Tüm alıştırma soruları

2237 soru

Soru 1761Soru

A network engineer is auditing IPv6 interface configurations on a core switch. An interface is manually configured with the fully expanded IPv6 address 2001:0db8:0000:0000:00ab:0000:0000:0001/642001:0\text{db8}:0000:0000:00\text{ab}:0000:0000:0001/64. According to standard RFC 5952 zero-compression and leading-zero suppression rules, which of the following represents the correct canonical form of this address?

Cevabı ve açıklamayı göster

Cevap: 2001:db8::ab:0:0:1/64

Cevap

The canonical form of the address is 2001:db8::ab:0:0:1/64.
According to RFC 5952 guidelines for canonical IPv6 address formatting: 1) Leading zeros in any hextet must be omitted (0db8 becomes db8, 00ab becomes ab, 0001 becomes 1). 2) The double-colon (::) must be used to shorten contiguous zero hextets. 3) If there are multiple zero sequences of equal length, the first sequence must be compressed using double-colon, leaving subsequent zero hextets represented as single zeros. Applying these rules yields 2001:db8::ab:0:0:1/64.

Adım Adım Çözüm

1
Suppress leading zeros in each 16-bit hextet.
2001:0db8 becomes 2001:db8, 0000 becomes 0, 00ab becomes ab, and 0001 becomes 1.
RFC 5952 mandates that leading zeros within each hextet must be suppressed.
2
Identify contiguous sequences of zero hextets.
Sequence 1 contains two zeros (hextets 3 and 4); Sequence 2 contains two zeros (hextets 6 and 7).
Double-colon zero compression can only be applied to contiguous sequences of all-zero hextets.
3
Apply the double-colon (::) operator to compress zero hextets according to tie-breaking rules.
Compress Sequence 1 to yield 2001:db8::ab:0:0:1/64.
When zero sequences are equal in length, RFC 5952 Section 4.2.3 requires compressing the first sequence, and double-colon can only be used once per address.

Anahtar Kavram

RFC 5952 IPv6 Address Representation and Compression Rules
Soru 1762Soru

A network administrator is conducting a final verification audit of a newly constructed Intermediate Distribution Frame (IDF) closet prior to production handoff. To maintain standard documentation practices, physical deployment attributes must be clearly separated from logical network models. Which of the following elements should be documented exclusively on physical topology diagrams or rack elevation schematics rather than logical network diagrams? (Select TWO.)

Geçerli olan tümünü seçin

Cevabı ve açıklamayı göster

Cevap: Exact rack unit (U) position and physical equipment mounting locations; Patch panel port terminations and cable tray pathway designations

Cevap

The correct answers are the option specifying exact rack unit (U) positions and physical equipment mounting locations, as well as the option specifying patch panel port terminations and cable tray pathway designations.
Physical network diagrams and rack elevation drawings depict physical assets and cabling infrastructure, including rack unit (U) height allocations, chassis dimensions, patch panel port layouts, power distribution unit (PDU) connections, and physical cable tray pathways. In contrast, logical topology diagrams document how data flows across the network using layer 2 and layer 3 abstractions.

Adım Adım Çözüm

1
Analyze the core distinction between physical and logical network documentation.
Physical documentation maps tangible hardware, physical spatial locations, cabling routes, and rack space allocation. Logical documentation maps protocol flow, IP addressing schemes, subnetting, VLAN boundaries, and routing domains.
Clear segregation of documentation types prevents operational confusion during hardware maintenance versus traffic troubleshooting.
2
Evaluate options representing physical hardware attributes.
Rack unit (U) positions in equipment enclosures and patch panel port terminations with physical cable routing describe hardware layout and cabling pathways.
These physical specifications are required for site visits, rack installations, and cable tracing in physical closets.
3
Evaluate options representing logical network abstractions.
VLAN IDs, OSPF routing areas, and FHRP Virtual IP addresses represent software and protocol configurations.
These parameters govern how data packets flow logically through the network regardless of physical rack placement.

Anahtar Kavram

Physical vs. Logical Network Diagrams
Soru 1763Soru

A network systems engineer is deploying an IPv6-enabled mail gateway. Remote mail servers are failing reverse DNS checks when accepting outbound messages from the gateway's IP address (2001:db8:85a3::8a2e:370:73342001:db8:85a3::8a2e:370:7334). The engineer runs the following diagnostic command from a terminal:

text
$ host 2001:db8:85a3::8a2e:370:7334
Host 4.3.3.7.0.7.3.0.e.2.a.8.0.0.0.0.0.0.0.0.3.a.5.8.8.b.d.0.1.0.0.2.ip6.arpa not found: 3(NXDOMAIN)

Which of the following resource records must be configured in the authoritative DNS zone to resolve the NXDOMAIN error?

Cevabı ve açıklamayı göster

Cevap: A PTR record within the ip6.arpa domain that maps the reverse nibble format of the IPv6 address to the mail gateway's FQDN

Cevap

A PTR record within the ip6.arpa domain that maps the reverse nibble format of the IPv6 address to the mail gateway's fully qualified domain name (FQDN).
Reverse DNS lookups resolve IP addresses into hostnames using Pointer (PTR) records. For IPv6, the address is expanded into 32 hexadecimal nibbles, reversed, and appended with .ip6.arpa. Creating a PTR record in this zone allows receiving servers to successfully resolve the mail gateway's IP address.

Adım Adım Çözüm

1
Analyze the diagnostic command and output.
The query 'host 2001:db8:85a3::8a2e:370:7334' performs a reverse DNS lookup against the reverse IPv6 domain (ip6.arpa) and returns NXDOMAIN, indicating the record is missing.
Reverse DNS resolution queries IP addresses to retrieve associated domain names.
2
Identify the required DNS record type for reverse lookup.
A Pointer (PTR) record is specifically designed to map IP addresses to FQDNs in reverse lookup zones (.in-addr.arpa for IPv4 and .ip6.arpa for IPv6).
Forward lookup records (A or AAAA) map hostnames to IP addresses, which will not satisfy reverse DNS lookup requests.
3
Select the option specifying the correct record type and zone structure.
Creating a PTR record in the ip6.arpa zone resolves the reverse lookup failure.
This establishes the valid mapping required by receiving mail servers verifying origin IP addresses.

Anahtar Kavram

IPv6 Reverse DNS Resolution (PTR Records in ip6.arpa)
Tahmini Süre:1m 30s
Soru 1764Soru

A network engineer is designing a multi-building enterprise wireless infrastructure across diverse indoor and outdoor physical environments. Match each wireless antenna type on the left with its optimal deployment scenario and RF propagation profile on the right.

Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın

Öğeler

Omnidirectional Dipole Antenna
Internal Patch / Wall Panel Antenna
Yagi-Uda Antenna
Parabolic Dish Antenna

Eşleşmeler

Cevabı ve açıklamayı göster

Cevap

Omnidirectional Dipole Antenna matches with ceiling-mounted 360-degree horizontal coverage; Internal Patch / Wall Panel Antenna matches with wall-mounted corridor directional coverage; Yagi-Uda Antenna matches with moderate beamwidth medium-distance outdoor bridging; and Parabolic Dish Antenna matches with extremely narrow beamwidth long-range outdoor bridging.
Omnidirectional antennas provide 360-degree horizontal coverage for open office floors; patch panel antennas focus RF energy forward down hallways; Yagi antennas deliver moderate directional gain for medium-distance outdoor bridging; and parabolic dish antennas provide ultra-focused high gain for long-range wireless links.

Adım Adım Çözüm

1
Analyze the radiation pattern of an omnidirectional dipole antenna.
Identify that energy is distributed equally in all horizontal directions (360 degrees).
Central indoor ceiling mounting maximizes area coverage for users spread across an open floor.
2
Evaluate the directional characteristics of patch/panel antennas.
Identify forward hemispherical RF projection.
Useful along facility borders and long hallways to prevent co-channel leakage into unneeded spaces.
3
Distinguish between Yagi and Parabolic Dish point-to-point bridging antennas.
Associate Yagi antennas with moderate directional gain for medium distances and Parabolic Dish antennas with extremely high gain and narrow pencil beams for long-range links.
Physical reflector design in parabolic antennas focuses RF energy much more tightly than Yagi elements, accommodating longer path distances.

Anahtar Kavram

Wireless Antenna Selection, Gain Characteristics, and RF Propagation Profiles
Soru 1765Soru

A network administrator is auditing the stateful address translation table on an edge firewall configured with Port Address Translation (PAT). Which of the following statements correctly describe how PAT processes outbound traffic and manages network connections? (Select TWO)

Geçerli olan tümünü seçin

Cevabı ve açıklamayı göster

Cevap: PAT maps multiple private IPv4 addresses to a single public IP address by dynamically assigning a unique Layer 4 source port number to each outbound session.; If two internal hosts initiate outbound traffic using identical source port numbers, the edge device modifies the outbound source port to maintain entry uniqueness in its translation table.

Cevap

The correct statements are that PAT maps multiple private IPv4 addresses to a single public IP address using unique Layer 4 source port numbers, and that the NAT device rewrites egress source ports if two internal hosts attempt to use identical source ports.
Port Address Translation (PAT) allows thousands of internal hosts on private IP addresses to share a single public IP address by tracking sessions using unique Layer 4 TCP/UDP port numbers. If two internal hosts select the same initial ephemeral source port, the PAT gateway alters the translated outbound source port to guarantee a unique translation entry.

Adım Adım Çözüm

1
Analyze how PAT handles internal-to-external translation.
Recognize that PAT uses Layer 4 source port numbers (TCP/UDP) alongside a single public IP address to differentiate traffic streams originating from multiple internal private host IP addresses.
PAT (also known as NAT Overload) relies on unique transport-layer port numbers to allow multiple private IP addresses to share one public IP address.
2
Evaluate port collision handling in PAT.
Confirm that if two client hosts pick the same source port number, the translating device rewrites the translated source port number on the WAN side to avoid ambiguous translation table entries.
Maintaining unique (Public IP, Public Port) tuples is necessary for returning traffic to be correctly de-multiplexed back to the originating internal (Private IP, Private Port) client.
3
Identify misconfigurations and incorrect operational descriptions in distractors.
Eliminate options that confuse Dynamic NAT pool assignment with PAT overload, or that incorrectly place PAT tracking at Layer 2 instead of Layer 3/4.
Dynamic NAT allocates 1-to-1 public IP mappings, and address/port translation operates at Network (Layer 3) and Transport (Layer 4) layers.

Anahtar Kavram

Port Address Translation (PAT / NAT Overload) session tracking and port rewriting mechanisms
Soru 1766Soru

A network engineer is configuring standard IEEE 802.1D Spanning Tree Protocol (STP) across a enterprise switch topology. Currently, all switches in the network operate using the default bridge priority of 3276832768. The engineer needs to explicitly configure Switch-1 to guarantee it becomes the primary Root Bridge, and Switch-2 to serve as the designated backup Root Bridge if Switch-1 fails. Which combination of bridge priority settings should the engineer assign to achieve this design?

Cevabı ve açıklamayı göster

Cevap: Assign a bridge priority of 40964096 to Switch-1 and 81928192 to Switch-2.

Cevap

Assign a bridge priority of 4096 to Switch-1 and 8192 to Switch-2.
In Spanning Tree Protocol (STP), the Root Bridge is elected based on the lowest Bridge ID, which consists of a 2-byte Bridge Priority and a 6-byte MAC Address. Because the default priority on switches is 3276832768, assigning a lower priority value such as 40964096 to Switch-1 guarantees it will win the root election. Assigning 81928192 to Switch-2 ensures that if Switch-1 fails, Switch-2 will possess the next lowest priority value in the network, allowing it to seamlessly take over as the backup Root Bridge.

Adım Adım Çözüm

1
Identify the STP Root Bridge election criteria.
STP elects the switch with the lowest Bridge ID (Bridge Priority + MAC Address) as the Root Bridge.
Lower numerical values have higher precedence in STP elections.
2
Determine the required priority value for the primary Root Bridge (Switch-1).
Switch-1 priority must be lower than the default value of 3276832768. Setting it to 40964096 guarantees primary root bridge status.
A lower priority value ensures Switch-1 beats all default switches in election comparisons.
3
Determine the required priority value for the secondary backup Root Bridge (Switch-2).
Switch-2 priority must be higher than Switch-1 (40964096) but lower than all other network switches (3276832768). Setting it to 81928192 achieves backup placement.
If Switch-1 fails, Switch-2 will have the next lowest priority (81928192) among remaining operational switches.

Anahtar Kavram

STP Root Bridge Election and Priority Mechanics
Tahmini Süre:1m 15s
Soru 1767Soru

Match each network documentation artifact on the left to its corresponding operational purpose on the right.

Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın

Öğeler

Rack Elevation Diagram
Logical Network Diagram
Wiring Schematic
Network Baseline Document

Eşleşmeler

Cevabı ve açıklamayı göster

Cevap

Rack Elevation Diagram matches planning vertical unit space allocation and equipment mounting in enclosures; Logical Network Diagram matches mapping IP subnet boundaries, VLAN IDs, and routing relationships; Wiring Schematic matches detailing cable pinout configurations and terminations; Network Baseline Document matches recording standard operational metrics to identify performance anomalies.
Each network documentation type addresses specific operational requirements: Rack elevation diagrams assist in equipment mounting and space management; logical diagrams depict subnets, VLANs, and routing topology; wiring schematics detail cable pinouts and physical conductor terminations; network baselines provide historical metrics for anomaly detection.

Adım Adım Çözüm

1
Analyze the operational scope of physical enclosure planning.
Rack elevation diagrams illustrate vertical U-height positioning and equipment layout inside standard racks.
This is essential for physical space management and thermal/power planning in server rooms.
2
Analyze logical abstraction layer requirements.
Logical diagrams represent Layer 2 and Layer 3 relationships such as IP subnets, VLANs, and dynamic routing protocols.
Logical diagrams reflect how data flows through logical structures rather than physical hardware locations.
3
Examine physical cabling and conductor termination documentation.
Wiring schematics detail conductor assignments, pinouts (e.g., T568A vs T568B), and port-to-patch-panel terminations.
This level of detail is required for physical layer cable installation and low-level cable troubleshooting.
4
Examine historical monitoring and performance reference documentation.
A network baseline records benchmark performance statistics (utilization, throughput, latency) during regular operations.
Baselines serve as the standard reference point for comparison during performance troubleshooting.

Anahtar Kavram

Distinguishing the functional purposes of rack elevations, logical diagrams, wiring schematics, and operational baselines in network documentation.
Soru 1768Soru

A network technician terminates a new Category 6A horizontal cable run between a patch panel and a modular wall jack using T568B standards. When testing the link, a basic wiremapper confirms that all eight conductors have proper 1-to-1 pin continuity. However, when connected to a multi-gigabit switch, the link fails to negotiate a 10Gbps connection and experiences high frame error rates. A cable certifier reveals severe Near-End Crosstalk (NEXT). Which TWO of the following physical installation faults are the most likely causes of this issue? (Select TWO.)

Geçerli olan tümünü seçin

Cevabı ve açıklamayı göster

Cevap: Untwisting the conductor pairs excessively at the patch panel or wall jack termination points; Accidentally wiring a split pair condition while maintaining straight-through pin continuity

Cevap

Excessive untwisting of conductor pairs at termination points and split pair wiring configurations are the primary causes of severe Near-End Crosstalk (NEXT) when 1-to-1 pin continuity is verified.
Excessive untwisting of wire pairs during termination disrupts pair geometry and reduces mutual noise cancellation, directly causing Near-End Crosstalk (NEXT). Additionally, split pair configurations swap conductors between pairs while preserving 1-to-1 pin continuity; basic continuity testers will report the cable as good, but high-frequency signals suffer catastrophic crosstalk.

Adım Adım Çözüm

1
Analyze the reported symptoms and diagnostic tool capabilities.
The basic wiremapper passes 1-to-1 continuity, but the certifier detects severe NEXT interference.
Basic continuity wiremappers only check DC continuity (pin 1 to pin 1, etc.) and cannot detect high-frequency AC crosstalk or pair separation errors.
2
Identify physical termination factors that destroy pair cancellation.
Excessive untwisting of pairs (> 0.5 inches / 13 mm) destroys mutual inductive and capacitive noise cancellation at high frequencies.
Maintaining tight pair twisting up to the point of termination is critical for differential signal noise rejection.
3
Identify pinout errors that pass continuity checks but fail frequency certification.
Split pairs maintain end-to-end 1-to-1 pin continuity but split twisted pairs across non-paired conductors.
Because the signal and return paths are no longer twisted with each other, differential mode noise cancellation fails completely, resulting in high Crosstalk.

Anahtar Kavram

Causes of Near-End Crosstalk (NEXT) and Split Pairs in Twisted-Pair Cabling
Soru 1769Soru

A field technician is dispatched to troubleshoot a physical layer connectivity failure at a newly installed workstation outlet. The technician needs to verify the individual conductor color coding, pinout standard, and precise punch-down block termination points for the wall jack run inside the wiring closet. Which document should the technician consult to obtain this specific information?

Cevabı ve açıklamayı göster

Cevap: Wiring schematic

Cevap

Wiring schematic
A wiring schematic (or cable plant diagram) detail physical cable construction and installation parameters. It specifies conductor pinouts, modular jack wiring standards (T568A/T568B), color codes, and exact wire placement on cross-connects and punch-down blocks.

Adım Adım Çözüm

1
Analyze the technical requirements of the scenario
The scenario requires locating cable conductor pinouts, twisted-pair color codes, and specific physical punch-down block termination points for a horizontal cable run.
Resolving physical layer wiring issues demands documentation that maps individual wire strands to interface connectors.
2
Evaluate the types of network documentation available
Wiring schematics explicitly document physical cabling standards, wire mapping, color pairs, and punch-down configurations.
Other documents focus on rack space positioning, logical routing/VLAN configurations, or telemetry performance data rather than conductor-level terminations.

Anahtar Kavram

Wiring Schematics and Cable Plant Documentation
Soru 1770Soru

An enterprise network security administrator discovers anomalous traffic on a switch interface where an attacker on VLAN 10 sent frames directly to a target server on VLAN 20 without passing through a router. Analysis of captured frames reveals two 802.1Q tags embedded within the Ethernet header. Which of the following conditions must be met for this double-tagging VLAN hopping attack to succeed? (Select TWO.)

Geçerli olan tümünü seçin

Cevabı ve açıklamayı göster

Cevap: The native VLAN of the 802.1Q trunk link must match the attacker's access VLAN.; The traffic must traverse an 802.1Q trunk line connecting two switches.

Cevap

Double-tagging VLAN hopping requires that the native VLAN of the trunk link matches the attacker's VLAN, and that the traffic traverses an 802.1Q trunk connecting switches.
A double-tagging attack succeeds when the attacker's access VLAN matches the native VLAN configured on an 802.1Q trunk port. Upon receiving the frame, the first switch strips the outer tag because it matches the native VLAN. The frame travels across the trunk to the second switch, which reads the inner 802.1Q tag and forwards the frame to the target VLAN, bypassing router access controls.

Adım Adım Çözüm

1
Analyze the incident details
The capture shows dual 802.1Q headers used to hop from VLAN 10 to VLAN 20 across a switch infrastructure.
Identifying double tagging isolates the specific conditions required for native VLAN header stripping on switch trunks.
2
Evaluate native VLAN processing behavior
When a frame's outer 802.1Q tag matches the trunk's native VLAN, the first switch strips the outer tag before sending the frame across the trunk.
This establishes that the attacker's VLAN must match the native VLAN of the trunk port.
3
Evaluate downstream switch trunk processing
The second switch inspects the remaining inner 802.1Q tag and forwards the frame to the destination VLAN specified in that tag.
This demonstrates that an active switch-to-switch trunk link is necessary for the second switch to interpret the inner tag.

Anahtar Kavram

Double-tagging VLAN hopping exploits native VLAN stripping mechanisms over 802.1Q trunk links to send unidirectional frames to a different VLAN without passing through a Layer 3 device.
Soru 1771Soru

A network engineer is documenting the IPv6 address allocation for an enterprise router interface. The fully expanded, uncompressed address assigned to the interface is 2001:0db8:0000:0042:0000:0000:0000:0007. According to RFC 5952 rules, what is the correctly compressed and canonicalized representation of this IPv6 address?

Cevabı ve açıklamayı göster

Cevap: 2001:db8:0:42::7

Cevap

2001:db8:0:42::7
According to RFC 5952 standards for IPv6 address canonicalization: 1) Leading zeros within each 16-bit field must be removed (0db8 -> db8, 0042 -> 42, 0007 -> 7). 2) A single all-zero field is written as 0. 3) The double-colon (::) must be used to compress the longest contiguous sequence of all-zero fields. In this address, the sequence of three zeros (0000:0000:0000) is longer than the single zero field, making 2001:db8:0:42::7 the only correct canonical compressed address.

Adım Adım Çözüm

1
Suppress leading zeros in each 16-bit hexadecimal field (hextet).
2001:0db8 becomes 2001:db8; 0000 becomes 0; 0042 becomes 42; 0000:0000:0000 becomes 0:0:0; 0007 becomes 7. The intermediate string is 2001:db8:0:42:0:0:0:7.
RFC 5952 requires removing leading zeros within each hextet while preserving a single zero for any all-zero hextet.
2
Identify all contiguous sequences of all-zero hextets and select the longest sequence to compress using double-colon (::).
Sequence 1 is at index 3 (length 1: '0'). Sequence 2 is at indices 5-7 (length 3: '0:0:0'). The longer sequence (length 3) is replaced with '::'.
RFC 5952 specifies that double-colon (::) must replace the longest contiguous run of all-zero hextets. Shorter single-zero hextets must remain as a single '0'.
3
Combine the compressed sections into the final canonical IPv6 address.
2001:db8:0:42::7
Ensures full compliance with RFC 5952 formatting and lowercase hexadecimal standards.

Anahtar Kavram

RFC 5952 IPv6 Address Compression and Canonical Representation
Soru 1772Soru

A core router receives a packet destined for 192.168.10.45192.168.10.45. The router's Routing Information Base (RIB) contains four distinct candidate routes for reaching this destination network:

- A static route to 192.168.10.0/24192.168.10.0/24 configured with an administrative distance of 130130.
- An OSPF route to 192.168.10.0/24192.168.10.0/24 with an administrative distance of 110110 and metric of 5050.
- An EIGRP internal route to 192.168.10.0/24192.168.10.0/24 with an administrative distance of 9090 and metric of 2560025600.
- A RIPv2 route to 192.168.10.0/24192.168.10.0/24 with an administrative distance of 120120 and metric of 22.

Which route will the router install into its active forwarding table to handle traffic destined for 192.168.10.45192.168.10.45?

Cevabı ve açıklamayı göster

Cevap: The EIGRP internal route because it possesses the lowest administrative distance value among all candidate routes.

Cevap

The router will select the EIGRP internal route because it has the lowest administrative distance (9090) among all routes advertising the exact same prefix mask length (192.168.10.0/24192.168.10.0/24).
When a router receives multiple routing updates for the exact same destination network prefix (192.168.10.0/24192.168.10.0/24), it uses Administrative Distance (AD) to evaluate which protocol source is most trustworthy. EIGRP internal routes have a default AD of 9090, which is lower (and thus preferred) over OSPF (110110), RIPv2 (120120), and the explicitly configured static route (130130).

Adım Adım Çözüm

1
Evaluate Longest Prefix Match (LPM)
All candidate routes advertise the exact same network prefix mask (192.168.10.0/24192.168.10.0/24), so prefix length comparison results in a tie.
Routers check prefix length specificity first before comparing routing source trustworthiness.
2
Compare Administrative Distance (AD) across competing protocols
EIGRP internal AD (9090) < OSPF AD (110110) < RIPv2 AD (120120) < Custom Static AD (130130).
Administrative Distance defines the trustworthiness of a route source; lower AD numbers indicate higher priority.
3
Select winning route for Forwarding Information Base (FIB)
The EIGRP route is selected and installed into the active routing table.
Metrics are only compared between routes learned from the exact same routing protocol instance, not across different protocols.

Anahtar Kavram

Administrative Distance Precedence in Route Selection
Soru 1773Soru

A security engineer is updating the baseline configuration of a remote branch router to comply with corporate security standards. The compliance mandate specifies two primary controls: preventing automated device discovery announcements from leaking network topology details to untrusted segments, and securing interactive management sessions against cleartext eavesdropping. Which set of configuration actions directly fulfills these security requirements?

Cevabı ve açıklamayı göster

Cevap: Disable CDP/LLDP on untrusted interfaces and restrict VTY lines to SSH transport.

Cevap

Disabling CDP/LLDP on untrusted interfaces and restricting VTY lines to SSH transport directly addresses both device hardening requirements.
Hardening best practices require disabling unencrypted discovery mechanisms (CDP/LLDP) on public or untrusted interfaces to minimize intelligence leakage. Simultaneously, remote terminal management must enforce secure, encrypted channels using SSH instead of cleartext protocols like Telnet.

Adım Adım Çözüm

1
Identify the protocol responsible for network topology discovery announcements.
CDP and LLDP broadcast device capabilities, system names, and IP addresses periodically.
Disabling CDP/LLDP on untrusted interfaces prevents unauthorized network reconnaissance.
2
Select the secure protocol for interactive remote management.
SSH encrypts session traffic over TCP port 22, whereas Telnet transmits data in cleartext.
Restricting virtual terminal (VTY) lines to accept SSH ensures encrypted management plane communication.

Anahtar Kavram

Management plane hardening via discovery protocol suppression and secure protocol enforcement
Soru 1774Soru

A network administrator is troubleshooting an issue where hosts on the 10.10.10.0/2410.10.10.0/24 management subnet cannot establish secure web connections to a server at 10.20.30.5010.20.30.50. Upon reviewing the inbound interface settings on the router, the administrator inspects the following Access Control List (ACL):

text 10 permit tcp 10.10.10.0 0.0.0.255 host 10.20.30.50 eq 80 20 deny ip any any

When attempting to access the server's web control portal via `https://10.20.30.50`, connection attempts time out. Which of the following identifies the root cause of this failure?

Cevabı ve açıklamayı göster

Cevap: The ACL permits HTTP traffic on port 80 rather than HTTPS traffic on port 443, causing HTTPS packets to match the deny rule.

Cevap

The ACL rule permits TCP port 80 (HTTP) instead of TCP port 443 (HTTPS), causing secure web connections to be blocked by the subsequent deny rule.
The correct option correctly identifies that HTTPS uses TCP port 443. Because rule 10 specifically matches `eq 80` (HTTP), packets destined for port 443 skip rule 10 and hit rule 20 (`deny ip any any`), resulting in a connection timeout.

Adım Adım Çözüm

1
Analyze the requested service protocol and target port.
Secure web traffic (`https://`) utilizes TCP port 443.
Identifying the target port is essential when evaluating ACL transport-layer matching rules.
2
Examine rule 10 of the active Access Control List.
Rule 10 permits TCP traffic targeting `eq 80` (HTTP).
Port 80 is for unencrypted HTTP traffic, not encrypted HTTPS traffic.
3
Evaluate how HTTPS traffic is processed through the ACL sequence.
HTTPS traffic (port 443) does not match rule 10 and falls through to rule 20 (`deny ip any any`).
ACLs process rules sequentially until a match is found; unmatched traffic falls through to subsequent deny rules.

Anahtar Kavram

ACL Port Filtering and Sequence Evaluation
Tahmini Süre:1m 30s
Soru 1775Soru

An enterprise organization recently expanded its data center by adding a secondary distribution switch to support a new multi-tenant virtualization cluster. During post-deployment testing, virtual machines assigned to VLAN 30 are unable to communicate with their default gateway, despite all physical cables being securely connected to the designated switch ports according to the hardware installation guide. Upon further investigation, a network analyst suspects that trunk encapsulation parameters, IP subnet boundaries, and virtual interface relationships were improperly provisioned on the inter-switch link. Which of the following documentation artifacts should the analyst reference to verify the intended 802.1Q VLAN IDs, logical network prefixes, and Layer 3 gateway assignments for this segment?

Cevabı ve açıklamayı göster

Cevap: Logical network diagram

Cevap

The logical network diagram is the correct documentation artifact because it explicitly details IP subnet allocations, 802.1Q VLAN assignments, and Layer 3 interface relationships.
Logical network diagrams depict the conceptual architecture of a network, including IP addressing schemes, subnet masks, 802.1Q VLAN boundaries, virtual interfaces, and routing boundaries. When troubleshooting misconfigured Layer 2/3 settings such as trunking tags or default gateways, the logical network diagram is the authoritative reference.

Adım Adım Çözüm

1
Analyze the technical requirements of the scenario.
The issue involves layer-3 gateway reachability, 802.1Q trunking, IP subnet prefixes, and VLAN identification.
Resolving logical routing and tagging errors requires documentation detailing software configuration abstractions rather than physical hardware placement.
2
Differentiate between logical and physical network documentation types.
Physical diagrams and rack elevations capture physical locations and cabling, whereas logical diagrams map virtual topologies, IP subnets, and VLAN structures.
Network configuration parameters such as gateway IPs and VLAN IDs exist at Layers 2 and 3 of the OSI model.
3
Select the documentation artifact that contains the required parameters.
The logical network diagram directly provides the missing configuration specification.
Logical diagrams represent the authoritative reference for network segmentation and addressing design.

Anahtar Kavram

Logical vs. Physical Network Documentation
Tahmini Süre:1m 30s
Soru 1776Soru

An organization is updating its disaster recovery documentation to ensure all team members understand key performance metrics. The network administrator needs to clarify the definitions of Recovery Time Objective (RTO) and Recovery Point Objective (RPO). Which of the following statements accurately describe these disaster recovery metrics? (Select TWO.)

Geçerli olan tümünü seçin

Cevabı ve açıklamayı göster

Cevap: RTO specifies the maximum acceptable duration of network and system downtime following an outage.; RPO measures the maximum acceptable amount of data loss measured in time prior to an incident.

Cevap

The statement identifying RTO as the maximum acceptable duration of downtime and the statement defining RPO as the maximum acceptable data loss measured in time are both correct.
Recovery Time Objective (RTO) dictates how quickly systems must be restored after a failure, defining maximum acceptable downtime. Recovery Point Objective (RPO) dictates how far back in time data recovery must go, defining maximum tolerable data loss.

Adım Adım Çözüm

1
Analyze the definition of Recovery Time Objective (RTO).
RTO establishes the service restoration timeframe goal (how long services can remain down).
It measures tolerable downtime from the moment a failure occurs until normal operations resume.
2
Analyze the definition of Recovery Point Objective (RPO).
RPO establishes the maximum age of data that must be recovered from backup storage (how much data loss is tolerable).
It dictates backup frequency; for example, an RPO of 4 hours requires backups at least every 4 hours.

Anahtar Kavram

Disaster Recovery Metrics (RTO vs RPO)
Soru 1777Soru

A wireless network administrator observes that roaming wireless clients in a multi-story corporate building consistently maintain connections to distant access points (APs) at very low received signal strength indicator (RSSI) values instead of roaming to nearer APs. This causes overall network degradation due to low data rates consuming excessive airtime. A physical site survey confirms that AP placement and transmit power levels are properly balanced across the floor plan. Which of the following configuration changes on the wireless LAN controller best remediates this sticky client behavior while optimizing overall airtime efficiency?

Cevabı ve açıklamayı göster

Cevap: Disabling legacy data rates (such as 1 Mbps1\text{ Mbps} through 11 Mbps11\text{ Mbps}) and raising the minimum basic data rate threshold on the wireless network

Cevap

Disabling legacy data rates and raising the minimum basic data rate threshold on the wireless network
Disabling low legacy data rates and increasing the minimum basic rate forces clients to disassociate and seek a stronger access point once their signal degrades below the set threshold. This prevents clients from lingering on distant access points at low transmission rates, freeing up wireless channel airtime and resolving sticky client issues.

Adım Adım Çözüm

1
Analyze the problem symptoms and underlying cause
Identify that sticky clients remain connected to distant APs at very low RSSI, transmitting at low data rates (e.g., 1 Mbps11 Mbps1\text{ Mbps} - 11\text{ Mbps}) which consumes excessive channel airtime.
Client devices evaluate roaming thresholds based on signal strength and data rate availability broadcast by the access point.
2
Evaluate wireless LAN controller rate tuning mechanisms
Disabling mandatory support for low legacy data rates shrinks the effective management cell boundary of each AP without altering RF physical power.
When a client drops below the configured minimum basic rate (e.g., 12 Mbps12\text{ Mbps} or 24 Mbps24\text{ Mbps}), it can no longer maintain management frames with that AP and is forced to roam to a closer AP with higher RSSI.
3
Verify airtime fairness impact
Eliminating low bitrates frees up valuable airtime for high-speed transmissions, improving total throughput for all connected wireless clients.
Slower bitrates require significantly longer channel occupancy times to transmit the same payload compared to higher OFDM rates.

Anahtar Kavram

Minimum Basic Data Rate Tuning and Airtime Fairness
Soru 1778Soru

A network administrator is assigned the IPv4 address block 10.20.0.0/2210.20.0.0/22 for a new branch location. The administrator needs to partition this block into equal-sized subnets, where each subnet must support at least 5050 usable host IP addresses. What is the maximum number of such subnets that can be created from this address block?

Cevabı ve açıklamayı göster

Cevap: 16

Cevap

The maximum number of subnets that can be created is 16.
To accommodate at least 50 hosts, each subnet requires 6 host bits because 262=622^6 - 2 = 62 usable addresses (5 host bits only provides 30 usable addresses). A subnet with 6 host bits uses a /26/26 prefix (326=2632 - 6 = 26). Subnetting a /22/22 prefix into /26/26 subnets borrows 4 bits (2622=426 - 22 = 4), resulting in 24=162^4 = 16 total subnets.

Adım Adım Çözüm

1
Determine the required host bits for each subnet.
6 host bits are required.
The formula for usable hosts per subnet is 2h22^h - 2. Setting h=6h = 6 yields 262=622^6 - 2 = 62 usable host IP addresses, satisfying the requirement of at least 50 hosts.
2
Determine the subnet CIDR prefix length.
The prefix length is /26/26.
Subtracting 6 host bits from the total 32 IPv4 bits gives 326=2632 - 6 = 26 network bits.
3
Calculate the total number of /26/26 subnets within the original /22/22 block.
16 subnets.
The difference between prefix lengths is 2622=426 - 22 = 4 borrowed subnet bits. Calculating 242^4 gives 16 subnets.

Anahtar Kavram

IPv4 Subnetting and Host Capacity Calculation
Tahmini Süre:1m 30s
Soru 1779Soru

A company is designing a disaster recovery plan and wants to lease an off-site secondary facility. The leased facility includes physical space, power, heating and cooling, and basic network connectivity, but contains no pre-installed computing hardware or restored data. Which type of recovery site does this location represent?

Cevabı ve açıklamayı göster

Cevap: Cold site

Cevap

The facility represents a cold site because it provides basic infrastructure utilities such as space, power, and cooling, but does not contain pre-installed hardware or active data.
A cold site is a secondary recovery location that provides essential physical infrastructure—such as power, HVAC, shell space, and basic communication links—but has no pre-installed server hardware, SAN storage, or active data backups. Organizations must bring in hardware and perform full system restores when activating a cold site.

Adım Adım Çözüm

1
Analyze the readiness parameters of the secondary facility described in the scenario.
The location includes physical space, power, HVAC, and network connectivity, but lacks pre-installed server hardware and data backups.
Categorizing a disaster recovery site requires evaluating the hardware and data readiness level.
2
Match the facility characteristics to standard disaster recovery site definitions.
A site with space and environmental utilities but no pre-configured computing hardware is defined as a cold site.
Cold sites are the least expensive recovery options but require the longest time to make fully operational after a disaster.

Anahtar Kavram

Disaster Recovery Site Classifications (Cold Site vs. Warm Site vs. Hot Site)
Tahmini Süre:45s
Soru 1780Soru

A workstation connected to an enterprise network fails to reach internal network resources. A network technician is assigned to troubleshoot the host's IP addressing and DHCP service connectivity. Arrange the diagnostic and troubleshooting steps in the correct order according to standard bottom-up network troubleshooting methodology.

Öğeleri doğru sıraya koymak için sürükleyin

Cevabı ve açıklamayı göster

Cevap

The correct troubleshooting sequence starts with inspecting physical network cabling and NIC link status, running `ipconfig /all` to evaluate the host IP configuration, verifying switch port VLAN assignment, checking `ip helper-address` (DHCP relay) settings on the default gateway, and finally checking central DHCP server scope statistics for pool exhaustion.
Following standard bottom-up network troubleshooting methodology, a technician verifies physical link connectivity (Layer 1) first, inspects host IP details (`ipconfig /all`) to identify APIPA assignment, checks access switch port VLAN configuration (Layer 2), verifies default gateway DHCP relay (`ip helper-address`) parameters (Layer 3), and finally inspects central DHCP server scope health and lease pool utilization.

Adım Adım Çözüm

1
Inspect Layer 1 physical link connectivity
Confirmed physical media connection and link signal LED activity on the NIC and switch port.
Rule out physical Layer 1 disconnects or faulty patch cables before analyzing protocol configurations.
2
Check local host IP address configuration
Determined the client has auto-assigned an APIPA address (169.254.x.x169.254.x.x).
Identify host-level IP parameters and establish that dynamic IP lease acquisition failed.
3
Verify access switch Layer 2 VLAN assignment
Confirmed the access switch port is assigned to the intended workstation VLAN.
Ensure client traffic resides within the proper broadcast domain and access control segment.
4
Inspect Layer 3 DHCP relay configuration
Verified `ip helper-address` is configured correctly on the gateway subinterface.
Ensure DHCP broadcast requests (255.255.255.255255.255.255.255) are relayed as unicast to the central DHCP server.
5
Verify central DHCP server scope utilization
Confirmed server scope health and available lease pool capacity.
Rule out server-level DHCP scope exhaustion or service failure preventing lease issuance.

Anahtar Kavram

Structured OSI bottom-up troubleshooting methodology applied to IP addressing and DHCP service failures
ÖncekiSayfa 89 / 112Sonraki
Tüm alıştırma soruları — CompTIA Network+ | Examkin