Comptia

N10-009 Free Practice Questions — Page 28

Question 272

A network engineer is designing an internal network that needs to support both IPv4 and IPv6 routing. Which of the following routing protocols is capable of supporting both IPv4 and IPv6?

A. OSPFv3
B. RIPv2
C. BGP
D. EIGRP
Show Answer
Correct Answer: A, C, D
Explanation:
OSPFv3 supports both IPv4 and IPv6 using address families. BGP supports both through Multiprotocol BGP (MP-BGP). EIGRP supports both IPv4 and IPv6. RIPv2 supports only IPv4; IPv6 uses RIPng. Sources: https://www.juniper.net/documentation/us/en/software/junos/interfaces-fundamentals/topics/topic-map/protocol-family-interface-address-properties.html

Question 273

A network administrator needs to efficiently deploy 200 systems using RFC1918 addresses. Which of the following networks should the administrator use?

A. 10.10.10.0/8
B. 150.200.1.0/24
C. 192.168.1.0/24
D. 254.169.0.0/24
Show Answer
Correct Answer: C
Explanation:
RFC1918 private address ranges are 10.0.0.0/8, 172.16.0.0/12, and 192.168.0.0/16. Among the options, 192.168.1.0/24 is a valid RFC1918 subnet. A /24 provides 256 addresses (254 usable), which is sufficient for 200 systems and is more efficient than using the entire 10.0.0.0/8 space. Option A is improperly expressed because 10.10.10.0 is not the network address for a /8 network; B is public, and D is not an RFC1918 private range.

Question 274

A network administrator deploys several new desk phones and workstation cubicles. Each cubicle has one assigned switchport. The administrator run the following commands: switchport mode access switchport voice vlan 69 With which of the following VLANs will the workstation traffic be tagged?

A. Private VLAN
B. Voice VLAN
C. Native VLAN
D. Data VLAN
Show Answer
Correct Answer: D
Explanation:
On a Cisco access port configured with 'switchport voice vlan 69', the attached IP phone tags voice traffic with VLAN 69. The workstation connected through the phone sends normal Ethernet frames untagged, and the switch associates that untagged traffic with the port's access (data) VLAN. If no explicit 'switchport access vlan' is configured, the access VLAN remains the default access VLAN (VLAN 1), which is still the data VLAN for the port. The native VLAN is a trunk-port concept, not the correct answer for an access port.

Question 275

Which of the following is used to separate a corporate network into multiple logical networks?

A. Load balancer
B. VLAN
C. CDN
D. IPS
Show Answer
Correct Answer: B
Explanation:
A VLAN (Virtual Local Area Network) logically segments a physical network into multiple separate broadcast domains, allowing a corporate network to be divided into multiple logical networks. A load balancer distributes traffic, a CDN caches content geographically, and an IPS detects/prevents malicious traffic rather than performing logical network segmentation.

Question 276

A tourist attempts to access an online banking site on a mobile device while in a public place. Which of the following is the tourist most likely to experience?

A. Vishing
B. Tailgating
C. Shoulder surfing
D. Peripheral attack
Show Answer
Correct Answer: C
Explanation:
Shoulder surfing is the risk of someone nearby observing the user's screen or keystrokes in a public place to steal sensitive information such as online banking credentials. Vishing is voice phishing, tailgating is unauthorized physical entry by following someone, and a peripheral attack is not the best fit for this scenario.

Question 277

A network engineer wants to implement a secure solution that provides authentication and encryption to gather and monitor logs within the company network. Which of the following tools will accomplish this task?

A. Syslog
B. RADIUS
C. SNMPv3
D. API
Show Answer
Correct Answer: C
Explanation:
SNMPv3 provides secure network monitoring and management with authentication and encryption (privacy), making it suitable for gathering and monitoring logs and device information securely. Syslog alone does not provide authentication and encryption, RADIUS is for AAA, and an API is a generic interface rather than a logging/monitoring protocol.

Question 278

A junior network administrator gets a text message from a number posing as the domain registrar of the firm. The administrator is tricked into providing global administrator credentials. Which of the following attacks is taking place?

A. DNS poisoning
B. ARP spoofing
C. Vishing
D. Smishing
Show Answer
Correct Answer: D
Explanation:
The attack is smishing, which is phishing conducted via SMS/text messages. The attacker impersonates a trusted entity (the domain registrar) through a text message to trick the administrator into revealing global administrator credentials. Vishing uses voice calls, while DNS poisoning and ARP spoofing are network-layer attacks rather than social engineering via text.

Question 279

Which of the following will allow secure, remote access to internal applications?

A. VPN
B. CDN
C. SAN
D. IDS
Show Answer
Correct Answer: A
Explanation:
A VPN (Virtual Private Network) provides secure remote access to internal applications by creating an encrypted connection between a remote user and the organization's network. A CDN distributes content, a SAN provides storage networking, and an IDS detects intrusions rather than providing remote access.

Question 280

Users report connectivity issues after a network switch is replaced. There are three separate subnets for users, voice, and servers. The users cannot reach the resources in the server subnet. Upon investigation, a separate voice switch has thousands of discarded packets, but no users report issues making or receiving calls. Which of the following is most likely the issue?

A. Incorrect cable
B. Port administratively disabled
C. VLAN misconfiguration
D. Duplex setting
Show Answer
Correct Answer: C
Explanation:
A switch replacement commonly introduces VLAN or trunk configuration errors. Separate user, voice, and server subnets are typically carried on distinct VLANs. If the user or server VLAN is missing or incorrectly tagged on the new switch or its uplink, users will be unable to reach server resources. The voice switch showing many discarded packets without impacting calls is likely incidental or related to QoS/buffering rather than the primary connectivity failure. The other options do not fit as well: an incorrect cable or administratively disabled port would typically cause obvious link failures, and a duplex mismatch would more likely cause widespread performance problems rather than selectively breaking communication between VLANs.

Question 281

Which of the following are benefits of implementing MFA and SSO in an enterprise environment? (Choose two.)

A. Eliminating the number of password resets
B. Centralizing user account management activities
C. Adding an extra layer of security against compromised credentials
D. Reducing the overhead of security tokens
E. Enforcing conditional access policies
F. Leveraging threat feed information from external sources
Show Answer
Correct Answer: B, C
Explanation:
SSO's primary enterprise benefit is centralized identity and user account management, simplifying provisioning, deprovisioning, and access administration. MFA's primary benefit is adding an extra layer of security so stolen or compromised passwords alone are insufficient for access. Eliminating password resets is not guaranteed, reducing security tokens is not an inherent benefit, conditional access is a capability of many identity platforms but not an inherent benefit of implementing MFA and SSO themselves, and threat feeds are unrelated.

$19

Get all 580 questions with detailed answers and explanations

  • Instant download HTML + PDF delivered the moment payment clears.
  • Secure Stripe checkout we never see or store your card details.
  • 7-day refund if files are defective see our refund policy.