An employee connects to the company network from home using a VPN. Company data uses the VPN, while internet traffic uses the home ISP connection. Which of the following best describes the connectivity method in use?
A. IPSec
B. Split-tunnel
C. Clientless
D. Out-of-band
Show Answer
Correct Answer: B
Explanation: A split-tunnel VPN routes traffic destined for the corporate network through the VPN while sending general internet traffic directly through the user's local ISP connection. IPSec is a VPN protocol, clientless VPNs use a web browser without a VPN client, and out-of-band refers to separate management or communication paths, not this traffic-routing behavior.
Question 92
A network engineer is implementing a new connection between core switches. The engineer deploys the following configurations to the switches:
Which of the following is the state of the core-sw01 port-channel interfaces?
A. Incrementing CRC errors
B. Error disabled
C. Administratively down
D. Suspended
Show Answer
Correct Answer: D
Explanation: With LACP configured in active mode on one side but no channel-group/LACP on the peer, the links do not bundle. On Cisco platforms, such member interfaces are typically placed in the suspended state rather than forming the EtherChannel. Error-disabled is used for specific protection or consistency violations, not ordinary LACP negotiation failure.
Sources:
https://community.cisco.com/t5/switching/lacp-etherchannel-between-4500x-and-6807-catalyst-switches/m-p/4525505
Question 93
Which of the following Layer 1 devices is responsible for the termination of fiber-optic connections on an SFP-capable switch?
A. Transceiver
B. Modem
C. Ethernet NIC
D. Repeater
Show Answer
Correct Answer: A
Explanation: An SFP-capable switch uses an SFP transceiver module to terminate the fiber-optic connection at the physical layer. The transceiver converts optical signals to electrical signals and vice versa. A modem is for modulating/demodulating signals over carrier media, an Ethernet NIC is an endpoint network interface, and a repeater regenerates signals but is not the SFP termination device.
Question 94
A network technician needs to use a private Class A RFC1918 addressing scheme for user laptops on the company's network. Which of the following subnets should the technician choose?
A. 10.1.1.0/24
B. 100.1.1.0/24
C. 172.16.1.0/24
D. 192.168.1.0/24
Show Answer
Correct Answer: A
Explanation: RFC 1918 private address space includes 10.0.0.0/8 (historically Class A), 172.16.0.0/12 (Class B), and 192.168.0.0/16 (Class C). The question specifically asks for a private Class A RFC1918 subnet, and 10.1.1.0/24 falls within 10.0.0.0/8. 100.1.1.0/24 is not RFC1918 private, while 172.16.1.0/24 and 192.168.1.0/24 are private but not Class A.
Question 95
A small business is choosing between static and dynamic routing for its network. Which of the following is the best reason to use dynamic routing in a growing network?
A. Easier to configure compared to using manually entered routes
B. Does not require additional network security controls
C. Features enhanced network monitoring and visibility
D. Includes automatic changes and updates in network topology
Show Answer
Correct Answer: D
Explanation: Dynamic routing protocols automatically learn and update routes as the network topology changes, making them well suited for growing networks. Static routing requires manual updates whenever the network changes. Dynamic routing is generally more complex to configure than static routing, does not eliminate the need for security controls, and its primary advantage is automatic route adaptation rather than enhanced monitoring.
Question 96
A user runs ifconfig on a PC and sees the following address information:
The user then plugs a new device into the network and statically assigns it the address 192.168.1.255. The device does not work on the network. Which of the following explains the issue?
A. The IP address is static.
B. The IP address is a broadcast address.
C. The IP address is outside the scope of the DHCP range.
D. The IP address has a wrong subnet mask.
Show Answer
Correct Answer: B
Explanation: In a typical 192.168.1.0/24 network, 192.168.1.255 is the subnet's directed broadcast address and cannot be assigned to a host. Devices using that address will not communicate normally because it is reserved for broadcasts.
Question 97
A user cannot access an external server for a client after connecting to a VPN. Which of the following commands would a support agent most likely use to examine the issue? (Choose two.)
A. nslookup
B. tcpdump
C. arp
D. dig
E. tracert
F. route print
Show Answer
Correct Answer: E, F
Explanation: A VPN connectivity issue preventing access to an external server is commonly investigated by checking the network path with tracert and inspecting the routing table with route print. These directly identify whether traffic is being incorrectly routed through the VPN or another gateway. DNS tools like nslookup or dig are useful only if name resolution is specifically suspected, but the question asks which commands would most likely be used to examine the overall issue.
Question 98
A network architect is implementing a VPN solution for remote workers. The architect wants to ensure that data transmitted through the VPN is protected from eavesdropping and tampering. Which of the following solutions meet these requirements? (Choose two.)
A. SSL
B. AES
C. TKIP
D. IPSec
E. EAP
F. SSH
Show Answer
Correct Answer: B, D
Explanation: IPSec is the VPN technology that provides authentication, integrity, and encryption for IP traffic, protecting against eavesdropping and tampering. AES is the strong symmetric encryption algorithm commonly used within VPNs (including IPSec) to provide confidentiality. SSL is a protocol used by SSL/TLS VPNs, but the question asks for two solutions meeting the security requirements, and IPSec plus AES directly address secure VPN tunneling and encryption. TKIP is legacy Wi-Fi encryption, EAP is an authentication framework, and SSH secures remote shell sessions rather than serving as a general VPN solution.
Question 99
A network administrator wants to update a geofencing policy to limit remote access to the corporate network based on country location. Which of the following would the administrator most likely leverage?
A. MAC filtering
B. Administrative distance
C. Bluetooth beacon signals
D. IP address blocks
Show Answer
Correct Answer: D
Explanation: Geofencing by country is typically implemented using IP geolocation databases that map public IP address ranges to countries. The administrator would leverage IP address blocks to allow or deny remote access based on the source country's IP ranges. MAC filtering only works on local networks, administrative distance is a routing preference metric, and Bluetooth beacons are for proximity-based location, not country-based remote access.
Question 100
A company is migrating a data center from on premises to the cloud. Which of the following tools will help maintain consistency, reliability, and efficiency of provisioning and management?
A. IaC
B. CDN
C. SASE
D. ZTA
Show Answer
Correct Answer: A
Explanation: Infrastructure as Code (IaC) automates the provisioning and management of infrastructure using declarative or scripted configurations. This improves consistency, reliability, repeatability, and efficiency during cloud migrations. A CDN accelerates content delivery, SASE is a networking/security architecture, and ZTA is a security model, none of which are primarily used for infrastructure provisioning and management.
$19
Get all 580 questions with detailed answers and explanations
Instant download HTML + PDF delivered the moment payment clears.
Secure Stripe checkout we never see or store your card details.
7-day refund if files are defective see our refund policy.