Courseiva

LPIC-1 Essential System Services and Networking Practice Question

A user reports that they cannot connect to a remote server using SSH. The administrator checks the SSH server status and it is running. Which of the following is the most likely cause?

⚠ Common exam trap

It's easy for candidates to assume a running SSH server guarantees connectivity, overlooking that a firewall can block the port even when the service is active, or they may confuse SSH's TCP usage with UDP-based protocols like DNS.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

A firewall is blocking port 22.

SSH operates over TCP port 22 by default. If the SSH server is running but the client cannot connect, a firewall blocking port 22 is the most likely cause because it would prevent the TCP handshake from completing, even though the SSH daemon (sshd) is active and listening.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    A firewall is blocking port 22.

    Why this is correct

    With the SSH daemon confirmed running, a firewall dropping inbound TCP port 22 is the most likely cause, since the service listens but packets never reach it. This directly explains the connection failure despite a healthy server process.

  • ✗

    The client's subnet mask is incorrect.

    Why it's wrong here

    An incorrect subnet mask would disrupt local routing broadly, not selectively block SSH to one reachable server. It is tempting because mask errors do cause connectivity failures, but the likely cause is server-side filtering, wrong port, or firewall rules rather than the client mask.

  • ✗

    The client cannot resolve the server's hostname.

    Why it's wrong here

    SSH clients resolve hostnames via DNS or /etc/hosts before connecting, so a resolution failure produces a name error rather than a refused connection; the stem confirms the daemon runs, so the fault lies elsewhere. Hostname resolution would be the culprit only if the user connected by name and DNS were misconfigured.

  • ✗

    The SSH server is using UDP instead of TCP.

    Why it's wrong here

    SSH uses TCP.

Visual reference

Client Server SYN (seq=100) SYN-ACK (seq=200, ack=101) ACK (ack=201) Connection established — data transfer begins

About these practice questions

This LPIC-1 question is part of Courseiva's 402-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This LPIC-1 practice question is part of Courseiva's free LPI certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the LPIC-1 exam.