220-1102 exam dumps

220-1102 practice question 600 of 828

A+ Core 2. Associate level, CompTIA. Free question with the correct answer and a full explanation.

220-1102 Question 600

Single answerConnectivity issues

A user reports that after connecting to the company's VPN from home, they can reach internal file shares by server name, but they cannot open any public websites in a browser. Before connecting to the VPN, internet access works normally. Other users on the same VPN service are not reporting this problem. You verify that the VPN connection establishes successfully and the user can access internal resources. Which of the following is the MOST likely cause?

  1. A

    The user's VPN connection is configured to tunnel all traffic, and the corporate VPN gateway is not properly forwarding internet-bound traffic

  2. B

    The user's home router is blocking DNS over HTTPS, preventing any website access while on the VPN

  3. C

    The user's browser cache is corrupted and must be cleared before public websites will load

  4. D

    The user's workstation has an incorrect local subnet mask, preventing access to external networks

Show answer and explanation

Correct answer: A

Explanation

The key troubleshooting clue is that internet access works before the VPN is connected, and internal corporate resources work after the VPN is connected. That means the endpoint has functional network connectivity, but traffic behavior changes when the VPN comes up. In a full-tunnel VPN design, the client sends all traffic through the VPN adapter. If the VPN concentrator, firewall, or gateway is not configured to allow or properly route/NAT internet-bound traffic, the user may lose public internet access while still reaching internal servers. This is a classic connectivity issue involving VPN routing and split-tunnel versus full-tunnel behavior. As a best practice, technicians should verify the client's routing table, VPN profile settings, DNS settings pushed by the VPN, and whether the organization intends to use split tunneling or full tunneling. Microsoft and common enterprise VPN vendors document that full-tunnel configurations redirect the default route through the VPN, which can affect internet connectivity if upstream routing is incomplete.

  • A. Correct.

    Correct. This scenario points to a full-tunnel VPN issue. The user can still resolve and reach internal resources after connecting, but public internet access fails only while the VPN is active. In a full-tunnel configuration, all traffic, including internet traffic, is sent through the VPN. If the VPN gateway or associated routing/NAT policies are not correctly handling internet-bound traffic for this user, public sites may become unreachable even though internal resources still work. This is a common real-world connectivity issue with remote users.

  • B. Incorrect.

    Incorrect. Blocking DNS over HTTPS on a home router would not typically explain why internet access works normally before the VPN but fails only after the VPN connection is established. Also, most browsing does not depend specifically on DNS over HTTPS; standard DNS resolution through the VPN or local resolver would still be possible depending on configuration. The symptom pattern is more consistent with VPN routing than a home-router content or protocol block.

  • C. Incorrect.

    Incorrect. A corrupted browser cache may cause problems with specific websites or stale content, but it would not reliably prevent access to all public websites only when the VPN is connected. The timing of the issue strongly suggests a network path or routing problem rather than an application-layer cache issue.

  • D. Incorrect.

    Incorrect. An incorrect local subnet mask can cause local network communication problems, inability to reach gateways, or issues accessing certain networks. However, if the user can connect to the VPN successfully and reach internal file shares by server name, the workstation's basic IP configuration is functioning well enough for network communication. The fact that the issue appears only after VPN connection makes the VPN routing configuration the more likely cause.

Timed practice exam

Take a 220-1102 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam