Courseiva
Networking →mediumMultiple Choice

220-1101 Networking Practice Question

A technician is setting up a small office network. The company has a single public IP address from the ISP. The technician needs to configure the router so that multiple internal devices can share that IP address to access the internet. Which of the following settings should the technician configure?

⚠ Common exam trap

Watch out — candidates often confuse NAT with port forwarding, thinking that port forwarding is required to allow internal devices to reach the internet, when in fact port forwarding is only needed for unsolicited inbound traffic to a specific internal host.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

NAT (Network Address Translation)

Network Address Translation (NAT) allows multiple devices on a private network to share a single public IP address by mapping their private IP addresses and port numbers to the public IP and unique port numbers. This is the standard method for conserving public IPv4 addresses and enabling internet access for internal hosts.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Port forwarding

    Why it's wrong here

    Port forwarding creates a static mapping from a specific external TCP/UDP port to an internal IP and port, so inbound connection attempts to that port are delivered to the designated host. It only affects incoming traffic, not the outbound flow from internal devices. While port forwarding often works alongside NAT to expose an internal service, it cannot by itself allow a pool of internal devices to share one public IP for general browsing; that requires NAT's stateful outbound translation.

    When this WOULD be correct

    A technician needs to allow external users to access a web server hosted on an internal private IP address. The router has a single public IP, and the technician should configure port forwarding to direct incoming HTTP/HTTPS traffic to the internal server.

  • ✓

    NAT (Network Address Translation)

    Why this is correct

    NAT (specifically PAT/overload) rewrites the source IP and source port of outbound packets from internal devices to the router's single public IP, while maintaining a translation table to map return traffic back to the correct internal device. This allows every workstation on the LAN to share one public address for internet access. Without NAT, the router would have no way to route replies from the internet to the correct internal host, making simultaneous outbound connections impossible.

  • ✗

    DMZ (Demilitarized Zone)

    Why it's wrong here

    A DMZ is a separate network segment that houses Internet-facing servers, such as web or email servers, which are deliberately exposed to inbound traffic from the outside. Placing a device in the DMZ does not perform any address translation for internal clients; it only changes the exposure and routing rules for that specific host. For outbound internet access from multiple internal devices, the DMZ provides no mechanism to convert private addresses into the single public IP — that function belongs exclusively to NAT.

    When this WOULD be correct

    A technician needs to host a public web server on the internal network while keeping the rest of the network secure. The correct answer would be DMZ to place the server in a separate, less secure network segment.

  • ✗

    DHCP (Dynamic Host Configuration Protocol)

    Why it's wrong here

    DHCP automatically assigns each internal device its IP address, subnet mask, default gateway, and DNS server information. These assigned IPs are typically private (RFC 1918) and are not routable on the public Internet. DHCP performs no address translation; even with DHCP configured, every device would still need its own public IP to reach the Internet unless NAT is used to multiplex outbound traffic onto the single public address.

    When this WOULD be correct

    A technician is setting up a network and needs to ensure that all devices receive IP addresses automatically without manual configuration. The correct answer would be DHCP, as it dynamically assigns IP addresses to clients on the local network.

Option-by-option analysis

Why each answer is right or wrong

Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The 220-1101 exam frequently reuses these exact scenarios with slightly different constraints.

✓NAT (Network Address Translation)Correct answer▾

Why this is correct

NAT (specifically PAT/overload) rewrites the source IP and source port of outbound packets from internal devices to the router's single public IP, while maintaining a translation table to map return traffic back to the correct internal device. This allows every workstation on the LAN to share one public address for internet access. Without NAT, the router would have no way to route replies from the internet to the correct internal host, making simultaneous outbound connections impossible.

✗Port forwardingWrong answer — click to see why▾

Why this is wrong here

Port forwarding allows external devices to access internal services through specific ports, but it does not enable multiple internal devices to share a single public IP address for outbound internet access.

★ When this WOULD be the correct answer

A technician needs to allow external users to access a web server hosted on an internal private IP address. The router has a single public IP, and the technician should configure port forwarding to direct incoming HTTP/HTTPS traffic to the internal server.

Why candidates choose this

Candidates may confuse port forwarding with NAT because both involve mapping between public and private addresses, but port forwarding is for inbound traffic, not outbound sharing.

✗DMZ (Demilitarized Zone)Wrong answer — click to see why▾

Why this is wrong here

DMZ exposes a device to the internet with no firewall protection, which does not allow multiple internal devices to share a single public IP for outbound internet access; it is used for inbound traffic to a specific host.

★ When this WOULD be the correct answer

A technician needs to host a public web server on the internal network while keeping the rest of the network secure. The correct answer would be DMZ to place the server in a separate, less secure network segment.

Why candidates choose this

Candidates may confuse DMZ with NAT because both involve public IPs and internal devices, but DMZ is for inbound exposure, not outbound sharing.

✗DHCP (Dynamic Host Configuration Protocol)Wrong answer — click to see why▾

Why this is wrong here

DHCP assigns IP addresses to devices on the local network, but it does not enable multiple devices to share a single public IP address for internet access. The question specifically asks for sharing one public IP among multiple internal devices, which is the function of NAT, not DHCP.

★ When this WOULD be the correct answer

A technician is setting up a network and needs to ensure that all devices receive IP addresses automatically without manual configuration. The correct answer would be DHCP, as it dynamically assigns IP addresses to clients on the local network.

Why candidates choose this

Candidates may confuse DHCP with NAT because both are common router settings, and they might think DHCP is responsible for internet connectivity, not just local IP assignment.

Analysis generated from the official 220-1101blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”

Visual reference

Inside (Private) PC-A 10.0.0.1 PC-B 10.0.0.2 NAT Router Outside (Public) 203.0.113.1 Inside Global Server PAT: many private IPs share one public IP via unique port numbers

About these practice questions

This 220-1101 question is part of Courseiva's 896-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 220-1101 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1101 exam.