CloudNetX Practice Questions
Prepare for CNX-001 with more than an answer.
- Exam fee
- $392 USD
- Level
- Expert
- Valid for
- 3 years
Domains covered on the exam 4
- Network Architecture Design31%
- Network Security28%
- Network Operations, Monitoring, and Performance16%
- Network Troubleshooting25%
- 1
A user in a branch office reports that they are unable to access an internal web application hosted in the central data center. A network technician uses
traceroutefrom the user's workstation. The trace successfully reaches the branch office gateway, traverses the WAN, and reaches the data center edge router, but then stops and shows timeouts for all subsequent hops. What is the MOST likely cause of this issue?Show answer details
Correct answer: C
tracerouteworks by sending packets with incrementally increasing TTL (Time-to-Live) values. Each router that decrements the TTL to zero sends back an ICMP 'Time Exceeded' message. If the trace stops at a specific hop and shows timeouts, it often means a device at that point (or just beyond it) is not sending back the ICMP responses, which is a common security practice for firewalls and routers to prevent network mapping. The packets are likely being forwarded correctly, but the diagnostic messages are being blocked. - 2
When designing a secure hybrid cloud architecture, an architect needs to select a connectivity model that provides consistent, private, and high-bandwidth access to the cloud provider's network. The solution must bypass the public internet and offer a service level agreement (SLA) for uptime. Which connectivity option should be chosen?
graph TD subgraph On-Premises Data Center A[Corporate Network] end subgraph Cloud Provider B[Virtual Private Cloud] end A -- ??? --> BShow answer details
Correct answer: B
Dedicated private connections like AWS Direct Connect, Azure ExpressRoute, or Google Cloud Interconnect provide a private, high-bandwidth, low-latency link between an on-premises data center and the cloud provider's network. This traffic does not traverse the public internet, offering greater security and more predictable performance. These services also come with SLAs, meeting all the stated requirements.
- 3
A security analyst is investigating a potential data exfiltration event. A review of DNS logs shows an unusually high number of queries for unique, long, and seemingly random subdomains of a domain owned by the attacker (e.g.,
a1b2c3d4e5f6.attacker.com,g7h8i9j0k1l2.attacker.com). The data within these subdomain queries appears to be Base64 encoded. What is this technique called?Show answer details
Correct answer: C
DNS tunneling is a method of C2 communication or data exfiltration that encodes data within DNS queries and responses. Since DNS traffic (UDP port 53) is often allowed through firewalls with minimal inspection, attackers use it as a covert channel. The scenario described, with encoded data placed in subdomains of an attacker-controlled domain, is a classic example of using DNS queries to exfiltrate data.
- 4
An organization is migrating to a Zero Trust Network Access (ZTNA) model. The PowerShell command to enable a specific ZTNA feature on a Windows server is
Enable-NetZTNFeature -Name '_____ '. Which of the following is a plausible, but fictitious, feature name that would fit this command structure?Show answer details
Correct answer: A
While
Enable-NetZTNFeatureis a fictitious command created for this question, 'DynamicMicroPerimeter' is a plausible parameter name that aligns with ZTNA concepts. ZTNA creates micro-perimeters around applications or resources, and these perimeters are dynamic based on user identity, device posture, and other contextual factors. The other options are either too generic or refer to different technologies. - 5
A cloud architect needs to design a highly available and scalable web application front-end. The solution must distribute incoming HTTP/HTTPS traffic across a fleet of web servers located in multiple Availability Zones within a single region. The load balancer must also be able to make routing decisions based on the content of the request, such as the URL path. Which type of load balancer should be used?
Show answer details
Correct answer: B
An Application Load Balancer (ALB) operates at Layer 7 (the application layer) of the OSI model. This allows it to inspect incoming HTTP/HTTPS traffic and make intelligent routing decisions based on content like URL paths, host headers, or query string parameters. This capability, combined with its inherent high availability across multiple Availability Zones, makes it the perfect choice for this scenario.
- 6
A financial services company is migrating its on-premises data center to a hybrid cloud model, leveraging a 10 Gbps dedicated connection to a public cloud provider. During performance testing of a latency-sensitive trading application, network architects observe intermittent packet loss and degraded performance, specifically with large data transfers. Initial analysis with
pingshows no packet loss for standard-sized packets, but issues arise with larger payloads. Which of the following is the MOST likely cause of this issue?Show answer details
Correct answer: C
The scenario describes a classic Path MTU Discovery (PMTUD) black hole. Standard pings work because they use small packets. Large data transfers require fragmentation if the packet size exceeds the MTU of any link in the path. PMTUD relies on ICMP 'Destination Unreachable; Fragmentation Needed' (Type 3, Code 4) messages to discover the correct MTU. If a firewall blocks these messages, the sending host never learns it needs to reduce its packet size, leading to dropped packets (a 'black hole') for large transfers.
- 7
An enterprise is designing a new data center network fabric to support high-performance computing (HPC) and east-west traffic patterns from containerized microservices. The primary requirements are low latency, predictable performance, and non-blocking throughput. Which network topology should the architect select to BEST meet these requirements?
Show answer details
Correct answer: B
A spine-and-leaf topology is specifically designed for modern data centers with heavy east-west (server-to-server) traffic. Every leaf switch connects to every spine switch, ensuring that any two servers are at most two hops away from each other. This creates a low-latency, non-blocking fabric with predictable performance, making it ideal for HPC and microservices.
- 8
A global retailer is implementing a Secure Access Service Edge (SASE) architecture to provide unified security and networking for its remote workforce and branch offices. A network security architect needs to ensure that security policies are enforced consistently, regardless of user location or the application being accessed. Which TWO of the following are core functional components of a SASE solution that achieve this? (Select TWO).
Show answer details
Correct answer: B, D
SASE converges networking and security into a single, cloud-delivered service. A core part of this is a cloud-native security stack that includes Firewall as a Service (FWaaS), Secure Web Gateway (SWG), and Cloud Access Security Broker (CASB) to enforce policies consistently.
The SASE architecture relies on a network of globally distributed PoPs. User traffic is directed to the nearest PoP, where security policies are applied before traffic is routed to its destination. This global backbone is essential for low-latency performance and consistent policy enforcement.
- 9
A DevOps team is using Terraform to manage a multi-cloud network infrastructure. They have defined resources for both AWS and Azure in their configuration files. A junior engineer on the team runs
terraform applyand receives an error related to provider authentication for Azure, even though the AWS resources were provisioned successfully. What is the MOST likely reason for this failure?Show answer details
Correct answer: B
Terraform uses provider-specific authentication methods. For AWS, it might be using environment variables or an IAM role. For Azure, it often relies on credentials configured in the Azure CLI or specific environment variables (like ARM_CLIENT_ID, etc.). An authentication error for one provider while another succeeds points directly to a misconfiguration of credentials for the failing provider in the execution environment.
- 10
True or False: In a Zero Trust architecture, once a user has successfully authenticated with multi-factor authentication (MFA) and their device posture has been verified, they are granted implicit trust and broad access to all network resources within their assigned security zone for the duration of their session.
Show answer details
Correct answer: B
This statement is false. A core principle of Zero Trust is 'never trust, always verify.' Access is granted on a per-session, per-application basis, and trust is never implicit. Even after initial authentication and verification, access is continuously re-evaluated based on context, such as user behavior, device health, and the sensitivity of the resource being accessed. Broad access is antithetical to the principle of least privilege inherent in Zero Trust.
