exam questions

Exam N10-008 All Questions

View all questions & answers for the N10-008 exam

Exam N10-008 topic 1 question 144 discussion

Actual exam question from CompTIA's N10-008
Question #: 144
Topic #: 1
[All N10-008 Questions]

A company just migrated its email service to a cloud solution. After the migration, two-thirds of the internal users were able to connect to their mailboxes, but the connection fails for the other one-third of internal users. Users working externally are not reporting any issues. The network administrator identifies the following output collected from an internal host: c:\user> nslookup newmail.company.com
Non-Authoritative answer:

Name: newmail.company.com -
IPs: 3.219.13.186, 64.58.225.184, 184.168.131.243
Which of the following verification tasks should the network administrator perform NEXT?

  • A. Check the firewall ACL to verify all required IP addresses are included.
  • B. Verify the required router PAT rules are properly configured.
  • C. Confirm the internal DNS server is replying to requests for the cloud solution.
  • D. Validate the cloud console to determine whether there are unlicensed requests.
Show Suggested Answer Hide Answer
Suggested Answer: A 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
StevenElev11n
Highly Voted 1 year, 2 months ago
Selected Answer: A
- The output of the nslookup command indicates that the newmail.company.com domain name resolves to three different IP addresses, which suggests that the email service has been migrated to a cloud solution. However, one-third of the internal users are not able to connect to their mailboxes, which may indicate that the firewall is blocking traffic to the cloud email service.
upvoted 30 times
jassssb
1 year, 1 month ago
Steven, you’re freaking awesome! I really enjoy reading your detailed explanations on these questions.
upvoted 13 times
...
[Removed]
1 year ago
Yeah in in aws this coud be a security group or a nacl issue.
upvoted 2 times
...
...
Mehsotopes
Most Recent 5 months, 1 week ago
Selected Answer: A
Port 25 is used for sending emails to other servers through firewall's ACL. 1/3 of users are not allowed through the firewall ACL to access mail, there being three IP addresses implies that one of these IP addresses are not included.
upvoted 1 times
...
osmaster
6 months, 1 week ago
Selected Answer: C
GPT says based on the information provided, the network administrator should perform the following verification tasks: C. Confirm the internal DNS server is replying to requests for the cloud solution. The nslookup output shows the IP addresses associated with "newmail.company.com," which is the cloud email service. The non-authoritative answer indicates that the DNS server is responding to requests for this domain. Since two-thirds of the internal users can connect to their mailboxes, it's likely that DNS resolution is working for them. The remaining one-third of internal users who cannot connect may be experiencing DNS-related issues. Therefore, confirming that the internal DNS server is correctly resolving requests for the cloud solution is a crucial next step in troubleshooting the problem. The other options (A, B, and D) are also important aspects of network and security management but are less likely to be the cause of the specific issue described in the scenario.
upvoted 1 times
JJay99
2 months, 1 week ago
This would be a site wide problem, the question specifically says 1/3 can't access while 2/3 can. C can't be the answer
upvoted 1 times
...
...
MitchF
8 months, 1 week ago
GPT picks (A): "The next verification task the network administrator should perform is (A) Check the firewall ACL to verify all required IP addresses are included. The provided output from the nslookup command indicates the IP addresses associated with the "newmail.company.com" domain. Since some internal users are unable to connect to their mailboxes after the migration, it's possible that the issue is related to network connectivity or firewall rules. By checking the firewall access control list (ACL), the network administrator can ensure that the required IP addresses (3.219.13.186, 64.58.225.184, 184.168.131.243) are allowed to establish connections. If any of these IP addresses are blocked by the firewall, it could be causing the connection failure for the affected internal users. Options (B) Verify the required router PAT rules, (C) Confirm the internal DNS server replies to requests, and (D) Validate the cloud console for unlicensed requests are also important tasks, but given the context of internal users unable to connect to the cloud email service, checking the firewall ACL would be the most immediate step to ensure proper connectivity."
upvoted 2 times
...
handcraft0093
1 year ago
Selected Answer: C
The internal DNS server must be able to resolve the domain name for the cloud-based email service to the correct IP address. If the internal DNS server is not configured to resolve the domain name to the correct IP address, some internal users may not be able to connect to the email service.
upvoted 1 times
Kessel
8 months, 3 weeks ago
But then why some users can connect and others can't? I assume all employees use the same internal DNS server, so it should affect everyone equally.
upvoted 6 times
...
...
1stAid
1 year ago
Selected Answer: A
two-thirds of the internal users were able to connect, but the connection fails for the other one-third wc indicates the internal DNS is working fine. ACL will need to be checked to make sure all IP addresses got the right permissions.
upvoted 3 times
...
Jay_Brzy
1 year ago
Selected Answer: C
C. Confirm the internal DNS server is replying to requests for the cloud solution. Since some internal users are unable to connect to the cloud email service, it is possible that the DNS server used by those users is not properly configured to resolve the domain name of the new cloud email service. By verifying that the internal DNS server is properly configured to resolve the domain name, the network administrator can ensure that all internal users are able to connect to the cloud email service.
upvoted 1 times
...
MelzTheArtist
1 year, 2 months ago
Selected Answer: C
C. Confirm the internal DNS server is replying to requests for the cloud solution. The output from nslookup shows that the domain name "newmail.company.com" is resolving to three IP addresses. However, the fact that only two-thirds of internal users can connect to their mailboxes suggests that there may be an issue with the DNS resolution for the cloud solution among the internal network. Therefore, the next verification task the network administrator should perform is to confirm whether the internal DNS server is responding to requests for the cloud solution.
upvoted 1 times
...
MelzTheArtist
1 year, 2 months ago
C. Confirm the internal DNS server is replying to requests for the cloud solution. The output from nslookup shows that the domain name "newmail.company.com" is resolving to three IP addresses. However, the fact that only two-thirds of internal users can connect to their mailboxes suggests that there may be an issue with the DNS resolution for the cloud solution among the internal network. Therefore, the next verification task the network administrator should perform is to confirm whether the internal DNS server is responding to requests for the cloud solution.
upvoted 1 times
...
Dogster
1 year, 2 months ago
An authoritative answer comes from a Nameserver (NS) that is considered authoritative for the domain which it's returning a record for (one of the nameservers in the list for the domain you did a lookup on). A non-authoritative answer comes from anywhere else (a nameserver not in the list for the domain you did a lookup on). Example If I perform a nslookup of google.com, I would get a response from one of my configured nameservers. (Either from my ISP, or my domain.) It would come back as non-authoritative because neither my ISP's nameservers, nor my own are in the list of nameservers for google.com. They aren't Google's nameservers, so they're not the authoritative source that creates the NS records. Recieved DNS record is ok, 2/3 of the users are behind a diffrent firewall/router that does allow the IP's. don't assume all are behind the same firewall because it is not stated in the question. thx comptia questions :(
upvoted 1 times
...
Cyali
1 year, 2 months ago
Selected Answer: A
3 email server IPs indicates load balancing to me, which would indicate each would handle roughly 1/3 of requests. While the comptia exams honestly don't reflect real life all the time, when I've experienced a similar situation it was an issue with the firewall - the firewall did not have one of the IPs whitelisted.
upvoted 4 times
...
opmint
1 year, 2 months ago
Selected Answer: C
Why is the answer A? To me this seems like an internal DNS issue due to 1/3 of the company being unable to access their new email server hosted to the cloud. I'd love clarification. For what its worth I did copy paste the question into ChatGPT and they also chose C as the correct answer.
upvoted 2 times
famco
1 year ago
1/3 of the users are not able to access but others can. Now the question does not say if the 1/3 of the same users are able to access, these questions are never clear but it is about guessing. If it is 1/3rd of the requests it is because one of the ip addresses are not in the allowed list. But if it is a public mail exchange it is not that it is not normally added to the firewall ACL with an explicit allow. But I will still choose A with a small analysis on how good the thinking if the question creator is.
upvoted 1 times
famco
1 year ago
Let me clarify, considering this is to a non standard port, it could be that the firewalls are configured to explicitly allow that port
upvoted 1 times
famco
1 year ago
Again, when I mean non-standard port I referred to the terminology I used and might not be clear. I meant not 80/443 that I know is normal traffic
upvoted 1 times
...
...
...
...
JakeCharles
1 year, 2 months ago
Selected Answer: A
The network administrator should check the firewall ACL to verify all required IP addresses are included. This is because the internal users are not able to connect to their mailboxes and the output shows multiple IP addresses for the newmail.company.com. Verifying that the correct IP addresses are allowed through the firewall would help to identify if that is the issue causing the connection failures for the internal users.
upvoted 1 times
...
vitasaia
1 year, 2 months ago
Selected Answer: D
All the other options should also affect the other 2/3 of users.
upvoted 1 times
...
kungfuseven
1 year, 4 months ago
A: Access Control Lists (ACLs) are a collection of permit and deny conditions, called rules, that provide security by blocking unauthorized users and allowing authorized users to access specific resources.
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago