1
Appendix D
CompTIA Network+ Practice Exam
The following exam contains questions that are similar in content and format to the
multiple-choice questions you will encounter on CompTIA’s Network+ N10-007
certification exam, released in 2018. This practice exam consists of 100 questions, all of
which are multiple choice. Some questions have more than one correct answer. The
number of questions from each domain reflects the weighting that CompTIA assigned to
these domains in its exam objectives. To simulate taking the CompTIA Network+
certification exam, allow yourself 90 minutes to answer all the questions.
1. To ensure that your private network is always protected, you decide to install
three redundant firewalls. Which of the following would allow you to assign
the same IP address to all three?
a. SMTP
b. CARP
c. SNMPv3
d. IMAP
e. NTP
2. What type of network could use the type of connector shown here?
2
a. 1000Base-LX
b. 10GBase-T
c. 100Base-T
d. 1000Base-T
e. 5GBase-T
3. While troubleshooting a workstation connectivity problem, you enter the
following command: ping 127.0.0.1. The response indicates the test failed.
What can you determine about that workstation?
a. Its network cable is faulty or not connected to the wall jack.
b. Its TCP/IP stack is not installed properly.
c. It has been prevented from transmitting data past the default gateway.
d. Its DHCP settings are incorrect.
e. Its DNS name server specification is incorrect.
4. You have been asked to help improve network performance on a store’s
small office network. The network relies on two switches, two access points,
and a router to connect its 18 employees to the Internet and other store
locations. You decide to determine what type of traffic the network currently
3
handles. In particular, you’re interested in the volume of unnecessary
broadcast traffic that might be bogging down shared segments. Which of the
following tools will help you identify the percentage of traffic made up of
broadcasts?
a. Port scanner
b. OTDR
c. Protocol analyzer
d. Multimeter
e. Cable tester
5. Which of the following standards describes a security technique, often used
on wireless networks, in which a port is prevented from receiving traffic until
the transmitter’s credentials are verified by an authentication server?
a. EAPoL
b. SSH
c. RADIUS
d. Kerberos
e. CCMP
6. Which of the following ports would be used during a domain name lookup?
4
a. 22
b. 23
c. 53
d. 110
e. 443
7. You are configuring a connection between two backbone switches, and you
want to make sure the connection doesn’t fail or become overwhelmed by
heavy traffic. Which of the following techniques would help you achieve both
aims?
a. Round-robin DNS
b. CARP
c. Clustering
d. Trunking
e. NIC teaming
8. As a network admin, you have decided to install additional physical security
to the main office’s data room. Due to the sensitivity of the data held in this
room, you decide it’s critical to ensure two-factor authentication before
granting anyone access to the room. You already have a lock on the door.
Which of the following physical security measures would provide 2FA?
5
a. Smart badge
b. Fingerprint scanner
c. Key fob
d. Video surveillance
e. Proximity card
9. You have installed and configured two virtual web servers and a virtual mail
server on a physical server. What networking mode will you assign to each
server’s vNIC to ensure that the virtual machines’ clients on the Internet can
access the virtual machines?
a. NAT
b. Bridged
c. Host-only
d. Internal
e. Grouped
10. At the beginning of the school year, students at your school must configure
their computers and other devices to obtain trusted access to the student
portion of the school’s network. What is this process called?
a. Authenticating
6
b. Remote wiping
c. Associating
d. Onboarding
e. Social engineering
11. When using NAT, how does an IP gateway ensure that outgoing traffic can
traverse public networks?
a. It modifies each outgoing frame’s Type field to indicate that the
transmission is destined for a public network.
b. It assigns each outgoing packet a masked ID via the Options field.
c. It replaces each outgoing packet’s Source address field with a public IP
address.
d. It interprets the contents of outgoing packets to ensure that they contain no
client-identifying information.
e. It modifies the frame length to create uniformly sized frames, called cells,
which are required for public network transmission.
12. Which of these authentication techniques only encrypts the password when
transmitting sign-in credentials?
a. RADIUS
7
b. TACACS+
c. Kerberos
d. Single sign-on
e. Local authentication
13. You are a networking technician in a radiology clinic, where physicians use
the network to transmit and store patients’ diagnostic results. Shortly after a
new wing, which contains X-ray and MRI (magnetic resonance imaging)
machines, is added to the building, computers in that area begin having
intermittent problems saving data to the file server. After you have gathered
information, identified the symptoms, questioned users, and determined
what has changed, what is your next step in troubleshooting this problem?
a. Establish a plan of action to resolve the problem.
b. Escalate the problem.
c. Document findings, actions, and outcomes.
d. Establish a theory of probable cause.
e. Implement the solution.
14. The software on a firewall you recently installed on your network examines
each incoming packet. It blocks or allows traffic based on a set of criteria,
including source IP address, source and destination ports, and protocols.
What type of system is this? Choose all that apply.
a. Content-filtering firewall
b. Stateful firewall
c. Stateless firewall
d. Packet-filtering firewall
e. Application layer firewall
15. Suppose you have created six subnets on a network that leases a group of
Class C IPv4 addresses. What subnet mask must you specify in your clients’
configurations to adhere to your subnetting scheme?
a. 255.255.255.6
b. 255.255.255.128
c. 255.255.255.192
d. 255.255.255.224
e. 255.255.255.0
9
16. What would the command route del default gw 192.168.5.1 eth1 accomplish
on your Linux workstation?
a. Delete the default gateway’s route to the host whose IP address is
192.168.5.1
b. Remove the assignment of IP address 192.168.5.1 from the eth1 interface
c. Remove the workstation’s route to the default gateway whose IP address
is 192.168.5.1
d. Add a route from the workstation to the default gateway whose IP address
is 192.168.5.1
e. Remove the designation of default gateway, but keep the route for the host
whose IP address is 192.168.5.1
17. From your laptop, you need to remote into a switch to make some
configuration changes. Which Transport-layer protocol and TCP/IP port
should you open in Windows Firewall to make this work using Telnet?
a. UDP, port 23
b. TCP, port 23
c. UDP, port 22
d. TCP, port 22
e. UDP, port 21
10
18. Recently, your company’s WAN experienced a disabling DDoS attack.
Which of the following devices could detect such an attack and prevent it
from affecting your network in the future?
a. A honeypot
b. SIEM
c. HIPS
d. HIDS
e. NIPS
19. Which of the following routing protocols offer fast convergence times and
can be used on both core and edge routers? Choose two.
a. RIPv2
b. ISIS
c. OSPF
d. BGP
e. EIGRP
20. A friend calls you for help with his home office Internet connection. He is
using an 802.11n wireless router connected to a DSL modem. The router’s
11
private IP address is 192.168.1.1 and it has been assigned an Internet
routable IP address of 76.83.124.35. Your friend cannot connect to any
resources on the Internet using his new Windows workstation. You ask him
to run the ipconfig command and read the results to you. He says his
workstation’s IP address is 192.168.1.3, the subnet mask is 255.255.255.0,
and the default gateway address is 192.168.1.10. What do you advise him to
do next?
a. Display his DNS information.
b. Change his gateway address.
c. Change his subnet mask.
d. Try pinging the loopback address.
e. Use the tracert command to contact the access point/router.
21. Your organization contracts with a cloud computing company to store some
backup data. The company promises 99.999% uptime. If it lives up to its
claims, what is the maximum number of minutes each year you can expect
your data to be unavailable?
a. Approximately 448 minutes
b. Approximately 199 minutes
c. Approximately 52 minutes
d. Approximately 14 minutes
12
e. Approximately 5 minutes
22. Ethernet and ATM both specify Data Link layer framing techniques. How do
they differ?
a. Ethernet uses CRC fields to confirm the validity of the frame, whereas
ATM uses no error detection.
b. Ethernet uses variably sized packets, whereas ATM uses fixed-sized cells.
c. Ethernet uses synchronous transmission, whereas ATM uses asynchronous
transmission.
d. Ethernet uses frame headers, whereas ATM does not.
e. Ethernet offers no guarantee of timely delivery, whereas ATM ensures
that packets are delivered within 10 ms.
23. What STP configuration ensures that a laptop connected to a switch cannot
alter the STP paths on the network?
a. BPDU filter
b. BPDU guard
c. Root bridge
d. BID
e. Designated port
13
24. What is the default subnet mask for the IP address 154.13.44.87?
a. 255.255.255.255
b. 255.255.255.0
c. 255.255.0.0
d. 255.0.0.0
e. 0.0.0.0
25. Your CFO has approved installing new backbone cabling on your school’s
campus. One of the buildings is particularly far away from the others, nearly
a kilometer. Which Ethernet standard will reach the distant building without
the use of a repeater?
a. 10GBase-T
b. 1000Base-LX
c. 1000Base-SX
d. 10GBase-SR
e. 1000Base-T
26. Which of the following is often used to secure data traveling over VPNs that
use L2TP?
14
a. PPTP
b. PPPoE
c. Kerberos
d. SSH
e. IPsec
27. You are a support technician working in a data closet in a remote office. You
suspect that a connectivity problem is related to a broken RJ-45 plug on a
patch cable that connects a switch to a patch panel. You need to replace that
connector, but you forgot to bring an extra patch cable. You decide to install
a new RJ-45 connector to replace the broken connector. Which tools must
you have in order to successfully accomplish this task? Choose two.
a. Punchdown tool
b. Crimper
c. Wire stripper
d. Cable tester
e. Multimeter
28. You have purchased an outdoor access point capable of exchanging data via
the 802.11n or 802.11ac wireless standard. According to these standards,
15
what is the maximum distance, in meters, from the access point that wireless
clients can travel and still reliably exchange data with the access point?
a. 20
b. 75
c. 100
d. 250
e. 450
29. Which of the following is a single sign-on authentication method?
a. IPsec
b. EAPoL
c. SSL
d. Kerberos
e. CHAP
30. Your organization has just ordered its first T1 connection to the Internet.
Prior to that, your organization relied on a DSL connection. Which of the
following devices must you now have that your DSL connection didn’t
require?
a. Modem
16
b. CSU/DSU
c. Switch
d. Hub
e. Router
31. Your friend’s printer isn’t printing the document she just sent it. In what
order should you perform the listed steps?
a. Follow the OSI model from bottom to top to check possible causes, send a
new document to the printer, determine if anything has changed on her
network.
b. Send a new document to the printer, follow the OSI model from bottom to
top to check possible causes, ask your friend when the problem started.
c. Take notes on the outcome, send a new document to the printer, determine
if anything has changed on her network.
d. Determine if anything has changed on her network, follow the OSI model
from bottom to top to check possible causes, send a new document to the
printer.
e. Determine if anything has changed on her network, take notes on the
outcome, send a new document to the printer.
17
32. A CEO fires her administrative assistant after the assistant was caught
stealing company funds. Over the weekend, the administrative assistant
hacks into the CEO’s private email account and steals some personal data.
What type of attack did the former employee most likely use to accomplish
this exploit?
a. Brute force attack
b. War driving
c. Logic bomb
d. Deauthentication
e. Man-in-the-middle
33. What is the network ID for a class C network that contains the group of IP
addresses from 194.73.44.10 through 194.73.44.254?
a. 194.73.44.0
b. 194.73.44.1
c. 194.73.0.0
d. 194.73.44.255
e. 194.1.1.1
18
34. Your organization is reassessing its WAN connections to determine how
much more bandwidth it will need to purchase in the next two years. As a
network administrator, which of the following data can you share that will
help management make the right decision?
a. Wiring schematic
b. Performance baselines
c. Logical network diagram
d. Syslogs
e. Change management documentation
35. You are creating a new Linux server as a virtual machine on your Windows
workstation. Which of the following commands will tell you the IP address
that is assigned to your virtual server?
a. ipconfig /all at the Windows workstation’s command prompt
b. ifconfig a at the Linux server’s shell prompt
c. iptables at the Linux server’s shell prompt
d. ping at the Windows workstation’s command prompt
e. ipconfig /all at the Linux server’s shell prompt
19
36. Which of the following requirements provide multifactor authentication?
Choose two.
a. Iris pattern and typing pattern.
b. Password and name of first elementary school
c. Location in a secured closet
d. Smart card and key fob
e. Fingerprint and name of first elementary school
Answer:
37. You are rearranging nodes on your Gigabit Ethernet network. Due to a
necessarily hasty expansion, you have decided to supply power to a wireless
router in a makeshift data room using PoE. What is the minimum cabling
standard you must use to connect this wireless router to the network’s
backbone?
a. RG-6
b. RG-59
c. Cat 5e
d. SMF
e. Cat 6
20
38. As you’re setting up APs in your client’s office space, you want to ensure that
all work areas and the meeting room have adequate access to the network.
What tool will give you the information you need?
a. Geofencing
b. Packet sniffer
c. Bandwidth speed tester
d. Wi-Fi analyzer
e. Toner probe
39. Which of the following protocols encapsulates data for transmission over
VPNs?
a. SFTP
b. L2TP
c. VNC
d. TCP
e. TACACS+
40. Which of the following is a valid MAC address?
a. C3:00:50:00:FF:FF