Courseiva
easyMultiple Choice

220-1201 Practice Question: A technician is setting up a virtualized test…

A technician is setting up a virtualized test environment where each virtual machine must have a unique MAC address and IP address, and the VMs must be able to communicate with each other and the physical network. The host has only one physical NIC. Which virtual switch configuration should the technician use?

⚠ Common exam trap

The trap is choosing NAT because it 'provides internet access,' but NAT hides VMs behind the host IP and prevents inbound connections — only bridged mode gives each VM a unique identity on the physical LAN.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Bridged (external) virtual switch

A bridged (external) virtual switch binds the virtual switch to the host's physical NIC, allowing VMs to obtain unique MAC and IP addresses from the physical network's DHCP and communicate with both each other and external hosts. This is the only configuration that provides full connectivity to the physical LAN while giving each VM its own network identity.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Internal virtual switch

    Why it's wrong here

    An internal virtual switch facilitates communication exclusively between virtual machines (VMs) and the host operating system. While VMs can communicate with each other and the host, this configuration intentionally prevents any direct access to the physical network or external internet. This isolation makes it unsuitable for a test environment that requires VMs to interact with external network resources or the internet.

  • ✗

    Private virtual switch

    Why it's wrong here

    A private virtual switch creates a completely isolated network segment where virtual machines (VMs) can communicate only with each other. This configuration strictly prevents any communication between the VMs and the host operating system, as well as any access to the physical network or the internet. Such extreme isolation is inappropriate for a test environment that likely needs to simulate real-world network interactions, including external connectivity.

  • ✓

    Bridged (external) virtual switch

    Why this is correct

    A bridged (external) virtual switch directly connects virtual machines (VMs) to the physical network adapter of the host computer. Each VM configured with a bridged connection receives its own unique MAC address and obtains an IP address from the physical network's DHCP server, appearing as a distinct, independent device on the physical network. This setup provides full, bidirectional network access to external resources and the internet, making it ideal for a test environment requiring realistic network interaction.

  • ✗

    NAT virtual switch

    Why it's wrong here

    A NAT (Network Address Translation) virtual switch allows virtual machines (VMs) to access external networks by sharing the host's IP address. VMs are placed on a private internal network, and the host performs NAT to translate their private IP addresses for outbound traffic. While VMs can initiate connections to the internet, direct inbound connections from the external network to the VMs are generally blocked or require complex port forwarding, which limits the flexibility needed for a comprehensive test environment.

Visual reference

Client DHCP Server 1 Discover (broadcast) 2 Offer (IP: 192.168.1.10) 3 Request (I accept) 4 Acknowledge (lease confirmed) DORA — the four-step DHCP lease process

Quick reference

Access Control Model Comparison

ModelAcronymWho Controls Access?Best For
Discretionary Access ControlDACResource ownerSmall teams, file shares
Mandatory Access ControlMACSystem / security labelsClassified govt / military
Role-Based Access ControlRBACAdministrator (via roles)Enterprise environments
Attribute-Based Access ControlABACPolicy engine (user + resource attributes)Fine-grained, dynamic policies
Rule-Based Access ControlRuBACSystem rules / ACLsFirewall rules, network ACLs

About these practice questions

Courseiva writes every 220-1201 question from scratch — 871 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This 220-1201 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1201 exam.