Comptia

N10-009 Free Practice Questions — Page 18

Question 168

An organization has four departments that each need access to different resources that do not overlap. Which of the following should a technician configure in order to implement and assign an ACL?

A. VLAN
B. DHCP
C. VPN
D. STP
Show Answer
Correct Answer: A
Explanation:
To implement and assign Access Control Lists (ACLs) for four departments with non-overlapping resource access, the network must first be logically segmented. Configuring VLANs allows each department to be placed in its own broadcast domain and subnet. ACLs can then be applied to control traffic between VLANs, ensuring departments only access their authorized resources. DHCP, VPN, and STP do not provide the necessary logical separation required for effective ACL assignment in this scenario.

Question 169

A network analyst is installing a wireless network in a corporate environment. Employees are required to use their domain identities and credentials to authenticate and connect to the WLAN. Which of the following actions should the analyst perform on the AP to fulfill the requirements?

A. Enable MAC security.
B. Generate a PSK for each user.
C. Implement WPS.
D. Set up WPA3 protocol.
Show Answer
Correct Answer: D
Explanation:
Employees must authenticate to the WLAN using domain identities and credentials, which requires 802.1X authentication with a backend RADIUS/Active Directory integration. WPA3-Enterprise supports 802.1X and per-user authentication. MAC filtering, per-user PSKs, and WPS do not provide domain-based authentication.

Question 170

A network administrator thinks a change was made to mail servers at comptia.org. Which of the following should the administrator execute to verify the change?

A. ping www.comptia.org
B. dig comptia.org ANY
C. nslookup -type=ns coir.ptia.org
D. tracert comptia.org
Show Answer
Correct Answer: B
Explanation:
To verify changes to mail servers, the administrator must check DNS Mail Exchanger (MX) records. The dig command queries DNS directly, and using an ANY query returns all available DNS records for the domain, including MX records. This allows verification of any mail server changes. The other options do not provide MX record information.

Question 171

Users at an organization report that the wireless network is not working in some areas of the building. Users report that other wireless network SSIDs are visible when searching for the network, but the organization’s network is not displayed. Which of the following is the most likely cause?

A. Interference or channel overlap
B. Insufficient wireless coverage
C. Roaming misconfiguration
D. Client disassociation issues
Show Answer
Correct Answer: B
Explanation:
If users can see other nearby SSIDs but not the organization’s SSID in certain areas, the most likely cause is insufficient wireless coverage. This indicates the access points’ signal does not reach those areas due to distance, poor placement, low transmit power, or physical obstructions. Interference or channel overlap typically degrades performance rather than completely hiding an SSID, while roaming misconfiguration and client disassociation affect connectivity after association, not SSID visibility.

Question 172

While conducting a network audit, an administrator notices the spanning tree root in VLAN 300 does not match the configuration baseline, which could cause network outages due to spanning tree update failures. Which of the following should the administrator do to restore consistency?

A. Change the designated port on the misconfigured switch to a root port.
B. Change the root port to a listening port on the misconfigured switch.
C. Change the blocked port of the misconfigured switch to a learning port.
D. Increase the bridge ID/priority on the misconfigured switch.
Show Answer
Correct Answer: D
Explanation:
In STP, the root bridge is the switch with the lowest bridge ID (priority + MAC). If an unintended switch has become the root for VLAN 300, restoring the baseline requires preventing that switch from winning the election. Increasing its bridge priority raises its bridge ID so it will no longer be selected as root, allowing the intended switch to regain root status. The other options incorrectly change port roles or states, which do not correct root bridge selection.

Question 173

Which of the following architecture types is most commonly associated with east-west traffic?

A. Colocated VMs
B. Hybrid cloud
C. Client-server
D. Hub and spoke
Show Answer
Correct Answer: A
Explanation:
East-west traffic describes lateral communication between workloads within the same data center or network, such as VM-to-VM or service-to-service traffic. This pattern is most commonly seen with colocated VMs, where applications communicate internally, unlike client-server or hub-and-spoke models that emphasize north-south traffic.

Question 174

A network technician is attempting to map networking devices. When logged in to the local switch, the technician uses LLDP and discovers only those devices that are connected directly to the switch. Which of the following should the technician perform to discover all the networking devices?

A. Reconfigure the management IP addresses of the networking devices on the same subnet.
B. Enable Spanning Tree Protocol to allow the switches on the network to be discovered.
C. Log in to each of the connected networking devices and perform the process again.
D. Upgrade the OS on the networking devices to the current version of LLDP.
Show Answer
Correct Answer: C
Explanation:
LLDP only advertises and discovers directly connected neighbors. It does not provide visibility beyond one hop. To discover all networking devices, the technician must log in to each discovered device and run LLDP again to map its neighbors, gradually building the full network topology.

Question 175

A technician needs to identify a computer on the network that is reportedly downloading unauthorized content. Which of the following should the technician use?

A. Anomaly alerts
B. Port mirroring
C. Performance monitoring
D. Packet capture
Show Answer
Correct Answer: D
Explanation:
To identify a specific computer downloading unauthorized content, the technician needs visibility into actual network traffic, including source IP/MAC addresses and the data being transferred. Packet capture provides this granular inspection and allows correlation of traffic to a specific host. Anomaly alerts and performance monitoring are indirect, and port mirroring only duplicates traffic—it still requires packet capture to analyze and identify the offending computer.

Question 176

Which of the following technologies uses a VIP to provide gateway redundancy between two routers?

A. LACP
B. PAT
C. FHRP
D. BGP
Show Answer
Correct Answer: C
Explanation:
Gateway redundancy using a shared Virtual IP (VIP) between two or more routers is provided by First Hop Redundancy Protocols (FHRPs). Protocols such as HSRP, VRRP, and GLBP create a virtual default gateway IP that can move between routers if the active one fails, ensuring uninterrupted connectivity for hosts. The other options do not provide gateway redundancy via a VIP.

Question 177

A security engineer is trying to connect cameras to a 12-port PoE switch, but only eight cameras turn on. Which of the following should the engineer check first?

A. Ethernet cable type
B. Voltage
C. Transceiver compatibility
D. DHCP addressing
Show Answer
Correct Answer: B
Explanation:
If only eight of twelve PoE devices power on, the most likely cause is that the switch’s PoE power budget has been exceeded. PoE switches can power all ports electrically, but they are limited by a total wattage budget; once that budget is reached, additional devices will not receive power. While the option says "Voltage," in practice this refers to checking the switch’s PoE power delivery (available electrical power), not data-plane issues. Cable type, transceivers, and DHCP would not selectively prevent devices from powering on.

$19

Get all 518 questions with detailed answers and explanations

  • Instant download HTML + PDF delivered the moment payment clears.
  • Secure Stripe checkout we never see or store your card details.
  • 7-day refund if files are defective see our refund policy.