Comptia

N10-009 Free Practice Questions — Page 7

Question 61

A company experienced a breach and wants to implement preventive measures. The network administrator is looking for a tool that can collect, analyze, and quickly correlate known attacks. Which of the following software tools can accomplish this task?

A. Syslog collector
B. SIEM
C. Packet capture
D. SNMP traps
Show Answer
Correct Answer: B
Explanation:
A Security Information and Event Management (SIEM) system collects logs and security events from multiple sources, analyzes them, and correlates events to identify known attack patterns and suspicious activity. A syslog collector primarily aggregates logs without advanced correlation, packet capture records network traffic for analysis, and SNMP traps report device events rather than correlating security attacks.

Question 62

Which of the following ports is commonly used for DHCPDISCOVER call requests for a new machine on a network?

A. 53
B. 68
C. 69
D. 80
Show Answer
Correct Answer: B
Explanation:
DHCP clients use UDP source port 68 and send DHCPDISCOVER messages to UDP destination port 67. Among the given options, port 68 is the DHCP client port associated with the initial DHCPDISCOVER process.

Question 63

A company is implementing a solution for users to gain access to a critical application. The solution will verity that the machine meets requirements and that the users have access to the application. Which of the following does this solution describe?

A. Policy-based authentication
B. Username and password
C. Application awareness
D. Single sign-on
Show Answer
Correct Answer: A
Explanation:
Policy-based authentication evaluates contextual factors such as device compliance (whether the machine meets security requirements) and user authorization before granting access to an application. Username/password only verifies credentials, application awareness refers to recognizing application traffic rather than access decisions, and single sign-on reduces repeated logins but does not inherently validate device compliance.

Question 64

A company's servers experience a malware attack, which causes a network outage. The source of the attack is traced back to an employee s infected laptop. Which of the following solutions should a network technician implement to mitigate this attack?

A. IPS
B. NAC
C. MFA
D. SSL
Show Answer
Correct Answer: B
Explanation:
Network Access Control (NAC) helps prevent infected or noncompliant endpoints from accessing the network by enforcing security policies such as health checks before granting network access. This directly mitigates malware spreading from an employee's infected laptop. An IPS can detect and block some malicious traffic but does not control endpoint admission. MFA protects authentication, and SSL encrypts communications but neither prevents an infected device from joining the network.

Question 65

Users are reporting issues with mobile phone connectivity after a cellular repeater was recently installed. Users also note that the phones are rapidly losing battery charge. Which of the following should the technician check first to troubleshoot the issue?

A. WPS configuration
B. Signal strength
C. Channel frequency
D. Power budget
Show Answer
Correct Answer: B
Explanation:
Rapid battery drain after installation of a cellular repeater commonly indicates the phone is struggling with weak or unstable cellular coverage, causing it to increase transmit power while searching for or maintaining a connection. The first troubleshooting step is to verify signal strength to ensure the repeater is providing adequate coverage. WPS is unrelated to cellular repeaters, channel frequency is not the primary initial check for this symptom, and power budget is more relevant to network infrastructure design than handset connectivity troubleshooting.

Question 66

A global company has acquired a local company. The companies are geographically separate. The fully utilized IP address ranges for the two companies are as follows: • Global company: 10.0.0.0/16 • Local company: 10.0.0.0/24 Which of the following can the network engineer do to quickly connect the two companies and minimize user disruption?

A. Assign static routing to advertise the local company's network.
B. Assign an overlapping IP address range to both companies.
C. Assign a new IP address range to the local company.
D. Assign a NAT range to the local company.
Show Answer
Correct Answer: D
Explanation:
The two companies have overlapping private address space because the local company's 10.0.0.0/24 is contained within the global company's 10.0.0.0/16. Static routing cannot resolve overlapping networks, and assigning the same overlapping range is invalid. Readdressing the local company is the long-term fix but is not the quickest or least disruptive approach. Using NAT at the interconnection translates the local company's addresses into a unique range for communication, allowing the networks to be connected quickly with minimal user disruption.

Question 67

Developers want to create a mobile application that requires a runtime environment, developer tools, and databases. The developers will not be responsible for security patches and updates. Which of the following models meets these requirements?

A. Container as a service
B. Infrastructure as a service
C. Platform as a service
D. Software as a service
Show Answer
Correct Answer: C
Explanation:
Platform as a Service (PaaS) provides the runtime environment, development tools, and managed databases while the cloud provider is responsible for maintaining the underlying platform, including security patches and updates. IaaS leaves OS and platform maintenance to the customer, SaaS is for consuming finished applications, and CaaS focuses on container orchestration rather than providing a full managed development platform.

Question 68

A network administrator is establishing Layer 3 connectivity between Layer 2 segments. Which of the following does the administrator need to complete this task?

A. VIP
B. NAT
C. SVI
D. 802.1Q tagging
Show Answer
Correct Answer: C
Explanation:
A Switch Virtual Interface (SVI) provides a Layer 3 interface on a multilayer switch, enabling routing between Layer 2 VLANs/segments. A VIP is a virtual IP used for redundancy/load balancing, NAT translates addresses, and 802.1Q tagging identifies VLAN traffic on trunk links but does not provide Layer 3 routing.

Question 69

Employees report that website requests are being redirected to other websites that display different content than expected. Which of the following attacks is most likely causing this issue?

A. MAC flooding
B. ARP spoofing
C. DNS poisoning
D. VLAN hopping
Show Answer
Correct Answer: C
Explanation:
DNS poisoning (DNS cache poisoning) redirects users to incorrect IP addresses for legitimate domain names, causing website requests to be sent to different websites with unexpected content. MAC flooding affects switch CAM tables, ARP spoofing redirects local traffic via a malicious host, and VLAN hopping targets VLAN isolation rather than causing domain-name-based website redirection.

Question 70

Which of the following is the best reason to create a golden configuration?

A. To provide configuration consistency
B. To decrease the size of configuration files
C. To increase security by encrypting configurations
D. To set up backup configurations for each device
Show Answer
Correct Answer: A
Explanation:
A golden configuration is a standardized, validated baseline configuration used across devices to ensure consistency, simplify deployment, reduce configuration drift, and ease management. It is not primarily intended to shrink configuration files, encrypt configurations, or serve as a backup configuration.

$19

Get all 580 questions with detailed answers and explanations

  • Instant download HTML + PDF delivered the moment payment clears.
  • Secure Stripe checkout we never see or store your card details.
  • 7-day refund if files are defective see our refund policy.