CompTIA CloudNetX CNX-001 (V1) Exam Practice Test 5

Reviewed by Editorial Team
The ProProfs editorial team is comprised of experienced subject matter experts. They've collectively created over 10,000 quizzes and lessons, serving over 100 million users. Our team includes in-house content moderators and subject matter experts, as well as a global network of rigorously trained contributors. All adhere to our comprehensive editorial guidelines, ensuring the delivery of high-quality content.
Learn about Our Editorial Process
| By Thames
T
Thames
Community Contributor
Quizzes Created: 11201 | Total Attempts: 9,875,275
| Questions: 25 | Updated: Sep 28, 2026
Please wait...
Question 1 / 26
🏆 Rank #-- ▾
0 %
0/100
Score 0/100

1. A security platform learns each user's typical login times, locations, and data access patterns, then flags an account when its behavior suddenly deviates significantly from that established baseline, even if valid credentials were used. What capability is this?

Explanation

UEBA establishes a behavioral baseline for users and entities over time and flags significant deviations from that baseline, which can catch compromised accounts or insider threats even when the credentials used are entirely valid and correctly authenticated. This adds a detection layer beyond simple authentication success or failure, since a stolen but valid credential would otherwise appear completely legitimate to traditional access controls. SSO instead simplifies the authentication experience across multiple applications but does not itself analyze behavior for anomalies.

Submit
Please wait...
About This Quiz
CompTIA CloudNetX Cnx-001 (V1) Exam Practice Test 5 - Quiz

This practice assessment focuses on the CompTIA CloudNetX CNX-001 (V1) exam, evaluating essential skills in cloud networking concepts, architecture, and security. It helps learners prepare effectively for certification by testing their knowledge on key topics relevant to cloud technologies and networking principles.

2.

What first name or nickname would you like us to use?

You may optionally provide this to label your report, leaderboard, or certificate.

2. A brand-new wireless access point supporting the latest Wi-Fi standard is deployed, but several older client devices in the building fail to connect at all, while newer devices connect without issue. What is the most likely explanation?

Explanation

Some older wireless client hardware may not support the newest Wi-Fi standards or the specific frequency bands and modulation schemes a new access point uses, resulting in an incompatibility where those older devices simply cannot associate at all, even though newer, fully compatible devices connect without any problem. This is a hardware capability mismatch rather than a configuration or security problem. Configuring the access point to also support legacy standards and bands, where the hardware allows it, or replacing incompatible legacy client devices, are the typical ways to resolve this.

Submit

3. A network appliance's CPU utilization climbs to 100% during a traffic spike, and it begins dropping packets and delaying processing across all connections, not just the ones associated with the spike. What is this condition called?

Explanation

Resource exhaustion occurs when a device's finite resources, such as CPU, memory, or a specific hardware table, are consumed to the point that it can no longer adequately service all of its workload, which explains why unrelated connections are affected alongside the traffic that triggered the spike. This differs from a targeted, connection-specific issue like an MTU mismatch, which would only affect traffic exceeding the mismatched size rather than degrading the device broadly. Addressing resource exhaustion typically involves scaling up device capacity, optimizing configuration to reduce unnecessary load, or adding additional devices to share the load.

Submit

4. After changing a DNS record to point a hostname to a new server, some users continue reaching the old server for several hours, even though the DNS record was verified correct at the authoritative server. What is the most likely explanation?

Explanation

DNS records include a time-to-live value that tells resolvers and clients how long they may cache a response before checking again, so users whose resolvers cached the old record before the change will continue receiving the stale answer until that cached entry expires. This is a very common and expected behavior during DNS changes, not necessarily an error, though it can be mitigated by lowering the TTL in advance of a planned change. Waiting out the cache expiration, or in urgent cases manually flushing caches on critical resolvers, are the typical ways to address this.

Submit

5. An engineer uses Postman to send a request to an internal REST API and receives a 401 response with a WWW-Authenticate header, whereas the same request worked yesterday. Which two next steps are reasonable? (Select two.)

Explanation

A 401 response specifically indicates an authentication problem, so checking whether the credential or token used has expired, been revoked, or otherwise become invalid is a direct and reasonable next step. It is also worth confirming whether the API's expected authentication method or header format changed on the server side, which would explain why a previously working request now fails. This kind of error says nothing about the overall network being down or the server's hardware failing, both of which would typically present very differently, such as a connection timeout rather than a clean 401 response.

Submit

6. An engineer wants to analyze historical NetFlow data that has already been collected over the past several days to identify a top-talker host that generated an unusual amount of traffic. Which tool is designed for querying and analyzing collected flow data like this?

Explanation

nfdump is designed specifically for querying and analyzing collected NetFlow data, including filtering and aggregating historical flow records to identify patterns such as top talkers or unusual traffic volumes. ping only tests live reachability and latency in real time and has no concept of historical flow analysis. ifconfig and route display and configure local interface and routing table information respectively, neither of which analyzes previously collected flow data.

Submit

7. After applying a fix for a reported connectivity issue, an engineer confirms not only that the original symptom is resolved, but also checks that no other previously working functionality was broken by the change. What step in the troubleshooting methodology does this represent?

Explanation

Verifying full system functionality after implementing a fix confirms not just that the reported symptom is gone, but that the fix did not introduce any new side effects elsewhere in the system, which is a distinct and important step separate from simply confirming the original complaint is resolved. This step may also include implementing preventive measures so the same problem is less likely to recur. Skipping this verification step risks declaring victory on the original ticket while leaving a new, unreported problem behind.

Submit

8. A team identifies a risk they are willing to accept for a limited time due to a valid business reason, and formally documents that decision along with an expiration date for review. This formal documentation of an accepted risk is called a risk ____ or exception.

Explanation

A risk waiver or exception formally documents a conscious decision to accept a known risk for a defined period, typically including the business justification and an expiration or review date so the decision does not simply persist indefinitely without reconsideration. This differs from simply ignoring a known risk, since a waiver creates an auditable record of who accepted the risk and why. Tracking waivers alongside a broader risk register helps ensure accepted risks are periodically revisited rather than forgotten.

Submit

9. A network operations team is piloting a tool that can draft configuration snippets and summarize lengthy log output in natural language based on a plain-language request from an engineer. What category of technology does this represent?

Explanation

Generative AI tools can draft configuration snippets, summarize log data, and respond to natural-language requests, which is increasingly being incorporated into network operations tooling to reduce manual effort for common but time-consuming tasks. This is a distinct category from traditional deterministic automation, since generative AI output should still be reviewed by an engineer before being applied to production systems. As with any automation, appropriate change management and review processes remain important even when a tool assists in drafting the initial configuration or summary.

Submit

10. A network operations center wants a real-time visual display of key network health indicators, along with underlying continuous data streams feeding into automated alerting. Which two concepts, respectively, describe these two needs? (Select two.)

Explanation

Dashboards present a real-time, often highly visual summary of key metrics and health indicators, giving operators an at-a-glance view without needing to query raw data directly. Telemetry refers to the underlying continuous streams of data collected from devices and applications, which feed both those dashboards and automated alerting systems that trigger when specific conditions are met. SNMP walk is a specific polling operation for retrieving MIB data, not a dashboard itself, and STP and PAT serve entirely unrelated Layer 2 loop prevention and address translation functions.

Submit

11. Two organizations that need to interconnect their networks for a joint project sign a document specifically defining the security requirements and responsibilities for that interconnection, separate from their overall broader business services contract. What is this specific document called?

Explanation

An Interconnection Security Agreement specifically defines the security requirements, responsibilities, and technical controls governing a connection between two organizations' networks, which is a more focused and technical document than a broader Master Service Agreement covering the overall business relationship. An MSA typically establishes general terms for services provided between the parties, but does not necessarily go into the specific security controls required for a network interconnection. Having a dedicated ISA ensures both parties have explicitly agreed on security expectations before the interconnection is established.

Submit

12. A security review finds that a router's web-based management interface is reachable from any address on the internet, rather than being limited to a specific management subnet. The hardening practice that addresses this is ____ access to administrative interfaces.

Explanation

Restricting access to administrative interfaces limits which source addresses or networks may even attempt to reach a device's management plane, which significantly reduces the attack surface compared to leaving management interfaces reachable from anywhere, including the public internet. This is frequently implemented through a combination of access control lists, a dedicated out-of-band management network, or requiring a VPN connection before the management interface becomes reachable at all. Combined with strong authentication, this practice significantly reduces the likelihood of a successful attack against the device's management plane specifically.

Submit

13. Match each wireless authentication concept to its correct description.

Explanation

A standard PSK is simple to deploy but shares one static secret across every connecting client, meaning it must be changed everywhere at once if it is ever compromised. PSK enterprise, more precisely 802.1X-based enterprise authentication, instead authenticates each user or device individually against a backend server such as RADIUS, allowing one compromised or departing user's access to be revoked without affecting anyone else. Guest access intentionally provides a separate, more limited level of connectivity for visitors, which should be isolated from internal resources regardless of which underlying authentication method is used.

Submit

14. Several servers in a cluster show slightly different timestamps in their logs, making it difficult to correlate events across systems during an investigation. Which protocol, if properly configured, keeps all device clocks synchronized to a common reference?

Explanation

NTP synchronizes device clocks against a common time source, which is essential for accurately correlating logs and events across many systems during troubleshooting or forensic investigation. Without synchronized time, even a few seconds of drift between servers can make it very difficult to reconstruct the true sequence of events. LDAP, DHCP, and DNS serve directory lookups, address assignment, and name resolution respectively, none of which addresses clock synchronization.

Submit

15. A company wants to grant network access only to laptops that are centrally managed, have disk encryption enabled, and are running an approved, up-to-date operating system version, regardless of which user is logging in. Which Zero Trust concept does this directly reflect?

Explanation

Device trust evaluates the security posture of the endpoint attempting to connect, such as whether it is managed, encrypted, and running approved and current software, independently of which user credentials are being presented. This ensures that even valid user credentials cannot grant access from a device that does not meet the organization's security baseline. Identity as the perimeter instead emphasizes verifying who is connecting rather than the security state of the device they are connecting from, which is a complementary but distinct Zero Trust concept.

Submit

16. A company wants to prevent sensitive customer data from being copied to unauthorized USB drives on corporate laptops, and also wants to prevent unauthorized devices from being plugged into unused network switch ports. Which two controls address these two goals respectively? (Select two.)

Explanation

DLP controls can be configured to detect and block sensitive data patterns from being copied to unauthorized destinations, including removable media like USB drives, directly addressing the data exfiltration concern. Port security on switches restricts which devices, often identified by MAC address or by simply disabling unused ports, may connect and pass traffic, addressing unauthorized physical network access. Geolocation rules and content filtering address different concerns entirely, namely traffic origin and web content categories, neither of which controls USB usage or switch port access.

Submit

17. A company running workloads entirely in a public cloud wants firewall capability that is deployed and scaled elastically alongside its cloud resources, managed through the cloud provider's own control plane, rather than a traditional physical appliance. What should they deploy?

Explanation

A cloud-native firewall is purpose-built to integrate with a cloud provider's control plane, scaling elastically alongside the workloads it protects and being managed through the same cloud-native tooling the rest of the environment uses. A traditional hardware appliance would not fit this fully cloud-based deployment model at all, since there is no physical data center to ship it to. While a WAF addresses application-layer web threats specifically, it is narrower in scope than a full cloud-native firewall covering broader network traffic.

Submit

18. A disgruntled employee with legitimate access to sensitive financial data copies large amounts of it to a personal cloud storage account shortly before resigning. What threat category does this represent?

Explanation

An insider threat comes from someone who already has legitimate authorized access, such as an employee, and misuses that access for unauthorized purposes, which is exactly what is described here. This differs from external threats like evil twins or rogue access points, which involve an attacker who does not already hold legitimate credentials or access. DLP controls and closely monitoring unusual data movement, especially around employee departures, are common mitigations against this specific threat category.

Submit

19. A user walks across a large warehouse while using a handheld scanner connected to Wi-Fi, moving between the coverage areas of several access points on the same SSID without any noticeable disruption to their active session. What wireless capability enables this seamless transition?

Explanation

Wireless roaming allows a client device to hand off its connection from one access point to another as it physically moves, ideally with minimal or no disruption to active sessions, which is essential for mobile devices like handheld scanners moving through a large facility. This typically relies on consistent SSID and security configuration across access points, along with roaming-assistance features that help clients make faster, better-informed handoff decisions. Poorly tuned roaming thresholds can lead to problems such as sticky clients that fail to hand off promptly to a stronger nearby access point.

Submit

20. Two network interfaces on a Linux server are combined into a single logical interface to provide both increased throughput and failover if one physical link fails. This technique, similar to link aggregation, is commonly referred to on Linux systems as interface ____.

Explanation

Bonding combines multiple physical network interfaces into a single logical interface on a host, providing increased aggregate throughput and failover redundancy similar to switch-side link aggregation. It requires the connected switch ports to be configured compatibly, often using a matching aggregation protocol, for the bonded interface to function correctly end to end. This is commonly used on servers that require both higher bandwidth and resilience against a single NIC or cable failure.

Submit

21. A facility experiences a brief, complete loss of utility power lasting only a few seconds before it is restored. What type of power disruption is this?

Explanation

A blackout is a complete loss of power, which can range from a few seconds to an extended outage, distinguishing it from a brownout, which is a sustained reduction in voltage rather than a complete loss. Surges and spikes instead describe increases in voltage, either sustained or momentary, rather than a loss of power at all. Properly sized UPS systems are designed to bridge exactly this kind of brief blackout until generators or utility power are restored.

Submit

22. A cloud architecture places redundant application instances in two different availability zones within the same region to survive a single data center failure, and also plans a secondary deployment in a separate region entirely to survive a regional-scale disaster. Which two statements correctly describe this design? (Select two.)

Explanation

Availability zones are typically isolated at the physical facility level within one region, meaning a failure affecting one data center is unlikely to affect another zone in the same region, which protects against localized hardware or facility failures. A separate region, being geographically distant, protects against much larger-scale events, such as a natural disaster or a widespread regional outage, that could plausibly affect every availability zone within a single region simultaneously. Treating availability zones and regions as interchangeable would understate the additional protection a genuinely separate region provides against exactly this kind of large-scale event.

Submit

23. A team wants to deploy a modern VPN protocol known for a smaller codebase, simpler configuration, and strong default cryptography compared to older VPN protocols. Which protocol fits this description?

Explanation

WireGuard is a modern VPN protocol designed around a much smaller codebase than many legacy VPN implementations, which reduces the attack surface for security review, along with strong default cryptographic choices and simplified configuration compared to older, more complex VPN protocols. TACACS+ is an authentication, authorization, and accounting protocol for network device administration, not a VPN protocol. SNMP and STP serve network monitoring and Layer 2 loop prevention respectively, both unrelated to VPN tunneling.

Submit

24. Match each term to its correct description.

Explanation

A trusted zone typically houses internal systems and applies a comparatively higher default trust level, though Zero Trust principles push organizations to avoid relying on zone-based trust as the sole security control. An untrusted zone, most commonly representing the public internet, is treated with a low default trust level, requiring traffic from it to pass through additional inspection and access controls before reaching more sensitive zones. North-south traffic crosses this boundary between external and internal zones, which is why it typically receives more inspection than traffic that stays within a single trusted zone.

Submit

25. A network is transitioning toward IPv6 but must still allow IPv6-only clients to reach some legacy IPv4-only servers during the migration. Which two statements about NAT64 are correct in this scenario? (Select two.)

Explanation

NAT64 specifically translates between IPv6 and IPv4 addressing, which is exactly the transitional mechanism needed to let IPv6-only clients reach IPv4-only legacy servers during a phased migration. It is commonly deployed alongside DNS64, which synthesizes a special IPv6 address representing an IPv4-only destination so IPv6-only clients can resolve and reach it. NAT64 is unrelated to translating between two private IPv4 ranges, which would instead be a straightforward NAT or PAT translation entirely within the IPv4 address family.

Submit
×
Saved
Thank you for your feedback!
View My Results
Cancel
  • All
    All (25)
  • Unanswered
    Unanswered ()
  • Answered
    Answered ()
A security platform learns each user's typical login times, locations,...
A brand-new wireless access point supporting the latest Wi-Fi standard...
A network appliance's CPU utilization climbs to 100% during a traffic...
After changing a DNS record to point a hostname to a new server, some...
An engineer uses Postman to send a request to an internal REST API and...
An engineer wants to analyze historical NetFlow data that has already...
After applying a fix for a reported connectivity issue, an engineer...
A team identifies a risk they are willing to accept for a limited time...
A network operations team is piloting a tool that can draft...
A network operations center wants a real-time visual display of key...
Two organizations that need to interconnect their networks for a joint...
A security review finds that a router's web-based management interface...
Match each wireless authentication concept to its correct description.
Several servers in a cluster show slightly different timestamps in...
A company wants to grant network access only to laptops that are...
A company wants to prevent sensitive customer data from being copied...
A company running workloads entirely in a public cloud wants firewall...
A disgruntled employee with legitimate access to sensitive financial...
A user walks across a large warehouse while using a handheld scanner...
Two network interfaces on a Linux server are combined into a single...
A facility experiences a brief, complete loss of utility power lasting...
A cloud architecture places redundant application instances in two...
A team wants to deploy a modern VPN protocol known for a smaller...
Match each term to its correct description.
A network is transitioning toward IPv6 but must still allow IPv6-only...
play-Mute sad happy unanswered_answer up-hover down-hover success oval cancel Check box square blue
Alert!