Skip to content

CNAE-101 Certified Network Administrator and Engineer Practice Questions

Prepare for CNAE-101 with more than an answer.

150 questions in the full set12 sample questionsUpdated Aug 13, 2026
Exam fee
$399 USD
Level
Professional
Valid for
5 years
Domains covered on the exam 5
  1. Network Design25%
  2. Network Administration20%
  3. Network Troubleshooting20%
  4. Network Security25%
  5. Network Governance and Operations10%
  1. 1

    The command to force an immediate update of group policy on a Windows client machine is: ________ /force

    Show answer details

    Correct answer: A

    The correct command to manually force an immediate update of Group Policy on a Windows machine is 'gpupdate /force'. This is a common administrative task when applying new configuration management baselines or security policies. 'gpresult' displays the resultant set of policies, and 'ipconfig' is for network interface configuration.

  2. 2

    A network administrator is replacing an outdated SNMPv2c deployment with SNMPv3 to comply with new security governance policies. The policy requires that all SNMP management traffic be both authenticated and encrypted. Which SNMPv3 security level must the administrator configure to meet this requirement?

    Show answer details

    Correct answer: D

    SNMPv3 introduces three security levels. 'authPriv' (Authentication and Privacy) provides both authentication (verifying the identity of the user/manager) and privacy (encrypting the payload data). 'authNoPriv' provides authentication but sends data in plaintext. 'noAuthNoPriv' provides neither, relying only on usernames, similar to SNMPv2c communities.

  3. 3

    Background:
    A university IT department is overhauling its AAA (Authentication, Authorization, and Accounting) architecture. Currently, they use a mix of local accounts on network devices and an aging RADIUS server for Wi-Fi authentication.

    Current Situation:
    The network engineering team manages over 500 routers and switches. They need granular control over which commands junior administrators can execute versus senior engineers. Additionally, all configuration commands typed by any administrator must be strictly logged for compliance audits.

    Requirements:

    1. Provide centralized authentication for device administration.
    2. Enable command-level authorization (e.g., allowing 'show' commands but denying 'configure terminal' for junior staff).
    3. Ensure the entire payload of the authentication packet is encrypted to prevent interception of credentials or command data.

    Based on these requirements, which protocol is the optimal choice for the device administration AAA solution?

    Show answer details

    Correct answer: A

    TACACS+ is designed specifically for device administration. It encrypts the entire payload (unlike RADIUS, which only encrypts the password field), uses TCP for reliable delivery, and completely separates the Authentication, Authorization, and Accounting processes. This separation allows for granular command-level authorization, which is a key requirement for the university's junior vs. senior administrator roles.

  4. 4

    A multinational enterprise is designing a highly available wide area network to connect three major regional headquarters. The architecture must ensure that if the primary multiprotocol label switching (MPLS) link fails, traffic is automatically rerouted over a backup internet-based VPN with minimal convergence time. Which routing protocol and feature combination represents the optimal design for this requirement?

    flowchart TD HQ[HQ Router] MPLS((MPLS Cloud)) INET((Internet)) BR1[Branch 1] HQ -->|Primary BGP| MPLS HQ -->|Backup BGP| INET MPLS --> BR1 INET --> BR1
    Show answer details

    Correct answer: A

    BGP is the standard protocol for WAN multihoming and enterprise edge routing. However, its default timers (e.g., 60-second keepalive, 180-second hold) are too slow for rapid convergence. Pairing BGP with Bidirectional Forwarding Detection (BFD) provides sub-second failure detection, allowing the router to switch to the backup VPN path almost immediately. OSPF and EIGRP are typically internal gateway protocols (IGPs) and are less suited for peering across disparate provider networks like internet VPNs and MPLS simultaneously without complex redistribution.

  5. 5

    To optimize east-west traffic in a newly constructed data center, the engineering team is migrating from a traditional three-tier hierarchical model to a spine-leaf architecture. Which of the following is a primary characteristic of a properly designed spine-leaf topology?

    Show answer details

    Correct answer: D

    In a spine-leaf architecture, every leaf switch connects to every spine switch, creating a non-blocking fabric with equidistant endpoints. This ensures that traffic between any two leaf switches is always exactly two hops away (Leaf -> Spine -> Leaf), which provides highly predictable latency for east-west traffic. Spine switches do not connect to each other, and endpoints (servers) only connect to leaf switches.

  6. 6

    When designing cloud and hybrid network environments, which TWO of the following technologies are primarily utilized to abstract network functions from proprietary hardware appliances and run them as software on standard servers? (Select TWO)

    Show answer details

    Correct answer: B, E

    NFV (Network Function Virtualization) is the concept of replacing dedicated network appliances (like firewalls, load balancers, or routers) with software running on commercial off-the-shelf (COTS) servers. VNF (Virtual Network Function) is the actual software instance that performs the function. Both are core to modern cloud and hybrid networking abstraction. SDN separates the control and data planes but doesn't inherently replace appliances with software instances in the same way, while VPC is a logical cloud isolation boundary.

    NFV (Network Function Virtualization) is the concept of replacing dedicated network appliances (like firewalls, load balancers, or routers) with software running on commercial off-the-shelf (COTS) servers. VNF (Virtual Network Function) is the actual software instance that performs the function. Both are core to modern cloud and hybrid networking abstraction. SDN separates the control and data planes but doesn't inherently replace appliances with software instances in the same way, while VPC is a logical cloud isolation boundary.

Create an account to continue.