Came from the IG reel? You commented, here are all 20. 👇
These are 20 free Network+ practice questions in the exact format of the N10-009 exam, spread across all five domains. Answer each one honestly — no Googling, no flashcards open — then click Show answer to reveal the explanation and check yourself.
The 20-question practice test
Pick your answer for each question first, then click Show answer to check it. No peeking — the whole point of a practice test is committing to an answer before you see the right one. Keep a tally as you go; there’s a scoring guide at the bottom.
Which port number is used by SSH?
A. 21
B. 22
C. 23
D. 25
Show answer
A user reports that they can ping their default gateway but cannot reach any website by name. Which service is most likely failing?
A. DHCP
B. DNS
C. ARP
D. SMTP
Show answer
What is the broadcast address of the subnet 192.168.5.0/29?
A. 192.168.5.6
B. 192.168.5.7
C. 192.168.5.8
D. 192.168.5.15
Show answer
Which device operates at OSI Layer 2 and forwards frames based on MAC addresses?
A. Hub
B. Switch
C. Router
D. Firewall
Show answer
A network administrator needs to connect two VLANs on the same switch. Which technology is required?
A. Inter-VLAN routing (or a Layer-3 switch)
B. Spanning Tree Protocol (STP)
C. Port mirroring
D. Link aggregation
Show answer
A new server needs an IP address that does not change. Which DHCP feature accomplishes this?
A. DHCP relay
B. DHCP reservation
C. DHCP scope
D. APIPA
Show answer
Which of the following provides authentication, authorization, and accounting for network device administration?
A. RADIUS
B. TACACS+
C. LDAP
D. Kerberos
Show answer
A user can log in to the corporate WiFi but cannot access internal file shares. Other users at the same access point have no issue. What is the most likely cause?
A. WPA2 key mismatch
B. The user is assigned to the wrong VLAN
C. The DNS server is offline
D. The access point is misconfigured
Show answer
Which command is the first step in troubleshooting “I can’t reach a server” from a Windows machine?
A. ipconfig /all
B. ping default-gateway
C. tracert server-address
D. nslookup server-name
Show answer
ipconfig /all). Before pinging anything, confirm your machine has a valid IP, default gateway, and DNS server. If ipconfig shows 169.254.x.x (APIPA), the problem is DHCP, not the destination server.A switchport is in a “blocking” state. Which protocol is most likely responsible?
A. CDP
B. LACP
C. STP
D. VTP
Show answer
At which OSI layer does a router make its forwarding decisions?
A. Layer 1 (Physical)
B. Layer 2 (Data Link)
C. Layer 3 (Network)
D. Layer 4 (Transport)
Show answer
A web server is configured to accept encrypted traffic only. Which port must be open on the firewall?
A. 80
B. 443
C. 8080
D. 21
Show answer
What is the maximum supported cable length for a 1000BASE-T (Gigabit Ethernet over copper) run?
A. 55 meters
B. 100 meters
C. 185 meters
D. 500 meters
Show answer
Which wireless standard is marketed as Wi-Fi 6 and operates in both the 2.4 GHz and 5 GHz bands?
A. 802.11n
B. 802.11ac
C. 802.11ax
D. 802.11g
Show answer
Which protocol synchronizes device clocks across the network so that log timestamps line up during an investigation?
A. SNMP
B. NTP
C. Syslog
D. NetFlow
Show answer
Which technology provides default-gateway redundancy so hosts keep connectivity if one router fails?
A. STP
B. LACP
C. FHRP (HSRP / VRRP)
D. QoS
Show answer
An attacker positions themselves between a user and the gateway, silently relaying and reading the traffic that passes through. What type of attack is this?
A. On-path (man-in-the-middle)
B. Denial of service
C. SQL injection
D. Brute force
Show answer
Which wireless security standard provides the strongest protection and introduces Simultaneous Authentication of Equals (SAE)?
A. WEP
B. WPA
C. WPA2
D. WPA3
Show answer
A gigabit link between two switches negotiates at only 100 Mbps. Both switches and both ports support gigabit. What is the most likely cause?
A. Duplex mismatch
B. A faulty cable with only two working pairs
C. Incorrect VLAN assignment
D. STP is blocking the port
Show answer
Users report slow performance, and you see “late collisions” incrementing on a switch interface. What is the most likely cause?
A. Duplex mismatch
B. Broadcast storm
C. DNS failure
D. IP address conflict
Show answer
Score yourself
The real exam passes at 720/900 ≈ 80%. On these 20 questions, that’s 16 correct.
| Score | What it means | Next step |
|---|---|---|
| 18–20 | Exam-ready. You’re consistently above the pass bar. | Schedule the exam — and take one more fresh test to confirm. |
| 15–17 | Right at the line. A focused weak-domain pass gets you clear. | Drill the domains you missed for another week, then retest. |
| 12–14 | Solid foundation, not exam-ready yet. | 2–3 more weeks. Use the final-week plan when you’re close. |
| Below 12 | More foundation work needed before booking the exam. | Work domain-by-domain. Don’t schedule until you’re consistently 16+. |
Spot your weak domain: each question is tagged with its official Network+ domain (Networking concepts, Implementation, Operations, Security, Troubleshooting). If you missed 2+ questions in the same domain, that’s exactly what to drill next.
Want more practice?
Practice with free flashcards, subnetting drills, and exam-style scenarios at network.it-learn.io — aligned to the current N10-009 objectives. Free with a quick signup.
The Network+ practice-test bank on network.it-learn.io has 500+ questions across all five domains — including the PBQ-style drag-and-drop scenarios (subnet allocation, OSI-layer mapping) that this multiple-choice set doesn’t cover. All aligned to the N10-009 objectives. Drill 20 a day for two weeks and you’ll be over the 80% bar on every domain.
All the free cert-study tools — Network+, Security+, CCIE Security, CHFI, ECIH — live at study.it-learn.io. Flashcards, quizzes, calculators, mnemonics. Free with a quick signup.






