Limited-Time Offer: Enjoy 50% Savings! Ends in 00h 00m 00s Coupon code: 50OFF
Skip to content

Free CompTIA Network+ Certification N10-009 Exam Questions

Page: 1 / 40 Total 600 questions

Want more questions? Get Premium Access.

Question 1

Which of the following is an example of a split-tunnel VPN?

Correct Answer: A. Only public resources are accessed through the user's internet connection.
Explanation:

In a split-tunnel VPN, only corporate traffic is sent through the VPN tunnel, while public internet traffic goes directly through the user's local ISP. This reduces bandwidth use on the corporate VPN concentrator and improves performance for non-work traffic.

B . Separate tunnels for encrypted traffic describes multi-tunnel VPNs, not split tunneling.

C . All traffic routed through on-site servers is a full-tunnel VPN, not split-tunnel.

D . ACLs balancing traffic relates to routing or load balancing, not VPN split tunneling.

Reference (CompTIA Network+ N10-009):

Domain: Networking Concepts --- VPN types, split vs. full tunnel, remote access.


Question 2

Which of the following recovery strategies should a company implement to ensure data center services are quickly restored and accessible after a disaster occurs?

Correct Answer: B. Active-passive approach
Explanation:

The correct answer is B. Active-passive approach. CompTIA Network+ N10-009 includes high availability and disaster recovery concepts such as failover, redundancy, and recovery strategies. An active-passive approach uses a primary production system, site, or service that actively handles traffic, while a secondary standby environment remains ready to take over if the primary environment fails. This design helps ensure data center services can be restored and made accessible quickly after a disaster because the standby environment is already planned and prepared for failover.

Backup and replication software is important for data protection, but backups alone do not guarantee that services will be quickly available. Restoring systems from backups may require significant time. Cloud computing can support disaster recovery, but it is a broad deployment model rather than a specific recovery strategy. Remote manual failover can restore services, but manual failover usually takes longer and increases the chance of administrative delay or error.

Because the question emphasizes quickly restored and accessible services after a disaster, an active-passive approach is the most appropriate option. It provides a standby recovery environment designed to assume operations when the active data center service becomes unavailable.


Question 3

A network administrator must implement a feature that supports redundancy and scaling on the switches at the distribution layer of the network. Which of the following is the best option?

Correct Answer: B. Spanning tree
Explanation:

The correct answer is B. Spanning tree. At the distribution layer, switch redundancy is common because multiple paths are usually built into the design to avoid a single point of failure. The problem with redundant Layer 2 paths is that they can create switching loops, broadcast storms, and unstable MAC address tables if nothing controls them. Spanning Tree Protocol solves that problem by logically blocking one or more redundant paths while still keeping those paths available as backups.

That makes spanning tree the best fit for a feature that supports both redundancy and safe scaling. As the switched environment grows, STP helps maintain a stable topology and prevents loop-related failures. If the active path fails, a blocked redundant path can be brought into service.

The other options do not address the real need. VLAN assignment is used to segment broadcast domains, but it does not manage redundant Layer 2 paths. Port speed only affects throughput on an interface. Full duplex improves communication efficiency on a link, but it also does not provide redundancy control or loop prevention.

When a Network+ question mentions redundancy on switches and asks for the best switching feature, spanning tree is the strongest answer.


Question 4

A medical clinic recently configured a guest wireless network on the existing router. Since then, guests have been changing the music on the speaker system. Which of the following actions should the clinic take to prevent unauthorized access? (Select two).

Correct Answer: A. Isolate smart devices to their own network segment.; E. Change the default credentials.
Explanation:

*A. Isolate smart devices to their own network segment: Network segmentation using VLANs or separate SSIDs ensures that smart devices (like speakers) are not on the same network as guests, preventing unauthorized control.

*E. Change the default credentials: Many IoT devices (e.g., smart speakers) come with default usernames and passwords. If these are not changed, unauthorized users can easily take control.

*Why not the other options?

*B. Configure IPS: IPS (Intrusion Prevention System) detects threats but cannot block specific guest actions on an IoT device.

*C. Install a new AP: A new access point does not solve the unauthorized control issue.

*D. Set up a syslog server: Helps with logging, but does not prevent unauthorized access.

*F. Configure GRE: Generic Routing Encapsulation (GRE) is used for VPN tunneling, which is irrelevant in this case.


CompTIA Network+ (N10-009) Official Guide -- Chapter 11: Network Security

Question 5

A research facility is expecting to see an exponential increase in global network traffic in the near future. The offices are equipped with 2.5Gbps fiber connections from the ISP, but the facility is currently only utilizing 1Gbps connections. Which of the following would need to be configured in order to use the ISP's connection speed?

Correct Answer: D. Link aggregation
Explanation:

Understanding Link Aggregation:

Definition: Link aggregation combines multiple network connections into a single logical link to increase bandwidth and provide redundancy.

Usage in High-Bandwidth Scenarios:

Combining Links: By aggregating multiple 1Gbps connections, the facility can utilize the full 2.5Gbps bandwidth provided by the ISP.

Benefits: Enhanced throughput, load balancing, and redundancy, ensuring better utilization of available bandwidth.

Comparison with Other Options:

802.1Q Tagging: Used for VLAN tagging, which does not affect the physical bandwidth utilization.

Network Address Translation (NAT): Used for IP address translation, not related to link speed or bandwidth aggregation.

Port Duplex: Refers to the mode of communication (full or half duplex) on a port, not the aggregation of bandwidth.

Implementation:

Configure link aggregation (often referred to as LACP - Link Aggregation Control Protocol) on network devices to combine multiple physical links into one logical link.


CompTIA Network+ study materials on network configuration and link aggregation.

Question 6

Which of the following is the step that a troubleshooter should take immediately after implementing a solution?

Correct Answer: C. Verify full system functionality.
Explanation:

After implementing the solution, the immediate next step is to verify full system functionality. This confirms that the problem has been resolved and helps ensure no new issues have been introduced.

From Andrew Ramdayal's guide:

''After the solution is implemented, test the system to ensure that it is fully operational, and the original problem has been resolved. Also, put in place any measures that could prevent the issue from recurring.''


Question 7

An administrator wants to find the top destination for traffic across the infrastructure on a specific day. Which of the following should the administrator use?

Correct Answer: C. NetFlow
Explanation:

NetFlow (and similar flow technologies like IPFIX/sFlow in concept) is used to collect traffic-flow metadata such as source/destination IPs, ports, protocols, interfaces, and byte/packet counts over time. In Network+ (N10-009) operations and monitoring objectives, flow data is ideal for identifying top talkers and top destinations across the network on a given day because it provides summarized, queryable information at scale without capturing every packet payload. An administrator can review reports to determine which destination IPs/hosts consumed the most bandwidth, which applications were most active, and what time ranges saw spikes---perfect for historical analysis.

SNMP is great for polling device counters (interface utilization, errors, CPU) but it does not natively tell you the ''top destination'' by conversation/flow without additional flow awareness. Packet capture can reveal exact conversations and payloads, but it is heavy, localized, and not efficient for infrastructure-wide daily top-destination reporting. traceroute maps the path to a destination and helps isolate routing/path issues; it does not provide usage statistics. Therefore, NetFlow is the best fit.


Question 8

A major natural disaster strikes a company's headquarters, causing significant destruction and data loss. The company needs to quickly recover and resume operations. Which of the following will a network administrator need to do first?

Correct Answer: A. Conduct a damage assessment
Explanation:

In disaster recovery, the first step after an incident is to conduct a thorough damage assessment to understand the extent of the damage and determine the next appropriate steps. This allows for informed decision-making during the recovery process. The document says:

''The first step after a disaster is to conduct a damage assessment. This involves evaluating the extent of damage to equipment, infrastructure, and data, forming the foundation for recovery efforts and prioritizing response actions.''


Question 9

A group of users cannot connect to network resources. The technician runs ipconfig from one user's device and is able to ping the gateway shown from the command. Which of the following is most likely preventing the users from accessing network resources?

Correct Answer: B. Rogue DHCP
Explanation:

A rogue DHCP server occurs when an unauthorized or misconfigured DHCP server assigns incorrect IP addresses, default gateways, or DNS settings to clients.

*In this scenario:

*The user can ping the gateway, meaning local network communication is working.

*However, they cannot access network resources, which suggests incorrect IP configuration (likely due to a rogue DHCP server assigning the wrong gateway or DNS).

*Why not the other options?

*VLAN hopping (A): This is an attack that exploits VLAN configurations to gain access to unauthorized VLANs. It would not typically cause multiple users to lose network access.

*Distributed DoS (C): A DDoS attack floods a network or service with traffic, but this issue is more likely misconfigured IP settings than an actual attack.

*Evil twin (D): This refers to a fraudulent Wi-Fi network mimicking a legitimate one. Since the users are on a wired network (ipconfig output checked), this is not applicable.


CompTIA Network+ (N10-009) Official Guide -- Chapter 11: Network Security Threats

Question 10

Which of the following does BGP use for loop avoidance?

Correct Answer: A. Autonomous system path
Explanation:

The correct answer is Autonomous system path because BGP (Border Gateway Protocol) prevents routing loops by using the AS_PATH attribute. According to CompTIA Network+ (N10-009) objectives under routing protocols, BGP is a path vector protocol used to exchange routing information between autonomous systems (AS) on the internet.

When a BGP router advertises a route, it includes its autonomous system number (ASN) in the AS_PATH attribute. As the route passes through additional autonomous systems, each AS appends its own ASN to the path. If a BGP router receives a route advertisement that already contains its own ASN in the AS_PATH list, it recognizes this as a loop and rejects the route. This mechanism effectively prevents routing loops across large-scale networks such as the internet.

Option B (Peer autonomous system) refers to neighboring BGP routers but does not describe the loop prevention mechanism. Option C (Autonomous system length) relates to path selection metrics, as shorter AS_PATH lengths are generally preferred, but this is not the loop avoidance function itself. Option D (Public autonomous system) is not a loop prevention mechanism.

Therefore, BGP uses the AS_PATH attribute for loop avoidance.


Question 11

A wireless technician wants to implement a technology that will allow user devices to automatically navigate to the best available frequency standard. Which of the following technologies should the technician use?

Correct Answer: A. Band steering
Explanation:

Band Steering: This technology enables wireless devices to connect to the most optimal frequency band (2.4 GHz or 5 GHz) by encouraging capable devices to switch to the less congested 5 GHz band. This improves overall network performance and prevents overcrowding on the 2.4 GHz band.

Wireless LAN controller (B): This manages multiple access points in a network but does not handle frequency optimization.

Directional antenna (C): This focuses the signal in a specific direction but does not affect frequency selection.

Autonomous access point (D): This operates independently but lacks advanced features like band steering.


Question 12

A network engineer needs to order cabling to connect two buildings within the same city. Which of the following media types should the network engineer use?

Correct Answer: C. Single-mode fiber
Explanation:

Single-mode fiber is best suited for long-distance communication, often exceeding 10 km (6.2 miles). It's immune to EMI and offers high bandwidth --- making it the ideal choice for connecting buildings across a city.

Coaxial (A) and Twinaxial (B) are used for shorter distances and specific use cases (e.g., storage or legacy systems).

Cat 5 (D) is limited to 100 meters and is not suitable for city-level interconnects.

For long-distance, high-speed, and reliable communication between buildings, Single-mode fiber is the professional choice.


Question 13

A user is unable to navigate to a website because the provided URL is not resolving to the correct IP address. Other users are able to navigate to the intended website without issue. Which of the following is most likely causing this issue?

Correct Answer: A. Hosts file
Explanation:

Role of the Hosts File:

The hosts file is a local file on a computer that maps hostnames to IP addresses. It can be used to override DNS resolution by providing a static mapping of a hostname to an IP address.

Common Issues with the Hosts File:

If an incorrect IP address is mapped to a hostname in the hosts file, it can cause the computer to resolve the hostname to the wrong IP address. This can lead to navigation issues for specific websites while other users, relying on DNS, do not face the same problem.

Why Other Options are Less Likely:

Self-signed certificate: Relates to SSL/TLS and would cause a security warning, not a navigation failure.

Nameserver record: Affects all users, not just one.

IP helper: Used to forward DHCP requests and is unrelated to DNS resolution issues.

Troubleshooting Steps:

Check the hosts file on the affected user's computer (C:\Windows\System32\drivers\etc\hosts on Windows or /etc/hosts on Unix/Linux).

Look for entries that map the problematic hostname to an incorrect IP address and correct or remove them.


CompTIA Network+ study materials and system administration documentation.

Question 14

Which of the following attacks forces a switch to send all traffic out of all ports?

Correct Answer: C. MAC flooding
Explanation:

MAC flooding overwhelms a switch's CAM (Content Addressable Memory) table by sending a flood of frames with spoofed MAC addresses. Once the CAM table overflows, the switch cannot learn legitimate MAC addresses and defaults to flooding all frames out all ports, effectively turning it into a hub. This allows an attacker to capture traffic not originally destined for their port.

A . ARP poisoning corrupts ARP tables to redirect traffic but does not overflow the CAM table.

B . Evil twin is a wireless rogue AP attack, unrelated to switch behavior.

D . DNS spoofing redirects domain queries, not Layer 2 switching.

Reference (CompTIA Network+ N10-009):

Domain: Network Security --- Switch security, CAM table attacks, MAC flooding.


Question 15

An administrator is setting up an SNMP server for use in the enterprise network and needs to create device IDs within a MIB. Which of the following describes the function of a MIB?

Correct Answer: C. Definition file for event translation
Explanation:

MIB (Management Information Base): A MIB is a database used for managing the entities in a communication network. The MIB is used by Simple Network Management Protocol (SNMP) to translate events into a readable format, enabling network administrators to manage and monitor network devices effectively.

Function of MIB: MIBs contain definitions and information about all objects that can be managed on a network using SNMP. These objects are defined using a hierarchical namespace containing object identifiers (OIDs).

CompTIA Network+ materials discussing SNMP and MIB functionality.