mediumMultiple Choice
220-1202 Practice Question: A technician is troubleshooting a remote user's…
A technician is troubleshooting a remote user's inability to connect to the corporate network via VPN. The user can ping the VPN server's public IP address. Which step should the technician take next to isolate the issue?
⚠ Common exam trap
220-1202 often tests the troubleshooting methodology order, and the trap is that candidates jump to remediation steps (reboot, reinstall, disable firewall) instead of gathering diagnostic data first when basic connectivity is already confirmed.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Check the VPN client logs for errors
Since the user can already ping the VPN server's public IP, basic network reachability is confirmed, so the next logical step is to examine the VPN client logs for errors such as authentication failures, certificate issues, or negotiation problems. This isolates whether the issue is at the VPN protocol/authentication layer rather than the network layer. Rebooting the modem, disabling the firewall, or reinstalling the client are premature and could disrupt the environment without diagnostic value.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Reboot the user's modem
Why it's wrong here
Rebooting the user's modem is an initial troubleshooting step for general internet connectivity issues. However, since the user can successfully ping a remote server, it indicates that the modem, the local network, and the internet service provider's connection are all functioning correctly at the network and transport layers. A modem reboot would not address a problem specific to VPN tunnel establishment, which typically involves higher-layer protocols and client software configurations.
- ✓
Check the VPN client logs for errors
Why this is correct
Checking the VPN client logs is the most effective and efficient diagnostic step for troubleshooting VPN connection failures. These logs provide detailed information, including specific error codes, timestamps, and messages related to authentication attempts, certificate validation, tunnel negotiation, and network connectivity issues. Analyzing these entries allows a technician to pinpoint the exact cause of the failure, such as incorrect credentials, firewall blocks, or incompatible security parameters, guiding precise corrective actions.
- ✗
Disable the user's firewall
Why it's wrong here
Disabling the user's firewall is a significant security risk and should only be considered as a temporary diagnostic measure, and only after other less intrusive steps have been exhausted. While a firewall can indeed block necessary VPN ports (e.g., UDP 500/4500 for IKE/IPsec or TCP 443 for SSL VPNs), disabling it completely exposes the user's system to potential threats. A more appropriate step would be to review firewall logs or temporarily create specific rules for VPN traffic, rather than a full disablement.
- ✗
Reinstall the VPN client software
Why it's wrong here
Reinstalling the VPN client software is a drastic and often unnecessary troubleshooting step that should be reserved as a last resort. This action is time-consuming and disruptive, and it fails to address underlying issues such as incorrect user credentials, network configuration problems, or server-side misconfigurations. Without first examining logs to identify the root cause, reinstalling the software is a shot in the dark that often doesn't resolve the actual problem and wastes valuable troubleshooting time.
Quick reference
VPN Protocol Comparison
| Protocol | Port | Encryption | Authentication | Use Case |
|---|---|---|---|---|
| IKEv2 / IPsec | UDP 500 / 4500 | AES-256 | Certificates / PSK | Site-to-site & remote access |
| SSL / TLS VPN | TCP 443 | TLS 1.3 | Certificates / MFA | Clientless remote access |
| L2TP / IPsec | UDP 1701 | AES (IPsec) | PSK / Certificates | Legacy remote access |
| WireGuard | UDP 51820 | ChaCha20 | Public keys | Modern high-performance VPN |
| PPTP | TCP 1723 | MPPE (weak) | MS-CHAPv2 | Legacy — avoid in production |
PPTP is considered insecure. IKEv2/IPsec and SSL VPN are the current recommended options.
Go deeper
Related to this question
About these practice questions
One of 687 original 220-1202 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This 220-1202 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1202 exam.