Courseiva
Software Troubleshooting →mediumMultiple Choice

220-1102 Software Troubleshooting Practice Question

A user reports that after installing a third-party antivirus suite, their web browser cannot connect to the internet. Other network-dependent applications such as email clients work correctly. The technician has confirmed that the network adapter is configured correctly and other devices on the same network can access the internet. Which built-in Windows tool should the technician use FIRST to investigate whether the antivirus software has created firewall rules that are blocking the browser?

⚠ Common exam trap

Many candidates assume the issue is a corrupted browser or DNS problem, but the question specifically isolates the problem to firewall rules created by the antivirus, making wf.msc the targeted first tool.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Windows Defender Firewall with Advanced Security (wf.msc)

The Windows Defender Firewall with Advanced Security (wf.msc) allows the technician to inspect and manage all firewall rules, including those created by third-party applications. Since the issue is isolated to the web browser while other network apps work, the most likely cause is a specific outbound or inbound rule blocking browser traffic. This tool provides granular filtering by program, port, or protocol, making it the correct first step to identify if the antivirus suite added a restrictive rule.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Windows Defender Firewall with Advanced Security (wf.msc)

    Why this is correct

    Windows Defender Firewall with Advanced Security (wf.msc) is the MMC snap-in that exposes granular inbound and outbound firewall rules, each tied to a specific program, port, or service and assigned to a network profile (Domain, Private, Public). Third-party antivirus suites commonly register their own filtering rules here via the Windows Filtering Platform, so a technician can inspect rule properties, locate blocking actions for the browser's executable path, and enable or disable offending rules. Additionally, the Monitoring section displays active connections and allows verification of firewall behavior in real time.

  • ✗

    Services console (services.msc)

    Why it's wrong here

    The Services console (services.msc) manages Windows services—their startup type, status, logon account, and recovery actions. Although a third-party antivirus may install a firewall-related service (for example, an antimalware engine or network filter driver), this console only controls the service lifecycle; it does not display or modify the individual filtering rules those services enforce. Therefore, it would not show why a specific browser is being blocked by an inbound or outbound firewall rule.

  • ✗

    Resource Monitor (resmon.exe)

    Why it's wrong here

    Resource Monitor (resmon.exe) provides a real-time dashboard of CPU, memory, disk, and network activity, including per-process network I/O and active TCP connections. While its Network tab can show whether a browser process is generating traffic, it does not enumerate firewall filter rules or indicate whether the Windows Filtering Platform is dropping packets for that process. Thus, it cannot reveal a third-party antivirus rule that is silently blocking the browser.

  • ✗

    Network and Sharing Center

    Why it's wrong here

    Network and Sharing Center offers a high-level view of network connectivity, such as active networks, link speed, IPv4/IPv6 addresses, and access to troubleshooters like Internet Connections or Network Adapter. In Windows 10/11 it provides a 'Windows Firewall' link only to the legacy firewall status page, not the advanced rule repository. It lacks the ability to inspect, filter, or manage specific firewall rules, so it cannot assist in diagnosing a program-specific block imposed by third-party software.

Visual reference

Source Router + ACL permit 10.0.0.0/8 deny any Server 10.0.0.5 ✓ 192.168.1.1 ✗ dropped ACLs evaluate top-down; first match wins — implicit deny all at end

About these practice questions

Courseiva writes every 220-1102 question from scratch — 925 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.