Comptia

N10-009 Free Practice Questions — Page 26

Question 249

A company wants to implement data loss prevention by restricting user access to social media platforms and personal cloud storage on workstations. Which of the following types of filtering should the company deploy to achieve these goals?

A. Port
B. DNS
C. MAC
D. Content
Show Answer
Correct Answer: D
Explanation:
Restricting access to social media platforms and personal cloud storage requires identifying and blocking specific websites, applications, or types of data. Content filtering (often implemented via web filtering/URL categorization or application-aware inspection) can recognize and block social media and cloud storage services based on content, URLs, or application signatures. Port, DNS, and MAC filtering are too coarse or indirect to reliably enforce this type of data loss prevention.

Question 250

Which of the following services runs on port 636?

A. SMTP
B. Syslog
C. TFTP
D. LDAPS
Show Answer
Correct Answer: D
Explanation:
Port 636 is assigned to LDAPS (LDAP over SSL/TLS). The other options use different ports: SMTP uses 25/587/465, Syslog uses 514 (UDP/TCP), and TFTP uses 69 (UDP).

Question 251

After providing a username and password, a user must input a passcode from a phone application. Which of the following authentication technologies is used in this example?

A. SSO
B. LDAP
C. MFA
D. SAML
Show Answer
Correct Answer: C
Explanation:
The scenario requires two different authentication factors: something the user knows (username and password) and something the user has (a passcode generated by a phone application). This is the definition of multi-factor authentication (MFA). The other options describe identity or access technologies, not an authentication method using multiple factors.

Question 252

Which of the following allows for the interception of traffic between the source and destination?

A. Self-signed certificate
B. VLAN hopping
C. On-path attack
D. Phishing
Show Answer
Correct Answer: C
Explanation:
An on-path (man-in-the-middle) attack places the attacker between the source and destination, allowing interception, monitoring, and potential modification of traffic in transit. The other options do not inherently enable interception between two communicating endpoints.

Question 253

Which of the following disaster recovery concepts is calculated by dividing the total hours of operation by the total number of units?

A. MTTR
B. MTBF
C. RPO
D. RTO
Show Answer
Correct Answer: B
Explanation:
MTBF (Mean Time Between Failures) is calculated by dividing the total hours of operation by the total number of failures (or units failing), which matches the description given. MTTR focuses on repair time, while RPO and RTO relate to data loss and recovery time objectives, not operational averages.

Question 254

Which of following must be implemented to securely connect a company’s headquarters with a branch location?

A. Split-tunnel VPN
B. Clientless VPN
C. Full-tunnel VPN
D. Site-to-site VPN
Show Answer
Correct Answer: D
Explanation:
A site-to-site VPN is specifically designed to securely connect two separate networks, such as a company headquarters and a branch office, over the internet. It creates an encrypted tunnel between network gateways, allowing seamless and secure communication between locations. The other options are intended for individual remote users rather than network-to-network connectivity.

Question 255

A network administrator wants to restrict inbound traffic to allow only HTTPS to the company website, denying all other inbound traffic from the internet. Which of the following would best accomplish this goal?

A. ACL on the edge firewall
B. Port security on an access switch
C. Content filtering on a web gateway
D. URL filtering on an outbound proxy
Show Answer
Correct Answer: A
Explanation:
An ACL on the edge firewall can explicitly permit inbound TCP traffic on port 443 (HTTPS) to the web server while denying all other inbound internet traffic. The other options address internal switch security or outbound/content filtering and do not control inbound internet access to the website.

Question 256

In an environment with one router, which of the following will allow a network engineer to communicate between VLANs without purchasing additional hardware?

A. Subinterfaces
B. VXLAN
C. Layer 3 switch
D. VIP
Show Answer
Correct Answer: A
Explanation:
Using router subinterfaces (router-on-a-stick) allows a single physical router interface to be logically divided into multiple VLAN-tagged subinterfaces, enabling inter-VLAN routing without additional hardware. VXLAN, a Layer 3 switch, or VIP do not meet the constraint of one router with no new hardware.

Question 257

Which of the following offers the ability to manage access at the cloud VM instance?

A. Security group
B. Internet gateway
C. Direct Connect
D. Network ACL
Show Answer
Correct Answer: A
Explanation:
A security group manages access at the cloud VM (instance) level by acting as a virtual firewall that controls inbound and outbound traffic based on rules for IPs, ports, and protocols. Network ACLs operate at the subnet level, while Internet Gateways and Direct Connect provide connectivity rather than instance-level access control.

Question 258

An IT department asks a newly hired employee to use a personal laptop until the company can provide one. Which of the following policies is most applicable to this situation?

A. IAM
B. BYOD
C. DLP
D. AUP
Show Answer
Correct Answer: B
Explanation:
The scenario describes an employee using a personal laptop for work purposes. This directly aligns with a Bring Your Own Device (BYOD) policy, which governs the use of personally owned devices to access company resources. IAM manages identities, DLP focuses on data protection, and AUP defines acceptable use but does not specifically address personal device usage.

$19

Get all 518 questions with detailed answers and explanations

  • Instant download HTML + PDF delivered the moment payment clears.
  • Secure Stripe checkout we never see or store your card details.
  • 7-day refund if files are defective see our refund policy.