All practice questions
2237 questions
A network technician is hardening remote administrative access on a core router deployed at an enterprise edge site. To comply with security baseline requirements, all remote management sessions must use strong payload encryption, and inactive administrative sessions must automatically terminate after five minutes. Which configuration strategy correctly fulfills these hardening requirements?
A network technician is troubleshooting an issue where client machines on the local network cannot access an internal secure web application hosted at `https://app.corp.local`. The technician executes `nslookup app.corp.local` on a client machine, which successfully resolves `app.corp.local` to IP address `10.10.20.15`. The technician then connects remotely to the server at `10.10.20.15` and runs the `netstat -ano` command, obtaining the following output snippet:
Proto Local Address Foreign Address State PID
TCP 10.10.20.15:80 0.0.0.0:0 LISTENING 2044
TCP 10.10.20.15:8080 0.0.0.0:0 LISTENING 3112
UDP 10.10.20.15:53 *:* 1088
Based on the command output and scenario details, which of the following is the primary cause of the connection failure?
A network administrator is investigating connectivity complaints from users on a newly deployed subnet (). An affected workstation displays an IP address of and a subnet mask of . The organization's central DHCP server is located on a separate administrative segment (). Which of the following issues could cause the client to receive this address? (Select TWO.)
Select all that apply
Place the standard IEEE 802.1D Spanning Tree Protocol (STP) port states in chronological sequence from initial link activation on an unconfigured switch interface to full user data transmission capability.
Drag items to arrange them in the correct order
During a security assessment on an enterprise network segment, a SOC analyst observes that users attempting to establish encrypted HTTPS connections to an external server are transparently modified in transit by an adversary on the local network segment. The adversary intercepts initial connection requests and converts HTTPS links into unencrypted HTTP links, forcing client browsers to transmit credentials in plaintext over port 80 while maintaining a separate secure session with the target server. Which of the following network attack types is being executed?
A network administrator is preparing to reconfigure VLAN assignments and update dynamic routing protocols across multiple switches in a campus network. To ensure proper IP address allocation, subnet boundaries, and virtual interface configurations are correctly mapped, the administrator needs to consult a document that illustrates how data flows logically through the network, regardless of physical cable connections or equipment rack positions. Which of the following documentation types best meets this requirement?
An enterprise organization is assigned the IPv6 global routing prefix . A network engineer is configuring a dedicated subnet for VLAN (represented as hexadecimal in the subnet field) and needs to assign the first usable host IPv6 address in that subnet to the default gateway interface. Which of the following represents the correctly compressed IPv6 address with its prefix length for the default gateway interface?
A client workstation on a corporate network initiates a web connection to `service.partner.org`. Assuming no DNS records are cached on the client or intermediate servers, place the following DNS resolution steps in the correct chronological order from the initial request to the final address delivery.
Drag items to arrange them in the correct order
A network security administrator is configuring a top-to-bottom IPv4 extended Access Control List (ACL) on a gateway router interface. The ACL must enforce the following security policy objectives:
1. Allow administrative host SSH access ( port 22) to management server .
2. Block all other traffic from internal subnet destined to management server .
3. Allow all hosts on subnet HTTP access ( port 80) to any destination.
4. Explicitly block all remaining IP traffic.
Arrange the ACL rules in the correct top-to-bottom processing order to satisfy these security requirements without shadowing any rules.
Drag items to arrange them in the correct order
A network technician is troubleshooting connectivity issues for several newly provisioned workstations on the finance VLAN (10.15.30.0/24). While the workstations can communicate with each other on the local switch, none of them can access corporate servers on external subnets or reach the internet. An inspection of `ipconfig /all` on one of the affected clients yields the following output:
IPv4 Address. . . . . . . . . . . : 10.15.30.45
Subnet Mask . . . . . . . . . . . : 255.255.255.0
Default Gateway . . . . . . . . . : 10.15.40.1
DHCP Server . . . . . . . . . . . : 10.15.10.10
Which of the following is the most likely cause of the routing failure?
A network engineer is analyzing poor throughput and high packet loss reported by mobile client devices roaming through a multi-floor facility. A wireless spectrum analyzer indicates that three neighboring access points providing coverage on the same floor are configured to broadcast on 2.4 GHz Channels 1, 3, and 5, respectively. Which of the following best explains the primary cause of the performance degradation and the required resolution?
Match each network diagnostic requirement or scenario to the most appropriate hardware testing tool or protocol analyzer function.
Click a left item, then click its matching right item
Items
Matches
A network administrator is troubleshooting an issue where servers on VLAN 40 (subnet 172.20.40.0/24) can successfully synchronize time with an internal NTP server (192.168.1.50), but fail to retrieve software updates from an HTTP repository located on the same server (192.168.1.50:80).
Inspection of the router's inbound ACL on the VLAN 40 interface reveals the following configuration:
ip access-list extended VLAN40_IN
10 permit tcp 172.20.40.0 0.0.0.255 host 192.168.1.50 eq 443
20 permit udp 172.20.40.0 0.0.0.255 host 192.168.1.50 eq 123
Which of the following TWO statements correctly identify the root cause of the failure and the necessary corrective action? (Select TWO.)
Select all that apply
A network administrator is configuring a subnet dedicated to security IP cameras in a warehouse facility. The subnet must support at least host devices, with each camera assigned a static IPv4 address. To minimize wasted IP address space, what is the minimum CIDR prefix length (represented as an integer for ) that should be assigned to this subnet?
A network administrator is diagnosing two distinct layer 2 issues on Switch-A. First, syslog logs display repeated `%CDP-4-NATIVE_VLAN_MISMATCH` messages for trunk link interface GigabitEthernet0/1 connected to Switch-B. Second, interface statistics for GigabitEthernet0/2 connected to a local database server show a high number of late collisions and alignment errors during heavy transfer periods. Which of the following actions should the administrator take to resolve these issues? (Select TWO.)
Select all that apply
An enterprise financial organization is designing a disaster recovery strategy for its core transaction processing systems. The business impact analysis defines a Recovery Point Objective (RPO) of near-zero data loss (less than 5 seconds) and a Recovery Time Objective (RTO) of under 15 minutes. Additionally, production application servers must resume operational capacity automatically in the event of a primary data center facility outage. Which of the following technical controls and site recovery strategies should the network operations team combine to meet these stringent BCDR metrics? (Select TWO)
Select all that apply
A network administrator is provisioning a dedicated subnet for a newly established server cluster that requires static IP assignments for exactly usable host devices. To conserve address space, which of the following is the most efficient subnet mask that satisfies this requirement?
A network technician is investigating performance degradation on a desktop host connected to switch port FastEthernet 0/12. The switch port speed and duplex settings were manually configured to 100 Mbps and Full Duplex, while the desktop network adapter was left on auto-negotiation. Running the `show interface fastEthernet 0/12` command reveals a rapidly incrementing counter for late collisions and Frame Check Sequence (FCS) errors.
Which of the following is the root cause of this connectivity issue?
A network administrator is configuring a workstation in a newly provisioned subnet with the IPv4 address . The host can successfully ping other devices on the local network, but cannot reach any external subnets or the internet. Executing `ipconfig` reveals the default gateway is configured as . Which of the following is the root cause of the connectivity failure?
A network administrator is troubleshooting an unexpected link outage on a 2 km single-mode fiber optic backbone connecting two enterprise distribution switches. While both optical transceivers are functioning properly, no signal reaches the remote end. The administrator needs to pinpoint the exact location of a suspected physical break along the cable run within an underground conduit. Which diagnostic tool should the administrator use?