A network architect is designing a new network for a rural hospital system. Given the following requirements:
Highly available
Consistent data transmission
Resilient to simultaneous failures
Which of the following topologies should the architect use?
A. Collapsed core
B. Hub-and-spoke
C. Mesh
D. Star
Show Answer
Correct Answer: C
Explanation: A mesh topology provides multiple paths between network nodes. If links or devices fail—even simultaneously—traffic can be rerouted over alternate paths, supporting high availability and resilient, consistent data transmission.
Question 12
A global company has depots in various locations. A proprietary application was deployed locally at each of the depots, but issues with getting the consolidated data instantly occurred. The Chief Information Officer decided to centralize the application and deploy it in the cloud. After the cloud deployment, users report the application is slow. Which of the following is most likely the issue?
A. Throttling
B. Overutilization
C. Packet loss
D. Latency
Show Answer
Correct Answer: D
Explanation: Centralizing the application in the cloud means depot users must communicate with a remote application rather than a local one. The increased network round-trip time is latency, which can make the application feel slow.
Question 13
A network load balancer is not correctly validating a client TLS certificate. The network architect needs to validate the certificate installed on the load balancer before progressing. Which of the following commands should the architect use to confirm whether the private key and certificate match?
Explanation: Use `openssl x509 -noout -modulus -in cert.crt | openssl md5` to hash the certificate’s public-key modulus, and `openssl rsa -noout -modulus -in privkey.txt | openssl md5` to hash the private key’s modulus. Matching hashes confirm that the certificate and private key correspond.
Question 14
An administrator needs to add a device to the allow list in order to bypass user authentication of an AAA system. The administrator uses MAC filtering and needs to discover the device's MAC address to accomplish this task. The device receives an IP address from DHCP, but the IP address changes daily. Which of the following commands should the administrator run on the device to locate its MAC address?
A. ipconfig /all
B. netstat -an
C. arp -a
D. nslookup
Show Answer
Correct Answer: A
Explanation: `ipconfig /all` displays detailed network adapter information on Windows, including the adapter’s physical (MAC) address. The changing DHCP-assigned IP address does not affect the MAC address.
Question 15
A company hosts its application s on the cloud and is expanding its business to Europe. The company must comply with General Data Protection Regulation to limit European customers' access to data. The network team configures the firewall rules but finds that some customers in the United States can access data hosted in Europe. Which of the following is the best option for the network team to configure?
A. SASE
B. Network security groups
C. CDN
D. Geofencing rule
Show Answer
Correct Answer: D
Explanation: A geofencing rule restricts access based on the requester’s geographic location, allowing the network team to block access from the United States while permitting access from approved regions.
Question 16
An organization wants to evaluate network behavior with a network monitoring tool that is not inline. The organization will use the logs for further correlation and analysis of potential threats. Which of the following is the best solution?
A. Syslog to a common dashboard used in the NOC
B. SNMP trap with log analytics
C. SSL decryption of network packets with preconfigured alerts
D. NetFlow to feed into the SIEM
Show Answer
Correct Answer: D
Explanation: NetFlow passively records network traffic-flow metadata without being inline, and forwarding it to the SIEM supports correlation and analysis of potential threats. Syslog and SNMP traps provide less direct detail about traffic behavior, while SSL decryption is not the best fit for this requirement.
Question 17
A company just launched a cloud-based application. Some users are reporting the application will not load. A cloud engineer investigates the issues and reports the following:
Not all users are experiencing the issue.
The application infrastructure is optimal.
Users experiencing the issue belong to the company's remote sales team.
Which of the following is most likely misconfigured?
A. Application load balancers
B. Ports and protocols
C. IP addressing
D. Geolocation rules
Show Answer
Correct Answer: D
Explanation: Geolocation rules can restrict access based on users’ locations. Since the application infrastructure is healthy and the issue affects a specific group of remote users, a location-based access rule is the most likely misconfiguration.
Question 18
A cloud architect must recommend an architecture approach for a new medical application that requires the lowest downtime possible. Which of the following is the best application deployment strategy given the high-availability requirement?
A. Two different availability zones (per region) using an active-active topology in two different regions
B. Four different availability zones using an active-passive topology in a single region
C. Four different availability zones using an active-active topology in a single region
D. Two different availability zones (per region) using an active-passive topology in two different regions
Show Answer
Correct Answer: A
Explanation: An active-active deployment across two regions, with each region spanning two availability zones, provides redundancy against both AZ-level and regional failures. Because both regions are already serving traffic, a regional outage can be handled by routing traffic to the surviving region without waiting for a standby environment to activate.
Question 19
A network architect is working on a new network design to better support remote and on-campus workers. Traffic needs to be decrypted for inspection in the cloud but is not required to go through the company's data center. Which of the following technologies best meets these requirements?
A. Secure web gateway
B. Transit gateway
C. Virtual private network
D. Intrusion prevention system
E. Network access control system
Show Answer
Correct Answer: A
Explanation: A cloud-based secure web gateway can decrypt and inspect web traffic for both remote and on-campus users without routing it through the company’s data center.
Question 20
An organization's Chief Technical Officer is concerned that changes to the network using IaC are causing unscheduled outages. Which of the following best mitigates this risk?
A. Making code changes to the master branch
B. Enforcing code review of the change by the author
C. Forking the code repository before making changes
D. Adding review/approval steps to the CI/CD pipelines
Show Answer
Correct Answer: D
Explanation: Adding review and approval gates to the CI/CD pipeline ensures IaC changes are checked before deployment, helping catch risky changes that could cause outages.
$19
Get all 81 questions with detailed answers and explanations
Instant download HTML + PDF delivered the moment payment clears.
Secure Stripe checkout we never see or store your card details.
7-day refund if files are defective see our refund policy.