `00:11:22:33:44:55`
- Switch-2: Bridge Priority = 40964096, MAC Address = `00:AA:BB:CC:DD:EE`
- Switch-3: Bridge Priority = 81928192, MAC Address = `00:11:22:11:22:33`
- Switch-4: Bridge Priority = 40964096, MAC Address = `00:AA:BB:CC:DD:AA`

When the switches finish initialization, which switch is elected as the STP Root Bridge, and for what reason?

Show answer & explanation

Answer: Switch-4, because it ties for the lowest bridge priority of 40964096 and possesses the lower MAC address tie-breaker.

Answer

Switch-4 is elected as the Root Bridge because it ties for the lowest priority value (40964096) and has a lower MAC address (`00:AA:BB:CC:DD:AA`) than Switch-2 (`00:AA:BB:CC:DD:EE`).
In IEEE 802.1D Spanning Tree Protocol, the Root Bridge election process evaluates the Bridge Identifier (BID), which combines a 2-byte Bridge Priority and a 6-byte MAC address. The switch with the lowest BID becomes the Root Bridge. Priority is evaluated first; both Switch-2 and Switch-4 have the lowest priority (40964096). To break the tie, STP compares MAC addresses. Comparing `00:AA:BB:CC:DD:AA` (Switch-4) and `00:AA:BB:CC:DD:EE` (Switch-2), Switch-4 has the smaller MAC address and is successfully elected as the Root Bridge.

Step-by-Step Solution

1
Evaluate Bridge Priority values for all candidate switches.
Switch-2 (40964096) and Switch-4 (40964096) share the lowest numerical bridge priority value.
STP Root Bridge election strictly prioritizes the lowest Bridge Priority (Bridge ID = Priority + MAC Address).
2
Compare MAC addresses as a tie-breaker between Switch-2 and Switch-4.
Switch-4 (`00:AA:BB:CC:DD:AA`) is numerically lower than Switch-2 (`00:AA:BB:CC:DD:EE`).
When bridge priorities are identical, the switch with the lowest MAC address breaks the tie to determine the Root Bridge.

Key Concept

STP Root Bridge Election Order (Priority then MAC Address)
Estimated Time:1m 15s
Question 1736Question

A network systems engineer is troubleshooting client connection behavior for an enterprise Voice over IP (VoIP) deployment. Telephony endpoints issue a DNS query to discover available Session Initiation Protocol (SIP) servers for the domain `voip.example.com`. The engineer executes a `dig` command from a test workstation and receives the following response:

text
;; QUESTION SECTION:
;_sip._tcp.voip.example.com. IN SRV

;; ANSWER SECTION:
_sip._tcp.voip.example.com. 3600 IN SRV 10 60 5060 pbx1.voip.example.com.
_sip._tcp.voip.example.com. 3600 IN SRV 10 20 5060 pbx2.voip.example.com.
_sip._tcp.voip.example.com. 3600 IN SRV 20 100 5060 pbx3.voip.example.com.

Based on the RFC-standard evaluation rules for DNS SRV records, which of the following statements accurately describes how client traffic will be distributed across these servers under normal operating conditions?

Show answer & explanation

Answer: Clients will attempt connection to pbx1.voip.example.com approximately 75% of the time and pbx2.voip.example.com 25% of the time, keeping pbx3.voip.example.com as a standby backup.

Answer

Clients will attempt connection to pbx1.voip.example.com approximately 75% of the time and pbx2.voip.example.com 25% of the time, keeping pbx3.voip.example.com as a standby backup.
DNS SRV records (RFC 2782) utilize two fields for server selection: Priority and Weight. Clients must attempt target hosts starting with the lowest numerical Priority value. Here, `pbx1.voip.example.com` and `pbx2.voip.example.com` both have a Priority of 10, making them preferred over `pbx3.voip.example.com` (Priority 20). Among targets with equal priority, clients select targets proportionally based on their Weight values. The combined weight for Priority 10 targets is 60+20=8060 + 20 = 80. Thus, `pbx1` receives 6080=75%\frac{60}{80} = 75\% of initial connection attempts and `pbx2` receives 2080=25%\frac{20}{80} = 25\%. Server `pbx3` will only be contacted if both Priority 10 servers fail.

Step-by-Step Solution

1
Evaluate the Priority field in the SRV record output
Servers pbx1 and pbx2 have a Priority value of 10, while pbx3 has a Priority value of 20.
Per RFC 2782, clients must attempt to contact target host with the lowest numbered priority first. Therefore, pbx1 and pbx2 are preferred primary targets, and pbx3 serves as a secondary backup target.
2
Calculate load balancing proportions using the Weight field for equal-priority targets
Total weight for Priority 10 targets = 60 (pbx1) + 20 (pbx2) = 80.
When multiple targets have the same priority value, clients distribute traffic probabilistically according to relative weight ratios.
3
Determine exact traffic allocation percentages for pbx1 and pbx2
pbx1 allocation = 60 / 80 = 75%; pbx2 allocation = 20 / 80 = 25%.
Dividing each server's weight by the combined weight sum of that priority group determines the expected connection ratio.

Key Concept

DNS SRV Record Structure and Priority/Weight Traffic Distribution
Question 1737Question

A network administrator is troubleshooting connectivity between internal network monitoring tools on subnet 10.80.4.0/2410.80.4.0/24 and an application server at 10.80.12.5010.80.12.50. The administrator configured an inbound extended Access Control List (ACL) on the router interface facing the monitoring subnet with only the following active rules:

- `permit tcp 10.80.4.0 0.0.0.255 host 10.80.12.50 eq 80`
- `permit tcp 10.80.4.0 0.0.0.255 host 10.80.12.50 eq 443`

While HTTP and HTTPS traffic reach the server successfully, ICMP echo requests (ping) sent from the monitoring tools to 10.80.12.5010.80.12.50 fail. Which of the following best explains why the ICMP traffic is being dropped?

Show answer & explanation

Answer: The ACL ends with an implicit deny rule that automatically blocks all traffic not explicitly permitted by a prior rule.

Answer

The ACL ends with an implicit deny rule that automatically blocks all traffic not explicitly permitted by a prior rule.
Every network Access Control List (ACL) features an default, invisible 'implicit deny all' rule at the very end of the rule list. When ICMP traffic arrives at the router interface, it is evaluated against the explicit entries. Because the only configured entries permit TCP traffic destined for ports 80 and 443, ICMP traffic fails to match any permit rule and is discarded by the implicit deny statement.

Step-by-Step Solution

1
Analyze the configured ACL rules
The ACL contains explicit permit entries strictly for TCP destination ports 80 (HTTP) and 443 (HTTPS).
Understanding which protocols and ports are permitted helps identify unhandled packet types.
2
Identify the protocol used by the failing traffic type
Ping utility uses ICMP (Internet Control Message Protocol), which is an IP-level protocol (IP protocol 1) and does not use TCP ports.
Comparing ICMP packet headers against the ACL entries reveals no matching rule.
3
Apply standard ACL processing logic to unmatched traffic
All IP Access Control Lists evaluate matching entries sequentially and terminate with an invisible 'implicit deny ip any any' rule.
Since the ICMP packet does not match Rule 1 or Rule 2, it hits the implicit deny statement at the end of the ACL and is dropped.

Key Concept

ACL Implicit Deny Rule
Question 1738Question

An enterprise network team experiences reports of recurring, intermittent latency spikes on a critical database subnet during peak business hours. A network engineer is tasked with identifying whether current bandwidth utilization, CPU loads, and frame drop counts represent anomalous behavior or typical operational performance under heavy load. Which of the following documentation artifacts should the engineer analyze to make this comparison?

Show answer & explanation

Answer: Network baseline documentation

Answer

The network engineer should analyze the network baseline documentation to evaluate current telemetry metrics against established normal performance benchmarks.
Network baseline documentation provides a historical reference point containing metric trends (such as average latency, CPU/memory usage, and interface utilization) captured during normal operating conditions. Comparing current performance metrics against the baseline allows an engineer to objectively assess whether reported issues stem from unusual system spikes or expected peak utilization.

Step-by-Step Solution

1
Identify the primary troubleshooting objective in the scenario.
The engineer needs to determine if current metrics (latency spikes, CPU load, frame drops) deviate from normal operational thresholds.
Effective performance analysis requires comparing real-time operational data against historical norms.
2
Evaluate the function of network baseline documentation.
Baseline documentation captures historical performance benchmarks collected during standard operation.
Without baseline metrics, it is impossible to quantitatively define what constitutes normal behavior versus an anomaly.
3
Differentiate baseline documentation from topological, physical, or change-tracking artifacts.
Logical topology maps show network structure, wiring schematics detail cabling paths, and change logs list historical maintenance, whereas baselines uniquely capture operational performance trends.
Selecting the correct documentation artifact depends on matching the specific operational requirement to the data stored within that artifact.

Key Concept

Network Baselines and Performance Monitoring Artifacts
Estimated Time:2m 0s
Question 1739Question

A network administrator provisions a new VLAN at a remote office site, routing inter-VLAN traffic through a local Layer 3 switch. Clients connected to the new VLAN are unable to access network resources and receive self-assigned IP addresses starting with 169.254.x.x169.254.x.x. The centralized DHCP server located at the main headquarters has a valid, non-exhausted scope created for the new subnet. Which of the following is the most likely cause of this issue?

Show answer & explanation

Answer: The Layer 3 switch interface serving the new VLAN lacks a DHCP relay agent configuration.

Answer

The Layer 3 switch interface serving the new VLAN lacks a DHCP relay agent configuration.
DHCP DISCOVER messages are sent as Layer 2 broadcast frames. Because routers and Layer 3 switches do not forward broadcast traffic, a DHCP relay agent (or IP helper address) must be enabled on the client-facing gateway interface to convert broadcasts into unicast traffic directed to the remote DHCP server. Without this relay, clients fail to reach the server and fall back to Automatic Private IP Addressing (APIPA).

Step-by-Step Solution

1
Analyze client symptoms and network topology.
Clients receive 169.254.x.x169.254.x.x (APIPA) addresses, indicating DHCP DISCOVER messages are failing to receive a DHCP OFFER from the server across the Layer 3 boundary.
DHCP broadcasts (Layer 2 broadcast destination address FF:FF:FF:FF:FF:FF) are restricted to their local broadcast domain and cannot traverse Layer 3 devices by default.
2
Evaluate the state of the centralized DHCP server.
The server has a configured, active, and unexhausted scope for the target subnet, ruling out server-side scope exhaustion.
If the scope is available and valid, the delivery mechanism between the client broadcast domain and the unicast DHCP server is broken.
3
Identify the required network service to bridge Layer 2 broadcasts across Layer 3 boundaries.
A DHCP relay agent (such as the `ip helper-address` directive) must be configured on the gateway interface to forward broadcast requests as unicast packets to the remote server.
Without a relay agent, DHCP DISCOVER broadcasts are dropped by the Layer 3 interface.

Key Concept

DHCP Relay / IP Helper Operation across Layer 3 Boundaries
Question 1740Question

Match each common network attack type on the left with its corresponding operational mechanism or technical signature on the right.

Click a left item, then click its matching right item

Items

TCP SYN Flood
Smurf Attack
Password Spraying
TLS Downgrade Attack

Matches

Show answer & explanation

Answer

TCP SYN Flood matches exhaustion of the server connection backlog queue; Smurf Attack matches ICMP broadcast amplification with spoofed source addresses; Password Spraying matches testing a single common password across multiple accounts to prevent lockouts; TLS Downgrade Attack matches manipulating negotiations to force legacy encryption protocols.
TCP SYN Flood targets server connection backlogs via unacknowledged SYN packets. Smurf Attack uses ICMP reflection/amplification via broadcast requests with a spoofed source IP address. Password Spraying tests one password against numerous accounts to evade lockout detection. TLS Downgrade Attack manipulates protocol negotiation to force communication over deprecated or weak ciphers.

Step-by-Step Solution

1
Analyze TCP SYN Flood mechanism.
Identified that TCP SYN Floods leverage uncompleted TCP handshakes (SYN sent, ACK never returned) to exhaust host connection buffers.
Understanding transport layer protocol state mechanisms differentiates SYN floods from other DoS methods.
2
Analyze Smurf Attack mechanism.
Identified that Smurf attacks use ICMP echo requests sent to network broadcast addresses with spoofed target IP source headers.
Distinguishing reflection and amplification attacks relies on identifying broadcast targets and spoofed headers.
3
Analyze Password Spraying mechanism.
Identified that password spraying targets horizontal user space by testing one common password against many accounts.
This strategy contrasts with brute-force attacks that attempt many passwords against a single account.
4
Analyze TLS Downgrade Attack mechanism.
Identified that downgrade attacks interfere with secure handshake negotiations to force fallback to older, vulnerable protocols.
Downgrade vectors target encryption protocol negotiation rather than network bandwidth or password guessing.

Key Concept

Common Network Attack Types and Vectors
PreviousPage 87 / 112Next
All practice questions — CompTIA Network+ | Examkin