Reinforce 220-1202 concepts with active-recall study cards covering all 4 blueprint domains. Each card shows the question on the front and the correct answer with a full explanation on the back.
Flashcards work through active recall — the process of retrieving information from memory rather than passively re-reading it. Research consistently shows that active recall produces stronger, longer-lasting memory than re-reading study guides. For 220-1202 preparation, this means flashcards are one of the highest-return study tools available.
Attempt recall first
Read the 220-1202 question on each card, pause, and attempt to formulate the answer in your own words before revealing. This retrieval attempt — even if wrong — dramatically strengthens memory compared to immediately reading the answer.
Review wrong cards again
When you get a card wrong, note it and add it back to your review pile. Spaced repetition — seeing difficult cards more frequently — is the mechanism that makes flashcard study far more efficient than linear reading.
Study by domain
Group your 220-1202 flashcard sessions by domain for the first 3–4 weeks. Master one domain before moving to the next. In the final week, shuffle all cards together to test cross-domain recall — which is what the real 220-1202 exam requires.
Short sessions beat marathon reviews
20–30 flashcard cards per session, done daily, produces better retention than a single 200-card marathon session. Five short daily sessions per week over 4 weeks gives you over 400 total card reviews — enough to reliably pass 220-1202.
Sample cards from the 220-1202 flashcard bank. Read the question, think of the answer, then read the explanation below.
A user reports that their Windows 11 laptop takes several minutes to reach the desktop after signing in, and the desktop icons and taskbar appear one by one. No error messages are displayed. You open Task Manager and see that disk usage is at 100% for several minutes after logon. Which Windows tool should you use first to identify the specific startup program causing the delay?
Task Manager > Startup tab
Task Manager's Startup tab is the built-in tool that specifically lists programs set to run at logon and provides an impact rating based on resource usage. Since the symptom is slow logon with high disk usage, checking this tab lets you quickly identify and disable the offending startup app. Other tools are either too broad or focus on the wrong object.
A technician is upgrading a Windows 11 Pro workstation from a SATA SSD to a larger NVMe drive. The user needs to retain installed applications, user profiles, and the existing domain join. Which tool should the technician use to move the installation to the new drive without reinstalling Windows?
Third-party drive cloning software, such as Macrium Reflect or Clonezilla
Cloning is the correct migration path because it duplicates the source disk's partitions and boot configuration onto the new NVMe drive, so the installed applications, profiles, and domain membership continue to work. Image-based restore and reset operations either rebuild the layout or strip applications, and Extend Volume cannot populate a blank disk.
A user calls the help desk because their Windows 11 laptop will not boot. The screen displays the message "Bootmgr is missing" immediately after the manufacturer logo. The technician needs to repair the boot configuration data so the system can start normally. Which command should the technician run from the Windows Recovery Environment?
bootrec /rebuildbcd
The "Bootmgr is missing" error means the boot manager cannot find a valid Boot Configuration Data entry for the Windows installation. The bootrec /rebuildbcd command scans for Windows installations and rebuilds the BCD store, directly resolving this issue. Other recovery commands address different problems such as MBR corruption, system file damage, or disk errors, and would not restore the missing boot entry.
A help desk technician receives a Windows 11 laptop that displays a message that the operating system cannot be found at startup. The drive is detected in firmware, and the technician wants to rebuild the boot configuration without reinstalling Windows. Which command should be run from the Windows Recovery Environment?
bootrec /rebuildbcd
The missing operating system message on a detected drive usually means the Boot Configuration Data store lacks a valid entry. Rebuilding it with bootrec /rebuildbcd from the recovery environment re-creates the Windows Boot Manager entry and restores startup without a full reinstall.
An administrator needs to deploy a standardized Windows 11 image to 40 new workstations and must remove the built-in consumer applications while preserving the Start layout and driver set. Which deployment approach best meets these requirements with the least manual effort per machine?
Create a Windows system image with DISM and deploy it with an unattend.xml answer file
A DISM-captured image applied with an unattend.xml answer file delivers a consistent, automated deployment. The administrator can remove built-in applications during image preparation, inject drivers, and define the Start layout once, then apply the same image to all 40 workstations with minimal per-machine interaction.
A user reports that when they connect to the corporate Wi-Fi at a coffee shop, a browser warning appears stating the site's certificate is not trusted. The user is able to browse the internet but sees the warning on every HTTPS site. A technician suspects an on-path attack. Which of the following should the technician check FIRST to confirm the presence of an on-path attack?
The certificate chain presented by the browser to see if it is issued by an unknown or self-signed certificate authority.
The certificate chain is the most direct evidence of an on-path attack because the attacker must present a certificate to intercept TLS traffic. If the certificate is self-signed or issued by an untrusted CA, the browser will warn the user. DNS or ARP checks might reveal other attack vectors, but the certificate warning specifically indicates TLS interception, so examining the certificate chain confirms the attack.
A technician is configuring a Windows 11 workstation for a small business that handles credit card payments. The owner wants to ensure that stored cardholder data cannot be read if the drive is removed and attached to another computer. Which Windows feature should the technician enable?
BitLocker
BitLocker encrypts the entire volume, so if the drive is removed and connected to another computer, the data remains unreadable without the recovery key or the original TPM. EFS, firewall rules, and UAC do not provide full-volume encryption, so they fail the physical-theft requirement. BitLocker is the correct built-in Windows feature for protecting data at rest.
A user reports that when visiting a banking website, the browser displays a warning that the site's certificate is not trusted, even though the site worked yesterday. The technician verifies the system clock is correct and the network is functioning. Which of the following is the MOST likely cause?
The root certificate for the issuing CA was removed from the Trusted Root Certification Authorities store.
A browser trusts a TLS certificate only if it can chain it to a root CA in the Trusted Root Certification Authorities store. If that root was removed, the chain breaks and the browser warns that the certificate is not trusted. An expired certificate or DNS problem could also cause warnings, but the sudden failure with a correct clock points to a missing root certificate.
A security analyst notices that several workstations on the same subnet are resolving popular banking domains to an IP address that belongs to an unknown server. The analyst confirms the DHCP server is legitimate and the DNS server settings have not been changed by Group Policy. Which of the following attacks is MOST likely occurring?
DNS poisoning
DNS poisoning inserts false records into a DNS resolver's cache, so clients receive attacker-controlled IP addresses for legitimate names. Because DHCP and Group Policy are intact, the misdirection must come from the DNS layer. Evil twin, ARP poisoning, and domain hijacking do not match the specific symptom of multiple clients resolving banking domains to an unknown server.
A technician is asked to dispose of several old company laptops that contain sensitive customer data. The company wants to ensure the data cannot be recovered while still allowing the laptops to be donated. Which of the following should the technician perform?
Perform a secure erase or overwrite the drives.
Secure erase or overwriting renders the original data unrecoverable while keeping the drive usable, so the laptops can be donated. Physical destruction prevents donation, and formatting or repartitioning leaves recoverable data. The technician should choose a sanitization method that meets both the security and reuse goals.
A user reports that after installing a new third-party backup utility, their Windows 11 computer takes several minutes to reach the desktop and shows a black screen with a spinning circle. The user wants to keep the backup utility but needs faster boot times. A technician opens Task Manager and notices the backup utility has a 'High' startup impact. Which of the following should the technician do FIRST to resolve the slow boot?
Disable the backup utility in the Startup tab of Task Manager.
Task Manager's Startup tab shows the impact of each startup program. When a specific application is flagged as high impact and the timing correlates with its installation, disabling that startup entry is the most direct and least disruptive fix. It preserves the application for manual use and avoids unnecessary system-wide changes.
A user reports that their Windows 11 laptop occasionally shows a blue screen with the stop code CRITICAL_PROCESS_DIED. The issue occurs randomly, about once every two days. The user has not installed any new hardware or software recently. Which of the following should a technician perform FIRST to troubleshoot this issue?
Run the System File Checker (SFC) utility.
CRITICAL_PROCESS_DIED indicates that a critical system process has terminated unexpectedly, often due to corrupted system files. Running System File Checker (SFC) is a standard first step because it can repair those files without data loss. Other options are either too invasive or target the wrong subsystem, making SFC the most appropriate initial action.
A user reports that after installing a new third-party disk cleanup utility, Windows 11 randomly displays a blue screen with the stop code CRITICAL_PROCESS_DIED. The system boots normally in Safe Mode, and the issue does not occur there. Which of the following is the BEST first step to resolve the issue?
Uninstall the third-party disk cleanup utility in Safe Mode.
The crash appeared only after installing a third-party cleanup tool and does not occur in Safe Mode, which strongly indicates a problematic third-party driver or service. Uninstalling that utility in Safe Mode removes the offending component directly. Broader repairs like SFC, System Restore, or memory testing are either unnecessary or address causes not supported by the evidence.
A technician is troubleshooting a Windows 10 workstation that repeatedly displays a message stating "The User Profile Service failed the logon. User profile cannot be loaded." The user can log in with a different account. Which of the following should the technician do to allow the user to log in with their original profile while preserving their data?
Use the Registry Editor to modify the ProfileList key and remove the .bak extension from the user's SID.
The "User Profile Service failed the logon" error typically stems from a corrupted user profile, often indicated by a .bak extension on the user's SID in the ProfileList registry key. Removing the .bak extension and correcting the profile path restores the original profile without data loss. Other methods either delete data or are less direct.
A technician is called to a user's desk where the user has left a sticky note with their password taped to the monitor. The technician needs to document this in the ticket. Which of the following should the technician do FIRST?
Report the security violation according to the organization's incident response policy.
The correct action is to report the security violation according to policy. Passwords left in plain sight are a serious security risk that must be escalated through proper channels. This allows the organization to handle the situation consistently, educate the user, and prevent similar incidents. Taking direct action like removing the note or sharing it could interfere with investigations or violate privacy.
A company is implementing a new policy that requires all employee laptops to have full-disk encryption enabled. A technician is asked to verify compliance on a Windows 11 Pro laptop. Which of the following tools should the technician use to check the encryption status?
BitLocker Drive Encryption Control Panel applet
The BitLocker Drive Encryption Control Panel applet is the correct tool to check encryption status. It provides a clear indication of whether BitLocker is enabled and the encryption progress. Other tools like Device Manager, Disk Management, and Task Manager do not offer this specific information. Using the correct tool ensures accurate compliance verification.
A user calls the help desk stating that their laptop screen is cracked and they need it replaced. The company policy requires that all hardware repairs be performed by the IT department. The user is remote and cannot come to the office. Which of the following should the technician do FIRST?
Create a ticket, document the damage, and arrange for a depot repair or onsite service.
The first action is to create a ticket, document the damage, and arrange for repair via depot or onsite service. This complies with company policy, ensures proper asset tracking, and addresses the remote user's needs. Other options either bypass policy, delay the process, or fail to follow standard operating procedures. Proper documentation and authorized repair channels are essential.
The 220-1202 flashcard bank covers all 4 official blueprint domains published by CompTIA. Cards are distributed proportionally, so domains with higher exam weight have more cards.
Domain Coverage
Operating Systems
Security
Software Troubleshooting
Operational Procedures
Both flashcards and practice questions are evidence-based study tools. The difference is in what they train:
Flashcards — concept retention
Best for memorising definitions, acronyms, protocol behaviours, command syntax, and conceptual distinctions. Use flashcards to build the foundational vocabulary that 220-1202 questions assume you know.
Best in: weeks 1–3
Practice tests — application
Best for applying concepts to realistic scenarios, eliminating distractors, and building exam stamina.220-1202 questions test scenario reasoning — not just recall — so practice tests are essential.
Best in: weeks 3–6
The most effective 220-1202 study plan combines both: use flashcards for the first 2–3 weeks to build conceptual foundations, then shift to practice tests and mock exams in the final 2–3 weeks to apply and benchmark that knowledge. Most candidates who pass on their first attempt use both tools.
Yes. Courseiva provides free 220-1202 flashcards across all official exam domains. Every card includes the correct answer and a full explanation of why it is right and why the distractors are wrong. The platform also includes topic-based practice, mock exams, and readiness tracking — no account required.
Courseiva has 687+ original 220-1202 flashcards across all 4 exam blueprint domains. New cards are added regularly as the question bank grows. All cards are checked against the official CompTIA exam objectives, with editorial oversight from an experienced network and security engineer.
Courseiva flashcards are purpose-built for IT certification exams. Unlike generic flashcard platforms where content quality varies, every Courseiva card is mapped to the official 220-1202 exam blueprint, written by engineers who hold the certification, and includes a full explanation of the correct answer and why the distractors are wrong. This explanation quality is what separates genuine learning from rote memorisation.
Courseiva is a web platform — an internet connection is required. For offline study, we recommend creating free Courseiva account, using the platform in your browser, and using your device's offline capabilities if your browser supports offline web apps.
Save your results, see which domains need more work, and get spaced repetition recommendations — all free.
Sign Up FreeFree forever · Every certification included