Pass the CompTIA CloudNetX CNX-001 Questions and answers with CertsForce

Viewing page 1 out of 3 pages
Viewing questions 1-10 out of questions
Questions # 1:

A security architect needs to increase the security controls around computer hardware installations. The requirements are:

    Auditable access logs to computer rooms

    Alerts for unauthorized access attempts

    Remote visibility to the inside of computer rooms

Which of the following controls best meet these requirements? (Choose two.)

Options:

A.

Video surveillance


B.

NFC access cards


C.

Motion sensors


D.

Locks and keys


E.

Security patrols


F.

Automated lighting


Questions # 2:

A network architect needs to design a new network to connect multiple private data centers. The network must:

    Provide privacy for all traffic between locations

    Use preexisting internet connections

    Use intelligent steering of application traffic over the best path

Which of the following best meets these requirements?

Options:

A.

MPLS connections


B.

SD-WAN


C.

Site-to-site VPN


D.

ExpressRoute


Questions # 3:

A cloud architect must recommend an architecture approach for a new medical application that requires the lowest downtime possible. Which of the following is the best application deployment strategy given the high-availability requirement?

Options:

A.

Two different availability zones (per region) using an active-active topology in two different regions


B.

Four different availability zones using an active-passive topology in a single region


C.

Four different availability zones using an active-active topology in a single region


D.

Two different availability zones (per region) using an active-passive topology in two different regions


Questions # 4:

A company is experiencing Wi-Fi performance issues. Three Wi-Fi networks are available, each running on the 2.4 GHz band and on the same channel. Connecting to each Wi-Fi network yields slow performance. Which of the following channels should the networks be configured to?

Options:

A.

Channel 1, Channel 2, and Channel 3


B.

Channel 2, Channel 4, and Channel 9


C.

Channel 1, Channel 6, and Channel 11


D.

Channel 3, Channel 5, and Channel 10


Questions # 5:

A company hosts its applications on the cloud and is expanding its business to Europe. Thecompany must comply with General Data Protection Regulation (GDPR) to limit European customers' access to data. The network team configures the firewall rules but finds that some customers in the United States can access data hosted in Europe. Which of the following is the best option for the network team to configure?

Options:

A.

SASE


B.

Network security groups


C.

CDN


D.

Geofencing rule


Questions # 6:

A network architect is working on a new network design to better support remote and on-campus workers. Traffic needs to be decrypted for inspection in the cloud but is not required to go through the company's data center. Which of the following technologies best meets these requirements?

Options:

A.

Secure web gateway


B.

Transit gateway


C.

Virtual private network


D.

Intrusion prevention system


E.

Network access control system


Questions # 7:

A cloud architect needs to change the network configuration at a company that uses GitOps to document and implement network changes. The Git repository uses main as the default branch, and the main branch is protected. Which of the following should the architect do after cloning the repository?

Options:

A.

Use the main branch to make and commit the changes back to the remote repository.


B.

Create a new branch for the change, then create a pull request including the changes.


C.

Check out the development branch, then perform and commit the changes back to the remote repository.


D.

Rebase the remote main branch after making the changes to implement.


Questions # 8:

You are designing a campus network with a three-tier hierarchy and need to ensure secure connectivity between locations and traveling employees.

INSTRUCTIONS

Review the command output by clicking on the server, laptops, and workstations on the network.

Use the drop-down menus to determine the appropriate technology and label for each layer on the diagram. Options may only be used once.

Click on the magnifying glass to make additional configuration changes.

If at any time you would like to bring back the initial state of the simulation, please click the Reset All button.

Question # 8


Questions # 9:

A SaaS company's new service currently is being provided through four servers. The company's end users are having connection issues, which is affecting about 25% of the connections. Which of the following is most likely the root cause of this issue?

Options:

A.

The service is using round-robin load balancing through a DNS server with one server down.


B.

The service is using weighted load balancing with 40% of the traffic on server A, 20% on server B, 20% on server C, and server D is down.


C.

The service is using a least-connection load-balancing method with one server down.


D.

Load balancing is configured with a health check in front of these servers, and one of these servers is unavailable.


Questions # 10:

Security policy states that all inbound traffic to the environment needs to be restricted, but all external outbound traffic is allowed within the hybrid cloud environment. A new application server was recently set up in the cloud. Which of the following would most likely need to be configured so that the server has the appropriate access set up? (Choose two.)

Options:

A.

Application gateway


B.

IPS


C.

Port security


D.

Firewall


E.

Network security group


F.

Screened subnet


Viewing page 1 out of 3 pages
Viewing questions 1-10 out of questions