LFCS Networking Practice Question
An administrator is troubleshooting name resolution on a server. Queries for internal names succeed, but every query for external names fails with 'connection timed out; no servers could be reached'. The file /etc/resolv.conf contains 'nameserver 10.20.30.40' and 'nameserver 10.20.30.41'. The internal DNS servers are reachable, and the administrator wants to test which external name servers actually respond. Which command best performs this test?
⚠ Common exam trap
The trap here is running dig without an @server argument, which silently reuses the resolv.conf servers that are already known to be failing for external names.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
dig @8.8.8.8 example.com
To determine whether an external resolver responds, the query must be sent directly to that resolver rather than to the servers in resolv.conf. The dig command's @server syntax does exactly this, bypassing local configuration. If a direct query to a public resolver succeeds, the problem is with the internal servers' forwarding or recursion; if it fails, outbound DNS traffic is likely blocked.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
getent hosts example.com
Why it's wrong here
The getent command consults the Name Service Switch and therefore uses the same configured sources, including the internal DNS servers. It cannot target an arbitrary external resolver, so it would reproduce the existing failure rather than test an alternative name server.
- ✗
nslookup 8.8.8.8 example.com
Why it's wrong here
The nslookup syntax here is reversed: the first argument is treated as the name to resolve and the second as the server, so this attempts to resolve the literal name 8.8.8.8 using example.com as a server. It is both incorrectly formed and uses a deprecated tool, so it will not perform the intended test.
- ✗
dig example.com
Why it's wrong here
Without an @server argument, dig queries the name servers listed in /etc/resolv.conf, which are exactly the internal servers already known to fail for external names. This repeats the failing path and provides no new information about whether an external resolver would respond.
- ✓
dig @8.8.8.8 example.com
Why this is correct
The dig command with an explicit @server argument sends the query directly to that name server, bypassing the servers listed in resolv.conf. This lets the administrator confirm whether an external resolver answers, isolating whether the failure lies with the configured internal servers or with outbound DNS connectivity.
Visual reference
Go deeper
Related to this question
About these practice questions
One of 406 original LFCS practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Linux Foundation exam blueprint
This LFCS practice question is part of Courseiva's free Linux Foundation certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the LFCS exam.