Pre-Summer Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: validbest

Pass the CompTIA CloudNetX CNX-001 Questions and answers with ValidTests

Exam CNX-001 All Questions
Exam CNX-001 Premium Access

View all detail and faqs for the CNX-001 exam

Viewing page 2 out of 3 pages
Viewing questions 11-20 out of questions
Questions # 11:

You are designing a campus network with a three-tier hierarchy and need to ensure secure connectivity between locations and traveling employees.

INSTRUCTIONS

Review the command output by clicking on the server, laptops, and workstations on the network.

Use the drop-down menus to determine the appropriate technology and label for each layer on the diagram. Options may only be used once.

Click on the magnifying glass to make additional configuration changes.

If at any time you would like to bring back the initial state of the simulation, please click the Reset All button.

Question # 11

Options:

Expert Solution
Questions # 12:

A company has a 40Gbps network that uses a network tap to inspect the traffic using an IDS. The IDS usually performs normally except when the servers are downloading patches from their local update repository 10.10.10.139 using HTTPS. During the patch windows, the IDS cannothandle the extra load and drops a significant number of packets. Which of the following would allow a network engineer to prevent this issue without compromising the network visibility?

Options:

A.

Configuring the IDS to ignore traffic from 10.10.10.139

B.

Using PF_RING offload to filter out "host 10.10.10.139 and port 443"

C.

Adding a "dst host 10.10.10.139" BPF on the tap

D.

Scheduling a cron job to stop the IDS service during the patch window

Expert Solution
Questions # 13:

A network engineer is installing new switches in the data center to replace existing infrastructure. The previous network hardware had administrative interfaces that were plugged into the existing network along with all other server hardware on the same subnet. Which of the following should the engineer do to better secure these administrative interfaces?

Options:

A.

Connect the switch management ports to a separate physical network.

B.

Disable unused physical ports on the switches to keep unauthorized users out.

C.

Set the administrative interfaces and the network switch ports on the same VLAN.

D.

Upgrade all of the switch firmware to the latest hardware levels.

Expert Solution
Questions # 14:

A cloud network engineer needs to enable network flow analysis in the VPC so headers and payload of captured data can be inspected. Which of the following should the engineer use for this task?

Options:

A.

Application monitoring

B.

Syslog service

C.

Traffic mirroring

D.

Network flows

Expert Solution
Questions # 15:

A company is experiencing multiple switch failures. The network analyst discovers the following:

    Network recovery time is unacceptable and occurs after the shutdown of some switches.

    Some loops were detected in the network.

    No broadcast storm was detected.

Which of the following is the most cost-effective solution?

Options:

A.

Add a new Layer 3 switch.

B.

Add multiple VLANs.

C.

Implement STP.

D.

Implement tagging.

Expert Solution
Questions # 16:

End users are getting certificate errors and are unable to connect to an application deployed in a cloud. The application requires HTTPS connection. A network solution architect finds that a firewall is deployed between end users and the application in the cloud. Which of the following is the root cause of the issue?

Options:

A.

The firewall on the application server has port 443 blocked.

B.

The firewall has port 443 blocked while SSL/HTTPS inspection is enabled.

C.

The end users do not have certificates on their laptops.

D.

The firewall has an expired certificate while SSL/HTTPS inspection is enabled.

Expert Solution
Questions # 17:

A company just launched a cloud-based application. Some users are reporting the application will not load. A cloud engineer investigates the issues and reports the following:

    Not all users are experiencing the issue

    The application infrastructure is optimal

    Users experiencing the issue belong to the company's remote sales team

Which of the following is most likely misconfigured?

Options:

A.

Application load balancers

B.

Ports and protocols

C.

IP addressing

D.

Geolocation rules

Expert Solution
Questions # 18:

A SaaS company's new service currently is being provided through four servers. The company's end users are having connection issues, which is affecting about 25% of the connections. Which of the following is most likely the root cause of this issue?

Options:

A.

The service is using round-robin load balancing through a DNS server with one server down.

B.

The service is using weighted load balancing with 40% of the traffic on server A, 20% on server B, 20% on server C, and server D is down.

C.

The service is using a least-connection load-balancing method with one server down.

D.

Load balancing is configured with a health check in front of these servers, and one of these servers is unavailable.

Expert Solution
Questions # 19:

An application is hosted on a three-node cluster in which each server has identical compute and network performance specifications. A fourth node is scheduled to be added to the cluster with three times the performance as any one of the preexisting nodes. The network architect wants to ensure that the new node gets the same approximate number of requests as all of the others combined. Which of the following load-balancing methodologies should the network architect recommend?

Options:

A.

Round-robin

B.

Load-based

C.

Least connections

D.

Weighted

Expert Solution
Questions # 20:

A company is transitioning from on-premises to a hybrid environment. Due to regulatory standards, the company needs to achieve a high level of reliability and high availability for the connection between its data center and the cloud provider. Which of the following solutions best meets the requirements?

Options:

A.

Establish a Direct Connect with the cloud provider and peer to two different VPCs in the cloud network.

B.

Establish a Direct Connect with the cloud provider and a redundant connection with a VPN over the internet.

C.

Establish two Direct Connect connections to the cloud provider using two different suppliers.

D.

Establish a VPN with two tunnels to a transit gateway at the cloud provider.

Expert Solution
Viewing page 2 out of 3 pages
Viewing questions 11-20 out of questions