Courseiva
Networking →hardMultiple Choice

220-1101 Networking Practice Question

A technician is troubleshooting inter-subnet connectivity. The network consists of a router with two interfaces: 192.168.1.1/24 for Subnet A and 192.168.2.1/24 for Subnet B. A device on Subnet A (192.168.1.10/24) can ping the router's Subnet A interface (192.168.1.1) and other devices on Subnet A, but cannot ping a device on Subnet B (192.168.2.10/24). The device on Subnet B can ping its gateway (192.168.2.1) and other Subnet B devices. The router has IP routing enabled and no ACLs are configured. Which of the following is the MOST likely cause of the issue?

⚠ Common exam trap

CompTIA often tests the misconception that inter-subnet ping failures are always due to routing or gateway issues, when in fact host-based firewalls on the source device can silently drop the return ICMP traffic, causing a one-way connectivity failure.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The device on Subnet A has a software firewall blocking incoming ICMP traffic

The device on Subnet A can reach its own gateway and local hosts, and the router has IP routing enabled with no ACLs, so routing is functional. The device on Subnet B can ping its own gateway, confirming that Subnet B's network and the router's interface are up. The most likely cause is that the device on Subnet A has a software firewall (e.g., Windows Defender Firewall) blocking incoming ICMP Echo Replies, which prevents the ping response from Subnet B from reaching Subnet A. This is a common scenario where outbound ICMP is allowed but inbound ICMP is blocked by the host firewall.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The router's interface on Subnet A is administratively down

    Why it's wrong here

    When a router interface is administratively down, the router does not participate in the subnet's L2 segment and removes the connected route from its routing table. The device on Subnet A would be unable to ping its own gateway (i.e., the interface IP) because no host responds to ARP or ICMP on that address. A failure on the Subnet A interface would affect all traffic from Subnet A, including local gateway reachability, not merely the one-way ping from Subnet B.

    When this WOULD be correct

    A technician cannot ping a router's interface from a directly connected device, and 'show ip interface brief' shows the interface is 'administratively down'. The question would describe no other connectivity issues, and the interface must be enabled with 'no shutdown'.

  • ✓

    The device on Subnet A has a software firewall blocking incoming ICMP traffic

    Why this is correct

    Although the device on Subnet A is otherwise healthy and can communicate within its own subnet, its host-based firewall (e.g., Windows Defender Firewall) can be configured to silently drop unsolicited inbound ICMP Echo Requests. Because the firewall inspects packets after the NIC receives them, the router on Subnet B still forwards the ping successfully; the reply simply never leaves the destination host. This produces a one-way failure where the Subnet B device can ping the router but not the end device, exactly matching an inter-subnet reachability symptom.

  • ✗

    The subnet mask on the device in Subnet B is incorrect

    Why it's wrong here

    An incorrect subnet mask on the Subnet B device changes its route determination logic: if the mask doesn't include the gateway address, the host believes 192.168.2.1 is on a different network and will not send ARP for it, making the gateway unreachable. Even a mask that still includes the gateway may cause the host to classify Subnet A's destination as local and attempt a direct ARP broadcast instead of forwarding the packet to the router. Either way, the failure manifests before any packet leaves Subnet B, so it would not specifically produce a successful ping to the gateway followed by failure to a host on Subnet A.

    When this WOULD be correct

    A question where a device on one subnet cannot ping a device on another subnet, and the device that cannot ping also cannot ping its own gateway, while other devices on its subnet can. This would point to an incorrect subnet mask on that device, causing it to believe the gateway is on a different network.

  • ✗

    The switch port connecting the router to Subnet B is configured as an access port in the wrong VLAN

    Why it's wrong here

    If the switch port connected to the router's Subnet B interface were assigned to the wrong access VLAN, the router would not be a member of the same broadcast domain as the hosts in Subnet B. That would prevent the router from seeing ARP requests or forwarding frames to those hosts, so the devices on Subnet B could not reach even their own default gateway. Since the reported symptom is limited to inter-subnet ping failure, this broken L2 path would cause complete loss of connectivity and is therefore not the correct cause.

    When this WOULD be correct

    This would be correct if the device on Subnet B could not ping its own gateway or other Subnet B devices, indicating a Layer 2 issue. For example, if the switch port connecting the router to Subnet B is in the wrong VLAN, the router's interface would be unreachable from Subnet B devices.

Option-by-option analysis

Why each answer is right or wrong

Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The 220-1101 exam frequently reuses these exact scenarios with slightly different constraints.

✓The device on Subnet A has a software firewall blocking incoming ICMP trafficCorrect answer▾

Why this is correct

Although the device on Subnet A is otherwise healthy and can communicate within its own subnet, its host-based firewall (e.g., Windows Defender Firewall) can be configured to silently drop unsolicited inbound ICMP Echo Requests. Because the firewall inspects packets after the NIC receives them, the router on Subnet B still forwards the ping successfully; the reply simply never leaves the destination host. This produces a one-way failure where the Subnet B device can ping the router but not the end device, exactly matching an inter-subnet reachability symptom.

✗The router's interface on Subnet A is administratively downWrong answer — click to see why▾

Why this is wrong here

If the router's interface on Subnet A were administratively down, the device on Subnet A could not ping that interface (192.168.1.1), but the scenario states it can ping it successfully.

★ When this WOULD be the correct answer

A technician cannot ping a router's interface from a directly connected device, and 'show ip interface brief' shows the interface is 'administratively down'. The question would describe no other connectivity issues, and the interface must be enabled with 'no shutdown'.

Why candidates choose this

Candidates may assume that any inter-subnet failure is due to a router interface issue, overlooking that the device can already reach its own gateway, which rules out this cause.

✗The subnet mask on the device in Subnet B is incorrectWrong answer — click to see why▾

Why this is wrong here

An incorrect subnet mask on the device in Subnet B would prevent it from communicating with devices outside its own subnet, but the device on Subnet B can already ping its gateway (192.168.2.1) and other Subnet B devices, indicating its subnet mask is correct. The issue is from Subnet A to Subnet B, not from Subnet B.

★ When this WOULD be the correct answer

A question where a device on one subnet cannot ping a device on another subnet, and the device that cannot ping also cannot ping its own gateway, while other devices on its subnet can. This would point to an incorrect subnet mask on that device, causing it to believe the gateway is on a different network.

Why candidates choose this

Candidates may think that any inter-subnet communication issue must be due to a subnet mask problem, overlooking that the symptoms here isolate the problem to the source device's outbound traffic being blocked.

✗The switch port connecting the router to Subnet B is configured as an access port in the wrong VLANWrong answer — click to see why▾

Why this is wrong here

The device on Subnet A can ping its own gateway and local devices, indicating Layer 2 connectivity is intact. The router has IP routing enabled and no ACLs, so inter-subnet routing should work. A misconfigured switch port would affect Layer 2 connectivity, not specifically inter-subnet pings while local pings succeed.

★ When this WOULD be the correct answer

This would be correct if the device on Subnet B could not ping its own gateway or other Subnet B devices, indicating a Layer 2 issue. For example, if the switch port connecting the router to Subnet B is in the wrong VLAN, the router's interface would be unreachable from Subnet B devices.

Why candidates choose this

Candidates may confuse a Layer 2 issue (switch port VLAN mismatch) with a Layer 3 routing problem, especially when inter-subnet connectivity fails but local connectivity works. They might assume the router's connection to Subnet B is misconfigured.

Analysis generated from the official 220-1101blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”

Visual reference

192.168.1.0 /24 256 addresses (254 usable) 192.168.1.0 /25 Subnet A 128 addr (126 usable) 192.168.1.128 /25 Subnet B 128 addr (126 usable) Borrowing 1 bit from host portion creates 2 subnets (/25)

About these practice questions

This 220-1101 question is part of Courseiva's 896-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 220-1101 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1101 exam.