A network administrator is setting up a firewall to protect the organization's network from external threats. Which of the following should the administrator consider first when configuring the firewall?
A. Required ports, protocols, and services
B. Inclusion of a deny all rule
C. VPN access
D. Outbound access originating from customer-facing servers
Show Answer
Correct Answer: A
Explanation: The first consideration when configuring a firewall is identifying the legitimate business traffic that must be permitted. Determining the required ports, protocols, and services establishes the allowlist, after which restrictive rules such as a default deny can be implemented. VPN access and outbound rules are configured based on those business requirements.
Question 246
A network administrator is unable to ping a remote server from a newly connected workstation that has been added to the network, Ping to 127.0.0.1 on the workstation is failing. Which of the following should the administrator perform to diagnose the problem?
A. Verify the NIC interface status.
B. Verify the network is not congested.
C. Verify the router is not dropping packets.
D. Verify that DNS is resolving correctly.
Show Answer
Correct Answer: A
Explanation: A failed ping to 127.0.0.1 indicates a problem on the local workstation rather than with the external network. The loopback test does not rely on DNS, routers, or network congestion. The administrator should first verify the network interface status (and related local TCP/IP configuration) because the issue is local to the host.
Question 247
Which of the following routing protocols is most commonly used to interconnect WANs?
A. IGP
B. EIGRP
C. BGP
D. OSPF
Show Answer
Correct Answer: C
Explanation: BGP (Border Gateway Protocol) is the standard exterior gateway protocol used to interconnect separate autonomous systems across wide area networks, especially between ISPs and large organizations. IGP is a category of internal protocols, while OSPF and EIGRP are primarily used for routing within a single autonomous system.
Question 248
A server administrator deploys a new web server with an IP address of 192.168.16.100. The security policy dictates that all non-secure connection methods should be blocked. Which of the following security rules will satisfy the request without prohibiting other traffic?
A. Deny any 192.168.16.0 255.255.255.0 80
B. Deny 192.168.16.100 255.255.255.255 any
C. Deny any 192.168.16.100 255.255.255.255 80
D. Permit any 192.168.16.100 255.255.255.255 80
E. Permit 192.168.16.100 255.255.255.255 any
Show Answer
Correct Answer: C
Explanation: The policy is to block only non-secure web connections while allowing other traffic. HTTP uses TCP port 80 and is the non-secure web protocol. A rule denying traffic to destination host 192.168.16.100 on port 80 blocks HTTP to that server without affecting HTTPS (443) or other services. The other options either block too much, apply to the wrong scope, or permit rather than deny.
Question 249
Which of the following protocol ports should be used to securely transfer a file?
A. 22
B. 69
C. 80
D. 3389
Show Answer
Correct Answer: A
Explanation: Port 22 is used by SSH, which supports secure file transfer via SFTP and SCP. Port 69 is TFTP (insecure), port 80 is HTTP (unencrypted by default), and port 3389 is RDP for remote desktop rather than file transfer.
Question 250
A network technician is installing a new switch that does not support STP at the access layer of a network. The technician wants a redundant connection to the distribution switch. Which of the following should the technician use?
A. Link aggregation
B. Subinterfaces
C. Switch virtual interfaces
D. Half-duplex connections
Show Answer
Correct Answer: A
Explanation: Link aggregation (EtherChannel/LACP or similar) bundles multiple physical links into a single logical connection, providing redundancy and increased bandwidth while preventing Layer 2 loops without relying on STP between the aggregated links. Subinterfaces are for router/interface VLAN configurations, switch virtual interfaces are for Layer 3 management/routing, and half-duplex is unrelated to redundancy.
Question 251
A company is expanding to another floor in the same building. The network engineer configures a new switch with the same VLANs as the existing stack. When the network engineer connects the new switch to the existing stack, all users lose connectivity. Which of the following is the most likely reason?
A. The new switch has unused ports disabled.
B. The new switch does not have a default gateway.
C. The new switch is connected to an access port.
D. The new switch is in a spanning tree loop.
Show Answer
Correct Answer: D
Explanation: A network-wide outage immediately after connecting a new switch most commonly indicates a Layer 2 switching loop causing a broadcast storm. Spanning Tree Protocol is designed to prevent such loops, but if a loop exists due to misconfiguration or STP not functioning as expected, connectivity for all users can be lost. The other options would affect only the new switch's management or connectivity, not the entire network.
Question 252
A network administrator changed an external DNS to point customers to a new server. Which of the following tools should the administrator use to test the new server’s configuration?
A. ping
B. tracert
C. tcpdump
D. nslookup
Show Answer
Correct Answer: D
Explanation: nslookup is the appropriate tool to verify DNS resolution after changing external DNS records. It queries DNS servers directly and confirms that the hostname resolves to the expected IP address of the new server. ping tests reachability, tracert traces the network path, and tcpdump captures packets but does not verify DNS record resolution.
Question 253
Which of the following is the most likely benefit of installing server equipment in a rack?
A. Simplified troubleshooting process
B. Decreased power consumption
C. Improved network performance
D. Increased compute density
Show Answer
Correct Answer: D
Explanation: Installing servers in racks allows vertical, standardized mounting that maximizes use of physical space, increasing the amount of compute equipment that can fit in a given footprint. While racks can aid cable management and maintenance, they do not inherently reduce power consumption or improve network performance.
Question 254
Which of the following technologies is most appropriate for a business that requires high-speed access to frequently used web content, such as images and videos?
A. CDN
B. SAN
C. Firewall
D. Switch
Show Answer
Correct Answer: A
Explanation: A Content Delivery Network (CDN) caches and serves frequently accessed web content such as images and videos from geographically distributed edge servers, reducing latency and improving load times. A SAN provides storage infrastructure, a firewall provides network security, and a switch connects devices on a network rather than accelerating web content delivery.
$19
Get all 652 questions with detailed answers and explanations
Instant download HTML + PDF delivered the moment payment clears.
Secure Stripe checkout we never see or store your card details.
7-day refund if files are defective see our refund policy.