A network administrator determines that some switch ports have more errors present than expected. The administrator traces the cabling associated with these ports. Which of the following would most likely be causing the errors?
A. Shielded conduit
B. Plenum spaces
C. Voltage transformers
D. Hydraulic lifts
Show Answer
Correct Answer: C
Explanation: Voltage transformers are a common source of electromagnetic interference (EMI). If network cabling, particularly unshielded twisted pair (UTP), is routed near transformers, induced noise can increase frame errors and other transmission problems. The other options are not typical causes of network port errors: shielded conduit helps reduce EMI, plenum spaces are a fire-safety installation consideration, and hydraulic lifts are not a common EMI source.
Question 152
Which of the following describes a malicious application that takes advantage of a software flaw?
A. Risk
B. Vulnerability
C. Exploit
D. Threat
Show Answer
Correct Answer: C
Explanation: An exploit is code, software, or a technique that takes advantage of a vulnerability (software flaw) to cause unintended behavior or gain unauthorized access. A vulnerability is the flaw itself, a threat is a potential cause of harm, and risk is the likelihood and impact of exploitation.
Question 153
After installing a new wireless access point, an engineer tests the device and sees that it is not performing at the rated speeds. Which of the following should the engineer do to troubleshoot the issue? (Choose two.)
A. Ensure a bottleneck is not coming from other devices on the network.
B. Install the latest firmware for the device.
C. Create a new VLAN for the access point.
D. Make sure the SSID is not longer than 16 characters.
E. Configure the AP in autonomous mode.
F. Install a wireless LAN controller.
Show Answer
Correct Answer: A, B
Explanation: Troubleshooting poor wireless performance should first verify that the AP is not being limited by external network bottlenecks and that it is running current firmware, which can address performance bugs and compatibility issues. Creating a VLAN, changing SSID length, autonomous mode, or installing a wireless LAN controller are not standard steps to resolve an individual AP failing to reach its rated speeds.
Question 154
A network administrator needs to monitor data from recently installed firewalls in multiple locations. Which of the following solutions would best meet the administrator's needs?
A. IDS
B. IPS
C. SIEM
D. SNMPv2
Show Answer
Correct Answer: C
Explanation: A SIEM (Security Information and Event Management) solution is designed to collect, centralize, correlate, and monitor logs and security events from multiple devices, including firewalls deployed across different locations. IDS and IPS are detection/prevention technologies rather than centralized monitoring platforms, and SNMPv2 is a network management protocol that can monitor device status but does not provide the centralized security event collection and correlation implied by the requirement.
Question 155
After a recent security awareness phishing campaign, the cybersecurity team discovers that additional security measures need to be set up when users access potentially malicious websites. Which of the following security measures will best address this concern?
A. Implement DNS filtering.
B. Update ACLs to only allow HTTPS.
C. Configure new IPS hardware.
D. Deploy 802.1X security features.
Show Answer
Correct Answer: A
Explanation: DNS filtering is the most direct control for preventing users from reaching known malicious or phishing domains by blocking DNS resolution before a connection is established. Allowing only HTTPS does not prevent access to malicious sites because attackers commonly use HTTPS. An IPS can detect and block some malicious traffic but is less targeted for preventing access to phishing domains. 802.1X provides network access control, not web filtering.
Question 156
A detective is investigating an identity theft case in which the target had an RFID-protected payment card issued and compromised in the same day. The only place the target claims to have used the card was at a local convenience store. The detective notices a video camera at the store is placed in such a way that customers’ credentials can be seen when they pay. Which of the following best explains this social engineering technique?
A. Shoulder surfing
B. Impersonation
C. Vishing
D. Tailgating
Show Answer
Correct Answer: A
Explanation: Shoulder surfing is the act of observing someone’s sensitive information, such as payment card details or PIN entry, during use. A strategically placed camera capturing customers’ payment credentials is an example of shoulder surfing. Impersonation involves pretending to be someone else, vishing uses voice calls, and tailgating is following an authorized person into a restricted area.
Question 157
An organization recently connected a new computer to the LAN. The user is unable to ping the default gateway. The technician examines the configuration and sees a self-assigned IP address. Which of the following is the most likely cause?
A. The DHCP server is not available.
B. An RFC1918 address is being used.
C. The TCP/IP stack is disabled.
D. A static IP is assigned.
Show Answer
Correct Answer: A
Explanation: A self-assigned IP address indicates APIPA (169.254.0.0/16), which is assigned when a host configured for DHCP cannot contact a DHCP server. Without a valid DHCP lease, the host will not receive the correct IP configuration, including the default gateway, so it cannot ping the gateway. RFC1918 private addresses are normal on LANs, disabling the TCP/IP stack would not result in APIPA, and a static IP would not be described as self-assigned.
Question 158
Which of the following steps of the troubleshooting methodology is most likely to involve talking to a user who opens a ticket?
A. Verifying full system functionality
B. Establishing a theory of probable cause
C. Identifying the problem
D. Implementing the solution
Show Answer
Correct Answer: C
Explanation: In the CompTIA troubleshooting methodology, the technician talks to the user during the 'Identify the problem' step to gather information, question the user, identify symptoms, determine what changed, and establish the scope of the issue. Establishing a theory, implementing a solution, and verifying functionality occur after the problem has been identified.
Question 159
A server administrator needs to add a record to the company’s DNS server to verify ownership of a web domain. The administrator has the record's name and value. Which of the following record types should the administrator use to add the record to the DNS server?
A. TXT
B. A
C. PTR
D. CNAME
Show Answer
Correct Answer: A
Explanation: A TXT record is the standard DNS record type used to store arbitrary text and is commonly required for domain ownership verification by web services, certificate authorities, and cloud providers. An A record maps a hostname to an IPv4 address, a PTR record is for reverse DNS lookups, and a CNAME record creates an alias to another hostname.
Question 160
Which of the following should a junior security administrator recommend implementing to mitigate malicious network activity?
A. IPS
B. Honeypot
C. SIEM
D. VPN
Show Answer
Correct Answer: A
Explanation: An Intrusion Prevention System (IPS) is designed to detect and actively block malicious network traffic in real time, directly mitigating malicious network activity. A honeypot is primarily for deception and detection, a SIEM aggregates and analyzes logs for monitoring and response, and a VPN provides secure remote connectivity rather than preventing malicious traffic.
$19
Get all 580 questions with detailed answers and explanations
Instant download HTML + PDF delivered the moment payment clears.
Secure Stripe checkout we never see or store your card details.
7-day refund if files are defective see our refund policy.