Comptia

CNX-001 Free Practice Questions — Page 5

Question 41

A company's IT department is expected to grow from 100 to 200 employees, and the sales department is expected to grow from 1,000 to a maximum of 2,000 employees. Each employee owns a single laptop with a single IP allocated. The network architect wants to deploy network segmentation using the IP range 10.0.0.0/8. Which of the following is the best solution?

A. Allocate 10.1.0.0/30 to the IT department. Allocate 10.2.0.0/16 to the sales department.
B. Allocate 10.1.0.0/16 to the IT department. Allocate 10.2.1.0/24 to the sales department.
C. Allocate 10.1.0.0/22 to the IT department. Allocate 10.2.0.0/15 to the sales department.
D. Allocate 10.1.0.0/16 to the IT department. Allocate 10.2.1.0/25 to the sales department.
Show Answer
Correct Answer: C
Explanation:
A /22 provides 1,022 usable host addresses, enough for IT’s maximum of 200 employees. A /15 provides 131,070 usable host addresses, enough for sales’ maximum of 2,000. The other options assign a subnet too small for at least one department.

Question 42

A partner is migrating a client from on premises to a hybrid cloud. Given the following project status information, the initial project timeline estimates need to be revised: Which of the following documents needs to be revised to best reflect the current status of the project?

A. BIA
B. SLA
C. SOW
D. WBS
Show Answer
Correct Answer: D
Explanation:
The WBS breaks the project into tasks and work packages, so it should be updated to reflect revised estimates for the project work and timeline. A BIA, SLA, and SOW serve different purposes and are not the best fit here.

Question 43

Application development team users are having issues accessing the database server within the cloud environment. All other users are able to use SSH to access this server without issues. The network architect reviews the following information to troubleshoot the issue: IPAM information: Traceroute output from an application developer's machine with the assigned IP 192.168.2.7: Which of the following is the most likely cause of the issue?

A. The core firewall is blocking the traffic.
B. Network security groups do not have the correct outbound rule configured.
C. The server segment firewall is dropping the traffic.
D. The server segment gateway is having bandwidth issues.
Show Answer
Correct Answer: C
Explanation:
The traceroute reaches the server segment firewall (192.168.4.1) and then times out. Since other users can access the database server, the likely issue is that the server segment firewall is dropping traffic from the application developers’ subnet.

Question 44

A customer asks a MSP to propose a ZTA design for its globally distributed remote workforce. Given the following requirements: Authentication should be provided through the customer's SAML identity provider. Access should not be allowed from countries where the business does not operate. Secondary authentication should be added to the workflow to allow for passkeys. Changes to the user's device posture and hygiene should require reauthentication into the network. Access to the network should only be allowed to originate from corporate-owned devices. Which of the following solutions should the MSP recommend to meet the requirements?

A. Enforce certificate-based authentication. Permit unauthenticated remote connectivity only from corporate IP addresses. Enable geofencing. Use cookie-based session tokens that do not expire for remembering user log-ins. Increase RADIUS server timeouts.
B. Enforce posture assessment only during the initial network log-on. Implement RADIUS for SSO. Restrict access from all non-U.S. IP addresses. Configure a BYOD access policy. Disable auditing for remote access.
C. Chain the existing identity provider to a new SAML. Require the use of time-based one-time passcode hardware tokens. Enable debug logging on the VPN clients by default. Disconnect users from the network only if their IP address changes.
D. Configure geolocation settings to block certain IP addresses. Enforce MFA. Federate the solution via SSO. Enable continuous access policies on the WireGuard tunnel. Create a trusted endpoints policy.
Show Answer
Correct Answer: D
Explanation:
Federating through SSO supports the customer’s SAML identity provider, and geolocation controls can block access from non-operating countries. MFA provides the secondary authentication step for passkeys. Continuous access policies can respond to device-posture changes by requiring reauthentication, while a trusted-endpoints policy restricts access to corporate-owned devices.

Question 45

A network engineer adds a large group of servers to a screened subnet and configures them to use IPv6 only. The servers need to seamlessly communicate with IPv4 servers on the internal networks. Which of the following actions is the best way to achieve this goal?

A. Add IPv6 to the network cards on the internal servers so they can communicate with the screened subnet.
B. Set up a bridge between the screened subnet and internal networks to handle the conversion.
C. Change the servers in the screened subnet from IPv6 addresses to IPv4 addresses.
D. Implement NAT64 on the router between the screened subnet and the internal network.
Show Answer
Correct Answer: D
Explanation:
NAT64 translates traffic between IPv6-only servers and IPv4 servers, enabling them to communicate across the network boundary without changing the address configuration of either server group.

Question 46

A network architect needs to design a solution to ensure every cloud environment network is built to the same baseline. The solution must meet the following requirements: Use automated deployment. Easily update multiple environments. Share code with a community of practice. Which of the following are the best solutions? (Choose two.)

A. CI/CD pipelines
B. Public code repository
C. Deployment runbooks
D. Private code repository
E. Automated image deployment
F. Deployment guides
Show Answer
Correct Answer: A, B
Explanation:
CI/CD pipelines automate consistent deployments and make it easier to roll out updates across multiple environments. A public code repository supports sharing the deployment code with a community of practice.

Question 47

A company is replacing reserved public IP addresses with dynamic IP addresses. The network architect creates a list of assets with some dependencies to these reserved IPs: Which of the following issues may begin to affect cloud assets after the replacement is made?

A. IP asymmetric routing
B. IP spoofing
C. IP exhaustion
D. IP reuse
Show Answer
Correct Answer: D
Explanation:
Dynamic public IP addresses can be released and later assigned to other cloud resources or customers. Assets that still depend on the former addresses may therefore encounter IP reuse.

Question 48

A network engineer identified several failed log-in attempts to the VPN from a user's account. When the engineer inquired, the user mentioned the IT help desk called and asked them to change their password. Which of the following types of attacks occurred?

A. Initialization vector
B. On-path
C. Evil twin
D. Social engineering
Show Answer
Correct Answer: D
Explanation:
The attacker impersonated the IT help desk and manipulated the user into changing their password, which is a social engineering attack.

Question 49

An outage occurred after a software upgrade on core switching. A network administrator thinks that the firmware installed had a bug. Which of the following should the network administrator do next?

A. Establish a plan of action to resolve the issue.
B. Test the theory to determine cause.
C. Document lessons learned.
D. Implement the solution.
Show Answer
Correct Answer: B
Explanation:
After forming a theory that the firmware is causing the outage, the next troubleshooting step is to test that theory to determine the cause. Planning and implementing a fix come afterward.

Question 50

A company deployed new applications in the cloud and configured a site-to-site VPN to connect the internal data center with the cloud. The IT team wants the internal servers to connect to those applications without using public IP addresses. Which of the following is the best solution?

A. Create a DNS server in the cloud. Configure the DNS server in the customer data center to forward DNS requests for cloud resources to the cloud DNS server.
B. Configure a NAT server on the cloud to allow internal servers to connect to the applications through the NAT server.
C. Register applications on the cloud with a public DNS sever and configure internal servers to connect to them using their public DNS names.
D. Configure proxy service in the site-to-site VPN to allow internal servers to access applications through the proxy.
Show Answer
Correct Answer: A
Explanation:
A cloud DNS server can resolve the applications’ private DNS names to their private IP addresses. Forwarding the relevant DNS queries from the on-premises DNS server lets internal servers reach the applications over the site-to-site VPN without using public IP addresses.

$19

Get all 81 questions with detailed answers and explanations

  • Instant download HTML + PDF delivered the moment payment clears.
  • Secure Stripe checkout we never see or store your card details.
  • 7-day refund if files are defective see our refund policy.