N10-009 exam dumps

N10-009 practice question 311 of 329

Network+. Associate level, CompTIA. Free question with the correct answer and a full explanation.

N10-009 Question 311

Select 3Switching issues: STP (Network loops, Root bridge selection, Port roles, Port states), Incorrect VLAN assignment, ACLs

A network administrator adds a new access switch to an office network. Shortly after installation, users on multiple floors report intermittent connectivity, high latency, and duplicate frame warnings. The administrator also notices that traffic from the guest wireless VLAN can reach a file server in the internal corporate VLAN, even though this should be blocked. After checking the switches, the administrator finds that the new switch has the lowest bridge priority in the topology, one uplink port is rapidly changing state, several user ports are assigned to VLAN 1 instead of their intended VLANs, and no filtering is applied at the Layer 3 interface for the guest VLAN. Which TWO actions should the administrator take first to address the most likely causes of these issues?

  1. A

    Change the STP bridge priority so the intended core switch becomes the root bridge, and verify blocked/forwarding port roles stabilize on the access switch

  2. B

    Disable STP on the new switch so all redundant links can forward traffic without delay

  3. C

    Reassign the incorrectly configured access ports to the proper VLANs and verify the trunk allows only the required VLANs

  4. D

    Increase the MAC address aging timer on all switches to reduce duplicate frame warnings

  5. E

    Apply an ACL to the guest VLAN interface to deny access to the internal file server subnet while permitting authorized traffic

Show answer and explanation

Correct answers: A, C, E

Explanation

This scenario combines three common switching issues tested on Network+: STP instability, incorrect VLAN assignment, and missing ACL enforcement for inter-VLAN traffic. The unstable topology and duplicate frame warnings indicate a likely Layer 2 loop or improper STP convergence. In production environments, administrators typically define the root bridge intentionally on a core or distribution switch rather than allowing a newly added access switch to win root election through a lower bridge ID. Under IEEE 802.1D/802.1w STP concepts, correct root bridge selection determines root ports, designated ports, and which redundant ports enter a non-forwarding state to prevent loops. Incorrect VLAN assignment explains why some users may be in the wrong broadcast domain, and trunk validation is a standard step to ensure only expected VLANs traverse switch uplinks. Finally, ACLs are commonly applied on routed interfaces or SVIs to control traffic between VLANs; without one, guest traffic may be able to reach internal resources. These actions align with standard enterprise switching best practices and common vendor guidance for STP design, VLAN segmentation, and ACL-based inter-VLAN access control.

  • A. Correct.

    Correct. The symptoms strongly suggest an STP problem caused by unintended root bridge selection. If the new access switch has the lowest bridge priority, it may become the root bridge, changing the Layer 2 topology unexpectedly and contributing to instability. Best practice is to set the intended distribution or core switch as the root bridge by configuring a lower bridge priority there. The administrator should then confirm that STP port roles and states stabilize, with redundant links placed into the appropriate blocking/discarding role instead of flapping.

  • B. Incorrect.

    Incorrect. Disabling STP in a network with redundant switch links is a common but serious mistake. STP exists to prevent Layer 2 loops, broadcast storms, and MAC table instability. Turning it off would likely worsen the intermittent connectivity and duplicate frame issues rather than resolve them.

  • C. Correct.

    Correct. Ports assigned to the wrong VLAN can place users into an unintended broadcast domain, causing reachability and segmentation problems. Verifying the access port VLAN assignments and confirming that trunks carry only the necessary VLANs are standard corrective actions. This directly addresses the observation that several user ports were left in VLAN 1 rather than their intended VLANs.

  • D. Incorrect.

    Incorrect. Increasing the MAC address aging timer does not fix switching loops or VLAN misconfiguration. Duplicate frame warnings and instability in this scenario are more consistent with an STP issue or loop condition. Someone might choose this option if they confuse MAC table churn with normal aging behavior, but the root cause is not the aging interval.

  • E. Correct.

    Correct. The scenario states that guest VLAN traffic can reach an internal file server and that no filtering is applied on the guest VLAN Layer 3 interface. An ACL is the appropriate control to restrict inter-VLAN traffic at the routed interface or SVI. This action addresses the security segmentation issue without affecting the Layer 2 loop remediation.

Timed practice exam

Take a N10-009 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam