220-1101 Networking Practice Question
A technician is configuring a small office network with a router that performs NAT. The router's WAN interface receives a public IP address from the ISP, and the LAN uses the private subnet 192.168.1.0/24. The technician needs to allow external users to access an internal web server at 192.168.1.100 on port 80. Which two actions should the technician take on the router? (Choose two.)
⚠ Common exam trap
The trap here is thinking that DMZ is a quick solution, but it exposes all ports and is less secure than port forwarding.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Configure port forwarding for port 80 to 192.168.1.100.
To allow external access to an internal web server behind NAT, the router must forward inbound traffic on port 80 to the server's internal IP address. Additionally, the server must have a consistent IP address, achieved via static IP or DHCP reservation, so the forwarding rule remains valid. Port forwarding and a stable IP are the two essential steps. DMZ, static routes, or VPNs are either insecure or do not meet the requirement.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Set up a VPN server on the router for external users to connect.
Why it's wrong here
A VPN would allow external users to securely access the internal network, but it requires clients to install and configure VPN software. The requirement is for general external users to access the web server via standard HTTP, not through a VPN tunnel. While VPN is more secure, it does not meet the accessibility requirement. Thus, it is not the correct action here.
- ✓
Configure port forwarding for port 80 to 192.168.1.100.
Why this is correct
Port forwarding (or port mapping) directs incoming traffic on a specific port from the WAN to a specific internal IP address and port. For the web server, forwarding TCP port 80 to 192.168.1.100 allows external users to reach it. Without this, NAT would block unsolicited inbound connections. This is a standard requirement for hosting services behind NAT.
- ✗
Configure a static route on the router for the 192.168.1.0/24 network.
Why it's wrong here
A static route is used to direct traffic to a different network, but the router already has a directly connected route for 192.168.1.0/24. Adding a static route would be redundant and would not help with inbound access from the internet. The issue is NAT, not routing. Therefore, this action does not solve the problem.
- ✗
Enable DMZ on the router and set the DMZ host to 192.168.1.100.
Why it's wrong here
A DMZ host forwards all inbound ports to a single internal device, which exposes it to unnecessary risks. While it would allow access to the web server, it also opens all other ports, creating a security vulnerability. Port forwarding is more secure because it only opens the required port. Thus, DMZ is not the recommended action for this scenario.
- ✓
Assign a static IP address to the web server or create a DHCP reservation.
Why this is correct
The web server must have a consistent IP address (192.168.1.100) for port forwarding to work reliably. If the server obtains a different IP via DHCP, the forwarding rule would break. A static IP or DHCP reservation ensures the server always gets the same address. This is essential for any inbound service behind NAT.
Visual reference
Go deeper
Related to this question
About these practice questions
This 220-1101 question is part of Courseiva's 896-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This 220-1101 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1101 exam.