Tüm alıştırma soruları

2237 soru

Soru 801Soru

A systems engineer is preparing to upgrade the operating system across multiple network security firewalls. Which of the following administrative tasks must be completed prior to applying the update to maintain change governance and ensure rapid system recovery? (Select TWO.)

Geçerli olan tümünü seçin

Cevabı ve açıklamayı göster

Cevap: Export a full backup of the current operating system image and configuration files to a remote repository.; Obtain explicit authorization through the change advisory board and document baseline performance metrics.

Cevap

Prior to flashing device software, administrators must back up existing system images and configurations off-device, and verify change management authorization alongside baseline performance capture.
Safe software updates require preserving a clean rollback state (backing up current configurations and firmware off-device) and adhering to organizational governance (securing change management approval and recording health baselines before making changes).

Adım Adım Çözüm

1
Identify risk mitigation requirements for software maintenance.
Determined that off-device backups of configuration and OS images are mandatory for rollback capability.
If an update causes boot failures or feature regression, having off-device backups allows quick rollback to the prior operational state.
2
Identify operational governance requirements.
Verified that change advisory board (CAB) approval and baseline metric capturing must occur prior to deployment.
Change control prevents unapproved network disruption, and health metrics allow validation after maintenance completes.

Anahtar Kavram

Software Maintenance Governance and Rollback Planning
Soru 802Soru

A network administrator needs to configure log retention to track user session durations and bytes transferred across remote access VPN connections for compliance auditing. Which pillar of the AAA framework directly delivers this tracking function?

Cevabı ve açıklamayı göster

Cevap: Accounting

Cevap

Accounting is the AAA framework pillar responsible for tracking user activity, connection statistics, session duration, and resource utilization.
Accounting measures and logs what a user does while connected, including session start and end times, commands executed, and bandwidth consumed.

Adım Adım Çözüm

1
Analyze the requirement stated in the scenario
The requirement focuses on tracking connection time, transferred data, and logging session activity for compliance auditing.
Identifying the core goal isolates which specific security function is needed.
2
Evaluate the AAA framework components
Authentication verifies identity, Authorization determines allowed rights, and Accounting logs and measures resource usage.
Applying the AAA definitions pinpoints the component handling metrics and audit logging.

Anahtar Kavram

AAA Framework Pillars (Authentication, Authorization, Accounting)
Soru 803Soru

An enterprise network utilizes two Layer 3 switches, Switch-A and Switch-B, to provide default gateway redundancy for VLAN 30 (172.16.30.0/24172.16.30.0/24). Switch-A is configured as the HSRP Active router with a priority of 120 and preemption enabled, using Virtual IP (VIP) 172.16.30.1172.16.30.1 (physical IP 172.16.30.2172.16.30.2). Switch-B is the HSRP Standby router with a default priority of 100 and physical IP 172.16.30.3172.16.30.3. Switch-A is also configured as the STP Root Bridge for VLAN 30. During a routine host setup, a technician manually sets a critical server's default gateway address to 172.16.30.2172.16.30.2 instead of the HSRP VIP. Later, Switch-A's tracked WAN uplink fails, decreasing its HSRP priority by 30 points and causing Switch-B to assume the HSRP Active role. Which of the following best describes the immediate pathing behavior for outbound traffic originating from this server?

Cevabı ve açıklamayı göster

Cevap: Outbound packets from the server continue targeting Switch-A's physical MAC address, forcing Switch-A to route the traffic across the inter-switch trunk link to Switch-B for external forwarding.

Cevap

Outbound packets from the server continue targeting Switch-A's physical MAC address, forcing Switch-A to route the traffic across the inter-switch trunk link to Switch-B for external forwarding.
When host workstations are incorrectly configured to use the physical IP address of a redundant router instead of the FHRP Virtual IP (VIP), they resolve ARP directly to the physical interface's MAC address. If an HSRP failover occurs, the physical interface of the former active router remains online and continues to receive and route packets sent directly to it. However, because external outbound paths may now prefer or traverse the newly active router, traffic from misconfigured hosts must cross the inter-switch trunk, leading to suboptimal hairpin routing and negating true gateway redundancy for that host.

Adım Adım Çözüm

1
Analyze host gateway address resolution
The host server uses IP 172.16.30.2172.16.30.2 (Switch-A physical IP) as its default gateway rather than VIP 172.16.30.1172.16.30.1.
Host traffic targeting a physical IP is encapsulated with the specific destination MAC address of that physical interface.
2
Evaluate FHRP state changes and interface operational status
Switch-A's priority drops from 120 to 90 (12030120 - 30), causing Switch-B (priority 100) to become Active for HSRP. However, Switch-A's physical LAN interface remains up and functional.
FHRP standby transition only changes ownership of the Virtual IP/MAC; physical interfaces remain active unless physically down.
3
Trace packet flow from misconfigured host
Packets arrive at Switch-A, which routes them toward their external destination via Switch-B over the inter-switch trunk link.
Switch-A retains Layer 3 routing functionality and forwards packets matching its routing table, even when acting as HSRP Standby.

Anahtar Kavram

First Hop Redundancy Protocol (FHRP) Virtual IP Configuration vs Physical Interface Forwarding
Soru 804Soru

A network administrator is configuring SNMP management on a core network switch. Organizational policy mandates that telemetry and monitoring traffic must support both cryptographic user authentication and payload encryption. Which SNMPv3 security level meets these requirements?

Cevabı ve açıklamayı göster

Cevap: authPriv

Cevap

The authPriv security level is required because it provides both authentication and privacy (encryption) for SNMP messages.
The authPriv setting enforces both cryptographic message authentication (Auth) and data confidentiality through encryption (Priv), fulfilling all compliance requirements.

Adım Adım Çözüm

1
Identify the required security parameters from the question prompt.
The requirements demand both cryptographic user authentication and payload encryption.
Protecting management traffic requires ensuring both origin verification and confidentiality.
2
Compare SNMPv3 security levels against the identified criteria.
noAuthNoPriv offers neither, authNoPriv offers authentication only, and authPriv offers both authentication and privacy.
SNMPv3 categorizes its security model into three distinct levels of protection.
3
Select the matching security level.
authPriv matches both authentication and privacy (encryption) requirements.
Only authPriv implements payload encryption ('Priv') in addition to authentication ('Auth').

Anahtar Kavram

SNMPv3 Security Levels
Soru 805Soru

An enterprise network technician is responding to recurring frame check sequence (FCS) and CRC error bursts on a 10GbE fiber optic link connecting a core switch to a newly installed modular SAN storage array across separate rooms in a data center. The fiber connection passes through multiple intermediate fiber distribution panels (FDPs) and structured patch bays. To systematically trace the specific optical strand IDs, bulkhead coupler locations, port assignments, and physical path terminations before dispatching a field engineer with an Optical Time-Domain Reflectometer (OTDR), which network document should the technician analyze first?

Cevabı ve açıklamayı göster

Cevap: Cable run schedule and patch panel port matrix

Cevap

The cable run schedule and patch panel port matrix is the primary documentation required to locate specific optical strands and physical termination endpoints.
The cable run schedule and patch panel port matrix documents point-to-point physical infrastructure, specifying cable labeling conventions, fiber strand numbers, patch panel jack allocations, and endpoint locations necessary to physically trace fiber optic link paths across intermediate patch bays.

Adım Adım Çözüm

1
Identify the technical requirement from the scenario
The technician needs to trace physical fiber strand IDs, bulkhead coupler positions, and patch bay port assignments across multiple rooms.
Resolving Layer 1 physical link errors like CRC/FCS across structured cabling requires exact physical media path details.
2
Evaluate document types against Layer 1 physical trace requirements
Logical topology diagrams display Layer 2/3 concepts, rack elevations detail cabinet space utilization, and baselines measure statistical traffic metrics.
None of these secondary documents contain point-to-point cable labels, strand color codes, or port matrix mappings.
3
Select the correct documentation artifact
The cable run schedule and port matrix contains explicit mappings for cable IDs, fiber pair/strand numbers, wall jack/FDP port designations, and end-to-end physical paths.
This documentation equips the technician to isolate the exact optical segment prior to physical OTDR testing.

Anahtar Kavram

Physical Network Documentation and Cable Schedules
Soru 806Soru

A network security administrator is replacing legacy switch administration protocols across an enterprise. The administrator attempts to configure RADIUS to enforce per-command authorization for individual privileged shell commands executed by engineers during SSH sessions on core switches, attempting to replicate an existing TACACS+ feature set. However, command-line execution validation fails to inspect individual commands once the administrative session is established. Which of the following technical characteristics of RADIUS explains why it cannot provide real-time, granular per-command authorization during an active interactive session?

Cevabı ve açıklamayı göster

Cevap: RADIUS combines authentication and authorization into unified transaction exchanges during session establishment, lacking a decoupled architecture to evaluate individual administrative commands post-login.

Cevap

RADIUS combines authentication and authorization into unified transaction exchanges during session establishment, lacking a decoupled architecture to evaluate individual administrative commands post-login.
The correct answer highlights the architectural difference between the two AAA protocols: RADIUS combines authentication and authorization into unified packet exchanges during session establishment. Because authentication and authorization are tightly bound at initial logon, RADIUS cannot perform real-time, command-by-command authorization checks during an active management session. TACACS+ explicitly decouples authentication, authorization, and accounting, allowing network devices to query the TACACS+ server for authorization on every single command executed by a user.

Adım Adım Çözüm

1
Identify the functional requirement requested by the administrator.
The requirement is granular, per-command authorization for interactive management shell commands during an active SSH session.
Security policy requires validating each command typed by an operator before the router or switch executes it.
2
Analyze TACACS+ architecture regarding AAA decoupling.
TACACS+ separates Authentication, Authorization, and Accounting into distinct operations over TCP port 49, sending an authorization request packet to the server for every individual command.
This decoupled structure allows real-time decision-making during an active shell session.
3
Analyze RADIUS architecture regarding AAA decoupling.
RADIUS couples Authentication and Authorization into a single exchange (Access-Request / Access-Accept).
Once the Access-Accept packet is returned, initial access is granted along with set session parameters (e.g., privilege level), but RADIUS provides no standard mechanism to intercept and authorize subsequent individual commands.

Anahtar Kavram

AAA Decoupling and RADIUS vs TACACS+ Protocol Architecture
Tahmini Süre:3m 0s
Soru 807Soru

An enterprise network infrastructure utilizes dual core switches configured with Virtual Router Redundancy Protocol (VRRP) to provide default gateway redundancy for multiple VLANs. Downstream access switches connect to both core switches via multi-chassis trunking. During traffic baseline audits, network engineers notice significant asymmetric traffic flow and sub-optimal hairpinning (tromboning) across the inter-switch link between the core switches. Which of the following configuration changes and architectural adjustments will optimize Layer 2/Layer 3 path symmetry and eliminate unnecessary inter-switch link transit? (Select TWO.)

Geçerli olan tümünü seçin

Cevabı ve açıklamayı göster

Cevap: Align the VRRP Master router assignment for each VLAN with the Spanning Tree Protocol (STP) Root Bridge priority for that same VLAN.; Implement Multi-Chassis Link Aggregation (MC-LAG) with active-active local forwarding enabled on both core switches.

Cevap

To resolve asymmetric routing and inter-switch link hairpinning, the network design must ensure that the VRRP Master router priority and the STP Root Bridge priority are aligned on the same switch per VLAN, and deploy Multi-Chassis Link Aggregation with local active-active Layer 3 forwarding capabilities.
Aligning the VRRP Master role with the STP Root Bridge role for a given VLAN ensures that the shortest Layer 2 spanning-tree path directly coincides with the active Layer 3 default gateway interface. Additionally, implementing Multi-Chassis Link Aggregation with local forwarding enables both core switches to process and route ingress traffic locally on their physical ports, avoiding suboptimal transit over the inter-switch peer link.

Adım Adım Çözüm

1
Analyze the cause of Layer 2/Layer 3 path asymmetry in dual-homed core topologies.
Identified that when the active STP root path terminates on Switch 1 while the VRRP active gateway resides on Switch 2, frames must cross the inter-switch link to reach their gateway.
Aligning STP Root Bridge election with VRRP Master status forces Layer 2 frames to flow directly to the active Layer 3 interface.
2
Evaluate link aggregation mechanisms across core switches.
Determined that using MC-LAG with active-active local forwarding allows both core switches to terminate Layer 2 LAG trunks and perform local Layer 3 routing.
Local forwarding eliminates the requirement to send packets across the inter-switch peer link prior to routing.

Anahtar Kavram

FHRP and STP Alignment with MC-LAG Active-Active Local Forwarding
Soru 808Soru

A network technician is setting up a Virtual Router Redundancy Protocol (VRRP) group between two routers to provide default gateway redundancy for hosts on Subnet 10.10.20.0/2410.10.20.0/24. Router 1 has interface IP 10.10.20.210.10.20.2, Router 2 has interface IP 10.10.20.310.10.20.3, and the Virtual IP (VIP) is configured as 10.10.20.110.10.20.1. Which IP address must be configured as the default gateway on client computers within this subnet?

Cevabı ve açıklamayı göster

Cevap: 10.10.20.1

Cevap

10.10.20.1 should be configured as the default gateway on all client workstations.
In First Hop Redundancy Protocols such as VRRP or HSRP, host endpoints must use the Virtual IP (VIP) address as their default gateway. This ensures that if the active master router fails, the standby router seamlessly takes over the VIP without requiring configuration updates on host workstations.

Adım Adım Çözüm

1
Identify the purpose of First Hop Redundancy Protocols (FHRP) like VRRP.
VRRP creates a single logical virtual router with a shared Virtual IP (VIP) out of multiple physical routers.
Client devices need a static gateway target that remains active even if one physical device fails.
2
Determine the IP address that hosts should point to for default gateway services.
Hosts must point to the Virtual IP address (10.10.20.1) rather than any physical interface address (10.10.20.2 or 10.10.20.3).
When the master router fails, the backup router assumes control of the Virtual IP seamlessly without host reconfiguration.

Anahtar Kavram

FHRP Virtual IP Gateway Assignment
Soru 809Soru

An organization deploys an active/standby pair of network gateways configured with a First Hop Redundancy Protocol to provide default gateway resiliency. During scheduled maintenance testing, when the primary active gateway is powered off, workstations on the local subnet immediately lose all outbound internet connectivity. Inspection reveals that internal workstations are receiving traffic normally within their local LAN, but failover routing does not resume internet access until the primary gateway is powered back on. Which misconfiguration is the most likely cause of this issue?

Cevabı ve açıklamayı göster

Cevap: The workstations have their default gateway setting pointing to the physical IP address of the primary gateway rather than the shared virtual IP address.

Cevap

The workstations have their default gateway setting pointing to the physical IP address of the primary gateway rather than the shared virtual IP address.
In high-availability network designs utilizing First Hop Redundancy Protocols (such as HSRP or VRRP), host endpoints must be configured to use the shared Virtual IP (VIP) as their default gateway. If hosts are incorrectly configured with the physical IP address of the primary router, outbound packets will continue targeting that specific physical device. Consequently, when the primary device fails or is powered down for maintenance, the secondary router cannot intercept that traffic, resulting in a complete loss of external network connectivity.

Adım Adım Çözüm

1
Analyze the reported symptom during high availability failover testing.
Local LAN traffic functions normally, but outbound internet traffic fails completely when the primary active gateway is powered off.
This indicates that local Layer 2 connectivity is operational, but Layer 3 default gateway traffic is not properly transitioning to the standby device.
2
Evaluate how First Hop Redundancy Protocols (FHRP) manage virtual and physical IP addresses.
FHRP protocols assign a shared Virtual IP (VIP) and virtual MAC address that move between primary and backup routers.
Host clients must send outbound packets to the VIP so that traffic is automatically received by whichever router is currently active.
3
Identify the configuration discrepancy on host workstations.
Pointing hosts directly to the physical interface IP of the primary router bypasses the FHRP virtual gateway mechanism.
When the primary router fails, traffic directed to its physical IP drops, rendering the redundant backup router unused.

Anahtar Kavram

FHRP Virtual Gateway IP Configuration
Soru 810Soru

An organization is deploying a pair of enterprise edge switches configured with multi-chassis link aggregation (mLAG) connected to two core routers configured with Virtual Router Redundancy Protocol (VRRP). Server host interfaces are configured in an LACP IEEE 802.3ad dynamic bond. During failure simulation testing, host traffic experiences intermittent packet loss and unidirectional asymmetry upon primary router failure. Which TWO of the following administrative actions or verification steps will resolve these specific high availability operational defects?

Geçerli olan tümünü seçin

Cevabı ve açıklamayı göster

Cevap: Verify that the VRRP virtual MAC address is correctly populated in the source address field of gratuitous ARP packets sent upon master state transitions.; Ensure that the LACP system identifier and operational mode on both mLAG switches are synchronized to present a single logical switch system to the host bond.

Cevap

The issues are resolved by verifying that VRRP transmits gratuitous ARP frames containing the virtual MAC address upon master state transitions, and ensuring the mLAG switch pair shares a synchronized LACP system identifier to maintain host link aggregation stability.
High availability designs utilizing both FHRP (VRRP) and multi-chassis link aggregation (mLAG) depend on seamless Layer 2 transition and unified control protocol appearance. Verifying that gratuitous ARP (GARP) broadcasts the VRRP virtual MAC allows adjacent switches to immediately update their MAC address tables upon gateway failover. Synchronizing the LACP system ID across mLAG peers allows host dual-homed NIC teams operating in IEEE 802.3ad mode to treat both physical switch connections as a single logical bundle without dropping member ports.

Adım Adım Çözüm

1
Analyze the layer 2 network topology and failover mechanisms
Identify that host NIC teaming uses LACP across two switches (requiring mLAG), while default gateway redundancy relies on VRRP.
Traffic asymmetry and intermittent loss after a failover typically indicate MAC table staleness (missing or unacknowledged GARP) or link aggregation protocol mismatches across multi-chassis nodes.
2
Evaluate default gateway ARP updates during failover
Confirm that VRRP state changes require gratuitous ARP (GARP) frames with the virtual MAC address to refresh switch forwarding tables.
Without GARP updating the switches' CAM tables, traffic destined for the Virtual IP will continue to be sent toward the failed master's interface port.
3
Evaluate link aggregation parameters across multi-chassis nodes
Confirm that the mLAG switch pair must synchronize its LACP system ID.
If the LACP system ID differs between the two switches in an mLAG pair, the host NIC team will split the aggregate group or disable links due to perceived switch mismatch.

Anahtar Kavram

High Availability Integration of FHRP (VRRP) and Multi-Chassis Link Aggregation (mLAG/LACP)
Soru 811Soru

A network security administrator needs to deploy a security solution that sits directly in the traffic path to inspect incoming packets and actively block identified threats in real time before they reach internal hosts. Which of the following devices should the administrator implement?

Cevabı ve açıklamayı göster

Cevap: Network Intrusion Prevention System (NIPS) placed inline

Cevap

Network Intrusion Prevention System (NIPS) placed inline
An inline Network Intrusion Prevention System (NIPS) processes traffic directly in the flow path, enabling automated real-time threat detection and packet drop actions before malicious traffic reaches target nodes.

Adım Adım Çözüm

1
Identify the primary functional requirement
The requirement demands active real-time inspection and automated packet dropping/blocking of malicious network traffic.
Preventative controls must operate in-band (inline) to intercept traffic prior to reaching target systems.
2
Compare passive (detection) versus active (prevention) network monitoring mechanisms
Passive systems (NIDS/SPAN) inspect copied frames out-of-band and generate alerts without inline blocking capability, while active systems (NIPS) sit in-line to enforce packet drop actions.
Inline deployment allows the security appliance to pass or stop live traffic dynamically.

Anahtar Kavram

Intrusion Prevention Systems (IPS) operate inline to actively block detected threats in real time, whereas Intrusion Detection Systems (IDS) operate passively out-of-band to monitor and alert.
Soru 812Soru

An IT administrator wants to ensure that a newly released software update for core network switches will not disrupt corporate operations or introduce instability before deploying it network-wide. Which of the following is the best initial step to validate the software update safely?

Cevabı ve açıklamayı göster

Cevap: Deploy the update to a non-production staging environment to test stability and compatibility.

Cevap

Testing the software update in a non-production staging environment before wide deployment.
Evaluating a software patch in a non-production staging environment allows administrators to observe device behavior, verify feature compatibility, and identify defects safely before introducing the update into live operations.

Adım Adım Çözüm

1
Identify the goal of safe patch validation.
Determine that software patches must be evaluated for bugs and compatibility before production deployment.
Applying unverified patches directly to production risks network outage and business interruption.
2
Select the appropriate environment for validation.
Use a dedicated non-production lab or staging environment that mirrors production conditions.
A staging environment allows full testing of device features and performance safely isolated from operational networks.

Anahtar Kavram

Patch Testing and Lab Staging
Tahmini Süre:45s
Soru 813Soru

During a security audit, a network administrator notices that event logs sent from a remote switch to a central log server contain significant gaps during periods of high network utilization. Investigation reveals that log packets sent via standard Syslog are being silently dropped by intermediate routers under heavy congestion. Which transport protocol and port configuration should be configured on the switch to ensure reliable, delivery-guaranteed log transmission?

Cevabı ve açıklamayı göster

Cevap: Configure Syslog to use TCP on port 514

Cevap

Configure Syslog to use TCP on port 514 to guarantee log message delivery across congested network paths.
The correct approach is configuring Syslog to use TCP on port 514. UDP-based Syslog relies on best-effort transport, which leads to lost audit events when network congestion causes packet drops. Using TCP introduces connection tracking, acknowledgments, and retransmissions to guarantee that every generated audit message reaches the central logging repository.

Adım Adım Çözüm

1
Identify the cause of missing audit logs
Standard Syslog operates by default over UDP port 514, which is a connectionless protocol without delivery guarantees or retransmission mechanisms during network congestion.
UDP packets are discarded by network devices during buffer exhaustion without notifying the sender.
2
Determine the transport protocol requirement for guaranteed log delivery
Switching log transport to TCP establishes reliable, acknowledged sessions with automatic retransmission of lost packets.
TCP sliding window mechanisms and positive acknowledgments prevent log entry loss when links experience drop conditions.
3
Select the proper standard port configuration
Standard unencrypted Syslog over TCP uses port 514.
Port 514 is the standard registered port for Syslog traffic over both UDP and TCP.

Anahtar Kavram

Syslog Transport Protocols and Reliability
Soru 814Soru

A network engineer is inspecting packet captures during an audit of network management traffic. The captures show authentication and administration sessions between network switches and a central server communicating over TCP port 49, where the complete packet payload following the header is cryptographically encrypted. Which protocol is being observed, and which feature accurately reflects its architecture relative to RADIUS?

Cevabı ve açıklamayı göster

Cevap: TACACS+, which decouples authentication and authorization into distinct services while encrypting the entire message body.

Cevap

TACACS+, which decouples authentication and authorization into distinct services while encrypting the entire message body.
The observed protocol is TACACS+ because it communicates over TCP port 49, encrypts the entire packet payload (excluding the header), and architecture-wise separates authentication and authorization, enabling detailed per-command administrative access controls.

Adım Adım Çözüm

1
Identify the transport protocol and port number given in the packet capture scenario.
The traffic utilizes TCP port 49, which uniquely identifies TACACS+ (Terminal Access Controller Access-Control System Plus). RADIUS operates over UDP ports 1812 and 1813.
Port numbers and transport protocols differentiate AAA management protocols.
2
Analyze the encryption boundaries described in the capture.
The scenario notes that the entire packet payload is encrypted. TACACS+ encrypts the entire body of the packet, whereas RADIUS only encrypts the password attribute within the packet payload.
Understanding security boundaries helps distinguish AAA protocol characteristics.
3
Evaluate the architectural separation of AAA components.
TACACS+ modularly separates Authentication, Authorization, and Accounting into distinct functions, allowing granular command-level authorization. RADIUS combines authentication and authorization into a unified flow.
Determining the correct feature description confirms protocol behavior.

Anahtar Kavram

AAA Framework protocol differences between TACACS+ and RADIUS regarding transport protocols, encryption boundaries, and architectural modularity.
Tahmini Süre:1m 30s
Soru 815Soru

A regional bank experienced a storage area network (SAN) volume failure on Thursday at 13:30. The network operations team maintains the following backup schedule for the critical database volume:

- Full backup: Executed every Sunday at 01:00
- Differential backup: Executed daily Monday through Wednesday at 23:00
- Incremental backup: Executed every 4 hours daily (03:00, 07:00, 11:00, 15:00, 19:00, 23:00)

To achieve the minimum Recovery Time Objective (RTO) while recovering all data up to the latest available recovery point prior to the outage, which restoration sequence must the backup engineer execute?

Cevabı ve açıklamayı göster

Cevap: Restore Sunday's Full backup, restore Wednesday's Differential backup, and sequentially apply Thursday's 03:00, 07:00, and 11:00 Incremental backups.

Cevap

The optimal sequence is to restore Sunday's Full backup, apply Wednesday's Differential backup, and then sequentially apply Thursday's 03:00, 07:00, and 11:00 Incremental backups.
The correct strategy combines the full baseline backup with the single latest cumulative differential backup, followed by every incremental backup taken after that differential up to the target restore time. Sunday's full backup restores the foundation, Wednesday's differential incorporates all changes up to Wednesday night in a single operation, and the three Thursday incrementals recover all subsequent changes prior to the failure, minimizing the total number of restoration operations to optimize RTO.

Adım Adım Çözüm

1
Identify the latest full baseline image.
Sunday's 01:00 Full backup establishes the baseline dataset.
Differential and incremental backups rely on the underlying full backup block state.
2
Select the latest cumulative differential backup taken prior to the outage.
Wednesday's 23:00 Differential backup contains all data changes from Sunday 01:00 to Wednesday 23:00.
Using the latest differential supersedes all previous differentials (Monday and Tuesday), minimizing total restore steps.
3
Identify and sequentially apply all incremental backups created after the selected differential backup.
Apply Thursday 03:00, Thursday 07:00, and Thursday 11:00 Incremental backups in chronological order.
Incremental backups contain changes only since the immediate prior backup (or differential), bringing the volume to 11:00 Thursday (the last clean state before the 13:30 outage).

Anahtar Kavram

Disaster recovery backup restoration sequencing combining full, differential, and incremental backup sets to optimize RTO.
Soru 816Soru

A network administrator receives a critical security advisory regarding a remote code execution vulnerability in the operating system running on the organization's enterprise switches. Which of the following procedures should the administrator perform first to ensure a safe patch deployment?

Cevabı ve açıklamayı göster

Cevap: Test the vendor-supplied patch in an isolated staging environment and perform a baseline configuration backup prior to production deployment.

Cevap

Testing the vendor-supplied patch in an isolated staging environment and performing a baseline configuration backup prior to production deployment is the correct initial procedure.
Before deploying software updates to production network hardware, administrators must perform staging tests in a non-production environment and perform a complete configuration and system image backup. This approach verifies patch compatibility, reduces unexpected downtime, and guarantees a rapid rollback path.

Adım Adım Çözüm

1
Analyze the vendor security advisory and evaluate patch requirements.
Identified the necessity of remediating the vulnerability while adhering to standard change management practices.
Security vulnerabilities must be addressed systematically to protect infrastructure without causing accidental network downtime.
2
Validate the software patch in a sandbox or staging environment.
Verified that the software operates stably with existing protocols and device configurations.
Staging validation ensures that software regression issues or unexpected bugs are discovered prior to impacting live network traffic.
3
Perform a complete configuration backup and document rollback procedures.
Established a clear restoration baseline in the event of an update failure.
Having a verified running configuration and flash image backup allows rapid restoration during maintenance windows if issues arise.

Anahtar Kavram

Patch Management Lifecycle and Pre-Deployment Staging
Soru 817Soru

Hosts on a newly provisioned user subnet fail to dynamically acquire IP addresses from an established DHCP server located on a separate administrative network segment. Why is a DHCP relay service required on the local gateway router to resolve this issue?

Cevabı ve açıklamayı göster

Cevap: DHCP discovery messages are sent as local broadcasts, which routers do not forward across subnets by default.

Cevap

DHCP discovery messages are sent as local broadcasts, which routers do not forward across subnets by default.
DHCP clients initially send broadcast messages to discover available servers. Because routers isolate subnets by dropping broadcast traffic by default, a DHCP relay agent (or IP helper address) must be configured on the router interface facing the client. The relay converts the client's broadcast discovery into a unicast packet directed straight to the central DHCP server's IP address.

Adım Adım Çözüm

1
Analyze how clients initiate DHCP requests
DHCP clients broadcast a DHCPDISCOVER message using destination IP address 255.255.255.255255.255.255.255.
The client does not yet have an IP address or knowledge of the local gateway and network topology.
2
Evaluate router behavior regarding local broadcast traffic
Routers drop Layer 3 broadcast frames by default to isolate broadcast domains.
Preventing broadcast propagation across subnets reduces network congestion and prevents broadcast storms.
3
Identify the role of the DHCP relay agent (IP Helper)
The relay agent intercepts the broadcast on the client-facing interface and forwards it as a unicast packet to the central DHCP server.
Unicast packets are routable across network boundaries, allowing the remote DHCP server to assign an IP address from the appropriate scope.

Anahtar Kavram

DHCP Relay Services and Broadcast Boundaries
Tahmini Süre:45s
Soru 818Soru

During a security compliance audit, a network administrator discovers that edge routers are transmitting critical audit logs across an untrusted WAN connection using default Syslog configurations over UDP port 514. Updated corporate policy mandates that all network event logging must guarantee connection-oriented reliable delivery and encrypt log payloads in transit to prevent eavesdropping. Which configuration modification should the administrator implement to fulfill both requirements?

Cevabı ve açıklamayı göster

Cevap: Reconfigure Syslog forwarding to use TLS over TCP port 6514.

Cevap

Reconfigure Syslog forwarding to use TLS over TCP port 6514.
Reconfiguring Syslog forwarding to use TLS over TCP port 6514 satisfies both security mandates. TCP ensures connection-oriented, reliable packet delivery with retransmissions across the WAN, while TLS provides cryptographic privacy and payload integrity for logs in transit.

Adım Adım Çözüm

1
Analyze the audit compliance requirements.
Identified two mandatory technical requirements: connection-oriented reliable delivery and encrypted payload transmission for log forwarding across the WAN.
Default Syslog uses UDP port 514, which is connectionless (unreliable) and unencrypted (cleartext).
2
Evaluate transport layer protocols for log forwarding.
TCP guarantees connection-oriented reliable delivery through sequence numbers and acknowledgments, whereas UDP offers no delivery guarantees.
Connection reliability requires replacing UDP with TCP.
3
Evaluate security and standard port specifications for secure Syslog.
RFC 5425 establishes Syslog over TLS using TCP port 6514 to provide cryptographic privacy (encryption) and data integrity.
Standard TCP port 514 does not provide TLS encryption by default, whereas TCP port 6514 is designated specifically for Syslog encapsulated within TLS.

Anahtar Kavram

Syslog over TLS (TCP Port 6514) Transport Security and Reliability
Tahmini Süre:2m 0s
Soru 819Soru

Match each high availability or redundancy concept on the left with its correct operational description on the right.

Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın

Öğeler

Hot Standby Router Protocol (HSRP)
Link Aggregation Control Protocol (LACP)
Virtual Router Redundancy Protocol (VRRP)
Active-Passive Clustering

Eşleşmeler

Cevabı ve açıklamayı göster

Cevap

The correct match pairs Hot Standby Router Protocol (HSRP) with the Cisco-proprietary first-hop redundancy protocol definition; Link Aggregation Control Protocol (LACP) with the IEEE 802.3ad open-standard multi-link bundling protocol; Virtual Router Redundancy Protocol (VRRP) with the open-standard default gateway redundancy protocol; and Active-Passive Clustering with the architecture where a secondary unit remains idle until primary failure.
Each concept directly matches its fundamental operational definition. HSRP is Cisco-proprietary for first-hop gateway failover, VRRP is an open-standard gateway redundancy protocol, LACP provides IEEE 802.3ad link bundling at Layer 2, and Active-Passive clustering reserves a secondary system for automated failover during active node failure.

Adım Adım Çözüm

1
Differentiate First-Hop Redundancy Protocols (FHRP) by vendor standards.
Identify HSRP as Cisco-proprietary and VRRP as the open-standard alternative for gateway fault tolerance.
Both HSRP and VRRP create virtual gateways, but their standard designations differ.
2
Identify link-level aggregation protocols.
Associate LACP with IEEE 802.3ad port channeling for bandwidth aggregation and link redundancy.
LACP aggregates switch interfaces at Layer 2 rather than routing at Layer 3.
3
Identify system failover deployment models.
Associate Active-Passive Clustering with primary node processing and standby secondary node takeover.
Active-Passive design ensures dedicated hardware failover without load sharing during normal operations.

Anahtar Kavram

High Availability and Redundancy Protocols
Soru 820Soru

Match each AAA authentication protocol or access control framework to its defining operational and structural characteristic.

Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın

Öğeler

TACACS+
RADIUS
Kerberos
802.1X with EAP-TLS

Eşleşmeler

Cevabı ve açıklamayı göster

Cevap

The correct matches are: TACACS+ aligns with full payload encryption over TCP port 49 and decoupled AAA services; RADIUS aligns with password-only encryption over UDP ports 1812/1813 and combined authentication/authorization; Kerberos aligns with KDC ticket-granting tickets for mutual authentication; and 802.1X with EAP-TLS aligns with port-based access control requiring dual X.509 certificates.
Each authentication mechanism possesses distinct transport protocols, encryption boundaries, and operational characteristics. TACACS+ uses TCP port 49 with full packet payload encryption and modular AAA separation. RADIUS uses UDP ports 1812 and 1813, encrypting only password attributes while coupling authentication and authorization. Kerberos relies on a Key Distribution Center issuing ticket-granting tickets for domain SSO. 802.1X with EAP-TLS enforces port access control through mutual certificate authentication.

Adım Adım Çözüm

1
Analyze transport layer protocols and payload encryption boundaries.
Identify TACACS+ as the protocol using TCP port 49 with full payload encryption, while RADIUS uses UDP ports 1812/1813 with password-only encryption.
Differentiating transport security boundaries isolates network administrative management (TACACS+) from network access control (RADIUS).
2
Examine AAA architectural separation vs combination.
Confirm TACACS+ strictly decouples authentication, authorization, and accounting, whereas RADIUS combines authentication and authorization.
Modular decoupling allows TACACS+ to authorize individual administrator commands independently.
3
Evaluate ticket-based and certificate-based authentication frameworks.
Map Kerberos to the KDC and ticket-granting mechanism, and map 802.1X with EAP-TLS to dual-sided certificate mutual authentication.
Kerberos is designed for domain single sign-on, whereas EAP-TLS provides robust physical/wireless port access security.

Anahtar Kavram

AAA Framework Protocol Architecture and Authentication Methods
ÖncekiSayfa 41 / 112Sonraki
Tüm alıştırma soruları — CompTIA Network+ | Examkin