Comptia

N10-009 Free Practice Questions — Page 23

Question 218

Which of the following typically uses compromised systems that become part of a bot network?

A. Evil twin attack
B. DDoS attack
C. XML injection
D. Brute-force password attack
Show Answer
Correct Answer: B
Explanation:
A Distributed Denial of Service (DDoS) attack typically relies on a botnet—many compromised systems (bots or zombies) controlled by an attacker—to simultaneously flood a target with traffic. The other options do not inherently require or use a network of compromised systems.

Question 219

Some of the 20 employees who use the wireless network report they are unable to access network resources even though the wireless network is available. An administrator recently made the following configuration changes to the wireless DHCP server: Network: 192.168.100.0 - Mask: 255.255.255.240 - Gateway: 192.168.100.1 - Which of the following is the cause of this issue?

A. Incorrect VLAN assignment
B. Incorrect ACL configuration
C. Incorrect subnet mask
D. Incorrect default gateway
Show Answer
Correct Answer: C
Explanation:
A subnet mask of 255.255.255.240 is a /28 network, which provides only 16 total IP addresses and 14 usable host addresses. With 20 wireless users, the DHCP scope cannot supply enough IP addresses, causing some users to be unable to access network resources. Therefore, the issue is an incorrect (too small) subnet mask.

Question 220

Which of the following would most likely be utilized to implement encryption in transit when using HTTPS?

A. SSH
B. TLS
C. SCADA
D. RADIUS
Show Answer
Correct Answer: B
Explanation:
HTTPS secures HTTP traffic by using TLS (Transport Layer Security) to provide encryption in transit, along with integrity and authentication. SSH is used for secure remote access, SCADA is for industrial control systems, and RADIUS handles authentication and accounting, not HTTPS encryption.

Question 221

The network engineering team needs to implement a wireless network within two separate buildings. Once the network is set up, users will need to authenticate using RADIUS in order to access internal resources. Which of the following wireless technologies should the team implement?

A. Mesh
B. Enterprise
C. Ad hoc
D. Point to point
Show Answer
Correct Answer: B
Explanation:
Enterprise wireless solutions support centralized authentication, authorization, and accounting using protocols such as RADIUS. They are designed for multi-user environments requiring secure access to internal resources, unlike ad hoc, mesh, or point-to-point technologies which do not provide native enterprise authentication capabilities.

Question 222

A network engineer discovers network traffic that is sending confidential information to an unauthorized and unknown destination. Which of the following best describes the cause of this network traffic?

A. Ransomware
B. Darkware
C. Malware
D. Adware
Show Answer
Correct Answer: C
Explanation:
The behavior described—confidential information being sent to an unauthorized and unknown destination—is characteristic of malware, which broadly includes malicious software designed to steal, exfiltrate, or misuse data. Ransomware focuses on encrypting data for extortion, adware targets advertising, and 'darkware' is not a standard specific category for this activity. Therefore, malware is the best description.

Question 223

A network administrator is configuring a network for a new site that will have 150 users. Within the next year, the site is expected to grow by ten uses. Each user will have two IP addresses, one computer, and one phone connected to the network. Which of the following classful IPv4 address ranges will be best-suited for the network?

A. Class D
B. Class B
C. Class A
D. Class C
Show Answer
Correct Answer: B
Explanation:
The network will have 160 users (150 + 10 growth), and each user requires two IP addresses (computer and phone), totaling 320 IP addresses, not including additional infrastructure devices. A Class C network supports only 254 usable host addresses, which is insufficient. Class D is reserved for multicast and cannot be used for host addressing, while Class A provides far more addresses than necessary. Class B, with up to 65,534 usable host addresses, comfortably meets the requirement and is the most appropriate classful choice.

Question 224

Which of the following provides an opportunity for an on-path attack?

A. Phishing
B. Dumpster diving
C. Evil twin
D. Tailgating
Show Answer
Correct Answer: C
Explanation:
An on-path (man-in-the-middle) attack requires the attacker to place themselves between the victim and a legitimate communication endpoint. An evil twin attack does exactly this by setting up a rogue Wi‑Fi access point that impersonates a trusted network, causing victims to connect through the attacker, who can then intercept or modify traffic. The other options are social or physical attacks that do not inherently place the attacker on the network communication path.

Question 225

Which of the following best represents north-south traffic?

A. A connection between a computer and a public web server
B. Data moving between a data center and a DR site
C. Traffic between a production server and a backup server
D. Routing updates between OSPF routers
Show Answer
Correct Answer: A
Explanation:
North–south traffic describes communication that flows into or out of a network, typically between internal systems and external networks such as the internet. A connection between a computer and a public web server is a classic example of this pattern. The other options describe internal or east–west traffic or control-plane communication.

Question 226

A network engineer is completing a new VoIP installation, but the phones cannot find the TFTP server to download the configuration files. Which of the following DHCP features would help the phone reach the TFTP server?

A. Exclusions
B. Lease time
C. Options
D. Scope
Show Answer
Correct Answer: C
Explanation:
VoIP phones use DHCP options (such as Option 66 or 150) to learn the IP address of the TFTP server where they download configuration files. Exclusions, lease time, and scope do not provide this server information.

Question 227

A firewall administrator is mapping a server's internal IP address to an external IP address for public use. Which of the following is the name of this function?

A. NAT
B. VIP
C. PAT
D. BGP
Show Answer
Correct Answer: A
Explanation:
Mapping an internal private IP address to an external public IP address for access from the internet is the function of Network Address Translation (NAT). VIP is a vendor-specific concept built on top of NAT, PAT is port-based translation, and BGP is a routing protocol.

$19

Get all 518 questions with detailed answers and explanations

  • Instant download HTML + PDF delivered the moment payment clears.
  • Secure Stripe checkout we never see or store your card details.
  • 7-day refund if files are defective see our refund policy.