Network Troubleshooting

486 soru

Soru 461Soru

A network technician is systematically troubleshooting a workstation that is unable to access an internal web portal (`app1.corp.internal`). Order the command-line network utilities in the correct logical sequence to isolate this issue, following a bottom-up methodology from local host configuration to remote transport port verification.

Öğeleri doğru sıraya koymak için sürükleyin

Cevabı ve açıklamayı göster

Cevap

The correct troubleshooting sequence is: 1) `ipconfig /all` to verify local host configuration, 2) `ping` the default gateway to confirm local subnet communication, 3) `nslookup` the FQDN to confirm proper DNS resolution, 4) `tracert` the destination IP to pinpoint routing path failures, and 5) `Test-NetConnection -Port 443` to verify remote transport port availability.
A systematic bottom-up OSI troubleshooting workflow begins at Layer 1/2/3 local host configuration (`ipconfig`), moves to local network reachability (`ping` gateway), confirms DNS resolution (`nslookup`), traces path routing to the destination IP (`tracert`), and concludes with transport port verification (`Test-NetConnection`).

Adım Adım Çözüm

1
Verify local interface configuration
Confirmed IP address, subnet mask, and gateway details using `ipconfig /all`.
Troubleshooting must begin by verifying that the local node has valid network properties assigned.
2
Verify local gateway reachability
Confirmed ICMP echo reply from gateway using `ping 192.168.1.1`.
Testing the local default gateway verifies link-layer connectivity and local Layer 3 functionality.
3
Verify name resolution
Obtained resolved IP address (10.10.50.2010.10.50.20) using `nslookup app1.corp.internal`.
Name resolution must be validated to ensure subsequent path diagnostic tools target the correct IP address.
4
Analyze intermediate routing path
Evaluated hop-by-hop latency and packet reachability using `tracert 10.10.50.20`.
Tracing the route isolates upstream network layer failures along the path to the remote host.
5
Test specific transport service port
Confirmed TCP handshake on port 443 using `Test-NetConnection 10.10.50.20 -Port 443`.
Transport port checks verify that firewall policies permit traffic and the destination daemon is listening.

Anahtar Kavram

Bottom-Up Command-Line Network Troubleshooting Sequence
Soru 462Soru

A network administrator is addressing an issue where remote branch office routers intermittently drop OSPF neighbor adjacencies with the central core router following a WAN circuit bandwidth upgrade. Place the administrator's troubleshooting actions in the correct sequential order according to the CompTIA troubleshooting methodology, from the initial step to the final step.

Öğeleri doğru sıraya koymak için sürükleyin

Cevabı ve açıklamayı göster

Cevap

The correct sequence follows the CompTIA 6-step troubleshooting methodology: 1. Identify the problem (gathering symptoms through user interviews and log inspection), 2. Establish a theory of probable cause (hypothesizing WAN provider MTU mismatch), 3. Test the theory to determine the cause (executing ping tests with the DF bit set), 4. Establish a plan of action to resolve the problem and identify potential effects (drafting a change request and evaluating routing impacts), 5. Verify full system functionality and implement preventive measures (confirming stable OSPF FULL state and adding automated alerts), 6. Document findings, actions, and outcomes (recording resolution details in the central repository).
The correct order follows CompTIA's official 6-step sequence: 1. Identify the problem by gathering information from users and logs, 2. Establish a theory of probable cause by considering recent changes, 3. Test the theory using targeted diagnostic tools (DF-bit pings), 4. Establish a plan of action and identify potential effects before applying changes, 5. Verify full system functionality and implement preventive measures, and 6. Document findings, actions, and outcomes as the final administrative step.

Adım Adım Çözüm

1
Identify the problem
Problem symptoms and error messages are collected from users and router system logs.
Troubleshooting must begin by gathering information to accurately define the problem and establish its scope.
2
Establish a theory of probable cause
A working hypothesis linking recent WAN upgrades to MTU-related packet drops is formulated.
Formulating a theory narrows down diagnostic focus based on evidence and recent environmental changes.
3
Test the theory to determine the cause
Empirical testing with DF-bit pings confirms packet fragmentation drops at the WAN interface boundary.
Testing verifies whether the hypothesis is correct before making configuration changes in production.
4
Establish a plan of action and identify potential effects
A structured plan outlining specific MTU parameter adjustments and potential convergence impacts is developed.
A plan of action ensures changes are controlled and side effects on the live network are anticipated and minimized.
5
Verify full system functionality and implement preventive measures
OSPF neighbor stability is verified and proactive MTU monitoring alerts are established.
System verification confirms the problem is completely resolved, while preventive measures guard against recurrence.
6
Document findings, actions, and outcomes
Complete diagnostic logs, configuration steps, and outcomes are entered into the enterprise documentation portal.
Documentation completes the process by building institutional knowledge for future reference.

Anahtar Kavram

CompTIA Troubleshooting Methodology Sequence
Tahmini Süre:2m 0s
Soru 463Soru

A network engineer is troubleshooting several complex wireless performance issues across an enterprise facility. Match each observed diagnostic symptom to its underlying wireless RF or configuration root cause.

Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın

Öğeler

A laptop displays high signal strength (-52 dBm RSSI) near a metal-reinforced wall, but experiences severe throughput degradation and frame retransmission rates exceeding 40%.
Mobile devices fail to transition smoothly to nearer access points while moving through corridors, maintaining weak links to distant access points until connectivity drops completely.
Multiple 5 GHz access points located near a municipal flight path simultaneously cease broadcasting on their channels for 60 seconds before shifting to alternative frequencies.
Handheld inventory scanners experience sudden 15–20 dB drops in signal strength when warehouse operators rotate the devices from vertical to horizontal orientation.

Eşleşmeler

Cevabı ve açıklamayı göster

Cevap

Each wireless symptom maps directly to a specific RF phenomenon: High RSSI with excessive frame retries near reflective metal maps to multipath fading; failure to roam due to unequal transmit power maps to power asymmetry; temporary 60-second 5 GHz channel drops near flight paths map to Dynamic Frequency Selection (DFS) radar detection; and orientation-dependent signal loss maps to antenna polarization mismatch.
Diagnosing these symptoms requires correlating observable wireless failures with core RF principles: multipath propagation creates signal self-interference near reflective metal; unequal transmit power creates sticky clients that fail to roam; DFS regulatory mandates force 60-second channel quiet periods when radar is detected; and physical rotation of handheld units introduces antenna polarization misalignment.

Adım Adım Çözüm

1
Analyze high RSSI combined with excessive retransmissions around metal structures.
Identified as multipath fading.
Metallic surfaces reflect RF signals, causing multiple out-of-phase copies to arrive at the receiver and degrade frame decoding despite high total signal amplitude.
2
Analyze the roaming failure where client devices remain connected to distant access points.
Identified as transmit power asymmetry (sticky client behavior).
Disproportionately high access point transmit power keeps the client's received RSSI high enough to prevent roaming, even though the low-power client cannot reach the access point reliably.
3
Analyze the 60-second broadcast hiatus on 5 GHz channels near an airport.
Identified as DFS radar detection.
IEEE 802.11h DFS requires access points operating on restricted 5 GHz bands to vacate the channel immediately upon detecting radar signals and perform a 60-second silence period.
4
Analyze orientation-dependent signal attenuation on handheld scanners.
Identified as antenna polarization mismatch.
Aligning a vertical receiving antenna horizontally relative to a vertically polarized transmitting antenna results in severe cross-polarization signal loss.

Anahtar Kavram

Troubleshooting Advanced Wireless RF Anomalies and Signal Degradation
Soru 464Soru

A network administrator needs to ensure that a primary distribution switch is selected as the Spanning Tree Protocol (STP) root bridge across the local switching domain. Which of the following configuration modifications will achieve this goal?

Cevabı ve açıklamayı göster

Cevap: Set the switch's STP bridge priority to the lowest available numerical value.

Cevap

Set the switch's STP bridge priority to the lowest available numerical value.
In Spanning Tree Protocol (STP), the root bridge is chosen based on the lowest Bridge ID, which is a combination of the configurable bridge priority and the switch MAC address. Decreasing the bridge priority to a lower value ensures that the switch will have a smaller Bridge ID than its peers and will be elected as the root bridge.

Adım Adım Çözüm

1
Identify how Spanning Tree Protocol (STP) selects the root bridge.
STP compares Bridge IDs (Bridge Priority + MAC address) across all switches in the Layer 2 domain.
The root bridge election algorithm awards root bridge status to the switch possessing the lowest numerical Bridge ID.
2
Determine the required configuration adjustment to force a specific switch to win the root bridge election.
Lowering the bridge priority value on the target switch ensures its Bridge ID is smaller than that of all neighboring switches.
Standard STP switches use a default priority of 32768. Lowering this value (e.g., to 4096 or 0) forces the switch to become the root bridge.

Anahtar Kavram

STP Root Bridge Election and Priority Calibration
Soru 465Soru

A workstation at 10.20.1.50/2410.20.1.50/24 cannot access an internal application server at 172.16.50.10172.16.50.10. The administrator suspects a default gateway mismatch, a missing static route, or an Access Control List (ACL) dropping the traffic on the core Layer 3 switch. Place the following troubleshooting steps in the correct sequential order according to standard network troubleshooting methodology.

Öğeleri doğru sıraya koymak için sürükleyin

Cevabı ve açıklamayı göster

Cevap

The correct sequence follows standard network troubleshooting methodology: 1) Run `ping` and `traceroute` from the workstation to isolate local vs. remote failure; 2) Review switch routing tables and ACL rules to establish a cause theory; 3) Test the theory using controlled CLI commands from the gateway; 4) Update the ingress ACL on the core switch; 5) Verify end-to-end host connectivity and update network documentation logs.
The proper troubleshooting sequence follows standard CompTIA methodology: gather initial host diagnostics (`ping`/`traceroute`), examine gateway configuration states to form a hypothesis, test the theory via targeted CLI tests, implement the corrective ACL statement, and verify end-to-end application functionality before documenting the outcome.

Adım Adım Çözüm

1
Gather symptoms and isolate the layer/location of failure using host CLI diagnostic commands.
Determines whether the issue resides at the local NIC, default gateway interface, or upstream routing hop.
Troubleshooting must begin by identifying the problem scope before examining network infrastructure configurations.
2
Analyze gateway routing tables (`show ip route`) and interface ACL configurations (`show ip access-lists`).
Identifies potential misconfigurations such as implicit deny ACL entries or missing summary routes.
This establishes a plausible theory of probable cause based on empirical device configuration data.
3
Test the ACL hypothesis using diagnostic command simulations from the router CLI.
Confirms whether ingress packet filtering or dynamic routing table updates caused the drops.
The theory must be empirically tested and validated prior to executing changes on production equipment.
4
Apply the updated ACL permit entry to the appropriate switch VLAN interface.
Permits host traffic through the default gateway to the remote server subnet.
Implementing the solution resolves the verified root cause.
5
Verify application-layer connectivity from the client host and document the resolution.
Ensures full system functionality and maintains accurate operational change records.
Final phases require confirming complete service restoration and recording change management details.

Anahtar Kavram

CompTIA Network Troubleshooting Methodology applied to Default Gateways, Routing, and ACLs
Soru 466Soru

A network administrator is reviewing switch console logs and interface statistics to diagnose several Layer 2 performance and connectivity issues across the enterprise network. Match each specific switch error output or diagnostic symptom on the left with its primary underlying root cause on the right.

Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın

Öğeler

Interface statistics show a rapidly increasing count of late collisions and FCS errors during peak traffic load.
Console log persistently reports %CDP-4-NATIVE_VLAN_MISMATCH on inter-switch trunk link interface GigabitEthernet0/1.
Access port interface GigabitEthernet0/10 enters an err-disabled state with log %SPANTREE-2-BLOCK_BPDUGUARD.
Trunk port successfully forwards frames for VLAN 10 and VLAN 20, but drops all frames for VLAN 30 despite VLAN 30 existing in the active VLAN database.

Eşleşmeler

Cevabı ve açıklamayı göster

Cevap

Late collisions and FCS errors match with Speed/Duplex mismatch. CDP native VLAN mismatch logs match with Mismatched native VLAN configuration across 802.1Q trunk endpoints. BPDU Guard error-disabled log matches with Reception of BPDUs on an edge access port. Traffic drop for active VLAN 30 on trunk matches with VLAN 30 omitted from the trunk allowed VLAN list.
Each diagnostic log message and port metric directly aligns with a fundamental Layer 2 misconfiguration: late collisions indicate a duplex mismatch where half-duplex senses collision after slot time; CDP warnings isolate mismatched native VLAN settings; BPDU Guard messages indicate unexpected STP frames on edge ports; and selective VLAN traffic loss on trunks points to allowed-list misconfigurations.

Adım Adım Çözüm

1
Analyze interface collision and error metrics.
Identify late collisions as the classic indicator of a duplex mismatch between full-duplex and half-duplex endpoints.
The full-duplex endpoint transmits at any time, causing the half-duplex endpoint to detect collisions after sending the preamble and slot time (64 bytes).
2
Inspect CDP diagnostic log warnings.
Determine that %CDP-4-NATIVE_VLAN_MISMATCH directly indicates mismatched untagged VLAN IDs on trunk link ends.
802.1Q trunks expect identical native VLAN IDs on both ends to ensure untagged control and data frames route to the correct broadcast domain.
3
Evaluate Spanning Tree Protocol port security features.
Recognize that receiving BPDUs on a BPDU Guard enabled port triggers the %SPANTREE-2-BLOCK_BPDUGUARD error and disables the port.
BPDU Guard prevents rogue switches or unauthorized bridge connections from altering the STP topology via designated edge access ports.
4
Verify trunking allowed-list parameters against active VLANs.
Establish that omitting a VLAN from `switchport trunk allowed vlan` causes the switch to filter and drop frames for that VLAN on the trunk interface.
Global VLAN database existence is necessary but insufficient; the VLAN must also be permitted on the specific trunk interface allowed list.

Anahtar Kavram

Troubleshooting Layer 2 Switching, Trunking, Duplex, and Spanning Tree Operational Issues
Soru 467Soru

A network technician is investigating several common Layer 2 switching and trunking issues on a campus network. Match each observed diagnostic symptom or console log message on the left with its corresponding underlying root cause on the right.

Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın

Öğeler

Console logs repeatedly display: %CDP-4-NATIVE_VLAN_MISMATCH discovered on interface GigabitEthernet0/1.
Interface statistics show an increasing count of late collisions and alignment errors on a full-duplex link.
An unexpected switch becomes the STP Root Bridge following a power outage due to default priority settings.
A workstation cannot reach its default gateway after being plugged into a newly provisioned switch port.

Eşleşmeler

Cevabı ve açıklamayı göster

Cevap

CDP Native VLAN mismatch log maps to mismatched untagged VLAN IDs across trunk ends; Late collisions and alignment errors map to a duplex mismatch between connected interfaces; Unintended STP root bridge election maps to default STP priority tie-breaking via MAC address; Workstation gateway unreachability maps to incorrect switch port VLAN assignment.
Each symptom directly corresponds to a fundamental Layer 2 switching error: CDP Native VLAN logs indicate mismatched untagged trunk VLANs; late collision counters indicate a duplex negotiation mismatch; default STP priority causes root elections based on MAC address; and lack of gateway access on a new port typically indicates incorrect access VLAN assignment.

Adım Adım Çözüm

1
Analyze CDP error messages
Identify that %CDP-4-NATIVE_VLAN_MISMATCH explicitly indicates mismatched native (untagged) VLAN numbers on an 802.1Q trunk connection.
802.1Q trunks require identical native VLAN settings on both connected switch ports to prevent traffic leakage across VLAN boundaries.
2
Analyze interface error counters for late collisions
Correlate late collisions with a speed/duplex mismatch where one interface is set to half-duplex and the connected interface is set to full-duplex.
Full-duplex transmits without listening, causing the half-duplex side to detect a collision after its 64-byte collision window (late collision).
3
Evaluate Spanning Tree Protocol root election criteria
Determine that when STP priority is unconfigured (default 32768), the switch with the numerically lowest MAC address wins the root bridge election.
Bridge ID consists of Priority + System ID Extension + MAC Address; default priorities force election based on MAC address.
4
Investigate host VLAN isolation symptoms
Recognize that a host connected to a port left in default VLAN 1 cannot reach a default gateway configured on a different functional VLAN.
VLANs isolate Layer 2 broadcast domains, requiring inter-VLAN routing to communicate across different VLAN IDs.

Anahtar Kavram

Troubleshooting VLAN, Trunking, and Switching Issues
Soru 468Soru

A network administrator is troubleshooting an issue where a workstation cannot access a critical web database service hosted at `db01.corp.internal` on TCP port 8443 in a remote subnet. Following standard network troubleshooting methodology to systematically isolate the issue from the local network layer up through path routing, domain name resolution, and transport socket state, in what logical sequence should the administrator execute the command-line network utilities?

Öğeleri doğru sıraya koymak için sürükleyin

Cevabı ve açıklamayı göster

Cevap

The correct logical execution sequence begins with local adapter configuration verification (`ipconfig /all`), followed by local gateway ICMP reachability (`ping 192.168.1.1`), then path routing analysis via destination IP (`tracert -d 10.250.32.50`), explicit DNS query resolution (`nslookup db01.corp.internal 10.1.1.5`), and concludes with transport layer socket state inspection (`netstat -ano | findstr :8443`).
Structured network troubleshooting mandates moving logically from the local host configuration outward through the network infrastructure up to higher-layer application services. Step 1 validates local interface settings (`ipconfig /all`). Step 2 tests local LAN/gateway reachability (`ping gateway`). Step 3 traces the Layer 3 path using an IP address to bypass DNS dependencies (`tracert -d IP`). Step 4 confirms domain name mapping via DNS (`nslookup FQDN DNS_IP`). Step 5 evaluates specific Layer 4 TCP port handshake and connection states (`netstat -ano`).

Adım Adım Çözüm

1
Verify local TCP/IP protocol stack and interface settings using `ipconfig /all`.
Confirms valid IP addressing, subnet mask, default gateway IP, and primary DNS server IP.
Root cause isolation must start at Layer 1-3 on the local endpoint before sending traffic across the network.
2
Test local link and default gateway communication using `ping 192.168.1.1`.
Determines whether local Layer 2 switching and local Layer 3 router interface communication is operational.
If the local gateway is unreachable, traffic cannot be routed to remote subnets.
3
Trace the Layer 3 routing path using IP address targeting with `tracert -d 10.250.32.50`.
Identifies the exact WAN/VPN router hop where packet forwarding fails or experiences severe latency.
Using `-d` bypasses DNS lookups during path tracing, preventing DNS failures from masking path routing failures.
4
Query DNS service directly using `nslookup db01.corp.internal 10.1.1.5`.
Verifies whether the internal DNS server returns the accurate A/AAAA resource record for the target FQDN.
Isolates application reachability failures caused by incorrect DNS records or DNS server unresponsiveness.
5
Analyze transport session establishment using `netstat -ano | findstr :8443`.
Displays active TCP connection states (e.g., SYN_SENT, ESTABLISHED, TIME_WAIT) for the target port.
Determines whether Layer 4 TCP three-way handshake succeeds or is blocked by access control lists (ACLs) or firewalls.

Anahtar Kavram

Bottom-Up and Layered CLI Diagnostic Workflow for Network Troubleshooting
Soru 469Soru

A system administrator is troubleshooting a hostname resolution issue on a Linux workstation. Users report they cannot connect to an internal intranet site at `app.dev.local`. The administrator executes a diagnostic DNS query using `dig` and receives the following terminal output snippet:

;; QUESTION SECTION:
;app.dev.local. IN A

;; ANSWER SECTION:
app.dev.local. 300 IN CNAME web-server-01.dev.local.

;; AUTHORITY SECTION:
dev.local. 3600 IN NS ns1.dev.local.

The output shows an alias (CNAME) pointing to `web-server-01.dev.local`, but no corresponding IPv4 address (`A` record) is included in the response. Based on this command-line output, which command should the administrator run NEXT to directly query the designated authoritative server `ns1.dev.local` specifically for the missing `A` record of target host `web-server-01.dev.local`?

Cevabı ve açıklamayı göster

Cevap: dig @ns1.dev.local web-server-01.dev.local A

Cevap

Execute the command `dig @ns1.dev.local web-server-01.dev.local A` to query the authoritative name server directly for the missing A record.
The command `dig @ns1.dev.local web-server-01.dev.local A` is correct because using the `@` symbol instructs `dig` to bypass local DNS resolution and query `ns1.dev.local` directly. Specifying `web-server-01.dev.local` and `A` requests the IPv4 address mapped to the canonical hostname discovered in the CNAME response.

Adım Adım Çözüm

1
Analyze the initial `dig` output
The query for `app.dev.local` returns a CNAME pointing to `web-server-01.dev.local` and identifies `ns1.dev.local` in the AUTHORITY SECTION as the domain's primary name server.
The local recursive resolver did not append the target A record for the canonical name `web-server-01.dev.local` in the initial response.
2
Identify the required command-line syntax for querying specific DNS servers with `dig`
The `@` symbol is used in `dig` to designate a specific DNS server to query, followed by the domain name and record type.
Bypassing the local cache/stub resolver and querying `ns1.dev.local` directly confirms whether the authoritative server holds the valid A record.
3
Formulate the exact command
`dig @ns1.dev.local web-server-01.dev.local A`
This correctly targets `@ns1.dev.local` for the hostname `web-server-01.dev.local` requesting record type `A`.

Anahtar Kavram

Utilizing `dig` to perform directed DNS queries against specific authoritative name servers for specific record types.
Tahmini Süre:2m 0s
Soru 470Soru

A network technician is investigating a connectivity issue on a Linux workstation. When executing `nslookup repo.corp.local`, the command returns an IP address of `10.50.10.25` from the internal DNS server. However, ping commands and web browser traffic directed to `repo.corp.local` consistently attempt to connect to `10.50.10.99`, resulting in connection timeouts.

Which of the following is the most likely cause of this name resolution discrepancy?

Cevabı ve açıklamayı göster

Cevap: The local /etc/hosts file contains an outdated entry mapping repo.corp.local to 10.50.10.99.

Cevap

The local /etc/hosts file contains an outdated entry mapping repo.corp.local to 10.50.10.99.
The correct answer identifies that the local `/etc/hosts` file contains an outdated mapping. In operating systems like Linux and Windows, standard applications (such as web browsers or the `ping` utility) follow the system's name resolution order, which prioritizes the local `hosts` file before sending a query to a DNS server. In contrast, diagnostic tools like `nslookup` bypass the local `hosts` file and query the configured DNS server directly. Therefore, `nslookup` retrieves the correct IP address (`10.50.10.25`) from DNS, while applications read the stale entry (`10.50.10.99`) from `/etc/hosts`.

Adım Adım Çözüm

1
Analyze the difference between how nslookup operates versus standard OS application traffic.
Recognize that nslookup uses its own internal stub resolver code to query configured DNS servers directly, ignoring local host files.
Utility tools like nslookup bypass local operating system host lookup files (/etc/hosts).
2
Examine the operating system name resolution order for standard network applications (ping, browsers).
Determine that OS applications consult local host files (/etc/hosts) prior to querying external or internal DNS servers.
Default OS Name Service Switch configuration checks local file entries before sending DNS queries.
3
Correlate the behavior to the root cause.
An old entry in /etc/hosts causes ping and browsers to use 10.50.10.99, while nslookup accurately fetches 10.50.10.25 from DNS.
A static host entry overrides dynamic DNS query results for general system traffic.

Anahtar Kavram

Operating System Name Resolution Order vs Direct DNS Diagnostic Utility Behavior
Soru 471Soru

A network technician is troubleshooting a network outage where hosts on VLAN 30 (192.168.30.0/24192.168.30.0/24) are unable to reach an internal application server on VLAN 50 (192.168.50.10192.168.50.10). Following the CompTIA network troubleshooting methodology, place the actions in the correct sequential order from first step to last step.

Öğeleri doğru sıraya koymak için sürükleyin

Cevabı ve açıklamayı göster

Cevap

The correct order follows the CompTIA Network Troubleshooting Methodology: 1. Gather network symptoms, 2. Formulate a hypothesis (theory of probable cause), 3. Inspect ACL rules with show commands (test the theory), 4. Draft a change plan, 5. Apply corrected ACL and verify connectivity (implement and verify), 6. Log findings and resolution in tickets (document outcomes).
The correct sequence aligns strictly with the 7-step CompTIA network troubleshooting methodology: (1) Identify the problem by gathering symptoms, (2) Establish a theory of probable cause, (3) Test the theory to determine cause, (4) Establish a plan of action, (5) Implement the solution and verify full system functionality, and (6) Document findings, actions, and outcomes.

Adım Adım Çözüm

1
Identify the problem
Information gathered from affected users and initial diagnostic commands.
Troubleshooting must begin with identifying symptoms and scope.
2
Establish a theory of probable cause
Hypothesis generated regarding an ACL blocking cross-VLAN traffic.
Developing a logical theory focuses diagnostic efforts.
3
Test the theory
Router ACL inspection confirms traffic hits an implicit deny statement.
Testing validates whether the hypothesis is accurate before making network modifications.
4
Establish a plan of action
Change request drafted detailing syntax changes and risk assessment.
Planning ensures changes are controlled and potential unintended consequences are mitigated.
5
Implement solution & verify functionality
ACL updated on router interface and ping/traceroute tests confirm restored access.
The fix must be deployed and validated to ensure the issue is completely resolved.
6
Document findings
Ticket updated with root cause, ACL configuration details, and resolution status.
Proper documentation preserves operational knowledge for future incidents.

Anahtar Kavram

CompTIA Network Troubleshooting Methodology applied to Routing and ACL issues
Soru 472Soru

Match each physical network cabling diagnostic tool on the left with the specific troubleshooting scenario or measurement task on the right for which it is primary suited.

Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın

Öğeler

Optical Power Meter (OPM)
Time-Domain Reflectometer (TDR)
Tone Generator and Probe
Cable Certifier

Eşleşmeler

Cevabı ve açıklamayı göster

Cevap

Optical Power Meter matches with measuring optical signal power loss; Time-Domain Reflectometer matches with determining precise location and distance to a conductor break; Tone Generator and Probe matches with tracing an unlabelled copper patch cable; Cable Certifier matches with verifying Category 6A compliance for parameters like NEXT and attenuation.
Each diagnostic instrument pairs with its designated function: Optical Power Meters quantify dB light loss across fiber strands; Time-Domain Reflectometers measure signal reflection return times to pinpoint copper conductor breaks; Tone Generators with Probes trace wire paths in crowded cabinets via inductive audio signals; and Cable Certifiers evaluate complex parameters like NEXT and return loss to verify TIA/EIA compliance.

Adım Adım Çözüm

1
Analyze the physical media and diagnostic requirement for each item.
Fiber testing requires optical measuring devices; distance-to-fault analysis on twisted pair uses impedance reflection; wire location uses signal tracing; standards certification requires high-frequency metric validation.
Matching tool capabilities to physical layer phenomena ensures correct diagnostic tool selection.
2
Pair each diagnostic tool with its matching primary application.
OPM monitors optical decibel loss; TDR uses pulse reflection timings to locate copper breaks; Tone/Probe identifies wire paths inductively; Cable Certifier tests TIA/EIA Category metrics (such as NEXT).
Each tool addresses specific physical attributes of copper or fiber cabling infrastructure.

Anahtar Kavram

Physical Cabling Diagnostic Tools and Capabilities
Soru 473Soru

A datacenter technician is troubleshooting a newly installed single-mode fiber optic link between two core switches that fails to establish a link status. A visual fault locator (VFL) confirms light continuity from end to end, but the switch transceivers report an absolute lack of signal. Which diagnostic instrument should the technician use to measure the exact optical loss in decibels (dB) and verify if the signal strength meets the transceiver operating specifications?

Cevabı ve açıklamayı göster

Cevap: An optical power meter paired with a calibrated optical light source

Cevap

An optical power meter paired with a calibrated optical light source
An optical power meter paired with an optical light source is designed specifically to test fiber optic runs by sending a light signal of known wavelength and power from one end and measuring the signal strength at the receiving end. This calculates total decibel (dB) loss to verify if the link complies with transceiver specifications.

Adım Adım Çözüm

1
Identify the media type and symptom requirements
The link utilizes single-mode optical fiber cabling, and the task requires quantifying optical loss (attenuation in dB) against transceiver power tolerances.
While a visual fault locator verifies continuity by projecting visible light, it cannot measure optical power levels or decibel loss.
2
Evaluate diagnostic instruments for fiber optic signal strength measurement
An optical power meter (OPM) combined with a calibrated optical light source measures signal attenuation by comparing emitted power with received power across the cable run.
Instruments intended for copper media rely on electrical signals and cannot interface with optical strands.
3
Select the correct testing equipment
The optical power meter paired with a calibrated light source is the accurate diagnostic tool for determining decibel loss.
This tool directly measures dB loss to confirm whether insertion loss exceeds the optical budget.

Anahtar Kavram

Selecting proper fiber optic testing tools to measure decibel attenuation and optical power levels.
Tahmini Süre:1m 0s
Soru 474Soru

An industrial IoT controller installed in a warehouse facility on VLAN 12 (subnet 10.120.12.0/2410.120.12.0/24) fails to send telemetry data to the central management server. A network technician reviews the controller's active network settings via a serial console connection and observes the following configuration details:

IP Address: 10.120.12.45
Subnet Mask: 255.255.255.0
Default Gateway: 10.120.13.1
DHCP Server: 10.120.1.10

Which of the following root causes explains why the controller cannot communicate with servers outside its local subnet?

Cevabı ve açıklamayı göster

Cevap: The default gateway is configured on a different IP subnet than the host.

Cevap

The default gateway address (10.120.13.1) resides outside the local subnet (10.120.12.0/24) assigned to the host, preventing remote IP routing.
For IP routing to function, a host's default gateway address must belong to the same local IP subnet defined by the host's IP address and subnet mask. Here, the host is on 10.120.12.0/24 while the gateway is configured as 10.120.13.1. As a result, the host cannot send traffic off its local network.

Adım Adım Çözüm

1
Analyze host network configuration parameters
Host IP is 10.120.12.45 with a netmask of 255.255.255.0 (/24). The valid host range for this local subnet is 10.120.12.1 through 10.120.12.254.
Determines the boundaries of the host's local Layer 3 network domain.
2
Evaluate the configured default gateway IP address
The gateway is configured as 10.120.13.1, which falls into the 10.120.13.0/24 subnet.
A host must have a default gateway located on its own local subnet to resolve the gateway's MAC address via ARP.
3
Identify the communication barrier
Because the gateway IP is not on the host's local subnet, the host cannot perform ARP resolution for its default gateway, preventing packets destined for remote subnets from being forwarded.
Explains why remote telemetry traffic fails while local subnet parameters might otherwise look functional.

Anahtar Kavram

Subnet Mask and Default Gateway Adjacency
Soru 475Soru

A network technician is troubleshooting an issue where remote users cannot reach an internal web server at IP address 192.168.10.45192.168.10.45 over a secure connection. The technician executes a diagnostic utility directly on the server to inspect network socket states, receiving the following output:

$ ss -tuln
Netid State Recv-Q Send-Q Local Address:Port Peer Address:Port
tcp LISTEN 0 128 0.0.0.0:22 0.0.0.0:*
tcp LISTEN 0 128 0.0.0.0:80 0.0.0.0:*
udp UNCONN 0 0 0.0.0.0:67 0.0.0.0:*

Based on the command output above, which of the following best explains why client HTTPS requests to `https://192.168.10.45` are failing?

Cevabı ve açıklamayı göster

Cevap: The web server daemon is not currently running or bound to listen on TCP port 443.

Cevap

The web server daemon is not currently running or bound to listen on TCP port 443.
The `ss` (socket statistics) command with `-tuln` flags displays listening TCP and UDP sockets with numeric port formatting. Standard HTTPS traffic relies on TCP port 443. In the provided terminal output, only TCP ports 22 (SSH) and 80 (HTTP) are listed under the `LISTEN` state. Because TCP port 443 is missing from the list, the web server daemon is either stopped, misconfigured, or not bound to port 443.

Adım Adım Çözüm

1
Analyze the CLI utility command flags
The `ss -tuln` command queries socket statistics for TCP (`-t`), UDP (`-u`), listening sockets (`-l`), using numeric port numbers (`-n`).
Understanding command switches ensures accurate output parsing.
2
Examine the active listening sockets in the terminal snippet
Identified TCP port 22 (SSH), TCP port 80 (HTTP), and UDP port 67 (DHCP server).
Pinpoints which transport protocols and port numbers are actively accepting incoming connections.
3
Correlate missing socket listeners with the reported failure symptom
HTTPS traffic requires an active listener on TCP port 443. Because port 443 does not appear in the listening state list, incoming HTTPS connection requests cannot complete a TCP 3-way handshake.
Identifies the root cause of connection failures.

Anahtar Kavram

Socket State Analysis using Command-Line Utilities
Tahmini Süre:2m 0s
Soru 476Soru

A network engineer is investigating why client workstations cannot establish a secure web session to an internal web service at `https://app.corp.local`. The engineer executes two CLI diagnostic commands:

1. On the Linux web server host:
text
$ ss -tuln
Netid State Recv-Q Send-Q Local Address:Port Peer Address:Port Process
tcp LISTEN 0 128 0.0.0.0:80 0.0.0.0:*

2. On a client workstation:
text
$ nslookup app.corp.local 192.168.10.5
Server: dns01.corp.local
Address: 192.168.10.5

Non-authoritative answer:
Name: app.corp.local
Address: 10.20.30.100

Based on the output of these command-line utilities, which TWO statements accurately diagnose the network status and root cause of the connection failure?

Geçerli olan tümünü seçin

Cevabı ve açıklamayı göster

Cevap: The target web application daemon is currently bound to and listening on TCP port 80 (HTTP) rather than TCP port 443 (HTTPS).; Name resolution for `app.corp.local` successfully resolved to IP address 10.20.30.100, confirming that DNS resolution is functioning properly.

Cevap

The web service process is listening on TCP port 80 instead of TCP port 443, and the DNS resolution for the host is functioning correctly.
Analyzing `ss -tuln` reveals the server is listening for HTTP traffic on TCP port 80 rather than HTTPS on TCP port 443, explaining why HTTPS connections fail. Additionally, `nslookup` successfully resolves `app.corp.local` to `10.20.30.100`, establishing that DNS resolution is functioning properly.

Adım Adım Çözüm

1
Analyze the output of `ss -tuln` on the web server host
Identified an active TCP listening socket on `0.0.0.0:80`, demonstrating that the daemon is listening for unencrypted HTTP traffic on port 80 rather than encrypted HTTPS traffic on port 443.
HTTPS requires a service listening on TCP port 443. Traffic sent to port 443 will be rejected when no process is listening on that port.
2
Analyze the output of `nslookup app.corp.local 192.168.10.5` on the client workstation
Confirmed that the hostname resolves to IP address `10.20.30.100`.
A valid IP address response confirms Layer 7 name resolution is working, regardless of whether the answer was served from cache (non-authoritative).

Anahtar Kavram

Interpreting network troubleshooting CLI utility outputs (`ss` / `netstat` socket states and `nslookup` DNS responses)
Soru 477Soru

A network technician is troubleshooting a newly installed Cat6 unshielded twisted-pair (UTP) cable run connecting a workstation to a switch patch panel. While a basic pin-to-pin continuity cable tester confirms that all eight conductors are connected straight-through with no open or short circuits, the connection suffers from severe packet loss and degraded throughput when transmitting data. Which of the following cable testing features or tools should the technician use to identify the root cause of this performance failure?

Cevabı ve açıklamayı göster

Cevap: A wiremap tester capable of detecting split pairs

Cevap

A wiremap tester capable of detecting split pairs is required because split pairs maintain straight-through electrical continuity but disrupt pair twisting, causing severe electromagnetic interference and crosstalk.
A wiremap tester equipped to detect split pairs is the correct choice because split pairs occur when conductors from different twisted pairs are wired to pin pairs in parallel across both ends of a cable. This configuration maintains DC continuity (passing a basic pin-to-pin tester), but completely eliminates the differential cancellation of electromagnetic interference provided by twisted pairs, resulting in severe near-end crosstalk (NEXT) and packet corruption during high-speed data transmission.

Adım Adım Çözüm

1
Analyze the symptoms presented in the scenario
Electrical continuity tests pass (no open or short circuits), but data transmission experiences severe packet loss and poor performance.
This indicates that physical electrical continuity is intact, but transmission properties (such as crosstalk resilience) are compromised.
2
Evaluate how split pair wiring affects twisted-pair copper cables
Split pairs occur when two wires from different twisted pairs are swapped at both ends of a cable run. Pin 1 connects to Pin 1, Pin 2 connects to Pin 2, etc., passing basic continuity checks.
Because conductors are paired with wires outside their protective twist, differential mode noise cancellation fails, causing high crosstalk and signal degradation.
3
Select the appropriate diagnostic tool feature
An advanced wiremap tester or cable certifier specifically tests pair geometry and detects split pairs.
Standard continuity testers only verify pin-to-pin DC electrical continuity, whereas advanced wiremap testers evaluate pair mapping to detect split pairs.

Anahtar Kavram

Identifying split pairs using advanced wiremap testing
Soru 478Soru

A network technician is troubleshooting a complete link failure across a 500-meter single-mode fiber-optic run that connects two building distribution switches through an underground conduit. The technician needs to determine whether the fiber core has suffered a physical break and measure the exact distance to the fault location from the patch panel. Which diagnostic tool should the technician use?

Cevabı ve açıklamayı göster

Cevap: An optical time-domain reflectometer (OTDR)

Cevap

An optical time-domain reflectometer (OTDR) is the correct tool to locate the distance to a fault in a long fiber-optic cable run.
An optical time-domain reflectometer (OTDR) transmits light pulses down an optical fiber and analyzes the Rayleigh backscattering and Fresnel reflections. By measuring the elapsed time of returned reflections, it accurately plots attenuation along the cable and calculates the precise distance to physical breaks, splices, or microbends.

Adım Adım Çözüm

1
Identify the key requirement in the troubleshooting scenario
The technician needs to locate the exact distance to a physical break in a long (500-meter) fiber-optic cable run.
Different optical diagnostic tools serve distinct purposes such as measuring total loss versus pinpointing specific fault distances.
2
Evaluate optical testing tool capabilities
An optical time-domain reflectometer (OTDR) sends high-frequency light pulses into the fiber and measures the time and intensity of reflected light backscatter, calculating the exact distance to high-reflection anomalies like breaks or splices.
Only reflectometry tools (TDR for copper, OTDR for fiber) can calculate distance to a fault based on signal reflection velocity.
3
Eliminate inappropriate tools for distance-to-fault determination
Optical power meters only measure overall decibel loss end-to-end; visual fault locators only work for nearby visible breaks; tone probes only work on copper wire.
Selecting the incorrect tool results in ineffective diagnostic testing and unnecessary downtime.

Anahtar Kavram

Fiber Optic Fault Location with Optical Time-Domain Reflectometry (OTDR)
Tahmini Süre:1m 0s
Soru 479Soru

A network administrator is investigating two distinct issues following an office expansion: several new workstation copper cabling drops are experiencing intermittent physical link loss, while other hosts on the subnet are intermittently failing to obtain valid IP configuration settings due to suspected rogue server activity on the local VLAN. Which of the following tools and diagnostic approaches should the technician utilize to isolate these issues? (Select TWO)

Geçerli olan tümünü seçin

Cevabı ve açıklamayı göster

Cevap: Use a Time-Domain Reflectometer (TDR) to measure internal signal reflections and determine the exact distance to a physical break or impedance discontinuity along the copper cable run.; Apply a packet analyzer capture filter for UDP ports 67 and 68 to capture and inspect DHCP transaction traffic across the local broadcast domain.

Cevap

To isolate physical cabling faults and rogue DHCP server activity, the administrator should use a Time-Domain Reflectometer (TDR) to pinpoint cable break locations by distance, and apply a packet analyzer filter specifying UDP ports 67 and 68 to capture DHCP transaction packets.
The combination of using a Time-Domain Reflectometer (TDR) for distance-to-fault location on copper cabling and filtering a packet analyzer on UDP ports 67 and 68 for DHCP traffic correctly addresses both troubleshooting requirements. A TDR analyzes electrical pulse reflections to determine the location of cable breaks, while UDP ports 67/68 capture all DHCP server offers to pinpoint rogue DHCP servers.

Adım Adım Çözüm

1
Select the appropriate physical layer tester for locating specific cable distance breaks.
Identify that a Time-Domain Reflectometer (TDR) emits electrical pulses to measure signal reflection timing, directly outputting the distance to cable anomalies.
Basic continuity testers only check wire mapping and pin continuity without distance metrics.
2
Determine the transport protocol and port parameters for analyzing DHCP traffic.
Identify that DHCP operates on UDP port 67 (DHCP server) and UDP port 68 (DHCP client).
Filtering packet captures on UDP ports 67 and 68 isolates DHCP Discover, Offer, Request, and Acknowledgment frames to identify unauthorized server IP and MAC addresses.

Anahtar Kavram

Utilizing TDR hardware for physical fault distance measurement and packet analyzers for UDP-based protocol troubleshooting.
Tahmini Süre:1m 30s
Soru 480Soru

A network administrator is investigating connectivity and performance problems on an 802.1Q trunk link connecting a distribution switch to a newly provisioned access switch. Syslog entries on the distribution switch repeatedly record %CDP-4-NATIVE_VLAN_MISMATCH alerts. Furthermore, interface status reports on the trunk link display a high count of late collisions and frame check sequence (FCS) errors on one side, alongside significant packet drops. Which TWO of the following root causes are responsible for these symptoms? (Select TWO.)

Geçerli olan tümünü seçin

Cevabı ve açıklamayı göster

Cevap: A native VLAN configuration discrepancy exists between the trunk interfaces on the two switches.; A duplex mismatch is present across the interconnected trunk switchports.

Cevap

The issues are caused by a native VLAN mismatch across the trunk link and a duplex mismatch on the trunk switchports.
The CDP syslog alert specifically diagnoses an 802.1Q native VLAN mismatch between the trunk peers. Simultaneously, late collisions accompanied by FCS frame errors are the classic diagnostic signatures of a duplex mismatch between connected interfaces.

Adım Adım Çözüm

1
Analyze syslog messages indicating %CDP-4-NATIVE_VLAN_MISMATCH.
Identifies that the 802.1Q native VLAN ID configured on the local switchport does not match the native VLAN ID configured on the remote switchport.
802.1Q trunks send untagged traffic on the native VLAN; mismatched IDs lead to untagged traffic leaking between different VLANs and logging alerts.
2
Analyze interface statistics showing late collisions and FCS errors.
Confirms a duplex mismatch where one end of the point-to-point link operates in full-duplex while the opposing end operates in half-duplex.
The full-duplex side transmits regardless of carrier sense, causing the half-duplex side to detect collision late during frame transmission.

Anahtar Kavram

Identifying symptoms of native VLAN mismatches and duplex mismatches on trunk links
ÖncekiSayfa 24 / 25Sonraki