CNX-001 Sample Questions & Answers
Designing hybrid connectivity into cloud network architectures carries the most weight, alongside identifying threats and mitigating them with access controls, resolving connectivity and performance problems, and day-to-day automation.
Launch the full CNX-001 simulator →Showing 10 of 20 free samples.
- Question 1Advanced
Network Security · Implementing microsegmentation for east-west traffic control
A healthcare organization is deploying a new critical patient records application in a public cloud VPC. To comply with HIPAA, all traffic between the application servers and the database servers must be isolated from other workloads and inspected for threats. The application tier consists of an auto-scaling group of virtual machines. What is the MOST effective way to enforce this security requirement?
Show answer & explanation
Correct answer: C
Microsegmentation provides the most granular and effective control for this scenario. An agent-based solution can enforce policies based on workload identity (e.g., tags, labels) rather than brittle IP addresses, which is crucial in an auto-scaling environment where IPs are dynamic. This allows for strict isolation and inspection of east-west traffic between the application and database tiers, regardless of their location or IP address, fulfilling the HIPAA compliance requirement.
- Question 2Intermediate
Network Architecture Design · Designing global load balancing solutions
A network architect is designing a global load balancing solution for a web application hosted in three different cloud regions: US-East, EU-West, and AP-Southeast. The goal is to provide the lowest latency for users worldwide and ensure automatic failover if an entire region becomes unavailable. Which DNS-based load balancing policy should be implemented to achieve these goals?
Show answer & explanation
Correct answer: C
A Geolocation routing policy directs users to the endpoint in the region geographically closest to them, minimizing latency. Combining this with a failover policy (often configured via health checks) ensures that if the primary region for a user becomes unhealthy, their DNS queries will be automatically resolved to the next-closest healthy region. This combination directly addresses both the low-latency and high-availability requirements.
- Question 3Intermediate
Network Troubleshooting · Troubleshooting BGP route selection
A company has established a hybrid cloud connection using AWS Direct Connect. They are using BGP to advertise routes between their on-premises network and their AWS VPC. An administrator notices that traffic from the on-premises network to a specific subnet in the VPC is taking a suboptimal path through a backup VPN connection instead of the Direct Connect link. Which BGP attribute should be modified on the on-premises router to make the Direct Connect path more preferable?
Show answer & explanation
Correct answer: B
Local Preference is a BGP attribute used to influence outbound traffic paths within a single Autonomous System (AS). By setting a higher Local Preference value for the routes received over the Direct Connect link, the on-premises router will prefer that path for egress traffic to AWS over the path learned via the backup VPN. AS Path Prepending is used to influence inbound traffic, not outbound.
- Question 4Intermediate
Network Operations, Monitoring, and Performance · Scripting for network operations
A systems administrator is tasked with writing a Python script to automate the process of checking the status of hundreds of network devices. The script needs to run concurrently to be efficient. The primary task is to send an ICMP echo request to each device and wait for a reply. Which Python library would be the MOST suitable for handling these concurrent, I/O-bound operations?
Show answer & explanation
Correct answer: C
The
asynciolibrary is ideal for I/O-bound and high-level structured network code. Sending a network request and waiting for a reply is a classic I/O-bound task.asynciouses a single-threaded, single-process cooperative multitasking model (event loop) that allows it to handle thousands of concurrent connections efficiently with less overhead than threading or multiprocessing, which are better suited for CPU-bound tasks. - Question 5Beginner
Network Troubleshooting · Troubleshooting VPN Phase 1 issues
A network engineer is configuring a new site-to-site IPsec VPN tunnel between a corporate headquarters and a new branch office. After configuring both endpoints, the engineer observes that the tunnel fails to establish. Log analysis on the headquarters' firewall shows the following message:
Phase 1 IKE proposal mismatch. What is the MOST likely cause of this error?Show answer & explanation
Correct answer: B
The IKE Phase 1 process involves negotiating a set of security parameters (a security association or SA) between the VPN peers. These parameters include the encryption algorithm (e.g., AES-256), hashing algorithm (e.g., SHA-256), authentication method (e.g., pre-shared key), and Diffie-Hellman group. A 'proposal mismatch' error explicitly indicates that the set of these parameters sent by one peer is not acceptable to or does not match a configured policy on the other peer.
- Question 6Beginner
Network Architecture Design · Configuring CDN caching policies
An e-commerce platform uses a Content Delivery Network (CDN) to accelerate its website for global users. The development team frequently updates product images, but users report seeing old images for several hours after an update. Which CDN feature should be used to resolve this issue promptly?
Show answer & explanation
Correct answer: C
CDNs cache content at edge locations based on a Time-to-Live (TTL) value to reduce requests to the origin server. When content is updated at the origin before the TTL expires, the CDN will continue to serve the old, cached version. Cache invalidation (or purging) is a mechanism to manually force the CDN to remove a specific object from its cache, compelling it to fetch the latest version from the origin on the next request.
- Question 7Intermediate
Network Security · Understanding Privileged Access Management (PAM) features
A security team is implementing a Privileged Access Management (PAM) solution to secure administrative access to critical infrastructure in a hybrid cloud environment. A primary goal is to eliminate standing privileges and reduce the attack surface. Which PAM feature directly supports this goal by granting administrative rights only for the duration of a specific, approved task?
Show answer & explanation
Correct answer: B
Just-in-Time (JIT) access is a core feature of modern PAM solutions that embodies the principle of least privilege. Instead of users having persistent, or 'standing,' administrative rights, JIT access allows for the temporary elevation of privileges for a specific purpose and a limited time. Once the task is complete or the time expires, the privileges are automatically revoked, thus eliminating standing privileges and significantly reducing the attack surface.
- Question 8Intermediate
Network Architecture Design · Configuring SD-WAN policies
A manufacturing company uses an SD-WAN solution to connect its factories to cloud applications. To ensure production is not impacted, the real-time industrial control system (ICS) traffic must always have the highest priority and lowest latency, while bulk data uploads from machinery can tolerate higher latency. Which SD-WAN feature should be configured to meet these requirements?
Show answer & explanation
Correct answer: B
Application-aware routing is a key feature of SD-WAN that allows the creation of policies based on application identification (e.g., Layer 7 inspection). An administrator can define a policy that identifies the ICS traffic and steers it over the highest-quality, lowest-latency path (e.g., an MPLS circuit), while routing the less critical bulk data uploads over a lower-cost broadband link. This ensures service level agreements (SLAs) are met for critical applications.
- Question 9AdvancedSelect 2
Network Operations, Monitoring, and Performance · Managing alerting and notification systems
A network operations center (NOC) is experiencing a high volume of alerts from their monitoring system, leading to 'alert fatigue' and potentially missed critical events. The lead engineer wants to implement a solution that only triggers notifications for sustained issues and automatically groups related alerts from different systems (e.g., a router failure causing multiple application alerts). Which set of techniques would BEST address this problem? (Select TWO).
Show answer & explanation
Correct answers: B, C
Using time-based thresholds (e.g., 'CPU > 90% for 5 minutes') prevents alerts from firing for transient spikes or momentary blips, which are a common cause of alert noise. This ensures that the NOC is only notified of sustained problems that require attention.
An event correlation engine or an AIOps (AI for IT Operations) platform is designed to ingest alerts from multiple sources and use algorithms or rules to identify relationships. It can group symptomatic alerts (e.g., 'application unavailable') under a single root cause alert (e.g., 'router down'), drastically reducing the number of notifications and helping the NOC focus on the actual problem.
- Question 10Intermediate
Network Operations, Monitoring, and Performance · Designing business continuity and disaster recovery solutions
A network architect is designing a disaster recovery (DR) plan for a critical application. The business has defined a Recovery Time Objective (RTO) of 15 minutes and a Recovery Point Objective (RPO) of 1 hour. Which DR strategy would be the MOST appropriate and cost-effective choice to meet these requirements?
Show answer & explanation
Correct answer: B
A Pilot Light strategy involves replicating data to a DR site and keeping a minimal, core set of services running (the 'pilot light'). In a disaster, the full infrastructure can be quickly scaled up around this core. This approach provides a much faster RTO (minutes to hours) than Backup and Restore, and is more cost-effective than a full Warm or Hot Standby. It can comfortably meet a 15-minute RTO and 1-hour RPO with proper automation.
Ready for the real thing?
The full CNX-001 simulator has every exam-style question, timed mode, and instant scoring.