Network Plus Exam Flashcards
A UTM ( unified threat management ) is deployed on the external edge of the main corporate office. The office connects to the WAN port of the edge router. The edge router at the main office connects to the remote offices using GRE IPsec ( generic routing encapsulation & internet protocol security ) tunnels. A network administrator notices that a worm that was not detected by the UTM has spread from the remote sites into the corporate network. Which of the following steps would MOST likely correct the issue.
C. Enable stateful inspection on the UTM ( unified threat management )
A technician has racked a new access switch and has run multimode fiber to a new location. After installing an extended-range 10Gb SFP in the core switch, the technician installed a 10 Gb SFP in the access switch and connected the port to the new extension with a fiber jumper. However, the link does not display and the technician cannot see light emitting from the core switch, Which of the following solutions is MOST likely to resolve the problem
B. Replace the jumpers with single-mode fiber
A network technician has implemented ACL’s to limit access to cloud based storage. Which of the following security mechanisms has the technician enforced?
C. WAF ( web application firewall )
A network technician receives a call from a user in the accounting department stating that internet connectivity has been lost after receiving a new workstation. No other users in accounting are reporting similar issues. The network technician is able to ping the machine from the IT network. Which of the following is MOST likely the cause.
A. Incorrect default gateway
A firewall administrator is implementing a rule that directs HTTP traffic to an internal server listening on a non-standard socket. Which of the following types of rules is the administrator implementing?
B. PAT ( port address translation )
A technician is installing a new wireless badging system on a hospital network. The requirements of the badging system are for it to have its own SSID ( service set identifier ) and low power levels. The badging system has to cover 99.9% of the hospital. Which of the following is the BEST action to take to meet the system requirements ?
A. install additional WAP’s ( wireless access points)
A technician attempts to replace a switch with a new one of similar model from the same vendor. When the technician moves the fiber and SFP plug, the switch does not completely boot up. Considering that the config files are the same, which of the following is the most likely cause of the failure.
B. corrupt operating system
A company has hundreds of nodes on a single subnet and has decided to implement VLAN’s. Which of the following BEST describes the benefit of this approach?
A. It segments broadcast domains in the network infrastructure.
A company has completed construction of a new datacenter and the IT staff is now planning to relocate all server and network equipment from the old site to the new site. Which of the following should the IT staff reference to determine the location of the equipment being moved.
A. rack diagrams
Which of the following would allow a device to maintain the same IP address lease based on the physical address of the network card?
A. MAC ( media access control ) address reservation
A technician wants to prevent an unauthorized host from connecting to the network via Ethernet. Which of the following is a layer 2 access control the technician should implement ?
D. Port security
A network engineer is configuring wireless access for guest at an organization. Access to other areas in the organization should not be accessible to guests. Which of the following represents the MOST secure method to configure guest access to the wireless network.
A. Guests should log into a separate wireless network using a captive portal.
The server team has just installed an application across three different servers. They are asking that all requests to the application are spread evenly across all three servers. Which of the following should the network team implement to fulfill the request?
D. Load balancer.
A network technician is deploying mobile phones for a company sales staff, Salespeople frequently travel nationally and internationally to meet with clients and often have to roam or switch cellular providers. Which of the following standards is the BEST option to fit the requirements ?
A. GSM ( global system for mobile communication )
A network administrator has been given a network of 172.16.85.0/21 and wants to know the usable range of IP addresses on that subnet. Which of the following indicates the correct IP address range?
C. 172.16.80.1 -172.16.87.254
A network technician is troubleshooting wireless network issues in a crowded office complex and suspects there is interference from nearby wireless networks. Which of the following should the technician perform to discover possible interference?
A. site survey
A network technician is troubleshooting an issue and has established a theory of probable cause. Which of the following steps should the network technician take NEXT ?
A. Test the possible solution
A network technician has discovered a rogue access point under an empty cubicle desk. Which of the following should the technician perform to ensure another cannot be placed on the network?
B. enable DHCP ( dynamic host configuration protocol ) guard to detect rogue servers.
Which of the following provides the ability to deploy consistent access point configurations from a central location ?
A. wireless controller
A network technician is configuring a wireless network at a branch office. Users at this office work with large files and must be able to access their files on the server quickly. Which of the following 802.11 standards provides the MOST bandwidth?
B. ac
A network administrator configures a router with the following IP address information. Gigabit Ethernet 1 interface 10.10.01/24 and serial 0 interface 10.10.0253/30 Clients are connected to a switch on the gigabit Ethernet interface: the ISP is connected to the serial 0 interface. When the router configuration is complete and client devices are reconfigured all clients report that they are unable to connect to the internet. Which of the following is the MOST likely reason ?
C. the router was configured with an incorrect subnet mask.
A penetration tester has been tasked with reconnaissance to determine which ports are open on the network. Which of the following tasks should be done FIRST ? ( choose 2 )
A. network scan
C. tracert.
Users are reporting internet connectivity issues. The network administrator wants to determine if the issues are internal to the company network or if there is an issue with the ISP. Which of the following tools should be used to BEST determine where the outage is occurring?
A. traceroute
Which of the following security mechanisms dynamically assigns a layer 2 address and restricts traffic only to that layer 2 address.
A. sticky MAC ( media access control )
Which of the following is a vulnerable system to detect and log unauthorized access?
B. honeypot
According to the OSI model, at which of the following layers is data encapsulated into a packet.
B. layer 3 ( network layer )
Which of the following WAN technologies is MOST preferred when developing a VOIP system with 23 concurrent channels
C. T1
A junior network technician is setting up a new email server on the company network. Which of the following default port should the technician ensure is open on the firewall so the new email server can relay email?
B. port 25 ( simple mail transfer protocol )
Which of the following policies would Joe, a user, have to agree to when he brings his personal tablet to connect to the company guest internet.
C. BYOD
In a service provider network, a company has an existing IP address scheme. Company A’s network currently uses the following scheme. Subnet 1: 192.168.1.0/26 and subnet 2 192.168.1.65/26. Company B uses the following scheme: Subnet 1 192.168.1.50/28
The network admin cannot force the customer to update it’s IP scheme. Considering this, which of the following is the BEST way for the company to connect these networks ?
C. NAT ( network address translation )
A network engineer is designing a new network for a remote site. The remote site consists of ten desktop computers, ten VOIP phones and 2 network printers. In addition, 2 of the desktop computers at the remote site will be used by managers who should be on a separate network from the other eight computers. Which of the following represents the BEST configuration for the remote site.
A. 1 router connected to one 24 port switch configured with three VLANS: one for the managers computers and printer, one for the other computers and printer and one for the VOIP phones.
A network technician is troubleshooting an end-user connectivity problem. The network technician goes to the appropriate IDF ( intermediate distribution frame ) but is unable to identify the appropriate cable due to the poor labeling. Which of the following should the network technician use to help identify the appropriate cable?
A. tone generator
A network technician notices the site to site VPN and internet connection have not come back up at a branch office after a recent power outage. Which of the following is an out of band method the technician would MOST likely utilize to check the branch office’s router status?
A. use a modem to console into the router.
A network technician is considering opening ports on the firewall for an upcoming VOIP PBX implementation. Which of the following protocols is the technician MOST likely to consider? ( choose 3 )
A. SIP ( session initiation protocol )
B. H.323
F. RTP ( real time transport protocol )
A device operating at Layer 3 of the OSI model uses which of the following protocols to determine the path to a different network.
C. RIP ( routing information protocol )
A network administrator is setting up a web based application that needs to be continually accessible to the end user, Which of the following concepts would BEST ensure this requirement?
A. high availability
Which of the following devices should a network administrator configure on the outermost part of the network ?
D. firewall
A company finds that many desktops are being reported as missing or lost. Which of the following would BEST assist in recovering these devices ?
D. computer locks
A technician is connecting a router directly to a PC using the G1/0/1 interface. Without the use of auto-sensing ports, which of the following cables should be used.
D. crossover
A technician is diagnosing an issue with a new T1 connection. The router is configured, the cable is connected, but the T1 is down. To verify the configuration of the router, which of the following tools should the technician use?
A. Loopback adapter
A network technician receives a call from a user who is experiencing network connectivity issues. The network technician questions the user and learns the user brought in a personal wired router to use multiple computers and connect to the network. Which of the following has the user MOST likely introduced to the network?
A. Rogue DHCP ( dynamic host configuration protocol ) server
A technician is setting up a direct connection between 2 older PC’s so they can communicate but not be on the corporate network. The technician does not have access to a spare switch but does have spare Cat 6 cables, RJ-45 plugs and crimping tool. The technician cuts off one end of the cable. Which of the following should the technician do to make a crossover cable before crimping the new tool?
D. reverse the wires leading to pins 2 and 4
Which of the following is the number of broadcast domain that are created when using an unmanaged 12 port switch ?
B. 1
A network engineer wants to segment the network into multiple domains. Which of the following devices would allow for communication between the segments?
B. layer 3 switch
The chief information officer ( CIO ) has notices the corporate wireless signal is available in the parking lot. Management request that the wireless network be changed so it is no longer accessible in public areas, without affecting the availability inside the building. Which of the following should be changed on the network.
A. power levels
A network technician is assisting the security team with some traffic captures. The security team wants to capture all traffic on a single subnet between the router and the core switch. To do so, the team must ensure there is only a single collision and broadcast domain between the router and the switch from which they will collect traffic. Which of the following should the technician install to BEST meet the goal?
C. hub
Based on networks 10.8.16.0/22 and 10.8.31.0/21 which of the following is the BEST summarized CIDR ( classless inter domain routing )
A. 10.8.0.0/16
A technician discovers that multiple switches require a major update. Which of the following policies should be followed ?
A. change management policy
A technician is troubleshooting a point to point fiber-optic connection. The technician is at a remote site and has no connectivity to the main site. The technician confirms the switch and the send and receive light levels are within acceptable range. Both fiber SFP’s are confirmed as working. Which of the following should the technician use to reveal the location of the fault?
A. OTDR ( optical time domain reflectometer )
A CIO wants to move IT services to a cloud service offering. However the network admin still wants to be able to control some parts of the cloud services networking component. Which of the following should be leveraged to complete this task?
B. PaaS ( platform as a service )
Client PC’s are unable to receive addressing information from a newly configured interface on a router. Which of the following should be added to allow the clients to connect?
B. IP helper
When enabling jumbo frames on a network device, which of the following parameters is being adjusted?
C. MTU ( maximum transmission unit )
A technician logs onto a system using Telnet because SSH is unavailable. SSH is enabled on the target device and access is allowed from all subnets. The technician discovers a critical step was missed, Which of the following would allow SSH to function.
B. generate new keys
A network admin wants to ensure sensitive data is not exfiltrated from the system electronically. Which of the following should be implemented?
A. DLP ( data loss prevention )
An office network consists of one two-port router connected to a 12 port switch. A four port hub is also connected to the switch. On this particular network, which of the following is the number of collision domain that exist?
D. 14
A network technician wants to remotely and securely access the desktop of a Linux workstation. The desktop is running remote control software without encryption. Which of the following should the technician use to secure the connection ?
A. SSH in tunnel mode
Which of the following should current network performance be compared against to determine network anomalies ?
A. baseline
A network admin configures an email server to use secure protocols. When the upgrade is completed, which of the following ports on the firewall should be configured to allow for connectivity ? (choose 3)
E. TCP 587
F. TCP 993
G. TCP 995
After a server outage, a technician discovers that a physically damaged fiber cable appears to be the problem, After replacing the cable, the server will still not connect to the network. Upon inspecting the cable at the server end, the technician discovers light can be seen thru one of the fibers strands. Which of the following should the technician do FIRST to reconnect the server to the network.
A. reverse the fiber strands of the cable and reconnect them to the server.
The backup server connects to a NAS ( network attached storage) device using block-level storage over Ethernet. The performance is very low, however the network technician suspects the performance issues are network related. Which of the following should the technician do to improve performance ?
C. Enable jumbo frames on the NAS and server
A technician is trying to determine the IP address of a customer router. The customer has an IP address of 192.168.1.55/24. Which of the following is the address of the customers router ?
B. 192.168.1.0
A network technician is able to connect the switches between 2 offices, but the offices cannot communicate with each other, as each office uses a different IP addressing scheme. Which of the following devices needs to be installed between the switches to allow communication?
C. router
A network technician is working on a proposal for email migration from an on premises email system to a vendor hosted email in the cloud. The technician needs to explain to management what type of cloud model will be utilized with the cloud hosted email. Which of the following cloud models should the technician identify in the proposal ?
C. SaaS ( Software as a Service )
Which of the following is the correct port number for NTP ( network time protocol )
C. 123
A network technician is connecting 2 switches together, Which of the following protocols should the technician use to increase speed and fault tolerance
C. LACP ( Link aggregation control protocol )
A company has a web-based application that is used by many different departments. The company has experienced some overload of resources on the database server. The network admin implements a network device in between the servers and the database, Which of the following BEST describes the purpose of this device?
B. Load balancing and providing high availability
A technician is replacing a switch at a branch office and discovers the existing backbone cable does not fit in the new switch. The fiber patch panel has circular connections. The new switch has a transceiver that accepts a smaller square adapter of two strands. Which of the following patch cables would the technician need to complete the installation ?
C. LC ( lucent connector ) to ST ( straight tip )
A computer lab on a campus network was recently reconfigured using recycled network cables. One of the 24 computers in the lab is unable to connect to the network after the upgrade. A network technician successfully uses the cable in question to connect directly to another computer. Which of the following is MOST likely the issue with the cable?
A. the cable is a crossover cable.
Which of the following is a reason why a business may be hesitant to move sensitive data to a SaaS cloud service ?
B. loss of full control over data resources
Users have been experiencing slow network response times and management has asked the network tech to provide evidence of network improvement. After optimizing the network, which of the following would be required ?
C. performance baseline
A network technician has created a network that consists of a router, a firewall, a switch and several PC’s. Which of the following physical network topologies was created?
D. bus
A tech is setting up a branch office on a point to point connection, Which of the following IP network blocks is the MOST efficient use of IP address space for the router connections between the two sites.
C. /30
A tech is upgrading the firmware on an older KVM switch, The specifications call for a serial port to connect to the computer on one side and an Ethernet jack to connect to the switch on the other side, Which of the following connectors does the tech need for this cable? ( choose 2 )
B. DB-9
E. RJ-45
An end-user device requires a specific IP address every time it connects to the corporate network: however, corporate policy does not allow the use of static IP addresses. Which of the following will allow the request to be fulfilled without breaking the corporate policy?
D. DHCP ( dynamic host configuration protocol ) reservation
A tech is planning a remote access strategy to manage routers and switches on a dedicated management network, The management network is segregated from the production network and uses site to site VPN connections. Some of the equipment does not support encryption. Which of the following should the tech choose that the equipment would support?
A. telnet
Which of the following protocols do MOST MITM attacks utilize ?
A. ARP ( address resolution protocol )
An ISP tech gets a call from a business that just changed equipment but can no longer connect to the internet. The tech checks the ARP table on the ISP switch and there is no corresponding MAC address present. instead the entry is incomplete. Which of the following causes this condition ?
B. duplex/speed mismatch
A system admin has recently purchased and installed a large electronic signage screen for the company’s parking garage. The screens management software was installed on a server with a public IP address to allow remote management. The system admin is now troubleshooting an issue with the screen displaying unknown, random and inappropriate messages. Which of the following is MOST effective in resolving this issue?
A. Changing the management software’s default credentials
A tech is investigating a server performance issue, The tech has gathered the server utilization statistics. Which of the following should the technician use to determine which statistics are not on the normal range?
A. baseline review
Which of the following devices, if implemented would result in decreased administration time of an 802.11 network running centralized authentication services ? (choose 2 )
C. wireless controller
D. RADIUS ( remote authentication dial-in user server )
A tech must determine if a web page user’s visits are connecting to a suspicious website’s IP address in the background. Which of the following tools would provide the information on TCP connections ?
A. netstat
An administrator is moving to a new office. There will be several network runs through the ceiling area of the office. Which of the following is the BEST to utilize in these areas ?
D. plenum-rated cable
A network tech receives a spool of Cat 6a cable and is asked to build several cables for a new set of Ethernet runs between devices. Which of the following tools are MOST likely needed to complete the task. ( choose 3 )
A. wire stripper
B. cable crimper
D. RJ-45 connectors
As part of a transition from a static to a dynamic routing protocol on an organization’s internal network, the routing protocol must support IPv4 and VLSM ( variable length subnet mask ) . Based on those requirements, which of the following should the network admin use ? ( choose 2 )
A. OSPF ( open shortest path first )
B. IS-IS ( intermediate system to intermediate system )
A telecommunications provider has just deployed a new OC ( optical carrier ) -12 circuit at a customer site. While the circuit showed no errors from the provider end to the customer’s demarcation point, a network admin is trying to determine the cause of dropped packets and errors on the circuit. Which of the following should the network admin do to rule out any problems at layer 1? ( choose 2 )
A. use a loopback and router at the demark and check for a link light.
B. Use an OTDR ( optical time domain reflectometer ) to validate the cable integrity )
A single PRI ( primary rate interface ) can deliver multiple voice calls simultaneously using which of the following layer 1 technologies?
A. time division multiplexing
A network tech is diagnosing a time-out issue generated from an end user web browser. The web browser issues standard HTTP get and post commands to interact with the website. Given this information, the technician would like to analyze the entire TCP ( transfer control protocol ) handshake of the HTTP requests offline. Which of the following tools would allow the technician to view the handshake?
A. packet analyzer
A customer cannot access a company’s secure website. The company’s network security is reviewing the firewall for the server and finds the following output.
Time Action Src IP Src Port Dat IP Dst Port
0902 Allow 12.73.15.5 31865 10.5.0.10 80
1005 Deny 12.73.15.5 31866 10.5.0.10 443
1006 Deny 12.73.15.5 31890 10.5.0.10 443
Which of the following changes should be made to allow all customers to access the company’s website?
C. allow 10.5.0.10 443 any any
Which of the following MUST be implemented to share metrics between routing protocols within the same router ?
B. routing table
An engineer is reviewing the implementation requirements for and upcoming project. The basic requirements identified by the customer include the following :
WLAN architecture supporting speeds in excess of 150 Mbps.
Clientless remote network access.
Port based network access control.
Which of the following solution sets properly addresses all of the identified requirements?
E. 802.11n, SSL-VPN, 802.1x
Which of the following is used to classify network data for the purpose of providing QoS?
D. DSCP ( differential services code point )
A network tech needs to separate a web server listening on port 80 from the internal LAN and secure the server from the public internet. The web server should be accessible to the public internet over port 80 but not the private LAN. Currently, the network is segmented with a network-based firewall using the following IP addressing scheme on each interface.
Zone Interface IP address
Public eth0 10.0.0.1/24
DMZ eth1 10.0.1.1/24
Private eth2 10.0.2.1/24
Which of the following ones should the tech use to place the web server and which of the following firewalls rules should the technician configure?
B. place the web server in the DMZ with an inbound rule from eth0 interface to eth1 to accept traffic over port 80 designated to the web server .
A company recently upgraded all of its printers to networked multifunction devices. Users can print to the new devices, but they would also like the ability to scan and fax files from their computers. Which of the following should the technician update to allow this functionality?
C. printer firmware
A disgruntled employee executes a man in the middle attack on the company network. Layer 2 traffic destined for the gateway is redirected to the employee’s computer. This type of attack is an example of :
A. ARP cache poisoning
The process of attempting to exploit a weakness in a network being given permission by the company is known as?
A. penetration testing
A company has contracted with an outside vendor to perform a service that will provide hardware, software and procedures in case of a catastrophic failure of the primary datacenter. The CIO is concerned because this contract does not include a long term strategy for extended outages, Which of the following should the CIO complete?
B. business continuity plan
A typical cell tower will have microwave and cellular antennas. Which of the following network topologies do these represent ? ( choose 2 )
C. point to point
D. mesh
A network admin has a monitoring system in place that is currently polling hundreds of network devices at regular intervals. The continuous polling is causing high CPU utilization on the server. Which of the following tasks should the admin perform to resolve the CPU issue while maintaining full monitoring capabilities.
A. Remove SNMP (simple network management protocol ) polling and configure SNMP traps on each network device.
A contractor is setting up and configuring conference rooms for a convention. The contractor sets up each room in the conference center to allow wired internet access going to individual tables. The contractor measured the distance between the hotels patch panel to the jack and the distance is within Cat5e specifications. The contractor is concerned that the room will be out of specification if cables are run in each room from the wall jacks. Which of the following actions should the contractor take to ensure the cables runs meet specifications and the network functions properly?
A. Place a switch at the hotel’s patch panel for connecting each room’s cable.
Users are reporting their network is extremely slow. The tech discovers pings to external host have excessive response times. However, internal pings to printers and other PC’s have acceptable response times. Which of the following steps should the technician take NEXT?
A. determine if any network equipment was replaced recently
Which of the following is a system of notation that uses base 16 rather then base 10?
A. hex
A network admin would like to collect information from several networking devices using SNMP. Which of the following SNMP options should a network admin use to ensure the data transferred is confidential ?
A. authpriv ( authentication & privacy )
The IT manager at a small firm is in the process of renegotiating and SLA ( service level agreement ) with the organizations ISP. As part of the agreement, the organization will agree to a dynamic bandwidth plan to provide 150Mbps of bandwidth. However, if the ISP determines that a host on the organizations internal network produces malicious traffic, the ISP reserves the right to reduce available bandwidth to 1.5Mbps. Which of the following policies is being agreed to in the SLA?
C. Throttling
A network tech has just configured NAC ( network access control ) for connections using Cat 6 cables. However, none of the windows clients can connect to the network.
Which of the following components should the technician check on the windows workstations? ( choose 2 )
A. start the wired autoconfig service in the service console.
C. enable IEEE 802.1x authentication in network interface card properties
The security manager reports that individual systems involved in policy or security violations of incidents cannot be located quickly. The security manager notices the hostnames all appear to be randomly generated characters. Which of the following would BEST assist the security manager identifying systems involved in security incidents?
B. implement a standardized UNC ( universal naming convention )
A building is equipped with light sensors that turn off the fluorescent when natural light is above a certain brightness, Users report experiencing network connection issues only during certain hours. The west side of the building experiences connectivity issues in the morning hours and the east side near the end of the day. At night the connectivity issues affect the entire building. Which of the following could be the cause of the connectivity issues?
C. Network wiring is run perpendicular to electrical conduit
A network tech configures a firewall’s ACL to allow outgoing traffic for several popular services such as email and web browsing. However, after the firewall’s deployment, users are still unable to retrieve their emails. Which of the following would best resolve the issue?
B. allow the firewall to accept inbound traffic to ports 80,110,143 and 443
A network security tech observes multiple attempts to scan network hosts and devices. All the attempts originate from a single host on the network. Which of the following threats is MOST likely involved?
C. compromised system
Which of the following would be the MOST efficient subnet mask for a point to point link?
C. /31
An office user cannot access local network drives but has full access to the internet. A tech troubleshoots the issue and observes the following output of the ipconfig command:
Windows IP configuration
Ethernet LAN adapter : 980GTS Connection-specification DNS suffix ....comptia.net APv4 Address : .......10.0.5.99 Subnet Mask ........255.255.255.0 Default Gateway ......10.0.5.1
Wireless LAN adapter : Fastwifi 99 Connection - specific DNS suffix ....guestwireless.local IPv4 address.......172.16.0.5 Subnet mask.............255.255.255.0 Default Gateway ............172.16.0.254
Which of the following would most likely allow the network drives to be accesses?
B. disable the WLAN adapter