[Q17-Q36] Get up-to-date Real Exam Questions for CNX-001 UPDATED [2026]

Share

Get up-to-date Real Exam Questions for CNX-001 UPDATED [2026]

Pass CompTIA CNX-001 Exam in First Attempt Guaranteed


CompTIA CNX-001 Exam Syllabus Topics:

TopicDetails
Topic 1
  • Network Security: This section of the exam measures the skills of Security Engineers and covers core practices for protecting network infrastructure. It includes applying firewall rules, implementing access control measures, and designing secure segmentation strategies. The content emphasizes threat mitigation techniques, secure configuration of networking devices, and adherence to compliance frameworks, preparing professionals to safeguard both internal and external network assets effectively.
Topic 2
  • Network Architecture Design: This section of the exam measures the skills of Network Architects and covers the ability to design scalable, secure, and efficient network architectures. It focuses on understanding design principles, selecting appropriate network components, and aligning architecture decisions with organizational needs. Candidates are expected to demonstrate a solid grasp of topology planning, high-availability configurations, and integration of cloud and on-premise systems to ensure reliability and performance.
Topic 3
  • Network Operations, Monitoring, and Performance: This section of the exam measures skills of Network Operations Specialists and covers day-to-day operational management of network environments. It involves configuring monitoring tools, analyzing performance data, and responding to alerts. Candidates are evaluated on their ability to maintain network health, optimize throughput, and ensure consistent uptime by applying best practices for proactive performance tuning and operations management.
Topic 4
  • Network Troubleshooting: This section of the exam measures the skills of Network Support Engineers and covers diagnosing and resolving connectivity and performance issues across various network layers. It focuses on identifying root causes, using diagnostic tools, and applying systematic troubleshooting methodologies. The goal is to ensure that professionals can minimize downtime, restore service quickly, and prevent recurring problems by maintaining a resilient and stable network environment.

 

NEW QUESTION # 17
A network administrator is troubleshooting an outage at a remote site. The administrator examines the logs and determines that one of the internet links at the site appears to be down. After the service provider confirms this information, the administrator fails over traffic to the backup link. Which of the following should the administrator do next?

  • A. Verify full system functionality.
  • B. Document the lessons learned.
  • C. Establish a plan of action.
  • D. Identify the problem.

Answer: A

Explanation:
Comprehensive and Detailed Explanation From Exact Extract:
According to the standard CompTIA troubleshooting methodology, once the issue has been identified and a solution has been implemented (e.g., failing over traffic to the backup link), the next logical step is to verify full system functionality. This ensures that the backup path is working as intended and that services have resumed properly for the users.
Relevant Extract from CompTIA CloudNetX CNX-001 Study Guide - under "Troubleshooting Process":
"After implementing the solution, it is critical to verify full system functionality to ensure the resolution has addressed the problem without causing unintended consequences." Other options:
* A. Documenting lessons learned is the final step.
* B. The plan of action should have been created before the failover.
* C. Identifying the problem already occurred earlier in the scenario.


NEW QUESTION # 18
A network load balancer is not correctly validating a client TLS certificate. The network architect needs to validate the certificate installed on the load balancer before progressing. Which of the following commands should the architect use to confirm whether the private key and certificate match?

  • A. openssl-list -noout -modulus -in cert.crt | openssl md5
    openssl rsa -noout -modulus -in privkey.txt | openssl md5
  • B. openssl x509 -noout -modulus -in cert.crt | openssl md5
    openssl rsa -noout -modulus -in privkey.txt | openssl md5
  • C. openssl req -in certificate.csr -verify
    openssl-verify -noout -modulus -in privkey.txt | openssl md5
  • D. openssl-rsa -noout -modulus -in cert.crt | openssl md5
    openssl-verify -noout -modulus -in privkey.txt | openssl md5

Answer: B

Explanation:
Comprehensive and Detailed Explanation From Exact Extract:
To verify that the certificate and the private key match, one can extract the modulus from both files and compare their hash values. The correct syntax involves using openssl x509 to extract the modulus from the certificate, and openssl rsa to extract the modulus from the private key, followed by an MD5 hash to ensure they match.
Relevant Extract from CompTIA CloudNetX CNX-001 Study Guide - under "TLS/SSL Certificate Validation and Troubleshooting":
"To verify that the private key and certificate match, compare the modulus values. A mismatch results in failed TLS handshakes." Other options:
* A & C: Incorrect syntax (openssl-list and openssl-rsa are not valid commands).
* B: The commands shown are used to verify CSRs, not matching keys.


NEW QUESTION # 19
A company hosts its application s on the cloud and is expanding its business to Europe. The company must comply with General Data Protection Regulation to limit European customers' access to data. The network team configures the firewall rules but finds that some customers in the United States can access data hosted in Europe. Which of the following is the best option for the network team to configure?

  • A. Network security groups
  • B. SASE
  • C. CDN
  • D. Geofencing rule

Answer: D

Explanation:
Using a geofencing (geo#restriction) policy lets you block or allow traffic based on the client's geographic location. This ensures that only users in approved regions (e.g., the United States) can reach the European- hosted data, effectively preventing unintended European customer access without complex IP ACLs.


NEW QUESTION # 20
A cloud architect must recommend an architecture approach for a new medical application that requires the lowest downtime possible. Which of the following is the best application deployment strategy given the high- availability requirement?

  • A. Two different availability zones (per region) using an active-active topology in two different regions
  • B. Four different availability zones using an active-passive topology in a single region
  • C. Four different availability zones using an active-active topology in a single region
  • D. Two different availability zones (per region) using an active-passive topology in two different regions

Answer: A

Explanation:
Comprehensive and Detailed Explanation From Exact Extract:
Using an active-active deployment across two regions with at least two Availability Zones (AZs) each provides the highest level of fault tolerance and geographic redundancy. This ensures continuity even if an entire region or multiple zones become unavailable. In regulated sectors such as healthcare, this meets strict availability and disaster recovery requirements.
Relevant Extract from CompTIA CloudNetX CNX-001 Study Guide - under "High Availability and Multi- Region Design":
"Active-active configurations across multiple regions and availability zones maximize uptime and ensure failover in the event of localized or regional failures." Other options:
* B. Active-passive introduces delays in failover.
* C. Active-active in one region offers no geographic redundancy.
* D. Active-passive in two regions is slower and less efficient during failover.


NEW QUESTION # 21
A network architect needs to build a new data center for a large company that has business units that process retail financial transactions. Which of the following information should the architect request from the company?

  • A. Statement of work
  • B. Regulatory requirements
  • C. Internal reference architecture
  • D. Business case study

Answer: B

Explanation:
Before designing a facility that will handle retail financial transactions, you need to understand all applicable compliance and security mandates (e.g. PCI DSS, SOX, GDPR). Those regulatory requirements will drive your choices around physical security, network segmentation, encryption, logging, redundancy, and operational controls, ensuring the data center meets its legal and industry-specific obligations.


NEW QUESTION # 22
A call center company provides its services through a VoIP infrastructure. Recently, the call center set up an application to manage its documents on a cloud application. The application is causing recurring audio losses for VoIP callers. The network administrator needs to fix the issue with the least expensive solution. Which of the following is the best approach?

  • A. Creating two VLANs, one for voice and the other for data
  • B. Setting up VoIP devices to use a voice codec with a higher compression rate
  • C. Configuring QoS rules at the internet router to prioritize the VoIP calls
  • D. Adding a second internet link and physically splitting voice and data networks into different routes

Answer: C

Explanation:
Comprehensive and Detailed Explanation From Exact Extract:
Quality of Service (QoS) rules at the internet router can prioritize VoIP traffic over other data, such as cloud document access. VoIP is sensitive to latency and jitter, and configuring QoS ensures that voice packets are prioritized during congestion. This is the most cost-effective solution that doesn't require additional infrastructure.
Relevant Extract from CompTIA CloudNetX CNX-001 Study Guide - under "Traffic Management and Prioritization":
"QoS policies are essential for ensuring that latency-sensitive traffic, such as VoIP, is prioritized over other types of data, particularly in bandwidth-limited scenarios." Other options:
* A. Adding a second internet link is effective but not cost-efficient.
* C. VLANs provide segmentation but don't guarantee bandwidth prioritization.
* D. Changing the codec may reduce bandwidth usage, but doesn't address prioritization directly.


NEW QUESTION # 23
A network administrator is configuring firewall rules to lock down the network from outside attacks. Which of the following should the administrator configure to create the most strict set of rules?

  • A. Network security group
  • B. URL filtering
  • C. File blocking
  • D. Allow List

Answer: D

Explanation:
By explicitly permitting only known, approved traffic and blocking everything else by default, an allow-list policy enforces the strictest firewall posture.


NEW QUESTION # 24
An architecture team needs to unify all logging and performance monitoring used by global applications across the enterprise to perform decision-making analytics. Which of the following technologies is the best way to fulfill this purpose?

  • A. Content delivery network
  • B. CIEM
  • C. Data lake
  • D. Relational database

Answer: C

Explanation:
A data lake provides a scalable, centralized repository that can ingest and store massive volumes of structured and unstructured data, including logs and performance metrics, from across your global applications. By keeping raw data in its native format, you can run batch and real-time analytics, machine learning, and business-intelligence workloads on one unified platform, making it ideal for enterprise-wide decision-making.


NEW QUESTION # 25
A security architect needs to increase the security controls around computer hardware installations. The requirements are:
* Auditable access logs to computer rooms
* Alerts for unauthorized access attempts
* Remote visibility to the inside of computer rooms
Which of the following controls best meet these requirements? (Choose two.)

  • A. Security patrols
  • B. NFC access cards
  • C. Locks and keys
  • D. Automated lighting
  • E. Motion sensors
  • F. Video surveillance

Answer: B,F

Explanation:
Comprehensive and Detailed Explanation From Exact Extract:
Video surveillance (A) provides continuous monitoring and allows for real-time, remote visibility of secure locations, such as computer rooms. When integrated with analytics, video surveillance systems can detect movement after hours or unauthorized access and generate immediate alerts. These systems also maintain video logs that can be audited later.
NFC access cards (B) allow controlled access to physical areas, generating time-stamped logs for each entry attempt. When connected to an access control system, these cards can trigger alerts for unauthorized access attempts, such as the use of expired credentials or access during restricted hours.
Relevant Extract from CompTIA CloudNetX CNX-001 Study Guide - Security Controls and Physical Security Section:
"Security access systems using NFC or smart cards allow traceability of personnel entry through electronic logs, while surveillance systems provide visibility and support forensic investigations."
"Video surveillance allows real-time monitoring of physical environments and helps detect unauthorized presence or access in sensitive locations."


NEW QUESTION # 26
A network engineer identified several failed log-in attempts to the VPN from a user's account. When the engineer inquired, the user mentioned the IT help desk called and asked them to change their password.
Which of the following types of attacks occurred?

  • A. Social engineering
  • B. Initialization vector
  • C. Evil twin
  • D. On-path

Answer: A

Explanation:
Comprehensive and Detailed Explanation From Exact Extract:
This scenario describes a classic example of social engineering. An attacker impersonated the help desk and convinced the user to change their password, likely to one the attacker controlled. Social engineering attacks manipulate human behavior to bypass technical security measures.
Relevant Extract from CompTIA CloudNetX CNX-001 Study Guide - under "Social Engineering Threats":
"Social engineering involves manipulating individuals to perform actions or divulge confidential information, such as passwords, often by impersonating trusted entities like IT support." Other options:
* A. Initialization vector relates to encryption vulnerabilities.
* B. On-path (formerly man-in-the-middle) requires network interception, which is not described here.
* C. Evil twin is a rogue Wi-Fi AP attack, not applicable to this VPN login context.


NEW QUESTION # 27
A company hosts its applications on the cloud and is expanding its business to Europe. Thecompany must comply with General Data Protection Regulation (GDPR) to limit European customers' access to data. The network team configures the firewall rules but finds that some customers in the United States can access data hosted in Europe. Which of the following is the best option for the network team to configure?

  • A. Network security groups
  • B. SASE
  • C. CDN
  • D. Geofencing rule

Answer: D

Explanation:
Comprehensive and Detailed Explanation From Exact Extract:
Geofencing allows enforcement of access policies based on the geographic location of the user's IP address.
To comply with GDPR and control access based on user region, geofencing should be implemented to restrict or permit access to resources hosted in specific regions like Europe.
Relevant Extract from CompTIA CloudNetX CNX-001 Study Guide - under "Data Sovereignty and Regional Access Control":
"Geofencing enables organizations to restrict access to data or services based on geographic IP address, aiding in GDPR and other compliance frameworks." Other options:
* A. SASE is a broader framework, not a direct access control mechanism.
* B. NSGs operate at subnet/NIC level and do not interpret geolocation.
* C. CDNs cache data globally but don't control access by region directly.


NEW QUESTION # 28
A network engineer is designing a Layer 2 deployment for a company that occupies several floors in an office building. The engineer decides to make each floor its own VLAN but still allow for communication between all user VLANs. The engineer also wants to reduce the time necessary for STP convergence to occur when new switches come online. Which of the following should the engineer enable to accomplish this goal?

  • A. Tagging
  • B. Priority
  • C. Portfast
  • D. BPDU Guard

Answer: C

Explanation:
Enabling PortFast on access ports lets them immediately enter the forwarding state, skipping the STP listening
/learning timers, and dramatically speeds up convergence when switches or end-stations come online.


NEW QUESTION # 29
An application is hosted on a three-node cluster in which each server has identical compute and network performance specifications. A fourth node is scheduled to be added to the cluster with three times the performance as any one of the preexisting nodes. The network architect wants to ensure that the new node gets the same approximate number of requests as all of the others combined. Which of the following load- balancing methodologies should the network architect recommend?

  • A. Weighted
  • B. Load-based
  • C. Round-robin
  • D. Least connections

Answer: A

Explanation:
Comprehensive and Detailed Explanation From Exact Extract:
Weighted load balancing allows distribution of traffic based on server capacity or assignedweights. In this case, the new node should receive a weight of 3, and each of the three older nodes a weight of 1. This ensures the new node handles the same total number of requests as the other three combined (3:1:1:1).
Relevant Extract from CompTIA CloudNetX CNX-001 Study Guide - under "Load Balancing Algorithms and Traffic Distribution":
"Weighted load balancing accounts for node capacity, distributing requests proportionally according to performance capability or administrator-defined weights." Other options:
* A. Round-robin sends traffic equally to all servers regardless of capacity.
* B. Load-based requires dynamic performance measurement and is more complex.
* C. Least connections may work in certain cases, but doesn't guarantee proportional traffic split based on server performance.


NEW QUESTION # 30
A network security engineer must secure a web application running on virtual machines in a public cloud. The virtual machines are behind an application load balancer. Which of the following technologies should the engineer use to secure the virtual machines? (Choose two.)

  • A. DLP
  • B. NSG
  • C. CDN
  • D. SIEM
  • E. IDS
  • F. WAF

Answer: B,F

Explanation:
Comprehensive and Detailed Explanation From Exact Extract:
WAF (Web Application Firewall) protects web applications by inspecting HTTP/S traffic to and from the application. It filters, monitors, and blocks malicious traffic and exploits targeting web application vulnerabilities. WAFs are deployed at the edge, often in conjunction with load balancers, and are ideal for mitigating threats like SQL injection, cross-site scripting, and protocol violations.
NSG (Network Security Group) is a native security feature offered by many cloud providers (such as Azure), functioning similarly to a firewall. NSGs control inbound and outbound traffic at the virtual network interface, subnet, or VM level, allowing engineers to define allowed or denied traffic rules.
Relevant Extract from CompTIA CloudNetX CNX-001 Study Guide under "Cloud Workload Protection & Security Tools":
"WAFs are critical for protecting web-facing applications in public cloud environments."
"Network Security Groups (NSGs) are used to enforce access policies on cloud-based virtual networks, providing filtering and segmentation at the instance or subnet level."


NEW QUESTION # 31
An organization's Chief Technical Officer is concerned that changes to the network using IaC are causing unscheduled outages. Which of the following best mitigates this risk?

  • A. Forking the code repository before making changes
  • B. Making code changes to the master branch
  • C. Enforcing code review of the change by the author
  • D. Adding review/approval steps to the CI/CD pipelines

Answer: D

Explanation:
Comprehensive and Detailed Explanation From Exact Extract:
The best way to prevent unscheduled outages caused by Infrastructure as Code (IaC) changes is to implement automated review and approval gates in the CI/CD pipeline. This ensures that all changes undergo validation, peer review, testing, and possibly approval from stakeholders before being deployed, thus reducing the likelihood of production-impacting issues.
Relevant Extract from CompTIA CloudNetX CNX-001 Study Guide - under "CI/CD Security and IaC Controls":
"Incorporating approval gates and automated validation into CI/CD pipelines helps detect misconfigurations and unauthorized changes before deployment, reducing the risk of outages." Other options:
* A. Making changes directly to the master branch violates best practices.
* B. Self-review (by the author) lacks objectivity and fails peer validation.
* C. Forking creates a copy but does not introduce formal validation processes.


NEW QUESTION # 32
Application development team users are having issues accessing the database server within the cloud environment. All other users are able to use SSH to access this server without issues. The network architect reviews the following information to troubleshoot the issue:

Traceroute output from an application developer's machine with the assigned IP 192.168.2.7:

* Application development gateway: 192.168.2.1/24
* Server segment gateway: 192.168.1.1/24
* Database server: 192.168.1.9
* Application developer machine IP: 192.168.2.7
* Traceroute ends at hop 4: 192.168.4.1 (server segment firewall), then times out Which of the following is the most likely cause of the issue?

  • A. The server segment firewall is dropping the traffic.
  • B. The core firewall is blocking the traffic.
  • C. Network security groups do not have the correct outbound rule configured.
  • D. The server segment gateway is having bandwidth issues.

Answer: A

Explanation:
Comprehensive and Detailed Explanation From Exact Extract:
The traceroute shows that the traffic successfully passes through the application development network (192.168.2.1), to the server segment gateway (192.168.1.1), and reaches the serversegment firewall (192.168.4.1). However, it times out immediately after hitting 192.168.4.1, indicating that the traffic is being dropped or filtered at that firewall.
Because other users (outside of the application development segment) are able to SSH into the database server (192.168.1.9), the issue is not with the database server itself or the core network. This points to the server segment firewall blocking traffic originating from the application development subnet (192.168.2.0/24), which is a common practice in segmented network designs unless proper access rules are defined.
Relevant Extract from CompTIA CloudNetX CNX-001 Study Guide - under "Network Segmentation and Firewall Rules":
"Firewalls between network segments may enforce security policies that restrict access based on source
/destination IP and port. Lack of proper allow rules can result in blocked traffic even if routing is successful." Other options:
* A. The core firewall is not in the traceroute path; it is irrelevant to this specific flow.
* B. NSGs (Network Security Groups) apply to cloud workloads, but the behavior and hop-by-hop flow suggest it is a firewall-level issue, not NSG misconfiguration.
* D. Bandwidth issues would typically show packet loss or high latency, not consistent timeouts at a specific hop.


NEW QUESTION # 33
A network architect must ensure only certain departments can access specific resources while on premises.
Those same users cannot be allowed to access those resources once they have left campus. Which of the following would ensure access is provided according to these requirements?

  • A. Enabling MFA for only those users within the departments needing access
  • B. Configuring UEBA to monitor all access to those resources during non-business hours
  • C. Configuring geofencing with the IPs of the resources
  • D. Implementing a PKI-based authentication system to ensure access

Answer: C

Explanation:
Comprehensive and Detailed Explanation From Exact Extract:
Geofencing is a network access control method that enforces restrictions based on location data. In this scenario, the organization requires access to be permitted only when users are on premises (i.e., within a specific physical location). Geofencing can be implemented using source IP ranges or GPS-based location data to define boundaries (fences). This allows access to certain applications or services only when the user is inside a designated network or area.
MFA (Option A) provides identity assurance but does not enforce physical location-based restrictions.
UEBA (Option C) provides behavioral analytics but is not used for real-time access control.
PKI (Option D) provides identity validation through certificates but is not location-aware.
Relevant Extract from CompTIA CloudNetX CNX-001 Official Study Guide:
"Geofencing allows organizations to define physical or logical boundaries that restrict or allow access based on user location. Policies can be configured to allow access only when users are on a trusted campus or corporate network, denying requests originating from outside the geofenced area." Covered under the topic: "Access Control Technologies and Identity Enforcement Mechanisms."


NEW QUESTION # 34
A network architect is designing a solution to place network core equipment in a rack inside a data center.
This equipment is crucial to the enterprise and must be as secure as possible to minimize the chance that anyone could connect directly to the network core. The current security setup is:
* In a locked building that requires sign in with a guard and identification check.
* In a locked data center accessible by a proximity badge and fingerprint scanner.
* In a locked cabinet that requires the security guard to call the Chief Information Security Officer (CISO) to get permission to provide the key.
Which of the following additional measures should the architect recommend to make this equipment more secure?

  • A. Have the CISO accompany any network engineer that needs to do work in this cabinet.
  • B. Make all engineers with access to the data center sign a statement of work.
  • C. Set up a video surveillance system that has cameras focused on the cabinet.
  • D. Require anyone entering the data center for any reason to undergo a background check.

Answer: C

Explanation:
Comprehensive and Detailed Explanation From Exact Extract:
Adding video surveillance that is focused on the cabinet enhances physical security by providing monitoring, deterrence, and forensic evidence in case of unauthorized access. Video surveillance complements existing layered access controls and is a recognized best practice for protecting high-value network assets.
Relevant Extract from CompTIA CloudNetX CNX-001 Study Guide - under "Physical Security Controls":
"Video surveillance provides 24/7 monitoring and records of physical access to critical infrastructure, supporting audit and incident investigation processes." Other options:
* A. A statement of work is administrative and does not enhance physical security.
* C. CISO accompaniment is impractical and not scalable.
* D. Background checks are useful but are generally a prerequisite and not a real-time security control.


NEW QUESTION # 35
A network architect is designing an expansion solution for the branch office network and requires the following business outcomes:
Maximize cost savings with reduced administration overhead
Easily expand connectivity to the cloud
Use cloud-based services to the branch offices
Which of the following should the architect do to best meet the requirements?

  • A. Design a SD-WAN solution to integrate with the cloud provider; use SD-WAN to connect branch offices to the cloud provider.
  • B. Design point-to-site branch connectivity for offices to headquarters; deploy ExpressRoute and/or DirectConnect between headquarters and the cloud; use headquarters connectivity to connect to the cloud provider.
  • C. Design an MPLS architecture for the branch offices and site-to-site VPN between headquarters and branch offices; use site-to-site connectivity to the cloud provider.
  • D. Design a dark fiber solution for headquarters and branch offices' connectivity; deploy point-to-site VPN between headquarters and the cloud provider; use the headquarters connectivity to the cloud provider.

Answer: A

Explanation:
By deploying SD-WAN you centrally manage and orchestrate all branch connections, minimizing administration overhead, while establishing direct, optimized tunnels into the cloud provider for low-latency, scalable access to cloud services.


NEW QUESTION # 36
......

CompTIA CNX-001 Study Guide Archives : https://www.practicetorrent.com/CNX-001-practice-exam-torrent.html

Pass CNX-001 Exam Latest Practice Questions: https://drive.google.com/open?id=1NOgOd5-fsSNTaKH2jPFFcOy-x-fC3Wpo