LFCS Networking Practice Question
An administrator is diagnosing why a server cannot reach the host 198.51.100.25. The server has one interface, eth0, with address 192.0.2.10/24. Running `ip route show` returns only the default route via 192.0.2.1. Which two commands will help determine whether the problem is at layer 2 or layer 3? (Choose two.)
⚠ Common exam trap
The trap here is selecting commands that show local socket or interface state instead of tools that test reachability and neighbor resolution.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
ip neigh show 192.0.2.1
To isolate layer 2 versus layer 3, check the neighbor table for the gateway and trace the path to the destination. An unresolved neighbor entry points to a layer 2 problem, while a resolved entry with a traceroute that stops beyond the first hop points to layer 3 or higher. Interface state and DNS queries do not make this distinction.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
ip neigh show 192.0.2.1
Why this is correct
This command displays the ARP/neighbor table entry for the gateway. If the gateway's MAC address is unresolved or shows FAILED, the problem is at layer 2. If it is REACHABLE, layer 2 to the gateway is working, and the issue is likely at layer 3 or beyond.
- ✗
ss -tulnp | grep 198.51.100.25
Why it's wrong here
The `ss` command lists local listening sockets and established connections. It does not test reachability to a remote host and would not show any useful information about a destination that is not a local listener. This is irrelevant to the diagnostic goal.
- ✗
ip link show eth0
Why it's wrong here
This shows interface flags and state such as UP or DOWN. While useful to confirm the interface is up, it does not distinguish layer 2 from layer 3 problems for a specific destination, because the link can be up while ARP or routing fails.
- ✗
dig +short 198.51.100.25
Why it's wrong here
The `dig` command queries DNS records. It cannot resolve an IP address to a hostname in this context and has no bearing on layer 2 or layer 3 connectivity. Using it here would not help isolate the fault.
- ✓
traceroute 198.51.100.25
Why this is correct
Traceroute reveals the path packets take and where they stop. If the first hop (the gateway) responds but subsequent hops do not, the issue is beyond the local segment. If the first hop never responds, the problem may be layer 2 to the gateway or the gateway itself.
Visual reference
Go deeper
Related to this question
About these practice questions
One of 406 original LFCS practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Linux Foundation exam blueprint
This LFCS practice question is part of Courseiva's free Linux Foundation certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the LFCS exam.