CompTIA CloudNetX CNX-001 (V1) Exam Practice Test 4

Reviewed by Editorial Team
The ProProfs editorial team is comprised of experienced subject matter experts. They've collectively created over 10,000 quizzes and lessons, serving over 100 million users. Our team includes in-house content moderators and subject matter experts, as well as a global network of rigorously trained contributors. All adhere to our comprehensive editorial guidelines, ensuring the delivery of high-quality content.
Learn about Our Editorial Process
| By Thames
T
Thames
Community Contributor
Quizzes Created: 11201 | Total Attempts: 9,875,275
| Questions: 25 | Updated: Sep 28, 2026
Please wait...
Question 1 / 26
🏆 Rank #-- ▾
0 %
0/100
Score 0/100

1. An organization wants new employee accounts, group memberships, and eventual deprovisioning to be automatically synchronized between its HR system and dozens of downstream cloud applications, without manually creating and deleting accounts in each one. Which protocol is designed for this kind of automated identity lifecycle synchronization?

Explanation

SCIM standardizes how identity data, such as user creation, updates, and deprovisioning, is automatically synchronized between an identity source and many downstream applications, which is exactly the automated lifecycle management this scenario calls for. RADIUS and TACACS+ instead focus on authenticating and authorizing access to network devices and services, not synchronizing user records across applications. LDAP provides a directory query protocol that other systems can read from, but it does not itself define the standardized provisioning and deprovisioning workflow that SCIM specifies.

Submit
Please wait...
About This Quiz
CompTIA CloudNetX Cnx-001 (V1) Exam Practice Test 4 - Quiz

This assessment focuses on the CompTIA CloudNetX CNX-001 (V1) certification, evaluating your understanding of cloud networking concepts, architecture, and security. It is essential for professionals preparing for the certification exam, ensuring you are well-versed in key topics and practical applications. By taking this practice assessment, you can identify areas fo... see moreimprovement and boost your confidence for the actual exam. see less

2.

What first name or nickname would you like us to use?

You may optionally provide this to label your report, leaderboard, or certificate.

2. Users near a specific area of an office report weak Wi-Fi signal that was fine last month, and a site survey finds a newly installed microwave-adjacent break room appliance operating in the same frequency range as the 2.4GHz Wi-Fi band. What does this describe?

Explanation

Certain non-Wi-Fi devices, including some microwave ovens and other appliances, can emit interference in the 2.4GHz range, which degrades wireless signal quality for nearby clients even though the access point configuration itself has not changed. Identifying this kind of interference typically requires a spectrum analyzer or a site survey that looks beyond just Wi-Fi traffic to any energy present in the relevant frequency range. Moving affected clients or access points to the less congested 5GHz or 6GHz bands, or physically relocating the interference source, are common remediations.

Submit

3. A WAN link consistently runs near 100% utilization during business hours, and applications relying on it experience delays specifically during those peak windows. What is the most accurate description of this condition?

Explanation

When a link consistently runs at or near its maximum capacity during peak periods, it becomes a bottleneck that constrains the performance of everything depending on it, causing delays that correlate directly with those high-utilization windows. This is a capacity problem rather than a configuration or addressing error, and it typically requires either increasing available bandwidth, applying QoS to prioritize critical traffic, or reducing unnecessary load on the link. Continuously monitoring bandwidth utilization trends helps identify this kind of problem before it becomes severe enough to noticeably affect users.

Submit

4. After enabling IPv6 on a network, some clients begin receiving unexpected default gateway and prefix information from a device that was never intended to act as an IPv6 router, disrupting connectivity for other clients. What is this issue called?

Explanation

Unauthorized or misconfigured IPv6 router advertisements can be sent by any device on the local segment, whether a rogue device or simply a misconfigured host with IPv6 forwarding accidentally enabled, and clients that accept these advertisements may end up with the wrong default gateway or prefix information. This can silently break connectivity for affected clients in ways that are easy to misattribute to other causes if IPv6 is not actively being monitored. Mitigations include RA guard features on switches that filter router advertisements from unauthorized ports.

Submit

5. A SIEM correlates a failed login from an unusual country, followed minutes later by a successful login from that same account using a different unusual location, followed by an unusual data export. Which two conclusions are reasonable? (Select two.)

Explanation

The specific sequence of a failed login, a subsequent successful login from an unusual location, and then an unusual data export together form a pattern strongly consistent with a compromised credential being used to exfiltrate data, even though any single event alone might not warrant urgent action. This is exactly the value that correlation across multiple events and sources provides over reviewing isolated logs, which is why SIEM platforms are built around correlating exactly these kinds of multi-step patterns. A single failed login alone is common and often benign, such as a simple typo, so it does not by itself prove compromise.

Submit

6. An engineer needs to inspect the details of a TLS certificate presented by a remote server, including its expiration date and issuing authority, directly from the command line. Which tool is well suited to this task?

Explanation

OpenSSL includes commands for connecting to a remote server and displaying the details of the TLS certificate it presents, including validity dates, subject and issuer information, and the certificate chain. Nmap is primarily used for port and service scanning rather than detailed certificate inspection, though some of its scripts can retrieve certificate data as well. Netcat and arp serve simple connectivity testing and local address resolution purposes respectively, neither of which parses certificate details.

Submit

7. A previously stable application suddenly becomes unreachable right after a maintenance window. According to the troubleshooting methodology, what is one of the most valuable early questions to ask?

Explanation

Determining what changed recently is one of the most direct ways to identify a probable cause, since a sudden failure immediately following a maintenance window strongly suggests the change itself introduced the problem. This focuses the investigation on reviewing the specific changes made during that window rather than searching broadly across the entire environment. This step is explicitly called out in the troubleshooting methodology as part of gathering information before forming a theory of probable cause.

Submit

8. After an incident is detected, a team spends time determining its scope and root cause before beginning actual repair work. The metric that measures the average duration of this investigation phase specifically is Mean Time To ____.

Explanation

Mean Time To Investigate measures the average time spent understanding an incident's scope and root cause after it has already been detected, which is a distinct phase from detection itself and from the repair phase measured by Mean Time To Recovery. Tracking this metric separately helps a team identify whether incidents are slow to resolve because of slow detection, slow investigation, or slow repair, each of which points to different improvement opportunities. Runbooks and better tooling for correlating logs and metrics are common ways organizations reduce MTTI over time.

Submit

9. A team writing infrastructure as code templates wants to catch syntax errors and style violations in their YAML files automatically before the code is ever applied to real infrastructure. Which two practices support this goal? (Select two.)

Explanation

Running a linter automatically catches syntax errors and style violations in code, including YAML-based infrastructure as code templates, before they are ever merged or applied to real infrastructure. Validating templates against a defined ruleset as part of the pipeline, before changes reach production, catches problems when they are cheapest and safest to fix. Applying untested templates directly to production first inverts the intended safety benefit of catching errors early, and removing code review does nothing to catch the syntax and style issues a linter is specifically designed to find.

Submit

10. A network carrying both voice calls and bulk file transfers on the same links begins experiencing choppy audio during peak usage, even though total bandwidth utilization has not yet reached 100%. Which technology is designed to prioritize the voice traffic over bulk transfers during contention?

Explanation

QoS mechanisms classify and prioritize traffic types, ensuring latency-sensitive traffic like voice is given preferential treatment over less time-sensitive bulk transfers whenever contention for bandwidth occurs. Without QoS, all traffic competes equally for available bandwidth, which can cause exactly the kind of choppy audio described here even before links are fully saturated. SNMP polling and dashboards support visibility into the problem but do not themselves change how traffic is prioritized.

Submit

11. A network team maintains a document that lists identified risks, their likelihood and impact, the chosen response strategy for each, and the owner responsible for tracking it. What is this document called?

Explanation

A risk register is a structured record of identified risks along with their assessed likelihood, potential impact, chosen treatment strategy, and an assigned owner, which supports ongoing risk management rather than a one-time assessment. It differs from a runbook, which documents step-by-step operational procedures rather than tracking risk exposure over time. Regularly reviewing and updating a risk register helps an organization ensure that accepted risks remain acceptable as circumstances change.

Submit

12. A security team requires that logs from network appliances be sent off the device to a centralized collector immediately, rather than only being retained locally where an attacker who compromises the device could delete them. This practice is called ____ logging.

Explanation

Remote logging sends log data off the originating device to a centralized collector in near real time, which protects the integrity of the logs even if the device itself is later compromised and its local logs are deleted or altered by an attacker. This is a critical hardening and forensic readiness practice, since local-only logs can simply disappear along with any evidence of how a device was compromised. Log rotation, by contrast, manages how long logs are retained and how they are archived locally, which is a related but distinct concern from where they are ultimately sent.

Submit

13. Match each encryption-related wireless term to its correct description.

Explanation

AES is the underlying symmetric encryption algorithm that both WPA2 and WPA3 rely on to protect wireless data in transit. WPA2 has been the dominant wireless security standard for many years and remains widely deployed, though it is gradually being replaced. WPA3 improves on WPA2 primarily by strengthening the handshake process against offline dictionary attacks and by requiring stronger baseline protections, which is why new deployments are increasingly standardizing on it where client compatibility allows.

Submit

14. A user reports they can see the wireless network name and successfully connect, but cannot reach any websites, while a colleague on the same access point browses normally. Framing this in OSI terms, connectivity most likely exists at Layer ____ but fails higher up the stack. Which layer is most likely the working baseline here?

Explanation

Successfully associating with an access point confirms that at least Layer 1 and Layer 2 connectivity are functioning, since the device completed the wireless association process. The failure to reach websites could then originate anywhere from Layer 3 addressing and routing up through Layer 7 application issues, such as a DNS problem or a captive portal not yet accepted. Using the OSI model to reason about which layers are confirmed working versus still unverified is a core troubleshooting technique.

Submit

15. A company wants to consolidate secure web gateway, cloud access security broker, and Zero Trust network access capabilities into a single cloud-delivered security service, without the full networking components that a broader converged offering would include. What is this narrower security-focused offering called?

Explanation

SSE represents the security-focused subset of the broader SASE model, bundling capabilities like secure web gateway, CASB, and Zero Trust network access into a single cloud-delivered service, without necessarily including the WAN optimization and networking components that a full SASE offering combines. This lets organizations adopt converged security capabilities even if they manage their WAN connectivity separately. SD-WAN instead focuses on the networking and path-selection side, which SSE is explicitly narrower than.

Submit

16. A security team is configuring a next-generation firewall to permit only explicitly approved outbound destinations for a highly restricted server, and to decrypt outbound TLS sessions to those destinations for inspection. Which two configurations accomplish this? (Select two.)

Explanation

An allow list, sometimes called a default-deny approach, is the appropriate model for a highly restricted server, since it only permits explicitly approved destinations rather than trying to enumerate every possible bad destination through a block list. Applying decryption rules specifically to the approved outbound sessions then allows the firewall to inspect the actual payload for policy violations or data exfiltration, rather than only seeing opaque encrypted traffic. A block list model, by contrast, defaults to allowing everything not specifically denied, which is a much weaker security posture for a highly restricted system.

Submit

17. A VPN tunnel setup process uses one algorithm type to securely exchange a shared session key between two parties who have never communicated before, and then switches to a much faster algorithm type to encrypt the actual bulk data using that now-shared key. Which two algorithm types are being described, in order?

Explanation

Asymmetric encryption, using separate public and private keys, is well suited to securely establishing a shared secret between two parties without a prior shared key, but it is computationally expensive for bulk data. Once that shared symmetric key is established, the much faster symmetric encryption takes over for encrypting the actual data flow, since both sides now hold the same key. This hybrid approach, combining asymmetric key exchange with symmetric bulk encryption, is the standard design used by protocols like TLS and IPSec.

Submit

18. A vulnerability scan flags a network appliance running firmware that was released four years ago and no longer receives security updates from the vendor. What is the most appropriate classification and response?

Explanation

A device running long-outdated firmware with no further vendor updates represents a known, often well-documented risk rather than an unknown zero-day, and it should be prioritized for patching, replacement, or additional compensating controls such as network segmentation if it cannot be immediately replaced. Ignoring it as a false positive would leave a genuine, exploitable gap in the environment. Tracking device firmware versions against vendor end-of-life and end-of-support dates helps organizations plan replacements proactively rather than reactively.

Submit

19. A multi-floor office building has a central telecommunications room on the ground floor connecting to smaller telecommunications closets on each upper floor, which in turn connect to wall jacks on that floor. What are the ground floor room and the upper-floor closets called, respectively?

Explanation

The main distribution frame is typically the central point where external connectivity and core building cabling terminate, often located centrally such as on the ground floor. Intermediate distribution frames are the smaller, per-floor or per-area cross-connect points that extend cabling from the MDF out to individual wall jacks and end-user devices. Proper cable management within both the MDF and IDFs is important for maintainability, airflow, and reducing the risk of accidental disconnections during future changes.

Submit

20. A data center's cooling capacity is measured and specified in a unit that represents the amount of heat that must be removed per hour, commonly abbreviated ____.

Explanation

British Thermal Units measure the heat load that cooling systems must remove to keep a data center within safe operating temperature and humidity ranges for its equipment. Underestimating BTU requirements during design can lead to overheating as equipment density increases over time, which is why cooling capacity planning is closely tied to projected rack density. Environmental monitoring for temperature and humidity works alongside adequately sized cooling infrastructure to protect hardware reliability.

Submit

21. A server needs both increased bandwidth beyond what a single network interface provides and resilience if one of its network cables fails. Which technology combines multiple physical links into one logical link to achieve both goals?

Explanation

Link aggregation, such as with LACP, bundles multiple physical NICs and cables into a single logical link, which both increases available bandwidth and provides redundancy since traffic can continue over the remaining links if one physical connection fails. A CDN instead distributes cached content geographically closer to end users, which is unrelated to a single server's local link redundancy. Global load balancing distributes traffic across multiple sites or data centers rather than aggregating a single server's network interfaces.

Submit

22. A company wants its virtual machines to reach a cloud provider's managed database service over the provider's private backbone network, without that traffic ever traversing the public internet, even though the database has a public endpoint available. Which connectivity option fits this requirement?

Explanation

Private link and service endpoint features let a virtual network reach specific managed cloud services over the provider's own private backbone, avoiding the public internet entirely even when a public endpoint also exists for that service. This reduces exposure to internet-based threats and can also improve performance and consistency of the connection. A site-to-site VPN encrypts traffic but still traverses the public internet as its underlying transport, which is a different guarantee than staying entirely on a private backbone.

Submit

23. Match each environment type to its correct description.

Explanation

Production environments serve real users and carry the business impact of any outage or performance issue, which is why changes to production typically go through the most rigorous change management and testing. Non-production environments, including development, testing, and staging, exist specifically to validate changes before they are ever exposed to real users or business-critical workloads. Clearly separating these environments, often through distinct network segments, is a foundational design practice that limits the blast radius of a mistake made during development or testing.

Submit

24. A network with only two routers and a single, unchanging path between them is being redesigned, while a separate multi-path data center fabric needs to automatically adapt if a link fails. Which two routing choices, respectively, fit these two scenarios? (Select two.)

Explanation

A static route is well suited to a simple topology with a single, unchanging path, since there is no need for the overhead of a dynamic protocol to compute a route that will never change. A dynamic routing protocol such as OSPF is better suited to a multi-path fabric, since it can automatically recalculate routes if a link or path fails, maintaining connectivity without manual intervention. Using a dynamic protocol on a trivially simple topology, or a static route on a complex, failure-prone fabric, would be a mismatch between the tool and the actual requirement.

Submit

25. An organization is planning IPv6 addressing for a new data center and needs a compact way to express a network prefix such as the first 48 bits of an address being fixed for routing while the rest is available for subnetting. Which notation expresses this?

Explanation

IPv6 addressing uses CIDR-style prefix notation, such as /48, to indicate how many leading bits are fixed for routing, leaving the remaining bits available for further subnetting within the organization. Dotted-decimal subnet masks are an IPv4-specific convention and are not used to express IPv6 prefixes. Understanding IPv6 prefix notation is essential for any organization planning a hierarchical IPv6 addressing scheme across multiple sites or subnets.

Submit
×
Saved
Thank you for your feedback!
View My Results
Cancel
  • All
    All (25)
  • Unanswered
    Unanswered ()
  • Answered
    Answered ()
An organization wants new employee accounts, group memberships, and...
Users near a specific area of an office report weak Wi-Fi signal that...
A WAN link consistently runs near 100% utilization during business...
After enabling IPv6 on a network, some clients begin receiving...
A SIEM correlates a failed login from an unusual country, followed...
An engineer needs to inspect the details of a TLS certificate...
A previously stable application suddenly becomes unreachable right...
After an incident is detected, a team spends time determining its...
A team writing infrastructure as code templates wants to catch syntax...
A network carrying both voice calls and bulk file transfers on the...
A network team maintains a document that lists identified risks, their...
A security team requires that logs from network appliances be sent off...
Match each encryption-related wireless term to its correct...
A user reports they can see the wireless network name and successfully...
A company wants to consolidate secure web gateway, cloud access...
A security team is configuring a next-generation firewall to permit...
A VPN tunnel setup process uses one algorithm type to securely...
A vulnerability scan flags a network appliance running firmware that...
A multi-floor office building has a central telecommunications room on...
A data center's cooling capacity is measured and specified in a unit...
A server needs both increased bandwidth beyond what a single network...
A company wants its virtual machines to reach a cloud provider's...
Match each environment type to its correct description.
A network with only two routers and a single, unchanging path between...
An organization is planning IPv6 addressing for a new data center and...
play-Mute sad happy unanswered_answer up-hover down-hover success oval cancel Check box square blue
Alert!