1. A technician needs to identify which hosts on a /24 subnet have port 3389 (RDP) open before applying a security patch. Which nmap command would BEST accomplish this?
Network Troubleshooting
A.nmap -p 3389 192.168.1.0/24
B.nmap -sL 192.168.1.0/24
C.nmap --traceroute 192.168.1.1
D.nmap -sn 192.168.1.0/24
Show answerAnswer
A. nmap -p 3389 192.168.1.0/24
The -p flag in nmap specifies a target port to scan, and providing a CIDR range like /24 scans all hosts in that subnet for that specific port's status. This directly identifies which hosts have RDP (port 3389) open.
2. A network engineer configures an internal NTP server that receives its time directly from a GPS receiver connected via a serial cable. This internal server then distributes time to all other devices on the corporate network. What stratum level is this internal NTP server?
Network Operations
A.Stratum 2
B.Stratum 0
C.Stratum 1
D.Stratum 3
Show answerAnswer
C. Stratum 1
Stratum 0 devices are the reference clocks themselves (such as GPS or atomic clocks) and do not communicate on the network. A server directly connected to a stratum 0 source, like this GPS-linked server, is stratum 1. Devices that then sync from this server become stratum 2.
3. Three OSPF routers are connected to the same Ethernet multiaccess segment. Which mechanism does OSPF use on this segment to reduce the number of adjacencies formed and minimize routing update traffic?
Network Implementation
A.Use of passive interfaces
B.Election of a Designated Router (DR) and Backup Designated Router (BDR)
C.Manual adjustment of interface cost
D.Configuration of route reflectors
Show answerAnswer
B. Election of a Designated Router (DR) and Backup Designated Router (BDR)
On multiaccess networks, OSPF elects a DR and BDR so that other routers form full adjacencies only with the DR/BDR instead of with every neighbor, drastically reducing the number of adjacencies and the volume of link-state advertisements exchanged.
4. A technician needs to verify that a domain's mail exchange (MX) records are correctly configured and also wants to see the authoritative name server response directly, bypassing local resolver cache. Which tool is BEST suited for this task?
Network Troubleshooting
A.tracert
B.nslookup
C.ping
D.dig
Show answerAnswer
D. dig
The dig command provides detailed, low-level DNS query information, including the ability to query a specific authoritative name server directly and view all record types such as MX records, making it more powerful and flexible than nslookup for this scenario.
5. An edge router receives the same route to 203.0.113.0/24 from two BGP neighbors. All BGP path attributes are equal except the AS_PATH attribute: one route has AS_PATH '65010 65020 65030' and the other has AS_PATH '65010 65040'. Assuming no other tie-breakers apply first, which route will BGP select as the best path?
Network Implementation
A.The route with the lower next-hop IP address is always chosen regardless of AS_PATH
B.Both routes are installed for load balancing since AS_PATH length is not a factor
C.The route with AS_PATH '65010 65040', because it has the shorter AS path length
D.The route with AS_PATH '65010 65020 65030', because it has more hops for stability
Show answerAnswer
C. The route with AS_PATH '65010 65040', because it has the shorter AS path length
BGP's path selection process prefers routes with a shorter AS_PATH length, as this typically indicates fewer autonomous systems traversed. The path '65010 65040' has 2 AS hops compared to 3 for '65010 65020 65030', making it the preferred route when other attributes like local preference and weight are equal.
6. A technician is terminating multiple Cat 6 cables from a wiring closet into a 48-port patch panel. Which tool is required to properly seat each wire into the IDC connectors on the back of the patch panel?
Network Implementation
A.Cable crimper
B.Toner probe
C.OTDR
D.Punch-down tool
Show answerAnswer
D. Punch-down tool
A punch-down tool is used to press individual wires into the insulation-displacement connectors (IDCs) on a patch panel or keystone jack, cutting the insulation and making the electrical connection. A crimper is used for RJ45 plugs, a toner probe traces cables, and an OTDR tests fiber optic links.
7. A network administrator wants a single Layer 3 switch to route traffic between VLAN 10, VLAN 20, and VLAN 30 using only one physical interface connected to a Layer 2 switch trunk. Which configuration approach should the administrator use?
Network Implementation
A.Enable port security on the single trunk interface to separate VLAN traffic
B.Configure the single interface as an access port and assign it to VLAN 10 only
C.Configure a router-on-a-stick using subinterfaces, each assigned to a VLAN and given an IP address
D.Configure three separate physical interfaces, one per VLAN, all in access mode
Show answerAnswer
C. Configure a router-on-a-stick using subinterfaces, each assigned to a VLAN and given an IP address
Router-on-a-stick uses a single physical trunk interface divided into logical subinterfaces (e.g., Gi0/0.10, Gi0/0.20), each tagged for a specific VLAN with 802.1Q encapsulation and assigned an IP address to act as that VLAN's gateway, enabling inter-VLAN routing over one physical link.
8. A company is allocated the network 192.168.10.0/24 and needs to create subnets that each support at least 50 hosts while wasting as few addresses as possible. Which subnet mask should be used?
Networking Concepts
A.255.255.255.128
B.255.255.255.192
C.255.255.255.240
D.255.255.255.224
Show answerAnswer
B. 255.255.255.192
To support 50 hosts, at least 6 host bits are needed since 2^6 - 2 = 62 usable addresses (2^5 - 2 = 30 is insufficient). Borrowing 2 bits from the host portion of a /24 gives a /26 mask (255.255.255.192), which provides 62 usable hosts per subnet, the smallest block that satisfies the requirement.
9. A small office wants a topology where every workstation connects directly to a central switch, and the failure of one cable only affects that single device. Which topology is being described?
Networking Concepts
A.Full mesh
B.Bus
C.Star
D.Ring
Show answerAnswer
C. Star
In a star topology, each device has an individual link to a central device (switch or hub). A cable failure only isolates that one device, unlike bus or ring topologies where a single failure can disrupt the entire segment.
10. An attacker positions a laptop between a victim and a legitimate website using a rogue access point, then intercepts the victim's HTTPS session and forces the browser to communicate over unencrypted HTTP instead, silently capturing login credentials. Which attack technique is being used?
Network Security
A.Deauthentication attack
B.MAC flooding
C.DNS cache poisoning
D.SSL stripping (on-path downgrade attack)
Show answerAnswer
D. SSL stripping (on-path downgrade attack)
SSL stripping is an on-path (man-in-the-middle) technique where the attacker intercepts traffic and downgrades the victim's connection from HTTPS to HTTP, allowing credentials and data to be captured in plaintext while the victim is often unaware the encryption was removed. This differs from deauth attacks, which simply disconnect clients, and MAC flooding, which targets switch CAM tables.
11. A workstation is manually configured with a valid IP address, subnet mask, and DNS server. Users can access other devices on the local subnet but cannot reach any external websites. Which missing configuration setting most likely explains this issue?
Networking Concepts
A.Default gateway
B.Loopback address
C.MAC address
D.DHCP lease time
Show answerAnswer
A. Default gateway
The default gateway is the router interface a device uses to send traffic destined for networks outside its local subnet. Without it, a host can only communicate with devices on its own subnet, matching the described symptoms.
12. A network administrator increases the MTU on a core router interface to 9000 bytes for jumbo frame support, but forgets to update an edge switch, which remains at the default 1500-byte MTU. Users report that small file downloads work fine, but large file transfers across this path consistently fail or hang. What is the MOST likely explanation?
Network Troubleshooting
A.An MTU mismatch causing fragmentation or packet drops for large packets
B.A duplex mismatch between the router and switch
C.An expired DHCP lease on the client's fragmentation router
D.DNS caching an outdated record for the file server
Show answerAnswer
A. An MTU mismatch causing fragmentation or packet drops for large packets
When devices along a path have mismatched MTU settings, packets larger than the smallest MTU in the path may be dropped (if fragmentation is disabled, such as with the Don't Fragment flag) or require fragmentation, which some paths mishandle, causing large transfers to hang while small packets pass fine.
13. A technician is troubleshooting poor Wi-Fi performance in a small office. A Wi-Fi analyzer shows three access points operating on channels 3, 7, and 10 in the 2.4GHz band. What is the MOST likely cause of the performance issues?
Network Troubleshooting
A.The access points are using non-overlapping channels
B.The access points are causing adjacent channel interference
C.The access points are set to different SSIDs
D.The access points are transmitting at too low a power level
Show answerAnswer
B. The access points are causing adjacent channel interference
In the 2.4GHz band, only channels 1, 6, and 11 are truly non-overlapping. Channels 3, 7, and 10 overlap with neighboring channels, causing adjacent channel interference and degraded performance. The fix is to reconfigure the APs to use 1, 6, or 11.
14. An organization is redesigning its network security model based on the principle that no user or device should be automatically trusted, regardless of whether they are inside or outside the corporate network perimeter. Which security concept is being implemented?
Networking Concepts
A.Perimeter-based security
B.Network segmentation
C.Defense in depth
D.Zero trust
Show answerAnswer
D. Zero trust
Zero trust is a security framework built on the principle of 'never trust, always verify,' requiring continuous authentication and authorization for every user and device regardless of network location, rather than assuming trust based on being inside the network perimeter.
15. A network technician is troubleshooting a client workstation that can access local network resources but cannot reach any external websites or services. The technician pings the local gateway, which responds successfully. Next, the technician attempts to ping 8.8.8.8 (Google's public DNS server) and receives 'Request timed out.' messages. Which of the following is the MOST likely cause of this issue?
Network Troubleshooting
A.A firewall blocking outbound traffic on the network.
B.The workstation's network interface card (NIC) is faulty.
C.Incorrect subnet mask configuration on the workstation.
D.The local DHCP server is offline.
Show answerAnswer
A. A firewall blocking outbound traffic on the network.
The workstation can reach the local gateway, indicating local network connectivity is fine. The inability to ping an external IP address (8.8.8.8) but successful ping of the gateway strongly suggests that outbound traffic is being blocked beyond the local subnet, commonly by a firewall.
16. A network administrator is deploying an SNMP-based monitoring solution across the enterprise. Management requires that all polling traffic between the network management station and managed devices be both encrypted and authenticated with per-user credentials. Which SNMP version should the administrator implement?
Network Operations
A.RMON
B.SNMPv3
C.SNMPv2c
D.SNMPv1
Show answerAnswer
B. SNMPv3
SNMPv3 is the only version that supports message authentication and encryption (privacy) along with per-user security models, unlike v1 and v2c which rely on plaintext community strings.
17. A small business has only one public IP address but needs to allow dozens of internal devices to access the internet simultaneously. Which technology allows all devices to share the single public IP by distinguishing sessions with different port numbers?
Networking Concepts
A.PAT (Port Address Translation)
B.Static NAT
C.Dynamic NAT
D.Anycast
Show answerAnswer
A. PAT (Port Address Translation)
PAT (also called NAT overload) allows many internal private IP addresses to share a single public IP by mapping each session to a unique port number, making it ideal for small networks with limited public addresses.
18. A network administrator is configuring an internal addressing scheme for a lab network that will never be routed on the public internet, similar in purpose to private IPv4 address ranges. Which IPv6 address type and prefix should be used?
Networking Concepts
A.Global unicast, 2000::/3
B.Multicast, ff00::/8
C.Unique local address, fc00::/7
D.Link-local, fe80::/10
Show answerAnswer
C. Unique local address, fc00::/7
Unique Local Addresses (ULA), defined by the fc00::/7 prefix, are the IPv6 equivalent of private IPv4 addressing (RFC 1918) and are intended for internal use, not routed on the public internet.
19. A hotel wants guest devices connected to the same VLAN and IP subnet to be completely unable to communicate with one another, while every guest device must still reach the internet gateway. Which switch feature should be configured to achieve this?
Network Security
A.Private VLAN (protected/isolated ports)
B.802.1Q trunking
C.Spanning Tree Protocol
D.Link aggregation
Show answerAnswer
A. Private VLAN (protected/isolated ports)
Private VLANs (or protected/isolated switch ports) allow devices within the same VLAN and subnet to reach an uplink (like a gateway) while being blocked from communicating with each other at Layer 2, which is exactly the isolation needed for guest networks. Trunking, STP, and link aggregation serve unrelated purposes.
20. A user reports that their workstation is unable to connect to the network. The technician inspects the workstation and confirms that the network cable is securely plugged into both the workstation and the wall jack. The link lights on both the workstation's NIC and the switch port are unlit. Which of the following is the MOST likely cause?
Network Troubleshooting
A.The DHCP server is down.
B.Incorrect IP address assigned to the workstation.
C.A faulty network cable.
D.The workstation's operating system is corrupted.
Show answerAnswer
C. A faulty network cable.
Unlit link lights on both the NIC and the switch port, despite the cable being plugged in, indicate a complete lack of physical layer connectivity. The most common and simplest cause for this symptom is a faulty network cable.
21. A network administrator is troubleshooting an issue where a newly deployed VoIP phone system is experiencing frequent call drops and garbled audio. A packet capture reveals significant packet reordering and high jitter values. The network infrastructure consists of several switches and routers. Which of the following is the MOST likely cause of these symptoms?
Network Troubleshooting
A.Insufficient bandwidth on the network links.
B.Missing Quality of Service (QoS) configuration.
C.Incorrect VLAN assignments for VoIP traffic.
D.Duplex mismatch on a network switch port.
Show answerAnswer
B. Missing Quality of Service (QoS) configuration.
Frequent call drops, garbled audio, packet reordering, and high jitter are classic symptoms of real-time traffic (like VoIP) being negatively impacted by network congestion or inconsistent packet delivery. Missing QoS configuration means that VoIP traffic is not being prioritized over other, less time-sensitive traffic, leading to these issues in a busy network.
22. Employees in a warehouse report that their wireless connections drop intermittently throughout the day, and a spectrum analyzer shows a persistent high noise floor across the entire 2.4 GHz band with no identifiable data traffic pattern. No unauthorized SSIDs are detected. Which type of attack is most likely occurring?
Network Security
A.Rogue access point
B.RF jamming
C.Evil twin attack
D.MAC flooding
Show answerAnswer
B. RF jamming
RF jamming floods the wireless spectrum with noise or interference signals, raising the noise floor and disrupting legitimate Wi-Fi communication without necessarily broadcasting any SSID or exchanging data frames. Because no rogue SSID exists and the disruption is broadband, this points to physical-layer jamming rather than a spoofed access point.
23. A technician is troubleshooting a server that is intermittently losing network connectivity. The server is connected via a Cat 6 cable to a network switch. During inspection, the technician notices the cable runs parallel to a large, unshielded power conduit for approximately 15 meters. Which of the following is the MOST likely cause of the intermittent connectivity?
Network Troubleshooting
A.Excessive EMI/RFI.
B.Incorrect IP address configuration.
C.Duplex mismatch.
D.Near-end crosstalk (NEXT).
Show answerAnswer
A. Excessive EMI/RFI.
Running an unshielded network cable parallel to a large power conduit creates a strong potential for Electromagnetic Interference (EMI) or Radio Frequency Interference (RFI). This interference can corrupt data signals, leading to intermittent connectivity issues, packet loss, and performance degradation.
24. A technician is installing a PTZ security camera that requires 25.5W of power delivered over Ethernet at the powered device. Which PoE standard must the switch support to meet this requirement?
Network Implementation
A.Passive 24V PoE injector only
B.802.3af (PoE)
C.802.3at (PoE+)
D.802.3bt Type 3 only for lighting
Show answerAnswer
C. 802.3at (PoE+)
802.3at, also known as PoE+, supplies up to 30W at the power sourcing equipment, which delivers approximately 25.5W at the powered device after accounting for cable loss, making it suitable for higher-power devices like PTZ cameras.
25. Workstations in Building A, which share the same subnet as the DHCP server, receive IP addresses normally. Workstations in Building B, located across a router on a different subnet, fail to receive DHCP-assigned addresses. Static IP addressing works fine in Building B. What is the most likely cause?
Network Troubleshooting
A.The DHCP server's lease duration is set too short
B.Building B workstations have DNS servers misconfigured
C.The DHCP server's scope has been exhausted
D.The router interface facing Building B is missing a DHCP relay (IP helper) configuration
Show answerAnswer
D. The router interface facing Building B is missing a DHCP relay (IP helper) configuration
DHCP is a broadcast-based protocol, and broadcasts do not cross routers by default. A router must be configured with a DHCP relay agent (IP helper address) to forward DHCPDISCOVER broadcasts from a remote subnet to the DHCP server. Since Building A works and static addressing works in Building B, the DHCP server and physical connectivity are fine.
On multiaccess (broadcast) networks, OSPF elects a Designated Router and Backup Designated Router so all other routers only peer with them, reducing adjacency count.
Election based on OSPF priority, then highest Router ID
DROTHER routers don't form full adjacency with each other
To determine the subnet mask for a required number of hosts, find the smallest number of host bits h such that 2^h - 2 is greater than or equal to the required host count.
A man-in-the-middle technique where an attacker intercepts a session and forces communication to fall back from HTTPS to unencrypted HTTP to capture sensitive data.
Requires the attacker to be positioned in the traffic path (on-path/MITM)
Victim's browser may show HTTP instead of HTTPS without obvious warning
Mitigated by HSTS (HTTP Strict Transport Security)
A condition where devices along a network path have differing Maximum Transmission Unit settings, causing large packets to be dropped or improperly fragmented.
Default Ethernet MTU is 1500 bytes; jumbo frames use up to 9000 bytes
Symptom: small packets succeed, large packets fail or hang ('black hole' MTU issue)
Diagnosed with ping using specific packet sizes and the Don't Fragment flag
A security model in which no user, device, or system is trusted by default, even inside the network perimeter, requiring continuous verification for every access request based on identity, device health, and context.
Core principle: 'never trust, always verify'
Relies on least privilege access and micro-segmentation
Continuously authenticates and authorizes rather than trusting a single login
ULA addresses use the fc00::/7 prefix and provide private, non-internet-routable addressing for internal IPv6 networks, similar to RFC 1918 private IPv4 space.
Prefix range: fc00::/7 (commonly fd00::/8 in practice)
Not routable on the public internet
Analogous to IPv4 private addresses (10.x, 172.16.x, 192.168.x)
A configuration where hosts in the same VLAN/subnet can reach an uplink port but cannot communicate directly with each other, commonly used for guest Wi-Fi and hotel networks.
Also called isolated or protected ports
Preserves single subnet while blocking peer-to-peer traffic
Common use case: guest networks, hotel/hospitality Wi-Fi
Network mechanisms that ensure certain traffic types (e.g., VoIP, video) receive preferential treatment over others to guarantee performance requirements.
Prioritizes critical traffic to reduce latency, jitter, and packet loss.
Achieved through classification, marking, queuing, and policing.
Essential for real-time applications like VoIP and video conferencing.
Disruption of operation of an electronic device when it is in the vicinity of an electromagnetic field (EM field) in the radio frequency (RF) spectrum that is caused by another electronic device.
Can cause intermittent connectivity, data corruption, and signal degradation.
Sources include power lines, fluorescent lights, motors, and radio transmitters.
Mitigated by shielding cables, proper grounding, and physical separation.
Questions are original practice items written to match the published exam objectives. Step2Study is not affiliated with or endorsed by any certification body.