About the Exam

CompTIA CloudNetX is a vendor-neutral certification for experienced technology professionals, including systems architects, network architects, cloud network architects, infrastructure architects, and enterprise architects. The exam covers network architecture design, security, operations, monitoring and performance, and troubleshooting in hybrid cloud environments, including automation and scripting. Passing demonstrates advanced ability to design, engineer, integrate, secure, and troubleshoot complex network solutions aligned with business requirements.

Exam Topics

  • Network architecture design31%
  • Network security28%
  • Network operations, monitoring, and performance16%
  • Network troubleshooting25%

How to Use This Practice Exam

  1. Browse — Read each question, select your answer, and reveal the explanation.
  2. Exam Mode — Simulate real exam conditions with a timed session and score report.
  3. Learn Mode — Spaced repetition schedules questions you struggle with for long-term retention.

Download the Full Exam PDF

Get every question and answer in a clean, printable PDF built for offline study. Purchase once, keep permanent access, and re-download the latest version anytime.

Last updated June 22, 2026 at 9:31 AM

Topic filter
Retired questions
Question sort
Questions per page

QuestionQ1

Network security

An administrator signed in to a cloud account on a shared computer but neglected to log out when the session ended. What type of security threat does this action create?

Explanation

An unattended authenticated administrator session lets another user act with the administrator’s elevated cloud permissions. Gaining or using higher-level permissions beyond one’s authorized level is privilege escalation.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!

QuestionQ2

Network troubleshooting

End users are receiving certificate errors and cannot connect to an application deployed in the cloud. The application requires an HTTPS connection. A network solution architect discovers that a firewall is deployed between the end users and the cloud application. Which of the following is the root cause of this issue?

Explanation

With SSL/HTTPS inspection enabled, the firewall participates in TLS inspection and its certificate must be valid. An expired firewall certificate causes clients to reject the HTTPS connection with certificate errors. Firewalls can terminate TLS sessions when certificate validity requirements are not met.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!

QuestionQ3

Network troubleshooting

A network administrator is troubleshooting a user's workstation that cannot connect to the company network. The results of commands run by the administrator on the workstation are shown below:

Question Image

A router on the same network displays the following output:

Question Image

Which of the following is the most likely cause of the issue?

Explanation

An IP address conflict exists because 10.21.12.8 is assigned to the workstation but the router resolves that address to a different MAC address in its ARP table. Traffic intended for the workstation can therefore be delivered to the other device using the duplicate address.

Community Discussion

No comments yet. Be the first to start the discussion!

QuestionQ4

Network architecture design

A network architect needs to design a new branch network that satisfies these requirements:

  • No single point of failure
  • Clients must not be affected by changes to the underlying medium
  • Clients must be able to communicate directly to preserve bandwidth

Which of the following network topologies should the architect choose?

Explanation

A mesh topology connects nodes through redundant, direct paths. This eliminates reliance on a single central device, allows alternate paths when a link or node fails, and enables direct client-to-client communication that avoids consuming bandwidth through a hub. Cisco describes full-mesh designs as resilient to link or node failures.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!

QuestionQ5

Network security

A network engineer is configuring guest access on a Wi-Fi network. Following a recent network analysis, the engineer found that a user could connect to the guest network and attack the corporate network because both networks use the same VLAN. Which of the following should the engineer do to prevent a similar attack from occurring?

Explanation

Layer 2 client isolation prevents direct client-to-client communication on the wireless Layer 2 network, reducing lateral attacks by guest devices against other endpoints on the shared VLAN. MAC filtering, a wireless password, and captive-portal registration restrict or identify access but do not stop an already connected guest from communicating with corporate devices on the same VLAN.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!
Know a question that should be here? Contribute to this exam
Back home