CompTIA CloudNetX CNX-001 (V1) Exam Practice Test 1

Reviewed by Editorial Team
The ProProfs editorial team is comprised of experienced subject matter experts. They've collectively created over 10,000 quizzes and lessons, serving over 100 million users. Our team includes in-house content moderators and subject matter experts, as well as a global network of rigorously trained contributors. All adhere to our comprehensive editorial guidelines, ensuring the delivery of high-quality content.
Learn about Our Editorial Process
| By Thames
T
Thames
Community Contributor
Quizzes Created: 11201 | Total Attempts: 9,875,275
| Questions: 25 | Updated: Sep 28, 2026
Please wait...
Question 1 / 26
🏆 Rank #-- ▾
0 %
0/100
Score 0/100

1. A company wants remote employees to be prompted for an additional verification step only when they log in from an unrecognized device or an unusual location, rather than every single time. Which identity capability supports this behavior?

Explanation

Conditional access evaluates contextual signals such as device recognition, location, and behavior, and risk-based authentication uses that context to decide when additional verification, like MFA, is actually warranted. This balances security with user convenience by not challenging every login equally. RBAC controls what an authenticated user can do, not whether additional verification is required at login.

Submit
Please wait...
About This Quiz
CompTIA CloudNetX Cnx-001 (V1) Exam Practice Test 1 - Quiz

This practice assessment focuses on the CompTIA CloudNetX CNX-001 (V1) Exam, evaluating your knowledge of cloud networking principles and practices. It covers essential topics such as cloud architecture, security, and deployment models, ensuring you are well-prepared for the certification. This resource is valuable for learners aiming to enhance their skills... see morein cloud technologies and succeed in their professional journey. see less

2.

What first name or nickname would you like us to use?

You may optionally provide this to label your report, leaderboard, or certificate.

2. Users report that a browser blocks access to an internal web application with a certificate warning. Investigation shows the certificate's common name does not match the URL being accessed. Which two categories from the exam objectives does this issue fall under? (Select two.)

Explanation

A certificate whose common name or subject alternative name does not match the requested URL is a textbook certificate mismatch issue, which browsers flag to protect users from potentially connecting to the wrong or a malicious server. If the certificate is additionally issued by an authority the client does not trust, that compounds into a separate trust issue on top of the mismatch. Neither DHCP exhaustion nor broadcast storms have anything to do with how a browser validates a presented certificate.

Submit

3. After enabling jumbo frames on a set of switches but not on an upstream router, large file transfers between two segments begin failing or running extremely slowly, while small packets pass normally. What is the most likely cause?

Explanation

When one segment is configured for jumbo frames but a device in the path still uses the standard MTU, large packets that exceed that device's MTU may be dropped or require fragmentation, which is especially disruptive if fragmentation is disabled or blocked. Small packets remain unaffected because they fall well under both MTU sizes. Ensuring MTU is configured consistently across every device in the path is required whenever jumbo frames are enabled.

Submit

4. A network with hundreds of internal hosts behind a single NAT device begins experiencing new outbound connections failing intermittently, especially during peak usage, while existing connections remain stable. What is a likely cause?

Explanation

A NAT device maintains a finite table of active address and port translations, and when that table fills up during peak usage, new outbound connections can fail to establish even though already-established sessions continue working. This is a common scaling issue for NAT devices serving many hosts through a limited pool of public addresses and ports. Increasing the available port range, adding more public IPs, or scaling out NAT capacity are typical remediations.

Submit

5. A traceroute to a remote server shows increasing round-trip times at several hops in the middle of the path, then a sudden timeout at the final hop, even though the service is reachable by other means. Which two conclusions are reasonable? (Select two.)

Explanation

Rising latency across several consecutive hops points toward congestion or a slower link somewhere in that segment of the path, which is useful for narrowing down where a performance problem originates. A timeout specifically at the final hop is a very common and often benign finding, since some devices are configured to silently drop or not respond to the ICMP or UDP probes traceroute uses, even while still forwarding or serving other traffic normally. Neither of these findings says anything about DNS resolution, which traceroute does not test.

Submit

6. An engineer needs to confirm whether a specific TCP port on a remote server is open and accepting connections, without needing full protocol-level packet inspection. Which tool is best suited for this quick check?

Explanation

Netcat is a lightweight utility well suited to quickly testing whether a specific port is open and accepting connections, without the overhead of a full packet capture and analysis tool. Wireshark is more appropriate when detailed packet-level inspection of the traffic itself is needed. Iperf measures throughput between two points rather than testing individual port reachability.

Submit

7. After gathering information about a reported outage and confirming what changed recently, a network engineer forms a hypothesis about the root cause before making any changes. According to the troubleshooting methodology, what is the next correct step?

Explanation

The troubleshooting methodology calls for testing a theory of probable cause before acting on it, since untested assumptions can lead to wasted effort or unintended side effects. If the test confirms the theory, the engineer proceeds to plan and implement a fix; if not, a new theory is established or the issue is escalated. Jumping straight to a fix skips validating that the theory actually explains the reported symptoms.

Submit

8. An internal networking team commits to an internal support team that switch replacement requests will be fulfilled within 4 business hours. Because this commitment is between two internal teams rather than with an external customer, it is best classified as an ____.

Explanation

An Operational-level Agreement defines commitments between internal teams supporting a service, distinct from a Service-level Agreement, which is typically a commitment made to an external customer. Both types of agreements support the overall service being delivered, but only the SLA typically carries customer-facing contractual weight, such as service credits. Understanding the distinction helps teams correctly escalate and track internal versus customer-facing commitments.

Submit

9. A team manages its network device configurations with a tool that continuously compares deployed configurations against a version-controlled baseline and reports drift when they diverge. What concept does this describe?

Explanation

Desired state configuration defines the intended configuration as code, and the tooling continuously or periodically compares the live device configuration against that baseline, flagging any drift caused by manual changes or unintended modifications. This is central to infrastructure as code practices applied to network devices, not just servers. Mutable infrastructure, by contrast, allows configurations to be changed in place without necessarily comparing against a declared baseline.

Submit

10. A network engineer is troubleshooting a voice-over-IP quality complaint and wants to measure variation in packet arrival timing as well as how much data actually gets through per second. Which two metrics are directly relevant? (Select two.)

Explanation

Jitter measures the variation in delay between packets arriving, which is especially disruptive for real-time voice and video traffic that expects a steady, predictable stream. Throughput measures the actual data transfer rate achieved, which is relevant to whether enough bandwidth is available for a smooth call. SSID naming, PoE wattage, and VLAN tagging are unrelated to diagnosing jitter or throughput-related call quality problems.

Submit

11. A disaster recovery plan specifies that after an outage, the organization can tolerate losing at most 15 minutes of data, and must have systems back online within 4 hours. Which two metrics do these numbers represent, respectively?

Explanation

Recovery Point Objective defines the maximum acceptable amount of data loss, measured as a point in time, so a 15-minute RPO means backups or replication must occur at least that frequently. Recovery Time Objective defines the maximum acceptable downtime before systems must be restored, so a 4-hour RTO drives how quickly failover or recovery procedures must complete. Confusing the two can lead to a disaster recovery plan that protects data adequately but restores service too slowly, or vice versa.

Submit

12. During a security audit, a network appliance is found still using its factory-set administrator username and password. The hardening practice that directly addresses this finding is ____ management.

Explanation

Default credential management requires changing every appliance's factory-set username and password before it is placed into production, since default credentials are widely known and are one of the first things attackers try against exposed devices. This is one of the most basic and impactful appliance-hardening steps, alongside disabling unneeded services and restricting administrative interface access. Automated configuration reviews can help catch appliances that were deployed without this step being completed.

Submit

13. Match each wireless security term to its correct description.

Explanation

WPA3 improves on WPA2 with stronger encryption and protection against offline dictionary attacks. A preshared key is a straightforward shared-secret authentication method common in home and small-office networks. Captive portals are commonly used for guest Wi-Fi to display terms of use or collect credentials before granting broader access, while MAC filtering restricts access by physical address, though it is easily bypassed by address spoofing and should not be relied on as a primary control.

Submit

14. A network architect must carve a /24 network into subnets that support 60, 30, 14, and 14 hosts respectively, wasting as few addresses as possible. Which technique should the architect use?

Explanation

VLSM allows each subnet to be sized to its actual host requirement rather than forcing every subnet to the same fixed size, which minimizes wasted address space. A /26 supports 62 usable hosts for the 60-host segment, while smaller /28s handle the 14-host segments efficiently. A single flat /24 would not provide the isolation the design calls for, and NAT64 solves IPv4-to-IPv6 translation, not subnet sizing.

Submit

15. A security team wants to ensure that if one web server in a subnet is compromised, the attacker cannot move laterally to other servers in the same subnet without explicit policy allowing it. Which Zero Trust concept directly addresses this?

Explanation

Microsegmentation applies granular security policy between individual workloads, even within the same subnet, so that lateral movement requires explicit permission rather than being allowed by default because two hosts happen to share a network segment. This directly limits how far an attacker can spread from a single compromised host. SSO and geofencing address authentication and location-based access, not lateral movement between workloads.

Submit

16. A cloud virtual machine can send traffic to the internet but cannot receive an inbound SSH connection from an administrator's IP address, even though the VM's operating system firewall allows SSH. What should be checked first?

Explanation

A network security group enforces its own inbound and outbound rules independently of the guest operating system's firewall, so traffic can be blocked at the NSG level even when the OS itself would allow it. Checking the NSG's inbound rules for a permitted rule from the administrator's source IP on the SSH port is the direct next step. DNS and time zone settings have no bearing on whether a specific inbound port is reachable.

Submit

17. A company needs to protect a public-facing web application from SQL injection and cross-site scripting, while also inspecting general east-west traffic for a broader set of threats across the network. Which two technologies should be deployed together? (Select two.)

Explanation

A WAF is purpose-built to detect and block application-layer attacks like SQL injection and cross-site scripting that target web applications specifically. An NGFW provides broader network traffic inspection, combining traditional firewalling with application awareness and intrusion prevention across general traffic. DNSSEC protects DNS record integrity and has no bearing on SQL injection, which occurs at the application layer.

Submit

18. An organization's public IP prefixes were suddenly announced by an unauthorized autonomous system, causing some internet traffic destined for the organization to be misrouted elsewhere. What attack does this describe?

Explanation

BGP hijacking occurs when an unauthorized or misconfigured autonomous system announces routes for IP prefixes it does not own, causing internet traffic to be misdirected toward it. This can lead to traffic interception, denial of service, or route instability for the legitimate owner. Mitigations include route origin validation and filtering based on registered prefix ownership.

Submit

19. A campus network has redundant physical links between switches to avoid a single point of failure, but without a loop-prevention protocol, this redundancy would cause a broadcast storm. The protocol that prevents this by blocking redundant paths is ____.

Explanation

Spanning Tree Protocol detects redundant Layer 2 paths between switches and logically blocks enough of them to eliminate loops, while keeping a path available to activate automatically if the active link fails. Without STP, redundant links at Layer 2 would create a loop that broadcasts and multicasts traffic indefinitely, quickly overwhelming the network. STP is a foundational requirement whenever physical link redundancy is built into a switched campus design.

Submit

20. A data center needs to bridge the gap between a utility power outage and when backup generators reach full output, which can take up to two minutes. What component is designed for this specific gap?

Explanation

A UPS provides nearly instantaneous battery-backed power the moment utility power fails, bridging the short gap until generators start and reach full capacity. Without a UPS, equipment would lose power during that transition window even with generators present. An EPO switch is a safety mechanism for manually cutting power in an emergency, not a power continuity solution.

Submit

21. A load balancer must distribute new connections to whichever backend server currently has the fewest active sessions, rather than cycling through servers in a fixed order. Which load balancing method is this?

Explanation

The least connections method actively tracks how many open connections each backend server currently has and routes new connections to the one with the fewest, which helps evenly distribute load when session durations vary widely. Round robin instead cycles through servers in a fixed order regardless of their current load. Weighted load balancing biases distribution toward servers assigned a higher capacity weight, not toward real-time connection counts.

Submit

22. A company needs a dedicated, private, high-bandwidth connection from its data center to its cloud provider that avoids the public internet entirely, for a latency-sensitive workload. Which solution fits best?

Explanation

Dedicated cloud interconnect offerings, such as AWS Direct Connect or Azure ExpressRoute, provide a private, dedicated circuit into the cloud provider's network that bypasses the public internet, offering more consistent latency and bandwidth. A site-to-site VPN still traverses the public internet, even though the payload is encrypted. Point-to-site VPNs and split tunneling are designed for individual remote users, not data center to cloud connectivity.

Submit

23. Match each network topology to its defining characteristic.

Explanation

Spine-and-leaf is the standard data center fabric because every leaf uplinks to every spine, giving consistent latency between any two leaf-connected devices, which suits heavy east-west traffic. Hub-and-spoke centralizes connectivity through a hub, which is cost-effective but makes the hub a potential bottleneck or single point of failure. Full mesh maximizes redundancy at the cost of significant cabling and configuration complexity, which is why it is reserved for small, critical cores.

Submit

24. A network team is designing port-based network access control for wired switch ports, with centralized authentication and accounting. Which two protocols are appropriate building blocks for this design? (Select two.)

Explanation

802.1X provides the port-based control that decides whether a device may pass traffic on a switch port until it authenticates. RADIUS commonly serves as the backend that 802.1X consults to authenticate the device or user and to log accounting data. LDAP is a directory access protocol that RADIUS or another system might query, but it does not itself perform port-based access control.

Submit

25. A network architect is designing routing between autonomous systems for a multi-region deployment that peers with two different cloud providers and an ISP. Which routing protocol is designed for this exact purpose?

Explanation

BGP is the protocol used to exchange routing information between autonomous systems, making it the standard choice for peering with multiple external providers such as cloud networks and ISPs. OSPF is a link-state protocol designed for routing within a single autonomous system, not between separate ones. STP prevents loops at Layer 2 and has no role in inter-AS routing.

Submit
×
Saved
Thank you for your feedback!
View My Results
Cancel
  • All
    All (25)
  • Unanswered
    Unanswered ()
  • Answered
    Answered ()
A company wants remote employees to be prompted for an additional...
Users report that a browser blocks access to an internal web...
After enabling jumbo frames on a set of switches but not on an...
A network with hundreds of internal hosts behind a single NAT device...
A traceroute to a remote server shows increasing round-trip times at...
An engineer needs to confirm whether a specific TCP port on a remote...
After gathering information about a reported outage and confirming...
An internal networking team commits to an internal support team that...
A team manages its network device configurations with a tool that...
A network engineer is troubleshooting a voice-over-IP quality...
A disaster recovery plan specifies that after an outage, the...
During a security audit, a network appliance is found still using its...
Match each wireless security term to its correct description.
A network architect must carve a /24 network into subnets that support...
A security team wants to ensure that if one web server in a subnet is...
A cloud virtual machine can send traffic to the internet but cannot...
A company needs to protect a public-facing web application from SQL...
An organization's public IP prefixes were suddenly announced by an...
A campus network has redundant physical links between switches to...
A data center needs to bridge the gap between a utility power outage...
A load balancer must distribute new connections to whichever backend...
A company needs a dedicated, private, high-bandwidth connection from...
Match each network topology to its defining characteristic.
A network team is designing port-based network access control for...
A network architect is designing routing between autonomous systems...
play-Mute sad happy unanswered_answer up-hover down-hover success oval cancel Check box square blue
Alert!