220-1101 Networking Practice Question
A network administrator recently installed a new firewall to replace an older router. After the installation, users can access the internet but cannot reach internal web servers by hostname (e.g., http://intranet). They can, however, access those servers by IP address. The administrator verifies that the DNS server is functioning and other traffic between the LAN and the internal server VLAN is allowed. What is the MOST likely cause of this issue?
⚠ Common exam trap
Watch out — candidates often assume DNS is working because internet access works, but they fail to distinguish between external DNS resolution (which may use a different DNS server or path) and internal DNS resolution, which requires specific firewall rules for the internal DNS server.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The firewall is blocking DNS traffic (UDP/TCP port 53) between the LAN and the internal DNS server
The firewall is blocking DNS traffic (UDP/TCP port 53) between the LAN and the internal DNS server. Since users can access the internet (external DNS queries likely go through a different path or the firewall allows outbound DNS), but internal hostname resolution fails, the most likely cause is that the firewall's rules are blocking DNS queries to the internal DNS server. This explains why IP-based access works (no DNS needed) while hostname-based access fails.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
The firewall is blocking DNS traffic (UDP/TCP port 53) between the LAN and the internal DNS server
Why this is correct
The firewall is correctly identified as the culprit if it is dropping DNS traffic on UDP/TCP port 53 between the LAN and the internal DNS server. Even though users can reach the internet, that traffic may be using a different DNS path (such as a public resolver or cached entries) or the DNS server's own forwarder for external names. Internal hostnames exist only in the internal DNS zone, so blocking 53 prevents the clients' queries from ever reaching that server, making internal resolution fail while external resolution still works. A stateful firewall rule must permit outbound UDP/53 and the corresponding return traffic, and TCP/53 for large responses or zone transfers.
- ✗
The VLAN configuration on the switch is preventing hostname resolution
Why it's wrong here
VLANs partition the Layer 2 broadcast domain and do not natively filter or block DNS protocol traffic; that function belongs to a Layer 3 device like a firewall or router. If the clients and the internal DNS server are on different VLANs, inter-VLAN routing is needed, but the switch alone cannot prevent DNS resolution unless it is performing layer 3 filtering (a layer 3 switch with ACLs). The symptom is specific to DNS rather than all inter-VLAN traffic, which points to a firewall rule rather than a switch VLAN misconfiguration. Also, a VLAN misconfiguration would typically cause a total loss of connectivity to those subnets, not just hostname lookup failure.
When this WOULD be correct
A scenario where users cannot access internal servers by hostname or IP, and the administrator finds that inter-VLAN routing is misconfigured or ACLs on the switch block traffic between VLANs, would make VLAN configuration the correct answer.
- ✗
The DHCP server is not assigning the correct DNS server address
Why it's wrong here
If DHCP were handing out an incorrect DNS server address, the clients would experience failure for both internal and external hostname resolution because all DNS queries would go to that server. Since users can access the internet, their DNS resolution for public names is functional, indicating that the DHCP-supplied DNS settings are either correct or at least pointing to a working resolver. Furthermore, internal hostname resolution requires the internal DNS server specifically; an incorrect DHCP DNS assignment would not selectively break only internal names while leaving external resolution intact, so this option is contradicted by the reported symptoms.
When this WOULD be correct
A scenario where users cannot resolve any hostnames (internal or external) and the administrator finds that the DHCP server is handing out an incorrect or non-existent DNS server address. For example, after a DHCP server migration, the scope option for DNS server points to an old, decommissioned server.
- ✗
The default gateway address has been misconfigured on the firewall
Why it's wrong here
This cannot be the cause because internet connectivity is working, which proves the firewall's default gateway (default route) is correctly forwarding traffic off the LAN. Internal hostname resolution is a task that stays within the local network or is routed only to the internal DNS server, not through the default gateway to the internet. A misconfigured default gateway would interrupt all traffic to external destinations, not selectively only DNS queries for internal names, so it is ruled out by the given symptoms.
Option-by-option analysis
Why each answer is right or wrong
Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The 220-1101 exam frequently reuses these exact scenarios with slightly different constraints.
✓The firewall is blocking DNS traffic (UDP/TCP port 53) between the LAN and the internal DNS serverCorrect answer▾
Why this is correct
The firewall is correctly identified as the culprit if it is dropping DNS traffic on UDP/TCP port 53 between the LAN and the internal DNS server. Even though users can reach the internet, that traffic may be using a different DNS path (such as a public resolver or cached entries) or the DNS server's own forwarder for external names. Internal hostnames exist only in the internal DNS zone, so blocking 53 prevents the clients' queries from ever reaching that server, making internal resolution fail while external resolution still works. A stateful firewall rule must permit outbound UDP/53 and the corresponding return traffic, and TCP/53 for large responses or zone transfers.
✗The VLAN configuration on the switch is preventing hostname resolutionWrong answer — click to see why▾
Why this is wrong here
The issue is that users can access internal web servers by IP but not by hostname, indicating DNS resolution failure. The VLAN configuration on the switch would not prevent DNS resolution if the DNS server is reachable and other traffic between VLANs is allowed.
★ When this WOULD be the correct answer
A scenario where users cannot access internal servers by hostname or IP, and the administrator finds that inter-VLAN routing is misconfigured or ACLs on the switch block traffic between VLANs, would make VLAN configuration the correct answer.
Why candidates choose this
Candidates may confuse VLAN configuration with DNS resolution, thinking that VLANs affect name resolution, or they may assume that a new firewall installation often involves VLAN changes.
✗The DHCP server is not assigning the correct DNS server addressWrong answer — click to see why▾
Why this is wrong here
The question states the DNS server is functioning and users can access internal servers by IP, indicating DNS resolution is working for some queries. If DHCP assigned an incorrect DNS server, users would likely fail to resolve any hostnames, not just internal ones, and the administrator's verification of DNS server functionality would contradict this.
★ When this WOULD be the correct answer
A scenario where users cannot resolve any hostnames (internal or external) and the administrator finds that the DHCP server is handing out an incorrect or non-existent DNS server address. For example, after a DHCP server migration, the scope option for DNS server points to an old, decommissioned server.
Why candidates choose this
Candidates may assume that DNS issues always stem from misconfiguration of DNS server addresses, overlooking that the problem is specific to internal hostnames and that DNS is verified as functional.
Analysis generated from the official 220-1101blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”
Visual reference
Go deeper
Related to this question
Learn chapter
Internet Connection Types
Key term
User Datagram Protocol
User Datagram Protocol (UDP) is a fast, connectionless network protocol that sends data without first checking if the receiver is ready or if the data arrived safely.
Key term
TCP
TCP is a connection-oriented transport layer protocol that ensures reliable, ordered, and error-checked delivery of data between applications over IP networks.
About these practice questions
One of 896 original 220-1101 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 220-1101 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1101 exam.