Wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

NET6201 Final Exam - Questions Only

Total questions: 100

Worksheet time: 50mins

Name
Class
Date
1.

A company has two offices. Office A uses network 192.168.1.0/24 and Office B uses network 192.168.1.0/24. When they connect both offices via a VPN, devices cannot communicate properly. What is the problem and how should it be solved?

a)

Both offices use the same network address, causing a conflict. The solution is to assign different subnets to each office.

b)

The VPN is not configured to allow traffic between the offices. The solution is to enable inter-office routing.

c)

The devices are using incompatible hardware. The solution is to upgrade the network devices.

d)

The internet connection is too slow. The solution is to increase bandwidth.

2.

A technician configures PC-A with IP 192.168.10.65/26 and PC-B with IP 192.168.10.130/26. Both are connected to the same switch. PC-A cannot ping PC-B. The technician believes the switch is faulty. Is this correct?

a)

No, because PC-A and PC-B are on different subnets and cannot communicate without a router.

b)

Yes, because a faulty switch can prevent communication between devices on the same network.

c)

No, because both PCs have incorrect IP addresses for the subnet mask used.

d)

Yes, because the switch must be configured for VLANs to allow communication.

3.

An administrator needs to create 4 subnets from network 10.0.0.0/8. Which subnet mask is more appropriate: /10 or /30, and why?

a)

/10, because it provides enough addresses for 4 subnets with many hosts each.

b)

/30, because it provides the maximum number of subnets possible.

c)

/30, because it allows for only 2 usable IP addresses per subnet.

d)

/10, because it limits the number of available subnets to just 2.

4.

Host A (10.1.1.50/16) sends a packet to Host B (10.2.1.50/16) with no router between them. Will the communication succeed?

a)

Yes, because both hosts are in the same subnet.

b)

No, because they are in different subnets and no router exists.

c)

Yes, because the IP addresses are similar.

d)

No, because the subnet mask is too small.

5.

Can the administrator use 172.16.5.128/28 from the original 172.16.0.0/16 network for Finance, given that Sales is using 172.16.5.0/24 and Finance needs a subnet for only 10 hosts?

a)

Yes, because 172.16.5.128/28 is a valid unused subnet within the original /16 and supports at least 10 hosts.

b)

No, because 172.16.5.128/28 overlaps with the Sales subnet 172.16.5.0/24.

c)

No, because 172.16.5.128/28 does not provide enough host addresses for Finance.

d)

Yes, but only if the Sales subnet is changed to a /25.

6.

6. A router has interface with IP 192.168.1.1/24. A host on that network is configured with IP 192.168.1.1/24. What will happen and why?

a)

There will be an IP address conflict because both the router and the host have the same IP address.

b)

The host will be able to communicate with the router without any issues.

c)

The router will automatically assign a new IP address to the host.

d)

The network will function normally as long as the subnet mask is correct.

7.

A VLSM design requires: LAN-A (100 hosts), LAN-B (50 hosts), LAN-C (25 hosts), and 2 WAN links (2 hosts each). Starting with 192.168.1.0/24, a technician allocates /25 for LAN-A, then /26 for LAN-B starting at 192.168.1.128. What mistake was made?

a)

The /26 subnet for LAN-B overlaps with the /25 subnet for LAN-A.

b)

The /25 subnet for LAN-A is too small for 100 hosts.

c)

The /26 subnet for LAN-B is too large for 50 hosts.

d)

The WAN links were not allocated any subnets.

8.

8. Two routers are connected via a serial link. Router A interface has 10.0.0.1/30 and Router B interface has 10.0.0.5/30. Routers cannot ping each other. What is wrong?

a)

The interfaces are not in the same subnet.

b)

The serial link is down.

c)

The IP addresses are not configured.

d)

The subnet mask is incorrect.

9.

A student claims that the broadcast address for 192.168.1.64/26 is 192.168.1.128. Is this statement correct?

a)

No, the correct broadcast address is 192.168.1.127.

b)

Yes, the broadcast address is 192.168.1.128.

c)

No, the correct broadcast address is 192.168.1.63.

d)

No, the correct broadcast address is 192.168.1.191.

10.

A network administrator notices that host 172.16.45.130/20 cannot communicate with host 172.16.33.200/20. Both hosts are connected to the same router. What should the administrator check first?

a)

Whether the hosts are in the same subnet

b)

If the router is powered on

c)

If the cables are connected properly

d)

Whether the hosts have the same MAC address

11.

11. During troubleshooting, a technician discovers that PC (192.168.5.67/27) has gateway set to 192.168.5.1. The actual router interface on this network is 192.168.5.65/27. Why can't the PC reach other networks?

a)

The PC's gateway is not in the same subnet as the PC.

b)

The PC's IP address is incorrect.

c)

The router interface is down.

d)

The subnet mask is set incorrectly on the router.

12.

What will the router do and why?

a)

The router will forward the packet because the destination is in its routing table.

b)

The router will drop the packet because the destination is unknown.

c)

The router will broadcast the packet to all interfaces.

d)

The router will send an error message to the sender.

13.

TTL=128 indicates which source operating system?

a)

Windows

b)

Linux

c)

macOS

d)

FreeBSD

14.

What will happen?

a)

An event will occur as a result of an action.

b)

Nothing will change.

c)

The situation will reverse.

d)

A new object will appear.

15.

15. Wireshark capture shows two packets from same source: Packet 1 - ID: 0x5F3A, Flags: 0x20 (More Fragments), Offset: 0, Length: 1500. Packet 2 - ID: 0x5F3A, Flags: 0x00, Offset: 185, Length: 700. What can you conclude?

a)

These packets are fragments of the same original IP datagram.

b)

These packets are from different sources.

c)

The packets are part of a TCP handshake.

d)

The packets indicate a routing loop.

16.

The packet will take which path and why?

a)

The packet will take the shortest available path due to routing protocols.

b)

The packet will take the longest path to avoid congestion.

c)

The packet will take a random path each time it is sent.

d)

The packet will always follow the same path regardless of network changes.

17.

The route used and the reason for its selection is:

a)

The intravenous route is used because it provides rapid drug action.

b)

The oral route is used because it is the most convenient.

c)

The subcutaneous route is used because it avoids first-pass metabolism.

d)

The intramuscular route is used because it allows for slow absorption.

18.

AA:BB:CC:DD:EE:99 is an example of which of the following?

a)

A MAC address

b)

An IP address

c)

A subnet mask

d)

A port number

19.

Protocol: 1 is used for which purpose in networking packets?

a)

It is used for ICMP packets.

b)

It is used for HTTP packets.

c)

It is used for FTP packets.

d)

It is used for SMTP packets.

20.

Will this route be used?

a)

Yes, this route will be used.

b)

No, this route will not be used.

c)

This route is optional.

d)

The route is not specified.

21.

The header information is consistent. Is this statement true or false?

a)

True

b)

False

c)

Cannot be determined

d)

Not enough information

22.

The difference between the C and L entries is:

a)

C represents capacitance, while L represents inductance.

b)

C represents current, while L represents length.

c)

C represents charge, while L represents light.

d)

C represents conductor, while L represents load.

23.

The asterisk (*) indicates a wildcard route and will be used when no other routes match. What does the asterisk (*) indicate and when will this route be used?

a)

It indicates a wildcard route and is used when no other routes match.

b)

It indicates a default route and is always used first.

c)

It indicates a secure route and is used for authentication only.

d)

It indicates a static route and is used for specific paths only.

24.

24. Router has these entries: S 10.0.0.0/8 [1/0] via 192.168.1.1 and S 10.0.0.0/8 [5/0] via 192.168.1.2. The link to 192.168.1.1 fails. What happens to traffic destined for 10.5.5.5?

a)

The router forwards the traffic via 192.168.1.2.

b)

The traffic is dropped as there is no valid route.

c)

The router sends the traffic to 192.168.1.1 anyway.

d)

The router broadcasts the traffic to all interfaces.

25.

25. Wireshark capture shows: Source: 169.254.100.50, Destination: 192.168.1.1, Protocol: ICMP (Echo Request). What can you conclude about the source host?

a)

The source host does not have a valid DHCP-assigned IP address.

b)

The source host is using a static IP address from the correct subnet.

c)

The source host is successfully communicating with the gateway.

d)

The source host is part of the 192.168.1.0/24 network.

26.

IHL: 7 indicates that this packet has a header length of how many bytes?

a)

28 bytes

b)

14 bytes

c)

20 bytes

d)

7 bytes

27.

A network administrator needs to determine if host 192.168.45.67/28 and host 192.168.45.72/28 are in the same subnet. What is the correct approach to solve this problem without using a calculator?

a)

Compare the network addresses of both hosts after applying the subnet mask.

b)

Ping both hosts to see if they respond to each other.

c)

Check if the last octet of both IP addresses is the same.

d)

Use traceroute to see if the path is the same for both hosts.

28.

A junior administrator sees subnet mask 255.255.255.240 and needs to find the CIDR notation. What is the correct CIDR notation for this subnet mask?

a)

/28

b)

/30

c)

/24

d)

/27

29.

29. Wireshark shows Source IP: C0.A8.01.64 in hexadecimal. What is this address in decimal notation and what type of address is it?

a)

192.168.1.100, Private address

b)

192.168.1.64, Public address

c)

192.168.100.1, Private address

d)

192.168.1.100, Public address

30.

A router receives a packet and sends back an ICMP message with Type 3, Code 0. What does this indicate and what should the source host understand from this message?

a)

The destination network is unreachable and the source host should stop sending packets to that network.

b)

The packet was successfully delivered to the destination.

c)

The router is overloaded and cannot process the packet.

d)

The source host needs to resend the packet with a different protocol.

31.

A host sends a ping to a remote server. After some time, it receives an ICMP message with Type 11, Code 0. What does this tell the administrator about the network path?

a)

The packet's TTL expired in transit, indicating a routing loop or a path that is too long.

b)

The destination port is unreachable on the remote server.

c)

The remote server is down and not responding to pings.

d)

The network path is clear and the ping was successful.

32.

Network documentation shows a subnet mask as 0xFFFFFF00. An administrator needs to configure a device that only accepts dotted decimal format. What should be entered?

a)

255.255.255.0

b)

255.255.0.0

c)

255.0.0.0

d)

255.255.255.255

33.

A student needs to determine how many hosts can exist in a /20 network. What is the correct number of hosts?

a)

4094

b)

2046

c)

8190

d)

1022

34.

An administrator pings a host and receives the reply Destination Host Unreachable from the local router (192.168.1.1). What does this indicate compared to receiving no response at all?

a)

The local router has no route to the destination network, while no response means the ping request may have been blocked or lost.

b)

The destination host is powered off, while no response means the host is online but not responding.

c)

The local router is down, while no response means the destination host is unreachable.

d)

The ping command is incorrect, while no response means the network is congested.

35.

A packet arrives at a router with TTL=0. What does the router do and why might this situation occur?

a)

The router discards the packet because it has exceeded its maximum allowed hops.

b)

The router forwards the packet to the next hop as usual.

c)

The router increases the TTL and sends the packet back to the sender.

d)

The router encrypts the packet and stores it temporarily.

36.

Wireshark shows a packet with Protocol field = 6. What protocol is being used above the IP layer?

a)

TCP (Transmission Control Protocol)

b)

UDP (User Datagram Protocol)

c)

ICMP (Internet Control Message Protocol)

d)

IGMP (Internet Group Management Protocol)

37.

A routing table shows: O IA 10.1.0.0/16 [110/30] via 192.168.1.1. What does IA indicate about this route?

a)

It is an OSPF inter-area route.

b)

It is an OSPF external route.

c)

It is a static route.

d)

It is a directly connected route.

38.

Host A (192.168.1.10/24) sends data to Host B (192.168.2.10/24). The packet leaves Host A with destination MAC set to Host A's default gateway because:

a)

Host B is on a different network, so Host A must send the packet to its default gateway for routing.

b)

Host A does not know Host B's MAC address and sends it to the gateway by default.

c)

The default gateway always handles all traffic, even within the same subnet.

d)

Host A's ARP table is empty, so it uses the gateway's MAC address.

39.

A router receives packets for 10.0.0.0/8 and has two equal-cost paths. What is this called and what happens?

a)

This is called equal-cost multi-path (ECMP) routing, and the router will load-balance the packets across both paths.

b)

This is called route summarization, and the router will drop the packets.

c)

This is called route poisoning, and the router will send the packets back to the source.

d)

This is called split horizon, and the router will block one of the paths.

40.

An IP packet has Total Length: 576, IHL: 5, and 20 bytes of options. Is this consistent?

a)

No, because IHL: 5 means there are no options, but 20 bytes of options are present.

b)

Yes, because IHL: 5 allows for 20 bytes of options.

c)

Yes, because Total Length includes options regardless of IHL.

d)

No, because Total Length should be less than 576 if options are present.

41.

A network administrator sees ARP entries for IP addresses that don't exist on the local network. This might be caused by:

a)

ARP spoofing or poisoning

b)

A faulty network cable

c)

Incorrect subnet mask configuration

d)

A DHCP server outage

42.

Wireshark shows an IP packet with source address 127.0.0.1 arriving at a router from the internet. What should the router do?

a)

Drop the packet as it has an invalid source address.

b)

Forward the packet to the local network.

c)

Send the packet back to the sender.

d)

Route the packet to the destination address.

43.

A packet fragmented into 3 fragments arrives at the destination, but fragment 2 is missing. What happens?

a)

The packet cannot be reassembled and is discarded.

b)

The remaining fragments are delivered to the application.

c)

The destination requests only fragment 2 again.

d)

The packet is partially reassembled with the available fragments.

44.

Routing table shows: S 10.0.0.0/8 [1/0] via 192.168.1.1 and O 10.1.0.0/16 [110/20] via 192.168.1.2. A packet for 10.1.5.5 arrives. Which route is used?

a)

The O 10.1.0.0/16 [110/20] via 192.168.1.2 route is used.

b)

The S 10.0.0.0/8 [1/0] via 192.168.1.1 route is used.

c)

Both routes are used simultaneously.

d)

The packet is dropped as no route matches.

45.

Wireshark shows ICMP Type 3, Code 4 with Next-Hop MTU: 1400. What is the host being told?

a)

The packet is too large and must be fragmented, but fragmentation is not allowed. The next-hop MTU is 1400.

b)

The destination port is unreachable.

c)

The network is unreachable.

d)

The packet was delivered successfully.

46.

A network has two routers: R1 and R2. R1's routing table shows 10.0.0.0/8 via R2. R2's routing table shows 10.0.0.0/8 via R1. What happens to packets destined for 10.5.5.5?

a)

The packets will loop indefinitely between R1 and R2.

b)

The packets will be delivered successfully to 10.5.5.5.

c)

The packets will be dropped by R1.

d)

The packets will be dropped by R2.

47.

Wireshark shows TCP segment with flags SYN, ACK set, Seq=0, Ack=1. What stage of TCP connection is this?

a)

Second step of the TCP three-way handshake (SYN-ACK).

b)

First step of the TCP three-way handshake (SYN).

c)

Third step of the TCP three-way handshake (ACK).

d)

TCP connection termination (FIN-ACK).

48.

A TCP connection shows: Host A Seq=100, sends 50 bytes. What should Host B's acknowledgment number be?

a)

150

b)

100

c)

149

d)

151

49.

Wireshark shows TCP RST flag set. Source port 80, destination port 45678. What likely happened?

a)

The web server reset the connection to the client.

b)

The client successfully completed a handshake with the server.

c)

The client sent a SYN packet to initiate a connection.

d)

The server sent a FIN packet to gracefully close the connection.

50.

What do these options tell you about the connection?

a)

They provide information about the status and type of the connection.

b)

They show the available color schemes for the interface.

c)

They list the different user accounts on the system.

d)

They display the recent notifications received.

51.

Wireshark shows source port 53, destination port 49152, protocol UDP. What application is likely involved?

a)

DNS

b)

FTP

c)

HTTP

d)

SMTP

52.

Identify the protocol shown in the image.

a)

HTTP

b)

FTP

c)

SMTP

d)

SSH

53.

Wireshark shows ICMP Port Unreachable (Type 3, Code 3) following a UDP packet. What happened?

a)

The destination port is closed and cannot receive the UDP packet.

b)

The UDP packet was successfully delivered to the destination port.

c)

The source IP address is unreachable.

d)

The network is experiencing a routing loop.

54.

A TCP capture shows window size going from 65535 to 32768 to 16384 to 0 across several segments. What is happening?

a)

The receiver's buffer is filling up and it is signaling the sender to stop sending data.

b)

The sender is increasing its transmission rate.

c)

A network device is dropping packets.

d)

The connection is being reset by the sender.

55.

A capture shows TCP retransmission after 200ms, then 400ms, then 800ms. What pattern is this?

a)

Exponential backoff

b)

Linear increase

c)

Constant interval

d)

Random delay

56.

A UDP header shows Length: 8. What does this indicate?

a)

It is valid and means there is no data, only the header.

b)

It is invalid because the minimum length should be greater than 8.

c)

It means the UDP packet is corrupted.

d)

It indicates the header is missing.

57.

Wireshark shows duplicate ACKs: Ack=5000, Ack=5000, Ack=5000. What is the receiver signaling?

a)

The receiver is signaling packet loss and requesting retransmission.

b)

The receiver is acknowledging new data segments.

c)

The receiver is closing the connection.

d)

The receiver is increasing the window size.

58.

A capture shows SACK blocks: 6000-6500, 7000-7500. The ACK number is 5000. What has been received?

a)

All bytes up to 5000 and bytes 6000-6500 and 7000-7500

b)

All bytes up to 7500

c)

All bytes up to 6500 and 7000-7500

d)

All bytes up to 5000 and bytes 5000-6000

59.

Wireshark shows TCP PSH flag set on a segment. What does this indicate and when is it typically used?

a)

It indicates that the sender is requesting immediate data push to the receiving application, typically used for interactive data transfer.

b)

It indicates the start of a TCP connection, typically used during the handshake process.

c)

It signals the termination of a TCP connection, typically used at the end of a session.

d)

It is used to acknowledge receipt of data, typically used in every TCP segment.

60.

Wireshark capture shows a TCP connection with consistently high RTT (500ms+) but no packet loss. What might cause this?

a)

Long physical distance between endpoints

b)

High packet loss on the network

c)

TCP window size too small

d)

Frequent retransmissions

61.

Fill in the blank: Overlapping subnets; change IP scheme or use _____

a)

NAT

b)

VLAN

c)

DNS

d)

DHCP

62.

Fill in the blank: No, different /_____ subnets.

a)

26

b)

24

c)

30

d)

28

63.

Fill in the blank: /_____ is correct.

a)

10

b)

5

c)

20

d)

15

64.

Fill in the blank: No, _____ required.

a)

router

b)

pencil

c)

car

d)

book

65.

Fill in the blank: Yes, _____ allows it.

a)

VLSM

b)

OSPF

c)

RIP

d)

NAT

66.

Fill in the blank: _____ conflict.

a)

IP

b)

MAC

c)

Port

d)

Subnet

67.

Fill in the blank: Address _____

a)

overlap

b)

space

c)

range

d)

block

68.

Fill in the blank: Different /_____ networks.

a)

30

b)

20

c)

10

d)

40

69.

Fill in the blank: No, broadcast is _____

a)

192.168.1.127

b)

192.168.1.1

c)

255.255.255.0

d)

10.0.0.1

70.

Fill in the blank: _____ mask.

a)

Subnet

b)

Face

c)

Dust

d)

Oxygen

71.

Fill in the blank: Wrong _____

a)

gateway

b)

password

c)

address

d)

number

72.

Fill in the blank: Drop packet, _____ expired.

a)

TTL

b)

IP

c)

MAC

d)

ARP

73.

Fill in the blank: _____

a)

Windows

b)

Linux

c)

MacOS

d)

Android

74.

Fill in the blank: Dropped, _____ sent.

a)

ICMP

b)

TCP

c)

UDP

d)

ARP

75.

Fill in the blank: _____ packet.

a)

Fragmented

b)

Connected

c)

Encrypted

d)

Compressed

76.

Fill in the blank: Via _____

a)

192.168.1.2

b)

10.0.0.1

c)

255.255.255.0

d)

172.16.0.5

77.

Fill in the blank: ________ is a type of route that is directly connected to the router.

a)

Connected route

b)

Static route

c)

Default route

d)

Dynamic route

78.

Fill in the blank: The MAC address of the gateway is called ________.

a)

Gateway MAC

b)

Host MAC

c)

Broadcast MAC

d)

Subnet MAC

79.

Fill in the blank: The message used to test network connectivity is called ________.

a)

ICMP Echo

b)

ARP Request

c)

DNS Query

d)

TCP SYN

80.

Fill in the blank: The answer to this networking question is ________.

a)

No

b)

Yes

c)

Maybe

d)

Always

81.

Fill in the blank: The answer to this networking question is ________.

a)

No

b)

Yes

c)

Maybe

d)

Always

82.

Fill in the blank: In routing tables, C stands for network and L stands for ________.

a)

local

b)

link

c)

loopback

d)

logical

83.

Fill in the blank: The route used when no other route matches is called the ________.

a)

Default route

b)

Static route

c)

Dynamic route

d)

Gateway route

84.

Fill in the blank: A route used as a backup in case the primary fails is called a ________.

a)

Backup route

b)

Static route

c)

Default route

d)

Dynamic route

85.

Fill in the blank: An automatically assigned IP address is called an ________.

a)

APIPA address

b)

Static address

c)

Loopback address

d)

Broadcast address

86.

Fill in the blank: Options that can be set in an IP header are called ________.

a)

IP options

b)

TCP flags

c)

Port numbers

d)

MAC addresses

87.

Fill in the blank: The process to verify the increment of subnets is called ________.

a)

Check subnet increment

b)

Subnet masking

c)

IP routing

d)

Address translation

88.

Fill in the blank: The CIDR notation for a subnet mask of 255.255.255.240 is ________.

a)

/28

b)

/24

c)

/30

d)

/32

89.

The IP address 192.168.1.100 is a ________ address.

a)

private

b)

public

c)

loopback

d)

broadcast

90.

Fill in the blank: The message indicating a destination cannot be reached is ________.

a)

Network unreachable

b)

Host available

c)

Packet delivered

d)

Connection established

91.

Fill in the blank: The message indicating the time to live has expired is ________.

a)

TTL expired

b)

Destination unreachable

c)

Parameter problem

d)

Source quench

92.

Fill in the blank: The subnet mask 255.255.255.0 can also be written as ________.

a)

/24

b)

/16

c)

/8

d)

/32

93.

Fill in the blank: The number 4094 is significant in networking as the maximum number of hosts in a ________.

a)

VLAN

b)

Class A network

c)

Class C network

d)

subnet with a /30 mask

94.

Fill in the blank: If there is no route to the destination, the message is ________.

a)

No route

b)

Delivered

c)

Queued

d)

Forwarded

95.

Fill in the blank: When a packet is intentionally discarded, it is called a ________.

a)

Drop packet

b)

Forwarded packet

c)

Routed packet

d)

Delayed packet

96.

Fill in the blank: The protocol used for reliable communication is ________.

a)

TCP

b)

UDP

c)

ICMP

d)

ARP

97.

Fill in the blank: OSPF that connects different areas is called ________.

a)

Inter-area OSPF

b)

Intra-area OSPF

c)

External OSPF

d)

Stub OSPF

98.

Fill in the blank: The MAC address of the gateway is called ________.

a)

Gateway MAC

b)

Host MAC

c)

Broadcast MAC

d)

Subnet MAC

99.

Fill in the blank: Equal-cost multipath routing is abbreviated as ________.

a)

ECMP

b)

OSPF

c)

BGP

d)

MPLS

100.

Fill in the blank: The answer to this networking question is ________.

a)

No

b)

Yes

c)

Maybe

d)

Always