Comptia

N10-009 Free Practice Questions — Page 29

Question 282

A company experiences an incident involving a user who connects an unmanaged switch to the network. Which of the following technologies should the company implement to help avoid similar incidents without conducting an asset inventory?

A. Screened subnet
B. 802.1X
C. MAC filtering
D. Port security
Show Answer
Correct Answer: D
Explanation:
Port security is designed to prevent unauthorized devices such as unmanaged switches from being connected by limiting the number of MAC addresses learned on a switch port. If an unmanaged switch is attached, multiple MAC addresses appear behind a single port, triggering a violation (restrict, protect, or shutdown). This does not require maintaining a full asset inventory. 802.1X provides port-based authentication, but the scenario specifically emphasizes preventing unmanaged switches without relying on asset inventory; port security is the more direct control.

Question 283

Two companies successfully merged. Following the merger, a network administrator identified a connection bottleneck. The newly formed company plans to acquire a high-end 40GB switch and redesign the network from a three-tier model to a collapsed core. Which of the following should the administrator do until the new devices are acquired?

A. Implement the FHRP.
B. Configure a route selection metric change.
C. Install a load balancer.
D. Enable link aggregation.
Show Answer
Correct Answer: D
Explanation:
Enabling link aggregation (LACP/EtherChannel) combines multiple physical links into a single logical link, increasing available bandwidth between switches and reducing inter-switch bottlenecks without replacing hardware. FHRP provides gateway redundancy, route metric changes affect path selection rather than link capacity, and a load balancer addresses server/application traffic rather than switch uplink congestion.

Question 284

Which of the following network ports is used when a client accesses an SFTP server?

A. 22
B. 80
C. 443
D. 3389
Show Answer
Correct Answer: A
Explanation:
SFTP (SSH File Transfer Protocol) runs over SSH and, by default, uses TCP port 22. The other ports correspond to HTTP (80), HTTPS (443), and Remote Desktop Protocol (3389).

Question 285

Which of the following typically uses compromised systems that become part of a bot network?

A. Evil twin attack
B. DDoS attack
C. XML injection
D. Brute-force password attack
Show Answer
Correct Answer: B
Explanation:
A DDoS (Distributed Denial of Service) attack commonly leverages a botnet—a network of compromised systems (bots or zombies) under an attacker's control—to generate large volumes of traffic against a target. The other options do not typically rely on compromised systems forming a bot network.

Question 286

Some of the 20 employees who use the wireless network report they are unable to access network resources even though the wireless network is available. An administrator recently made the following configuration changes to the wireless DHCP server: Network: 192.168.100.0 - Mask: 255.255.255.240 - Gateway: 192.168.100.1 - Which of the following is the cause of this issue?

A. Incorrect VLAN assignment
B. Incorrect ACL configuration
C. Incorrect subnet mask
D. Incorrect default gateway
Show Answer
Correct Answer: C
Explanation:
A subnet mask of 255.255.255.240 (/28) provides 16 total addresses, with only 14 usable host IP addresses. A wireless network serving 20 employees can exhaust the DHCP pool, causing some clients to obtain no IP address and therefore be unable to access network resources. The default gateway shown is valid for the subnet, and the symptoms do not specifically indicate VLAN or ACL misconfiguration.

Question 287

Which of the following would most likely be utilized to implement encryption in transit when using HTTPS?

A. SSH
B. TLS
C. SCADA
D. RADIUS
Show Answer
Correct Answer: B
Explanation:
HTTPS uses Transport Layer Security (TLS) to provide encryption, integrity, and server (and optionally client) authentication for data in transit. SSH secures remote shell sessions, SCADA refers to industrial control systems, and RADIUS is an authentication/AAA protocol rather than the protocol that encrypts HTTPS traffic.

Question 288

The network engineering team needs to implement a wireless network within two separate buildings. Once the network is set up, users will need to authenticate using RADIUS in order to access internal resources. Which of the following wireless technologies should the team implement?

A. Mesh
B. Enterprise
C. Ad hoc
D. Point to point
Show Answer
Correct Answer: B
Explanation:
WPA2/WPA3-Enterprise wireless uses 802.1X authentication with a RADIUS server, which matches the requirement that users authenticate via RADIUS before accessing internal resources. Mesh, ad hoc, and point-to-point describe network topologies or link types rather than the authentication framework required.

Question 289

A network engineer discovers network traffic that is sending confidential information to an unauthorized and unknown destination. Which of the following best describes the cause of this network traffic?

A. Ransomware
B. Darkware
C. Malware
D. Adware
Show Answer
Correct Answer: C
Explanation:
Confidential information being sent to an unauthorized, unknown destination is characteristic of data exfiltration by malware. Ransomware primarily encrypts data for extortion, adware focuses on advertising, and 'darkware' is not a standard malware category. Malware is the broad and best-fitting description.

Question 290

A network administrator is configuring a network for a new site that will have 150 users. Within the next year, the site is expected to grow by ten uses. Each user will have two IP addresses, one computer, and one phone connected to the network. Which of the following classful IPv4 address ranges will be best-suited for the network?

A. Class D
B. Class B
C. Class A
D. Class C
Show Answer
Correct Answer: B
Explanation:
The network is expected to support 160 users, each requiring two IP addresses (computer and phone), for a minimum of 320 host addresses, not including infrastructure devices. In classful addressing, a Class C network provides only 254 usable host addresses, which is insufficient. Class D is reserved for multicast, and Class A is far larger than necessary. Class B supports up to 65,534 usable host addresses and is the smallest classful network that can accommodate the requirement.

Question 291

Which of the following provides an opportunity for an on-path attack?

A. Phishing
B. Dumpster diving
C. Evil twin
D. Tailgating
Show Answer
Correct Answer: C
Explanation:
An on-path (man-in-the-middle) attack requires the attacker to position themselves between a victim and the network or another communicating party. An evil twin is a rogue Wi-Fi access point that impersonates a legitimate network, enticing victims to connect so the attacker can intercept or modify traffic. Phishing steals credentials, dumpster diving recovers discarded information, and tailgating is a physical access attack rather than an on-path network attack.

$19

Get all 580 questions with detailed answers and explanations

  • Instant download HTML + PDF delivered the moment payment clears.
  • Secure Stripe checkout we never see or store your card details.
  • 7-day refund if files are defective see our refund policy.