A VoIP phone powers up, but it is unable to receive or place calls. After connecting to another switchport, the issue is resolved. Which of the following was most likely the issue with the previous port?
A. The port had a half-duplex configuration.
B. The port was in an error-disabled state.
C. The port had an incorrect VLAN assignment.
D. The port exceeded its PoE budget.
Show Answer
Correct Answer: C
Explanation: A VoIP phone can still power on via PoE even if the switchport is misconfigured. If the port is assigned to the wrong VLAN (for example, a data VLAN instead of the correct voice VLAN), the phone may not be able to reach the call manager or VoIP services, preventing it from placing or receiving calls. Moving the phone to a correctly configured port resolves the issue, making an incorrect VLAN assignment the most likely cause.
Question 189
A customer calls the help desk to report issues connecting to the internet. The customer can reach a local database server. A technician goes to the site and examines the configuration:
Which of the following is causing the user's issue?
A. Incorrect DNS
B. Unreachable gateway
C. Failed root bridge
D. Poor upstream routing
Show Answer
Correct Answer: B
Explanation: The user can access a local database server, which confirms local subnet connectivity is working. The issue is reaching the internet, which requires a valid default gateway. With an IP address of 192.168.1.223 and a subnet mask of 255.255.255.192 (/26), the valid host range is 192.168.1.192–192.168.1.254. The configured default gateway of 192.168.1.190 lies outside this subnet, making it unreachable. As a result, traffic destined for the internet cannot leave the local network.
Question 190
A help desk technician receives a report that users cannot access internet URLs. The technician does some ping tests and finds that sites fail when a URL is used but work when an IP is used. Which of the following tools should the technician utilize next?
A. tcpdump
B. tracert
C. nmap
D. dig
Show Answer
Correct Answer: D
Explanation: Accessing sites by IP but not by URL indicates a DNS name resolution problem. The appropriate next tool is dig, which queries DNS servers directly to diagnose DNS resolution issues. Tools like tcpdump, tracert, or nmap do not directly test DNS name resolution.
Question 191
Which of the following is the part of a DR plan that identifies the critical systems that should be recovered first after an incident?
A. RTO
B. SLA
C. MTBF
D. SIEM
Show Answer
Correct Answer: A
Explanation: RTO (Recovery Time Objective) defines the maximum acceptable downtime for systems after an incident. By establishing RTOs, a disaster recovery plan identifies which systems are most critical and therefore must be restored first. The other options do not serve this prioritization role in DR planning.
Question 192
Which of the following is the best VPN to use for reducing data bandwidth requirements of the corporate network?
A. Split-tunnel
B. Site-to-site
C. Full tunnel client
D. GRE tunnel
Show Answer
Correct Answer: A
Explanation: A split-tunnel VPN sends only corporate-destined traffic through the VPN while allowing general internet traffic to go directly to the internet. This minimizes traffic traversing the corporate network, thereby reducing bandwidth usage compared to full-tunnel, site-to-site, or GRE tunnels.
Question 193
An ISP provided a company with a pre-configured modem and five public static IP addresses. Which of the following does the company's firewall require to access the internet? (Choose two.)
A. NTP server
B. Default gateway
C. The modem’s IP address
D. One static IP address
E. DNS servers
F. DHCP server
Show Answer
Correct Answer: B, D
Explanation: To access the internet, the firewall must have a valid IP configuration. It requires a default gateway so it knows where to forward traffic destined for external networks, and it must be assigned one of the public static IP addresses provided by the ISP to communicate on the internet. Services like NTP, DNS, or DHCP are not strictly required for basic internet connectivity, and the modem’s IP itself is not needed by the firewall.
Question 194
During a recent security assessment, an assessor attempts to obtain user credentials by pretending to be from the organization's help desk. Which of the following attacks is the assessor using?
A. Social engineering
B. Tailgating
C. Shoulder surfing
D. Smishing
E. Evil twin
Show Answer
Correct Answer: A
Explanation: Pretending to be from the help desk to trick users into revealing credentials is a classic form of social engineering, where an attacker manipulates people rather than exploiting technical vulnerabilities.
Question 195
Which of the following dynamic routing protocols is used on the internet?
A. EIGRP
B. BGP
C. RIP
D. OSPF
Show Answer
Correct Answer: B
Explanation: BGP (Border Gateway Protocol) is the dynamic routing protocol used on the internet to exchange routing information between autonomous systems. EIGRP, RIP, and OSPF are primarily interior gateway protocols used within private or internal networks, not for internet-wide routing.
Question 196
A technician is implementing a new SD-VVAN device with a default configuration. The technician receives a URL via email and connects the new device to the internet to complete the installation. Which of the following is this an example of?
A. SASE device installation
B. Zero-touch provisioning
C. Infrastructure as code
D. Configuration management
Show Answer
Correct Answer: B
Explanation: Connecting a new SD-WAN/SD-VVAN device with a default configuration to the internet and having it automatically retrieve its configuration from a provided URL is characteristic of zero-touch provisioning. ZTP enables devices to self-configure without manual intervention once powered on and connected.
Question 197
Which of the following would allow a network administrator to remotely access a secure subnet from a shared, secure workstation?
A. Enable SSH through the firewall.
B. Dial into an in-band modem.
C. Connect through a jump host.
D. Configure a site-to-site VPN.
Show Answer
Correct Answer: C
Explanation: A jump host (jump server) is a hardened intermediary system placed between a shared workstation and a secure subnet. Administrators authenticate to the jump host and then access internal resources, providing controlled, auditable, and least-privilege remote access. The other options either expose services broadly, are outdated/insecure, or serve different use cases.
$19
Get all 518 questions with detailed answers and explanations
Instant download HTML + PDF delivered the moment payment clears.
Secure Stripe checkout we never see or store your card details.
7-day refund if files are defective see our refund policy.