CompTIA CloudNetX Free Sample Questions

Create a free account to browse all 20 sample questions. The full practice test includes 280 questions. Use the simulator for timed and flashcard mode.

Try Simulator

CNX-001 Sample Questions

  1. Question 1

    Q1

    A financial services company is migrating its on-premises data center to a hybrid cloud model, leveraging a 10 Gbps dedicated connection to a public cloud provider. During performance testing of a latency-sensitive trading application, network architects observe intermittent packet loss and degraded performance, specifically with large data transfers. Initial analysis with ping shows no packet loss for standard-sized packets, but issues arise with larger payloads. Which of the following is the MOST likely cause of this issue?

    Show answer & explanation

    Correct answer: C

    The scenario describes a classic Path MTU Discovery (PMTUD) black hole. Standard pings work because they use small packets. Large data transfers require fragmentation if the packet size exceeds the MTU of any link in the path. PMTUD relies on ICMP 'Destination Unreachable; Fragmentation Needed' (Type 3, Code 4) messages to discover the correct MTU. If a firewall blocks these messages, the sending host never learns it needs to reduce its packet size, leading to dropped packets (a 'black hole') for large transfers.

  2. Question 2

    Q2

    An enterprise is designing a new data center network fabric to support high-performance computing (HPC) and east-west traffic patterns from containerized microservices. The primary requirements are low latency, predictable performance, and non-blocking throughput. Which network topology should the architect select to BEST meet these requirements?

    Show answer & explanation

    Correct answer: B

    A spine-and-leaf topology is specifically designed for modern data centers with heavy east-west (server-to-server) traffic. Every leaf switch connects to every spine switch, ensuring that any two servers are at most two hops away from each other. This creates a low-latency, non-blocking fabric with predictable performance, making it ideal for HPC and microservices.

  3. Question 3

    Q3Multiple answers

    A global retailer is implementing a Secure Access Service Edge (SASE) architecture to provide unified security and networking for its remote workforce and branch offices. A network security architect needs to ensure that security policies are enforced consistently, regardless of user location or the application being accessed. Which TWO of the following are core functional components of a SASE solution that achieve this? (Select TWO).

    Show answer & explanation

    Correct answers: B, D

    SASE converges networking and security into a single, cloud-delivered service. A core part of this is a cloud-native security stack that includes Firewall as a Service (FWaaS), Secure Web Gateway (SWG), and Cloud Access Security Broker (CASB) to enforce policies consistently.

    The SASE architecture relies on a network of globally distributed PoPs. User traffic is directed to the nearest PoP, where security policies are applied before traffic is routed to its destination. This global backbone is essential for low-latency performance and consistent policy enforcement.

  4. Question 4

    Q4

    A DevOps team is using Terraform to manage a multi-cloud network infrastructure. They have defined resources for both AWS and Azure in their configuration files. A junior engineer on the team runs terraform apply and receives an error related to provider authentication for Azure, even though the AWS resources were provisioned successfully. What is the MOST likely reason for this failure?

    Show answer & explanation

    Correct answer: B

    Terraform uses provider-specific authentication methods. For AWS, it might be using environment variables or an IAM role. For Azure, it often relies on credentials configured in the Azure CLI or specific environment variables (like ARM_CLIENT_ID, etc.). An authentication error for one provider while another succeeds points directly to a misconfiguration of credentials for the failing provider in the execution environment.

  5. Question 5

    Q5

    True or False: In a Zero Trust architecture, once a user has successfully authenticated with multi-factor authentication (MFA) and their device posture has been verified, they are granted implicit trust and broad access to all network resources within their assigned security zone for the duration of their session.

    Show answer & explanation

    Correct answer: B

    This statement is false. A core principle of Zero Trust is 'never trust, always verify.' Access is granted on a per-session, per-application basis, and trust is never implicit. Even after initial authentication and verification, access is continuously re-evaluated based on context, such as user behavior, device health, and the sensitivity of the resource being accessed. Broad access is antithetical to the principle of least privilege inherent in Zero Trust.

  6. Question 6

    Q6

    A healthcare organization is deploying a new critical patient records application in a public cloud VPC. To comply with HIPAA, all traffic between the application servers and the database servers must be isolated from other workloads and inspected for threats. The application tier consists of an auto-scaling group of virtual machines. What is the MOST effective way to enforce this security requirement?

    Show answer & explanation

    Correct answer: C

    Microsegmentation provides the most granular and effective control for this scenario. An agent-based solution can enforce policies based on workload identity (e.g., tags, labels) rather than brittle IP addresses, which is crucial in an auto-scaling environment where IPs are dynamic. This allows for strict isolation and inspection of east-west traffic between the application and database tiers, regardless of their location or IP address, fulfilling the HIPAA compliance requirement.

  7. Question 7

    Q7

    A network architect is designing a global load balancing solution for a web application hosted in three different cloud regions: US-East, EU-West, and AP-Southeast. The goal is to provide the lowest latency for users worldwide and ensure automatic failover if an entire region becomes unavailable. Which DNS-based load balancing policy should be implemented to achieve these goals?

    Show answer & explanation

    Correct answer: C

    A Geolocation routing policy directs users to the endpoint in the region geographically closest to them, minimizing latency. Combining this with a failover policy (often configured via health checks) ensures that if the primary region for a user becomes unhealthy, their DNS queries will be automatically resolved to the next-closest healthy region. This combination directly addresses both the low-latency and high-availability requirements.

  8. Question 8

    Q8

    A company has established a hybrid cloud connection using AWS Direct Connect. They are using BGP to advertise routes between their on-premises network and their AWS VPC. An administrator notices that traffic from the on-premises network to a specific subnet in the VPC is taking a suboptimal path through a backup VPN connection instead of the Direct Connect link. Which BGP attribute should be modified on the on-premises router to make the Direct Connect path more preferable?

    Show answer & explanation

    Correct answer: B

    Local Preference is a BGP attribute used to influence outbound traffic paths within a single Autonomous System (AS). By setting a higher Local Preference value for the routes received over the Direct Connect link, the on-premises router will prefer that path for egress traffic to AWS over the path learned via the backup VPN. AS Path Prepending is used to influence inbound traffic, not outbound.

  9. Question 9

    Q9

    A systems administrator is tasked with writing a Python script to automate the process of checking the status of hundreds of network devices. The script needs to run concurrently to be efficient. The primary task is to send an ICMP echo request to each device and wait for a reply. Which Python library would be the MOST suitable for handling these concurrent, I/O-bound operations?

    Show answer & explanation

    Correct answer: C

    The asyncio library is ideal for I/O-bound and high-level structured network code. Sending a network request and waiting for a reply is a classic I/O-bound task. asyncio uses a single-threaded, single-process cooperative multitasking model (event loop) that allows it to handle thousands of concurrent connections efficiently with less overhead than threading or multiprocessing, which are better suited for CPU-bound tasks.

  10. Question 10

    Q10

    A network engineer is configuring a new site-to-site IPsec VPN tunnel between a corporate headquarters and a new branch office. After configuring both endpoints, the engineer observes that the tunnel fails to establish. Log analysis on the headquarters' firewall shows the following message: Phase 1 IKE proposal mismatch. What is the MOST likely cause of this error?

    Show answer & explanation

    Correct answer: B

    The IKE Phase 1 process involves negotiating a set of security parameters (a security association or SA) between the VPN peers. These parameters include the encryption algorithm (e.g., AES-256), hashing algorithm (e.g., SHA-256), authentication method (e.g., pre-shared key), and Diffie-Hellman group. A 'proposal mismatch' error explicitly indicates that the set of these parameters sent by one peer is not acceptable to or does not match a configured policy on the other peer.

Register free to unlock 10 more sample questions

Create a free account to continue with the rest of the CNX-001 sample set.

Lifetime One

Own this practice test forever.

$79.99
$75.99
one-time
  • Full access to 280 questions
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • Brainy AI Assistant
  • Lifetime updates

Two

Any 2 exams per month.

$20.00/exam
$39.99
/month
  • 2 active exam slots
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • 1,000 Brainy AI Credits
  • Cancel anytime

Premium Twelve

Any 12 exams over 3 months.

$15.00/exam
$179.99
/3 months
  • 4 active exam slots
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • 15,000 Brainy AI Credits
  • Dedicated support
  • Friend seat included — full access

Trusted by professionals at

NvidiaSupabaseGitHubOpenAITursoClerkClaude AIAmazon