Courseiva
Networking →mediumMultiple Choice

Windows Firewall Blocking Inbound Connections Prevents Network Visibility

A technician is setting up a small office network with a wireless router serving as the DHCP server and an unmanaged 24-port switch. All desktop computers are connected to the switch via Ethernet cables. The computers can access the internet without any issues, but they cannot see each other in the network discovery list or ping each other by IP address. The technician checks the IP configuration on one computer and finds it has an IP address of 192.168.1.10 with a subnet mask of 255.255.255.0. The technician can ping the router (192.168.1.1). Which of the following is the MOST likely cause of this issue?

Quick Answer

The correct answer identifies Windows Firewall because the pattern of symptoms points precisely at a host-based blocking mechanism rather than anything wrong with addressing or the physical network. The technician already confirmed that DHCP is handing out valid addresses, that the subnet mask is correct, and that the switch is forwarding frames, since every computer can reach the internet and ping the router. What fails is only communication between peers on the same subnet, specifically ping and network discovery, both of which depend on inbound traffic (ICMP echo requests and NetBIOS/LLMNR broadcasts) being allowed on each machine. Windows Firewall, especially under a Public network profile, blocks unsolicited inbound connections by default while still permitting outbound requests like web browsing, which is exactly the asymmetry described here. This rules out DHCP misconfiguration, cabling, or switch problems, since those would also break internet access or router connectivity, not just peer-to-peer visibility. When you see a scenario where a device can reach the gateway and the internet but cannot be pinged or discovered by other local devices, train yourself to think host-based firewall before chasing switch or routing issues, since the selective failure pattern (outbound fine, inbound blocked) is the fingerprint of a local firewall rule rather than a network-layer fault.

⚠ Common exam trap

Candidates often assume a connectivity issue must be caused by misconfigured IP settings or a faulty switch, but the fact that internet access works and the router is reachable narrows the problem to host-based firewalls blocking peer-to-peer traffic, which is a classic CompTIA 220-1101 exam twist.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The Windows firewall on each computer is blocking inbound connections.

The computers can access the internet and ping the router, confirming that the DHCP server is correctly assigning IP addresses, subnet masks, and default gateways, and that the switch is forwarding traffic properly. The inability to ping each other by IP address or see each other in network discovery strongly indicates that the Windows firewall on each computer is blocking inbound ICMP and NetBIOS/LLMNR traffic, which are required for ping responses and network discovery. This is a common default behavior of Windows Firewall in certain network profiles (e.g., Public), which blocks inbound connections unless explicitly allowed.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The DHCP server is not assigning the correct default gateway.

    Why it's wrong here

    Internet access and successful pings to 192.168.1.1 confirm the default gateway is correctly assigned and functional. A wrong gateway would prevent off-subnet traffic while leaving local peer pings working, which is the opposite of the reported symptoms.

  • ✗

    The switch is not properly forwarding broadcast traffic between ports.

    Why it's wrong here

    An unmanaged switch floods broadcasts to every port by design, so broadcast suppression is not occurring. The router responds to pings, proving Layer 2 forwarding works; the actual cause is host-based, typically the Windows network profile set to Public, which blocks discovery and inbound ICMP.

    When this WOULD be correct

    In a scenario where a managed switch has VLANs configured and ports are assigned to different VLANs without inter-VLAN routing, computers on different VLANs cannot communicate. The switch would not forward broadcast traffic between VLANs, causing similar symptoms.

  • ✓

    The Windows firewall on each computer is blocking inbound connections.

    Why this is correct

    Windows Defender Firewall blocks inbound ICMP echo requests and network discovery traffic by default, so hosts can reach the router and internet yet cannot ping or see each other. The router's DHCP and subnet mask are correct, ruling out addressing faults.

  • ✗

    The computers are receiving IP addresses from different VLANs.

    Why it's wrong here

    An unmanaged switch forwards all frames regardless of VLAN tags, and the router's single DHCP scope issues one subnet, so no VLAN separation exists. VLANs would require managed switches and 802.1Q configuration; the fault lies in client-side discovery settings such as network profile or firewall rules.

    When this WOULD be correct

    In a network with managed switches configured with multiple VLANs and a DHCP server that assigns IP addresses from different subnets per VLAN, computers on different VLANs would be unable to communicate with each other even if they can access the internet through a router.

Option-by-option analysis

Why each answer is right or wrong

Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The 220-1101 exam frequently reuses these exact scenarios with slightly different constraints.

✓The Windows firewall on each computer is blocking inbound connections.Correct answer▾

Why this is correct

Windows Defender Firewall blocks inbound ICMP echo requests and network discovery traffic by default, so hosts can reach the router and internet yet cannot ping or see each other. The router's DHCP and subnet mask are correct, ruling out addressing faults.

✗The switch is not properly forwarding broadcast traffic between ports.Wrong answer — click to see why▾

Why this is wrong here

An unmanaged switch forwards broadcast traffic by default, so it does not block the ARP or NetBIOS broadcasts needed for network discovery and ping by IP. The issue is not with the switch's forwarding behavior.

★ When this WOULD be the correct answer

In a scenario where a managed switch has VLANs configured and ports are assigned to different VLANs without inter-VLAN routing, computers on different VLANs cannot communicate. The switch would not forward broadcast traffic between VLANs, causing similar symptoms.

Why candidates choose this

Candidates may think that switches can block broadcast traffic, confusing unmanaged switches with managed switches that have features like broadcast storm control or VLAN isolation.

✗The computers are receiving IP addresses from different VLANs.Wrong answer — click to see why▾

Why this is wrong here

The computers have IP addresses in the same subnet (192.168.1.0/24) and can ping the router, indicating they are on the same VLAN. An unmanaged switch does not support VLANs, so different VLANs cannot exist.

★ When this WOULD be the correct answer

In a network with managed switches configured with multiple VLANs and a DHCP server that assigns IP addresses from different subnets per VLAN, computers on different VLANs would be unable to communicate with each other even if they can access the internet through a router.

Why candidates choose this

Candidates may confuse VLAN segmentation with the symptoms of isolated hosts, not realizing that an unmanaged switch cannot create VLANs and that the IP addresses are in the same subnet.

Analysis generated from the official 220-1101blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”

Visual reference

Client DHCP Server 1 Discover (broadcast) 2 Offer (IP: 192.168.1.10) 3 Request (I accept) 4 Acknowledge (lease confirmed) DORA — the four-step DHCP lease process

About these practice questions

Courseiva writes every 220-1101 question from scratch — 896 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on 220-1101

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. A small office network uses a router (192.168.1.1/24) and an unmanaged switch. A technician configures a server with a static IP address 192.168.1.100/24, gateway 192.168.1.1, and connects it to the switch. Workstations on the same subnet can ping the router (192.168.1.1) but cannot ping the server. The server can ping its own IP and the router. Which of the following is the MOST likely cause?

hard
  • A.The server has a duplicate IP address
  • B.The switch port is administratively disabled
  • ✓ C.The server's firewall is blocking ICMP
  • D.The default gateway is incorrect

Why C: The server can ping its own IP, indicating its IP stack is functioning. It can also ping the router, which confirms local network connectivity (the router is on the same subnet). Since workstations can reach the router but not the server, the issue is isolated to the server. The most likely cause is a host-level firewall blocking inbound ICMP echo requests, a common default on server operating systems.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 220-1101 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1101 exam.