Which of the following is the best way to securely access a network appliance from an external location?
A. RDP
B. Telnet
C. FTPS
D. SSH
Show Answer
Correct Answer: D
Explanation: SSH is the standard secure protocol for remotely administering network appliances over an untrusted network. It encrypts authentication and session traffic. Telnet is insecure because it sends data in plaintext, RDP is primarily for remote desktop access rather than typical network appliance management, and FTPS is for secure file transfer, not interactive device administration.
Question 22
Which of the following allows for the fastest recovery during a catastrophic event?
A. Warm site
B. Asynchronous replication
C. Cold site
D. Hot site
Show Answer
Correct Answer: D
Explanation: A hot site provides the fastest disaster recovery because it is a fully equipped, operational duplicate of the primary site and can be brought online with minimal downtime. Warm sites require additional configuration, cold sites require the most setup, and asynchronous replication is a data replication method rather than a recovery site and may involve some data loss.
Sources:
https://brainly.com/question/47488544
Question 23
A network administrator needs to establish a tunnel that can:
• Authenticate packet headers.
• Exchange encryption keys over the network.
• Transmit encrypted payloads.
Which of the following technologies should the administrator choose?
A. IPSec
B. ESP
C. AH
D. GRE
Show Answer
Correct Answer: A
Explanation: IPsec is the full suite that provides authenticated packet headers (via AH), encrypted payloads (via ESP), and key exchange over the network using IKE. ESP alone encrypts payloads but does not perform key exchange, AH authenticates headers but does not encrypt payloads, and GRE provides tunneling without built-in security.
Sources:
https://www.juniper.net/documentation/us/en/software/junos/vpn-ipsec/topics/topic-map/security-ike-basics.html
Question 24
Which of the following is the most appropriate solution to verify credentials?
A. MFA
B. ACL
C. Role-based access control
D. Least privilege
Show Answer
Correct Answer: A
Explanation: Multi-factor authentication (MFA) is the control specifically used to verify a user's credentials by requiring additional authentication factors beyond a password. ACLs, role-based access control, and least privilege govern authorization (what an authenticated user can access), not credential verification.
Question 25
A network administrator needs to divide a Class B network into four equal subnets, each with a host range of 1,000 hosts. Which of the following subnet masks should the administrator use?
A. 255.255.0.0
B. 255.255.252.0
C. 255.255.255.0
D. 255.255.255.128
Show Answer
Correct Answer: B
Explanation: A Class B network has a default /16 mask. To create four equal subnets, borrow 2 bits, resulting in a /18 mask (255.255.192.0). However, that mask is not among the choices. Of the provided options, only 255.255.252.0 (/22) supports approximately 1,022 usable hosts per subnet, matching the stated host requirement of about 1,000 hosts. The question is internally inconsistent, but /22 best satisfies the host-count requirement.
Sources:
https://induwara.lk/tools/ip-subnet-calculator
Question 26
Some newly installed wireless APs are not broadcasting. Which of the following is the most likely cause of the issue?
A. PoE power budget exceeded
B. Improper VLAN assignment
C. Limited signal strength/degradation
D. Uplink transceiver incorrectly configured
Show Answer
Correct Answer: A
Explanation: If some newly installed access points are not broadcasting after installation, the most likely cause is that the switch's PoE power budget has been exceeded. In that case, some APs may not receive sufficient power to boot or enable their radios. Improper VLAN assignment or an incorrectly configured uplink transceiver can affect network connectivity, but the APs would typically still power on and may still broadcast an SSID. Limited signal strength affects clients' ability to receive the signal, not whether the AP broadcasts at all.
Question 27
After a recent building renovation, the number of tickets regarding network slowness during lunch breaks increases. A cable from the server room is traced to the break room, which has high levels of known interference. Which of the following types of network cables should be used to address this issue while keeping costs low?
A. Single-mode fiber
B. Multimode fiber
C. Unshielded twisted pair
D. Shielded twisted pair
Show Answer
Correct Answer: D
Explanation: Shielded twisted pair (STP) is designed to reduce electromagnetic interference (EMI), making it appropriate for a cable run through an area with high interference. It is significantly less expensive than replacing the run with fiber while addressing the interference issue. Unshielded twisted pair lacks shielding, and while fiber is immune to EMI, it is more costly than necessary for this scenario.
Sources:
https://quizlet.com/944986578/network-v2-2616-lesson-review-flash-cards
Question 28
A user reports issues connecting to the network via an Ethernet Cat 6 cable. A network technician examines the cable and notices that it is terminated properly, but the color code is incorrect. Which of the following steps should the technician take next to troubleshoot this issue?
A. Implement a fiber cable.
B. Replace the Ethernet cable.
C. Change the switchport speed.
D. Use a cable tester.
Show Answer
Correct Answer: D
Explanation: If the cable appears properly terminated but the wire color sequence is incorrect, the next troubleshooting step is to verify the actual pinout and continuity with a cable tester. The tester will identify miswires, crossed pairs, split pairs, or other wiring faults before deciding whether the cable needs retermination or replacement.
Sources:
https://www.discountedcables.com/blogs/dc-blog/cat-6-ethernet-cable-color-code-a-simplified-guide
Question 29
Which of the following acts as the core of a network?
A. MDF
B. MTU
C. MPO
D. MIB
Show Answer
Correct Answer: A
Explanation: The Main Distribution Frame (MDF) is the central point for network cabling and cross-connects within a building or campus and is commonly considered the core of the physical network infrastructure. MTU is Maximum Transmission Unit, MPO is a fiber connector type, and MIB is a Management Information Base used by SNMP.
Question 30
A network engineer configures a new DHCP scope with 100 usable IP addresses but wants to reserve the first ten addresses to configure statically on the printers. Which of the following DHCP parameters is the best way to accomplish this task?
A. Reservation
B. Exclusion
C. IP helper
D. Option
Show Answer
Correct Answer: B
Explanation: An exclusion range removes specific IP addresses from the DHCP pool so they are not leased dynamically. This is the appropriate way to keep the first ten addresses available for static printer configuration. A reservation is used to assign a specific DHCP address to a specific client, an IP helper relays DHCP requests across subnets, and DHCP options provide configuration values such as DNS or gateway.
Sources:
https://dev.to/andrew_despres/comptia-network-n10-009-53-study-guide-routing-switching-and-ip-issues-28i6
$19
Get all 580 questions with detailed answers and explanations
Instant download HTML + PDF delivered the moment payment clears.
Secure Stripe checkout we never see or store your card details.
7-day refund if files are defective see our refund policy.