dc dotCreds
CompTIA CloudNetX Practice Test

CompTIA CloudNetX Practice Test

Start today’s free 10-question CompTIA CloudNetX set with source-backed explanations, local progress, and a fresh rotation every morning.

10 Free Daily Questions Source-backed Explanations 200 Verified Questions

Questions updated at Aug 23, 2026, 8:12 PM CDT

Go Pro - One Time Unlock

Unlock the full CNX-001 bank

200 verified questions Exam Mode Practice Mode Detailed explanations Weak-area review No subscription - one-time unlock

Get the complete source-backed bank with Interview Questions, the full Study Guide, full Course Notes, detailed explanations, weak-area review, and exam-style practice.

Interview Questions Full Study Guide Full Course Notes Exam Mode Practice Mode Guided Course Detailed explanations Weak-area review No subscription
$4.99 One-time payment
See bundle and PDF options

We will confirm your site email in one quick checkout step.

Why DotCreds?

Practice with explanations that teach.

Source links for every answer Every wrong answer explained Guided Course included Practice and Exam Mode Weak-area tracking Same verified bank across web practice

What you get with free practice

10 Free Questions Daily Fresh set every day from the live bank
Detailed Explanations Learn with clear source-backed answers
Track Your Progress Daily history and performance insights
Upgrade Anytime Unlock the full bank when you are ready
Today's 10 CompTIA CloudNetX questions

Use this CompTIA CloudNetX practice test to review CompTIA CloudNetX. Questions rotate daily and each answer links back to the source used to write it.

Today’s Set
10 questions
Rotates at 10:00 AM local time
Progress
0/10
Answered on this page
Accuracy
0%
Loading countdown…

200 verified questions are in the live bank. Free daily questions are selected from a rotating sample set. Unlock Pro to access the full question bank.

Preparing today’s free questions... Ordering the final locked-bank set before showing the practice cards.
Question 1 of 10
Objective 3.1 — Operate and maintain network environments Network Operations, Monitoring, and Performance (16%)

Over one quarter, a WAN service experiences four failures. Mean time to detect drops from 20 minutes to 4 minutes, but repair work still takes an average of 90 minutes after detection. Which metric improved while the principal restoration metric did not?

Concept tested:
Question 2 of 10
Objective 1.4 — Design network availability and redundancy Network Architecture Design (31%)

A stateless API tier experiences a 10× traffic spike for 15 minutes every morning. The load balancer remains healthy, but fixed backend capacity causes queueing and 5xx responses. Which paired design best addresses both distribution and capacity?

Concept tested:
Question 3 of 10
Objective 2.3 — Configure network access controls Network Security (28%)

An application security group should allow database connections only from members of the application-tier security group, even as instances autoscale and addresses change. Which rule design is best?

Concept tested:
Question 4 of 10
Objective 3.1 — Operate and maintain network environments Network Operations, Monitoring, and Performance (16%)

A cloud audit finds unattached public IPs, idle load balancers, and old NAT gateways left behind after projects were deleted. They continue to generate charges. Which cost-management action is most direct?

Concept tested:
Question 5 of 10
Objective 4.4 — Troubleshoot network connectivity Network Troubleshooting (25%)

Traceroute alternates repeatedly between routers R3 and R4 until TTL expires, and neither router has an interface failure. Which connectivity issue is most strongly indicated?

Concept tested:
Question 6 of 10
Objective 1.8 — Select architecture documentation artifacts Network Architecture Design (31%)

A regulated project has a business requirement for 99.99% availability, a technical requirement for dual diverse paths, and a regulatory requirement that inspection logs be retained. During validation, the team must prove each implemented control traces back to an approved requirement. Which practice best supports that goal?

Concept tested:
Question 7 of 10
Objective 2.5 — Apply identity and access management controls Network Security (28%)

An HR system is authoritative for employees. When a worker is hired, transferred, or terminated, accounts and group memberships in dozens of SaaS applications should be created, updated, or disabled automatically. Which standard is most directly intended for this lifecycle synchronization?

Concept tested:
Question 8 of 10
Objective 3.2 — Monitor network health and performance Network Operations, Monitoring, and Performance (16%)

A NOC dashboard normally shows 3–8 ms latency on a private interconnect. It rises to 18 ms after a maintenance event but remains below a generic 50-ms static alert threshold. Users report a measurable transaction slowdown. What monitoring improvement is best?

Concept tested:
Question 9 of 10
Objective 4.6 — Troubleshoot Wi-Fi performance Network Troubleshooting (25%)

A warehouse has dead zones behind metal shelving. AP channel plan is clean, but surveys show signal attenuation and low RSSI only behind the racks. Which remediation should be evaluated first?

Concept tested:
Question 10 of 10
Objective 1.6 — Select campus wired-network components and designs Network Architecture Design (31%)

A campus has 350 access switches. The current Layer 2 domain spans buildings, causing large STP reconvergence events and broad broadcast failure domains. The redesign should localize failures while preserving scalable routing to the core. Which change is most appropriate?

Concept tested:
Locked preview

You are viewing today’s free 10. Unlock 190 more questions.

Unlock full bank
Daily sample Rotating practice Free daily questions are selected from a rotating sample set.
Pro bank Full access Unlock Pro to access the full question bank, Exam Mode, Practice Mode, and random tests.
CNX-001 Pro $4.99 one-time

50 Exam Practice Test $1.99 one-time

A 50-question CNX-001 PDF for short review sessions. Questions come first, then the answer review and explanations later in the file.

CompTIA Infrastructure Bundle $9.99 one-time

Unlock all 4 active CompTIA Infrastructure Bundle practice banks in one permanent purchase.

What’s includedLinux+, Server+, Cloud+, CloudNetX
All Access $6.99/month

Unlock every active practice exam, bundle and path experience, Pro course and study content, and included downloads.

What’s includedEvery current and future active practice exam, All active bundle and career-path practice content, Pro course lessons, study content, and supported paid downloads

Choose an unlock option to continue. We will confirm your site email in one quick checkout step.

Secure checkout powered by Stripe. Source-backed questions. Not brain dumps. Checkout stays on this page and unlocks the same Pro builder on this practice page.

Purchase options

Unlock the full CNX-001 bank.

Get the full bank, Exam Mode, Practice Mode, question sets, random tests, readiness tracking, saved box scores, and review tools for this exam.

The PDF versions keep questions first and move the answer review, explanations, and distractor notes to the back of the file.

200 verified exam-style questions Every choice explained Exam Mode and Practice Mode Question sets and random tests Readiness score and trends Previous test box scores

You've answered 0/10 questions in today's set.

Locked: 190 more questions in the full bank.

Locked: exam simulation mode, practice mode, readiness tracking, and saved review history.

Checkout stays on this page, so you can keep practicing, unlock the full bank, and start Exam Mode or Practice Mode when you are ready.

Cheat Sheets

7-day score keeper

Answer questions today and this will become a rolling 7-day scorecard.

Local history
Optional progress sync

Keep today’s practice moving

Guest progress saves automatically on this device. Add an email later when you want a magic link that keeps your daily CNX-001 practice in sync across browsers.

Guest progress saves on this device automatically

Guest progress is available without an account.

Source-backed answer review

The free daily CompTIA CloudNetX set includes crawlable question text, answer choices, correct answer labels, objective mapping, and source links. Only the first SEO card includes answer explanations and any extra learning features. Pro-only bank questions stay locked; this section mirrors only the 10 free daily questions already shown on this page.

Question 1 Over one quarter, a WAN service experiences four failures. Mean time to detect drops from 20 minutes to 4 minutes, but repair work still takes an average of 90 minutes after detection. Which metric improved while the principal restoration metric did not?

Answer choices

  1. A. MTTD improved; MTTR remains roughly 90 minutes plus any defined measurement boundary for repair, under end-to-end security-and-governance requirements.
  2. B. MTBF improved because detection is faster, under the stated technical, operational, and governance constraints.
  3. C. RPO improved automatically, for the described technical objective and its associated operational control requirements, as described.
  4. D. CapEx decreased, for the described technical objective and its associated operational control requirements, within the proposed design.

Correct answer

MTTD improved; MTTR remains roughly 90 minutes plus any defined measurement boundary for repair, under end-to-end security-and-governance requirements.

Detection became faster, but the time required to restore service after the failure was detected did not change.

Wrong-answer review

  • B. MTBF improved because detection is faster, under the stated technical, operational, and governance constraints.: Incorrect. Failure frequency/spacing did not improve merely because failures were detected sooner.
  • C. RPO improved automatically, for the described technical objective and its associated operational control requirements, as described.: Incorrect. Detection speed does not directly change tolerated data loss.
  • D. CapEx decreased, for the described technical objective and its associated operational control requirements, within the proposed design.: Incorrect. No capital-spending information is provided.

Extra learning features

Why candidates miss this

The distractor 'MTBF improved because detection is faster' is tempting because it links detection speed to overall system reliability. However, MTBF (Mean Time Between Failures) measures the *time between failures*, not the speed of detection. The core issue is the repair time, which remains unchanged, directly contradicting MTBF's definition. Likely wrong answer: MTBF improved because detection is faster. Review focus: NIST SP 800-34 Rev. 1 — Contingency Planning Guide

Interview question

Q: Detection became faster, but the time required to restore service after the failure was detected did not change. This highlights the critical difference between MTTD and MTTR, where faster detection alone doesn't necessarily translate to quicker overall recovery. Understanding this distinction is crucial for accurately assessing network performance and prioritizing restoration efforts. Strong answer: MTTD improved; MTTR remains roughly 90 minutes plus any defined measurement boundary for repair.

  • MTTD
  • MTTR
  • detection
  • repair

Caution: The question asks for a single metric improvement, not a general statement about network performance.

Why this matters

A WAN service experiencing frequent failures, even with faster detection, represents a significant operational risk. If repair times remain lengthy, the impact on business operations – lost revenue, disrupted services, and damaged customer relationships – escalates dramatically. Faster detection is only half the solution; optimizing the subsequent repair process is equally vital.

Objective/domain: Network Operations, Monitoring, and Performance (16%)

Source: NIST SP 800-34 Rev. 1 — Contingency Planning Guide

Question 2 A stateless API tier experiences a 10× traffic spike for 15 minutes every morning. The load balancer remains healthy, but fixed backend capacity causes queueing and 5xx responses. Which paired design best addresses both distribution and capacity?

Answer choices

  1. A. Use health-aware load balancing in front of an autoscaling backend pool, for the stated implementation and support requirements.
  2. B. Increase DNS TTL and keep a fixed backend pool, for the stated requirement.
  3. C. Replace the load balancer with a single larger server, within the described operational context.
  4. D. Enable link aggregation on one backend, as the proposed design for the complete governed operational workflow.

Correct answer

Use health-aware load balancing in front of an autoscaling backend pool, for the stated implementation and support requirements.

Objective/domain: Network Architecture Design (31%)

Source: AWS Well-Architected Framework — Reliability Pillar

Question 3 An application security group should allow database connections only from members of the application-tier security group, even as instances autoscale and addresses change. Which rule design is best?

Answer choices

  1. A. Allow the entire VPC CIDR to the database port, within the documented operational, security, ownership, and validation requirements.
  2. B. Allow 0.0.0.0/0 and rely on database passwords, for the described technical objective and its associated operational control requirements, when applied.
  3. C. Pin the rule to the first application's ephemeral IP address, within organization-wide risk-and-accountability boundaries.
  4. D. Reference the application-tier security group or equivalent workload identity as the database rule source, as the selected response to the described condition.

Correct answer

Reference the application-tier security group or equivalent workload identity as the database rule source, as the selected response to the described condition.

Objective/domain: Network Security (28%)

Source: NIST SP 800-41 Rev. 1 — Guidelines on Firewalls and Firewall Policy

Question 4 A cloud audit finds unattached public IPs, idle load balancers, and old NAT gateways left behind after projects were deleted. They continue to generate charges. Which cost-management action is most direct?

Answer choices

  1. A. Identify ownership and remove or reclaim validated orphaned resources through lifecycle controls, within the described operational context.
  2. B. Increase the service's RTO, as the proposed design for the complete governed operational workflow.
  3. C. Add another monitoring dashboard without remediation, as the primary implementation for the described business requirement.
  4. D. Advertise the resources through BGP, for the described technical objective and its associated operational control requirements.

Correct answer

Identify ownership and remove or reclaim validated orphaned resources through lifecycle controls, within the described operational context.

Objective/domain: Network Operations, Monitoring, and Performance (16%)

Source: FinOps Framework

Question 5 Traceroute alternates repeatedly between routers R3 and R4 until TTL expires, and neither router has an interface failure. Which connectivity issue is most strongly indicated?

Answer choices

  1. A. A duplicate DNS A record, under the organization’s defined implementation and exception-management process.
  2. B. A routing loop between R3 and R4, under organization-wide implementation-governance requirements.
  3. C. Client port exhaustion, under the proposed approach.
  4. D. A certificate trust failure, as the primary proposed approach.

Correct answer

A routing loop between R3 and R4, under organization-wide implementation-governance requirements.

Objective/domain: Network Troubleshooting (25%)

Source: RFC 4271 — Border Gateway Protocol 4 (BGP-4)

Question 6 A regulated project has a business requirement for 99.99% availability, a technical requirement for dual diverse paths, and a regulatory requirement that inspection logs be retained. During validation, the team must prove each implemented control traces back to an approved requirement. Which practice best supports that goal?

Answer choices

  1. A. Keep only the final physical diagram, for the described technical objective and its associated operational control requirements.
  2. B. Rely on verbal sign-off from the lead architect, for the described technical objective and its associated operational control requirements, for this scenario.
  3. C. Maintain requirements traceability and verification/validation evidence linking each requirement to design elements and tests, for the required outcome.
  4. D. Use only a vendor reference architecture, for the described technical objective and its associated operational control requirements, as the selected response to the described condition.

Correct answer

Maintain requirements traceability and verification/validation evidence linking each requirement to design elements and tests, for the required outcome.

Objective/domain: Network Architecture Design (31%)

Source: NIST SP 800-160 Vol. 1 Rev. 1 — Engineering Trustworthy Secure Systems

Question 7 An HR system is authoritative for employees. When a worker is hired, transferred, or terminated, accounts and group memberships in dozens of SaaS applications should be created, updated, or disabled automatically. Which standard is most directly intended for this lifecycle synchronization?

Answer choices

  1. A. SAML
  2. B. TLS, as described.
  3. C. SCIM, as the primary proposed approach.
  4. D. BGP, for the stated scenario.

Correct answer

SCIM, as the primary proposed approach.

Objective/domain: Network Security (28%)

Source: RFC 7644 — System for Cross-domain Identity Management Protocol

Question 8 A NOC dashboard normally shows 3–8 ms latency on a private interconnect. It rises to 18 ms after a maintenance event but remains below a generic 50-ms static alert threshold. Users report a measurable transaction slowdown. What monitoring improvement is best?

Answer choices

  1. A. Raise the static threshold to 100 ms, within cross-functional operational-accountability boundaries.
  2. B. Disable latency alerts and monitor only CPU, as the proposed design for the complete governed operational workflow.
  3. C. Alert on every single packet, for the described technical objective and its associated operational control requirements, as selected.
  4. D. Use service-specific baselines and anomaly/deviation alerting in addition to absolute thresholds, as described.

Correct answer

Use service-specific baselines and anomaly/deviation alerting in addition to absolute thresholds, as described.

Objective/domain: Network Operations, Monitoring, and Performance (16%)

Source: NIST SP 800-53 Rev. 5 — Security and Privacy Controls

Question 9 A warehouse has dead zones behind metal shelving. AP channel plan is clean, but surveys show signal attenuation and low RSSI only behind the racks. Which remediation should be evaluated first?

Answer choices

  1. A. Change the default gateway, for the described technical objective and its associated operational control requirements, within the network troubleshooting (25%) context.
  2. B. Increase DNS resolver capacity, for the described technical objective and its associated operational control requirements, within this design.
  3. C. Adjust AP/antenna placement or use suitable directional coverage to overcome the physical obstruction while revalidating the RF plan, as presented.
  4. D. Rotate TLS certificates, for the described technical objective and its associated operational control requirements, within the documented scope, ownership, and validation boundaries.

Correct answer

Adjust AP/antenna placement or use suitable directional coverage to overcome the physical obstruction while revalidating the RF plan, as presented.

Objective/domain: Network Troubleshooting (25%)

Source: NIST SP 800-153 — Guidelines for Securing WLANs

Question 10 A campus has 350 access switches. The current Layer 2 domain spans buildings, causing large STP reconvergence events and broad broadcast failure domains. The redesign should localize failures while preserving scalable routing to the core. Which change is most appropriate?

Answer choices

  1. A. Extend every VLAN through the core to all buildings, for the described technical objective and its associated operational control requirements.
  2. B. Disable STP so links never block, for the described technical objective and its associated operational control requirements, as described.
  3. C. Move Layer 3 boundaries closer to the access/distribution edge and use routed uplinks instead of stretching Layer 2 campus-wide, for the described technical objective.
  4. D. Use one larger broadcast domain with higher-capacity links, for the described technical objective and its associated operational control requirements, in context.

Correct answer

Move Layer 3 boundaries closer to the access/distribution edge and use routed uplinks instead of stretching Layer 2 campus-wide, for the described technical objective.

Objective/domain: Network Architecture Design (31%)

Source: Cisco Campus LAN and Wireless LAN Solution Design Guide

Where to go after the daily web set

How are CompTIA CloudNetX questions generated?

dotCreds builds CompTIA CloudNetX practice questions from public exam objectives and CompTIA exam objectives and source-backed references. The questions are written for realistic study practice, not copied from exam dumps.

How are explanations sourced?

Each question includes an explanation and, when available, a source link back to the provider documentation or reference used to validate the answer. That keeps the practice tied to study material you can actually review.

What score do I get?

The page tracks today's answered count and accuracy for the 10-question daily set, then saves a 7-day score history on this device so you can see your recent practice trend.

Why use this site?

The site is the fastest way to start CompTIA CloudNetX practice without installing anything. It is built for daily recall, quick weak-topic discovery, and source-backed explanations you can review immediately.