CCNA Network Services and Security Practice Question
Exhibit
C:\Users\admin> nslookup www.example.com Server: dns.example.com Address: 192.0.2.5 Name: www.example.com Address: 198.51.100.1 C:\Users\admin> ping 198.51.100.1 Pinging 198.51.100.1 with 32 bytes of data: Reply from 192.0.2.10: Destination host unreachable. C:\Users\admin> ping 192.0.2.10 Pinging 192.0.2.10 with 32 bytes of data: Reply from 192.0.2.10: bytes=32 time<1ms TTL=128
A network administrator is troubleshooting an issue where internal hosts can ping the company's web server by IP address (192.0.2.10) but cannot access it using the fully qualified domain name www.example.com. The DNS server (192.0.2.5) is reachable and responds to queries. The administrator runs nslookup www.example.com from a host and receives the following output:
C:\> nslookup www.example.com
Server: UnKnown Address: 192.0.2.5
Name: www.example.com Address: 192.0.2.20
Based on the output, what is the most likely cause of the problem?
⚠ Common exam trap
Many candidates assume a DNS server that responds to queries is functioning correctly, overlooking that the response itself can contain an incorrect A record, which is the actual cause of the resolution failure.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The DNS A record for www.example.com is incorrect; update it to point to 192.0.2.10.
The nslookup output shows that www.example.com resolves to 192.0.2.20, but the web server is at 192.0.2.10. This indicates the DNS A record is incorrect and must be updated to point to the correct IP. Pinging by IP works because it bypasses DNS, confirming network connectivity. The host's DNS cache is not the issue because nslookup queries the server directly and still returns the wrong address. The firewall is not involved since pinging by IP succeeds, and the DNS server is authoritative (the response is received).
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The host's DNS cache is corrupted; flush it using ipconfig /flushdns.
Why it's wrong here
The host's DNS cache is not the issue because the nslookup query goes directly to the DNS server and still returns the wrong IP address 192.0.2.20. Flushing the cache would not correct the DNS record.
- ✓
The DNS A record for www.example.com is incorrect; update it to point to 192.0.2.10.
Why this is correct
Correct. The nslookup output shows that www.example.com resolves to 192.0.2.20, but the actual web server is at 192.0.2.10. This indicates the DNS A record is incorrect and must be updated to point to the correct IP address.
- ✗
The web server's firewall is blocking traffic from the host; add an allow rule.
Why it's wrong here
The web server's firewall is not likely the cause because the host can successfully ping the server at 192.0.2.10, indicating network connectivity. The problem is DNS resolution, not firewall blocking.
- ✗
The DNS server is not authoritative for the example.com zone; delegate the zone to a different server.
Why it's wrong here
The DNS server is responding to queries, so it is authoritative for the zone (or at least has the record). The issue is not about delegation; it is that the A record itself is wrong.
Option-by-option analysis
Why each answer is right or wrong
Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The 200-301 exam frequently reuses these exact scenarios with slightly different constraints.
✓The DNS A record for www.example.com is incorrect; update it to point to 192.0.2.10.Correct answer▾
Why this is correct
Correct. The nslookup output shows that www.example.com resolves to 192.0.2.20, but the actual web server is at 192.0.2.10. This indicates the DNS A record is incorrect and must be updated to point to the correct IP address.
✗The host's DNS cache is corrupted; flush it using ipconfig /flushdns.Wrong answer — click to see why▾
Why this is wrong here
The nslookup output shows the DNS server is returning an incorrect IP address (198.51.100.1) for www.example.com, not a local cache issue. Flushing the DNS cache would not resolve the problem because the host is querying the DNS server and receiving the wrong answer.
Why candidates choose this
Students often confuse DNS resolution failures with local cache corruption, especially when the host can ping the correct IP but not the FQDN. The ipconfig /flushdns command is a common troubleshooting step for DNS issues, but it is only effective when the cache contains stale or incorrect entries, not when the authoritative server returns a wrong record.
✗The web server's firewall is blocking traffic from the host; add an allow rule.Wrong answer — click to see why▾
Why this is wrong here
The host can successfully ping the web server at 192.0.2.10, which indicates that ICMP traffic is not blocked by the firewall. The problem is that the host is trying to reach the wrong IP address (198.51.100.1) due to DNS resolution, not that the correct IP is being blocked.
Why candidates choose this
Firewall rules are a common cause of connectivity issues, and students may assume that if a web server is unreachable by name, the firewall is blocking HTTP/HTTPS traffic. However, the successful ping to the correct IP shows that the network path is open; the issue is purely with name resolution.
✗The DNS server is not authoritative for the example.com zone; delegate the zone to a different server.Wrong answer — click to see why▾
Why this is wrong here
The nslookup response includes the server name 'dns.example.com', which indicates that the DNS server is authoritative for the example.com zone. If it were not authoritative, the response would typically show a non-authoritative answer or refer to another server. Delegation is not needed because the server is already authoritative.
Why candidates choose this
Students may think that if a DNS server returns an incorrect IP, it might not be authoritative for the zone. However, the nslookup output clearly shows the server is authoritative. The issue is a misconfiguration within the zone, not a lack of authority.
Analysis generated from the official 200-301blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”
Visual reference
Quick reference
Common DNS Record Types
| Record | Purpose | Example |
|---|---|---|
| A | IPv4 address mapping | example.com → 93.184.216.34 |
| AAAA | IPv6 address mapping | example.com → 2606:2800::1 |
| CNAME | Alias to another hostname | www → example.com |
| MX | Mail server for domain | example.com → mail.example.com (priority 10) |
| TXT | Text data (SPF, DKIM, verification) | v=spf1 include:_spf.example.com ~all |
| NS | Authoritative name servers | example.com NS ns1.example.com |
| PTR | Reverse DNS (IP → hostname) | 34.216.184.93.in-addr.arpa → example.com |
| SOA | Zone authority record | Primary NS, admin email, serial, TTL defaults |
Go deeper
Related to this question
Learn chapter
Diagnosing DNS Record Issues — A, AAAA, CNAME, MX, NS, and PTR Records
Key term
ICMP
ICMP is a network-layer protocol used by network devices to send error messages and operational information about network connectivity.
Key term
CAN
A CAN (Controller Area Network) is a robust vehicle bus standard designed to allow microcontrollers and devices to communicate with each other without a host computer.
About these practice questions
Courseiva writes every 200-301 question from scratch — 1,389 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 200-301 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-301 exam.