Lab 20 — Network+ Final Practical Assessment
Mission Information
Section titled “Mission Information”| Item | Details |
|---|---|
| Lab | 20 |
| Lab Name | Network+ Final Practical Assessment |
| Track | CompTIA Network+ |
| Difficulty | Advanced |
| Estimated Time | 240–300 minutes |
| Primary Role | Network Technician / Junior Network Administrator |
| Environment | GHC Enterprise Network |
| Mission Type | Final Practical Assessment |
| Primary Systems | RTR01, SW01, SW02, SW03, AP01, SERVER01, DNS01, NMS01, CLIENT01–CLIENT04 |
| Primary Tools | Network Device CLI, Windows/Linux Utilities, Wireshark, SNMP, Syslog, DNS/DHCP Tools |
| Assessment Areas | Design, Configuration, Security, Services, Monitoring, Troubleshooting, Documentation |
Mission Objective: Design, deploy, validate, secure, monitor, troubleshoot, and document a complete enterprise network from a set of business requirements. Unlike previous guided labs, this assessment requires you to determine the correct implementation approach and prove that the resulting network meets all technical and operational requirements.
Mission Scenario
Section titled “Mission Scenario”GHC Enterprise is opening a new office.
The organization requires a production-style network supporting:
Employees
Engineering
Servers
Network Management
Corporate Wireless
Guest WirelessYou have been assigned responsibility for the initial network deployment.
Management provides only:
Business Requirements
Device Inventory
Security Requirements
Service Requirements
Availability RequirementsYou must transform these requirements into:
Network Design ↓IP Addressing ↓VLAN Architecture ↓Switching ↓Routing ↓Network Services ↓Wireless ↓Security ↓Monitoring ↓Validation ↓DocumentationDuring final validation, several faults will also be introduced.
You must identify and resolve them without being told where they are located.
Assessment Rules
Section titled “Assessment Rules”This is a practical assessment.
You should not simply copy previous configurations.
For every major design decision, be prepared to explain:
What did you configure?
Why did you configure it?
How did you validate it?
How would you troubleshoot it?Do not:
Randomly Configure Devices
Use Unnecessary Default Settings
Disable Security Controls
Make Multiple Troubleshooting Changes Simultaneously
Ignore Documentation
Declare Success Based Only on PingYour final network must be:
Functional+Secure+Observable+Troubleshootable+DocumentedAssessment Objectives
Section titled “Assessment Objectives”By completing this assessment, you will demonstrate your ability to:
-
interpret business networking requirements
-
create logical network designs
-
develop IPv4 addressing plans
-
design VLAN architectures
-
configure access ports
-
configure 802.1Q trunks
-
implement inter-VLAN routing
-
configure default gateways
-
implement DHCP
-
implement DHCP relay
-
configure DNS
-
validate name resolution
-
configure wireless networks
-
separate corporate and guest wireless
-
apply basic network security controls
-
implement management access
-
configure network monitoring
-
configure SNMP
-
configure centralized Syslog
-
establish network baselines
-
measure latency and packet loss
-
analyze network traffic
-
troubleshoot physical faults
-
troubleshoot switching faults
-
troubleshoot routing faults
-
troubleshoot DHCP and DNS
-
troubleshoot wireless connectivity
-
troubleshoot performance problems
-
perform root cause analysis
-
document the final environment
1. Business Requirements
Section titled “1. Business Requirements”GHC Enterprise requires support for:
| Department / Service | Users |
|---|---|
| Corporate Users | 80 |
| Engineering | 40 |
| Servers | 20 |
| Network Management | 15 |
| Corporate Wireless | 60 |
| Guest Wireless | 100 |
The network must support future growth.
2. Technical Requirements
Section titled “2. Technical Requirements”The environment must provide:
Ethernet Switching
VLAN Segmentation
Inter-VLAN Routing
DHCP
DNS
Corporate Wi-Fi
Guest Wi-Fi
Internet Connectivity
Central Monitoring
Central Logging3. Security Requirements
Section titled “3. Security Requirements”The network must:
-
separate users from servers
-
separate management traffic
-
separate guest wireless
-
restrict guest access to internal networks
-
use secure wireless authentication where supported
-
restrict network-device management
-
avoid insecure default credentials
-
use secure SNMP where supported
-
centralize security and operational logs
-
disable unused switch ports where appropriate
4. Device Inventory
Section titled “4. Device Inventory”You have:
1 × Edge Router
1 × Core Switch
2 × Access Switches
1 × Wireless Access Point
1 × Application Server
1 × DNS/DHCP Server
1 × Network Monitoring Server
4 × Test Client SystemsRepresent them as:
RTR01
SW01
SW02
SW03
AP01
SERVER01
DNS01
NMS01
CLIENT01
CLIENT02
CLIENT03
CLIENT045. Design the Network
Section titled “5. Design the Network”Create a logical topology before configuring devices.
Recommended architecture:
INTERNET | | ┌───────┐ │ RTR01 │ └───┬───┘ | Trunk | ┌───────┐ │ SW01 │ │ Core │ └─┬───┬─┘ | | Trunk| |Trunk | | ┌──────┘ └──────┐ | | ┌───────┐ ┌───────┐ │ SW02 │ │ SW03 │ └───┬───┘ └───┬───┘ | | Users / AP01 Servers / NMS6. Create the VLAN Architecture
Section titled “6. Create the VLAN Architecture”Design VLANs for:
| VLAN | Name | Purpose |
|---|---|---|
| 10 | USERS | Corporate endpoints |
| 20 | ENGINEERING | Engineering systems |
| 30 | SERVERS | Enterprise servers |
| 40 | MANAGEMENT | Network management |
| 50 | CORP-WIFI | Corporate wireless |
| 60 | GUEST-WIFI | Guest wireless |
7. Create the Addressing Plan
Section titled “7. Create the Addressing Plan”Use a private addressing architecture.
Example:
| VLAN | Network | Gateway |
|---|---|---|
| 10 | 10.10.10.0/24 |
10.10.10.1 |
| 20 | 10.10.20.0/24 |
10.10.20.1 |
| 30 | 10.10.30.0/24 |
10.10.30.1 |
| 40 | 10.10.40.0/24 |
10.10.40.1 |
| 50 | 10.10.50.0/24 |
10.10.50.1 |
| 60 | 10.10.60.0/24 |
10.10.60.1 |
For an additional challenge, subnet the environment yourself instead of using /24 networks.
8. Document Static Infrastructure Addresses
Section titled “8. Document Static Infrastructure Addresses”Reserve static addresses for infrastructure.
Example:
RTR01:10.10.40.1
SW01:10.10.40.2
SW02:10.10.40.3
SW03:10.10.40.4
AP01:10.10.40.10
DNS01:10.10.30.53
SERVER01:10.10.30.30
NMS01:10.10.40.509. Create the Physical Network
Section titled “9. Create the Physical Network”Connect:
RTR01 |SW01 / \SW02 SW03Then connect:
CLIENT01CLIENT02AP01to SW02.
Connect:
SERVER01DNS01NMS01to appropriate switch ports according to your design.
10. Validate Physical Connectivity
Section titled “10. Validate Physical Connectivity”Before configuring VLANs, verify:
Power
Cable
Link LEDs
Interface State
Speed
DuplexOn switches:
show interfaces statusRecord the physical baseline.
11. Configure Device Identity
Section titled “11. Configure Device Identity”Configure meaningful hostnames:
RTR01
SW01
SW02
SW03Verify:
show running-config12. Secure Administrative Access
Section titled “12. Secure Administrative Access”Where supported:
-
configure strong administrator credentials
-
enable SSH
-
disable unnecessary remote-management protocols
-
restrict management access
-
configure session timeouts
-
configure login banners where required
Prefer:
SSHover:
Telnet13. Create VLANs
Section titled “13. Create VLANs”On required switches, create:
VLAN 10USERS
VLAN 20ENGINEERING
VLAN 30SERVERS
VLAN 40MANAGEMENT
VLAN 50CORP-WIFI
VLAN 60GUEST-WIFIVerify:
show vlan brief14. Configure Access Ports
Section titled “14. Configure Access Ports”Assign endpoints to appropriate VLANs.
Example:
CLIENT01→ VLAN 10
CLIENT02→ VLAN 20
SERVER01→ VLAN 30
NMS01→ VLAN 40Verify each assignment.
15. Configure Trunks
Section titled “15. Configure Trunks”Configure links:
SW01 ↔ RTR01
SW01 ↔ SW02
SW01 ↔ SW03as required by your architecture.
Verify:
show interfaces trunk16. Validate Allowed VLANs
Section titled “16. Validate Allowed VLANs”Ensure required VLANs traverse appropriate trunks.
Do not automatically allow every VLAN everywhere.
Think about:
Least Required Connectivity17. Configure Inter-VLAN Routing
Section titled “17. Configure Inter-VLAN Routing”Use the routing approach supported by your environment.
One possible design:
Router-on-a-StickConceptually:
RTR01 |802.1Q |SW01Create gateway interfaces for each VLAN.
18. Configure VLAN Gateways
Section titled “18. Configure VLAN Gateways”Provide:
VLAN 1010.10.10.1
VLAN 2010.10.20.1
VLAN 3010.10.30.1
VLAN 4010.10.40.1
VLAN 5010.10.50.1
VLAN 6010.10.60.119. Verify Routing
Section titled “19. Verify Routing”Run:
show ip interface briefThen:
show ip routeVerify every required network appears.
20. Configure Infrastructure Management
Section titled “20. Configure Infrastructure Management”Place management interfaces in:
VLAN 40Verify NMS01 can reach:
RTR01
SW01
SW02
SW03
AP0121. Configure DHCP
Section titled “21. Configure DHCP”Create scopes for:
USERS
ENGINEERING
CORP-WIFI
GUEST-WIFIServer and management systems may use static addressing according to the design.
22. DHCP Scope Requirements
Section titled “22. DHCP Scope Requirements”Each scope should provide:
Network
Subnet Mask
Default Gateway
DNS Server
Lease Range
Exclusions23. Reserve Infrastructure Addresses
Section titled “23. Reserve Infrastructure Addresses”Exclude:
Default Gateways
Servers
Switches
Routers
Access Points
Monitoring Systemsfrom dynamic allocation.
24. Configure DHCP Relay
Section titled “24. Configure DHCP Relay”If DNS01 provides DHCP from the server VLAN, configure appropriate relay functionality on routed interfaces.
Conceptually:
Client Broadcast ↓Gateway ↓DHCP Relay ↓DNS01 / DHCP Server25. Validate DHCP
Section titled “25. Validate DHCP”On CLIENT01:
ipconfig /releaseipconfig /renewipconfig /allVerify:
Correct VLAN Address
Correct Mask
Correct Gateway
Correct DNS26. Capture DHCP
Section titled “26. Capture DHCP”Wireshark:
dhcpIdentify:
Discover
Offer
Request
AcknowledgmentDocument:
DORA27. Configure DNS
Section titled “27. Configure DNS”Create an internal zone:
ghc.labCreate:
portal.ghc.lab→SERVER01Example:
portal.ghc.lab→10.10.30.3028. Validate DNS
Section titled “28. Validate DNS”Run:
nslookup portal.ghc.labExpected:
10.10.30.30Then:
ping portal.ghc.labwhere ICMP is permitted.
29. Capture DNS
Section titled “29. Capture DNS”Wireshark:
dnsIdentify:
Query
Response
Requested Hostname
Returned Address30. Configure the Internal Application
Section titled “30. Configure the Internal Application”SERVER01 should provide a test application.
Example:
HTTPSTCP 443Verify locally before testing across the network.
Linux:
ss -lntp31. Test Application Connectivity
Section titled “31. Test Application Connectivity”From CLIENT01:
Test-NetConnection 10.10.30.30 -Port 443Then test:
https://portal.ghc.lab32. Configure Corporate Wireless
Section titled “32. Configure Corporate Wireless”Create:
SSID:GHC-CORPMap it to:
VLAN 50Use the strongest authentication method supported by your lab platform.
33. Configure Guest Wireless
Section titled “33. Configure Guest Wireless”Create:
SSID:GHC-GUESTMap it to:
VLAN 60Guest traffic must remain separated from internal enterprise systems.
34. Validate Corporate Wi-Fi
Section titled “34. Validate Corporate Wi-Fi”Connect CLIENT03.
Verify:
SSID:GHC-CORP
Address:10.10.50.x
Gateway:10.10.50.1
DNS:CorrectThen test internal services.
35. Validate Guest Wi-Fi
Section titled “35. Validate Guest Wi-Fi”Connect CLIENT04.
Verify:
SSID:GHC-GUEST
Address:10.10.60.x
Gateway:10.10.60.136. Apply Guest Isolation
Section titled “36. Apply Guest Isolation”Guest users should not be able to reach:
10.10.10.0/24
10.10.20.0/24
10.10.30.0/24
10.10.40.0/24
10.10.50.0/24while still being allowed appropriate external connectivity where your lab supports it.
37. Validate Segmentation
Section titled “37. Validate Segmentation”From GHC-GUEST:
Internal Server:DENIED
Management Network:DENIED
Corporate Clients:DENIEDDocument the results.
38. Apply Basic Switch Security
Section titled “38. Apply Basic Switch Security”Where supported, configure appropriate protections such as:
Disable Unused Ports
Place Unused Ports in an Unused VLAN
Restrict Management Access
Apply Port Security Where Appropriate39. Secure Unused Ports
Section titled “39. Secure Unused Ports”Unused interfaces should not remain unnecessarily active.
Example:
Unused Port ↓Unused VLAN ↓Administratively Disabled40. Validate Management Separation
Section titled “40. Validate Management Separation”Corporate or guest users should not have unrestricted access to:
Switch Management
Router Management
NMS AdministrationTest according to your security policy.
41. Configure NTP
Section titled “41. Configure NTP”Configure network infrastructure to use a consistent time source.
Verify:
RTR01
SW01
SW02
SW03
SERVER01
NMS01have synchronized time.
42. Why Time Synchronization Matters
Section titled “42. Why Time Synchronization Matters”Accurate time enables:
Log Correlation
Incident Timelines
Troubleshooting
Security Investigations43. Configure SNMP
Section titled “43. Configure SNMP”Configure monitoring access from:
NMS01to network infrastructure.
Prefer:
SNMPv3where supported.
44. Restrict SNMP
Section titled “44. Restrict SNMP”Monitoring should be allowed only from authorized management systems.
Conceptually:
NMS01 ↓SNMP ↓Network Devicesnot:
Any Network Host ↓SNMP45. Validate SNMP
Section titled “45. Validate SNMP”From NMS01, retrieve:
System Name
System Description
System Uptime
Interface StatusSave the results.
46. Configure SNMP Traps
Section titled “46. Configure SNMP Traps”Configure devices to send appropriate notifications to NMS01.
Test:
Link Down
Link Upusing a non-critical lab interface.
47. Configure Syslog
Section titled “47. Configure Syslog”Configure:
RTR01
SW01
SW02
SW03to send logs to:
NMS0148. Validate Syslog
Section titled “48. Validate Syslog”Generate a controlled interface event.
Confirm NMS01 receives:
Timestamp
Hostname
Severity
Event Message49. Establish a Monitoring Baseline
Section titled “49. Establish a Monitoring Baseline”Measure:
Latency
Packet Loss
Interface Utilization
CPU
Memory
Interface Errors
AvailabilityRecord normal values.
50. Create Monitoring Thresholds
Section titled “50. Create Monitoring Thresholds”Example lab thresholds:
CPU > 80%for 10 minutes
Interface Utilization > 80%for 15 minutes
Packet Loss > 2%for 5 minutesAdjust according to your environment.
51. Test Latency
Section titled “51. Test Latency”From CLIENT01:
ping 10.10.30.30 -n 50Record:
Minimum:
Maximum:
Average:
Packet Loss:52. Test the Network Path
Section titled “52. Test the Network Path”Run:
tracert 10.10.30.30Document the expected path.
53. Test Throughput
Section titled “53. Test Throughput”Use your approved lab throughput-testing tool.
Measure:
CLIENT01→SERVER01Record:
Throughput:
Latency:
Packet Loss:54. Capture Normal Traffic
Section titled “54. Capture Normal Traffic”Create a baseline packet capture containing:
ARP
DHCP
DNS
ICMP
TCPSave:
LAB20-BASELINE.pcapng55. Phase Two — Troubleshooting Assessment
Section titled “55. Phase Two — Troubleshooting Assessment”Once the network has been validated, introduce several faults.
The learner should not be told which faults were introduced.
Possible faults include:
Disconnected Cable
Disabled Interface
Incorrect VLAN
Missing Allowed VLAN
Incorrect IP Address
Incorrect Gateway
DHCP Failure
DHCP Relay Failure
Incorrect DNS Record
Missing Route
Wireless VLAN Error
Application Port Failure
High Utilization
Physical Errors56. Troubleshooting Rule
Section titled “56. Troubleshooting Rule”For every fault:
Identify Symptom ↓Determine Scope ↓Gather Evidence ↓Establish Theory ↓Test Theory ↓Identify Root Cause ↓Plan Corrective Action ↓Implement ↓Verify ↓Document57. Fault Ticket 01
Section titled “57. Fault Ticket 01”Provide:
INC-NETPLUS-2001
Department:Corporate Users
Problem:Multiple users cannot reach internal services.
Internet:Unknown
Started:Approximately 10 minutes ago.No root-cause information should be given.
58. Investigate Ticket 01
Section titled “58. Investigate Ticket 01”Learner should inspect:
Physical Connectivity
Client Addressing
VLAN Membership
Trunking
Gateway
RoutingRecord each test.
59. Fault Ticket 02
Section titled “59. Fault Ticket 02”Provide:
INC-NETPLUS-2002
Department:Engineering
Problem:portal.ghc.lab does not work.
Additional Information:One engineer reports that the server IP responds.60. Investigate Ticket 02
Section titled “60. Investigate Ticket 02”Learner should compare:
Server IP ReachabilityvsHostname ResolutionThen inspect DNS.
61. Fault Ticket 03
Section titled “61. Fault Ticket 03”Provide:
INC-NETPLUS-2003
Department:Sales
Problem:Corporate Wi-Fi connects but internal applications are unavailable.Investigate:
Association
Authentication
DHCP
VLAN Mapping
Gateway
DNS
Routing62. Fault Ticket 04
Section titled “62. Fault Ticket 04”Provide:
INC-NETPLUS-2004
Department:Multiple
Problem:Network performance is extremely slow.
Symptoms:High latencyIntermittent packet lossSlow file transfers63. Investigate Performance
Section titled “63. Investigate Performance”Collect:
Latency
Packet Loss
Utilization
Errors
Speed
Duplex
TCP RetransmissionsCompare against the baseline.
64. Use Monitoring Evidence
Section titled “64. Use Monitoring Evidence”Review:
SNMP
Syslog
Interface Graphs
Availability
Packet Loss
Utilization
Error CountersMonitoring should help narrow the investigation.
65. Use Wireshark
Section titled “65. Use Wireshark”Select appropriate filters based on symptoms.
Examples:
arpdnsdhcpicmptcp.analysis.retransmission66. Build a Troubleshooting Matrix
Section titled “66. Build a Troubleshooting Matrix”| Incident | Symptom | Fault Domain | Evidence | Root Cause |
|---|---|---|---|---|
| 2001 | ||||
| 2002 | ||||
| 2003 | ||||
| 2004 |
67. Perform Root Cause Analysis
Section titled “67. Perform Root Cause Analysis”Do not write:
Network was down.Instead identify exactly:
What Failed?
Why?
Who Was Affected?
What Corrected It?68. Example Root Cause
Section titled “68. Example Root Cause”Corporate users lost access to internal resources becauseVLAN 10 was removed from the SW02 uplink allowed-VLANlist during a configuration change.
The trunk remained operational, but VLAN 10 frames couldno longer traverse the uplink.69. Verify Every Remediation
Section titled “69. Verify Every Remediation”After each fix, verify:
Original Symptom
Related Services
Monitoring
No New Problems Introduced70. Perform Full End-to-End Validation
Section titled “70. Perform Full End-to-End Validation”When troubleshooting is complete, test:
CLIENT01→Gateway
CLIENT01→DNS01
CLIENT01→SERVER01
CLIENT01→portal.ghc.lab
CORP-WIFI→Internal Services
GUEST-WIFI→Internet
GUEST-WIFI→Internal NetworkDENIED71. Validate All VLANs
Section titled “71. Validate All VLANs”Confirm:
VLAN 10Operational
VLAN 20Operational
VLAN 30Operational
VLAN 40Operational
VLAN 50Operational
VLAN 60Operational72. Validate Switching
Section titled “72. Validate Switching”Confirm:
Access Ports:Correct
Trunks:Operational
Allowed VLANs:Correct
MAC Learning:Normal73. Validate Routing
Section titled “73. Validate Routing”Confirm:
Gateway Interfaces:UP
Required Routes:Present
Inter-VLAN Routing:Operational74. Validate DHCP
Section titled “74. Validate DHCP”Confirm clients receive:
Correct Address
Correct Mask
Correct Gateway
Correct DNS75. Validate DNS
Section titled “75. Validate DNS”Confirm:
portal.ghc.lab→10.10.30.3076. Validate Wireless
Section titled “76. Validate Wireless”Confirm:
GHC-CORP→Corporate Access
GHC-GUEST→Guest Accesswith required segmentation.
77. Validate Security
Section titled “77. Validate Security”Confirm:
Guest Isolation
Management Restrictions
Unused Port Security
Secure Administration
Monitoring Restrictions78. Validate Monitoring
Section titled “78. Validate Monitoring”Confirm NMS01 receives:
SNMP Metrics
SNMP Notifications
Syslog
Availability Data
Performance Data79. Validate Performance
Section titled “79. Validate Performance”Compare:
| Metric | Baseline | Final |
|---|---|---|
| Latency | ||
| Packet Loss | ||
| Throughput | ||
| Utilization | ||
| Interface Errors |
Final measurements should return to acceptable baseline ranges.
80. Create the Assessment Workspace
Section titled “80. Create the Assessment Workspace”Create:
mkdir -p ~/NetworkPlus-Labs/LAB20/{Design,Configs,Captures,Screenshots,Incidents,Reports}81. Save Device Configurations
Section titled “81. Save Device Configurations”Save:
RTR01-running-config.txt
SW01-running-config.txt
SW02-running-config.txt
SW03-running-config.txt
AP01-config.txt82. Save Packet Captures
Section titled “82. Save Packet Captures”Save:
LAB20-BASELINE.pcapng
LAB20-DHCP.pcapng
LAB20-DNS.pcapng
LAB20-TROUBLESHOOTING.pcapng
LAB20-FINAL-VALIDATION.pcapng83. Create the Network Design Document
Section titled “83. Create the Network Design Document”# GHC Enterprise Network Design
## Business Requirements
## Physical Topology
## Logical Topology
## VLAN Architecture
## IPv4 Addressing Plan
## Gateway Architecture
## Routing Design
## DHCP Design
## DNS Design
## Wireless Design
## Security Controls
## Management Network
## Monitoring Architecture
## Logging Architecture84. Create the Configuration Record
Section titled “84. Create the Configuration Record”# Network Configuration Record
## RTR01
### Interfaces
### Routing
### Security
### Monitoring
## SW01
### VLANs
### Trunks
### Management
### Security
## SW02
### VLANs
### Access Ports
### Trunks
## SW03
### VLANs
### Access Ports
### Trunks
## AP01
### Corporate Wireless
### Guest Wireless85. Create the Validation Report
Section titled “85. Create the Validation Report”# Network Validation Report
## Physical Connectivity
## VLAN Validation
## Trunk Validation
## Routing Validation
## DHCP Validation
## DNS Validation
## Application Validation
## Wireless Validation
## Security Validation
## SNMP Validation
## Syslog Validation
## Performance Validation
## Final Result86. Create the Incident Report
Section titled “86. Create the Incident Report”# Network+ Final Assessment Incident Report
## Incident ID
## Reported Problem
## Business Impact
## Scope
## Initial Evidence
## Troubleshooting Actions
## Theory
## Testing
## Root Cause
## Corrective Action
## Verification
## Preventive Recommendation
## Final Status87. Evidence to Capture
Section titled “87. Evidence to Capture”Capture:
01-final-network-topology.png
02-vlan-design.png
03-ip-addressing-plan.png
04-device-hostnames.png
05-vlan-configuration.png
06-access-port-configuration.png
07-trunk-configuration.png
08-routing-configuration.png
09-routing-table.png
10-dhcp-scopes.png
11-dhcp-client-lease.png
12-dhcp-packet-capture.png
13-dns-record.png
14-dns-resolution.png
15-dns-packet-capture.png
16-server-service.png
17-application-test.png
18-corporate-wireless.png
19-guest-wireless.png
20-guest-isolation.png
21-management-network.png
22-unused-port-security.png
23-ntp-status.png
24-snmp-configuration.png
25-snmp-query.png
26-snmp-trap.png
27-syslog-configuration.png
28-syslog-event.png
29-monitoring-dashboard.png
30-performance-baseline.png
31-normal-packet-capture.png
32-incident-2001.png
33-incident-2002.png
34-incident-2003.png
35-incident-2004.png
36-fault-isolation.png
37-root-cause-analysis.png
38-remediation.png
39-final-performance.png
40-final-monitoring.png
41-final-security-validation.png
42-final-end-to-end-test.png88. Final Practical Assessment Checklist
Section titled “88. Final Practical Assessment Checklist”Network Design
Section titled “Network Design”-
Business requirements reviewed
-
Physical topology created
-
Logical topology created
-
VLAN architecture documented
-
IPv4 addressing documented
-
Infrastructure addresses reserved
Switching
Section titled “Switching”-
VLANs created
-
Access ports configured
-
Trunks configured
-
Required VLANs allowed
-
MAC learning verified
-
Unused ports secured
Routing
Section titled “Routing”-
Gateway interfaces configured
-
Inter-VLAN routing operational
-
Routing table verified
-
Remote networks reachable
-
Required scopes created
-
Infrastructure addresses excluded
-
Gateway options correct
-
DNS options correct
-
DHCP relay configured
-
Client leases verified
-
DORA captured
-
DNS server operational
-
Internal zone configured
-
Application record configured
-
DNS resolution verified
-
DNS packet capture analyzed
Application
Section titled “Application”-
SERVER01 reachable
-
Required service running
-
Application port reachable
-
Application accessible by hostname
Wireless
Section titled “Wireless”-
Corporate SSID configured
-
Guest SSID configured
-
Corporate VLAN correct
-
Guest VLAN correct
-
Wireless DHCP operational
-
Corporate services accessible
-
Guest isolation verified
Security
Section titled “Security”-
Administrative access secured
-
Management network separated
-
Guest network isolated
-
Unused switch ports secured
-
Default credentials avoided
-
Monitoring access restricted
-
Internal segmentation validated
Network Services
Section titled “Network Services”-
NTP operational
-
DHCP operational
-
DNS operational
-
Network time synchronized
Monitoring
Section titled “Monitoring”-
NMS01 operational
-
SNMP configured
-
SNMP queries successful
-
SNMP traps tested
-
Syslog configured
-
Syslog events received
-
Availability monitored
-
Performance monitored
Performance
Section titled “Performance”-
Latency baseline captured
-
Packet-loss baseline captured
-
Throughput measured
-
Interface utilization reviewed
-
Interface errors reviewed
-
Final metrics compared with baseline
Packet Analysis
Section titled “Packet Analysis”-
ARP analyzed
-
DHCP analyzed
-
DNS analyzed
-
ICMP analyzed
-
TCP behavior analyzed
-
Baseline capture saved
-
Troubleshooting capture saved
Troubleshooting
Section titled “Troubleshooting”-
Incident scope determined
-
Symptoms documented
-
Evidence gathered
-
Theories established
-
Theories tested
-
Fault domains isolated
-
Root causes identified
-
Corrective actions implemented
-
Original symptoms retested
-
Full functionality verified
Documentation
Section titled “Documentation”-
Network design completed
-
Addressing plan completed
-
VLAN plan completed
-
Device configurations saved
-
Packet captures saved
-
Screenshots captured
-
Validation report completed
-
Incident reports completed
-
Root cause analysis completed
89. Assessment Scoring
Section titled “89. Assessment Scoring”Use the following scoring model:
| Area | Weight |
|---|---|
| Network Design | 10% |
| Switching & VLANs | 15% |
| Routing & Addressing | 15% |
| DHCP & DNS | 10% |
| Wireless | 10% |
| Security | 10% |
| Monitoring & Logging | 10% |
| Troubleshooting | 15% |
| Documentation | 5% |
| Total | 100% |
90. Recommended Passing Score
Section titled “90. Recommended Passing Score”80%Suggested interpretation:
90–100%Excellent
80–89%Assessment Passed
70–79%Review Required
Below 70%Repeat Practical Assessment91. Critical Failure Conditions
Section titled “91. Critical Failure Conditions”Regardless of total score, require remediation if the learner:
Cannot Establish Basic Connectivity
Cannot Configure VLAN Segmentation
Cannot Configure Correct Default Gateways
Cannot Troubleshoot DHCP
Cannot Troubleshoot DNS
Cannot Isolate Guest Traffic
Cannot Identify Introduced Network FaultsThese represent foundational Network+ operational skills.
92. Final Learner Deliverables
Section titled “92. Final Learner Deliverables”Submit:
01 — Network Topology
02 — IPv4 Addressing Plan
03 — VLAN Plan
04 — Device Configurations
05 — DHCP Configuration
06 — DNS Configuration
07 — Wireless Configuration
08 — Security Validation
09 — Monitoring Configuration
10 — Packet Captures
11 — Performance Baseline
12 — Troubleshooting Incident Reports
13 — Root Cause Analysis
14 — Final Validation Report93. Final Mission Review
Section titled “93. Final Mission Review”Across these labs, you progressed from understanding individual networking components to operating a complete enterprise environment.
The journey became:
Physical Networking ↓Ethernet ↓Switching ↓VLANs ↓IPv4 Addressing ↓Routing ↓DHCP ↓DNS ↓Wireless ↓Network Services ↓Security ↓Performance ↓Monitoring ↓Troubleshooting ↓Enterprise Capstone ↓Final Practical AssessmentA network technician must understand more than:
Which Command Should I Run?You must understand:
What Should the Network Be Doing?
What Is It Actually Doing?
Where Does Expected Behavior Stop?
What Evidence Proves It?
What Is the Safest Fix?
How Do I Verify the Fix?
How Do I Prevent Recurrence?That is the transition from:
Learning Networkingto:
Operating NetworksSkills Demonstrated
Section titled “Skills Demonstrated”By completing the final practical assessment, you have demonstrated practical skills in:
-
enterprise network design
-
Ethernet networking
-
switching
-
VLAN segmentation
-
trunking
-
IPv4 addressing
-
subnetting
-
inter-VLAN routing
-
DHCP
-
DHCP relay
-
DNS
-
wireless networking
-
network segmentation
-
basic network security
-
secure device administration
-
network services
-
NTP
-
SNMP
-
Syslog
-
centralized monitoring
-
network baselining
-
latency analysis
-
packet-loss analysis
-
throughput testing
-
Wireshark analysis
-
fault isolation
-
troubleshooting methodology
-
root cause analysis
-
remediation
-
validation
-
incident documentation
-
network documentation
Network+ Labs Complete
Section titled “Network+ Labs Complete”You have now completed the practical lab sequence for the CompTIA Network+ learning path.
The progression has taken you from:
Networking Fundamentals ↓Network Configuration ↓Network Operations ↓Network Security ↓Network Troubleshooting ↓Enterprise NetworkingThe objective was never simply to prepare you to answer:
"What is a VLAN?"The objective was to prepare you to answer:
Why does the VLAN exist?
How do I configure it?
How do I validate it?
How do I secure it?
How do I monitor it?
How do I troubleshoot it?You have reached the end of the CompTIA Network+ practical lab track. The next step is to consolidate these skills through exam preparation, repeated troubleshooting practice, and increasingly complex real-world networking environments.
What’s Next?
Section titled “What’s Next?”CompTIA Network+ Runbooks
Section titled “CompTIA Network+ Runbooks”You have completed the practical labs.
The next stage converts those skills into repeatable operational procedures that can be used when working with real enterprise networks.
Recommended runbooks:
Runbook 01 — Network Connectivity Troubleshooting
Runbook 02 — VLAN and Trunk Troubleshooting
Runbook 03 — DHCP and IP Addressing Troubleshooting
Runbook 04 — DNS Troubleshooting
Runbook 05 — Routing Troubleshooting
Runbook 06 — Wireless Network Troubleshooting
Runbook 07 — Network Performance Troubleshooting
Runbook 08 — Network Monitoring and Alert Investigation
Runbook 09 — Network Outage Incident Response
Runbook 10 — Enterprise Network Health CheckThe progression now becomes:
Knowledge ↓Hands-On Labs ↓Troubleshooting ↓Capstone ↓Practical Assessment ↓Operational Runbooks ↓Job-Ready Network Operations➡️ Next: Runbook 01 — Network Connectivity Troubleshooting