Courseiva

CompTIA A+ Core 2 220-1202 (220-1202) — Questions 676–687

687 questions total · 10pages · All types, answers revealed

Page 9

Page 10 of 10

676
MCQeasy

A user calls the help desk, frustrated that their laptop 'keeps freezing' during video conferences. They admit they have 15 browser tabs open, are running a resource-heavy design app, and have not restarted the laptop in three weeks. The technician needs to recommend a solution while maintaining professionalism. What should the technician say first?

A."You need to close some tabs and restart your laptop immediately."
B."I understand that's frustrating. Let's look at what might be causing this. Have you noticed it happens when certain programs are open?"
C."That's because you never restart your computer. You should do that weekly."
D."Let me transfer you to our advanced support team for this issue."
AnswerB

This response effectively combines empathy with a structured diagnostic approach, which is crucial for effective technical support. Acknowledging the user's frustration builds rapport, while immediately asking about specific program usage helps narrow down potential causes, such as resource-intensive applications, memory leaks, or software conflicts. This collaborative inquiry is a foundational step in troubleshooting, guiding the technician toward a more precise solution rather than guessing or making assumptions.

Why this answer

It first validates the user's frustration (professionalism) and then uses a probing question to gather diagnostic data about the specific conditions causing the freezing. This aligns with the CompTIA A+ troubleshooting methodology (identify the problem) and maintains rapport, which is critical for customer satisfaction. The technician avoids premature blame or dismissal, instead focusing on correlating the symptom (freezing) with resource contention from the browser tabs and design app.

Exam trap

CompTIA often tests the candidate's ability to prioritize professional communication over technical action; the trap here is that many candidates jump to a technical fix (Option A or C) instead of first acknowledging the user's issue and gathering information, which is the correct first step in the troubleshooting process.

How to eliminate wrong answers

Option A is wrong because it issues a direct command without acknowledging the user's frustration or gathering additional context, which violates professional communication standards and may escalate the user's frustration. Option C is wrong because it blames the user for not restarting, which is unprofessional and dismissive; it also assumes the root cause without verifying whether the freezing is due to memory leaks, driver issues, or thermal throttling. Option D is wrong because it escalates prematurely without attempting basic triage; the issue is likely within the technician's scope (resource management and reboot), and transferring without effort wastes time and frustrates the user further.

677
MCQeasy

A user reports that after a Windows update, their default browser keeps resetting to Microsoft Edge every time they restart the computer. They need to keep Google Chrome as the default. Which Control Panel or Settings applet should you use to permanently change this setting?

A.Programs and Features
B.Default Apps
C.Internet Options
D.Device Manager
AnswerB

The "Default Apps" section within Windows Settings is the designated interface for users to configure which applications open specific file types, protocols, or perform common tasks like web browsing or email. This centralized location allows for granular control over application associations, ensuring that user preferences for default programs are correctly registered and ideally maintained across system updates, although occasional resets can occur. It directly addresses the problem of default application settings being altered.

Why this answer

The Default Apps settings page (Settings > Apps > Default Apps) is the correct location in Windows 10/11 to permanently set Google Chrome as the default browser. This applet allows you to choose a specific browser for the HTTP, HTTPS, and .HTM/.HTML file associations. After a Windows update, these associations can be reset to Microsoft Edge; re-selecting Chrome here and confirming the change ensures the setting persists across reboots.

Exam trap

The trap here is that candidates confuse the 'Set your default programs' link inside Internet Options with the actual Default Apps page, not realizing that Internet Options only provides a shortcut to the same Settings page and does not itself store or manage the association data.

How to eliminate wrong answers

Option A (Programs and Features) is wrong because it is used for uninstalling, changing, or repairing installed programs, not for configuring file or protocol associations. Option C (Internet Options) is wrong because while it contains a 'Programs' tab with a 'Set programs' link, that link redirects to the Default Apps page; the Internet Options applet itself does not directly manage default browser associations. Option D (Device Manager) is wrong because it manages hardware devices and drivers, not software or default application settings.

678
MCQmedium

You are deploying a new application to multiple Windows 10 workstations using a script. The application requires administrator privileges, and you need to run the command with elevated rights from within the script. Which command should precede your installation command?

A.runas /user:Administrator
B.net user
C.cd
D.whoami
AnswerA

This command runs the subsequent program with administrator privileges, as required for the installation.

Why this answer

The `runas /user:Administrator` command allows you to execute a subsequent command with the security context of the specified user (in this case, the built-in Administrator account), which provides the elevated privileges required to install the application. This is necessary because the script itself runs under the current user's context, which may lack the administrative rights needed for the installation.

Exam trap

CompTIA often tests the misconception that `runas` is the only way to elevate privileges within a script, but the trap here is that candidates might confuse `runas` with simply running the script itself as Administrator, forgetting that the command must explicitly precede the installation command to elevate that specific process.

How to eliminate wrong answers

Option B is wrong because `net user` is used to manage user accounts (create, delete, or modify) and does not execute a command with elevated privileges. Option C is wrong because `cd` changes the current directory and has no capability to elevate permissions. Option D is wrong because `whoami` displays the current user's username and security context but does not alter or elevate privileges.

679
MCQhard

A security analyst notices that several workstations on the same subnet are resolving popular banking domains to an IP address that belongs to an unknown server. The analyst confirms the DHCP server is legitimate and the DNS server settings have not been changed by Group Policy. Which of the following attacks is MOST likely occurring?

A.Evil twin
B.Domain hijacking
C.ARP poisoning
D.DNS poisoning
AnswerD

DNS poisoning corrupts the DNS resolver's cache so that legitimate domain names resolve to attacker-controlled IP addresses. Since DHCP and Group Policy are unchanged, the redirection of banking domains to an unknown server strongly indicates that the DNS cache has been poisoned. This allows the attacker to redirect users to malicious sites without altering client configuration.

Why this answer

DNS poisoning inserts false records into a DNS resolver's cache, so clients receive attacker-controlled IP addresses for legitimate names. Because DHCP and Group Policy are intact, the misdirection must come from the DNS layer. Evil twin, ARP poisoning, and domain hijacking do not match the specific symptom of multiple clients resolving banking domains to an unknown server.

Exam trap

The trap here is confusing DNS poisoning with ARP poisoning, because both can redirect traffic, but only DNS poisoning changes name resolution results.

680
MCQeasy

A customer complains that their Windows 10 PC fails to boot and displays a 'Bootmgr is missing' error. You suspect the Boot Configuration Data (BCD) is corrupted. Which tool should you use to repair the BCD from the Windows Recovery Environment?

A.chkdsk /f
B.sfc /scannow
C.bootrec /rebuildbcd
D.diskpart
AnswerC

The bootrec /rebuildbcd command is specifically designed to scan all hard drives for compatible Windows installations and then reconstruct the Boot Configuration Data (BCD) store. This process effectively creates a new BCD store, incorporating any found Windows operating systems, which is critical for resolving boot failures caused by a corrupted or missing BCD. It directly addresses the boot configuration, enabling the Windows Boot Manager to locate and load the operating system.

Why this answer

The 'Bootmgr is missing' error indicates that the Windows Boot Manager cannot locate or read the Boot Configuration Data (BCD) store. The bootrec /rebuildbcd command, run from the Windows Recovery Environment, scans the disk for Windows installations and rebuilds the BCD store, restoring the boot configuration. This is the correct tool for repairing a corrupted BCD.

Exam trap

220-1202 often tests the confusion between boot repair tools — candidates may select sfc or chkdsk for boot issues when the specific error points to BCD corruption requiring bootrec /rebuildbcd.

How to eliminate wrong answers

Option A is wrong because chkdsk /f checks and repairs file system integrity and disk errors; it does not rebuild the BCD store and would not resolve a 'Bootmgr is missing' error caused by BCD corruption. Option B is wrong because sfc /scannow scans and repairs protected Windows system files but requires a booted OS to run and does not address boot configuration data. Option D is wrong because diskpart is a disk partitioning tool used to create, delete, and manage partitions; it does not repair boot configuration or BCD entries.

681
MCQhard

While configuring a new Windows 11 workstation, you need to ensure that a legacy application can always run with administrative privileges without prompting the user. The user is a standard user. What is the best way to accomplish this?

A.Set the application's compatibility mode to 'Run this program as an administrator' and grant the user full control over the program's folder.
B.Create a scheduled task that runs with the highest privileges and launches the application at user logon.
C.Disable User Account Control (UAC) via the Control Panel.
D.Add the user to the local Administrators group.
AnswerB

A scheduled task can be configured to run with stored administrator credentials and launch the application without any UAC prompt. This is the supported method for standard users to run legacy apps that require elevation.

Why this answer

Forcing a legacy app to run as administrator without UAC prompts for a standard user requires creating a scheduled task that runs with elevated privileges. The task can be set to run at user logon or on demand, and the application is launched by the task with the stored admin credentials. This bypasses UAC while maintaining security for the standard user account.

682
MCQeasy

A user calls the help desk, frantic because they received an email from what appears to be the CEO asking them to urgently purchase $500 in gift cards for a client and reply with the codes. The email address looks slightly off, and the signature is missing the usual legal disclaimer. What type of social engineering attack is this most likely an example of?

A.Shoulder surfing
B.Phishing
C.Tailgating
D.Pretexting
AnswerB

Phishing is a highly prevalent social engineering attack where cybercriminals send fraudulent communications, typically emails, designed to appear as if they originate from a legitimate and trustworthy source. The primary objective is to deceive recipients into revealing sensitive information, such as login credentials or financial details, or to perform harmful actions like purchasing gift cards. The scenario involving deceptive emails prompting gift card purchases perfectly aligns with the definition and common tactics of a phishing attack.

Why this answer

This is a classic example of phishing, specifically a subtype known as spear phishing or whaling, because the attacker impersonates a high-level executive (the CEO) to trick the user into performing a financial action. The telltale signs are the slightly off email address (spoofed domain or lookalike character) and the missing legal disclaimer, which are common indicators of a fraudulent email designed to harvest credentials or money. Phishing relies on social engineering to bypass technical controls by exploiting human trust and urgency.

Exam trap

The CompTIA A+ exam often tests the distinction between phishing and pretexting by presenting a scenario where the attacker uses a fabricated story (pretext) but delivers it via email, leading candidates to choose pretexting instead of recognizing that the email delivery method makes it phishing.

How to eliminate wrong answers

Option A is wrong because shoulder surfing involves directly observing a user's screen or keystrokes over their shoulder to capture sensitive information, which does not apply to an email-based request. Option C is wrong because tailgating is a physical security attack where an unauthorized person follows an authorized individual into a restricted area without proper authentication, not a digital email scam. Option D is wrong because pretexting is a social engineering technique where the attacker fabricates a scenario (pretext) to obtain information, often via phone or in person, but the core mechanism here is the fraudulent email itself, which is the defining characteristic of phishing.

683
MCQmedium

A small business owner reports that all their employees are receiving emails from each other containing a link that, when clicked, downloads a file that installs a program that spreads to other contacts. The emails appear to come from known senders. What type of malware is this?

A.Virus
B.Worm
C.Trojan horse
D.Rootkit
AnswerB

A worm is a standalone malicious program that replicates itself to spread to other computers, often exploiting network vulnerabilities or sending copies via email attachments. Unlike viruses, worms do not need to attach to an existing program and can operate independently. They are designed to self-propagate across networks, consuming bandwidth and system resources, making them a highly effective method for widespread infection without direct user intervention beyond the initial compromise.

Why this answer

(Worm) because the malware self-replicates by sending copies of itself via email to all contacts without requiring user action beyond clicking the link. Unlike a virus, it does not need to attach to a host file; it spreads autonomously over the network using the email system as a transport mechanism.

Exam trap

CompTIA often tests the distinction between a virus and a worm by emphasizing that a worm self-propagates without user intervention beyond initial activation, whereas a virus requires host file attachment and user execution of that file.

How to eliminate wrong answers

Option A is wrong because a virus requires attaching to a legitimate program or file to execute and replicate, whereas this malware spreads independently via email without modifying existing files. Option C is wrong because a Trojan horse disguises itself as legitimate software but does not self-replicate; it relies on deception to install, not on automatic propagation to contacts. Option D is wrong because a rootkit is designed to hide its presence and provide unauthorized access at the kernel level, not to spread via email or replicate to other contacts.

684
MCQhard

A technician is setting up remote access for a user who will be traveling internationally. The user needs to access files on a Windows server using RDP. Which additional security measure should the technician implement to protect the RDP session?

A.Enable Network Level Authentication (NLA) on the server
B.Use a VPN to encrypt all traffic before initiating RDP
C.Change the RDP port to a non-standard number
D.Disable clipboard redirection in the RDP session
AnswerB

Utilizing a Virtual Private Network (VPN) establishes an encrypted tunnel between the client and the remote network before any RDP traffic is sent. All data, including the RDP session, is encapsulated and encrypted within this secure tunnel, making it unreadable to unauthorized parties even if intercepted. This comprehensive encryption protects the entire RDP session from end-to-end, ensuring confidentiality and integrity against eavesdropping and tampering.

Why this answer

B is correct because RDP traffic is encrypted but not authenticated at the transport layer, making it vulnerable to man-in-the-middle attacks, especially over untrusted international networks. A VPN (e.g., IPsec or OpenVPN) provides an additional layer of encryption and authentication for the entire session before RDP traffic is sent, ensuring confidentiality and integrity even if the RDP protocol itself is compromised.

Exam trap

CompTIA often tests the misconception that RDP's built-in encryption is sufficient for all scenarios, leading candidates to overlook the need for a VPN when the connection traverses untrusted networks, especially in international travel contexts.

How to eliminate wrong answers

Option A is wrong because Network Level Authentication (NLA) requires the user to authenticate before a full RDP session is established, which protects against some attacks but does not encrypt the traffic; it is a pre-session authentication mechanism, not a transport-layer security measure. Option C is wrong because changing the RDP port from the default 3389 to a non-standard number is a form of security through obscurity that does not provide actual encryption or authentication; it only reduces automated scans but does not protect the session from targeted attacks. Option D is wrong because disabling clipboard redirection prevents data transfer via the clipboard but does not encrypt or secure the RDP session itself; it is a data-leakage prevention measure, not a security measure for the session's confidentiality.

685
MCQmedium

A user reports that their Android phone's screen is unresponsive to touch, but the buttons and notification LED still work. They have already performed a forced restart. What should the technician do NEXT?

A.Replace the screen assembly.
B.Boot the phone into Safe Mode to check if the issue persists.
C.Perform a factory reset from the recovery menu.
D.Update the phone's firmware using a computer.
AnswerB

Booting the Android phone into Safe Mode is the most appropriate next diagnostic step because it loads the operating system with only essential system applications and services, temporarily disabling all third-party applications. If the screen's touch functionality works correctly in Safe Mode, it strongly indicates that a recently installed or updated third-party application is interfering with the device's display or input system, allowing for targeted uninstallation or troubleshooting.

Why this answer

Safe Mode is the correct next step because it boots Android with only system apps, disabling all third-party apps. If the touchscreen works in Safe Mode, the issue is caused by a downloaded app; if it still fails, the problem is hardware or system-level. This is a non-destructive diagnostic step that isolates the cause before committing to a factory reset or hardware replacement.

Exam trap

220-1202 often tests the order of troubleshooting operations — candidates jump to destructive fixes (factory reset, screen replacement) because the symptom sounds hardware-related, but the exam expects the least-invasive diagnostic step (Safe Mode) first.

How to eliminate wrong answers

Option A is wrong because replacing the screen assembly is a hardware action that should only be taken after software causes are ruled out — the buttons and LED working suggests the digitizer, not the display, may be at fault, but Safe Mode must confirm that first. Option C is wrong because a factory reset from recovery is destructive and premature; it should only be done after Safe Mode and other diagnostics indicate a system-level issue that cannot be fixed otherwise. Option D is wrong because updating firmware via a computer is a recovery/flashing action that does not diagnose the touch issue and may not even be possible if the device is not recognized or already on the latest firmware.

686
MCQeasy

A user reports that after a recent software update, their inventory management application crashes on launch. The change log shows the update was applied last night by a junior technician. What is the first step the technician should take according to change management best practices?

A.Restore the user’s system from a backup taken before the update.
B.Check the change log for the update details and rollback procedure.
C.Uninstall the update immediately to restore functionality.
D.Escalate the issue to the IT manager for a decision.
AnswerB

Checking the change log is the most appropriate first step because it provides critical documentation regarding the software update. This log details the changes implemented, any known issues, and, most importantly, the approved and tested rollback procedure. Following the documented rollback plan minimizes the risk of further system instability or data corruption, aligning with best practices for incident resolution and change management.

Why this answer

Change management best practices require that before any action is taken, the technician should first consult the change log to understand what was changed and identify the documented rollback procedure. This ensures a controlled, reversible approach rather than risking data loss or further instability by acting without full knowledge of the update's scope.

Exam trap

CompTIA often tests the misconception that immediate restoration or uninstallation is the fastest fix, but the trap here is that candidates overlook the critical first step of consulting the change log to understand the update's scope and the documented rollback procedure before taking any action.

How to eliminate wrong answers

Option A is wrong because immediately restoring from backup is a reactive step that should only be taken after reviewing the change log and rollback plan; it may also be unnecessary if a simpler rollback exists. Option C is wrong because uninstalling the update without first checking the change log could leave the system in an inconsistent state or miss dependencies that require a specific rollback order. Option D is wrong because escalating to the IT manager bypasses the technician's responsibility to first gather information from the change log, which is a standard first step in incident response per change management frameworks.

687
MCQhard

A company's security policy requires that all laptops have a TPM chip enabled and be configured to require a PIN at startup before the operating system loads. Which security feature is being configured?

A.Secure Boot
B.BitLocker with TPM and PIN protector
C.Windows Defender System Guard
D.Group Policy password complexity enforcement
AnswerB

BitLocker with a Trusted Platform Module (TPM) and PIN protector is a robust full-disk encryption solution that directly addresses the security requirement for laptops. The TPM provides a hardware-based root of trust, verifying the system's integrity before releasing the encryption key to unlock the drive. Adding a PIN protector requires the user to enter a specific code before the operating system even begins to load, providing a crucial second factor of authentication (something you know) in addition to the TPM's hardware validation (something you have), thereby securing data even if the laptop is stolen or the TPM is tampered with.

Why this answer

The scenario describes using a TPM chip and requiring a PIN at startup before the OS loads. This is exactly how BitLocker's TPM+PIN protector works: the TPM validates the system integrity, and the PIN provides an additional factor of authentication, unlocking the drive encryption key before Windows boots. Option B is correct because it directly matches the described configuration.

Exam trap

The trap here is that candidates confuse Secure Boot (which only verifies bootloader integrity) with the full-disk encryption and pre-boot authentication provided by BitLocker with TPM+PIN.

How to eliminate wrong answers

Option A is wrong because Secure Boot ensures only signed firmware and bootloaders run, but it does not provide full-disk encryption or require a PIN at startup. Option C is wrong because Windows Defender System Guard is a set of hardware-backed security features (like credential guard) that protect the kernel and system integrity, but it does not encrypt the drive or require a PIN before the OS loads. Option D is wrong because Group Policy password complexity enforcement applies to user account passwords after the OS has loaded, not to a pre-boot PIN for drive decryption.

Page 9

Page 10 of 10

All pages

Practice 220-1202 by domain

Target a specific domain to shore up weak areas.

See all domains with question counts →