220-1101 Networking Practice Question
A user reports that they can access internal company servers by IP address but cannot access the internet. The user can ping the default gateway successfully. Other users on the same subnet have full internet access. The technician checks the user's IP configuration and sees that the IP address, subnet mask, and default gateway are correct. The DNS server address is set to the company's internal DNS server (10.0.1.10). Which of the following is the MOST likely cause of the issue?
⚠ Common exam trap
Candidates often assume internet access failure must be a gateway or subnet issue, but the ability to ping the gateway and access internal resources by IP points directly to a name resolution problem, specifically a local DNS cache issue.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The user's computer has a stale DNS cache
The user can access internal servers by IP and ping the default gateway, confirming that Layer 3 connectivity is intact. Since other users on the same subnet have full internet access, the issue is isolated to this specific computer. A stale DNS cache can prevent name resolution for external domains while leaving internal IP-based access unaffected, which matches the symptom exactly.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
The user's computer has a stale DNS cache
Why this is correct
A stale DNS cache retains old or incorrect IP mappings for external domain names, so when the user's browser sends a name resolution request, the cached entry is returned instead of querying an authoritative server. Because internal servers are accessed directly by IP address, no DNS lookup is needed, which explains why internal IP-based access works while external hostname-based access fails. Flushing the cache with ipconfig /flushdns clears these stale entries and forces a fresh query, resolving the symptom.
- ✗
The DHCP scope is exhausted and the user received an APIPA address
Why it's wrong here
A DHCP scope exhaustion would leave the client with an APIPA address (169.254.x.x), which is link-local and has no default gateway, making communication with the company's internal servers or any off-subnet device impossible. Since the user can successfully ping the default gateway and reach internal servers by IP, their interface has a valid, routable IP configuration rather than an APIPA address. Therefore, DHCP exhaustion cannot be the cause of the external name resolution failure.
When this WOULD be correct
A user cannot access any network resources, including internal servers, and the IP configuration shows an APIPA address (169.254.x.x). Other users on the same subnet have no issues, and the DHCP server is unreachable or out of addresses.
- ✗
The user has an incorrect default gateway configured
Why it's wrong here
An incorrect default gateway would disrupt all traffic destined for off-subnet networks, including the internal company servers the user is successfully reaching by IP address. Since the user can ping the default gateway, the gateway is both configured and reachable; a wrong gateway would either be unreachable or would fail to route packets out of the local subnet. The selective failure (only external names) points to name resolution, not Layer 3 routing.
When this WOULD be correct
A user cannot access any network resources (internal or internet) and cannot ping the default gateway, but other users on the same subnet have connectivity. The IP configuration shows a default gateway that is different from the subnet's gateway address.
- ✗
The user's subnet mask is incorrect
Why it's wrong here
An incorrect subnet mask would misclassify which destinations are on the local network, causing the host to attempt ARP for remote IPs or to route to the gateway when it should be local. Because the user is able to ping the default gateway, the mask must be consistent enough to recognize the gateway as local, and the ability to access internal servers by IP shows that off-subnet routing is unaffected. A bad subnet mask would cause broad connectivity failures, not just DNS-related outages.
When this WOULD be correct
A user cannot communicate with any other devices, including the default gateway, but the IP address and default gateway appear correct. The technician finds that the subnet mask is mismatched with the network's mask, causing the system to believe the gateway is on a different subnet.
Option-by-option analysis
Why each answer is right or wrong
Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The 220-1101 exam frequently reuses these exact scenarios with slightly different constraints.
✓The user's computer has a stale DNS cacheCorrect answer▾
Why this is correct
A stale DNS cache retains old or incorrect IP mappings for external domain names, so when the user's browser sends a name resolution request, the cached entry is returned instead of querying an authoritative server. Because internal servers are accessed directly by IP address, no DNS lookup is needed, which explains why internal IP-based access works while external hostname-based access fails. Flushing the cache with ipconfig /flushdns clears these stale entries and forces a fresh query, resolving the symptom.
✗The DHCP scope is exhausted and the user received an APIPA addressWrong answer — click to see why▾
Why this is wrong here
The user can access internal servers by IP and ping the default gateway, indicating correct IP configuration and connectivity. An APIPA address (169.254.x.x) would prevent internal access and gateway pings, so DHCP exhaustion is not the issue.
★ When this WOULD be the correct answer
A user cannot access any network resources, including internal servers, and the IP configuration shows an APIPA address (169.254.x.x). Other users on the same subnet have no issues, and the DHCP server is unreachable or out of addresses.
Why candidates choose this
Candidates may assume that internet access failure is due to DHCP exhaustion, especially when other users are unaffected, but the ability to ping the gateway and access internal servers rules out APIPA.
✗The user has an incorrect default gateway configuredWrong answer — click to see why▾
Why this is wrong here
The user can ping the default gateway successfully, indicating the default gateway is correctly configured and reachable. An incorrect default gateway would prevent successful pings to the gateway.
★ When this WOULD be the correct answer
A user cannot access any network resources (internal or internet) and cannot ping the default gateway, but other users on the same subnet have connectivity. The IP configuration shows a default gateway that is different from the subnet's gateway address.
Why candidates choose this
Candidates may assume that internet access issues are always due to gateway misconfiguration, especially when internal access works, without considering that DNS resolution could be the bottleneck.
✗The user's subnet mask is incorrectWrong answer — click to see why▾
Why this is wrong here
The user can access internal servers by IP address and ping the default gateway, indicating that the subnet mask is correct. An incorrect subnet mask would typically prevent communication with both internal and external hosts.
★ When this WOULD be the correct answer
A user cannot communicate with any other devices, including the default gateway, but the IP address and default gateway appear correct. The technician finds that the subnet mask is mismatched with the network's mask, causing the system to believe the gateway is on a different subnet.
Why candidates choose this
Candidates may think that an incorrect subnet mask could cause internet access issues while still allowing local communication, but in reality it would break all routing beyond the local subnet.
Analysis generated from the official 220-1101blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”
Visual reference
Quick reference
IPv4 Address Class Summary
| Class | First Octet Range | Default Mask | Networks | Hosts per Network |
|---|---|---|---|---|
| A | 1–126 | /8 (255.0.0.0) | 126 | 16,777,214 |
| B | 128–191 | /16 (255.255.0.0) | 16,384 | 65,534 |
| C | 192–223 | /24 (255.255.255.0) | 2,097,152 | 254 |
| D | 224–239 | N/A | Multicast groups | — |
| E | 240–255 | N/A | Reserved / experimental | — |
127.x.x.x is reserved for loopback. Modern networks use CIDR (classless) rather than classful addressing.
Go deeper
Related to this question
About these practice questions
One of 896 original 220-1101 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 220-1101 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1101 exam.