N10-009 exam dumps

N10-009 practice question 236 of 329

Network+. Associate level, CompTIA. Free question with the correct answer and a full explanation.

N10-009 Question 236

Single answerTime protocols: NTP, Precision Time Protocol (PTP), Network Time Security (NTS)

A manufacturing company is deploying high-speed robotics and industrial cameras on a converged Ethernet network. The control systems require sub-microsecond clock synchronization between devices so that motion events and video captures line up precisely. The network engineer also needs to protect time synchronization traffic from spoofing when systems obtain time from external sources over the internet. Which solution best meets both requirements?

  1. A

    Use NTP only for all devices because it is designed for the highest-precision LAN synchronization and already provides strong cryptographic protection by default

  2. B

    Use PTP on the local industrial network for high-precision synchronization, and use NTS to secure NTP when synchronizing with external time servers

  3. C

    Use SNMP traps to distribute time updates internally, and use DNSSEC to authenticate external time servers

  4. D

    Use Syslog timestamps as the source of truth internally, and rely on HTTPS certificate validation to secure time synchronization externally

Show answer and explanation

Correct answer: B

Explanation

The best answer is to use PTP internally and NTS with NTP externally. PTP, defined by IEEE 1588, is intended for highly accurate clock synchronization on local networks and is appropriate when applications require sub-microsecond alignment. NTP remains the common protocol for broader time synchronization, especially to internet-based time sources, but standard NTP alone has known security limitations. Network Time Security (NTS), standardized by the IETF for NTP, adds authenticated key establishment and protects the integrity of NTP exchanges against spoofing and some interception attacks. In practice, organizations often use PTP where deterministic, high-precision timing is required on the LAN and use NTP/NTS for secure upstream time distribution from trusted external servers. Relevant references include IEEE 1588 for PTP and the IETF NTS for NTP specification (RFC 8915), along with NTP best practices from the Network Time Foundation and vendor implementation guidance.

  • A. Incorrect.

    Incorrect. NTP is widely used for general time synchronization, but it is not the best choice when sub-microsecond precision is required across a LAN. That level of precision is the domain of Precision Time Protocol (PTP, IEEE 1588), especially in industrial and media environments. Also, traditional NTP does not provide strong protection by default; Network Time Security (NTS) is the modern mechanism used to add authenticated, encrypted key establishment for NTP sessions.

  • B. Correct.

    Correct. PTP is specifically designed for very accurate time synchronization on local networks and is commonly used in industrial automation, telecom, and audiovisual environments where extremely low timing error matters. For external time sources, NTS is the appropriate security enhancement for NTP, helping protect against spoofing and certain man-in-the-middle risks by authenticating NTP exchanges after a TLS-based key establishment step. This combination matches the need for high precision internally and stronger security externally.

  • C. Incorrect.

    Incorrect. SNMP is a management and monitoring protocol, not a time-distribution protocol for precision synchronization. DNSSEC protects DNS record integrity and authenticity, but it does not secure NTP time exchanges. A candidate might choose this option because both SNMP and DNSSEC are legitimate infrastructure technologies, but neither solves precise clock synchronization in this scenario.

  • D. Incorrect.

    Incorrect. Syslog records timestamps but does not distribute authoritative time to devices. In fact, syslog usually depends on accurate system time already being present. HTTPS certificate validation is unrelated to securing NTP or PTP traffic directly. This option reflects a common misconception that any security mechanism involving certificates can secure time protocols, but certificate use in web traffic does not replace NTS for NTP.

Timed practice exam

Take a N10-009 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam