Courseiva
Software Troubleshooting →mediumMultiple Choice

220-1102 Software Troubleshooting Practice Question

A user reports that after installing a new third-party firewall suite, their Windows 10 workstation can no longer connect to the internet. Other computers on the same network are working fine. The technician confirms the third-party firewall is active and has its own filtering. Which of the following should the technician do FIRST to restore internet connectivity?

⚠ Common exam trap

The trap here is that candidates often jump to resetting the TCP/IP stack or disabling the built-in firewall, overlooking that the third-party firewall's outbound rules are the most likely cause and the easiest to verify first.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Check the third-party firewall's outbound filtering rules

The third-party firewall suite is actively filtering traffic, and since other computers on the same network are working, the issue is isolated to this workstation. The most direct and least disruptive first step is to check the third-party firewall's outbound filtering rules, as it may be blocking all outbound connections by default or after installation. This aligns with the CompTIA troubleshooting methodology of checking configuration settings before making changes like uninstalling software or resetting the stack.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Uninstall the third-party firewall suite

    Why it's wrong here

    Uninstalling the third-party suite is premature and overly destructive when troubleshooting a post-install Internet failure. The suite likely has a default-deny outbound policy that simply needs a per-application allow rule, which can be fixed in minutes. Removing the software would strip the system of protections and may also leave behind WFP filters or LSPs, requiring a clean-up. Reconfiguration should be attempted before considering uninstallation.

  • ✗

    Disable Windows Defender Firewall

    Why it's wrong here

    Disabling Windows Defender Firewall is a common but misguided attempt because the third-party suite operates as a separate filtering layer via the Windows Filtering Platform, not as a simple on/off switch controlled by Defender. Even if Defender is disabled, the third-party firewall continues to enforce its own outbound rules, so Internet access remains blocked. Additionally, Windows Security Center may show the third-party firewall as the active firewall, making Defender's state irrelevant to the problem at hand.

  • ✓

    Check the third-party firewall's outbound filtering rules

    Why this is correct

    When a third-party firewall is installed, it often enables a 'block all' outbound policy until the user explicitly allows traffic, so the correct first step is to open its console and review the outbound filtering rules. Look for the default action (usually 'deny') and check program-specific rules for the browser, DNS client, or svchost.exe; either switch the default action to 'ask' or add an allow rule for the needed applications. This directly addresses the root cause, unlike resetting the stack or uninstalling, and keeps the suite's protection intact.

  • ✗

    Reset the TCP/IP stack using netsh commands

    Why it's wrong here

    Resetting the TCP/IP stack with netsh int ip reset is intended for corruption in the TCP/IP protocol driver, not for policy-based blocks introduced by a firewall installation. The inability to reach the Internet after installing a third-party firewall is caused by the firewall's packet filtering dropping outbound frames, not by a misconfigured route or invalid sockets. Running this command will not modify the firewall's rule set and will likely require a reboot, wasting time while the block persists.

Visual reference

Source Router + ACL permit 10.0.0.0/8 deny any Server 10.0.0.5 ✓ 192.168.1.1 ✗ dropped ACLs evaluate top-down; first match wins — implicit deny all at end

About these practice questions

This 220-1102 question is part of Courseiva's 925-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.