Courseiva
Networking →hardMultiple Select

LFCS Networking Practice Question

An administrator is diagnosing why a server cannot reach the host 198.51.100.25. The server has one interface, eth0, with address 192.0.2.10/24. Running `ip route show` returns only the default route via 192.0.2.1. Which two commands will help determine whether the problem is at layer 2 or layer 3? (Choose two.)

⚠ Common exam trap

The trap here is selecting commands that show local socket or interface state instead of tools that test reachability and neighbor resolution.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

ip neigh show 192.0.2.1

To isolate layer 2 versus layer 3, check the neighbor table for the gateway and trace the path to the destination. An unresolved neighbor entry points to a layer 2 problem, while a resolved entry with a traceroute that stops beyond the first hop points to layer 3 or higher. Interface state and DNS queries do not make this distinction.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    ip neigh show 192.0.2.1

    Why this is correct

    This command displays the ARP/neighbor table entry for the gateway. If the gateway's MAC address is unresolved or shows FAILED, the problem is at layer 2. If it is REACHABLE, layer 2 to the gateway is working, and the issue is likely at layer 3 or beyond.

  • ✗

    ss -tulnp | grep 198.51.100.25

    Why it's wrong here

    The `ss` command lists local listening sockets and established connections. It does not test reachability to a remote host and would not show any useful information about a destination that is not a local listener. This is irrelevant to the diagnostic goal.

  • ✗

    ip link show eth0

    Why it's wrong here

    This shows interface flags and state such as UP or DOWN. While useful to confirm the interface is up, it does not distinguish layer 2 from layer 3 problems for a specific destination, because the link can be up while ARP or routing fails.

  • ✗

    dig +short 198.51.100.25

    Why it's wrong here

    The `dig` command queries DNS records. It cannot resolve an IP address to a hostname in this context and has no bearing on layer 2 or layer 3 connectivity. Using it here would not help isolate the fault.

  • ✓

    traceroute 198.51.100.25

    Why this is correct

    Traceroute reveals the path packets take and where they stop. If the first hop (the gateway) responds but subsequent hops do not, the issue is beyond the local segment. If the first hop never responds, the problem may be layer 2 to the gateway or the gateway itself.

Visual reference

Client Recursive Resolver Root DNS (13 root servers) TLD DNS (.com, .org, …) Authoritative example.com query IP addr answer

About these practice questions

One of 406 original LFCS practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Linux Foundation exam blueprint

This LFCS practice question is part of Courseiva's free Linux Foundation certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the LFCS exam.