Courseiva
Networking →mediumMultiple Choice

220-1101 Networking Practice Question

A user installs a new third-party security software suite on their Windows workstation. After installation, the user can still access files on the local network and can ping external IP addresses like 8.8.8.8, but cannot browse any websites using a web browser. Other workstations on the same network are unaffected. Which of the following is the MOST likely cause?

⚠ Common exam trap

CompTIA often tests the distinction between network-layer connectivity (ICMP ping) and application-layer connectivity (HTTP/HTTPS), leading candidates to incorrectly suspect DNS or gateway issues when the real problem is a firewall blocking specific ports.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The security software's firewall is blocking outbound HTTP/HTTPS traffic

The user can ping external IP addresses (e.g., 8.8.8.8) and access local network files, which confirms that IP connectivity, the default gateway, and DNS resolution for local resources are working. However, the inability to browse websites (which use HTTP/HTTPS) while other workstations are unaffected strongly indicates that the new third-party security software's firewall is blocking outbound TCP ports 80 and 443. This is a common behavior of security suites that enable strict outbound filtering by default.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    The security software's firewall is blocking outbound HTTP/HTTPS traffic

    Why this is correct

    The security suite's firewall is the primary suspect because it operates at the application/transport layer and can selectively drop TCP segments destined for ports 80 and 443 while still permitting ICMP echo requests (ping) on the network layer. Third-party security products often activate a default 'block unknown' policy during installation, silently denying outbound HTTP/HTTPS connections until the user manually creates an allow rule for the browser. This precisely matches the observed symptom: IP connectivity is intact (ping succeeds), but web traffic fails because port 80/443 packets are discarded at the host-based firewall before reaching the network stack.

  • ✗

    The DNS server address was changed by the software

    Why it's wrong here

    If the security software merely altered the DNS server assignment, name resolution would fail, causing the browser to report 'server not found' when entering a domain name. However, pinging the IP address 8.8.8.8 does not require DNS at all, so that test would succeed despite a broken resolver. Because the user can reach an external IP directly, the IP route and network stack are functional; DNS problems would not impair HTTP/HTTPS access if the browser used a numeric IP, but here the failure persists regardless of hostname, confirming DNS is not the bottleneck.

  • ✗

    The workstation's default gateway was removed

    Why it's wrong here

    A missing or incorrect default gateway would make it impossible to send packets to any destination outside the local subnet, including 8.8.8.8. Since the user successfully pings 8.8.8.8, the workstation must have a valid default gateway configured and the router is forwarding traffic. Additionally, removing the gateway would affect all outbound traffic—not just HTTP/HTTPS—whereas the observed failure is limited to web protocols, which points to a port-specific block rather than a routing problem.

  • ✗

    The security software corrupted the browser's configuration files

    Why it's wrong here

    Corrupted browser configuration files could cause crashes, startup errors, or homepage redirects, but they would not selectively block HTTP/HTTPS while leaving other IP-based traffic like ping unaffected. A firewall block operates at the packet level, dropping or rejecting connections to port 80/443 regardless of the application's configuration; file corruption would likely produce different symptoms for different browsers or network applications, and it would not consistently permit ping. The fact that ping works and only web browsing fails is a classic signature of a filtering rule, not a local file integrity issue.

Visual reference

Client Recursive Resolver Root DNS (13 root servers) TLD DNS (.com, .org, …) Authoritative example.com query IP addr answer

About these practice questions

This 220-1101 question is part of Courseiva's 896-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 220-1101 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1101 exam.