Comptia

N10-009 Free Practice Questions

This is the free Comptia N10-009 practice question bank — 260 of 518 total questions, each with a full explanation, free to read with no signup required. Updated 2026-04-24.

Every answer is verified against official Comptia documentation — see our methodology.

Question 1

Internet applications are timing out for users in the finance department. The company has a 10GB internet connection. Other department users are not experiencing any issues, and the performance from the core switch is good. Which of the following would best provide more bandwidth to the finance department users?

A. Link aggregation
B. Load balancer
C. Jumbo frames
D. Quality of service
Show Answer
Correct Answer: A
Explanation:
Only the finance department is affected, while the core switch and internet connection perform well, indicating a local uplink bottleneck for that department. Link aggregation increases the available bandwidth of the uplink by combining multiple physical links. QoS only prioritizes traffic and does not add bandwidth, jumbo frames provide minimal efficiency gains, and a load balancer does not address this issue.

Question 1

Which of the following ports is commonly used for DHCPDISCOVER call requests for a new machine on a network?

A. 53
B. 68
C. 69
D. 80
Show Answer
Correct Answer: B
Explanation:
DHCP uses UDP ports 67 and 68. A new client sends DHCPDISCOVER messages from UDP port 68 (client port) to the server on port 67, typically as a broadcast. Therefore port 68 is the correct choice.

Question 2

A user calls the help desk stating that an application successfully connects to a server, but the sync process fails when trying to sync data. Which of the following should the help desk use to resolve the issue? (Choose two.)

A. netstat
B. arp
C. Speed tester
D. nslookup
E. Nmap
F. ping
Show Answer
Correct Answer: C, F
Explanation:
Because the application can already establish a connection, basic DNS resolution and port availability are likely functioning. A failed sync often points to performance or packet-loss issues rather than outright connectivity. Using ping helps verify latency and packet loss to the server, while a speed tester checks available bandwidth and throughput, both of which directly impact data synchronization.

Question 2

Which of the following is an attack that provides a malicious default gateway IP over a wired network?

A. Evil twin
B. DNS spoofing
C. ARP poisoning
D. Rogue DHCP server
Show Answer
Correct Answer: D
Explanation:
A rogue DHCP server can hand out network configuration to wired clients, including a malicious default gateway IP address via DHCP options. ARP poisoning does not provide a gateway IP; it forges IP-to-MAC mappings to intercept traffic. Therefore, the attack that supplies a malicious default gateway IP is a rogue DHCP server.

Question 3

Which of the following would a network administrator most likely use to securely manage a network device on a closed network?

A. Bastion host
B. Remote desktop
C. SSH
D. Split-tunnel VPN
Show Answer
Correct Answer: C
Explanation:
SSH provides encrypted, authenticated command-line access and is the standard method for securely managing network devices (routers, switches, firewalls), especially on closed or internal networks. A bastion host is for controlled access from untrusted networks, remote desktop is less appropriate for network device management, and a split-tunnel VPN is unrelated to direct device management.

Question 3

A customer wants to segment the local network into eight sections with 30 devices each. A junior network technician needs to select the appropriate subnet mask for the customer's chosen Class С network. Which of the following meets the requirement?

A. /25
B. /26
C. /27
D. /28
Show Answer
Correct Answer: C
Explanation:
A Class C network has 8 host bits. To create 8 subnets, 3 bits must be borrowed (2^3 = 8), leaving 5 host bits. Five host bits provide 2^5 − 2 = 30 usable host addresses per subnet. Borrowing 3 bits gives a /27 mask, which meets both the subnet and host requirements.

Question 4

A company experienced a breach and wants to implement preventive measures. The network administrator is looking for a tool that can collect, analyze, and quickly correlate known attacks. Which of the following software tools can accomplish this task?

A. Syslog collector
B. SIEM
C. Packet capture
D. SNMP traps
Show Answer
Correct Answer: B
Explanation:
A SIEM (Security Information and Event Management) system is specifically designed to collect logs and events from multiple sources, analyze them, and correlate known attack patterns in near real time. Syslog collectors only gather logs without advanced correlation, packet capture focuses on raw traffic inspection, and SNMP traps are limited to device status alerts rather than security event correlation.

Question 4

A wireless administrator is setting up a small mesh network in an open-concept office space. The administrator must select a supported frequency that offers the fastest speeds for the backhaul connection. Which of the following should the administrator select?

A. 2.4GHz
B. 5GHz
C. 6GHz
D. 45GHz
Show Answer
Correct Answer: C
Explanation:
For a wireless mesh backhaul, the fastest practical Wi‑Fi speeds are achieved on higher frequencies with wider channels and less interference. 6 GHz (used by Wi‑Fi 6E and Wi‑Fi 7) supports the widest channels and highest throughput among the listed Wi‑Fi bands. 2.4 GHz and 5 GHz are slower, and 45 GHz is not a standard Wi‑Fi frequency for enterprise mesh networks. Therefore, 6 GHz is the best choice.

Question 5

A company is implementing a solution for users to gain access to a critical application. The solution will verity that the machine meets requirements and that the users have access to the application. Which of the following does this solution describe?

A. Policy-based authentication
B. Username and password
C. Application awareness
D. Single sign-on
Show Answer
Correct Answer: A
Explanation:
The solution described evaluates both the device posture (whether the machine meets security or compliance requirements) and the user's authorization to access the application. This aligns with policy-based authentication, which uses defined policies to make access decisions based on multiple conditions such as device state, user identity, and access rights. The other options do not incorporate both device verification and access control logic.

Question 6

A company's servers experience a malware attack, which causes a network outage. The source of the attack is traced back to an employee s infected laptop. Which of the following solutions should a network technician implement to mitigate this attack?

A. IPS
B. NAC
C. MFA
D. SSL
Show Answer
Correct Answer: B
Explanation:
The attack originated from an employee’s infected laptop connecting to the network. Network Access Control (NAC) is designed to prevent or limit network access by non-compliant or infected endpoints by enforcing security posture checks before and during connectivity. IPS detects/prevents malicious traffic but does not control device access, MFA is for authentication, and SSL provides encryption, none of which directly mitigate infected endpoint access.

$19

Get all 518 questions with detailed answers and explanations

  • Instant download HTML + PDF delivered the moment payment clears.
  • Secure Stripe checkout we never see or store your card details.
  • 7-day refund if files are defective see our refund policy.