CNAE-101 Sample Questions

CNAE-101 Sample Questions & Answers

Network security ties with highly available architecture design for the heaviest weight, alongside remote access paired with network-service management, routing and switching techniques, performance and connectivity diagnostics, and capacity-planning governance.

Launch the full CNAE-101 simulator →

Free CNAE-101 Sample Questions with Answers

Real questions from the Certified Network Administrator and Engineer practice test — answers and explanations included. Showing 6 of 12 free samples.

  1. Question 1Beginner

    Network Design · Implement advanced routing and switching solutions

    An architect is designing a QoS policy for a corporate network that handles heavy voice and video traffic. The design requires that Voice over IP (VoIP) packets receive strict priority queuing over all other traffic types. Which Differentiated Services Code Point (DSCP) value is the industry standard recommendation for marking this voice traffic?

    Show answer & explanation

    Correct answer: C

    In the Differentiated Services (DiffServ) architecture, the Expedited Forwarding (EF) DSCP value (decimal 46) is the industry standard for voice traffic. It provides a low-loss, low-latency, low-jitter, assured bandwidth end-to-end service, which is critical for real-time VoIP. AF41 is typically used for interactive video, CS3 for call signaling, and default routing for best-effort data.

  2. Question 2Beginner

    Network Design · Design and integrate cloud and hybrid cloud network environments

    True or False: In a containerized networking environment utilizing the Container Network Interface (CNI), each container is natively assigned a globally routable public IP address by default to communicate across the internet.

    Show answer & explanation

    Correct answer: B

    False. By default, container networking models (such as those managed by CNI in Kubernetes or Docker's default bridge) assign private, internal IP addresses to containers. They rely on Network Address Translation (NAT), ingress controllers, or load balancers to communicate with or be accessed from external networks or the public internet.

  3. Question 3Advanced

    Network Design · Design and integrate cloud and hybrid cloud network environments

    Background:
    A global financial institution is redesigning its hybrid cloud architecture. The company currently operates two on-premises data centers (DC1 and DC2) and utilizes a major public cloud provider for customer-facing web applications.

    Current Situation:
    The web applications in the cloud Virtual Private Cloud (VPC) need to securely query backend databases located in the on-premises data centers. Traffic volume is extremely high, and latency must be minimized. The current architecture relies on standard IPsec VPNs over the public internet, which has resulted in unpredictable latency and occasional packet loss during peak trading hours.

    Requirements:

    1. Establish a dedicated, high-throughput, low-latency connection between the cloud VPC and the on-premises data centers.
    2. Ensure that if the connection to DC1 fails, traffic automatically and seamlessly fails over to DC2.
    3. The routing protocol must support dynamic updates and scale with thousands of routes.

    Based on these requirements, which design approach is optimal?

    Show answer & explanation

    Correct answer: A

    Dedicated private circuits (like Direct Connect or ExpressRoute) bypass the public internet, satisfying the requirement for high-throughput, low-latency, and predictable performance. Using dual circuits to separate data centers provides the necessary redundancy. BGP is the required and optimal dynamic routing protocol for these types of hybrid connections, as it easily handles large routing tables and dynamic failover.

  4. Question 4Beginner

    Network Design · Develop network documentation and diagramming standards for networks

    When creating physical network documentation, standardizing the symbols and diagramming conventions is essential. Which of the following details is MOST critical to include in a physical network diagram, but typically omitted from a logical network diagram?

    Show answer & explanation

    Correct answer: C

    Physical network diagrams map out the tangible hardware and cabling of a network. Critical details include cable types (e.g., Cat6, single-mode fiber), specific port numbers, rack locations, and patch panel connections. Logical diagrams focus on how data flows and how the network is structured from an IP/routing perspective, including VLANs, IP subnets, and routing domains, abstracting away the physical cabling.

  5. Question 5Intermediate

    Network Design · Implement advanced routing and switching solutions

    A network engineer needs to configure OSPF in a large enterprise environment. To prevent the Link-State Database (LSDB) from becoming too large and consuming excessive router memory, the engineer decides to use an OSPF Stub Area. Which OSPF Link-State Advertisement (LSA) types are specifically blocked from entering a standard Stub Area?

    Show answer & explanation

    Correct answer: C

    A standard OSPF Stub Area blocks LSA Type 5 (External routes injected by an ASBR) and LSA Type 4 (ASBR Summary LSA), replacing them with a default route (generated as a Type 3 LSA by the ABR). This significantly reduces the size of the routing table and LSDB for routers inside the stub area. Type 1, 2, and 3 LSAs are still allowed in a standard Stub Area.

  6. Question 6Intermediate

    Network Design · Design highly available and scalable network architectures

    A systems architect is designing a web application delivery solution using a load balancer. The requirement is that all HTTP requests from a specific client IP address must consistently be forwarded to the exact same backend server to maintain session state. Which load balancing feature must be implemented?

    flowchart LR Client([Client IP: 192.0.2.5]) --> LB[Load Balancer] LB -.-> |Session 1| S1[Server A] LB -.-> |Session 2| S1 LB -.-> |Session 3| S1
    Show answer & explanation

    Correct answer: C

    Session affinity (also known as sticky sessions or persistence) is a feature that ensures all requests from a specific client are directed to the same backend server for the duration of the session. This is critical for applications that store state locally on the server. Round Robin distributes traffic sequentially, and Least Connections sends traffic to the server with the fewest active sessions, neither of which guarantees the same client goes to the same server.

Ready for the real thing?

The full CNAE-101 simulator has every exam-style question, timed mode, and instant scoring.