220-1101 Networking Practice Question
A network technician is troubleshooting a connectivity issue. Users on VLAN 10 (192.168.10.0/24) can access the internet but cannot reach a server on VLAN 20 (192.168.20.0/24) by IP address. The router's ACL allows all traffic between VLANs. The technician pings the server IP from a client on VLAN 10 and gets a request timed out. The technician then checks the routing table on the router and sees routes for both VLANs. Which of the following is the NEXT step to isolate the issue?
⚠ Common exam trap
Candidates often assume the problem is at Layer 2 (VLAN membership) or Layer 3 (default gateway) because those are common causes, but the given information (working internet, correct routes, permissive ACL) points to a path or filtering issue that traceroute is designed to diagnose.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Perform a traceroute from the client to the server.
A traceroute (using ICMP or UDP probes with increasing TTL values) will reveal the path packets take from the client to the server. Since the router's ACL permits all inter-VLAN traffic and routes exist for both VLANs, the issue likely lies beyond Layer 3 routing—possibly at a firewall, a misconfigured switch port, or a routing loop. Traceroute isolates exactly where packets are dropped, narrowing the troubleshooting scope.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Check the server's firewall settings.
Why it's wrong here
A server firewall may be discarding incoming packets, but it only becomes a suspect after traffic has successfully arrived at the server's network stack. Running traceroute first can show whether packets even reach the server's subnet or whether they are dropped before arriving; if the trace stops at the server's IP address, firewall rules then become a plausible cause. However, that conclusion requires path data to be gathered first—blindly inspecting firewall rules without such evidence could waste time if the real problem is a routed black hole.
When this WOULD be correct
In a scenario where a client on one VLAN can ping the server's IP but cannot access a specific service (e.g., HTTP), and the router's ACL is not the issue, checking the server's firewall would be the next step to see if it's blocking the service port.
- ✗
Check the switch port for the server is in the correct VLAN.
Why it's wrong here
An incorrect VLAN assignment on the server's switch port could indeed prevent network communication, but it is only one of several possible causes. A traceroute that stops at the switch or shows no response beyond it would specifically implicate Layer 2 forwarding, yet without that evidence you cannot reasonably assume the VLAN is at fault. The systematic approach is to trace the path first, then inspect the switch configuration if the trace indicates a local link-layer failure.
When this WOULD be correct
If the router's routing table did not show a route for VLAN 20, or if the server was unreachable from other devices on the same VLAN, checking the switch port VLAN assignment would be the correct next step to ensure the server is in the correct VLAN.
- ✓
Perform a traceroute from the client to the server.
Why this is correct
Performing a traceroute from the client to the server sends ICMP Echo Request packets with incrementing Time-to-Live values, causing each router along the path to return an ICMP Time Exceeded message. This maps the exact route and reveals the last hop that responded, isolating whether the failure occurs on the local network, an intermediate router, or at the destination itself. Traceroute is the most efficient first diagnostic because it narrows the fault domain before further testing.
- ✗
Check the default gateway on the client.
Why it's wrong here
Because the client can already reach the internet, its default gateway is functioning correctly and is not the source of the client-to-server failure. Checking the default gateway would merely repeat a basic connectivity verification that has already passed, and it does not distinguish between problems on the LAN, WAN, or server subnet. The diagnostic focus should be on the path and reachability of the server, not on an already-confirmed-valid default gateway.
When this WOULD be correct
When a client cannot access any external network (e.g., internet) but other devices on the same VLAN can, checking the client's default gateway is the next step to isolate a misconfigured gateway address.
Option-by-option analysis
Why each answer is right or wrong
Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The 220-1101 exam frequently reuses these exact scenarios with slightly different constraints.
✓Perform a traceroute from the client to the server.Correct answer▾
Why this is correct
Performing a traceroute from the client to the server sends ICMP Echo Request packets with incrementing Time-to-Live values, causing each router along the path to return an ICMP Time Exceeded message. This maps the exact route and reveals the last hop that responded, isolating whether the failure occurs on the local network, an intermediate router, or at the destination itself. Traceroute is the most efficient first diagnostic because it narrows the fault domain before further testing.
✗Check the server's firewall settings.Wrong answer — click to see why▾
Why this is wrong here
The question states that the router's ACL allows all traffic between VLANs, so the issue is not with the server's firewall. The problem is likely a routing or path issue, not a server-side block.
★ When this WOULD be the correct answer
In a scenario where a client on one VLAN can ping the server's IP but cannot access a specific service (e.g., HTTP), and the router's ACL is not the issue, checking the server's firewall would be the next step to see if it's blocking the service port.
Why candidates choose this
Candidates often assume that a firewall on the server could be blocking traffic, but the question specifies that the ACL allows all traffic and the ping fails, indicating a network layer issue rather than a server-side filter.
✗Check the switch port for the server is in the correct VLAN.Wrong answer — click to see why▾
Why this is wrong here
The server's VLAN membership is already verified by the routing table showing routes for both VLANs, and the ACL allows all traffic. The issue is likely a routing problem between VLANs, not a switch port misconfiguration.
★ When this WOULD be the correct answer
If the router's routing table did not show a route for VLAN 20, or if the server was unreachable from other devices on the same VLAN, checking the switch port VLAN assignment would be the correct next step to ensure the server is in the correct VLAN.
Why candidates choose this
Candidates often assume that VLAN misconfiguration is a common cause of inter-VLAN connectivity issues, but here the routing table confirms VLANs are configured, so the problem lies elsewhere.
✗Check the default gateway on the client.Wrong answer — click to see why▾
Why this is wrong here
The client can access the internet, so its default gateway is correctly configured. The issue is between VLANs, not at the client's gateway.
★ When this WOULD be the correct answer
When a client cannot access any external network (e.g., internet) but other devices on the same VLAN can, checking the client's default gateway is the next step to isolate a misconfigured gateway address.
Why candidates choose this
Candidates often assume that any connectivity failure is due to a misconfigured default gateway, overlooking that internet access confirms the gateway is working.
Analysis generated from the official 220-1101blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”
Visual reference
Go deeper
Related to this question
About these practice questions
Courseiva writes every 220-1101 question from scratch — 896 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 220-1101 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1101 exam.