CompTIA CloudNetX CNX-001 (V1) Exam Practice Test 3

Reviewed by Editorial Team
The ProProfs editorial team is comprised of experienced subject matter experts. They've collectively created over 10,000 quizzes and lessons, serving over 100 million users. Our team includes in-house content moderators and subject matter experts, as well as a global network of rigorously trained contributors. All adhere to our comprehensive editorial guidelines, ensuring the delivery of high-quality content.
Learn about Our Editorial Process
| By Thames
T
Thames
Community Contributor
Quizzes Created: 11201 | Total Attempts: 9,875,275
| Questions: 25 | Updated: Sep 28, 2026
Please wait...
Question 1 / 26
🏆 Rank #-- ▾
0 %
0/100
Score 0/100

1. A security team wants administrative access to a sensitive system to be granted only for the specific duration an approved task requires, and automatically revoked afterward, rather than remaining active indefinitely. Which identity concept describes this approach?

Explanation

JIT provisioning grants elevated access only for the specific window of time it is actually needed, often tied to an approved request or ticket, and automatically revokes it afterward rather than leaving standing privileged access active indefinitely. This significantly reduces the window during which a privileged credential could be misused or compromised. Role-based access control defines what a role can do in general, but does not by itself address the time-bound nature that JIT provisioning specifically adds.

Submit
Please wait...
About This Quiz
CompTIA CloudNetX Cnx-001 (V1) Exam Practice Test 3 - Quiz

This practice assessment focuses on the CompTIA CloudNetX CNX-001 (V1) certification, evaluating key concepts in cloud networking, architecture, and deployment strategies. It is designed to help learners reinforce their understanding and prepare effectively for the certification exam, ensuring a solid grasp of essential cloud computing principles.

2.

What first name or nickname would you like us to use?

You may optionally provide this to label your report, leaderboard, or certificate.

2. Several access points in a dense office deployment are configured on overlapping 2.4GHz channels, and users report frequent slowdowns and retransmissions in areas where multiple access points' signals reach the same desk. What is the most likely cause?

Explanation

In the 2.4GHz band, only channels 1, 6, and 11 in most regions do not overlap with each other, so access points placed close together on overlapping channels interfere with one another, causing retransmissions and reduced effective throughput wherever their coverage areas intersect. This is a very common design mistake in dense deployments where more access points were added without a careful channel plan. Reassigning access points to a proper non-overlapping channel plan, or moving to the less congested 5GHz or 6GHz bands, typically resolves this.

Submit

3. Traffic from an internal client to another internal server unnecessarily routes out to an external gateway or cloud edge device and back in again, adding latency, instead of staying within the local network. What is this pattern called?

Explanation

Hairpinning describes traffic that leaves a local network segment through a gateway device and immediately routes back in to reach a destination that was actually reachable locally, adding unnecessary latency and load on the gateway device. This often results from routing or NAT configuration that does not correctly recognize when both endpoints are local to each other. Correcting the routing so that local-to-local traffic stays local, sometimes called NAT reflection or hairpin NAT handling when intentional, resolves the added latency.

Submit

4. Two devices on the same subnet suddenly both experience intermittent connectivity, and switch logs show frequent MAC address table flapping for a single IP address between two different physical ports. What is the most likely cause?

Explanation

When two devices are both configured with the same IP address, the network sees that address appear to move rapidly between two different MAC addresses and switch ports, which shows up as MAC table flapping and causes intermittent connectivity for both devices as traffic is inconsistently delivered to whichever device most recently claimed the address. This is a classic and disruptive addressing conflict, often caused by a static assignment colliding with a DHCP-assigned address or two static assignments made independently. Resolving it requires identifying and correcting the duplicate assignment, often with the help of DHCP logs or ARP table inspection.

Submit

5. An engineer runs a socket statistics command and finds an unusually high number of connections stuck in a half-open state to a single destination port. Which two conclusions are worth investigating further? (Select two.)

Explanation

A large number of half-open connections to one port is a classic signature of a SYN flood attack, where an attacker sends many initial connection requests without completing the handshake, exhausting resources on the target. The same pattern can also arise from a legitimate but misbehaving application or client that repeatedly attempts and fails to complete a connection, so both an attack and an application bug are reasonable hypotheses worth investigating. This output says nothing about whether a service has been patched, and it does not by itself point to a NIC hardware failure.

Submit

6. An engineer wants a single tool that combines the path-tracing of traceroute with the continuous, repeated loss and latency measurement of ping, updating live per hop. Which tool fits this description?

Explanation

mtr combines the functionality of traceroute and ping into one continuously updating view, showing loss percentage and latency statistics at each hop over time rather than a single snapshot. This makes it especially useful for diagnosing intermittent path issues that a single traceroute or ping might miss. arp resolves local Layer 2 to Layer 3 address mappings, and ipconfig and ss report local interface and socket information respectively, neither of which traces a multi-hop path.

Submit

7. A help desk ticket says only "the network is down." Before forming any theory about the cause, what should the engineer do first, according to the troubleshooting methodology?

Explanation

The troubleshooting methodology begins with gathering information and questioning users to understand the actual symptoms, since a vague report like the network is down could mean anything from a single application being unreachable to a full site outage. Jumping straight to a specific theory or drastic action risks wasting time on the wrong problem entirely. Only after clarifying scope and symptoms should the engineer move on to forming and testing a theory of probable cause.

Submit

8. A hardware vendor publishes a statistic representing the number of unit failures expected per a defined number of operating hours across a large population of devices, which helps predict how often replacements will be needed at scale. This statistic is known as the ____.

Explanation

Failure rate expresses how frequently a type of device is statistically expected to fail over a given amount of operating time across a large population, which supports capacity and spares planning as well as budgeting for expected replacements. It complements related reliability metrics like MTBF, which express the same underlying reliability concept as an average time between failures rather than a rate. Network teams responsible for large device fleets use these statistics to plan proactive replacement cycles rather than only reacting to failures as they occur.

Submit

9. A network automation team wants every change to network device configuration to go through a pull request, be reviewed, then automatically applied by a pipeline once merged, rather than engineers manually pushing changes to devices. Which two practices support this workflow? (Select two.)

Explanation

GitOps treats a Git repository as the single source of truth for desired configuration, and changes are only applied after going through the normal Git workflow of proposing, reviewing, and merging. A CI/CD pipeline then automatically takes merged changes and applies them consistently, removing the need for engineers to manually SSH into individual devices and reducing the risk of ad hoc, undocumented changes. Removing review steps or manually pushing changes outside this workflow would undermine the traceability and consistency that GitOps and CI/CD are meant to provide.

Submit

10. A network operations team wants to poll hundreds of switches and routers for interface statistics, CPU utilization, and error counters using a standardized, widely supported protocol. Which protocol is designed for this purpose?

Explanation

SNMP is a standardized protocol specifically designed for polling and monitoring network device statistics such as interface counters, CPU and memory utilization, and error rates across a large fleet of devices from many vendors. It relies on a management information base to define what data points are available on a given device. IPSec instead secures IP traffic, STP prevents Layer 2 loops, and DHCP assigns addresses, none of which is designed for statistics polling.

Submit

11. A cloud team notices that several virtual network resources, including unattached public IPs and idle load balancers, are still incurring charges even though nothing is using them. What cost management concept does this describe?

Explanation

Orphaned resources are provisioned assets, such as unattached IPs or idle load balancers, that remain running and billing even though nothing actively depends on them anymore, often left behind after a project or environment is decommissioned incompletely. Identifying and removing them is a straightforward way to reduce unnecessary operating expenditure. A chargeback model instead is about attributing costs to the business units that incur them, which is a different concept from simply having unused resources in the first place.

Submit

12. A security policy requires that administrative passwords on network appliances be changed on a defined recurring schedule, rather than remaining unchanged indefinitely once set. This practice is called password ____.

Explanation

Password rotation reduces the window of usefulness for a credential that may have been compromised without detection, since even a leaked password eventually becomes invalid once the next rotation occurs. It is typically paired with complexity and minimum length requirements to ensure that each rotated password remains difficult to guess or crack. Overly frequent rotation can backfire by encouraging predictable password patterns, so rotation schedules are usually balanced against other controls like MFA.

Submit

13. A hotel wants visitors to get internet access through the wireless network, but wants each visitor isolated from other guests' devices and from the internal staff network entirely. Which combination of wireless security features addresses this?

Explanation

A dedicated guest SSID, kept on its own VLAN with no routing path to internal staff resources, combined with Layer 2 client isolation so guest devices cannot reach each other directly, addresses both isolation requirements at once. A single shared PSK with no other restrictions would still allow guest devices to potentially reach each other and offers no separation from internal resources on its own. Disabling encryption would make matters worse by exposing guest traffic to anyone nearby, rather than improving isolation.

Submit

14. New laptops joining a corporate wireless network automatically receive an IP address, subnet mask, default gateway, and DNS server without any manual configuration. Which protocol is responsible for this?

Explanation

DHCP automatically assigns IP configuration, including address, subnet mask, gateway, and DNS servers, to clients as they join a network, eliminating the need for manual configuration on every device. NTP instead synchronizes clocks across devices, and LDAP provides directory lookups for identity information, neither of which assigns IP configuration. Losing DHCP availability typically causes new or renewing clients to fail to obtain a usable address.

Submit

15. An engineer is granted full administrative access to every production system so they can occasionally troubleshoot any of them, even though their regular job only requires access to two specific applications. Which Zero Trust principle is being violated?

Explanation

The principle of least privilege holds that access should be limited to only what is strictly necessary for a person's role, rather than broad access granted for convenience or rare edge cases. Granting full administrative access across every production system, when only two applications are actually needed, significantly expands the potential damage from a compromised or misused account. A better approach would grant scoped, time-limited elevated access only when a specific troubleshooting need arises, often through privileged access management.

Submit

16. An organization wants to block employee access to gambling and social media websites during business hours, and also prevent uploads of files larger than 50MB to unapproved cloud storage sites. Which two access control features address these two goals? (Select two.)

Explanation

Content and URL filtering solutions commonly support blocking by category, such as gambling or social media, without needing to maintain a list of every individual site. File blocking rules, often built into the same filtering platform, can restrict uploads or downloads based on file size or type to unapproved destinations. Geolocation rules block based on the geographic source of traffic rather than website category, and port security and NACLs operate on network addressing and ports rather than web content categories.

Submit

17. A security team wants a system that not only detects known attack patterns in network traffic but also automatically blocks matching traffic in real time, rather than only generating an alert for a human to review. Which capability do they need?

Explanation

An IPS sits inline with traffic flow, allowing it to actively drop or block traffic matching a known malicious signature the moment it is detected, rather than merely alerting after the fact. An IDS, by contrast, typically operates passively out of the main traffic path, generating alerts for a human or downstream system to act on without directly blocking traffic itself. Choosing between IPS and IDS deployment involves weighing the value of automatic blocking against the risk of a false positive disrupting legitimate traffic.

Submit

18. An attacker obtains a list of usernames and passwords leaked from an unrelated website and successfully logs into several corporate VPN accounts because employees reused the same passwords. What threat category does this best represent?

Explanation

Credential reuse occurs when the same username and password combination is used across multiple unrelated services, so a breach at one service can be leveraged to compromise accounts elsewhere. This differs from a brute-force attack, which guesses credentials through repeated attempts rather than using already-known, previously leaked values. Enforcing unique passwords and multifactor authentication are common mitigations against this specific threat.

Submit

19. Match each documentation artifact to its purpose.

Explanation

A runbook gives operators a repeatable, step-by-step procedure to follow for a specific task, reducing reliance on tribal knowledge during routine or emergency operations. A WBS decomposes a project into progressively smaller pieces of work, which supports estimation, assignment, and tracking. Baselines capture what normal looks like so that future deviations, whether performance or configuration drift, can be detected by comparison, while reference architectures provide a proven starting design pattern that reduces the risk of designing a new deployment entirely from scratch.

Submit

20. A campus deployment includes wireless access points and IP phones mounted in locations without nearby electrical outlets. What technology allows both data and electrical power to be delivered over the same Ethernet cable?

Explanation

PoE delivers both data and electrical power over a standard Ethernet cable, eliminating the need for a separate power outlet at the device's location, which is especially useful for ceiling-mounted access points and desk phones. This simplifies installation and allows centralized backup power through the switch rather than individual outlets. Link aggregation instead combines multiple physical links into one logical link for bandwidth and redundancy, which is a different concern from power delivery.

Submit

21. A data center uses a clean-agent gas-based system instead of water sprinklers to extinguish fires without damaging sensitive electronic equipment. This category of protection is called ____ suppression.

Explanation

Fire suppression systems in data centers commonly use clean agents or inert gases rather than water, since water sprinklers would risk damaging servers, switches, and other electronic equipment even in areas not directly on fire. These systems are designed to extinguish a fire quickly while minimizing collateral damage to hardware. Physical access controls and environmental monitoring for temperature and humidity are separate but related safeguards for protecting the same physical space.

Submit

22. A cloud architect wants to ensure that a scheduled host patching cycle does not take down all instances of a service simultaneously, and that a hardware failure in one rack does not affect every instance either. Which two concepts, respectively, address these two concerns?

Explanation

Update domains group resources so that planned maintenance, such as host patching, is rolled out to only one group at a time, keeping the rest of the service available during the maintenance window. Fault domains instead group resources by shared physical infrastructure, such as a rack or power source, so an unplanned hardware failure only affects instances within that one domain rather than the entire service. Spreading instances correctly across both types of domains is necessary for genuinely resilient availability design.

Submit

23. A retail chain with 200 branch locations wants to dynamically choose the best available path, such as MPLS, broadband, or cellular, for each type of traffic based on real-time link performance, rather than relying on a single static WAN circuit per site. Which technology fits this requirement?

Explanation

SD-WAN abstracts multiple underlying transport types, such as MPLS, broadband internet, and cellular, and dynamically steers traffic across whichever path currently offers the best performance for that application's requirements. A single dedicated MPLS circuit lacks this dynamic, multi-path flexibility and is typically more expensive to scale across hundreds of sites. Dark fiber is a physical, unlit fiber connection that an organization lights and manages itself, which is a different concern from dynamic path selection across diverse transport types.

Submit

24. Match each segmentation technology to its correct description.

Explanation

VLANs are the traditional way to segment a Layer 2 network into separate broadcast domains using 802.1Q tags, but they are typically limited in scale and confined to a single Layer 2 domain. VXLAN extends segmentation across Layer 3 boundaries by encapsulating Layer 2 frames inside UDP packets, which is essential for large virtualized data centers and multi-site designs. GENEVE was designed as a more extensible successor, carrying variable-length metadata that VXLAN's fixed header cannot accommodate, which is useful for carrying additional context in complex overlay networks.

Submit

25. A platform team is designing networking for a Kubernetes cluster where each container needs its own virtual network presence, and multiple containers on one host need to communicate efficiently. Which two concepts are directly relevant? (Select two.)

Explanation

Container networking gives each container or pod a distinct network identity so it can be addressed and communicate independently, which is foundational to how orchestration platforms like Kubernetes route traffic between pods. Virtual network interfaces let a single physical NIC be logically divided or virtualized to support multiple isolated network contexts on the same host, which underpins many container networking implementations. STP, PAT, and RADIUS serve loop prevention, address translation, and authentication purposes respectively, none of which is the mechanism for container-level addressing.

Submit
×
Saved
Thank you for your feedback!
View My Results
Cancel
  • All
    All (25)
  • Unanswered
    Unanswered ()
  • Answered
    Answered ()
A security team wants administrative access to a sensitive system to...
Several access points in a dense office deployment are configured on...
Traffic from an internal client to another internal server...
Two devices on the same subnet suddenly both experience intermittent...
An engineer runs a socket statistics command and finds an unusually...
An engineer wants a single tool that combines the path-tracing of...
A help desk ticket says only "the network is down." Before forming any...
A hardware vendor publishes a statistic representing the number of...
A network automation team wants every change to network device...
A network operations team wants to poll hundreds of switches and...
A cloud team notices that several virtual network resources, including...
A security policy requires that administrative passwords on network...
A hotel wants visitors to get internet access through the wireless...
New laptops joining a corporate wireless network automatically receive...
An engineer is granted full administrative access to every production...
An organization wants to block employee access to gambling and social...
A security team wants a system that not only detects known attack...
An attacker obtains a list of usernames and passwords leaked from an...
Match each documentation artifact to its purpose.
A campus deployment includes wireless access points and IP phones...
A data center uses a clean-agent gas-based system instead of water...
A cloud architect wants to ensure that a scheduled host patching cycle...
A retail chain with 200 branch locations wants to dynamically choose...
Match each segmentation technology to its correct description.
A platform team is designing networking for a Kubernetes cluster where...
play-Mute sad happy unanswered_answer up-hover down-hover success oval cancel Check box square blue
Alert!