CompTIA CloudNetX CNX-001 (V1) Exam Practice Test 2

Reviewed by Editorial Team
The ProProfs editorial team is comprised of experienced subject matter experts. They've collectively created over 10,000 quizzes and lessons, serving over 100 million users. Our team includes in-house content moderators and subject matter experts, as well as a global network of rigorously trained contributors. All adhere to our comprehensive editorial guidelines, ensuring the delivery of high-quality content.
Learn about Our Editorial Process
| By Thames
T
Thames
Community Contributor
Quizzes Created: 11201 | Total Attempts: 9,875,275
| Questions: 25 | Updated: Sep 28, 2026
Please wait...
Question 1 / 26
🏆 Rank #-- ▾
0 %
0/100
Score 0/100

1. A company wants to authenticate devices connecting to its wireless network using cryptographic certificates issued to each device, rather than a single shared preshared key that all devices use. Which technology underpins this approach?

Explanation

PKI issues each device its own unique certificate, and certificate-based authentication verifies that certificate during network access, which is far more secure and manageable at scale than a single PSK shared by every device. If one device's certificate is compromised, it can be revoked individually without affecting every other device on the network, unlike a shared PSK that would need to be rotated everywhere. Captive portals and MAC filtering address different access scenarios and offer weaker per-device assurance.

Submit
Please wait...
About This Quiz
CompTIA CloudNetX Cnx-001 (V1) Exam Practice Test 2 - Quiz

This practice assessment focuses on the CompTIA CloudNetX CNX-001 (V1) certification, evaluating your understanding of cloud networking concepts and skills. It covers essential topics such as cloud infrastructure, networking protocols, and security measures. This resource is vital for anyone preparing for the certification, helping you identify strengths and areas fo... see moreimprovement. see less

2.

What first name or nickname would you like us to use?

You may optionally provide this to label your report, leaderboard, or certificate.

2. A user's laptop remains connected to a distant access point with a weak signal even after walking much closer to a different, stronger access point on the same SSID. What wireless troubleshooting term describes this behavior?

Explanation

A sticky client is a device that does not aggressively re-evaluate and roam to a stronger nearby access point, instead remaining associated with a weaker, more distant one until the signal degrades much further or drops entirely. This is a client-side roaming behavior issue rather than a problem with the access points themselves. Adjusting minimum signal thresholds, enabling 802.11k/v/r roaming assistance features, or updating client wireless drivers are common ways to address sticky client behavior.

Submit

3. A campus network experiences a sudden, severe slowdown across an entire VLAN after a new switch was cabled in with a loop accidentally created between two of its ports. What is the most likely cause of the network-wide slowdown?

Explanation

A Layer 2 loop without functioning loop prevention causes broadcast, multicast, and unknown-unicast traffic to circulate endlessly and multiply across the loop, rapidly consuming all available bandwidth and CPU on connected switches, which is known as a broadcast storm. This explains the sudden, network-wide impact rather than a problem isolated to a single connection. Verifying that Spanning Tree Protocol is enabled and correctly blocking the redundant link is the typical fix.

Submit

4. A firewall configured for stateful inspection is dropping legitimate return traffic because outbound packets take one path while the corresponding inbound replies take a different path that bypasses the firewall's state table. What issue does this describe?

Explanation

Asymmetric routing occurs when traffic in one direction takes a different path than the return traffic, which is especially problematic for stateful devices like firewalls that expect to see both directions of a flow to correctly track and permit the session. If the return path bypasses the stateful device entirely, it may drop the reply as unrecognized, breaking the connection. Correcting this usually involves adjusting routing policy so that both directions of a flow consistently traverse the same path through the stateful device.

Submit

5. A packet capture from a Wireshark session shows repeated TCP retransmissions between a client and server, along with a small number of duplicate ACKs. Which two conclusions are reasonable based on this pattern? (Select two.)

Explanation

Repeated TCP retransmissions and duplicate ACKs are classic indicators that packets are being lost or delayed somewhere along the path, prompting the sender to resend data it believes was not acknowledged in time. This points toward investigating link quality, congestion, or a lossy hop rather than DNS resolution, since retransmissions occur at the transport layer well after DNS has already resolved a name to an address. A firewall blocking all traffic would typically show no response at all rather than partial delivery with retransmissions.

Submit

6. An engineer wants detailed DNS query output, including all returned resource records and response flags, for scripting into an automated health check. Which command is generally preferred for this kind of detailed, scriptable output?

Explanation

dig provides detailed, well-structured DNS query output, including record types, TTLs, and response flags, and its output format is generally easier to parse in scripts compared to the more interactive nslookup. ping tests basic reachability and latency, not DNS record details. arp and route deal with local address resolution and routing tables, not DNS queries.

Submit

7. A user reports that a web application is slow. Rather than guessing randomly, an engineer checks whether the problem exists at the network layer, then the application server, then the database, narrowing down where along the path the delay is introduced. What approach is this?

Explanation

Divide and conquer troubleshooting tests an intermediate point in a suspected chain of components and then narrows the search up or down based on the result, which is often faster than exhaustively checking every layer from top to bottom. This is one of the multiple approaches suggested when establishing a theory of probable cause. It is particularly effective when a problem could plausibly originate at several different points along a request's path.

Submit

8. A team wants a metric that specifically measures how long it takes, on average, to notice that an incident has occurred, separate from how long it then takes to investigate or repair it. This metric is called Mean Time To ____.

Explanation

Mean Time To Detect measures the average time between an incident actually starting and someone or something noticing it, which is a distinct phase from Mean Time To Investigate or Mean Time To Recovery that follow detection. Improving MTTD often comes from better monitoring, alerting, and anomaly detection rather than faster repair processes. Tracking all of these mean-time metrics separately helps a team pinpoint exactly which phase of incident response needs improvement.

Submit

9. A team stores its network device configuration templates in a Git repository, but a recent audit found an API key for a monitoring tool committed directly in one of the template files. What practice was violated?

Explanation

Secrets management practices require that credentials, API keys, and similar sensitive values never be committed directly into a version control repository, since repository history retains old commits indefinitely and access to the repository often extends to many collaborators. Instead, secrets should be pulled at runtime from a dedicated secrets manager or vault. Desired state configuration and GitOps describe how configuration is declared and synchronized, not how sensitive values should be stored.

Submit

10. A network team currently only investigates performance problems after users file complaints. They want to shift toward catching issues before they affect users. Which two practices support this shift? (Select two.)

Explanation

Proactive monitoring uses alerting thresholds and continuous trend analysis of metrics like utilization to catch developing problems, such as a link trending toward saturation, before they cause a user-visible outage. This contrasts with reactive monitoring, where the team only learns about a problem once someone reports it. Waiting for scheduled maintenance windows or disabling telemetry would move the team further toward a reactive posture, not away from it.

Submit

11. A security team wants logs from firewalls, switches, and servers across the environment correlated in one place to detect multi-stage attacks that no single device's logs would reveal alone. What should they deploy?

Explanation

A SIEM centralizes and correlates logs from many different sources, which allows it to detect patterns spanning multiple devices, such as a reconnaissance scan followed by a login attempt on a different system, that would be invisible if each device's logs were reviewed in isolation. A single device's local log buffer has no visibility beyond itself and is also often limited in retention. SNMP polling gathers performance metrics rather than the detailed event logs a SIEM correlates.

Submit

12. A network appliance ships with FTP, Telnet, and SNMPv1 enabled by default, none of which the organization actually uses. The hardening practice of turning off these unused services is known as ____ unneeded services.

Explanation

Disabling unneeded services reduces the appliance's attack surface by removing avenues an attacker could exploit through insecure or unused protocols like Telnet and SNMPv1, which both transmit credentials or data without encryption. Even if a service is not actively being used, leaving it enabled still exposes a potential entry point. This is one of the most basic and cost-free hardening steps available for nearly any network appliance.

Submit

13. Match each wireless term to its correct description.

Explanation

TKIP was introduced as an interim improvement over WEP but has since been superseded by AES-based encryption in WPA2 and WPA3 due to known weaknesses. PSK enterprise, more precisely 802.1X-based enterprise authentication, lets each user or device authenticate individually, which allows per-user revocation instead of one shared secret for everyone. Layer 2 client isolation is common on guest networks to prevent one guest device from directly reaching another, and hiding an SSID provides only minor obscurity rather than real security, since it can still be discovered by monitoring wireless traffic.

Submit

14. A small office has one public IP address but needs to allow 40 internal devices to browse the internet simultaneously. Which NAT technique allows many internal addresses to share a single public address by translating port numbers?

Explanation

PAT, sometimes called NAT overload, maps many internal private addresses to a single public address by also translating the source port number, which allows far more simultaneous sessions than a one-to-one NAT mapping would permit. Port forwarding instead exposes a specific internal service to the outside world on a fixed port, which solves a different problem. NAT64 translates between IPv6 and IPv4 addressing, not between many private hosts and one public address.

Submit

15. A company wants to enforce consistent security policy for remote users accessing both internal applications and sanctioned cloud SaaS applications, without backhauling all traffic through a central data center. Which two Zero Trust-aligned technologies help achieve this? (Select two.)

Explanation

SASE converges networking and security capabilities, such as secure web gateway and firewall functions, into a cloud-delivered service that can enforce policy close to the user rather than requiring a trip back to a central data center. CASB specifically extends visibility and policy enforcement over sanctioned cloud application usage, helping ensure data handled by SaaS applications meets the organization's security requirements. STP and PAT operate at very different layers and are unrelated to policy enforcement for remote or cloud access.

Submit

16. A company wants to block login attempts to its administrative portal that originate from countries where it has no employees or business operations, regardless of the credentials used. Which access control fits this requirement?

Explanation

Geolocation rules restrict or block traffic based on the geographic origin of the source IP address, which is well suited to blocking access attempts from regions where the organization has no legitimate reason to expect traffic. This adds a coarse but useful layer of defense against certain classes of unauthorized access attempts. DLP controls instead focus on preventing sensitive data from leaving the organization, which is a different concern from where a login attempt originates.

Submit

17. A security appliance needs to inspect the contents of encrypted web traffic for malware and data exfiltration, which normal firewalls cannot see because the payload is encrypted. What capability enables this?

Explanation

SSL/TLS inspection terminates the encrypted session at the security appliance, inspects the decrypted payload for threats, and then re-establishes an encrypted connection onward to the destination, effectively acting as a controlled man-in-the-middle for security purposes. This is necessary because encrypted payloads are otherwise opaque to traditional inspection tools. Port security and NACLs control access based on addresses and ports, not the ability to see inside an encrypted payload.

Submit

18. A security review finds a firewall rule that allows any source address to reach any destination port on a critical internal server. Even though no active exploitation has been detected, what should this be classified as?

Explanation

An overly permissive rule grants far more access than is actually required for the server's function, which unnecessarily expands the attack surface even if it has not yet been actively exploited. Tightening the rule to only the specific sources, ports, and protocols the server genuinely needs reduces risk without waiting for an incident to force the issue. A zero-day vulnerability instead refers to a previously unknown software flaw, which is a different category of risk entirely.

Submit

19. An organization maintains a centralized system of record that tracks every network device, its configuration attributes, and its relationships to other assets, used to support change management and impact analysis. This system is called a ____.

Explanation

A configuration management database, or CMDB, centralizes information about an organization's assets and their relationships, which supports impact analysis before changes are made and helps teams understand dependencies during incident response. It differs from a simple asset inventory by explicitly tracking relationships between items, not just a flat list. Keeping a CMDB accurate typically requires integration with automated discovery and change management processes.

Submit

20. A campus network design places switches that aggregate multiple access-layer switches and enforce policy between them, without directly connecting to end-user devices. Which layer of the three-tier hierarchy does this describe?

Explanation

The distribution layer sits between the access layer, which directly connects end-user devices, and the core, which provides high-speed backbone connectivity between distribution blocks. It commonly enforces policy, aggregates traffic from multiple access switches, and can perform routing between VLANs. A collapsed core design instead merges the core and distribution layers into a single tier, typically in smaller networks where a separate distribution layer is not justified.

Submit

21. A team is designing redundancy for a critical database cluster. Which two statements correctly distinguish active-active from active-passive configurations? (Select two.)

Explanation

Active-active designs let both nodes serve production traffic simultaneously, which both provides redundancy and can add usable capacity compared to a single node. Active-passive keeps a standby node idle, ready to take over only once the active node fails, which typically introduces some failover delay compared to an already-active peer. Active-active database designs exist and are common, though they require careful handling of data consistency across nodes.

Submit

22. A security architecture requires that administrators never connect directly to production servers from the internet, but instead pass through a single hardened, tightly monitored intermediary host first. What is this intermediary called?

Explanation

A bastion host is a hardened, closely monitored server that sits at the network's edge and serves as the single controlled entry point for administrative access, so that production servers themselves are never directly exposed to external connections. This centralizes logging, patching, and access control onto one well-secured system. A transit gateway instead handles routing between multiple virtual networks and is not specifically an administrative access control point.

Submit

23. Match each networking term to its correct description.

Explanation

A screened subnet, historically called a DMZ, hosts externally facing services while isolating them from the fully trusted internal network. North-south traffic crosses the data center's edge, such as a user request coming in from the internet, while east-west traffic stays internal, such as one microservice calling another. VXLAN encapsulates Layer 2 frames inside Layer 3 UDP packets, allowing virtual networks to span physical Layer 3 boundaries, which is especially useful in large virtualized or cloud data centers.

Submit

24. A security team wants to both verify that DNS responses have not been tampered with and encrypt DNS queries so they cannot be read in transit by a network observer. Which two technologies address these two goals respectively? (Select two.)

Explanation

DNSSEC adds cryptographic signatures to DNS records so a resolver can verify that a response genuinely came from the authoritative source and was not tampered with in transit, addressing integrity rather than confidentiality. DNS over TLS and DNS over HTTPS instead encrypt the query and response in transit, protecting against eavesdropping on what domains are being looked up, but do not on their own validate authenticity the way DNSSEC does. STP, PAT, and 802.1X serve entirely different purposes at Layer 2, NAT, and port authentication respectively.

Submit

25. An architect assigns a fixed 10.0.5.10 address to a database server so its address never changes, while workstations receive addresses automatically from a pool that may change over time. What best describes this design choice?

Explanation

Assigning a fixed address by hand to a server that other systems depend on, such as a database, is static addressing, and using a private range like 10.0.5.10 keeps it unreachable directly from the internet. Workstations commonly receive private addresses dynamically through DHCP since their exact address rarely matters to other systems. Using public addresses for internal servers and workstations would needlessly expose them and consume scarce public address space.

Submit
×
Saved
Thank you for your feedback!
View My Results
Cancel
  • All
    All (25)
  • Unanswered
    Unanswered ()
  • Answered
    Answered ()
A company wants to authenticate devices connecting to its wireless...
A user's laptop remains connected to a distant access point with a...
A campus network experiences a sudden, severe slowdown across an...
A firewall configured for stateful inspection is dropping legitimate...
A packet capture from a Wireshark session shows repeated TCP...
An engineer wants detailed DNS query output, including all returned...
A user reports that a web application is slow. Rather than guessing...
A team wants a metric that specifically measures how long it takes, on...
A team stores its network device configuration templates in a Git...
A network team currently only investigates performance problems after...
A security team wants logs from firewalls, switches, and servers...
A network appliance ships with FTP, Telnet, and SNMPv1 enabled by...
Match each wireless term to its correct description.
A small office has one public IP address but needs to allow 40...
A company wants to enforce consistent security policy for remote users...
A company wants to block login attempts to its administrative portal...
A security appliance needs to inspect the contents of encrypted web...
A security review finds a firewall rule that allows any source address...
An organization maintains a centralized system of record that tracks...
A campus network design places switches that aggregate multiple...
A team is designing redundancy for a critical database cluster. Which...
A security architecture requires that administrators never connect...
Match each networking term to its correct description.
A security team wants to both verify that DNS responses have not been...
An architect assigns a fixed 10.0.5.10 address to a database server so...
play-Mute sad happy unanswered_answer up-hover down-hover success oval cancel Check box square blue
Alert!