CompTIA Network+ Free Sample Questions

Create a free account to browse all 21 sample questions. The full practice test includes 313 questions. Use the simulator for timed and flashcard mode. Or, view 706 more questions in the alternate version N10-007 706 Questions.

Try Simulator

N10-009 Sample Questions

  1. Question 1

    Q1

    Which of the following steps of the troubleshooting methodology would most likely include checking through each level of the OSI model after the problem has been identified?

    Show answer & explanation

    Correct answer: A

  2. Question 2

    Q2

    While troubleshooting a VoIP handset connection, a technician's laptop is able to successfully connect to network resources using the same port. The technician needs to identify the port on the switch. Which of the following should the technician use to determine the switch and port?

    Show answer & explanation

    Correct answer: A

  3. Question 3

    Q3

    A network administrator needs to set up a file server to allow user access. The organization uses DHCP to assign IP addresses. Which of the following is the best solution for the administrator to set up?

    Show answer & explanation

    Correct answer: B

  4. Question 4

    Q4

    Which of the following technologies are X.509 certificates most commonly associated with?

    Show answer & explanation

    Correct answer: A

  5. Question 5

    Q5

    A financial services firm is migrating to a Zero Trust security model. A network engineer is tasked with implementing microsegmentation for a new application environment hosted in a virtualized data center. The application consists of a web tier, an application tier, and a database tier, each on its own subnet. The security policy dictates that the web tier should only accept traffic from the internet on port 443 and initiate connections to the application tier on port 8443. The application tier should only accept traffic from the web tier and initiate connections to the database tier on port 3306. Which technology would be MOST effective for enforcing these granular, east-west traffic policies between virtual machines?

    Show answer & explanation

    Correct answer: B

    A distributed firewall, often integrated directly into the hypervisor, is the most effective technology for enforcing granular east-west microsegmentation policies in a virtualized environment. This approach allows security policies to be applied at the virtual NIC (vNIC) of each virtual machine. It can inspect and filter traffic between VMs on the same host without the traffic ever leaving the hypervisor, providing highly granular control that is central to a Zero Trust model. Traditional VLANs with ACLs are less scalable and do not provide visibility into intra-host traffic. A perimeter firewall is ineffective for east-west traffic, and port security only operates at Layer 2, lacking the application-layer awareness needed to enforce policies based on ports like 8443 and 3306.

  6. Question 6

    Q6

    A company is deploying a new SD-WAN solution to connect its headquarters to 50 branch offices. The solution uses a centralized controller for policy management and two redundant data centers for traffic aggregation. For the overlay network, the administrator needs a routing protocol that is highly scalable, supports complex policy-based routing, and is an open standard to ensure compatibility with future hardware from different vendors. Which routing protocol should be used for the SD-WAN overlay?

    Show answer & explanation

    Correct answer: C

    BGP (Border Gateway Protocol) is the standard and most suitable routing protocol for large-scale SD-WAN overlays. It is an open standard (ensuring multi-vendor compatibility) and is designed for scalability and complex policy implementation, which are key requirements for managing traffic across many branch offices and data centers. BGP's path attributes allow for granular, policy-based routing decisions, making it ideal for the intelligent path selection capabilities of SD-WAN. While OSPF is an open standard, it is an IGP not designed for the policy-rich, large-scale nature of WAN overlays. EIGRP is historically Cisco-proprietary and less suited for multi-vendor policy enforcement. RIP is outdated and lacks the required scalability and features.

  7. Question 7

    Q7

    A network administrator is troubleshooting an issue where virtual machines in a data center cannot communicate with each other, despite being in the same Layer 2 segment (VLAN 100). The data center uses VxLAN to extend Layer 2 segments across the physical Layer 3 infrastructure. The administrator checks two VMs on different physical hosts and confirms their IP and VLAN settings are correct. What is the MOST likely cause of the communication failure between the VMs?

    graph TD subgraph Host1 VM1(VM1 - VLAN 100) --> VTEP1[VTEP 1] end subgraph Host2 VM2(VM2 - VLAN 100) --> VTEP2[VTEP 2] end VTEP1 |VxLAN Tunnel| VTEP2 VTEP1 & VTEP2 -- Layer 3 Network -- L3Router(Underlay Network)

    Show answer & explanation

    Correct answer: C

    In a VxLAN environment, the VxLAN Network Identifier (VNI) is used to segment traffic in the overlay network, similar to how a VLAN ID works in a traditional network. For two VMs to communicate within the same logical Layer 2 segment, their traffic must be mapped to the same VNI by their respective VxLAN Tunnel Endpoints (VTEPs). A misconfigured VNI on one VTEP would cause it to encapsulate or decapsulate traffic into the wrong logical segment, preventing communication even if the underlying VLANs and IP settings are correct. Since VxLAN operates over a Layer 3 underlay, STP on the physical switches is not directly involved in the overlay forwarding path. A mismatched VLAN ID was ruled out in the scenario.

  8. Question 8

    Q8Multiple answers

    A network technician is tasked with documenting the physical network layout of a new three-story building. The main telecommunications room, where the ISP connection and core router are located, is on the second floor. Each floor has its own wiring closet with switches that serve the users on that floor. According to TIA/EIA structured cabling standards, what are the correct terms for the main telecommunications room and the wiring closets on each floor? (Select TWO).

    Show answer & explanation

    Correct answers: B, D

    The Main Distribution Frame (MDF) is the central point of a structured cabling system where external connections (like the ISP) terminate and connect to the internal network's core equipment. In this scenario, the main telecommunications room on the second floor serves this function.

    Intermediate Distribution Frames (IDFs) are secondary wiring closets that connect to the MDF and distribute network access to end-users in a specific area, such as a single floor. The wiring closets on each floor fit this description perfectly.

  9. Question 9

    Q9

    A DevOps engineer is using an Infrastructure as Code (IaC) tool to automate the deployment of network security groups in a cloud environment. The engineer writes a declarative configuration file specifying the desired state for a set of firewall rules. When the configuration is applied, the IaC tool compares the file to the current state of the cloud resources and only makes the necessary changes to achieve the desired state. This property, where running the same configuration multiple times results in the same state without causing errors or additional changes, is known as:

    Show answer & explanation

    Correct answer: B

    Idempotence is a core principle of declarative IaC tools like Terraform and Ansible. It means that an operation can be applied multiple times without changing the result beyond the initial application. In this scenario, the IaC tool ensures that running the configuration script repeatedly will only configure the firewall rules once to match the desired state. Subsequent runs will detect that the state is already correct and will make no further changes. This makes automation safe and predictable. Immutability refers to creating new resources instead of changing existing ones. Orchestration is the broader coordination of automated tasks. Abstraction hides underlying complexity.

  10. Question 10

    Q10

    True or False: In a Secure Access Service Edge (SASE) architecture, both network traffic routing decisions and security policy enforcement are primarily handled by on-premises appliances located at each branch office.

    Show answer & explanation

    Correct answer: B

    The statement is false. A core principle of SASE is the convergence of networking and security into a single, cloud-delivered service model. In a SASE architecture, traffic is directed to a cloud-based point of presence (PoP) where security inspections (like SWG, CASB, FWaaS, ZTNA) and optimized routing decisions are made. This is the opposite of the traditional model of deploying and managing separate on-premises appliances at each branch office.

Register free to unlock 11 more sample questions

Create a free account to continue with the rest of the N10-009 sample set.

Lifetime One

Own this practice test forever.

$79.99
$75.99
one-time
  • Full access to 1,019 questions
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • Brainy AI Assistant
  • Lifetime updates

Two

Any 2 exams per month.

$20.00/exam
$39.99
/month
  • 2 active exam slots
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • 1,000 Brainy AI Credits
  • Cancel anytime

Premium Twelve

Any 12 exams over 3 months.

$15.00/exam
$179.99
/3 months
  • 4 active exam slots
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • 15,000 Brainy AI Credits
  • Dedicated support
  • Friend seat included — full access

Trusted by professionals at

NvidiaSupabaseGitHubOpenAITursoClerkClaude AIAmazon