Courseiva
Networking →hardMultiple Choice

LFCS Networking Practice Question

An administrator is troubleshooting name resolution on a server. Queries for internal names succeed, but every query for external names fails with 'connection timed out; no servers could be reached'. The file /etc/resolv.conf contains 'nameserver 10.20.30.40' and 'nameserver 10.20.30.41'. The internal DNS servers are reachable, and the administrator wants to test which external name servers actually respond. Which command best performs this test?

⚠ Common exam trap

The trap here is running dig without an @server argument, which silently reuses the resolv.conf servers that are already known to be failing for external names.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

dig @8.8.8.8 example.com

To determine whether an external resolver responds, the query must be sent directly to that resolver rather than to the servers in resolv.conf. The dig command's @server syntax does exactly this, bypassing local configuration. If a direct query to a public resolver succeeds, the problem is with the internal servers' forwarding or recursion; if it fails, outbound DNS traffic is likely blocked.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    getent hosts example.com

    Why it's wrong here

    The getent command consults the Name Service Switch and therefore uses the same configured sources, including the internal DNS servers. It cannot target an arbitrary external resolver, so it would reproduce the existing failure rather than test an alternative name server.

  • ✗

    nslookup 8.8.8.8 example.com

    Why it's wrong here

    The nslookup syntax here is reversed: the first argument is treated as the name to resolve and the second as the server, so this attempts to resolve the literal name 8.8.8.8 using example.com as a server. It is both incorrectly formed and uses a deprecated tool, so it will not perform the intended test.

  • ✗

    dig example.com

    Why it's wrong here

    Without an @server argument, dig queries the name servers listed in /etc/resolv.conf, which are exactly the internal servers already known to fail for external names. This repeats the failing path and provides no new information about whether an external resolver would respond.

  • ✓

    dig @8.8.8.8 example.com

    Why this is correct

    The dig command with an explicit @server argument sends the query directly to that name server, bypassing the servers listed in resolv.conf. This lets the administrator confirm whether an external resolver answers, isolating whether the failure lies with the configured internal servers or with outbound DNS connectivity.

Visual reference

Client Recursive Resolver Root DNS (13 root servers) TLD DNS (.com, .org, …) Authoritative example.com query IP addr answer

About these practice questions

One of 406 original LFCS practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Linux Foundation exam blueprint

This LFCS practice question is part of Courseiva's free Linux Foundation certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the LFCS exam.