Courseiva
Networking →mediumMultiple Choice

220-1101 Networking Practice Question

A user reports that they can access internal company servers by IP address and hostname, but cannot browse the internet. The user can ping the default gateway (192.168.1.1) successfully. Other users on the same subnet have full internet access. The technician checks the user's IP configuration and sees that the IP address, subnet mask, default gateway, and DNS server (192.168.1.10) are all correct. Which of the following should the technician check NEXT?

⚠ Common exam trap

CompTIA often tests the concept that successful ping to the default gateway and correct IP configuration do not guarantee internet access, and candidates mistakenly focus on DHCP or gateway issues instead of application-layer settings like proxy configuration.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Check the browser's proxy settings

Since the user can access internal resources by hostname (indicating DNS resolution works for internal names) and can ping the default gateway, the issue is isolated to internet-bound traffic. The most likely cause is that the browser is configured to use a proxy server that is unreachable or misconfigured, which would prevent internet access while leaving local network connectivity intact. Checking the browser's proxy settings is the logical next step because the user's IP configuration is correct and other users on the same subnet have full internet access.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Check the browser's proxy settings

    Why this is correct

    A proxy configured in the browser intercepts HTTP/HTTPS requests and forwards them through the specified server. If that proxy is an internal server with no outbound internet route—or is simply unreachable—requests to external domains fail, yet direct access to internal IP addresses (which bypasses the proxy) remains functional. Since the issue is isolated to the user's browsing and internal IP access works, inspecting the browser's proxy settings (including any PAC file or system-level proxy) is the correct next step.

  • ✗

    Check the default gateway

    Why it's wrong here

    The default gateway is the router interface that forwards packets to destinations outside the local network. The user successfully pings the gateway, proving Layer 3 connectivity to that router; if the gateway were wrong, the ping would fail or the interface would be unreachable. Furthermore, an incorrect or down gateway would prevent access to both external and remote internal networks, not specifically internet websites, while direct internal server access would still work only if on the same subnet. Therefore re-checking the gateway is redundant.

    When this WOULD be correct

    A user cannot access any network resources (internal or external) and cannot ping the default gateway. The technician would then check the default gateway configuration or its status.

  • ✗

    Check the DHCP lease status

    Why it's wrong here

    The DHCP lease determines the client's IPv4 address, mask, gateway, and DNS servers. If the lease were expired, conflicted, or misassigned, the user would typically see an APIPA address (169.254.x.x) or an incorrect gateway, causing total loss of connectivity beyond the local subnet. Because the user has a valid IP configuration, can ping the gateway, and reaches internal servers by IP, the lease is not the culprit; a DHCP fault would also likely affect other clients on the same broadcast domain.

    When this WOULD be correct

    A user cannot access network resources and has an IP address starting with 169.254.x.x (APIPA) or an incorrect IP. The technician should check the DHCP lease status to see if the client received a valid lease.

  • ✗

    Check the switch port security settings

    Why it's wrong here

    Switch port security works by restricting the number of MAC addresses or locking a port to a specific MAC; a violation triggers an error-disabled state or frame filtering that halts all traffic on that port. Since the user's client can still communicate with internal servers and the gateway, the port is forwarding normal traffic, so the switch has not blocked the client. Port security operates at Layer 2 and cannot selectively block outbound internet HTTP/HTTPS while permitting internal IP traffic, so it is not a plausible cause.

    When this WOULD be correct

    A technician would check switch port security when a user cannot access any network resources (neither internal nor external) while other users on the same switch can, and the port shows err-disable or security violations.

Option-by-option analysis

Why each answer is right or wrong

Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The 220-1101 exam frequently reuses these exact scenarios with slightly different constraints.

✓Check the browser's proxy settingsCorrect answer▾

Why this is correct

A proxy configured in the browser intercepts HTTP/HTTPS requests and forwards them through the specified server. If that proxy is an internal server with no outbound internet route—or is simply unreachable—requests to external domains fail, yet direct access to internal IP addresses (which bypasses the proxy) remains functional. Since the issue is isolated to the user's browsing and internal IP access works, inspecting the browser's proxy settings (including any PAC file or system-level proxy) is the correct next step.

✗Check the default gatewayWrong answer — click to see why▾

Why this is wrong here

The user can ping the default gateway successfully, indicating the gateway is reachable and functioning. The issue is internet access, not local connectivity, so checking the gateway again is unnecessary.

★ When this WOULD be the correct answer

A user cannot access any network resources (internal or external) and cannot ping the default gateway. The technician would then check the default gateway configuration or its status.

Why candidates choose this

Candidates may assume internet issues are always gateway-related, overlooking that successful ping to the gateway rules out that problem.

✗Check the DHCP lease statusWrong answer — click to see why▾

Why this is wrong here

The user's IP configuration is correct, and other users on the same subnet have internet access, so DHCP is functioning properly. The issue is isolated to this user, not a DHCP lease problem.

★ When this WOULD be the correct answer

A user cannot access network resources and has an IP address starting with 169.254.x.x (APIPA) or an incorrect IP. The technician should check the DHCP lease status to see if the client received a valid lease.

Why candidates choose this

Candidates may think internet access failure is due to DHCP issues, but the user has a correct IP and gateway, ruling out DHCP problems.

✗Check the switch port security settingsWrong answer — click to see why▾

Why this is wrong here

The user can access internal servers by hostname, indicating DNS resolution works. The issue is internet access only, and other users on the same subnet have full access, so switch port security is not the cause.

★ When this WOULD be the correct answer

A technician would check switch port security when a user cannot access any network resources (neither internal nor external) while other users on the same switch can, and the port shows err-disable or security violations.

Why candidates choose this

Candidates may think port security could block internet traffic, but it typically blocks all traffic based on MAC address, not selectively internet-only.

Analysis generated from the official 220-1101blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”

Visual reference

Client Recursive Resolver Root DNS (13 root servers) TLD DNS (.com, .org, …) Authoritative example.com query IP addr answer

Quick reference

IPv4 Address Class Summary

ClassFirst Octet RangeDefault MaskNetworksHosts per Network
A1–126/8 (255.0.0.0)12616,777,214
B128–191/16 (255.255.0.0)16,38465,534
C192–223/24 (255.255.255.0)2,097,152254
D224–239N/AMulticast groups—
E240–255N/AReserved / experimental—

127.x.x.x is reserved for loopback. Modern networks use CIDR (classless) rather than classful addressing.

About these practice questions

One of 896 original 220-1101 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 220-1101 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1101 exam.