Comptia

N10-009 Free Practice Questions — Page 19

Question 178

A network administrator is setting up a firewall to protect the organization's network from external threats. Which of the following should the administrator consider first when configuring the firewall?

A. Required ports, protocols, and services
B. Inclusion of a deny all rule
C. VPN access
D. Outbound access originating from customer-facing servers
Show Answer
Correct Answer: A
Explanation:
Firewall configuration should begin by identifying which traffic must be permitted for business operations. Determining the required ports, protocols, and services allows the administrator to create precise allow rules and then enforce a default-deny posture, aligning with the principle of least privilege.

Question 179

A network administrator is unable to ping a remote server from a newly connected workstation that has been added to the network, Ping to 127.0.0.1 on the workstation is failing. Which of the following should the administrator perform to diagnose the problem?

A. Verify the NIC interface status.
B. Verify the network is not congested.
C. Verify the router is not dropping packets.
D. Verify that DNS is resolving correctly.
Show Answer
Correct Answer: A
Explanation:
Failure to ping 127.0.0.1 indicates a problem with the local TCP/IP stack or network interface on the workstation, not the external network. The first diagnostic step is to verify that the NIC is present, enabled, and functioning correctly.

Question 180

Which of the following routing protocols is most commonly used to interconnect WANs?

A. IGP
B. EIGRP
C. BGP
D. OSPF
Show Answer
Correct Answer: C
Explanation:
Border Gateway Protocol (BGP) is the standard routing protocol used to interconnect wide area networks, particularly between different autonomous systems such as ISPs and large organizations. It is designed for inter-domain routing across the Internet, unlike IGPs such as OSPF or EIGRP, which are intended for internal network routing.

Question 181

A server administrator deploys a new web server with an IP address of 192.168.16.100. The security policy dictates that all non-secure connection methods should be blocked. Which of the following security rules will satisfy the request without prohibiting other traffic?

A. Deny any 192.168.16.0 255.255.255.0 80
B. Deny 192.168.16.100 255.255.255.255 any
C. Deny any 192.168.16.100 255.255.255.255 80
D. Permit any 192.168.16.100 255.255.255.255 80
E. Permit 192.168.16.100 255.255.255.255 any
Show Answer
Correct Answer: C
Explanation:
The requirement is to block non-secure connection methods to the specific web server without affecting other traffic. HTTP uses TCP port 80 and is non-secure, while HTTPS (443) should remain allowed. Option C denies traffic to 192.168.16.100 on port 80 only, leaving other ports and hosts unaffected. Other options either block too much traffic or permit the insecure service.

Question 182

Which of the following protocol ports should be used to securely transfer a file?

A. 22
B. 69
C. 80
D. 3389
Show Answer
Correct Answer: A
Explanation:
Port 22 is used by SSH, which supports secure file transfer via SFTP and SCP with encryption of credentials and data. Port 69 (TFTP) has no security, port 80 (HTTP) is not encrypted by default, and port 3389 (RDP) is for remote desktop access rather than file transfer.

Question 183

A network technician is installing a new switch that does not support STP at the access layer of a network. The technician wants a redundant connection to the distribution switch. Which of the following should the technician use?

A. Link aggregation
B. Subinterfaces
C. Switch virtual interfaces
D. Half-duplex connections
Show Answer
Correct Answer: A
Explanation:
Link aggregation (EtherChannel/LACP) bundles multiple physical links into a single logical interface, providing redundancy and increased bandwidth while preventing Layer 2 loops. This avoids the need for STP support on the access switch. The other options do not provide loop-free redundancy between switches.

Question 184

A company is expanding to another floor in the same building. The network engineer configures a new switch with the same VLANs as the existing stack. When the network engineer connects the new switch to the existing stack, all users lose connectivity. Which of the following is the most likely reason?

A. The new switch has unused ports disabled.
B. The new switch does not have a default gateway.
C. The new switch is connected to an access port.
D. The new switch is in a spanning tree loop.
Show Answer
Correct Answer: D
Explanation:
When the new switch is connected, all users immediately lose connectivity, which is a classic symptom of a switching loop. A loop causes broadcast storms that overwhelm the switching fabric and disrupt the entire network. Spanning Tree Protocol is designed to prevent this, but if the new switch is misconfigured or creates an unintended loop, the whole network can go down. The other options would only affect specific ports or the new switch itself, not all users.

Question 185

A network administrator changed an external DNS to point customers to a new server. Which of the following tools should the administrator use to test the new server’s configuration?

A. ping
B. tracert
C. tcpdump
D. nslookup
Show Answer
Correct Answer: D
Explanation:
After changing an external DNS record, the administrator needs to verify that the hostname now resolves to the new server’s IP address. Nslookup directly queries DNS servers and shows the resolved IP, making it the correct tool. Ping and tracert test connectivity/path, and tcpdump captures packets, but none directly validate DNS resolution.

Question 186

Which of the following is the most likely benefit of installing server equipment in a rack?

A. Simplified troubleshooting process
B. Decreased power consumption
C. Improved network performance
D. Increased compute density
Show Answer
Correct Answer: D
Explanation:
Racks allow servers to be mounted vertically in a standardized footprint, maximizing use of floor space and enabling a higher concentration of computing resources per square foot. This increased compute density is the primary and most direct benefit compared to the other options.

Question 187

Which of the following technologies is most appropriate for a business that requires high-speed access to frequently used web content, such as images and videos?

A. CDN
B. SAN
C. Firewall
D. Switch
Show Answer
Correct Answer: A
Explanation:
A Content Delivery Network (CDN) caches and delivers frequently accessed web content such as images and videos from servers closer to end users, reducing latency and providing high-speed access. The other options do not specialize in accelerating web content delivery.

$19

Get all 518 questions with detailed answers and explanations

  • Instant download HTML + PDF delivered the moment payment clears.
  • Secure Stripe checkout we never see or store your card details.
  • 7-day refund if files are defective see our refund policy.