FreeQAs
 Request Exam  Contact
  • Home
  • View All Exams
  • New QA's
  • Upload
PRACTICE EXAMS:
  • Oracle
  • Fortinet
  • Juniper
  • Microsoft
  • Cisco
  • Citrix
  • CompTIA
  • VMware
  • ISC
  • SAP
  • EMC
  • PMI
  • HP
  • Salesforce
  • Other
  • Oracle
    Oracle
  • Fortinet
    Fortinet
  • Juniper
    Juniper
  • Microsoft
    Microsoft
  • Cisco
    Cisco
  • Citrix
    Citrix
  • CompTIA
    CompTIA
  • VMware
    VMware
  • ISC
    ISC
  • SAP
    SAP
  • EMC
    EMC
  • PMI
    PMI
  • HP
    HP
  • Salesforce
    Salesforce
  1. Home
  2. CompTIA Certification
  3. N10-008 Exam
  4. CompTIA.N10-008.v2025-06-03.q684 Dumps
  • ««
  • «
  • …
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • …
  • »
  • »»
Download Now

Question 181

A malicious user is using special software 10 perform an on-path attack. Which of the following best practices should be configured to mitigate this threat?

Correct Answer: A
An on-path attack is a type of attack where an attacker intercepts and modifies the traffic between two devices on the same network. One common example of an on-path attack is ARP poisoning, where an attacker sends fake ARP replies to trick the devices into sending their traffic to the attacker instead of the intended destination. This allows the attacker to eavesdrop, alter, or redirect the traffic.
To mitigate this threat, one of the best practices is to use dynamic ARP inspection (DAI), which is a security feature that validates ARP packets on a network. DAI checks the MAC address and IP address bindings in the ARP packets against a trusted database, such as the DHCP snooping table or a static ARP access list. If the ARP packet contains an invalid or spoofed binding, DAI drops the packet and prevents the ARP poisoning attack.
The other options are not as effective as DAI for mitigating on-path attacks. Role-based access is a method of controlling access to resources based on the roles and permissions of the users, but it does not prevent an attacker from spoofing the MAC address or IP address of a legitimate user. Control plane policing is a feature that protects the control plane of a router or switch from excessive or malicious traffic, but it does not verify the MAC address or IP address bindings in the data plane. MAC filtering is a feature that allows or denies access to a network based on the MAC address of the device, but it does not prevent an attacker from spoofing the MAC address of an allowed device.
References:
https://www.professormesser.com/security-plus/sy0-601/sy0-601-video/on-path-attacks/
https://www.cisco.com/c/en/us/td/docs/ios/12_2sb/feature/guide/cpp.html
insert code

Question 182

Which of the following protocol types describes secure communication on port 443?

Correct Answer: C
TCP is the protocol type that describes secure communication on port 443. TCP (Transmission Control Protocol) is a connection-oriented protocol that provides reliable and ordered delivery of data packets over an IP network. TCP uses port numbers to identify different applications or services on a device. Port 443 is the default port for HTTPS (Hypertext Transfer Protocol Secure), which is an extension of HTTP that uses SSL (Secure Sockets Layer) or TLS (Transport Layer Security) encryption to protect data in transit between a web server and a web browser. References:
https://www.cisco.com/c/en/us/support/docs/ip/routing-information-protocol-rip/13788-3.html
insert code

Question 183

Which of the following OSI model layers is where conversations between applications are established, coordinated, and terminated?

Correct Answer: A
Reference:
https://www.techtarget.com/searchnetworking/definition/OSI#:~:text=The%20session%20layer,and%20terminat The session layer is where conversations between applications are established, coordinated, and terminated. It is responsible for creating, maintaining, and ending sessions between different devices or processes. The physical layer deals with the transmission of bits over a medium. The presentation layer formats and translates data for different applications. The data link layer provides reliable and error-free delivery of frames within a network.
insert code

Question 184

SIMULATION
A network technician replaced a switch and needs to reconfigure it to allow the connected devices to connect to the correct networks.
INSTRUCTIONS
Click on the appropriate port(s) on Switch 1 and Switch 3 to verify or reconfigure the correct settings:
* Ensure each device accesses only its correctly associated network
* Disable all unused switch ports
* Require fault-tolerant connections between the switches
* Only make necessary changes to complete the above requirements
If at any time you would like to bring back the initial state of the simulation, please click the Reset All button.














Correct Answer:
See the explanation for this solution.
Explanation
Switch 1 and Switch 2 is the only two switches that can be configured. Only switches linked together with there switch ports needs to be "tagged" and "LACP" needs to be enabled. The other ports must be untagged with no LACP enabled. You only need to assign the correct vlan via each port. 'Speed and Duplex' needs to be Speed=1000 and Duplex=Full, with is by default.
https://resources.infosecinstitute.com/topic/what-are-tagged-and-untagged-ports/
insert code

Question 185

A technician is documenting an application that is installed on a server and needs to verify all existing web and database connections to the server. Which of the following tools should the technician use to accomplish this task?

Correct Answer: C
The correct tool for verifying existing network connections on a server is C. Netstat. Netstat (network statistics) displays active network connections, routing tables, interface statistics, masquerade connections, and multicast memberships.
Tracert: Tracert (traceroute) is used to trace the route taken by packets from the source to the destination. It helps identify the path and latency between routers.
Ipconfig: Ipconfig is used to view and manage IP configuration settings on a local machine (such as IP address, subnet mask, default gateway, etc.). It does not provide information about existing connections.
Netstat: Netstat displays active network connections, including listening ports, established connections, and associated processes. It's useful for troubleshooting and monitoring network activity.
Nslookup: Nslookup is used for DNS (Domain Name System) queries to resolve domain names to IP addresses. It does not provide information about existing connections.
Reference:
CompTIA Network+ Certification Exam Objectives
insert code
  • ««
  • «
  • …
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • …
  • »
  • »»
[×]

Download PDF File

Enter your email address to download CompTIA.N10-008.v2025-06-03.q684 Dumps

Email:

FreeQAs

Our website provides the Largest and the most Latest vendors Certification Exam materials around the world.

Using dumps we provide to Pass the Exam, we has the Valid Dumps with passing guranteed just which you need.

  • DMCA
  • About
  • Contact Us
  • Privacy Policy
  • Terms & Conditions
©2026 FreeQAs

www.freeqas.com materials do not contain actual questions and answers from Cisco's certification exams.