220-1101 Networking Practice Question
A small office network uses a router with DHCP enabled on the 192.168.1.0/24 subnet. A technician configures a file server with a static IP address of 192.168.1.150, subnet mask 255.255.255.0, and default gateway 192.168.1.1. Workstations on the same subnet can ping the router (192.168.1.1) but cannot ping the server. The server can ping its own IP and the router. Which of the following is the MOST likely cause?
⚠ Common exam trap
Test-takers frequently assume a failed ping means a network configuration error (like wrong subnet mask or IP conflict), when in fact the server's firewall is intentionally blocking ICMP, a common security practice that does not indicate a misconfiguration.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The server's firewall is blocking ICMP echo requests
The server can ping its own IP and the router, indicating its IP configuration (address, subnet mask, default gateway) is correct and it has network connectivity. Workstations can ping the router but not the server, which rules out a routing or subnet issue. The most likely cause is that the server's firewall is blocking ICMP echo requests (pings), a common security configuration that prevents the server from responding to ping probes while allowing other traffic.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
The server's firewall is blocking ICMP echo requests
Why this is correct
A host-based firewall on the server, such as Windows Defender Firewall, commonly drops inbound ICMP echo requests even when the network stack is fully functional. Because the server can originate traffic (like pinging the router), outbound rules and the network interface are fine, but the unsolicited inbound echo is filtered. This produces a one-way ping failure that is entirely independent of IP addressing or DHCP, making it the most direct and likely cause.
- ✗
The server has been assigned a duplicate IP address
Why it's wrong here
An IP address conflict with another device usually causes frequent, unpredictable connectivity interruptions for both hosts, including ARP cache poisoning and TCP connection resets. If the server could still successfully ping the router, its IP stack and local traffic are working; a conflicting device would typically trigger continuous broadcast traffic and make the link unreliable, not simply block inbound ICMP while leaving outbound communication smooth. Additionally, since the server uses a static address, it would not wait for a DHCP lease, but the conflict would still produce ARP instability rather than a clean firewall-like drop.
- ✗
The subnet mask on the server is incorrect
Why it's wrong here
An incorrect subnet mask, especially one that is too restrictive (e.g., /28 instead of /24), would make the server see the router's IP as being on a remote network and try to forward the packets to a default gateway, which may not exist. The fact that the server can ping the router proves the local subnet reachability is working, so the mask—if wrong—must still include the router's address (e.g., /16), and that kind of error would not prevent other devices from reaching the server. It would also not selectively drop ICMP; it would affect all traffic to certain subnets, so it cannot explain a one-way ping failure.
- ✗
The DHCP server has already assigned the address 192.168.1.150 to another device
Why it's wrong here
While this could cause an IP conflict, the server can still send and receive traffic to the router, and the static IP assignment would override the DHCP lease. The firewall is a more direct explanation.
Visual reference
Quick reference
IPv4 Address Class Summary
| Class | First Octet Range | Default Mask | Networks | Hosts per Network |
|---|---|---|---|---|
| A | 1–126 | /8 (255.0.0.0) | 126 | 16,777,214 |
| B | 128–191 | /16 (255.255.0.0) | 16,384 | 65,534 |
| C | 192–223 | /24 (255.255.255.0) | 2,097,152 | 254 |
| D | 224–239 | N/A | Multicast groups | — |
| E | 240–255 | N/A | Reserved / experimental | — |
127.x.x.x is reserved for loopback. Modern networks use CIDR (classless) rather than classful addressing.
Go deeper
Related to this question
About these practice questions
This 220-1101 question is part of Courseiva's 896-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 220-1101 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1101 exam.