Comptia

N10-009 Free Practice Questions — Page 5

Question 41

Which of the following connection methods allows a network engineer to automate the configuration deployment for network devices across the environment?

A. RDP
B. Telnet
C. GUI
D. API
Show Answer
Correct Answer: D
Explanation:
APIs enable programmatic access to network devices, allowing scripts and automation platforms to deploy configurations consistently across many devices. RDP, Telnet, and GUIs are primarily interactive management methods and are not the standard mechanism for scalable automated configuration deployment.

Question 42

A network engineer sees traffic going to 224.7.8.99. Which of the following describes this traffic type?

A. Broadcast
B. Unicast
C. Multicast
D. Anycast
Show Answer
Correct Answer: C
Explanation:
IPv4 addresses in the range 224.0.0.0 through 239.255.255.255 are Class D multicast addresses. The destination 224.7.8.99 falls within this range, so the traffic is multicast.

Question 43

A systems administrator is configuring a new domain server in the network. Which of the following ports should the administrator open in the firewall to allow secure LDAP communications between the domain and the desktops?

A. 389
B. 587
C. 636
D. 3389
Show Answer
Correct Answer: C
Explanation:
Secure LDAP (LDAPS) uses TCP port 636. Port 389 is standard (unencrypted or StartTLS-capable) LDAP, 587 is SMTP message submission, and 3389 is Remote Desktop Protocol (RDP). Sources: https://www.sentinelone.com/cybersecurity-101/identity-security/ldap-injection https://learn.microsoft.com/en-us/defender-for-identity/deploy/prerequisites-sensor-version-2

Question 44

A public library wants to implement a solution in which users need to connect to the wireless network and then authenticate via HTTPS with provided credentials. Which of the following technologies fulfills this requirement?

A. WPA3
B. Captive portal
C. Single sign-on
D. SAML
Show Answer
Correct Answer: B
Explanation:
A captive portal redirects users to a web page where they authenticate, typically over HTTPS, before being granted network access. WPA3 provides wireless encryption/authentication at the Wi-Fi layer, while SSO and SAML are identity technologies rather than guest Wi-Fi access control.

Question 45

Which of the following is the administrative distance for internal BGP routes?

A. 20
B. 110
C. 170
D. 200
Show Answer
Correct Answer: D
Explanation:
On Cisco routers, the default administrative distance for iBGP (internal BGP) routes is 200. By comparison, eBGP routes have an administrative distance of 20, OSPF is 110, and EIGRP external routes are 170.

Question 46

Which of the following cloud platform technology characteristics would a quantum computing host most likely prioritize?

A. Scalability
B. Elasticity
C. Multitenancy
D. Cost
Show Answer
Correct Answer: A
Explanation:
A quantum computing host would most likely prioritize scalability because quantum workloads and supporting infrastructure are expected to grow substantially as hardware capabilities and demand increase. Elasticity is more associated with dynamically provisioning conventional cloud resources, multitenancy is often limited due to specialized hardware, and cost is generally not the primary defining technology characteristic.

Question 47

A network administrator notices unusual traffic patterns on the network and suspects malicious activity. The administrator identifies the source IP. Along with running arp, which of the following commands should the administrator use to locate the source device on the network?

A. show mac-address-table
B. ping
C. show interface
D. show vlan
E. traceroute
Show Answer
Correct Answer: A
Explanation:
After identifying the source IP and checking the ARP table to map the IP address to a MAC address, the administrator should use the switch command 'show mac-address-table' to determine which switch port has learned that MAC address. This locates the connected source device on the network. The other commands do not directly map a host's MAC address to a switch port.

Question 48

Users on the network are experiencing slow throughput. A technician wants to increase throughput without changing any switch hardware. Which of the following solutions should the technician implement?

A. SVI configuration
B. VLAN trunking
C. 802.1Q tagging
D. Link aggregation
Show Answer
Correct Answer: D
Explanation:
Link aggregation (EtherChannel/LACP) combines multiple physical links into a single logical link, increasing available bandwidth and throughput without replacing switch hardware. SVI configuration enables Layer 3 interfaces, while VLAN trunking and 802.1Q tagging carry multiple VLANs over a link but do not increase throughput by themselves.

Question 49

A technician is plugging an Ethernet cable into a switch to bring a new device online, but the device is not showing an active network connection. Previously, another technician turned off unused switchports as part of device hardening. Which of the following describes the port status?

A. Error disabled
B. Idle
C. Suspended
D. Administratively down
Show Answer
Correct Answer: D
Explanation:
A switchport that has been manually shut down as part of device hardening is in an administratively down state. An error-disabled port is automatically disabled due to a security or protocol violation, not because an administrator intentionally shut it down. 'Idle' is not the normal Cisco switchport administrative state, and 'Suspended' is associated with specific features such as EtherChannel or VLAN conditions rather than a manually disabled port. Sources: https://www.cisco.com/c/en/us/support/docs/switches/catalyst-6500-series-switches/12027-53.html

Question 50

A systems administrator is hardening IoT devices. Threat modeling suggests that the devices are most likely to be targeted by low-level attackers. Which of the following is the highest priority task?

A. Deploying the devices in a screened subnet
B. Setting up URL filtering
C. Changing default passwords
D. Implementing port security
Show Answer
Correct Answer: C
Explanation:
Changing default passwords is the highest-priority hardening step for IoT devices because default credentials are one of the most common attack vectors, especially for low-skill attackers who rely on known vendor defaults. The other options can improve security but do not address this fundamental and frequently exploited weakness.

$19

Get all 580 questions with detailed answers and explanations

  • Instant download HTML + PDF delivered the moment payment clears.
  • Secure Stripe checkout we never see or store your card details.
  • 7-day refund if files are defective see our refund policy.