N10-009 exam dumps

N10-009 practice question 62 of 329

Network+. Associate level, CompTIA. Free question with the correct answer and a full explanation.

N10-009 Question 62

Single answerTFTP: 69

A network administrator is deploying several new IP phones that must download their boot configuration from a provisioning server during startup. The phones are on a different subnet than the server. The administrator confirms the phones receive IP addresses successfully from DHCP, but the phones still fail to download their configuration files. Packet captures show the phones attempting to contact the server using UDP port 69. Which of the following is the MOST likely cause of the failure?

  1. A

    A firewall is blocking TFTP traffic between the phone subnet and the provisioning server

  2. B

    The switchports for the phones are missing an 802.1Q trunk configuration

  3. C

    DNS is not resolving the provisioning server's hostname over TCP port 53

  4. D

    The provisioning server is rejecting connections because TFTP requires TLS encryption

Show answer and explanation

Correct answer: A

Explanation

This question tests practical troubleshooting of TFTP in a real provisioning scenario. TFTP is commonly used for bootstrapping devices such as IP phones, network equipment, and PXE clients because it is lightweight and simple. Its well-known port is UDP 69 for the initial request. After that initial exchange, TFTP uses UDP for data transfer as negotiated between client and server, which means firewalls and ACLs can easily disrupt the session if they are not configured appropriately. In this scenario, DHCP is already functioning, so the most likely issue is filtering of TFTP traffic rather than a basic connectivity problem. This aligns with standard networking references and vendor deployment guidance, which commonly note that TFTP is connectionless, uses UDP, and lacks security features such as authentication and encryption. Best practice is to use TFTP only where appropriate, limit it to trusted management or provisioning networks, and ensure intermediary security devices permit the required traffic.

  • A. Correct.

    Correct. TFTP uses UDP port 69 for the initial request, and it is commonly used by devices such as IP phones, routers, and PXE clients to retrieve boot or configuration files. If DHCP is working but the phones cannot download files and packet captures show TFTP attempts, the most likely issue is that a firewall or ACL is blocking TFTP-related traffic. In real deployments, administrators must allow the initial UDP 69 request and the subsequent UDP data exchange used by TFTP.

  • B. Incorrect.

    Incorrect. Missing 802.1Q trunking could cause VLAN connectivity problems in some voice deployments, but the scenario already states that the phones successfully receive IP addresses from DHCP and are sending TFTP requests. That indicates the phones have at least basic Layer 2 and Layer 3 connectivity. The problem is more specific to the file transfer service.

  • C. Incorrect.

    Incorrect. DNS could be relevant if the phones were using a hostname and could not resolve it, but the key troubleshooting detail is that packet captures already show the phones attempting to contact the server on UDP port 69. That means the phones have enough information to send TFTP traffic. Also, DNS primarily uses UDP 53 for standard queries, not TCP 53 except in specific cases such as zone transfers or large responses.

  • D. Incorrect.

    Incorrect. TFTP does not use TLS. It is a simple, lightweight file transfer protocol with no built-in encryption or authentication. Someone might pick this option because modern secure management protocols often use encryption, but TFTP is intentionally minimal and is therefore commonly restricted to trusted networks or replaced with more secure alternatives when possible.

Timed practice exam

Take a N10-009 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam