5.0 Network Troubleshooting N10-009 Practice Quiz

388 exam-style questions covering 24% of the N10-009 exam. Instant feedback on every answer, progress tracking, no signup required.

This domain is part of the CompTIA Network+ practice test. Each question is tagged by exam objective and difficulty so you can drill exactly the areas you need.

Sample Questions

A user calls the help desk reporting their computer cannot access the internet but can access the internal file server. What CompTIA troubleshooting methodology step comes first and what questions should be asked?
  • A. The first step is Identify the Problem, gathering information by questioning the user: When did the problem start? What were you doing when it first occurred? Has anything changed recently (new software installed, Windows update, cable moved)? Does anyone else in your area have the same problem? Can you access any internet site or just some? This information narrows the scope, the fact that the file server is accessible but the internet is not suggests the workstation IP configuration, default gateway, or DNS may be the issue rather than the physical connection; approaching systematically with questions before taking action prevents wasted effort chasing the wrong cause
  • B. The first step is to immediately reboot the user's computer; rebooting resolves most network issues and should always be the first action before gathering any information
  • C. The first step is to check all firewall rules; internet access problems are always caused by firewall misconfigurations and the help desk should review the firewall rule set before asking the user any questions
  • D. The first step is to escalate immediately to the network team; help desk staff should not troubleshoot network issues and must escalate without gathering any information to avoid causing further problems

Identify the Problem is explicitly step one in CompTIA's troubleshooting methodology; gathering information through user questions provides the data needed to form an intelligent theory; the symptom pattern (internal works, internet fails) already provides diagnostic value before any technical investigation begins. This is the correct answer.

A network technician installs a 90-meter Cat5e cable run. Users on that run report slow and unreliable connectivity. Testing shows high error rates but the cable tests pass continuity. What physical layer issues could cause this and what is the likely cause?
  • A. Several physical layer issues could cause high error rates on a passing-continuity cable: attenuation, at 90 meters (near the 100m Cat5e limit) signal strength is reduced and combined with any connector losses, patch cable lengths, or aging cable quality could push the channel over the attenuation limit causing bit errors; crosstalk, if the cable was installed near fluorescent lights, power cables, or other EMI sources interference causes errors that do not show as opens or shorts in continuity testing; improper termination, if pairs were untwisted beyond 13mm at terminations the reduced twist degrades crosstalk performance causing near-end crosstalk (NEXT) errors; the most likely cause at 90m with existing errors is that the total channel length (90m plus patch cables at each end) may exceed 100m or the cable quality and termination combined are insufficient for the attenuation budget; verify with a cable certification tester not just continuity tester
  • B. Cat5e cannot physically carry data at distances over 50 meters; 90 meters exceeds the absolute maximum for any Ethernet standard; the entire cable run must be replaced with fiber optic
  • C. The errors are caused by incorrect IP addressing; physical cable errors and IP configuration errors produce identical symptoms; change the IP subnet mask before investigating the physical layer
  • D. Cat5e cable runs longer than 50 meters require a signal booster (repeater) every 25 meters; without boosters all Cat5e runs over 50m experience the described errors; install repeaters at 50m intervals

Attenuation, crosstalk, and improper termination all cause bit errors without showing as continuity failures; a continuity tester only verifies conductors connect end-to-end; a certification tester measures the actual electrical performance parameters (insertion loss, NEXT, return loss) needed to confirm Cat5e compliance. This is the correct answer.

A network engineer has identified that intermittent packet loss affects 30 users on VLAN 20. They form two competing theories: (1) a failing switch uplink port, (2) a spanning tree topology change causing brief forwarding interruptions. How does the methodology guide testing both theories and what does divide and conquer mean in this context?
  • A. The engineer should implement both solutions simultaneously; fixing both the switch port and the spanning tree configuration at the same time resolves the issue faster than testing one at a time
  • B. Divide and conquer means dividing the work between two engineers; one engineer tests Theory 1 while another simultaneously tests Theory 2 and implements both fixes; the divide refers to dividing the labor not the diagnostic approach
  • C. CompTIA methodology requires testing each theory independently to confirm or deny it: for Theory 1 (failing port) the engineer checks interface error counters (show interface) looking for incrementing CRC errors, input errors, or output drops on the uplink; if errors are present and correlate with the outage timing the theory is confirmed; for Theory 2 (STP topology changes) the engineer checks show spanning-tree detail for topology change counts and timing correlation; divide and conquer means starting testing at the most likely failure layer rather than always starting at Layer 1 or Layer 7, since both theories point to Layer 2 the engineer tests there directly instead of starting from physical cable inspection; if Theory 1 is confirmed the next step is replacing the port or cable; if not confirmed a new theory is established or escalation occurs; testing one theory at a time prevents confusion about which fix resolved the problem
  • D. Both theories should be dismissed and the engineer should start fresh with a bottom-to-top OSI approach beginning with physical layer inspection of every cable connected to VLAN 20 regardless of which theories have been formed

Testing theories individually with specific diagnostic commands and divide-and-conquer starting at the most likely OSI layer are both correct methodology applications; interface error counters and STP topology change counters are the specific evidence sources for each theory. This is the correct answer.

A help desk ticket describes: My VPN keeps disconnecting every hour. The engineer asks when it started and the user says after the IT update last Tuesday. Which methodology step does determine if anything has changed serve and how does this information narrow the investigation?
  • A. Determine if anything has changed is the final step in the methodology used only after all other approaches have failed; the IT update information should be gathered last not early in the troubleshooting process
  • B. Determine if anything has changed is part of the Identify the Problem step, gathering information about recent changes is critical because most network problems correlate with recent changes; knowing the IT update happened Tuesday and the VPN disconnections started Tuesday immediately narrows the investigation from why does VPN disconnect (broad) to what did the Tuesday update change that affects VPN session persistence (specific); the engineer can review the change log for Tuesday's update looking for VPN client software updates, certificate changes, firewall rule modifications, or security policy changes affecting session timeout; this dramatically reduces investigation time compared to starting from scratch; the information also helps form an initial theory before any technical diagnostic work begins
  • C. The information about the IT update is irrelevant because IT updates are always tested before deployment and cannot cause production issues; the engineer should disregard the timing correlation and look for other causes
  • D. Determine if anything has changed is a separate step that occurs after establishing a theory; the timing information gathered from the user would only be used after the engineer has independently identified a suspected cause

Change correlation is one of the most powerful troubleshooting shortcuts; when problem onset correlates with a known change the investigation starts at the change rather than at an open-ended search; the methodology explicitly includes Determine if anything has changed as part of information gathering for this reason. This is the correct answer.

A fiber optic link between two switches shows the interface as up but experiences intermittent packet loss. The transceiver receive power is -18 dBm and the minimum receiver sensitivity is -20 dBm. The TX power is +1 dBm and fiber loss budget is 3 dB. What is the optical power budget situation and what could explain the intermittent packet loss?
  • A. The link is fine; -18 dBm receive power is above the -20 dBm minimum sensitivity providing 2 dB of margin; no investigation is needed as the link meets specifications
  • B. The intermittent packet loss is caused by the switches automatically renegotiating speed and duplex; fiber optic links cannot negotiate properly and always require manual speed configuration; set both switches to 1000 full duplex to resolve the intermittent packet loss
  • C. The power budget analysis: TX power +1 dBm minus fiber loss budget 3 dB equals expected receive power of -2 dBm; actual receive power is -18 dBm indicating approximately 16 dB of unaccounted loss; the link barely passes minimum sensitivity (-18 dBm vs -20 dBm minimum) with only 2 dB margin; the margin is dangerously low and intermittent packet loss results when any additional loss occurs such as temperature fluctuations causing connector expansion, micro-bends under varying building stress, or contaminated connector faces that sometimes partially block light; while the link works the 2 dB margin is insufficient for reliable operation (standard design allows 3-6 dB margin); the 16 dB unexplained loss difference indicates: dirty or damaged connectors causing high connector loss, a cracked or excessively bent fiber causing micro-bend loss, or incorrect fiber type (mixing single-mode and multimode); the fix requires cleaning all connectors with proper cleaning tools, inspecting connectors with a fiber microscope, and using an OTDR to locate high-loss points along the link
  • D. The -18 dBm receive power indicates the fiber is transmitting in the wrong direction; TX and RX fibers are transposed at one of the connectors; swapping the TX and RX strands resolves the packet loss and brings receive power to the expected level

Power budget analysis revealing 16 dB of unexplained loss alongside inadequate margin is the correct diagnostic approach; contaminated connectors are the most common cause of high fiber optic connector loss and are easily remediated with proper cleaning. This is the correct answer.

A change management system shows that a routing protocol configuration was changed at 2 PM yesterday. Network performance issues began at 2:15 PM and continue. The network engineer confirms the theory that the routing change caused suboptimal path selection. What are the next methodology steps and what documentation is required?
  • A. Immediately roll back the routing change without further analysis; any change that correlates with a problem should be automatically reverted without establishing a plan of action
  • B. After confirming the theory immediately escalate to management before taking any action; the engineer should not implement any resolution without explicit management approval for every change regardless of severity or urgency
  • C. The methodology is complete once the theory is confirmed; documentation is optional and only required for major outages; for performance issues the engineer should implement the fix without further planning or documentation
  • D. After confirming the theory the methodology steps are: Establish a Plan of Action, determine whether to roll back the routing change (fastest resolution) or modify the configuration to achieve the intended goal without the performance impact; identify potential effects of each option; Implement the Solution, execute the plan; Verify Full System Functionality, confirm the performance issue is resolved, check that routing behaves as expected, verify no other services were affected; Document Findings, record in the change management system the root cause (routing change caused suboptimal path selection), the symptoms and their timeline, the diagnostic steps taken, the resolution applied, and lessons learned (perhaps improve change testing procedures to catch routing impact before production); documentation ensures the organization learns from the incident

Plan of action, implementation, verification, and documentation are the final four steps of CompTIA's methodology after theory confirmation; each step serves a specific purpose; documentation is explicitly mandatory throughout the process. This is the correct answer.

A new 10GBase-T deployment fails certification testing on multiple cable runs. The tester shows ANEXT (Alien Near-End Crosstalk) failures on bundled cables but individual cables pass when tested alone. What does this indicate and what installation practice corrections are needed?
  • A. ANEXT failures indicate the cables are too long; shorten all cable runs to under 50 meters and ANEXT will pass; length is the only factor affecting ANEXT in Cat6A deployments
  • B. ANEXT failures are caused by incorrect cable jacket color; Cat6A cables must use a specific jacket color for 10GBase-T certification; ensure all cables in the bundle use the same jacket color to resolve ANEXT failures
  • C. ANEXT failures indicate the wrong tester was used; ANEXT is not a real certification parameter and does not affect network performance; recertify with a standard Cat6 tester that does not measure ANEXT to pass the certification
  • D. ANEXT failures on bundled cables that pass individually indicate that electromagnetic coupling between adjacent cables is exceeding the Cat6A specification; 10GBase-T is uniquely sensitive to alien crosstalk because it uses all four pairs simultaneously for bidirectional transmission at high frequencies (500 MHz for Cat6A); individual cable testing isolates each cable removing the coupling effect; when bundled together the transmissions on neighboring cables induce interference in the test cable; installation practice corrections include: maintaining proper cable separation; using individually shielded Cat6A (F/UTP or S/FTP) instead of unshielded Cat6A which relies on physical separation for ANEXT compliance; avoiding tightly cinching cable bundles with zip ties which compress cables together increasing coupling; using horizontal cable managers that space cables rather than bundling them; verifying that Cat6A cable was used consistently and not mixed with Cat6 which cannot meet ANEXT specifications; re-testing with cables separated to confirm the bundling is the cause

Bundling-induced ANEXT failure is the exact scenario that the Cat6A standard was developed to address; the 500 MHz bandwidth requirement for 10GBase-T made ANEXT a critical specification that Cat6 cannot meet; separation and shielding are the correct remediation approaches for ANEXT failures in bundled installations. This is the correct answer.

A switch interface shows incrementing CRC errors and occasional runts. What do these counters indicate and what physical layer causes should be investigated?
  • A. CRC errors indicate software corruption in the switch operating system and runts indicate that the switch is overloaded; upgrade the switch firmware and add more RAM to resolve both counters
  • B. CRC (Cyclic Redundancy Check) errors indicate frames arrived with invalid checksums, the frame data was corrupted in transit and failed the integrity check; common causes include damaged cables, dirty or oxidized connectors, EMI interference on the cable, and duplex mismatches; runts are frames smaller than the minimum Ethernet frame size (64 bytes) indicating either collisions causing truncated frames (duplex mismatch) or a malfunctioning NIC generating undersized frames; both symptoms together strongly suggest a duplex mismatch between the switch port and the connected device (one side is full-duplex, the other is half-duplex causing collisions and corrupt short frames), cable damage or excessive length, or a failing NIC; verify the duplex setting on both the switch port and connected device as the first diagnostic step
  • C. CRC errors and runts are normal on all busy switch ports; any port transmitting more than 1000 frames per minute generates CRC errors and runts as a normal byproduct of high utilization; these counters do not require investigation unless they exceed 5 percent of total frames
  • D. CRC errors indicate the cable is too long and runts indicate the cable is too short; adjust the cable length to the correct specification for the interface type to clear both counters

CRC and runt correlation pointing to duplex mismatch is the classic interface counter diagnostic pattern; duplex mismatches create a situation where the full-duplex side transmits continuously while the half-duplex side expects collision detection pauses, generating collisions that produce truncated frames (runts) and checksum failures (CRC errors). This is the correct answer.

Link to this quiz

Studying with a group or teaching a class? Send this address or paste the link into your notes, wiki, or course page:

https://quizbuffet.com/comptia-network-plus/network-troubleshooting/

<a href="https://quizbuffet.com/comptia-network-plus/network-troubleshooting/">CompTIA Network+ Network Troubleshooting practice quiz on QuizBuffet</a>

Other N10-009 Domains

← Back to N10-009 practice test overview

Questions are written against the published N10-009 objectives and checked for accuracy and balance before they go live. How QuizBuffet writes and reviews its questions.