220-1101 Networking Practice Question
A network administrator configures a router with VLANs. Devices on VLAN 10 can successfully ping a web server (IP 192.168.20.10) on VLAN 20. However, when users on VLAN 10 attempt to access the web server via a browser using its IP address, the connection times out. The router's ACLs permit ICMP and TCP/80 traffic between VLANs. Which of the following should the administrator check NEXT?
⚠ Common exam trap
CompTIA often tests the distinction between network-layer reachability (ICMP) and application-layer access (TCP/80), leading candidates to incorrectly suspect router ACLs or DNS when the real issue is a host-based firewall blocking the specific service port.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Check if the web server's host firewall is blocking HTTP traffic
Since ICMP (ping) succeeds and the router's ACLs explicitly permit TCP/80, the issue is likely at the web server itself. The server's host firewall (e.g., Windows Defender Firewall, iptables) may be blocking inbound HTTP traffic while allowing ICMP, causing the browser connection to time out. This is the next logical check because the network path is verified working for ICMP and the ACL is confirmed permissive for TCP/80.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Verify the DHCP address assignment on VLAN 20
Why it's wrong here
The web server has a static IP address, 192.168.20.10, so a DHCP failure or incorrectly configured scope on VLAN 20 would have no impact on the server's IP settings. Successful ping also proves the server's IP, netmask, and default gateway are correctly assigned; if DHCP had issued an incorrect gateway, traffic wouldn't route back and even ping would fail. Additionally, DHCP issues would affect all hosts on VLAN 20, not selectively block ONLY HTTP while leaving ICMP working.
When this WOULD be correct
This would be correct if users on VLAN 10 could not reach the web server at all (no ping, no HTTP), and the web server was configured to obtain an IP via DHCP. The administrator would then check if the DHCP server on VLAN 20 is functioning and assigning correct addresses.
- ✓
Check if the web server's host firewall is blocking HTTP traffic
Why this is correct
A host firewall filters at the transport/application layer and can selectively permit ICMP echo requests (Layer 3) while dropping inbound TCP SYN packets to port 80. If the server's firewall zone or profile allows ping but not HTTP, the client's ping succeeds yet the TCP handshake times out, exactly matching the reported symptom. This should be the first check because routing and VLAN ACLs are already proven functional—ICMP traffic from VLAN 10 reaches the server and returns.
- ✗
Review the router's ACLs for any implicit deny rules
Why it's wrong here
The scenario explicitly states that the router ACLs contain permit statements for both ICMP and HTTP from VLAN 10 to the server, so an implicit deny at the end of the ACL wouldn't block either protocol. Moreover, because ping (an ICMP echo request) succeeds, the router is forwarding traffic and the ACL has a matching permit entry for ICMP; a separate implicit deny for HTTP would be contradictory unless the ACL is misordered, but the question indicates it is correctly configured. Reviewing ACLs would not explain why one Layer 3 protocol is permitted while a Layer 4 TCP port is selectively blocked.
- ✗
Confirm that DNS resolution for the web server's hostname is correct
Why it's wrong here
DNS is used only for translating a hostname to an IP address; the problem states users access the web server by its static IP 192.168.20.10, so no DNS query is performed. If DNS were misconfigured, ping to that IP would still work and HTTP to that IP would still function, unless the server's virtual host configuration requires a specific Host header, which is not implied here. Therefore confirming DNS resolution is irrelevant to this specific symptom of web access timing out while ping succeeds.
When this WOULD be correct
A user reports being unable to access a website by its domain name (e.g., www.example.com) but can access it by IP address. The administrator should then check DNS resolution to ensure the hostname resolves correctly.
Option-by-option analysis
Why each answer is right or wrong
Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The 220-1101 exam frequently reuses these exact scenarios with slightly different constraints.
✓Check if the web server's host firewall is blocking HTTP trafficCorrect answer▾
Why this is correct
A host firewall filters at the transport/application layer and can selectively permit ICMP echo requests (Layer 3) while dropping inbound TCP SYN packets to port 80. If the server's firewall zone or profile allows ping but not HTTP, the client's ping succeeds yet the TCP handshake times out, exactly matching the reported symptom. This should be the first check because routing and VLAN ACLs are already proven functional—ICMP traffic from VLAN 10 reaches the server and returns.
✗Verify the DHCP address assignment on VLAN 20Wrong answer — click to see why▾
Why this is wrong here
The issue is that HTTP (TCP/80) traffic fails while ICMP succeeds, indicating a problem specific to port 80, not DHCP. DHCP assigns IP addresses, but the web server already has a static IP (192.168.20.10) and is reachable via ping, so DHCP on VLAN 20 is irrelevant.
★ When this WOULD be the correct answer
This would be correct if users on VLAN 10 could not reach the web server at all (no ping, no HTTP), and the web server was configured to obtain an IP via DHCP. The administrator would then check if the DHCP server on VLAN 20 is functioning and assigning correct addresses.
Why candidates choose this
Candidates may think that if the web server's IP is not properly assigned, connectivity would fail. However, the server's IP is static and ping works, so DHCP is not the issue.
✗Confirm that DNS resolution for the web server's hostname is correctWrong answer — click to see why▾
Why this is wrong here
The question states that users can ping the web server successfully, which confirms IP connectivity. DNS resolution is irrelevant because users are accessing the server via its IP address, not a hostname.
★ When this WOULD be the correct answer
A user reports being unable to access a website by its domain name (e.g., www.example.com) but can access it by IP address. The administrator should then check DNS resolution to ensure the hostname resolves correctly.
Why candidates choose this
Candidates often associate web access issues with DNS, forgetting that the scenario explicitly uses IP address access, making DNS irrelevant.
Analysis generated from the official 220-1101blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”
Visual reference
Go deeper
Related to this question
About these practice questions
This 220-1101 question is part of Courseiva's 896-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 220-1101 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1101 exam.