220-1102 exam dumps

220-1102 practice question 538 of 828

A+ Core 2. Associate level, CompTIA. Free question with the correct answer and a full explanation.

220-1102 Question 538

Single answerIP filtering

A small business hosts an internal file server at 10.20.30.15. Employees in the 10.20.30.0/24 office network should be able to access the server, but guest Wi-Fi users on 10.20.40.0/24 must be prevented from connecting to it. The technician wants to use IP filtering on the server to meet this requirement without affecting employee access. Which action should the technician take?

  1. A

    Create an inbound IP filter that blocks traffic from source network 10.20.40.0/24 to the file server

  2. B

    Create an outbound IP filter that blocks traffic from destination network 10.20.40.0/24 on the file server

  3. C

    Disable DHCP on the guest Wi-Fi network so guest devices cannot get addresses in 10.20.40.0/24

  4. D

    Configure DNS to stop resolving the file server name for guest Wi-Fi users

Show answer and explanation

Correct answer: A

Explanation

The best answer is to block traffic from the guest subnet with an inbound IP filter on the file server. IP filtering is intended to permit or deny traffic based on source or destination IP information, making it a practical control for separating internal and guest access. In a real environment, administrators often enforce this at a host firewall or network firewall, but the core concept is the same: deny traffic from the untrusted subnet while allowing traffic from the trusted internal subnet. This aligns with standard security best practices such as least privilege and network segmentation. Microsoft Windows Defender Firewall and common host-based firewalls support rules based on remote IP addresses, which is a typical implementation of IP filtering for this type of requirement.

  • A. Correct.

    Correct. IP filtering is used to allow or deny traffic based on IP addresses. In this scenario, the goal is to stop guest devices from reaching the file server while still allowing office users. An inbound filter on the server that denies traffic originating from 10.20.40.0/24 directly addresses the requirement because it prevents connection attempts from the guest subnet from being accepted by the server.

  • B. Incorrect.

    Incorrect. An outbound filter on the server aimed at destination network 10.20.40.0/24 would control traffic leaving the server toward that subnet, not incoming connection attempts from guest clients to the server. While outbound filtering can be useful in other scenarios, it does not best solve the stated problem of blocking guest access to the file server.

  • C. Incorrect.

    Incorrect. Disabling DHCP on the guest network would disrupt guest connectivity rather than selectively preventing access to the file server. It is not an IP filtering solution and would create a broader service issue. Guests could also still use static IP addresses, so this does not reliably enforce the intended access control.

  • D. Incorrect.

    Incorrect. DNS controls name resolution, not actual network access. Even if guests could not resolve the hostname, they might still connect by using the server's IP address directly. This is a common misconception: hiding or limiting DNS responses is not the same as enforcing traffic restrictions.

Timed practice exam

Take a 220-1102 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam