CompTIA · Free Practice Questions · Last reviewed May 2026
24real exam-style questions organised by domain, each with the correct answer highlighted and a plain-English explanation of why it's right — and why the others are wrong.
A user reports that their Windows 11 laptop takes several minutes to reach the desktop after signing in, and the desktop icons and taskbar appear one by one. No error messages are displayed. You open Task Manager and see that disk usage is at 100% for several minutes after logon. Which Windows tool should you use first to identify the specific startup program causing the delay?
System Configuration (msconfig) > Services tab
Task Manager > Startup tab
The Startup tab in Task Manager lists all programs configured to launch at user logon and shows an impact rating for each. Disabling or investigating high-impact entries directly addresses the slow post-logon behavior. It is the quickest built-in tool to identify which startup app is saturating disk I/O during sign-in.
Event Viewer > Windows Logs > Application
Performance Monitor with a Data Collector Set
A technician is upgrading a Windows 11 Pro workstation from a SATA SSD to a larger NVMe drive. The user needs to retain installed applications, user profiles, and the existing domain join. Which tool should the technician use to move the installation to the new drive without reinstalling Windows?
Disk Management's Extend Volume on the new disk after cloning
Windows System Image Backup (wbadmin) restore to the new disk
Third-party drive cloning software, such as Macrium Reflect or Clonezilla
Cloning software copies the entire partition structure and boot files from the SATA SSD to the NVMe drive, preserving Windows, installed applications, user profiles, and the domain join. After cloning, the technician can extend the system partition into remaining space. This is the standard method for a like-for-like drive upgrade when reinstalling is not acceptable.
Windows Recovery Environment's Reset this PC with Keep my files
A technician is troubleshooting a Windows 10 workstation that fails to boot. The technician suspects a problem with the boot configuration data (BCD). Which two commands can be used to rebuild the BCD? (Choose two.)
bootrec /fixboot
bootrec /fixmbr
bootrec /rebuildbcd
bootrec /rebuildbcd scans the disk for Windows installations and allows you to select which ones to add to the BCD store. It is a standard command in the Windows Recovery Environment to repair boot issues. This command directly addresses rebuilding the BCD, making it a correct choice.
bcdedit /export
bcdboot C:\Windows
bcdboot is a command-line tool that creates or repairs the BCD store and copies boot files. Running bcdboot C:\Windows rebuilds the BCD from the specified Windows directory. It is a valid method to rebuild the BCD, especially when the BCD is missing or corrupted. This makes it a correct choice.
A user calls the help desk because their Windows 11 laptop will not boot. The screen displays the message "Bootmgr is missing" immediately after the manufacturer logo. The technician needs to repair the boot configuration data so the system can start normally. Which command should the technician run from the Windows Recovery Environment?
bootrec /rebuildbcd
The /rebuildbcd switch scans all disks for Windows installations and lets the technician add missing entries to the Boot Configuration Data store. Because the error indicates that the boot manager cannot locate a valid BCD entry, rebuilding the BCD is the appropriate repair. This command directly addresses the missing or corrupted boot configuration that prevents Windows 11 from starting.
bootrec /fixmbr
chkdsk /f
sfc /scannow
A help desk technician receives a Windows 11 laptop that displays a message that the operating system cannot be found at startup. The drive is detected in firmware, and the technician wants to rebuild the boot configuration without reinstalling Windows. Which command should be run from the Windows Recovery Environment?
chkdsk C: /f /r
sfc /scannow
bootrec /fixmbr
bootrec /rebuildbcd
bootrec /rebuildbcd scans all disks for Windows installations and rebuilds the Boot Configuration Data store, re-creating the missing boot entry that produces the operating system not found error. Running it from the Windows Recovery Environment restores the ability to boot without reinstalling, and it works with both BIOS/MBR and UEFI/GPT configurations.
An administrator needs to deploy a standardized Windows 11 image to 40 new workstations and must remove the built-in consumer applications while preserving the Start layout and driver set. Which deployment approach best meets these requirements with the least manual effort per machine?
Install Windows manually on each PC, then run a PowerShell script to remove applications
Perform an in-place upgrade on each workstation using a mounted ISO
Use Windows Backup to restore a reference workstation's files to each new PC
Create a Windows system image with DISM and deploy it with an unattend.xml answer file
Capturing a generalized image with DISM and applying it through an answer file lets the administrator strip unwanted built-in applications, inject drivers, and apply a standard Start layout in one automated pass. The unattend.xml handles computer naming, domain join, and locale settings, so each of the 40 workstations receives an identical configuration without manual per-machine steps.
Want more Operating Systems practice?
Practice this domainA user reports that when they connect to the corporate Wi-Fi at a coffee shop, a browser warning appears stating the site's certificate is not trusted. The user is able to browse the internet but sees the warning on every HTTPS site. A technician suspects an on-path attack. Which of the following should the technician check FIRST to confirm the presence of an on-path attack?
The DNS server settings on the user's device and compare them to the corporate DNS servers.
The certificate chain presented by the browser to see if it is issued by an unknown or self-signed certificate authority.
An on-path attack often involves a self-signed or rogue CA certificate to intercept TLS traffic. Inspecting the certificate chain will reveal if the certificate is not issued by a trusted CA, confirming interception. This is the most direct evidence of an on-path attack, as the attacker must present a certificate to decrypt traffic, and it will not be trusted by the user's device.
The ARP cache on the user's device to look for duplicate MAC addresses.
The Wi-Fi encryption type configured on the user's device to ensure it is using WPA3.
A technician is configuring a Windows 11 workstation for a small business that handles credit card payments. The owner wants to ensure that stored cardholder data cannot be read if the drive is removed and attached to another computer. Which Windows feature should the technician enable?
BitLocker
BitLocker provides full volume encryption for Windows 11, protecting data at rest so a removed drive cannot be read on another system. Enabling it on the OS drive with a TPM satisfies the requirement to render cardholder data unreadable if the disk is physically stolen. It is the built-in Windows feature that directly addresses this scenario.
Encrypting File System (EFS)
Windows Defender Firewall
User Account Control (UAC)
A user reports that when visiting a banking website, the browser displays a warning that the site's certificate is not trusted, even though the site worked yesterday. The technician verifies the system clock is correct and the network is functioning. Which of the following is the MOST likely cause?
The user's account password has expired.
The root certificate for the issuing CA was removed from the Trusted Root Certification Authorities store.
If the root CA certificate is missing from the Trusted Root Certification Authorities store, the browser cannot build a chain of trust to the site's certificate, producing an untrusted warning. Since the clock and network are fine, removal of the root certificate is the most likely cause. Reinstalling the root CA or using a trusted root update resolves the issue.
The website's TLS certificate has expired.
The DNS server is resolving the banking site to an incorrect IP address.
A security analyst notices that several workstations on the same subnet are resolving popular banking domains to an IP address that belongs to an unknown server. The analyst confirms the DHCP server is legitimate and the DNS server settings have not been changed by Group Policy. Which of the following attacks is MOST likely occurring?
Evil twin
Domain hijacking
ARP poisoning
DNS poisoning
DNS poisoning corrupts the DNS resolver's cache so that legitimate domain names resolve to attacker-controlled IP addresses. Since DHCP and Group Policy are unchanged, the redirection of banking domains to an unknown server strongly indicates that the DNS cache has been poisoned. This allows the attacker to redirect users to malicious sites without altering client configuration.
A technician is asked to dispose of several old company laptops that contain sensitive customer data. The company wants to ensure the data cannot be recovered while still allowing the laptops to be donated. Which of the following should the technician perform?
Run a standard format on the drives.
Delete all partitions and create a new one.
Perform a secure erase or overwrite the drives.
Secure erase or overwriting writes patterns across the entire drive, making the original data unrecoverable while leaving the drive functional for donation. This satisfies both the security and reuse requirements. It is the appropriate sanitization method when the hardware will remain in service elsewhere.
Physically destroy the hard drives.
A user at a small office reports that whenever they connect to the corporate Wi-Fi in the break room, their laptop warns that the network is unsecured and other devices on the same network can see their traffic. The access point in the break room broadcasts an open SSID with no password. Which of the following should a technician configure on the access point to protect wireless traffic while keeping the SSID available to employees?
Enable WPA3-Personal with SAE
WPA3-Personal with Simultaneous Authentication of Equals replaces the WPA2 pre-shared key handshake with a password-authenticated key exchange, protecting the wireless traffic and preventing offline dictionary attacks. It keeps a single shared passphrase for employees while encrypting each session, directly addressing the open, unencrypted break-room network described.
Change the access point to operate on the 5 GHz band only
Disable SSID broadcast on the access point
Enable MAC address filtering for known employee devices
Want more Security practice?
Practice this domain23% of exam · 6 sample questions below
A user reports that after installing a new third-party backup utility, their Windows 11 computer takes several minutes to reach the desktop and shows a black screen with a spinning circle. The user wants to keep the backup utility but needs faster boot times. A technician opens Task Manager and notices the backup utility has a 'High' startup impact. Which of the following should the technician do FIRST to resolve the slow boot?
Disable the backup utility in the Startup tab of Task Manager.
Disabling the startup entry prevents the utility from launching at boot, directly addressing the high startup impact. The application remains installed and can be launched manually when needed, so the user keeps it while boot time improves. This is the least invasive first step before considering uninstallation or more drastic measures.
Perform a clean boot using msconfig and disable all non-Microsoft services.
Use msconfig to set the computer to Safe Boot with minimal services.
Run the System File Checker (sfc /scannow) to repair corrupted system files.
A user reports that their Windows 11 laptop occasionally shows a blue screen with the stop code CRITICAL_PROCESS_DIED. The issue occurs randomly, about once every two days. The user has not installed any new hardware or software recently. Which of the following should a technician perform FIRST to troubleshoot this issue?
Run the System File Checker (SFC) utility.
SFC is a built-in Windows tool that scans for and repairs corrupted system files, which can cause CRITICAL_PROCESS_DIED. Since the issue occurs randomly and no recent changes were made, corrupted system files are a likely cause. Running SFC is a safe, non-destructive first step that may resolve the problem without further disruption.
Update the graphics card driver to the latest version.
Replace the hard drive with a new solid-state drive (SSD).
Perform a clean installation of Windows 11.
A user reports that after installing a new third-party disk cleanup utility, Windows 11 randomly displays a blue screen with the stop code CRITICAL_PROCESS_DIED. The system boots normally in Safe Mode, and the issue does not occur there. Which of the following is the BEST first step to resolve the issue?
Run System File Checker (SFC) with the /scannow parameter.
Perform a System Restore to a point before the utility was installed.
Run the Windows Memory Diagnostic tool to test for faulty RAM.
Uninstall the third-party disk cleanup utility in Safe Mode.
The timeline directly links the new utility to the CRITICAL_PROCESS_DIED stop code, and the absence of crashes in Safe Mode confirms a third-party driver or service is responsible. Removing that utility in Safe Mode eliminates the faulty component and is the least invasive, most targeted first step before considering broader repairs.
A technician is troubleshooting a Windows 10 workstation that repeatedly displays a message stating "The User Profile Service failed the logon. User profile cannot be loaded." The user can log in with a different account. Which of the following should the technician do to allow the user to log in with their original profile while preserving their data?
Delete the user's profile folder from C:\Users and have the user log in again.
Recreate the user's account and copy the contents of the old profile folder to the new one.
Run the System File Checker (SFC) utility to repair corrupted system files.
Use the Registry Editor to modify the ProfileList key and remove the .bak extension from the user's SID.
This error often occurs when the user's profile is corrupted, and the ProfileList registry key may have a .bak extension appended to the user's SID. Removing the .bak extension and ensuring the correct profile path is set can restore the profile without losing data. This is a standard fix for this specific error.
A technician is troubleshooting a Windows 10 workstation that repeatedly shows a message stating the operating system could not be found. The drive is detected in UEFI/BIOS, and the technician suspects the boot configuration is damaged. Which command should the technician run from the Windows Recovery Environment to rebuild the Boot Configuration Data store?
chkdsk /r
bootrec /rebuildbcd
This command scans all disks for Windows installations and rebuilds the Boot Configuration Data store, which is exactly what is needed when the BCD is damaged and the OS cannot be located at boot. It is the targeted repair for this symptom on both BIOS and UEFI systems.
diskpart /clean
bootrec /fixmbr
A user reports that their Android smartphone is running very slowly, the battery drains quickly, and they see frequent pop-up ads even when not using the browser. The user installed several apps from a third-party app store recently. Which of the following is the MOST likely cause of these symptoms?
The device needs a factory reset to clear cache.
The device has been infected with malware.
The combination of slow performance, battery drain, and pop-up ads outside the browser is classic malware behavior on Android. Third-party app stores are common sources of malicious apps. Malware can run background processes, display ads, and steal resources, causing these exact symptoms.
The device's storage is nearly full.
The battery is failing and needs replacement.
Want more Software Troubleshooting practice?
Practice this domain21% of exam · 6 sample questions below
A technician is called to a user's desk where the user has left a sticky note with their password taped to the monitor. The technician needs to document this in the ticket. Which of the following should the technician do FIRST?
Report the security violation according to the organization's incident response policy.
Leaving a password visible is a security violation that must be reported through the proper incident response channel. This ensures the organization can investigate, educate the user, and enforce policies. Documenting and reporting is the first step before taking any corrective action that might destroy evidence or overstep the technician's authority.
Ignore it because it is the user's personal workspace and not the technician's concern.
Remove the sticky note and discard it, then close the ticket as resolved.
Take a photo of the sticky note and post it in the team chat as a joke.
A company is implementing a new policy that requires all employee laptops to have full-disk encryption enabled. A technician is asked to verify compliance on a Windows 11 Pro laptop. Which of the following tools should the technician use to check the encryption status?
Device Manager
Disk Management console
Task Manager
BitLocker Drive Encryption Control Panel applet
The BitLocker Drive Encryption Control Panel applet provides a straightforward interface to view the encryption status of each drive. It shows whether BitLocker is on or off, and the encryption method used. This is the correct tool for quickly verifying compliance with the full-disk encryption policy on a Windows 11 Pro system.
A user calls the help desk stating that their laptop screen is cracked and they need it replaced. The company policy requires that all hardware repairs be performed by the IT department. The user is remote and cannot come to the office. Which of the following should the technician do FIRST?
Instruct the user to purchase a replacement screen online and install it themselves.
Remote into the laptop and run diagnostics to confirm the screen is cracked.
Create a ticket, document the damage, and arrange for a depot repair or onsite service.
Following standard operating procedures, the technician should first create a ticket to document the issue, then arrange for repair according to company policy. Since the user is remote, a depot repair or authorized onsite service is appropriate. This ensures accountability and proper asset tracking. It also aligns with the requirement that IT performs all hardware repairs.
Ship the user a replacement laptop and have them return the damaged one.
A technician is preparing to dispose of several old hard drives that contain sensitive company data. The organization's data destruction policy requires physical destruction. Which of the following methods are appropriate for physically destroying the drives? (Choose two.)
Incineration
Incineration burns the drive at high temperatures, completely destroying the media and any data. This is a form of physical destruction that ensures no recoverable data remains. It must be performed in a controlled environment that meets environmental regulations. For organizations with strict data destruction policies, incineration is an appropriate method.
Shredding
Shredding physically breaks the drive into small pieces, making data recovery virtually impossible. This meets the requirement for physical destruction. Industrial shredders are designed for this purpose and can handle both HDDs and SSDs. It is a widely accepted method for secure data destruction when the media will not be reused.
Low-level formatting
Overwriting
Degaussing
A technician is preparing to replace a failed hard drive in a user's desktop PC. The drive contains sensitive company data. The technician wants to ensure proper disposal of the old drive and maintain data security. Which of the following TWO actions should the technician take? (Choose two.)
Use a software tool to perform a secure erase or wipe.
A secure erase or wipe overwrites the entire drive with random data, making recovery extremely difficult. This is a valid method for sanitizing storage media before disposal or reuse. It complies with data security policies and is appropriate when physical destruction is not feasible. The technician should verify the wipe completed successfully.
Run a standard format on the drive before disposal.
Delete all partitions and recreate a single empty partition.
Physically destroy the drive by shredding or degaussing.
Physical destruction ensures that data cannot be recovered, which is critical for sensitive company data. Shredding or degaussing renders the drive unusable and is a recommended method for end-of-life storage media. This action aligns with data security policies and prevents data remanence. It is especially important if the drive is not being reused or if encryption was not employed.
Store the drive in a secure cabinet until it can be reused.
A technician is troubleshooting a Windows 10 workstation that is running very slowly. The technician suspects a malware infection. Which of the following should the technician do FIRST according to best practices for malware removal?
Quarantine the system by disconnecting it from the network.
Disconnecting the system from the network prevents the malware from spreading or communicating with command-and-control servers. This is the first step in the malware removal process to contain the infection. It also preserves evidence and prevents further damage while the technician investigates. Quarantining is a critical initial action before attempting removal.
Restore the system from a known good backup.
Educate the end user about safe browsing habits.
Run a full antivirus scan immediately.
Want more Operational Procedures practice?
Practice this domainThe 220-1202 exam has 90 questions and must be completed in 90 minutes. The passing score is 700/1000.
Multiple-choice and performance-based questions covering IT security, networking, and operations. Some questions are performance-based (PBQs), asking you to complete tasks in a simulated environment.
The exam covers 4 domains: Operating Systems, Security, Software Troubleshooting, Operational Procedures. Questions are weighted by domain — higher-weight domains appear more on your actual exam.
No. These are original exam-style practice questions written against the official CompTIA 220-1202 exam objectives. They are not copied from the real exam. Courseiva focuses on genuine understanding, not memorisation of braindumps.
Courseiva tracks your accuracy per domain and routes you toward weak areas automatically. Free, no account required.