Courseiva
Networking →hardMultiple Choice

220-1101 Networking Practice Question

A network technician is troubleshooting inter-VLAN routing. Clients on VLAN 10 (192.168.10.0/24) cannot communicate with servers on VLAN 20 (192.168.20.0/24). The router has subinterfaces for both VLANs and is connected to a layer 2 switch. The switch port connecting to the router is configured as an access port in VLAN 10. An ACL on the router is configured to permit all traffic between the VLANs. Which of the following is the MOST likely cause of the issue?

⚠ Common exam trap

CompTIA often tests the concept that a router-on-a-stick requires a trunk link between the router and switch, and candidates mistakenly think an access port can carry multiple VLANs or that an ACL is the default culprit.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The switch port is not configured as a trunk

The switch port connecting to the router is configured as an access port in VLAN 10, which means it can only carry traffic for VLAN 10. For inter-VLAN routing, the router's subinterfaces need to receive frames tagged with their respective VLAN IDs. A trunk port (802.1Q) must be used on the switch side to allow both VLAN 10 and VLAN 20 traffic to reach the router. Without a trunk, frames from VLAN 20 are dropped at the switch port, preventing communication.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The ACL on the router is misconfigured

    Why it's wrong here

    The trouble is that the router is not receiving packets from VLAN 20 at all, so a router ACL cannot be the root cause. Even a misconfigured ACL only filters traffic after the router has already received and routed it, and the note states the ACL is set to permit all traffic. If an ACL were blocking, you would see packets arriving at the router but being dropped; here the failure occurs at Layer 2 on the switch, before the router ever sees the frames.

    When this WOULD be correct

    In a scenario where inter-VLAN routing fails and the ACL is configured to deny traffic by default or has a specific deny statement blocking the required traffic, then a misconfigured ACL would be the most likely cause.

  • ✓

    The switch port is not configured as a trunk

    Why this is correct

    Router-on-a-stick requires the switch port facing the router to be configured as an 802.1Q trunk, carrying tagged frames for both VLANs. On an access port, only the assigned VLAN's untagged traffic is sent toward the router, so frames from VLAN 20 are never delivered to the router. This precisely matches the symptom where the router receives packets from VLAN 10 but never from VLAN 20, even though devices in both VLANs have connectivity.

  • ✗

    The default gateway on the servers is set incorrectly

    Why it's wrong here

    An incorrect default gateway on the servers would prevent the servers from sending replies back to clients in VLAN 10, but it would not stop the clients' frames from reaching the router. The reported issue is that the router receives traffic from VLAN 10 but not from VLAN 20, indicating the missing traffic is the client-to-server request path, not the server's return path. Since the failure is on ingress from VLAN 20, the problem lies in the switch's port configuration, not server settings.

    When this WOULD be correct

    In a scenario where clients on VLAN 10 can ping the router's VLAN 10 interface but cannot reach servers on VLAN 20, and the router's ACL permits all traffic, the servers' default gateway might be misconfigured (e.g., pointing to the wrong router interface or an incorrect IP).

  • ✗

    VLAN 20 is not defined on the switch

    Why it's wrong here

    If VLAN 20 were not defined on the switch, the ports assigned to it would not be in an operational state and the servers would have no link or connectivity at all. The scenario indicates that servers exist on VLAN 20 and presumably have basic network access, so the VLAN must be defined and active. This option cannot explain why the router receives VLAN 10 frames but not VLAN 20 frames, because VLAN 20 must already exist for the servers to communicate at all.

    When this WOULD be correct

    In a scenario where a router-on-a-stick is used and the switch does not have VLAN 20 defined, hosts on VLAN 20 would be unable to communicate with any other VLAN because the switch would drop frames tagged with VLAN 20. For example, if clients on VLAN 20 cannot ping the router's subinterface for VLAN 20, the cause could be that VLAN 20 is not created on the switch.

Option-by-option analysis

Why each answer is right or wrong

Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The 220-1101 exam frequently reuses these exact scenarios with slightly different constraints.

✓The switch port is not configured as a trunkCorrect answer▾

Why this is correct

Router-on-a-stick requires the switch port facing the router to be configured as an 802.1Q trunk, carrying tagged frames for both VLANs. On an access port, only the assigned VLAN's untagged traffic is sent toward the router, so frames from VLAN 20 are never delivered to the router. This precisely matches the symptom where the router receives packets from VLAN 10 but never from VLAN 20, even though devices in both VLANs have connectivity.

✗The ACL on the router is misconfiguredWrong answer — click to see why▾

Why this is wrong here

The ACL is configured to permit all traffic between VLANs, so it is not blocking communication. The issue is that the switch port connecting to the router is an access port in VLAN 10, which prevents VLAN 20 traffic from reaching the router's subinterface.

★ When this WOULD be the correct answer

In a scenario where inter-VLAN routing fails and the ACL is configured to deny traffic by default or has a specific deny statement blocking the required traffic, then a misconfigured ACL would be the most likely cause.

Why candidates choose this

Candidates often assume that ACLs are the default culprit for traffic filtering issues, overlooking Layer 2 configuration problems like trunking.

✗The default gateway on the servers is set incorrectlyWrong answer — click to see why▾

Why this is wrong here

The servers are on VLAN 20, and their default gateway should be the router's subinterface for VLAN 20. The issue is that the switch port to the router is an access port in VLAN 10, preventing VLAN 20 traffic from reaching the router. The default gateway setting is irrelevant because the traffic never reaches the router.

★ When this WOULD be the correct answer

In a scenario where clients on VLAN 10 can ping the router's VLAN 10 interface but cannot reach servers on VLAN 20, and the router's ACL permits all traffic, the servers' default gateway might be misconfigured (e.g., pointing to the wrong router interface or an incorrect IP).

Why candidates choose this

Candidates often assume that inter-VLAN routing issues are due to IP configuration errors like default gateways, especially when ACLs are involved, overlooking layer 2 connectivity problems like trunking.

✗VLAN 20 is not defined on the switchWrong answer — click to see why▾

Why this is wrong here

The question states the switch is a layer 2 switch and the router has subinterfaces for both VLANs. If VLAN 20 were not defined on the switch, the switch would not forward frames from VLAN 20 to the router, but the issue is inter-VLAN routing from VLAN 10 to VLAN 20. The switch port connecting to the router is an access port in VLAN 10, which prevents VLAN 20 traffic from reaching the router, regardless of VLAN 20 being defined.

★ When this WOULD be the correct answer

In a scenario where a router-on-a-stick is used and the switch does not have VLAN 20 defined, hosts on VLAN 20 would be unable to communicate with any other VLAN because the switch would drop frames tagged with VLAN 20. For example, if clients on VLAN 20 cannot ping the router's subinterface for VLAN 20, the cause could be that VLAN 20 is not created on the switch.

Why candidates choose this

Candidates may assume that if a VLAN is not defined on the switch, inter-VLAN routing will fail, but they overlook that the immediate issue is the access port configuration, which blocks all VLAN 20 traffic at the switch-to-router link.

Analysis generated from the official 220-1101blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”

Visual reference

Switch VLAN 10 Sales (192.168.10.0/24) PC-A PC-B VLAN 20 HR (192.168.20.0/24) PC-C PC-D Router VLANs isolate traffic — inter-VLAN routing requires a Layer 3 device

About these practice questions

Courseiva writes every 220-1101 question from scratch — 896 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 220-1101 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1101 exam.