Courseiva
Networking →mediumMultiple Choice

220-1101 Networking Practice Question

A network administrator recently installed a new firewall to replace an older router. After the installation, users can access the internet but cannot reach internal web servers by hostname (e.g., http://intranet). They can, however, access those servers by IP address. The administrator verifies that the DNS server is functioning and other traffic between the LAN and the internal server VLAN is allowed. What is the MOST likely cause of this issue?

⚠ Common exam trap

Watch out — candidates often assume DNS is working because internet access works, but they fail to distinguish between external DNS resolution (which may use a different DNS server or path) and internal DNS resolution, which requires specific firewall rules for the internal DNS server.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The firewall is blocking DNS traffic (UDP/TCP port 53) between the LAN and the internal DNS server

The firewall is blocking DNS traffic (UDP/TCP port 53) between the LAN and the internal DNS server. Since users can access the internet (external DNS queries likely go through a different path or the firewall allows outbound DNS), but internal hostname resolution fails, the most likely cause is that the firewall's rules are blocking DNS queries to the internal DNS server. This explains why IP-based access works (no DNS needed) while hostname-based access fails.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    The firewall is blocking DNS traffic (UDP/TCP port 53) between the LAN and the internal DNS server

    Why this is correct

    The firewall is correctly identified as the culprit if it is dropping DNS traffic on UDP/TCP port 53 between the LAN and the internal DNS server. Even though users can reach the internet, that traffic may be using a different DNS path (such as a public resolver or cached entries) or the DNS server's own forwarder for external names. Internal hostnames exist only in the internal DNS zone, so blocking 53 prevents the clients' queries from ever reaching that server, making internal resolution fail while external resolution still works. A stateful firewall rule must permit outbound UDP/53 and the corresponding return traffic, and TCP/53 for large responses or zone transfers.

  • ✗

    The VLAN configuration on the switch is preventing hostname resolution

    Why it's wrong here

    VLANs partition the Layer 2 broadcast domain and do not natively filter or block DNS protocol traffic; that function belongs to a Layer 3 device like a firewall or router. If the clients and the internal DNS server are on different VLANs, inter-VLAN routing is needed, but the switch alone cannot prevent DNS resolution unless it is performing layer 3 filtering (a layer 3 switch with ACLs). The symptom is specific to DNS rather than all inter-VLAN traffic, which points to a firewall rule rather than a switch VLAN misconfiguration. Also, a VLAN misconfiguration would typically cause a total loss of connectivity to those subnets, not just hostname lookup failure.

    When this WOULD be correct

    A scenario where users cannot access internal servers by hostname or IP, and the administrator finds that inter-VLAN routing is misconfigured or ACLs on the switch block traffic between VLANs, would make VLAN configuration the correct answer.

  • ✗

    The DHCP server is not assigning the correct DNS server address

    Why it's wrong here

    If DHCP were handing out an incorrect DNS server address, the clients would experience failure for both internal and external hostname resolution because all DNS queries would go to that server. Since users can access the internet, their DNS resolution for public names is functional, indicating that the DHCP-supplied DNS settings are either correct or at least pointing to a working resolver. Furthermore, internal hostname resolution requires the internal DNS server specifically; an incorrect DHCP DNS assignment would not selectively break only internal names while leaving external resolution intact, so this option is contradicted by the reported symptoms.

    When this WOULD be correct

    A scenario where users cannot resolve any hostnames (internal or external) and the administrator finds that the DHCP server is handing out an incorrect or non-existent DNS server address. For example, after a DHCP server migration, the scope option for DNS server points to an old, decommissioned server.

  • ✗

    The default gateway address has been misconfigured on the firewall

    Why it's wrong here

    This cannot be the cause because internet connectivity is working, which proves the firewall's default gateway (default route) is correctly forwarding traffic off the LAN. Internal hostname resolution is a task that stays within the local network or is routed only to the internal DNS server, not through the default gateway to the internet. A misconfigured default gateway would interrupt all traffic to external destinations, not selectively only DNS queries for internal names, so it is ruled out by the given symptoms.

Option-by-option analysis

Why each answer is right or wrong

Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The 220-1101 exam frequently reuses these exact scenarios with slightly different constraints.

✓The firewall is blocking DNS traffic (UDP/TCP port 53) between the LAN and the internal DNS serverCorrect answer▾

Why this is correct

The firewall is correctly identified as the culprit if it is dropping DNS traffic on UDP/TCP port 53 between the LAN and the internal DNS server. Even though users can reach the internet, that traffic may be using a different DNS path (such as a public resolver or cached entries) or the DNS server's own forwarder for external names. Internal hostnames exist only in the internal DNS zone, so blocking 53 prevents the clients' queries from ever reaching that server, making internal resolution fail while external resolution still works. A stateful firewall rule must permit outbound UDP/53 and the corresponding return traffic, and TCP/53 for large responses or zone transfers.

✗The VLAN configuration on the switch is preventing hostname resolutionWrong answer — click to see why▾

Why this is wrong here

The issue is that users can access internal web servers by IP but not by hostname, indicating DNS resolution failure. The VLAN configuration on the switch would not prevent DNS resolution if the DNS server is reachable and other traffic between VLANs is allowed.

★ When this WOULD be the correct answer

A scenario where users cannot access internal servers by hostname or IP, and the administrator finds that inter-VLAN routing is misconfigured or ACLs on the switch block traffic between VLANs, would make VLAN configuration the correct answer.

Why candidates choose this

Candidates may confuse VLAN configuration with DNS resolution, thinking that VLANs affect name resolution, or they may assume that a new firewall installation often involves VLAN changes.

✗The DHCP server is not assigning the correct DNS server addressWrong answer — click to see why▾

Why this is wrong here

The question states the DNS server is functioning and users can access internal servers by IP, indicating DNS resolution is working for some queries. If DHCP assigned an incorrect DNS server, users would likely fail to resolve any hostnames, not just internal ones, and the administrator's verification of DNS server functionality would contradict this.

★ When this WOULD be the correct answer

A scenario where users cannot resolve any hostnames (internal or external) and the administrator finds that the DHCP server is handing out an incorrect or non-existent DNS server address. For example, after a DHCP server migration, the scope option for DNS server points to an old, decommissioned server.

Why candidates choose this

Candidates may assume that DNS issues always stem from misconfiguration of DNS server addresses, overlooking that the problem is specific to internal hostnames and that DNS is verified as functional.

Analysis generated from the official 220-1101blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”

Visual reference

Client Recursive Resolver Root DNS (13 root servers) TLD DNS (.com, .org, …) Authoritative example.com query IP addr answer

About these practice questions

One of 896 original 220-1101 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 220-1101 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1101 exam.