Comptia

N10-009 Free Practice Questions — Page 10

Question 87

A network administrator needs to monitor data from recently installed firewalls in multiple locations. Which of the following solutions would best meet the administrator's needs?

A. IDS
B. IPS
C. SIEM
D. SNMPv2
Show Answer
Correct Answer: C
Explanation:
The requirement is centralized monitoring of data from firewalls across multiple locations. A SIEM collects and aggregates logs/events from many distributed devices, including firewalls, and provides centralized monitoring, correlation, alerting, and reporting. IDS/IPS focus on detection/prevention, and SNMPv2 is limited to basic device metrics rather than comprehensive security log analysis.

Question 88

After a recent security awareness phishing campaign, the cybersecurity team discovers that additional security measures need to be set up when users access potentially malicious websites. Which of the following security measures will best address this concern?

A. Implement DNS filtering.
B. Update ACLs to only allow HTTPS.
C. Configure new IPS hardware.
D. Deploy 802.1X security features.
Show Answer
Correct Answer: A
Explanation:
The goal is to add protection when users attempt to access potentially malicious websites after a phishing campaign. DNS filtering blocks access to known malicious or suspicious domains at the DNS resolution stage, preventing users from connecting to phishing and malware sites in the first place. Allowing only HTTPS does not stop malicious sites, IPS is broader and less targeted for phishing-driven web access, and 802.1X addresses network access control rather than web threats.

Question 89

A detective is investigating an identity theft case in which the target had an RFID-protected payment card issued and compromised in the same day. The only place the target claims to have used the card was at a local convenience store. The detective notices a video camera at the store is placed in such a way that customers’ credentials can be seen when they pay. Which of the following best explains this social engineering technique?

A. Shoulder surfing
B. Impersonation
C. Vishing
D. Tailgating
Show Answer
Correct Answer: A
Explanation:
The attacker observes the victim’s payment credentials as they are entered at the point of sale. Whether done in person or via a camera positioned to view the keypad/card, this is shoulder surfing—capturing sensitive information by watching the victim. The other options involve pretending to be someone else (impersonation), phone-based scams (vishing), or following someone into a secure area (tailgating).

Question 90

An organization recently connected a new computer to the LAN. The user is unable to ping the default gateway. The technician examines the configuration and sees a self-assigned IP address. Which of the following is the most likely cause?

A. The DHCP server is not available.
B. An RFC1918 address is being used.
C. The TCP/IP stack is disabled.
D. A static IP is assigned.
Show Answer
Correct Answer: A
Explanation:
A self-assigned IP address indicates APIPA (169.254.x.x), which occurs when a host is configured for DHCP but cannot reach a DHCP server. Without a valid DHCP lease, it cannot communicate with the default gateway.

Question 91

Which of the following steps of the troubleshooting methodology is most likely to involve talking to a user who opens a ticket?

A. Verifying full system functionality
B. Establishing a theory of probable cause
C. Identifying the problem
D. Implementing the solution
Show Answer
Correct Answer: C
Explanation:
In standard troubleshooting methodologies (such as CompTIA’s), talking to the user who opened the ticket occurs during the first step, *Identify the problem*. This step involves gathering information by asking the user questions, clarifying symptoms, and understanding the context of the issue. The other steps focus on analysis, implementation, or verification rather than initial user interaction.

Question 92

A server administrator needs to add a record to the company’s DNS server to verify ownership of a web domain. The administrator has the record's name and value. Which of the following record types should the administrator use to add the record to the DNS server?

A. TXT
B. A
C. PTR
D. CNAME
Show Answer
Correct Answer: A
Explanation:
Domain ownership verification requires adding a DNS record that can store an arbitrary verification string provided by the service. TXT records are specifically designed for this purpose and are commonly used for domain verification, SPF/DKIM/DMARC, and similar checks. A records map hostnames to IPs, PTR records are for reverse lookups, and CNAME records create aliases, none of which are suitable for ownership verification.

Question 93

Which of the following should a junior security administrator recommend implementing to mitigate malicious network activity?

A. IPS
B. Honeypot
C. SIEM
D. VPN
Show Answer
Correct Answer: A
Explanation:
An Intrusion Prevention System (IPS) actively monitors network traffic and can automatically detect, block, or drop malicious activity in real time, directly mitigating attacks. A honeypot is mainly for detection and research, a SIEM focuses on log aggregation and alerting, and a VPN provides secure remote access rather than stopping malicious traffic.

Question 94

A network administrator needs to securely connect to an Ubuntu server for management purposes. Which of the following protocols will most likely address this requirement?

A. HTTPS
B. SFTP
C. RDP
D. SSH
Show Answer
Correct Answer: D
Explanation:
SSH (Secure Shell) is the standard protocol for securely managing and administering Linux systems such as Ubuntu. It provides encrypted remote command-line access and is specifically designed for secure remote administration. HTTPS is for web traffic, SFTP is for secure file transfer only, and RDP is primarily used for remote graphical access to Windows systems.

Question 95

Users in a company report that after walking from one room to another, wireless connectivity is lost. The SSID is available, but the users have to manually reconnect every time they change rooms. Which of the following is most likely the cause of this issue?

A. Each room has wireless interference.
B. There is poor wireless coverage.
C. MAC filtering is applied in the WLAN.
D. Roaming configuration is disabled.
Show Answer
Correct Answer: D
Explanation:
The SSID remains visible but users must manually reconnect when moving between rooms, which indicates access points are not allowing seamless client handoff. In a properly configured WLAN, roaming enables clients to transition between APs without disconnecting. If roaming is disabled or misconfigured, clients drop the connection and require manual reconnection despite seeing the same SSID.

Question 96

A new backup system takes too long to copy files to the new SAN each night. A network administrator makes a simple change to the network and the devices to decrease backup times. Which of the following does the network administrator change?

A. QoS
B. SDN
C. MTU
D. VXLAN
E. TTL
Show Answer
Correct Answer: C
Explanation:
Increasing the MTU (enabling jumbo frames) reduces packet overhead by sending larger frames, which significantly improves throughput for large, sequential data transfers like nightly backups to a SAN. This is a simple network/device configuration change commonly used to speed up backup traffic.

$19

Get all 518 questions with detailed answers and explanations

  • Instant download HTML + PDF delivered the moment payment clears.
  • Secure Stripe checkout we never see or store your card details.
  • 7-day refund if files are defective see our refund policy.