LFCS Networking Practice Question
The command 'ss -tuln' shows port 80 is listening on a server, but a remote client cannot connect via HTTP. What is the most likely cause?
⚠ Common exam trap
The trap here is that candidates see 'listening' on port 80 and assume the service is fully accessible, forgetting that a firewall can silently drop incoming packets even when the service is up and listening.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
A firewall is blocking incoming TCP port 80
The `ss -tuln` command shows that port 80 is in the LISTEN state, which means the HTTP service (e.g., Apache or Nginx) is bound to the port and ready to accept connections. Since the server is listening but the remote client cannot connect, the most likely cause is a firewall (such as iptables, nftables, or a cloud security group) that is blocking incoming TCP SYN packets destined for port 80, preventing the three-way handshake from completing.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The HTTP service is not running
Why it's wrong here
'ss -tuln' already proves a process holds port 80 in LISTEN state, so the service is running. This is tempting because a stopped service is the commonest cause of refused connections, but here the socket exists, so the fault lies in filtering or binding address.
- ✗
The client has a misconfigured default gateway
Why it's wrong here
A bad default gateway on the client would prevent reaching any remote subnet, not just port 80 on this host. It is tempting because gateway faults cause broad connectivity loss, but the stem implies other traffic may work, and the server-side listener is the specific evidence to explain.
- ✗
The server's /etc/hosts file is misconfigured
Why it's wrong here
/etc/hosts maps hostnames to addresses locally and cannot block inbound HTTP to a listening socket. It is tempting because name resolution failures do break connectivity, but that would affect the client resolving the server's name, not the server accepting TCP connections on port 80.
- ✓
A firewall is blocking incoming TCP port 80
Why this is correct
The socket is bound and listening, so the service itself is reachable locally; the failure occurs in transit. A firewall dropping or rejecting inbound TCP port 80 prevents the remote client's SYN from reaching the listener, which is the classic symptom here.
Visual reference
Go deeper
Related to this question
About these practice questions
One of 406 original LFCS practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This LFCS practice question is part of Courseiva's free Linux Foundation certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the LFCS exam.