N10-009 Question 297
Single answerDocument findings, actions, outcomes, and lessons learned throughout the processA network administrator resolves an intermittent connectivity issue affecting several users in a branch office. The root cause was a duplex mismatch between an access switch port and a legacy printer server. After correcting the configuration, the administrator verifies normal performance and closes the incident. Which action should the administrator take NEXT to best support future troubleshooting and process improvement?
- A
Update the incident record with the symptoms, troubleshooting steps performed, final root cause, configuration changes made, validation results, and lessons learned
- B
Reboot all branch office switches to confirm no other hidden issues exist before documenting anything
- C
Delete temporary logs and monitoring alerts related to the issue so the ticket contains only the final fix
- D
Escalate the ticket to management for approval before recording technical details in the documentation
Show answer and explanation
Correct answer: A
Explanation
Network+ troubleshooting methodology includes documenting findings, actions, outcomes, and lessons learned after identifying and resolving an issue. In a real environment, the final record should capture the original symptoms, affected systems, diagnostic results, root cause, remediation steps, verification of service restoration, and any recommendations to prevent recurrence. This supports future troubleshooting, change tracking, knowledge base creation, and operational continuity. Options involving unnecessary reboots, deleting evidence, or delaying documentation do not follow best practice for incident closure.
- A. Correct.
Correct. Good operational practice is to fully document the issue after resolution, including findings, actions taken, outcomes, and lessons learned. This creates a useful historical record for future incidents, supports knowledge transfer, and aligns with standard troubleshooting methodology that ends with documenting findings, actions, outcomes, and preventive recommendations.
- B. Incorrect.
Incorrect. Rebooting all switches is unnecessary and potentially disruptive after the issue has already been isolated, fixed, and validated. This choice reflects a common misconception that additional broad changes improve confidence, but they can introduce new problems and are not the next best step compared to proper documentation.
- C. Incorrect.
Incorrect. Removing logs and alerts reduces the forensic and operational value of the incident record. Temporary data may help correlate symptoms, confirm timelines, and support trend analysis. A common mistake is thinking concise documentation means deleting evidence, when best practice is to preserve relevant details and summarize them clearly.
- D. Incorrect.
Incorrect. Management notification may be required in some organizations for major incidents, but it does not replace technical documentation and is not the best immediate next step here. The scenario focuses on post-resolution process closure, where recording findings and lessons learned is the key action.