An end-user at an Internet cafe tries to visit an online retailer\\’s website; however, the website for a competitor loads.
The user checks the URL in the address bar and verifies it is correct, but the competitor\\’s page still loads. Which of the
following BEST describes what is occurring?
A. Cross-site scripting
B. Session hijacking
C. Man in the middle
D. DNS poisoning
Correct Answer: D


A small company has decided to use a single virtual appliance to filter spam as well as a reverse proxy and filter traffic to
its internal webserver. Which of the following has the company MOST likely deployed?
B. Firewall
E. Content filter
Correct Answer: E


A network technician has recently installed new VoIP phones at all employees\\’ desks to support a new SIP cloud
solution. However, the technician is unable to make a call from the device after testing. Which of the following should
the technician verify?
A. TCP 433 is allowed.
B. UDP 1720 is allowed.
C. UDP 50860 is allowed.
D. UDP 5061 is allowed.
E. TCP 8080 is allowed.
F. TCP 8181 is allowed.
Correct Answer: CD


A technician needs to manage a Linux-based system from the GUI remotely. Which of the technician should the
Does the technician deploy?
D. Telnet
Correct Answer: B


Which of the following BEST describes the BGP routing protocol?
A. distance vector
B. hybrid
C. static
D. link-state
Correct Answer: B


A contractor is setting up and configuring conference rooms for a convention. The contractor sets up each room in the
conference center to allow wired Internet access going to individual tables. The contractor measured the distance
between the hotel\\’s patch panel to the jack, and the distance is within Cat 5e specifications. The contractor is
concerned that the room will be out of specification if cables are run in each room from the wall jacks. Which of the
following actions should the contractor take to ensure the cable runs meet specifications and the network functions
A. Place a switch at the hotel\\’s patch panel for connecting each room\\’s cables
B. Place a switch on each table to ensure strong connectivity
C. Place repeaters between the patch panel and the rooms
D. place a switch at the wall jack and run the cables in the room from there
Correct Answer: D

While troubleshooting a connectivity issue, a network technician successfully pinged the loopback address and external
DNS server tut was unable to ping the website\\’s URL Which of the following tools should the technician use to
determine where the network issue is located?
A. Nmap
B. netstat
C. nslookup
D. ipconftg
E. tracert
Correct Answer: E


A network administrator wishes to ensure there are no unnecessary open communication paths into a server. Using a
port scanner, the administrator finds that ports are reported as closed. Which of the following BEST explains this
A. The ports belong to an active system and are denying requests
B. The ports are associated with deprecated services
C. The ports do not belong to a live system
D. The ports replied with an SYN/ACK response
Correct Answer: B


A network technician has established an internal HTTP connection from a browser to the webserver to access an
organization\\’s intranet services in which of the following layers of the OSI model is the HTTP protocol found?
A. Session
B. Datalink
C. Network
D. Application
Correct Answer: A

A network administrator has created a new VLAN for the server and clients within the accounting department and wants
to outline how it integrates with the existing network. Which of the following should the administrator create?
A. Logical diagram
B. Physical diagram
C. Rack diagram
D. Configuration diagram
Correct Answer: A


A company runs Linux servers in its own data center and also on a popular public cloud service provider. The servers
hosted by the cloud provider can only be accessed with proper authorization and are only accessed by the company\\’s
datacenter. Which of the following BEST describes the type of cloud architecture being used? (Choose two.)
A. Private
B. Hybrid
C. Public
D. IaaS
E. PaaS
F. SaaS
Correct Answer: BD

An organization recently installed a firewall on the network. Employees must be able to send and receive email from a
POP3 server. In which of the following ways should the firewall be configured? (Select TWO).
A. Allow TCP port 23
B. Allow TCP port 25
C. Allow TCP port 110
D. Allow UDP port 25
E. Allow UDP port 110
Correct Answer: BC

Keeping an authoritative and timely record of network devices and their settings is a key activity of which of the
A. Project management
B. Quality of service
C. Configuration management
D. Bandwidth shaping
Correct Answer: C

Lisa, a technician, has configured a new switch that is remotely accessed using SSH. The switch is working properly but
cannot be accessed remotely. Which of the following items is MOST likely missing in the configuration?
A. Port speed
B. Cryptokey
C. Data VLAN
Correct Answer: B

A network engineer is configuring wireless access for guests at an organization. Access to other areas in the
organization should not be accessible to guests. Which of the following represents the MOST secure method to
configure guest access to the wireless network?
A. Guests should log into a separate wireless network using a captive portal
B. Guests should log into the current wireless network using credentials obtained upon entering the facility
C. The existing wireless network should be configured to allow guest access
D. An additional wireless network should be configured to allow guest access
Correct Answer: A

Which of the following network topologies typically has all devices on a network directly connected to every other
network device?
A. Mesh
B. Star
C. Ad hoc
D. Ring
Correct Answer: A

Which of the following BEST describes how a layer 2 switch functions?
A. Switches packets within the same subnet based on MAC addresses
B. Switches packets between different subnets based on IP addresses
C. Switches packets between different subnets based on MAC addresses
D. Switches packets between different subnets based on MAC addresses
Correct Answer: A

A network technician is trying to terminate CAT5 modular jacks. Which of the following tools would be MOST
appropriate for this scenario?
A. Crimper
C. Throughput tester
D. Punch down tool
Correct Answer: D

Jeff, an administrator, has just finished installing a new switch and connected two servers with IPs of
and .30. The servers are able to communicate with each other, but are unable to reach the Internet. Jeff sees the
following information in the switch configuration: interface VLAN 105 IP address Jeff is
able to ping the router at from the switch.
Which of the following is the MOST likely cause of the problem?
A. The subnet mask is incorrect.
B. A routing loop has occurred.
C. Jeff used a crossover cable to connect the switch to the gateway.
D. The server is missing default-gateway information.
Correct Answer: D

A supervisor requests that a technician downloads a MIB for a particular server. Which of the following protocols
requires MIBs?
A. IPSec
Correct Answer: D

A second router was installed on a network to be used as a backup for the primary router that works as a gateway. The
infrastructure team does not want to change the IP address of the gateway on the devices. Which of the following
network components should be used in this scenario?
A. Loopback IP
B. Virtual IP
C. Reserved IP
D. Public
Correct Answer: B

Management has requested that a wireless solution be installed at a new office. Which of the following is the FIRST
thing the network technician should do?
A. Order equipment
B. Create network diagrams
C. Perform a site survey
D. Create an SSID.
Correct Answer: C

Which of the following network topologies allows only communication to take place from one node at a time by passing
a token around the network?
A. Star
B. Mesh
C. Bus
D. Ring
Correct Answer: D

Privilege creep among long-term employees can be mitigated by which of the following procedures?
A. User permission reviews
B. Mandatory vacations
C. Separation of duties
D. Job function rotation
Correct Answer: A

Which of the following ports would Zach, a technician, need to open on a firewall to allow SSH on the default port?
A. 20
B. 21
C. 22
D. 23
Correct Answer: C

A technician needs to connect two routers using copper cables. Which of the following cables would utilize both the
TIA/EIA 568a and TIA/EIA 568b standards?
A. Cat5 crossover
B. Cat5e straight-through
C. Cat5e rollover
D. Cat6 console
E. Cat6a straight-through
Correct Answer: A

