Courseiva
Network Services and SecurityhardMultiple ChoiceObjective-mapped

CCNA Network Services and Security Practice Question

Exhibit

C:\Users\admin> nslookup www.example.com
Server:  dns.example.com
Address:  192.0.2.5

Name:    www.example.com
Address:  198.51.100.1

C:\Users\admin> ping 198.51.100.1
Pinging 198.51.100.1 with 32 bytes of data:
Reply from 192.0.2.10: Destination host unreachable.

C:\Users\admin> ping 192.0.2.10
Pinging 192.0.2.10 with 32 bytes of data:
Reply from 192.0.2.10: bytes=32 time<1ms TTL=128

A network administrator is troubleshooting an issue where internal hosts can ping the company's web server by IP address (192.0.2.10) but cannot access it using the fully qualified domain name www.example.com. The DNS server (192.0.2.5) is reachable and responds to queries. The administrator runs nslookup www.example.com from a host and receives the following output:

C:\> nslookup www.example.com

Server: UnKnown Address: 192.0.2.5

Name: www.example.com Address: 192.0.2.20

Based on the output, what is the most likely cause of the problem?

⚠ Common exam trap

Many candidates assume a DNS server that responds to queries is functioning correctly, overlooking that the response itself can contain an incorrect A record, which is the actual cause of the resolution failure.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

The DNS A record for www.example.com is incorrect; update it to point to 192.0.2.10.

The nslookup output shows that www.example.com resolves to 192.0.2.20, but the web server is at 192.0.2.10. This indicates the DNS A record is incorrect and must be updated to point to the correct IP. Pinging by IP works because it bypasses DNS, confirming network connectivity. The host's DNS cache is not the issue because nslookup queries the server directly and still returns the wrong address. The firewall is not involved since pinging by IP succeeds, and the DNS server is authoritative (the response is received).

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • The host's DNS cache is corrupted; flush it using ipconfig /flushdns.

    Why it's wrong here

    The host's DNS cache is not the issue because the nslookup query goes directly to the DNS server and still returns the wrong IP address 192.0.2.20. Flushing the cache would not correct the DNS record.

  • The DNS A record for www.example.com is incorrect; update it to point to 192.0.2.10.

    Why this is correct

    Correct. The nslookup output shows that www.example.com resolves to 192.0.2.20, but the actual web server is at 192.0.2.10. This indicates the DNS A record is incorrect and must be updated to point to the correct IP address.

  • The web server's firewall is blocking traffic from the host; add an allow rule.

    Why it's wrong here

    The web server's firewall is not likely the cause because the host can successfully ping the server at 192.0.2.10, indicating network connectivity. The problem is DNS resolution, not firewall blocking.

  • The DNS server is not authoritative for the example.com zone; delegate the zone to a different server.

    Why it's wrong here

    The DNS server is responding to queries, so it is authoritative for the zone (or at least has the record). The issue is not about delegation; it is that the A record itself is wrong.

Option-by-option analysis

Why each answer is right or wrong

Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The 200-301 exam frequently reuses these exact scenarios with slightly different constraints.

The DNS A record for www.example.com is incorrect; update it to point to 192.0.2.10.Correct answer

Why this is correct

Correct. The nslookup output shows that www.example.com resolves to 192.0.2.20, but the actual web server is at 192.0.2.10. This indicates the DNS A record is incorrect and must be updated to point to the correct IP address.

The host's DNS cache is corrupted; flush it using ipconfig /flushdns.Wrong answer — click to see why

Why this is wrong here

The nslookup output shows the DNS server is returning an incorrect IP address (198.51.100.1) for www.example.com, not a local cache issue. Flushing the DNS cache would not resolve the problem because the host is querying the DNS server and receiving the wrong answer.

Why candidates choose this

Students often confuse DNS resolution failures with local cache corruption, especially when the host can ping the correct IP but not the FQDN. The ipconfig /flushdns command is a common troubleshooting step for DNS issues, but it is only effective when the cache contains stale or incorrect entries, not when the authoritative server returns a wrong record.

The web server's firewall is blocking traffic from the host; add an allow rule.Wrong answer — click to see why

Why this is wrong here

The host can successfully ping the web server at 192.0.2.10, which indicates that ICMP traffic is not blocked by the firewall. The problem is that the host is trying to reach the wrong IP address (198.51.100.1) due to DNS resolution, not that the correct IP is being blocked.

Why candidates choose this

Firewall rules are a common cause of connectivity issues, and students may assume that if a web server is unreachable by name, the firewall is blocking HTTP/HTTPS traffic. However, the successful ping to the correct IP shows that the network path is open; the issue is purely with name resolution.

The DNS server is not authoritative for the example.com zone; delegate the zone to a different server.Wrong answer — click to see why

Why this is wrong here

The nslookup response includes the server name 'dns.example.com', which indicates that the DNS server is authoritative for the example.com zone. If it were not authoritative, the response would typically show a non-authoritative answer or refer to another server. Delegation is not needed because the server is already authoritative.

Why candidates choose this

Students may think that if a DNS server returns an incorrect IP, it might not be authoritative for the zone. However, the nslookup output clearly shows the server is authoritative. The issue is a misconfiguration within the zone, not a lack of authority.

Analysis generated from the official 200-301blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”

Visual reference

Client Recursive Resolver Root DNS (13 root servers) TLD DNS (.com, .org, …) Authoritative example.com query IP addr answer

Quick reference

Common DNS Record Types

RecordPurposeExample
AIPv4 address mappingexample.com → 93.184.216.34
AAAAIPv6 address mappingexample.com → 2606:2800::1
CNAMEAlias to another hostnamewww → example.com
MXMail server for domainexample.com → mail.example.com (priority 10)
TXTText data (SPF, DKIM, verification)v=spf1 include:_spf.example.com ~all
NSAuthoritative name serversexample.com NS ns1.example.com
PTRReverse DNS (IP → hostname)34.216.184.93.in-addr.arpa → example.com
SOAZone authority recordPrimary NS, admin email, serial, TTL defaults

About these practice questions

Courseiva writes every 200-301 question from scratch — 1,389 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 200-301 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-301 exam.