Courseiva

CompTIA A+ Core 2 220-1202 (220-1202) — Questions 226–300

687 questions total · 10pages · All types, answers revealed

Page 3

Page 4 of 10

Page 5
226
MCQeasy

A technician needs to deploy a configuration change to 50 Windows 10 computers using a script. The script must check if a specific registry key exists before modifying it. Which scripting construct should be used?

A.A for loop
B.A while loop
C.An if-else statement
D.A try-catch block
AnswerC

An if-else statement is the most appropriate control structure for this scenario because it explicitly allows a script to evaluate a specific condition, such as the existence of a registry key. If the condition evaluates to true (e.g., the key exists), a defined block of code is executed. Optionally, an 'else' block can be executed if the condition is false, providing a clear path for conditional logic and ensuring the configuration change is applied only when necessary or handled differently if the key is absent.

Why this answer

The script needs to conditionally execute code based on whether a registry key exists. An if-else statement is the correct construct for this because it evaluates a condition (e.g., Test-Path 'HKLM:\Software\MyKey') and executes one block if true (modify the key) and another if false (skip or create). Loops are for repetition, not conditional branching, and try-catch handles runtime errors, not existence checks.

Exam trap

The trap here is that candidates confuse conditional logic (if-else) with error handling (try-catch), thinking that checking for existence requires exception handling, when in fact a simple conditional test is the correct and more efficient approach.

How to eliminate wrong answers

Option A is wrong because a for loop is designed for iterating over a sequence or a fixed number of times, not for making a single conditional decision about a registry key's existence. Option B is wrong because a while loop repeats a block of code as long as a condition is true, which is unnecessary for a one-time check and could cause an infinite loop if misused. Option D is wrong because a try-catch block is used to handle exceptions (runtime errors) such as access denied or missing paths, not to test for the existence of a registry key before modification.

227
MCQmedium

A technician is assisting a user who is visibly upset because their critical presentation file was deleted accidentally. The user is speaking loudly and interrupting. What is the best way to handle this situation professionally?

A.Politely ask the user to calm down and speak more quietly so you can understand the issue.
B.Interrupt the user to explain that files can often be recovered from the Recycle Bin or backup.
C.Listen without interrupting, then say, "I can see this is urgent. Let's check the Recycle Bin first, and if it's not there, we have backups."
D.Transfer the user to a supervisor because the user is being difficult.
AnswerC

This response exemplifies best practices in customer service by first validating the user's emotional state with empathy ("I can see this is urgent"). It then immediately transitions into a clear, logical, and reassuring technical troubleshooting plan, starting with common, quick solutions like the Recycle Bin. Furthermore, it provides a confident fallback solution (backups), which effectively de-escalates the situation and instills user confidence in the technician's ability to resolve the issue.

Why this answer

It demonstrates active listening and empathy while immediately addressing the technical issue. The technician first allows the user to vent without interruption, then acknowledges the urgency and proposes a clear, step-by-step recovery plan starting with the Recycle Bin (a common first-resort recovery method) and escalating to backups if needed. This approach de-escalates the emotional situation while efficiently moving toward a solution, which is key for professional customer service in IT support.

Exam trap

CompTIA often tests the candidate's ability to balance empathy with technical action; the trap here is that candidates may choose Option B (interrupting with a solution) because they focus solely on technical correctness, ignoring the professionalism and communication skills required to de-escalate an emotional user.

How to eliminate wrong answers

Option A is wrong because telling an upset user to 'calm down' can be perceived as dismissive and may escalate the situation; it does not address the technical problem. Option B is wrong because interrupting the user, even with a valid technical solution, can increase frustration and prevent the technician from gathering full details about the file deletion (e.g., whether it was permanently deleted or from a specific location). Option D is wrong because transferring a user solely for being upset avoids the technician's responsibility to handle emotional situations professionally and delays resolution; it should only be done if the issue is beyond the technician's scope or authority.

228
MCQhard

A user reports that their Windows 10 PC is unable to connect to network shares on a server, but internet access works fine. You suspect the 'Workstation' service is not running. Which administrative tool should you use to verify and start this service?

A.Task Manager > Startup tab to check if the service is enabled.
B.Network and Sharing Center to run the network troubleshooter.
C.Services console to locate the 'Workstation' service and start it.
D.Device Manager to reinstall the network adapter driver.
AnswerC

The Services console (services.msc) is the definitive administrative tool for managing all Windows services. The 'Workstation' service (also known as LanmanWorkstation) is crucial for enabling client-side Server Message Block (SMB) protocol functionality, allowing a Windows PC to connect to and access shared folders, printers, and other resources on a network. If this service is stopped, the client cannot establish SMB connections, directly preventing access to network shares. Starting this service through the console restores the necessary functionality.

Why this answer

The 'Workstation' service (LanmanWorkstation) is a core Windows service that enables the computer to initiate outbound SMB connections to network shares. The Services console (services.msc) is the correct administrative tool to check the status of this service and start it if it is stopped. Option C directly addresses the need to verify and manage this service.

Exam trap

The trap here is that candidates may confuse a service issue with a driver or network configuration problem, leading them to choose Device Manager or Network and Sharing Center instead of the Services console.

How to eliminate wrong answers

Option A is wrong because the Task Manager Startup tab only manages programs that launch at user logon, not Windows services; the 'Workstation' service is a system service controlled via the Services console or SC command. Option B is wrong because Network and Sharing Center runs network troubleshooters that diagnose connectivity issues like IP configuration or DNS, but cannot start or stop Windows services. Option D is wrong because Device Manager is used to manage hardware drivers; reinstalling the network adapter driver would not resolve a service that is stopped, and the issue is not driver-related.

229
MCQmedium

An organization is moving to a cloud-based system and needs to dispose of several tape backup cartridges that contain years of financial data. The tapes are LTO-5 and are still readable. Which destruction method is most appropriate?

A.Overwrite the tapes with a bulk eraser or degausser.
B.Perform a quick format of the tapes using a tape drive.
C.Reuse the tapes for non-sensitive data after deleting the files.
D.Burn the tapes in an industrial incinerator.
AnswerA

A bulk eraser or degausser applies a strong, fluctuating magnetic field to the entire tape, effectively randomizing the magnetic domains that store data. This process completely neutralizes the magnetic patterns, rendering all previously recorded data unreadable and unrecoverable by any means, including advanced forensic techniques. Degaussing is a highly effective and industry-standard method for securely sanitizing magnetic storage media like tapes, ensuring compliance with data privacy regulations.

Why this answer

A degausser or bulk eraser generates a powerful magnetic field that disrupts the magnetic domains on the LTO-5 tape media, rendering the previously stored data unrecoverable. This method is the most appropriate for LTO-5 tapes because it physically destroys the magnetic encoding without requiring a compatible tape drive, and it is faster and more reliable than attempting to overwrite the entire tape. For secure disposal of magnetic media containing sensitive financial data, degaussing is the industry-standard approach when physical destruction is not mandated.

Exam trap

CompTIA A+ often tests the misconception that a quick format or file deletion is sufficient for secure data destruction on magnetic media, when in fact only degaussing or physical destruction ensures the data is irrecoverable.

How to eliminate wrong answers

Option B is wrong because a quick format only erases the file system index or directory structure, not the underlying data on the tape; the financial data remains recoverable with forensic tools. Option C is wrong because simply deleting files or reusing the tapes after file deletion does not remove the residual magnetic signature of the original data, leaving it vulnerable to recovery using specialized equipment. Option D is wrong because while incineration would physically destroy the tapes, it is unnecessarily extreme, costly, and environmentally hazardous for LTO-5 cartridges; degaussing is the appropriate and sufficient method for magnetic media that does not require physical destruction.

230
MCQmedium

A helpdesk technician receives a call from an employee who says their smart card stopped working for building access. The employee is in a hurry and asks the technician to remotely disable the card and issue a temporary PIN for the day. What should the technician do first?

A.Disable the smart card and provide a temporary PIN as requested.
B.Ask the employee to visit the security office in person with a photo ID.
C.Reset the smart card remotely and test it with a badge reader.
D.Send a temporary PIN via email to the employee's company address.
AnswerB

Smart card issuance and PIN reset are high-risk identity operations requiring in-person identity proofing. Verifying the employee's photo ID at the security office prevents an attacker from social-engineering a card disablement or temporary credential over the phone.

Why this answer

Smart card credentials for physical access are typically managed by a separate physical security system (e.g., an access control server), not the helpdesk's IT identity management system. The technician cannot remotely disable the card or issue a temporary PIN without proper authorization and verification of the caller's identity. The standard procedure is to require in-person verification with a photo ID at the security office to prevent social engineering attacks.

Exam trap

The trap here is that candidates assume the helpdesk has full control over all credential types (logical and physical) and can perform remote operations on smart cards, when in fact physical access systems are usually separate and require in-person identity verification.

How to eliminate wrong answers

Option A is wrong because disabling a smart card and issuing a temporary PIN without verifying the caller's identity violates security policy and could allow an attacker to gain unauthorized physical access. Option C is wrong because the technician cannot reset or test a smart card remotely; smart cards are physical tokens that require local interaction with a reader, and remote testing is not possible. Option D is wrong because sending a temporary PIN via email is insecure; email is not encrypted end-to-end by default and could be intercepted, and the PIN should be delivered through a secure out-of-band method.

231
MCQmedium

A user receives an email with a link that appears to be from their bank, asking them to verify their account. The link leads to a page that looks exactly like the bank's login page. What type of attack is this?

A.A man-in-the-middle attack.
B.A phishing attack.
C.A ransomware attack.
D.A cross-site scripting (XSS) attack.
AnswerB

Phishing deceives the recipient into trusting a spoofed message and surrendering credentials on a counterfeit login page. The lookalike bank page and the verification request satisfy the scenario's defining constraint: credential harvesting through social engineering rather than malware or network exploitation.

Why this answer

This scenario describes a phishing attack, where the attacker sends a deceptive email impersonating a trusted entity (the bank) to trick the user into clicking a malicious link. The link leads to a fraudulent website that mimics the legitimate bank login page, designed to capture the user's credentials. Phishing exploits social engineering rather than technical vulnerabilities, relying on the user's trust and inattention to detail.

Exam trap

CompTIA often tests the distinction between phishing and man-in-the-middle attacks by presenting a scenario where the user is tricked into voluntarily providing credentials on a fake site, which is phishing, not an active interception of network traffic.

How to eliminate wrong answers

Option A is wrong because a man-in-the-middle (MITM) attack involves the attacker intercepting and potentially altering communications between two parties in real time, typically by exploiting network-level vulnerabilities (e.g., ARP spoofing or rogue Wi-Fi), not by sending a deceptive email with a fake link. Option C is wrong because a ransomware attack encrypts the victim's files or locks their system and demands payment for decryption, which is not described here; the email does not contain malware or encryption. Option D is wrong because cross-site scripting (XSS) is a web application vulnerability that allows an attacker to inject malicious scripts into trusted websites, executed in the victim's browser; the attack described does not involve injecting scripts into a legitimate site but rather creating a fake login page.

232
MCQmedium

A technician is configuring a wireless network for a school that uses Chromebooks and iPads. The network must support fast roaming and prioritize security. The technician enables WPA2-Enterprise with 802.1X. What additional configuration is needed to ensure seamless roaming between access points?

A.Enable WPA3-SAE on all access points.
B.Configure all access points with the same SSID and passphrase.
C.Enable 802.11r (Fast Roaming) on the wireless controller.
D.Disable WPS on all access points.
AnswerC

802.11r enables fast BSS transition, letting clients pre-authenticate with the target access point and skip full 802.1X re-authentication during roaming. This satisfies the school's requirement for seamless roaming while retaining WPA2-Enterprise security across Chromebooks and iPads.

Why this answer

802.11r (Fast Roaming) enables seamless key distribution between access points during client transitions, eliminating the need for full re-authentication with the RADIUS server. This is essential for devices like Chromebooks and iPads that move frequently across a school campus, ensuring low-latency roaming while maintaining WPA2-Enterprise security.

Exam trap

A common misconception in CompTIA A+ is that simply using the same SSID and passphrase (Option B) is sufficient for seamless roaming, but in WPA2-Enterprise, the passphrase is not used, and without 802.11r, clients must perform a full 802.1X re-authentication at each AP, causing noticeable delays.

How to eliminate wrong answers

Option A is wrong because WPA3-SAE is a different security protocol for personal networks, not enterprise; it does not integrate with 802.1X and does not address roaming optimization. Option B is wrong because while using the same SSID is necessary for roaming, a shared passphrase is irrelevant for WPA2-Enterprise, which uses per-user credentials via 802.1X, not a pre-shared key. Option D is wrong because disabling WPS improves security by preventing brute-force attacks on PIN-based authentication, but it has no effect on roaming performance or seamless handoff between access points.

233
MCQmedium

A company is relocating and needs to dispose of 50 old desktop computers with HDDs that contain sensitive client data. The policy requires data destruction to be verifiable and the drives to be physically destroyed. Which method meets these requirements?

A.Use a degausser and then donate the drives to a school.
B.Overwrite each drive with three passes of random data.
C.Send the drives to a certified e-waste recycler for shredding.
D.Reformat each drive and install a fresh OS for reuse.
AnswerC

Sending the drives to a certified e-waste recycler for shredding ensures complete physical destruction of the storage media, rendering any data absolutely unrecoverable. This method directly satisfies a company policy requiring physical destruction and provides an auditable chain of custody, often including a certificate of destruction from the recycler. This approach also adheres to environmental regulations for electronic waste disposal, ensuring responsible and secure asset retirement.

Why this answer

Physical destruction methods like shredding or crushing provide verifiable destruction (e.g., through a certificate of destruction) and ensure the drives cannot be reused, meeting strict security policies. Degaussing also destroys data but may not physically destroy the drive.

234
MCQhard

A company's security policy requires that all workstations use a host-based firewall to block incoming connections except for specific allowed applications. A technician needs to configure this on a Windows 10 PC. Which tool should they use?

A.Windows Defender Antivirus settings
B.Windows Defender Firewall with Advanced Security
C.Group Policy Editor
D.Network and Sharing Center
AnswerB

This Microsoft Management Console (MMC) snap-in, accessible via wf.msc, is the definitive tool for granularly configuring the host-based firewall on a Windows workstation. It allows technicians to create highly specific inbound and outbound rules based on applications, service ports, protocols (TCP/UDP), IP addresses, and even user or computer accounts. This advanced interface is essential for implementing detailed security policies that require precise control over network traffic flow, such as allowing specific applications while blocking others.

Why this answer

The Windows Defender Firewall with Advanced Security (wf.msc) is the correct tool because it provides granular control over inbound rules, allowing the technician to block all incoming connections by default and then create explicit allow rules for specific applications. This meets the security policy requirement for a host-based firewall that blocks incoming traffic except for permitted applications.

Exam trap

CompTIA often tests the distinction between basic firewall settings (accessible via Control Panel) and the Advanced Security console, where candidates mistakenly choose the simpler interface or confuse firewall management with antivirus or group policy tools.

How to eliminate wrong answers

Option A is wrong because Windows Defender Antivirus settings manage malware protection, not firewall rules; it cannot create or modify inbound connection rules. Option C is wrong because Group Policy Editor (gpedit.msc) is used to configure system-wide policies across a domain, not for per-workstation firewall rule management on a standalone Windows 10 PC. Option D is wrong because Network and Sharing Center is a network status and troubleshooting interface; it does not provide the advanced inbound rule configuration needed to block all incoming connections except specific applications.

235
MCQhard

During a security audit, a technician finds that a user's workstation was infected with malware after the user inserted a USB drive found in the parking lot. The drive was labeled 'Employee Salary Info Q4'. What social engineering principle did the attacker exploit?

A.Scarcity
B.Baiting
C.Pretexting
D.Tailgating
AnswerB

Baiting is a social engineering attack where an attacker leaves a physical device, such as a USB flash drive, CD/DVD, or even a malicious mobile charging station, infected with malware in a public or semi-public location. The goal is to entice an unsuspecting victim, driven by curiosity or the desire for free content, to pick up the device and insert it into their computer or connect to it, thereby executing the malicious payload. This method directly exploits human curiosity and the inherent trust in physical objects to compromise a system.

Why this answer

Baiting is the correct answer because the attacker exploited the victim's curiosity by leaving a malware-infected USB drive in a visible location, labeled with an enticing message ('Employee Salary Info Q4'). When the user inserted the drive, the malware executed automatically (e.g., via Autorun.inf in Windows), compromising the workstation. This is a classic baiting attack, which relies on offering something desirable to trick the victim into performing a risky action.

Exam trap

The trap here is that candidates confuse baiting with pretexting because both involve deception, but baiting specifically uses a physical lure (like a USB drive) to trigger an action, whereas pretexting relies on a fabricated story or identity to gain information.

How to eliminate wrong answers

Option A (Scarcity) is wrong because scarcity involves creating a false sense of urgency or limited availability (e.g., 'Only 5 licenses left!'), not leaving a physical device to be found. Option C (Pretexting) is wrong because pretexting requires the attacker to fabricate a false identity or scenario (e.g., pretending to be IT support) to extract information, not relying on the victim's curiosity about a found object. Option D (Tailgating) is wrong because tailgating involves an unauthorized person physically following an authorized person into a restricted area, not leaving a malicious device for the victim to pick up and use.

236
MCQeasy

After deploying a new application to 50 workstations, several users report that the application crashes on launch. You need to quickly check if the application is running on a remote computer. Which command should you use?

A.regsvr32 /s C:\App\core.dll
B.ipconfig /flushdns
C.chkdsk C:
D.tasklist /S remotePC
AnswerD

The `tasklist /S remotePC` command is specifically designed to display a list of all running processes on a specified remote computer. By providing the hostname or IP address of the `remotePC`, an administrator can effectively query the target workstation and identify if the newly deployed application's executable is present in the process list. Its presence directly confirms that the application is actively running, making it an ideal tool for remote application status verification.

Why this answer

The `tasklist /S remotePC` command queries the running processes on a remote computer named remotePC, allowing the technician to verify whether the application is running. This is the correct built-in Windows CLI tool for remote process enumeration, and it can be combined with `/U` and `/P` for credentials if needed. It directly addresses the need to quickly check application status on a remote workstation.

Exam trap

The trap is selecting a command that sounds like it deals with applications (regsvr32) or system health (chkdsk), but the exam expects you to know that `tasklist` with the `/S` switch is the specific tool for remote process inspection.

How to eliminate wrong answers

Option A is wrong because `regsvr32 /s C:\App\core.dll` silently registers a DLL on the local machine, which does not check remote process status and could worsen the issue if the DLL is incompatible. Option B is wrong because `ipconfig /flushdns` clears the local DNS resolver cache and has no bearing on application processes. Option C is wrong because `chkdsk C:` checks and repairs disk errors on the local C: drive, not remote process status, and can take a long time.

237
MCQeasy

A user calls the help desk, frantic because their banking app shows an unauthorized transfer of $500. They say they received a call earlier from 'bank security' asking them to install a remote access tool to 'verify their account'. What type of social engineering attack did the user fall victim to?

A.Phishing
B.Vishing
C.Smishing
D.Shoulder surfing
AnswerB

Vishing, or voice phishing, is a social engineering tactic that utilizes telephone calls to trick individuals into divulging personal or financial information, installing malware, or performing other actions detrimental to their security. Attackers often impersonate legitimate organizations, such as banks, government agencies, or tech support, creating a sense of urgency or fear to manipulate the victim. This method directly matches the scenario where a user is frantic after a phone call-initiated attack.

Why this answer

The user received a phone call (voice channel) and was tricked into installing remote access software, which is the hallmark of vishing (voice phishing). Unlike phishing, which uses email or malicious links, vishing exploits telephone systems and social engineering to gain unauthorized access or sensitive information.

Exam trap

CompTIA A+ 220-1202 often tests the distinction between vishing and phishing by emphasizing the communication medium (voice call vs. email), so candidates mistakenly choose phishing when the attack vector is a phone call rather than a digital message.

How to eliminate wrong answers

Option A is wrong because phishing typically involves deceptive emails or websites that trick users into clicking a link or entering credentials, not a phone call requesting software installation. Option C is wrong because smishing uses SMS text messages to deliver malicious links or requests, not a live voice call. Option D is wrong because shoulder surfing relies on physically observing a user's screen or keystrokes, not a remote phone-based interaction.

238
MCQhard

A technician needs to deploy a custom configuration profile to 20 Mac computers in a small office without using a third-party MDM. The profile must enforce Wi-Fi settings and disable iCloud. Which macOS tool can create and sign this configuration profile?

A.Apple Configurator
B.System Settings > Profiles
C.Terminal with 'profiles' command
D.Profile Manager in macOS Server
AnswerA

Apple Configurator is the correct tool because it provides a graphical user interface specifically designed for creating, editing, and digitally signing custom configuration profiles (.mobileconfig files) for both macOS and iOS/iPadOS devices. This standalone utility is ideal for technicians needing to deploy specific settings, restrictions, or network configurations to a small number of devices without the overhead of a full Mobile Device Management (MDM) solution.

Why this answer

Apple Configurator is the correct tool because it can create and sign custom configuration profiles (.mobileconfig files) for macOS without requiring a third-party MDM. It allows a technician to specify Wi-Fi settings and restrictions like disabling iCloud, then export the signed profile for manual deployment to the 20 Macs via USB or email.

Exam trap

Candidates often confuse Apple Configurator (which creates and signs profiles) with built-in tools like System Settings or the 'profiles' terminal command, which only install or manage existing profiles—not create or sign them.

How to eliminate wrong answers

Option B is wrong because System Settings > Profiles is only for viewing and manually installing profiles that are already signed, not for creating or signing them. Option C is wrong because the Terminal 'profiles' command can install, remove, or list profiles but cannot create or sign a new configuration profile from scratch. Option D is wrong because Profile Manager in macOS Server requires a running MDM service and is considered a third-party MDM solution, which the question explicitly excludes.

239
MCQmedium

A user reports that their Windows 10 PC is unable to connect to shared network folders on the office server. You need to verify that the necessary network discovery and file sharing services are running. Which administrative tool should you open to check the status of services like 'Function Discovery Resource Publication' and 'SSDP Discovery'?

A.Network and Sharing Center
B.Device Manager
C.Services.msc
D.Task Manager
AnswerC

The Services Microsoft Management Console (MMC) snap-in, `services.msc`, is the dedicated tool for viewing, starting, stopping, pausing, resuming, and configuring the startup type of all Windows services. This includes critical services like 'Function Discovery Resource Publication' and 'SSDP Discovery,' which are essential for network discovery functionality. It provides granular control over these background processes, making it the correct utility for diagnosing and resolving service-related issues.

Why this answer

The 'Services.msc' (Services console) is the dedicated Microsoft Management Console (MMC) snap-in used to start, stop, and configure Windows services. To verify that 'Function Discovery Resource Publication' (which publishes the machine's resources for network discovery) and 'SSDP Discovery' (which implements the Simple Service Discovery Protocol for UPnP devices) are running, you must open the Services console. Network and Sharing Center only shows connection status and sharing settings, not the underlying service state.

Exam trap

The trap here is that candidates often confuse the 'Network and Sharing Center' (which displays network discovery settings) with the actual service management console, not realizing that the service state must be verified separately in Services.msc because the GUI toggle in Network and Sharing Center only changes the firewall rules, not the underlying service status.

How to eliminate wrong answers

Option A is wrong because Network and Sharing Center is a GUI for viewing network status, setting up new connections, and managing sharing profiles; it does not display or allow control of individual Windows services like 'Function Discovery Resource Publication' or 'SSDP Discovery'. Option B is wrong because Device Manager is used to manage hardware drivers and devices, not software services; it has no interface for service state or startup type. Option D is wrong because Task Manager shows running processes and performance metrics, but it does not list system services by their service name or provide controls for service startup type; it only shows a limited view of processes under the 'Services' tab, not the full service management console.

240
MCQmedium

A technician is configuring a Windows 10 kiosk system that will run a single application in a public library. The kiosk must automatically log on and start the app without any user interaction. Which security setting combination is required?

A.Enable 'Sticky Keys' and configure the 'Ease of Access' settings
B.Configure 'Automatic logon' in the registry and enable 'Assigned Access' for the kiosk account
C.Set the 'Shutdown: Allow system to be shut down without having to log on' policy
D.Enable 'User Account Control: Run all administrators in Admin Approval Mode'
AnswerB

Automatic logon via the registry removes the credential prompt, while Assigned Access locks the kiosk account to the single application. Together they satisfy the no-interaction requirement, since each alone leaves either a login prompt or full desktop access.

Why this answer

Configuring 'Automatic logon' in the registry (via the WinLogon key) allows the kiosk to boot directly to the desktop without user interaction, while enabling 'Assigned Access' restricts the kiosk account to running only a single specified Universal Windows Platform (UWP) app, preventing access to the rest of the system. This combination meets the requirement for an unattended, single-application kiosk in a public library.

Exam trap

The trap here is that candidates may confuse 'Automatic logon' with general security policies like shutdown permissions or UAC, or mistakenly think accessibility features can automate logon, when in fact only the registry-based autologon combined with Assigned Access satisfies the unattended single-app requirement.

How to eliminate wrong answers

Option A is wrong because 'Sticky Keys' and 'Ease of Access' settings are accessibility features that modify keyboard input behavior, not security or autologon mechanisms; they cannot automatically log on a user or launch a single app. Option C is wrong because the 'Shutdown: Allow system to be shut down without having to log on' policy (a local security policy) only controls whether the shutdown command is available on the logon screen, not autologon or application restriction. Option D is wrong because 'User Account Control: Run all administrators in Admin Approval Mode' is a UAC setting that affects how administrative privileges are elevated, but it does not enable automatic logon or enforce a single-app kiosk environment.

241
MCQmedium

A technician is writing a PowerShell script to check the last boot time of a remote computer. The script uses Get-CimInstance Win32_OperatingSystem. The script works locally but fails with an access denied error when targeting a remote machine. Both computers are domain-joined and the technician has admin rights. What is the most likely issue?

A.The remote computer does not have PowerShell installed.
B.The remote computer has Windows Firewall blocking WMI traffic.
C.The script uses an incorrect namespace.
D.The technician is not a member of the Remote Management Users group.
AnswerB

For remote WMI queries to succeed, the Windows Firewall on the target computer must be configured to allow inbound WMI traffic. This typically involves enabling specific firewall rules, such as "Windows Management Instrumentation (WMI)" or "Remote Administration (WMI-In)", which permit DCOM and RPC connections over the necessary ports. If these rules are not enabled, the firewall will block the communication attempts, resulting in a connection failure for Get-CimInstance.

Why this answer

Get-CimInstance uses the WS-Management (WSMan) protocol, which relies on WinRM. By default, Windows Firewall blocks inbound WinRM traffic on port 5985 (HTTP) and 5986 (HTTPS). Even though the technician has admin rights and both machines are domain-joined, the remote firewall must allow WinRM traffic for the CIM session to succeed.

The local success is because no firewall traversal is needed.

Exam trap

CompTIA often tests the misconception that access denied errors are always due to permissions or group membership, when in fact network-level firewall blocking of WinRM/WMI traffic is a frequent real-world cause.

How to eliminate wrong answers

Option A is wrong because PowerShell is not required on the remote machine for Get-CimInstance; it uses WMI via WinRM, which only requires the WMI service to be running. Option C is wrong because the default namespace for Win32_OperatingSystem is root/cimv2, which is correct and not the cause of an access denied error. Option D is wrong because the Remote Management Users group is not required for WMI access; membership in the local Administrators group on the remote computer is sufficient for WMI queries.

242
MCQmedium

A technician is troubleshooting a remote user's inability to connect to the corporate network via VPN. The user can ping the VPN server's public IP address. Which step should the technician take next to isolate the issue?

A.Reboot the user's modem
B.Check the VPN client logs for errors
C.Disable the user's firewall
D.Reinstall the VPN client software
AnswerB

Checking the VPN client logs is the most effective and efficient diagnostic step for troubleshooting VPN connection failures. These logs provide detailed information, including specific error codes, timestamps, and messages related to authentication attempts, certificate validation, tunnel negotiation, and network connectivity issues. Analyzing these entries allows a technician to pinpoint the exact cause of the failure, such as incorrect credentials, firewall blocks, or incompatible security parameters, guiding precise corrective actions.

Why this answer

Since the user can already ping the VPN server's public IP, basic network reachability is confirmed, so the next logical step is to examine the VPN client logs for errors such as authentication failures, certificate issues, or negotiation problems. This isolates whether the issue is at the VPN protocol/authentication layer rather than the network layer. Rebooting the modem, disabling the firewall, or reinstalling the client are premature and could disrupt the environment without diagnostic value.

Exam trap

220-1202 often tests the troubleshooting methodology order, and the trap is that candidates jump to remediation steps (reboot, reinstall, disable firewall) instead of gathering diagnostic data first when basic connectivity is already confirmed.

How to eliminate wrong answers

Option A is wrong because rebooting the modem is a random action that does not isolate the VPN issue, especially since ping to the public IP already succeeded, proving basic connectivity. Option C is wrong because disabling the user's firewall is a security risk and an untargeted change; the firewall may be a factor, but disabling it outright is not a diagnostic step and could mask or worsen the problem. Option D is wrong because reinstalling the VPN client is a remediation attempt, not an isolation step, and should only be done after logs or configuration point to a client software fault.

243
MCQhard

A security incident occurred on a Windows 10 workstation, and you need to review detailed logs of user logon attempts, including successful and failed logins, to identify unauthorized access. Which tool should you use to view these security logs?

A.Reliability Monitor
B.Performance Monitor
C.Event Viewer
D.Group Policy Editor
AnswerC

Event Viewer's Security log records Windows logon events, including audit success and failure entries with account names, timestamps and logon types. Reviewing event IDs 4624 and 4625 satisfies the requirement to identify both successful and failed logon attempts during the incident investigation.

Why this answer

Event Viewer is the correct tool because it provides access to Windows Security logs, which record detailed information about user logon attempts, including both successful (Event ID 4624) and failed (Event ID 4625) logins. These logs are essential for forensic analysis of unauthorized access on a Windows 10 workstation.

Exam trap

The A+ exam often tests the distinction between tools that view logs (Event Viewer) versus tools that configure settings (Group Policy Editor) or monitor performance (Performance Monitor), leading candidates to confuse administrative utilities.

How to eliminate wrong answers

Option A is wrong because Reliability Monitor tracks system stability and application failures, not security-related logon events. Option B is wrong because Performance Monitor focuses on system performance metrics like CPU and memory usage, not security audit logs. Option D is wrong because Group Policy Editor is used to configure system policies and security settings, not to view existing event logs.

244
MCQmedium

A technician is writing a PowerShell script to retrieve the IP configuration of all computers in a domain and output the results to a CSV file. The script must run on a management workstation and target remote machines. Which cmdlet should the technician use to execute commands on remote computers?

A.Invoke-Command
B.Enter-PSSession
C.Get-WmiObject
D.Out-File
AnswerA

This cmdlet is the primary tool for executing script blocks or individual commands on one or more remote computers using PowerShell Remoting. It establishes a non-interactive session, runs the specified code, and efficiently returns the results to the calling machine, making it ideal for large-scale data collection and automation tasks across an enterprise network.

Why this answer

Invoke-Command is the correct cmdlet because it is designed to execute PowerShell commands or script blocks on one or more remote computers and return the results to the local session. This allows the technician to run the IP configuration retrieval script against all domain computers from the management workstation and then pipe the output to Export-Csv.

Exam trap

CompTIA often tests the distinction between interactive remote sessions (Enter-PSSession) and one-off command execution (Invoke-Command), leading candidates to choose Enter-PSSession when the requirement is to run a script against multiple computers and capture output.

How to eliminate wrong answers

Option B (Enter-PSSession) is wrong because it creates an interactive, persistent session with a single remote computer, which is not suitable for running a script against multiple remote machines and capturing output to a CSV file. Option C (Get-WmiObject) is wrong because while it can retrieve WMI data from remote computers using the -ComputerName parameter, it is not a cmdlet for executing arbitrary PowerShell commands or script blocks; it is a specific cmdlet for WMI queries. Option D (Out-File) is wrong because it is used to send output to a text file on the local machine, not to execute commands on remote computers.

245
MCQmedium

A customer brings in a laptop that they want to recycle, but they are concerned about personal data. The laptop has a 256GB SSD and the customer wants to keep the laptop functional for resale. Which method should the technician recommend?

A.Remove the SSD and physically destroy it, then sell the laptop without a drive.
B.Use a degausser on the SSD.
C.Perform a standard format and reinstall Windows.
D.Use the 'Reset this PC' option with the 'Remove everything and clean the drive' setting.
AnswerD

The 'Reset this PC' option, specifically with the 'Remove everything and clean the drive' setting, is the most appropriate method for securely erasing data from an SSD while maintaining laptop functionality. This feature performs a secure wipe by overwriting all data sectors multiple times, often leveraging the SSD's built-in TRIM command and secure erase capabilities. This process renders previous data virtually unrecoverable, ensuring privacy before resale.

Why this answer

The 'Reset this PC' option with 'Remove everything and clean the drive' performs a secure erase that overwrites the drive, making data recovery difficult while keeping the laptop functional for resale. This satisfies both the customer's data security concern and the desire to resell the working laptop. Physical destruction or degaussing would render the drive unusable, and a standard format does not securely erase data.

Exam trap

220-1202 often tests whether candidates know the difference between standard format, secure erase, degaussing, and physical destruction, and which is appropriate for SSDs versus HDDs, so the trap is selecting a method that is either ineffective for SSDs or destroys the resale value.

How to eliminate wrong answers

Option A is wrong because physically destroying the SSD removes the storage and makes the laptop non-functional for resale, which contradicts the customer's goal. Option B is wrong because a degausser is designed for magnetic media (HDDs) and is ineffective and potentially damaging to SSDs, which store data in flash memory. Option C is wrong because a standard format and reinstall does not securely erase the data; remnants can be recovered with forensic tools, so it does not address the customer's data concern.

246
MCQeasy

A junior admin needs to list all files in /var/log that were modified in the last 24 hours. Which command accomplishes this?

A.ls -la /var/log | grep '24 hours'
B.find /var/log -mtime 0
C.find /var/log -atime 0
D.locate /var/log | sort -m
AnswerB

find's -mtime test compares file modification time against 24-hour periods, so -mtime 0 matches files modified within the last day. It recurses through /var/log and prints each matching path, satisfying the requirement without extra flags.

Why this answer

The `find` command with `-mtime 0` searches for files whose modification time is within the last 24 hours. The `-mtime` argument uses a 24-hour period, where `0` means modified less than 24 hours ago, making it the precise tool for this task.

Exam trap

The A+ exam often tests the distinction between `-mtime` (modification time) and `-atime` (access time), trapping candidates who confuse the two or who think `ls` with `grep` can perform time-based filtering.

How to eliminate wrong answers

Option A is wrong because `ls -la` lists files but does not filter by modification time; piping to `grep '24 hours'` would only match lines containing that literal string, not files modified in the last 24 hours. Option C is wrong because `-atime 0` checks access time (last read), not modification time, so it would list files accessed in the last 24 hours, not those modified. Option D is wrong because `locate` searches a pre-built database of file paths and does not support time-based filtering; `sort -m` merges sorted files, which is irrelevant to listing recently modified files.

247
MCQhard

An organization wants to ensure that even if a laptop is stolen, the data on the hard drive cannot be read. The laptop runs Windows 10 Pro and is used by employees who travel frequently. Which security feature should be enabled?

A.Enable BitLocker Drive Encryption on the system drive.
B.Set a strong BIOS/UEFI password.
C.Configure a screensaver password with a short timeout.
D.Use EFS to encrypt individual files and folders.
AnswerA

BitLocker encrypts the entire system drive with AES, so data remains unreadable if the laptop is stolen. Because travelling employees face physical theft risk, full-disk encryption addresses the confidentiality requirement directly, unlike passwords or BIOS locks.

Why this answer

BitLocker Drive Encryption is the correct choice because it encrypts the entire system drive at the block level, using AES encryption (typically 128-bit or 256-bit) with a TPM (Trusted Platform Module) to protect the encryption keys. This ensures that if the laptop is stolen, the hard drive cannot be removed and read from another system, as the data remains encrypted without the correct authentication (e.g., TPM + PIN or recovery key).

Exam trap

CompTIA A+ often tests the distinction between encryption at rest (BitLocker) and access control (BIOS password, screensaver) or partial encryption (EFS), leading candidates to choose a non-encryption option that does not protect data when the drive is physically removed.

How to eliminate wrong answers

Option B is wrong because a strong BIOS/UEFI password only prevents unauthorized booting or changes to firmware settings, but it does not encrypt the hard drive; an attacker can remove the drive and read its data directly from another machine. Option C is wrong because a screensaver password with a short timeout only locks the user session when idle, but it does not protect data if the laptop is stolen while powered off or if the drive is removed; it also does not encrypt the drive. Option D is wrong because EFS (Encrypting File System) encrypts only individual files and folders at the file system level, not the entire drive, and it relies on the user's Windows profile, which can be bypassed if the drive is removed or if the user account is compromised; it also does not protect system files or the pagefile.

248
MCQmedium

A company is migrating to new laptops and needs to dispose of 50 old hard drives securely. The drives contain proprietary software and client data. The IT manager wants a method that is both environmentally friendly and compliant with data protection laws. Which disposal method should be chosen?

A.Donate the drives to a local charity after wiping them with a free tool.
B.Use a certified e-waste recycler that offers secure destruction and recycling.
C.Physically break the drives with a drill and dispose of them in the regular trash.
D.Perform a quick format and sell the drives online.
AnswerB

A certified e-waste recycler provides a secure and compliant solution for end-of-life data storage devices. These facilities adhere to strict industry standards, often employing physical destruction methods like shredding or degaussing, which guarantee irreversible data sanitization. This approach ensures sensitive corporate data cannot be recovered, simultaneously meeting regulatory compliance requirements and promoting environmentally responsible disposal of electronic components, thereby minimizing ecological impact.

Why this answer

Certified e-waste recyclers follow strict data destruction standards (e.g., NIST SP 800-88) and environmental regulations (e.g., R2 or e-Stewards certification). This ensures the drives are physically destroyed or degaussed to prevent data recovery, while responsibly recycling materials, meeting both security and compliance requirements.

Exam trap

Candidates often think that physical destruction (e.g., drilling) is sufficient for security, but the trap is that it must be combined with proper disposal (e.g., through a certified recycler) to be both environmentally compliant and legally defensible.

How to eliminate wrong answers

Option A is wrong because free wiping tools may not overwrite data to a secure standard (e.g., only a single pass or not covering hidden areas like HPA/DCO), and donating drives still risks residual data exposure if the tool fails or is misused. Option C is wrong because physically breaking drives with a drill does not guarantee complete destruction of all platters or chips, and disposing of them in regular trash violates environmental laws and can lead to data recovery from remaining fragments. Option D is wrong because a quick format only removes the file system pointers, leaving all data intact and easily recoverable with forensic tools, and selling drives online exposes proprietary software and client data to unauthorized parties.

249
MCQmedium

A small business owner wants to ensure that if a laptop is stolen, the data on the drive cannot be read. The laptop runs Windows 11 Pro. What is the most appropriate remediation?

A.Set a strong BIOS password
B.Enable BitLocker on the system drive
C.Install an antivirus with anti-theft features
D.Use a cloud backup service
AnswerB

BitLocker encrypts the entire system drive with AES, so a thief removing the disk cannot read its contents without the recovery key or TPM-bound credentials. Windows 11 Pro supports BitLocker, meeting the requirement that stolen-laptop data remain unreadable.

Why this answer

BitLocker is the native full-disk encryption feature in Windows 11 Pro that encrypts the entire system drive, including the operating system, applications, and all user data. If the laptop is stolen, the data on the drive remains unreadable without the recovery key or TPM authentication, even if the drive is removed and attached to another computer. This directly addresses the requirement to prevent data access after theft.

Exam trap

The trap here is that candidates often confuse a BIOS password with drive encryption, thinking it secures the data, but BIOS passwords only control boot access and do not protect against physical drive removal and forensic analysis.

How to eliminate wrong answers

Option A is wrong because a BIOS password only prevents unauthorized booting or BIOS changes but does not encrypt the drive; the data can still be read by removing the drive and connecting it to another system. Option C is wrong because antivirus with anti-theft features typically provides location tracking, remote lock, or wipe capabilities, but it does not encrypt the drive at rest, so data remains accessible if the drive is removed. Option D is wrong because a cloud backup service protects against data loss but does not prevent an attacker from reading data already stored on the laptop's drive.

250
MCQmedium

A user reports that their Windows 11 laptop occasionally shows a blue screen with the stop code CRITICAL_PROCESS_DIED. The issue occurs randomly, about once every two days. The user has not installed any new hardware or software recently. Which of the following should a technician perform FIRST to troubleshoot this issue?

A.Run the System File Checker (SFC) utility.
B.Update the graphics card driver to the latest version.
C.Replace the hard drive with a new solid-state drive (SSD).
D.Perform a clean installation of Windows 11.
AnswerA

SFC is a built-in Windows tool that scans for and repairs corrupted system files, which can cause CRITICAL_PROCESS_DIED. Since the issue occurs randomly and no recent changes were made, corrupted system files are a likely cause. Running SFC is a safe, non-destructive first step that may resolve the problem without further disruption.

Why this answer

CRITICAL_PROCESS_DIED indicates that a critical system process has terminated unexpectedly, often due to corrupted system files. Running System File Checker (SFC) is a standard first step because it can repair those files without data loss. Other options are either too invasive or target the wrong subsystem, making SFC the most appropriate initial action.

Exam trap

The trap here is assuming that any blue screen requires a clean install or hardware replacement, when in fact software corruption is a common cause that can be fixed with built-in utilities.

251
MCQmedium

A technician is tasked with deploying 50 Android tablets for a field sales team. The tablets need to have a consistent set of apps, settings, and security policies. The technician wants to avoid manually configuring each device. Which Android feature should the technician use?

A.Samsung DeX
B.Google Backup
C.Android Enterprise (Zero-Touch Enrollment)
D.Developer Options > OEM Unlocking
AnswerC

Android Enterprise, particularly with Zero-Touch Enrollment, is the ideal solution for deploying a large fleet of Android tablets. This system allows organizations to pre-configure devices through an authorized reseller, so when a new tablet is unboxed and connected to the internet, it automatically enrolls into the designated Mobile Device Management (MDM) solution. This seamless process enables IT administrators to remotely apply consistent security policies, configure network settings, and push required applications to all 50 devices without manual intervention on each tablet, ensuring standardized and secure deployment.

Why this answer

Android Enterprise Zero-Touch Enrollment allows IT administrators to provision devices automatically by associating them with a management provider (e.g., Samsung Knox, VMware Workspace ONE) via the manufacturer's portal. When the tablets are powered on and connected to Wi-Fi, they download a policy that enforces apps, settings, and security configurations without any manual intervention. This is the correct solution for deploying 50 tablets consistently.

Exam trap

The trap here is that candidates confuse Google Backup (a personal restore tool) with enterprise provisioning, or think Samsung DeX can manage device settings, when in fact only Android Enterprise Zero-Touch Enrollment automates bulk deployment of apps and policies.

How to eliminate wrong answers

Option A is wrong because Samsung DeX is a desktop-like interface for productivity, not a mass provisioning or enrollment feature. Option B is wrong because Google Backup is designed to restore personal user data (e.g., contacts, app data) from the cloud, not to enforce enterprise-wide policies or install a consistent set of apps across multiple devices. Option D is wrong because Developer Options > OEM Unlocking is used to unlock the bootloader for custom ROMs or rooting, which is a security risk and irrelevant to enterprise enrollment and policy deployment.

252
MCQeasy

A user reports that their Windows 10 computer runs a script every time they log in that maps a network drive, but the drive mapping fails intermittently. The script uses the 'net use' command. Which scripting element should be added to handle the failure gracefully and retry the mapping?

A.A comment line explaining the net use syntax
B.A variable to store the drive letter
C.An exit code check and a loop to retry the mapping
D.A 'pause' command after the net use line
AnswerC

Checking the exit code, often via ERRORLEVEL in batch or $LastExitCode in PowerShell, allows a script to programmatically determine the success or failure of the preceding command. When combined with a loop, the script can detect a failure and then re-attempt the net use command multiple times. This approach provides crucial fault tolerance, enabling the script to overcome transient network issues or temporary server unavailability until the mapping succeeds or a predefined retry limit is reached.

Why this answer

Adding an exit code check after 'net use' and a loop to retry the mapping allows the script to detect failure (non-zero exit code) and attempt the mapping again, handling intermittent network issues gracefully. This is a standard scripting pattern for resilience.

Exam trap

220-1202 often tests the difference between cosmetic script elements (comments, variables, pause) and actual error-handling constructs like exit code checks and loops.

How to eliminate wrong answers

Option A is wrong because a comment does not affect execution and cannot handle failures. Option B is wrong because storing the drive letter in a variable does not provide error handling or retry logic. Option D is wrong because 'pause' only suspends execution and waits for user input, which is not suitable for an automated login script and does not retry the mapping.

253
MCQmedium

A user reports that their virtual machine running on a Type 2 hypervisor is extremely slow. The host machine has 16 GB of RAM, and the VM is configured with 8 GB. The host's task manager shows 90% memory usage. What should the technician do to improve the VM's performance?

A.Increase the number of virtual CPUs assigned to the VM.
B.Reduce the amount of RAM allocated to the VM to 4 GB.
C.Change the virtual disk from thin to thick provisioning.
D.Enable hyper-threading on the host CPU.
AnswerB

Reducing the VM's RAM frees up memory for the host, alleviating the memory pressure and improving overall performance.

Why this answer

The host is experiencing 90% memory pressure, meaning the host OS is starved of RAM. A Type 2 hypervisor (like VMware Workstation or VirtualBox) relies on the host OS to manage memory; if the host is paging heavily, the VM will also suffer. Reducing the VM’s allocated RAM from 8 GB to 4 GB frees memory for the host, reducing swapping and improving overall VM performance.

Exam trap

A common mistake is the misconception that adding more virtual resources (vCPUs or disk provisioning changes) always improves performance, when in reality the root cause is host memory starvation, and the correct fix is to reduce the VM's allocated RAM.

How to eliminate wrong answers

Option A is wrong because increasing virtual CPUs would increase CPU scheduling overhead and could worsen performance, especially when the bottleneck is memory, not CPU. Option C is wrong because changing from thin to thick provisioning affects disk I/O performance and storage allocation, not the immediate memory pressure causing the slowness. Option D is wrong because enabling hyper-threading on the host CPU improves parallel processing but does not address the host’s 90% memory usage; it could even increase memory contention if more threads compete for the same limited RAM.

254
MCQeasy

A technician needs to map a network drive to a shared folder on a file server for a user who frequently works remotely. The share path is \\Server\Data. Which command would you use to persistently map this drive as drive letter Z:?

A.net user Z: \\Server\Data /add
B.net use Z: \\Server\Data /persistent:yes
C.chkdsk Z: /f
D.ipconfig /renew
AnswerB

The net use command maps drive Z: to the UNC path \\Server\Data, and the /persistent:yes switch writes the mapping into the user's profile so it survives reboots. This satisfies the requirement for a persistent mapped drive for the remote user.

Why this answer

The `net use` command is used to map a network share to a drive letter, and the `/persistent:yes` switch ensures the mapping is reconnected automatically after a reboot or network interruption, which is essential for a user who works remotely. The syntax `net use Z: \\Server\Data /persistent:yes` correctly specifies the drive letter, UNC path, and persistence flag.

Exam trap

The trap here is confusing `net use` with `net user` — candidates often misremember the command name or think `/add` applies to drive mappings, when in fact `net user` is strictly for account management.

How to eliminate wrong answers

Option A is wrong because `net user` is used to manage local user accounts, not to map network drives; the `/add` switch adds a user account, making this command entirely unrelated to drive mapping. Option C is wrong because `chkdsk` checks the file system integrity of a volume and cannot map a network share; the `/f` flag fixes errors on a local disk, not a remote path. Option D is wrong because `ipconfig /renew` renews the DHCP lease for a network adapter, which does not map a drive or create a persistent connection to a shared folder.

255
MCQmedium

A customer calls to report that their laptop won't turn on. The technician suspects a dead battery. Which of the following responses demonstrates proper troubleshooting and professionalism?

A.Tell the customer to buy a new battery immediately.
B.Ask the customer to plug in the charger and see if any lights appear.
C.Say that the motherboard is likely dead and needs replacement.
D.Tell the customer to bring the laptop to the shop without further questions.
AnswerB

This is the most logical and effective initial troubleshooting step. By instructing the customer to connect the AC adapter, the technician can quickly ascertain if the laptop receives external power and if the charging circuitry or power-on sequence initiates, indicated by status lights. This action helps differentiate between a completely dead battery, a faulty AC adapter, or a more severe internal hardware failure, guiding subsequent diagnostic efforts.

Why this answer

A systematic approach to troubleshooting shows competence. Starting with simple checks and explaining each step keeps the customer informed and involved.

256
MCQeasy

During a software deployment, a technician must explain to a non-technical manager why a critical security update requires an immediate reboot of all workstations, even though it interrupts work. The manager is concerned about productivity loss. How should the technician communicate this?

A."The update fixes a vulnerability that could let attackers steal company data. A reboot is required to apply it. The risk of a breach outweighs the short downtime."
B."Just schedule the reboot for after hours and it won't affect productivity."
C."It's IT policy. We have to do this. Please inform your team."
D."The update is mandatory, but you can delay it for a week if needed."
AnswerA

This response effectively communicates the critical nature of the update by explaining the direct business impact: preventing data theft due to a vulnerability. It clearly states the technical requirement (reboot) and provides a strong justification by weighing the risk of a security breach against the short operational downtime. This approach demonstrates a technician's ability to translate technical issues into understandable business terms, fostering informed decision-making and cooperation from non-technical stakeholders.

Why this answer

It directly addresses the manager's concern about productivity loss by clearly explaining the security risk (data theft via an unpatched vulnerability) and why the reboot is necessary to apply the update. This approach uses risk-benefit language that a non-technical manager can understand, aligning with the CompTIA A+ objective of communicating technical requirements to stakeholders in business terms.

Exam trap

CompTIA often tests the candidate's ability to prioritize security over convenience and to communicate technical risks in business terms, so the trap here is choosing a technically correct but poorly communicated answer (like B or C) that fails to address the manager's legitimate productivity concerns.

How to eliminate wrong answers

Option B is wrong because it suggests scheduling the reboot for after hours, which may not be feasible if the security update requires an immediate reboot to close a critical vulnerability that is actively being exploited; delaying the reboot even a few hours could expose the network to attack. Option C is wrong because citing 'IT policy' without explaining the technical reason fails to build trust or address the manager's productivity concern, and it does not provide the necessary context for why the reboot cannot be deferred. Option D is wrong because allowing a one-week delay for a critical security update is irresponsible; the vulnerability could be exploited in the wild within hours, and delaying the patch violates security best practices and potentially compliance requirements.

257
MCQhard

A technician is investigating a security incident where multiple workstations on the same network are showing signs of infection: slow performance, unusual network traffic, and the presence of a file named 'svch0st.exe' in the Startup folder. The technician suspects a worm that spreads through network shares. What is the most effective containment strategy?

A.Run a full antivirus scan on all workstations simultaneously.
B.Disable network shares and isolate infected workstations from the network.
C.Update the antivirus definitions on one workstation and scan it.
D.Reboot all workstations into Safe Mode with Networking.
AnswerB

Disabling network shares and isolating infected workstations are critical immediate steps for containing a spreading worm. This action directly cuts off common propagation vectors, such as shared folders and network services, preventing the worm from infecting additional machines or escalating its impact. By segmenting the network and quarantining compromised systems, the technician effectively halts the spread, allowing for a more controlled and effective remediation process.

Why this answer

Disabling network shares and isolating infected workstations from the network is the most effective containment strategy because the worm spreads through network shares (SMB protocol). By cutting off the propagation vector (network shares) and isolating infected hosts, you prevent the worm from reaching other workstations, even if the malware is still active locally. This aligns with the immediate containment phase of incident response, which prioritizes stopping the spread over remediation.

Exam trap

The 220-1202 exam often tests the distinction between remediation (cleaning the infection) and containment (stopping the spread), and the trap here is that candidates choose a remediation action like scanning or updating definitions instead of the immediate containment step of disabling the propagation vector.

How to eliminate wrong answers

Option A is wrong because running a full antivirus scan on all workstations simultaneously does not stop the worm from actively spreading through network shares during the scan; the worm can continue to infect new systems while scans are running, and scanning without isolation is ineffective for containment. Option C is wrong because updating antivirus definitions on one workstation and scanning only that single system ignores the fact that the worm is already on multiple workstations and actively spreading via network shares; this does not contain the outbreak. Option D is wrong because rebooting all workstations into Safe Mode with Networking still leaves network shares enabled and the workstations connected to the network, allowing the worm to continue spreading via SMB; Safe Mode with Networking does not disable file sharing or isolate the systems.

258
MCQhard

A technician is investigating a security breach where sensitive customer data was exfiltrated. The only malware found is a hidden driver that intercepts keystrokes and sends them to a remote server. Which malware type is responsible, and what is the best removal strategy?

A.Spyware; remove by running a standard antivirus scan.
B.Keylogger; use a rescue disk to boot and run an anti-rootkit scanner.
C.Ransomware; restore from backup.
D.Adware; uninstall suspicious programs from Control Panel.
AnswerB

A keylogger operating as a rootkit embeds itself deeply within the operating system's kernel, allowing it to intercept keystrokes while remaining hidden from standard security software. Using a rescue disk allows the system to boot into a clean, uncompromised environment, bypassing the rootkit's stealth mechanisms. From this clean state, an anti-rootkit scanner can effectively detect and remove the malicious kernel-level components without the rootkit actively defending itself.

Why this answer

The malware is a hidden driver that intercepts keystrokes and sends them to a remote server, which is the classic behavior of a keylogger. Because it is a driver, it likely operates at the kernel level, making it a rootkit. Standard antivirus scans may miss it because the OS is compromised, so the best removal strategy is to boot from a rescue disk (clean OS) and run an anti-rootkit scanner to detect and remove the driver without the rootkit hiding itself.

Exam trap

The CompTIA A+ exam often tests the misconception that any malware that steals data is spyware, but the specific mechanism (hidden driver intercepting keystrokes) points to a keylogger, and the trap is that candidates overlook the need for a rescue disk because they assume a standard antivirus scan can remove kernel-level threats.

How to eliminate wrong answers

Option A is wrong because spyware typically collects browsing habits or personal data without necessarily intercepting keystrokes, and a standard antivirus scan is often ineffective against kernel-level drivers that hide from the OS. Option C is wrong because ransomware encrypts files and demands payment, not exfiltrates data via keystroke interception; restoring from backup does not remove the hidden driver. Option D is wrong because adware displays unwanted ads and is usually removed via Control Panel, but a hidden driver keylogger requires specialized tools like anti-rootkit scanners, not simple uninstallation.

259
MCQeasy

A customer reports that their laptop was stolen from a locked office over the weekend. The office door uses a standard key lock, and the laptop was not physically secured. Which physical security control would have most likely prevented this theft?

A.Use a smart card reader on the door
B.Install a security camera in the hallway
C.Attach a cable lock to the laptop
D.Enable BitLocker on the laptop
AnswerC

Attaching a cable lock directly to the laptop provides a robust physical security measure by anchoring the device to a fixed, immovable object. This significantly impedes the physical removal of the laptop, making it much harder and more time-consuming for a thief to steal without specialized tools or causing noticeable damage. It directly prevents the easy physical displacement of the asset.

Why this answer

A cable lock physically tethers the laptop to a fixed object such as a desk or wall mount, directly preventing removal from the premises. Since the laptop was stolen from a locked office, the failure was the lack of a physical tether, not the door lock itself. A cable lock is the specific physical control designed to deter and prevent laptop theft.

Exam trap

220-1202 often tests the distinction between preventive physical controls (cable lock) and detective/logical controls (camera, BitLocker) — candidates pick BitLocker because it 'protects the laptop,' but it only protects data, not the hardware.

How to eliminate wrong answers

Option A is wrong because a smart card reader on the door is an authentication control that restricts who can enter, but the door was already locked and the thief still gained entry — it does not prevent removal of the laptop once inside. Option B is wrong because a security camera is a detective control that records activity for later investigation; it does not physically stop a theft in progress. Option D is wrong because BitLocker is a data-at-rest encryption control that protects the contents of the drive if the laptop is stolen, but it does not prevent the physical theft itself.

260
MCQeasy

A user reports that they can no longer connect to the company network from home using VPN. They confirm their internet connection is working and that they can browse websites. Which of the following should a technician check first to resolve the VPN connectivity issue?

A.Check if the VPN client software is up to date
B.Verify the user's VPN username and password
C.Restart the VPN server at the data center
D.Reinstall the network adapter drivers
AnswerB

Incorrect or expired user credentials, including the username and password, are an extremely common and easily overlooked cause of VPN connection failures. Authentication is the initial gateway to establishing a secure tunnel, and any mismatch or invalidation of these details will prevent the client from authenticating with the VPN server. Verifying these details with the user and potentially testing them is a fundamental and efficient first troubleshooting step, as it addresses a frequent point of failure without impacting other systems.

Why this answer

The user's internet connection is working (they can browse websites), which rules out general network connectivity issues. The most common cause of VPN authentication failure is incorrect or expired credentials, so verifying the username and password is the quickest and most logical first step before escalating to more complex troubleshooting.

Exam trap

CompTIA often tests the principle of 'start with the simplest and most likely cause'—the trap here is that candidates jump to advanced fixes like updating software or restarting servers, overlooking the basic credential check that resolves the majority of single-user VPN failures.

How to eliminate wrong answers

Option A is wrong because checking if the VPN client software is up to date is a secondary step; outdated client software typically causes compatibility or feature issues, not authentication failures, and the user's ability to browse indicates the client is at least launching. Option C is wrong because restarting the VPN server at the data center is a drastic, disruptive action that should only be taken after ruling out client-side and authentication issues; it is not a first-line troubleshooting step for a single user. Option D is wrong because reinstalling network adapter drivers addresses hardware or driver-level connectivity problems, but the user's internet is working, so the network adapter is functioning correctly.

261
MCQmedium

A user complains that their Android phone's battery drains extremely fast after a recent OS update. They have already tried restarting the device. What is the most likely cause and solution?

A.The update installed a malware app; perform a factory reset.
B.The update reset battery optimization settings; re-enable them.
C.The device is performing background indexing; wait a day or two.
D.The battery is failing due to the update; replace the battery.
AnswerC

After a major Android system update, devices often perform extensive background tasks such as re-indexing files, optimizing installed applications for the new OS version, rebuilding caches, and synchronizing data. These intensive processes utilize the CPU, storage, and network, leading to temporarily increased power consumption and noticeable battery drain. Allowing the device a day or two to complete these essential post-update operations typically resolves the issue as the system stabilizes and returns to normal power usage patterns.

Why this answer

After a major OS update, Android devices often perform background indexing of files, media, and app data to optimize search and performance. This process is CPU- and I/O-intensive, causing increased battery drain for 24–48 hours. The correct solution is to wait a day or two for indexing to complete, as restarting alone does not stop this background task.

Exam trap

CompTIA often tests the misconception that any post-update battery drain is due to malware or a failing battery, when in fact background system processes like indexing are the most common cause.

How to eliminate wrong answers

Option A is wrong because malware is not a typical consequence of an official OS update from the device manufacturer or carrier; a factory reset is an extreme and unnecessary step for temporary post-update battery drain. Option B is wrong because OS updates do not reset battery optimization settings; they may change default app permissions or background restrictions, but the core optimization settings remain intact. Option D is wrong because a battery does not suddenly fail due to a software update; battery degradation is gradual and unrelated to OS version changes.

262
MCQhard

A technician is troubleshooting a user's slow computer. The user mentions they received a call from 'Windows Support' saying their computer had a virus. The user gave the caller remote access to 'fix' it. Now, the computer is running slower and has strange pop-ups. What is the most likely consequence of this social engineering attack?

A.The computer is now part of a botnet used for DDoS attacks.
B.The attacker installed a keylogger to steal credentials and sensitive data.
C.The computer's BIOS has been corrupted.
D.The hard drive has been physically damaged.
AnswerB

A keylogger is a highly effective form of spyware designed to record every keystroke made on the compromised system. This allows an attacker to covertly capture sensitive information such as usernames, passwords, credit card numbers, and other personal data as the user types it. The exfiltrated data can then be used for identity theft, unauthorized financial transactions, or gaining access to other online accounts, directly leading to significant personal and financial compromise.

Why this answer

The attacker gained remote access to the user's computer under the guise of tech support. Once in, they installed a keylogger to capture keystrokes, which is a common payload in such social engineering attacks. This allows the attacker to steal credentials, banking information, and other sensitive data, explaining the continued slow performance and pop-ups.

Exam trap

CompTIA A+ often tests the distinction between generic malware effects (like botnet membership) and the specific, high-value goal of credential theft in social engineering scenarios, leading candidates to choose a broader but less precise answer.

How to eliminate wrong answers

Option A is wrong because while a botnet infection is possible, the immediate and most likely consequence of a tech support scam is credential theft via a keylogger, not necessarily DDoS participation. Option C is wrong because BIOS corruption requires specific, targeted firmware-level access and is not a typical outcome of a remote desktop session; the attacker would need to reboot into a special mode or use a BIOS flashing tool. Option D is wrong because physical hard drive damage cannot occur through remote access; the symptoms are caused by malicious software, not hardware failure.

263
MCQmedium

A technician is configuring a new virtual machine for a developer. The developer needs to run multiple isolated environments for testing, but the host machine has limited storage space. Which type of virtual disk configuration should the technician use to minimize storage usage while still allowing the VM to grow as needed?

A.Thick provisioning
B.Thin provisioning
C.Fixed-size disk
D.Dynamic disk
AnswerB

Thin provisioning is a virtual disk allocation method that allocates storage space on an as-needed basis, allowing the virtual machine's disk to grow incrementally as data is written to it. Initially, only a small amount of physical storage is consumed on the host, with additional blocks being allocated from the storage pool only when the VM actually writes new data. This approach significantly minimizes storage usage by avoiding the pre-allocation of unused space, making it ideal for environments where storage efficiency and oversubscription are critical.

Why this answer

Thin provisioning (Option B) allocates storage on demand, writing only the data blocks that are actually used, which minimizes initial storage consumption while allowing the virtual disk to grow dynamically up to its maximum configured size. This is ideal for the developer's scenario of multiple isolated test environments on a host with limited storage space.

Exam trap

The A+ exam often tests the distinction between thin provisioning and dynamic disks, where candidates mistakenly choose 'dynamic disk' because it sounds like it grows, but it is a Windows RAID-like volume manager, not a virtual disk provisioning type.

How to eliminate wrong answers

Option A is wrong because thick provisioning pre-allocates the entire virtual disk size at creation, consuming maximum storage immediately and defeating the goal of minimizing storage usage. Option C is wrong because a fixed-size disk is synonymous with thick provisioning, requiring the full allocated space upfront with no ability to grow dynamically. Option D is wrong because 'dynamic disk' is a Windows disk management concept unrelated to virtual disk provisioning; the correct VMware/Hyper-V term for on-demand allocation is thin provisioning.

264
MCQmedium

A user complains that their Remote Desktop session to a Windows 10 Pro workstation frequently disconnects after a few minutes of inactivity. The workstation is on a local network. Which setting should the technician modify on the host computer to prevent this?

A.Disable the screensaver
B.Increase the idle session limit in Remote Desktop settings
C.Change the power plan to High Performance
D.Enable Network Level Authentication
AnswerB

Increasing the idle session limit directly addresses the problem of premature disconnections. Remote Desktop Services on the host system incorporates specific policies, often configured via Group Policy or local security policy, that dictate how long an active session can remain idle before being automatically disconnected or terminated. By extending this configured timeout value, the Remote Desktop host will allow the user's session to persist for a longer duration of inactivity, preventing early disconnections.

Why this answer

The Remote Desktop Session Host (RDSH) has a configurable idle session limit that disconnects sessions after a period of inactivity. By default, Windows 10 Pro may enforce a short idle timeout (often 1-5 minutes) to conserve resources. Increasing this limit in the Remote Desktop Session Host settings (under Local Group Policy or the Remote Desktop Services configuration) prevents the automatic disconnection the user is experiencing.

Exam trap

The trap here is that candidates confuse the idle session timeout with power management or screensaver settings, assuming that preventing the screen from turning off will keep the RDP session alive, when in fact the disconnect is controlled by a dedicated Remote Desktop timeout policy.

How to eliminate wrong answers

Option A is wrong because disabling the screensaver prevents the screen from locking or turning off, but it does not affect the Remote Desktop idle session timeout, which is controlled by RDSH policies, not display settings. Option C is wrong because changing the power plan to High Performance prevents the computer from sleeping or reducing power, but the idle disconnect is a session-level timeout set in Remote Desktop services, not a power management feature. Option D is wrong because Network Level Authentication (NLA) is a security feature that requires pre-authentication before a full RDP connection is established; it does not control session disconnection due to inactivity.

265
MCQmedium

A company is moving its on-premises email server to a cloud-based service. The IT manager is concerned about data security and wants to ensure that the email data is encrypted both at rest and in transit. Which cloud service model is the company most likely using?

A.Infrastructure as a Service (IaaS)
B.Platform as a Service (PaaS)
C.Software as a Service (SaaS)
D.Desktop as a Service (DaaS)
AnswerC

SaaS delivers a complete application managed by the provider, which handles encryption at rest and in transit. The company consumes hosted email without managing infrastructure, matching the stem's cloud email migration and its encryption requirements.

Why this answer

The company is moving its on-premises email server to a cloud-based service, which means they are using a complete email application delivered over the internet. Software as a Service (SaaS) provides ready-to-use applications like email (e.g., Microsoft 365, Google Workspace) where the provider manages the infrastructure, platform, and application, including encryption at rest (e.g., AES-256) and in transit (e.g., TLS 1.2/1.3). This aligns with the IT manager's concern about data security without the company needing to manage underlying servers or platforms.

Exam trap

The exam often tests the distinction between IaaS, PaaS, and SaaS by presenting a scenario where a specific application (like email) is being moved, and the trap is that candidates confuse the underlying infrastructure (IaaS) with the service model that actually provides the application (SaaS).

How to eliminate wrong answers

Option A is wrong because Infrastructure as a Service (IaaS) provides virtualized computing resources (e.g., VMs, storage) but not a pre-built email application; the company would still need to install and manage the email server software and configure encryption themselves. Option B is wrong because Platform as a Service (PaaS) provides a development and deployment environment (e.g., runtime, database) but not a ready-to-use email application; the company would have to build or deploy their own email solution on the platform. Option D is wrong because Desktop as a Service (DaaS) delivers virtual desktops to end-users, not a specific application like email; it focuses on providing a full desktop OS experience, not a managed email service.

266
MCQmedium

During a wireless site survey, a technician discovers that an employee has set up a personal wireless router in their cubicle, connected to the corporate network. This rogue access point is broadcasting an open SSID. Which security risk is most immediately concerning?

A.The rogue AP may cause radio frequency interference with the corporate WLAN.
B.The rogue AP provides an unencrypted entry point for attackers to access the corporate network.
C.The rogue AP will consume additional power from the corporate UPS.
D.The rogue AP's DHCP server may conflict with the corporate DHCP server.
AnswerB

A rogue access point, especially one configured without encryption or authentication (an open SSID), creates a critical vulnerability by providing an unauthorized and unsecured entry point directly into the corporate network. Attackers can easily connect to this unencrypted network, bypass perimeter defenses, and then launch various attacks, such as sniffing traffic, performing man-in-the-middle attacks, or attempting to access internal resources and sensitive data, posing an immediate and severe security breach.

Why this answer

The most immediate security risk of a rogue access point broadcasting an open SSID is that it provides an unencrypted entry point into the corporate network. Any attacker within range can associate with the open SSID and, because the AP is connected to the corporate LAN, gain direct access to internal resources without authentication or encryption, bypassing perimeter security controls.

Exam trap

The 220-1202 exam often tests the distinction between operational nuisances (interference, DHCP conflicts, power draw) and actual security threats, so the trap here is that candidates may focus on the technical annoyance of a rogue AP rather than the critical security implication of an unencrypted entry point.

How to eliminate wrong answers

Option A is wrong because while a rogue AP can cause RF interference, that is a performance issue, not a security risk, and the question specifically asks about the most immediately concerning security risk. Option C is wrong because power consumption from a single small AP is negligible and does not represent a meaningful security threat. Option D is wrong because a DHCP conflict is a network configuration problem that can cause connectivity issues, but it is not a security vulnerability; the open SSID allowing unauthorized network access is far more critical.

267
MCQeasy

A user reports that their workstation cannot connect to the company file server after a scheduled network maintenance window last night. The technician checks the change management records and finds no mention of any changes to the file server. What is the most likely cause of the issue?

A.The file server requires a firmware update
B.The maintenance window affected a network switch that the file server relies on
C.The user’s account password has expired
D.The file server’s hard drive has failed
AnswerB

A maintenance window implies changes were made to systems or infrastructure. If an undocumented or unannounced change occurred on a critical network device, such as a switch, router, or firewall, that provides the network path to the file server, it would directly explain a sudden loss of network access for user workstations. Even if the file server itself was untouched, its network connectivity could be severed or reconfigured incorrectly, leading to the workstation's inability to establish a connection post-maintenance.

Why this answer

The scheduled network maintenance window is the key clue: it likely involved changes to network infrastructure such as switches, routers, or VLAN configurations. If a network switch that the file server depends on was modified or rebooted during maintenance, the workstation would lose connectivity even though the file server itself was untouched. Change management records only track changes to the file server, not to network devices, so the absence of file server changes does not rule out a network-level cause.

Exam trap

CompTIA often tests the concept that change management records only reflect changes to the specific device in question, not to the broader network infrastructure, leading candidates to overlook network-level causes like a switch misconfiguration during maintenance.

How to eliminate wrong answers

Option A is wrong because a firmware update is a planned change that would be documented in change management; it is not a typical outcome of a maintenance window and would not suddenly cause a connectivity issue without prior notice. Option C is wrong because an expired password would prevent authentication but not block network connectivity to the file server; the user would still be able to ping or reach the server at the transport layer. Option D is wrong because a hard drive failure would cause the file server to become unresponsive or fail to boot, but the user would likely see a 'server not found' error rather than a simple connectivity loss, and such a failure is unrelated to the scheduled maintenance window.

268
MCQmedium

A technician is replacing a damaged power supply in a desktop PC. After removing the old unit, the technician notices a large capacitor on the motherboard is bulging. What should the technician do to safely handle this situation?

A.Proceed with installing the new power supply and ignore the bulging capacitor.
B.Use a screwdriver to short the capacitor leads to discharge it.
C.Wear insulated gloves and carefully remove the motherboard for replacement.
D.Apply electrical tape over the bulging capacitor to contain it.
AnswerC

Wearing insulated gloves is a crucial safety measure when handling internal computer components, especially near potentially charged capacitors, as it protects against accidental electrical shock. A bulging capacitor signifies a severe defect in the motherboard's power delivery system, making the entire board unreliable and potentially dangerous. Replacing the entire motherboard is the most effective and safest solution because it completely eliminates the faulty component and its associated risks, ensuring system stability and preventing future issues. This approach prioritizes technician safety and system integrity.

Why this answer

A bulging capacitor indicates a failed or failing component that can leak electrolyte, cause further damage, or even burst. The safest course is to wear insulated gloves to avoid electric shock or chemical exposure and replace the entire motherboard, as the capacitor cannot be safely repaired in the field. Ignoring it or attempting makeshift fixes risks short circuits, fire, or injury.

Exam trap

The trap here is that candidates may think a bulging capacitor is harmless or can be safely discharged with a screwdriver, but the exam tests the correct safety protocol of replacing the damaged component with proper personal protective equipment.

How to eliminate wrong answers

Option A is wrong because ignoring a bulging capacitor can lead to electrolyte leakage, short circuits, or catastrophic failure that may damage the new power supply or other components. Option B is wrong because shorting capacitor leads with a screwdriver can cause a dangerous spark, electric shock, or damage to the motherboard traces; capacitors should be discharged through a proper resistor or allowed to self-discharge. Option D is wrong because applying electrical tape does not address the internal failure, and the capacitor may still leak, burst, or cause a short circuit under load.

269
MCQhard

A security analyst notices that an employee's account is logging in successfully from two different countries within a five-minute window. The account uses a complex password, and the employee confirms they did not travel. The organization already requires multifactor authentication for all users. Which of the following is the MOST likely cause of the suspicious logins?

A.The employee is using a corporate VPN that assigns an exit node in another country
B.The employee's password was guessed by a brute-force attack
C.The employee's session cookie was stolen and reused by an attacker
D.The multifactor authentication provider is synchronizing time zones incorrectly
AnswerC

When MFA is enforced, an attacker who cannot replay the password may steal an authenticated session cookie and present it from another location, bypassing the need to re-authenticate. Two successful logins from distant countries within minutes, with a valid complex password and no travel, match session hijacking rather than password compromise or normal behavior.

Why this answer

MFA blocks credential replay, so an attacker who obtains a valid session token can continue using the already-authenticated session without triggering another challenge. Two successful logins from distant countries within minutes, with a complex password and no travel, point to stolen session cookies rather than password guessing, time-zone display issues, or a single VPN exit node.

Exam trap

The trap here is assuming MFA prevents all account takeover, when stolen session cookies let an attacker ride an already-authenticated session from a different location.

270
MCQmedium

A user reports that a shared file on a Linux server is not accessible to their team. The file permissions are -rwxr----- and the user is a member of the group 'staff'. The file's group owner is 'admin'. Which command should the administrator run to allow the staff group to read the file?

A.chmod 755 file
B.chmod g+r file
C.chgrp staff file
D.chown user:staff file
AnswerC

The `chgrp staff file` command directly changes the group ownership of the specified file from its current group (e.g., 'admin') to the 'staff' group. By doing so, any existing group permissions (e.g., read, write, execute) associated with the file will now apply to all members of the 'staff' group. This precisely resolves the access issue for the user's team by aligning the file's group ownership with their team's group, granting them the intended access without altering owner or 'others' permissions.

Why this answer

The file's current permissions (-rwxr-----) grant the owner full access and the group 'admin' read-only access, but the user is in the 'staff' group, not 'admin'. To allow the 'staff' group to read the file, the file's group owner must be changed to 'staff' using `chgrp staff file`. This ensures that the group read permission (r--) applies to members of the 'staff' group.

Exam trap

The trap here is that candidates often confuse 'chmod g+r' (which modifies permissions for the current group) with changing the group ownership, leading them to overlook the core issue that the file's group owner is 'admin', not 'staff'.

How to eliminate wrong answers

Option A is wrong because `chmod 755 file` sets permissions to -rwxr-xr-x, which would give read and execute to everyone, including users outside the intended group, and does not address the group ownership mismatch. Option B is wrong because `chmod g+r file` adds read permission for the current group owner ('admin'), not for the 'staff' group; the user is in 'staff', so this command does not grant access to the user's group. Option D is wrong because `chown user:staff file` changes both the owner and group to 'user' and 'staff', which is excessive and could disrupt other access controls; the requirement is only to change the group ownership to 'staff', not the file owner.

271
MCQhard

During a major software rollout, a technician discovers that the deployment script modifies a registry key that is also used by a legacy application. The change was not included in the original change request. What should the technician do?

A.Proceed with the deployment since the registry change is necessary for the new software.
B.Modify the script to skip the registry change and continue.
C.Stop the deployment and submit a new change request for the registry modification.
D.Document the registry change after the deployment is complete.
AnswerC

Stopping the deployment immediately prevents the execution of an unapproved and potentially harmful registry modification. Submitting a new change request ensures that the proposed registry alteration undergoes proper review, impact assessment, testing, and approval by all relevant stakeholders, thereby mitigating risks to both the new software and existing legacy applications, and maintaining system integrity.

Why this answer

Any unapproved change to a system, even if necessary, must follow the change management process. The technician discovered that the deployment script modifies a registry key shared with a legacy application, which was not included in the original change request. Stopping the deployment and submitting a new change request ensures proper review, risk assessment, and approval before altering a shared resource that could impact the legacy application.

Exam trap

The trap here is that candidates may think a necessary change can be made immediately without approval, confusing 'necessary' with 'authorized,' but CompTIA emphasizes that all changes must follow the change management process regardless of urgency.

How to eliminate wrong answers

Option A is wrong because proceeding without approval violates change management policy and could cause unexpected failures in the legacy application due to the unplanned registry modification. Option B is wrong because skipping the registry change may break the new software deployment, as the script likely depends on that key for functionality, and modifying the script without authorization is also a change management violation. Option D is wrong because documenting the change after deployment bypasses the required pre-approval process and does not mitigate the risk of impacting the legacy application during the rollout.

272
MCQhard

During a routine security audit, a technician discovers that a user's computer has a program that opens a backdoor on port 4444 and allows remote control. The program was installed alongside a free PDF converter the user downloaded last week. Which malware type is this, and what is the most effective removal method?

A.Worm; use a network-based firewall to block port 4444.
B.Trojan horse; boot into Safe Mode and run a full anti-malware scan.
C.Ransomware; pay the ransom to regain control.
D.Rootkit; perform a clean installation of Windows.
AnswerB

A Trojan horse is a type of malware that masquerades as legitimate software, often bundled with freeware, to trick users into installing it. Once executed, it performs malicious activities, such as opening backdoors for remote access. Booting into Safe Mode loads only essential system services and drivers, preventing the Trojan from fully executing or hiding its processes, thereby making it more vulnerable to detection and removal by a full anti-malware scan.

Why this answer

The program is a Trojan horse because it disguises itself as a legitimate PDF converter while secretly installing a backdoor. The most effective removal method is to boot into Safe Mode, which loads only essential drivers and services, preventing the Trojan from running, and then perform a full anti-malware scan to detect and remove the malicious files.

Exam trap

The A+ exam often tests the distinction between a Trojan horse and a worm by emphasizing that a Trojan requires user action to install, whereas a worm spreads autonomously, leading candidates to incorrectly choose 'worm' when they see a backdoor on a specific port.

How to eliminate wrong answers

Option A is wrong because a worm self-replicates and spreads across networks without user interaction, whereas this malware required the user to download and install it alongside a PDF converter. Option C is wrong because ransomware typically encrypts files and demands payment for decryption, not opening a backdoor for remote control. Option D is wrong because a rootkit hides deep in the operating system, often at the kernel level, and requires a clean installation to ensure removal; however, this program is a user-level Trojan that can be removed via Safe Mode scanning without full reinstallation.

273
MCQmedium

A company has a policy that all workstations must automatically lock after 10 minutes of inactivity. A user complains that their computer does not lock automatically. Which setting should you check and remediate?

A.Check the power plan settings for sleep timeout
B.Verify that the screen saver is enabled and set to 'On resume, display logon screen' with a 10-minute wait
C.Ensure Windows Update is fully installed
D.Disable the Fast Startup feature
AnswerB

Enabling the screen saver and configuring it to 'On resume, display logon screen' with a specified wait time directly addresses the security requirement for locking a workstation after inactivity. This setting explicitly triggers the Windows security mechanism, requiring the user to re-authenticate with their credentials to regain access to their session. A 10-minute wait period is a common corporate standard, ensuring that unattended workstations are secured promptly against unauthorized access, thereby meeting the company's policy for workstation security.

Why this answer

The automatic lock behavior in Windows is controlled by the screen saver settings. When 'On resume, display logon screen' is enabled with a 10-minute wait, the screen saver triggers after inactivity and locks the workstation by requiring authentication upon resume. This is the standard mechanism for enforcing a lock timeout, not the power plan sleep timeout.

Exam trap

CompTIA often tests the distinction between sleep/screen saver/lock settings, and the trap here is that candidates confuse the power plan sleep timeout with the screen saver lock timeout, assuming sleep automatically locks the workstation.

How to eliminate wrong answers

Option A is wrong because the power plan sleep timeout controls when the system enters a low-power sleep state, not the lock screen; a computer can be idle and unlocked without sleeping. Option C is wrong because Windows Update installation status does not affect the screen saver or lock timeout behavior; missing updates would not prevent automatic locking. Option D is wrong because Fast Startup is a boot optimization feature that affects shutdown and startup, not idle-time locking; disabling it has no impact on the lock timeout.

274
MCQeasy

A user reports that their MacBook Pro running macOS Ventura is unable to open any applications after a recent system update. They see a spinning beach ball when clicking app icons. Which macOS tool should you use first to diagnose and resolve this issue?

A.Terminal
B.Activity Monitor
C.Disk Utility
D.System Information
AnswerB

Activity Monitor is the primary macOS utility for real-time system resource monitoring, making it the correct first step to diagnose an unresponsive application. It provides a comprehensive overview of CPU, memory, energy, disk, and network usage for all running processes. This allows a technician to quickly identify applications consuming excessive resources or those that are frozen, enabling direct termination of the problematic process to restore system responsiveness.

Why this answer

Activity Monitor is the correct first tool because it allows you to inspect running processes, CPU usage, memory pressure, and disk activity. The spinning beach ball indicates a hung or unresponsive process, likely caused by a kernel extension or system daemon failing after the update. Activity Monitor can identify the offending process (e.g., a high CPU or stuck I/O process) so you can force quit it or gather logs for further troubleshooting.

Exam trap

CompTIA A+ exams often test the misconception that Disk Utility is the universal fix for post-update issues, but the spinning beach ball is a process-level symptom, not a filesystem problem, so Activity Monitor is the correct initial diagnostic tool.

How to eliminate wrong answers

Option A is wrong because Terminal is a command-line interface that requires prior knowledge of specific commands (e.g., `top`, `kill`, `fs_usage`) and is not the first diagnostic tool for a GUI-level hang; it is more advanced and less accessible for initial triage. Option C is wrong because Disk Utility is used for repairing disk permissions, verifying disk integrity, and managing volumes, but the issue here is a process hang, not a filesystem corruption or disk error. Option D is wrong because System Information provides hardware and software configuration details but does not show real-time process activity or resource usage, making it useless for diagnosing a spinning beach ball caused by a stuck application.

275
MCQmedium

A technician is preparing to replace a failed hard drive in a server that hosts a critical database. The change requires a planned downtime of two hours. Which documentation must the technician review before proceeding?

A.The server's warranty information.
B.The approved change request and the backout plan.
C.The network topology diagram.
D.The employee handbook.
AnswerB

The approved change request is paramount as it formally authorizes the work, details the scope, potential impact, and scheduled downtime, ensuring the technician operates within established IT governance and avoids unauthorized modifications. Concurrently, the backout plan is essential for risk mitigation, outlining the precise steps to revert the system to its pre-change state if the new hard drive fails or the replacement process encounters unforeseen issues, thereby minimizing service disruption and data loss.

Why this answer

Before performing any hardware replacement that requires planned downtime, the technician must review the approved change request to confirm the change has been authorized and to understand the scope, risk, and implementation steps. The backout plan is equally critical as it provides the documented steps to revert the server to its previous state if the replacement fails, ensuring database integrity and minimizing extended downtime. This aligns with ITIL change management best practices and CompTIA A+ 220-1202 objectives for documentation review during hardware maintenance.

Exam trap

The trap here is that candidates confuse operational documentation (like network diagrams or warranty info) with the change management artifacts (change request and backout plan) that are mandatory before any planned downtime, leading them to choose a plausible but incorrect option.

How to eliminate wrong answers

Option A is wrong because warranty information is irrelevant to the immediate task of replacing a failed hard drive; it would be consulted after the fact for potential RMA, not before the procedure. Option C is wrong because a network topology diagram shows how devices are connected but does not contain the authorization, risk assessment, or rollback steps needed for a planned hardware change. Option D is wrong because the employee handbook covers company policies and conduct, not the technical change management documentation required for server maintenance.

276
MCQmedium

A user reports that their computer is running slowly and they suspect a virus. After scanning, the technician finds malware that has encrypted several files. The technician decides to wipe the drive and reinstall the OS. What should be done to ensure the malware is completely removed before data destruction?

A.Run a quick format and then reinstall the OS.
B.Use a secure erase utility that overwrites the entire drive including the boot sector.
C.Delete the encrypted files and run a registry cleaner.
D.Use System Restore to revert to a previous state.
AnswerB

A secure erase utility performs a low-level overwrite of the entire storage device, including the Master Boot Record (MBR) or GUID Partition Table (GPT), all partitions, and every data sector. This comprehensive process ensures that any persistent malware, such as bootkits or rootkits that embed themselves in the boot sector or unallocated space, is completely eradicated. By completely sanitizing the drive, it provides a clean slate for a fresh operating system installation, effectively eliminating the source of the reported slow performance if caused by deeply embedded malicious software.

Why this answer

When malware has encrypted files and the decision is to wipe and reinstall, a secure erase utility that overwrites the entire drive — including the boot sector — ensures no remnants of the malware survive. The boot sector is a common hiding place for bootkits and ransomware persistence mechanisms, so it must be included in the wipe. This is the only option that guarantees complete removal before OS reinstallation.

Exam trap

220-1202 often tests the misconception that formatting or deleting files removes malware, when in fact only a full overwrite of the drive — including the boot sector — guarantees complete eradication.

How to eliminate wrong answers

Option A is wrong because a quick format only rewrites file system metadata and leaves the underlying data and boot sector intact, allowing malware to persist. Option C is wrong because deleting encrypted files and running a registry cleaner does not remove the malware itself and leaves the system compromised. Option D is wrong because System Restore may restore the system to a point where the malware was already present, and it does not remove the infection.

277
MCQeasy

During a network upgrade, a technician needs to dispose of several old CRT monitors. Which disposal method complies with environmental regulations?

A.Place them in the regular dumpster for pickup.
B.Sell them to a scrap metal dealer.
C.Take them to an e-waste recycling center.
D.Remove the glass and dispose of the plastic casing separately.
AnswerC

Taking CRTs to an e-waste recycling center is the correct and safest method for disposal. These specialized facilities are designed and certified to properly handle and process hazardous electronic waste. They employ specific techniques to dismantle CRTs, separating leaded glass, mercury, and phosphors from recyclable materials like plastics, copper, and circuit boards, ensuring that toxic substances are contained and processed according to strict environmental regulations.

Why this answer

CRT monitors contain hazardous materials like lead, phosphorus, and other heavy metals that require specialized handling. Taking them to an e-waste recycling center ensures compliance with environmental regulations such as the Resource Conservation and Recovery Act (RCRA) and local e-waste laws, as these facilities are equipped to safely dismantle and recycle the toxic components.

Exam trap

CompTIA often tests the misconception that 'recycling' or 'selling to scrap' is always acceptable, but the trap here is that only certified e-waste recycling centers are legally authorized to handle CRT monitors due to their hazardous material content, while scrap dealers and general recycling are not compliant.

How to eliminate wrong answers

Option A is wrong because placing CRT monitors in a regular dumpster violates environmental regulations due to the leaded glass and other hazardous substances, which can leach into landfills and contaminate soil and groundwater. Option B is wrong because selling CRT monitors to a scrap metal dealer is not compliant unless the dealer is a certified e-waste recycler; general scrap dealers often lack the permits and processes to handle the toxic components safely, and the monitors may contain non-metallic hazardous materials. Option D is wrong because removing the glass and disposing of the plastic casing separately does not address the hazardous nature of the leaded glass, which still requires proper e-waste recycling; moreover, this practice is typically illegal without proper certification and equipment to prevent environmental release.

278
MCQmedium

A small business has no formal change management process. A technician installs a new antivirus program on a server, which later conflicts with the existing backup software, causing backups to fail. Which principle of change management was most clearly violated?

A.The change was not tested in a staging environment
B.The change was not approved by the change advisory board
C.The change was not documented or communicated to stakeholders
D.The technician did not create a rollback plan
AnswerC

Documentation and communication are foundational elements of even the most rudimentary change management practices, regardless of business size. Without a record of what was changed, when, and by whom, troubleshooting becomes significantly more challenging, and the impact on other systems or users remains unknown. Failing to document or communicate changes directly violates the core principle of transparency and control inherent in any structured approach to modifications.

Why this answer

The scenario describes a small business with no formal change management process. The core failure is that the technician installed new antivirus software without documenting the change or communicating it to stakeholders (such as the backup administrator or other IT staff). If the change had been documented and communicated, the potential conflict with the existing backup software could have been identified and avoided.

This directly violates the principle that all changes must be documented and communicated to relevant parties, even in the absence of a formal CAB or staging environment.

Exam trap

CompTIA often tests the distinction between formal processes (like CAB approval or staging environments) and the fundamental principle of communication and documentation, leading candidates to overthink and select a more 'technical' or 'formal' answer when the scenario clearly lacks any formal structure.

How to eliminate wrong answers

Option A is wrong because while testing in a staging environment is a best practice, the question explicitly states there is 'no formal change management process,' and the primary violation is the lack of communication and documentation, not the absence of a staging environment. Option B is wrong because a Change Advisory Board (CAB) is a formal governance body typically used in larger organizations; a small business without a formal process would not have a CAB, so failing to get CAB approval is not the most clearly violated principle. Option D is wrong because although a rollback plan is important, the technician could have avoided the conflict entirely by simply communicating the change to stakeholders; the lack of a rollback plan is a secondary issue, not the core violation of change management principles.

279
MCQmedium

A company's security policy requires that all Windows 10 workstations automatically install critical updates as soon as they are released. However, users must not be forced to restart during work hours. Which Windows Update setting should you configure to meet these requirements?

A.Defer feature updates
B.Set Active Hours to cover the workday
C.Set the connection as metered
D.Configure Windows Update to 'Notify to schedule restart'
AnswerB

Setting Active Hours allows Windows to understand when the user is actively using the computer, preventing automatic restarts during these specified times. Updates will still download and install automatically in the background throughout the day or night. The system will then perform the necessary restart outside of the defined Active Hours, ensuring updates are applied without disrupting user productivity during the workday, thus meeting the policy's requirement for automatic installation without user action.

Why this answer

Configuring Active Hours in Windows Update allows you to specify the time range during which the system should not automatically restart after installing updates. By setting Active Hours to cover the entire workday, critical updates can be downloaded and installed automatically, but the required restart is deferred until outside those hours, meeting both the security policy and the user experience requirement.

Exam trap

CompTIA often tests the distinction between controlling update installation versus controlling restart behavior; the trap here is that candidates may confuse 'deferring updates' with 'scheduling restarts,' or think that marking a connection as metered is a valid way to manage restart timing, when it actually blocks all automatic updates.

How to eliminate wrong answers

Option A is wrong because 'Defer feature updates' delays the installation of non-security feature updates, not critical security updates, and does not control restart timing. Option C is wrong because setting the connection as metered prevents all automatic downloads of updates, including critical ones, which violates the policy requiring automatic installation. Option D is wrong because 'Notify to schedule restart' only alerts the user to schedule a restart but does not enforce automatic installation of critical updates; it relies on user action, which may delay installation and violate the policy.

280
MCQeasy

A technician is configuring a cloud-based backup solution for a company's critical data. The company wants to ensure that if the primary cloud provider experiences an outage, the data remains accessible from another provider. Which concept should the technician implement?

A.High availability
B.Cloud federation
C.Load balancing
D.Disaster recovery plan
AnswerB

Cloud federation links identity and services across multiple providers, so workloads and data remain reachable through a partner provider when the primary one fails. This directly addresses the requirement for continued accessibility during a provider outage.

Why this answer

Cloud federation enables the interconnection of multiple cloud providers' environments, allowing data and resources to be shared across them. By implementing cloud federation, the technician can replicate critical data to a secondary provider, ensuring that if the primary provider experiences an outage, the data remains accessible from the federated provider. This directly addresses the requirement for cross-provider data accessibility during a provider outage.

Exam trap

CompTIA A+ often tests the distinction between high availability (which keeps services running within a single provider) and cloud federation (which ensures data accessibility across providers), leading candidates to mistakenly choose high availability when the question explicitly requires cross-provider access.

How to eliminate wrong answers

Option A is wrong because high availability (HA) focuses on eliminating single points of failure within a single provider's infrastructure (e.g., redundant servers, storage, or network paths) to ensure service uptime, but it does not provide data accessibility from a different provider if the entire primary provider fails. Option C is wrong because load balancing distributes incoming traffic across multiple servers or resources to optimize performance and availability, but it does not replicate data to another provider or ensure data access during a provider-wide outage. Option D is wrong because a disaster recovery plan (DRP) outlines the processes and procedures for recovering data and IT infrastructure after a disaster, but it is a broader strategy that may include cloud federation; the specific concept that enables cross-provider data accessibility is cloud federation, not the plan itself.

281
MCQeasy

A junior admin needs to list all files in the current directory, including hidden files, with detailed information such as permissions, owner, and size. Which command should they use?

A.ls -l
B.ls -a
C.ls -la
D.ll
AnswerC

This command correctly combines the `-l` (long format) and `-a` (all files) options, providing a complete and detailed listing. `ls -la` displays comprehensive information for every file and directory, including permissions, number of links, owner, group, size, and last modification timestamp, even for those conventionally hidden by a leading dot. This combination fully satisfies the requirement to list all files with detailed attributes.

Why this answer

The `ls -la` command combines the `-l` (long format) and `-a` (all files, including hidden ones) options. This fulfills the requirement to list all files in the current directory, including hidden files (those starting with a dot), with detailed information such as permissions, owner, group, size, and modification time.

Exam trap

A common mistake is to think that either `ls -l` (shows details but not hidden files) or `ls -a` (shows hidden files but no details) is sufficient. The correct answer is `ls -la` which combines both options.

How to eliminate wrong answers

Option A is wrong because `ls -l` lists files in long format but does not include hidden files (those starting with a dot). Option B is wrong because `ls -a` lists all files including hidden ones but does not provide detailed information such as permissions, owner, or size. Option D is wrong because `ll` is often an alias for `ls -l` (not `ls -la`) in many distributions, so it would not show hidden files unless specifically aliased to include `-a`; it is not a standard command and its behavior is not guaranteed across systems.

282
MCQmedium

A technician is tasked with removing a persistent malware infection that survives reboots and re-infects the system even after a full antivirus scan in Safe Mode. The malware appears to hide in the Master Boot Record (MBR). Which removal method should the technician use?

A.Run a system file checker (sfc /scannow) from within Windows.
B.Use the Windows Recovery Environment to run bootrec /fixmbr.
C.Perform a clean installation of Windows without formatting the drive.
D.Disable System Restore and delete all restore points.
AnswerB

Using the Windows Recovery Environment (WinRE) to run `bootrec /fixmbr` is the correct approach because this command specifically targets and overwrites the Master Boot Record (MBR) with a clean, standard MBR. This action effectively eradicates any malware that has infected or modified the MBR, preventing it from loading during system startup. Performing this operation from WinRE ensures the operating system is not running, allowing for a clean and unhindered repair of the critical boot sector.

Why this answer

The malware is hiding in the Master Boot Record (MBR), which is the first sector of the boot drive and loads before the operating system. Running `bootrec /fixmbr` from the Windows Recovery Environment (WinRE) overwrites the MBR code with a clean Windows bootloader, effectively removing the malware that persists there. This method targets the infection at its source, unlike antivirus scans that run after the OS loads and cannot access the MBR while it is in use.

Exam trap

The 220-1202 exam often tests the misconception that antivirus scans in Safe Mode can remove all malware, but the trap here is that MBR-based infections load before the OS and require boot-level repair tools like `bootrec /fixmbr` to be eradicated.

How to eliminate wrong answers

Option A is wrong because `sfc /scannow` only checks and repairs protected system files within the Windows installation, not the MBR; it cannot remove malware that resides in the boot sector. Option C is wrong because performing a clean installation of Windows without formatting the drive leaves the MBR intact, allowing the malware to survive and re-infect the new OS installation. Option D is wrong because disabling System Restore and deleting restore points only removes backup copies of system files and registry, not the MBR; the malware in the boot sector remains unaffected.

283
MCQmedium

A user reports that their Windows 10 PC is running slowly and the hard drive light is constantly active. You suspect the indexing service is consuming resources. Which Control Panel applet allows you to modify which folders are indexed, or to rebuild the index?

A.File Explorer Options
B.System > Advanced system settings > Performance
C.Indexing Options
D.Administrative Tools > Services
AnswerC

Indexing Options is the dedicated control panel applet for managing the Windows Search service's indexing process. It provides comprehensive tools to specify which folders and file types are included or excluded from the search index, modify advanced indexing settings, and crucially, rebuild the entire search index database. Rebuilding the index is a common troubleshooting step to resolve issues like slow searches, incomplete results, or index corruption.

Why this answer

The Indexing Options applet (C) is the correct Control Panel tool for managing the Windows Search index. It allows you to add or remove folders from the index and provides a button to rebuild the index, which can resolve performance issues caused by a corrupted or overly broad index. The constantly active hard drive light indicates the indexing service is actively processing files, and modifying or rebuilding the index directly addresses this resource consumption.

Exam trap

CompTIA often tests the distinction between managing a service's behavior (Indexing Options) versus managing the service's running state (Services.msc), leading candidates to choose Administrative Tools > Services when the question specifically asks about modifying indexed folders or rebuilding the index.

How to eliminate wrong answers

Option A is wrong because File Explorer Options (formerly Folder Options) controls file browsing settings like showing hidden files, folder views, and search behavior, but it does not manage the indexing service or allow you to modify indexed folders or rebuild the index. Option B is wrong because System > Advanced system settings > Performance opens the Performance Options dialog, which configures visual effects, processor scheduling, and virtual memory, not indexing settings. Option D is wrong because Administrative Tools > Services lets you start, stop, or disable the Windows Search service, but it does not provide a GUI to modify which folders are indexed or to trigger a rebuild; those actions require the Indexing Options applet.

284
MCQmedium

A company uses AppLocker to control which applications can run on Windows 10 workstations. A user needs to run a portable application from a USB drive for a presentation, but it is blocked by AppLocker. The user has local admin rights. What is the best way to allow this specific application while maintaining security?

A.Temporarily disable AppLocker service.
B.Add the user to the 'Power Users' group.
C.Create a new AppLocker path rule for the USB drive.
D.Run the application as Administrator.
AnswerC

Creating a new AppLocker path rule specifically for the USB drive's location (e.g., "E:\*" or "E:\ApplicationName.exe") is the most appropriate and secure solution. This method allows the desired application to execute from the specified removable media while maintaining all other AppLocker restrictions for other applications and locations. It provides granular control, ensuring the company's security posture remains intact for all other software.

Why this answer

AppLocker enforces application control policies regardless of user privileges, including local admin rights. Creating a new path rule for the USB drive allows the specific portable application to run while keeping AppLocker active and maintaining security for other executables. This is the correct approach because it grants a targeted exception without disabling the entire control mechanism.

Exam trap

The trap here is that candidates assume local admin rights can override AppLocker restrictions, but AppLocker operates at a lower security layer that applies to all users, including administrators.

How to eliminate wrong answers

Option A is wrong because temporarily disabling the AppLocker service removes all application control, exposing the system to unauthorized software and violating security policy. Option B is wrong because the 'Power Users' group does not bypass AppLocker rules; AppLocker evaluates rules based on file path, publisher, or hash, not group membership. Option D is wrong because running the application as Administrator does not override AppLocker; AppLocker blocks execution before the process starts, regardless of the user's privilege level.

285
MCQeasy

A technician is configuring an Android phone for a user who frequently travels internationally. The user wants to ensure that data roaming is disabled to avoid high charges, but still wants to receive calls and texts while abroad. Which setting should the technician configure?

A.Enable Airplane Mode and turn on Wi-Fi.
B.Disable Mobile Data entirely.
C.Turn off Data Roaming in the mobile network settings.
D.Set the network mode to 2G only.
AnswerC

Disabling Data Roaming in mobile network settings blocks packet data over foreign networks while leaving the circuit-switched cellular connection registered, so calls and SMS still arrive. This directly satisfies the stem's constraint: avoiding roaming charges without losing voice and text services abroad.

Why this answer

Disabling Data Roaming in the mobile network settings prevents the device from using cellular data on foreign networks, which avoids expensive roaming charges, while still allowing voice calls and SMS (which use the cellular voice and signaling channels, not the data channel). This setting is specific to roaming scenarios and does not affect the phone's ability to connect to a visited network for non-data services.

Exam trap

CompTIA often tests the distinction between disabling Mobile Data entirely (which kills all data, even at home) and disabling Data Roaming (which only blocks data while on a foreign network), leading candidates to mistakenly choose Option B.

How to eliminate wrong answers

Option A is wrong because enabling Airplane Mode disables all cellular radios (including voice and SMS), so the user cannot receive calls or texts at all; turning on Wi-Fi only provides internet access, not cellular services. Option B is wrong because disabling Mobile Data entirely (via the quick settings toggle or data usage settings) also disables data on the home network, which is unnecessary and may prevent MMS or other data-dependent features even when not roaming; it does not specifically address roaming behavior. Option D is wrong because setting the network mode to 2G only forces the device to use a slower, often less available network, but does not disable data roaming—if data roaming is enabled, the device could still use 2G data and incur charges; additionally, 2G networks may not support simultaneous voice and data or may have limited coverage.

286
MCQmedium

A technician is configuring a new firewall for a small office. They need to allow remote employees to securely access the internal network. Which technology should be enabled on the firewall?

A.Port forwarding
B.VPN passthrough
C.VPN server
D.DMZ
AnswerC

A VPN server terminates encrypted tunnels from remote employees, giving them secure access to internal resources over the public internet. This directly satisfies the requirement for secure remote access, unlike packet filtering or NAT, which do not provide encrypted tunnelling.

Why this answer

A VPN server on the firewall enables secure remote access by encrypting traffic between remote employees and the internal network, typically using protocols like IPsec or SSL/TLS. This provides authenticated, encrypted tunnels that protect data in transit, which is the standard solution for secure remote connectivity.

Exam trap

The trap here is that candidates confuse 'VPN passthrough' (which only forwards existing VPN traffic) with 'VPN server' (which terminates and creates VPN connections), leading them to select option B when the question explicitly asks for enabling secure remote access.

How to eliminate wrong answers

Option A is wrong because port forwarding only redirects external traffic to a specific internal IP/port without encryption or authentication, exposing internal services directly to the internet. Option B is wrong because VPN passthrough merely allows existing VPN traffic (from a client to an external VPN server) to traverse the firewall, it does not terminate or create a VPN connection for remote employees. Option D is wrong because a DMZ is a separate network segment for public-facing servers, not a mechanism for secure remote access to the internal network.

287
MCQmedium

A technician is assigned to install new accounting software on a user's computer. The user is a senior manager who is very busy. The technician arrives and the manager says, 'Just make it work, I don't have time for questions.' Which action is MOST professional?

A.Proceed with the installation without asking any questions to respect their time.
B.Explain that you need just two quick questions to avoid problems later, and keep it brief.
C.Insist on a full meeting to discuss requirements.
D.Install the software and leave a note with questions for later.
AnswerB

This option demonstrates professionalism by acknowledging the user's time constraints while prioritizing a correct and functional installation. By briefly explaining the necessity of a few targeted questions, the technician ensures critical configuration details, such as server locations, user permissions, or specific data migration paths, are accurately captured upfront. This proactive communication minimizes the likelihood of post-installation issues, reduces potential downtime, and builds user confidence in the technician's competence.

Why this answer

The most professional action because it balances respect for the manager's time with the need to gather critical information. Asking two quick, targeted questions—such as verifying the software version compatibility with the OS or confirming the required database connection string—can prevent installation failures or post-installation issues that would waste even more of the manager's time. This approach demonstrates proactive problem-solving and aligns with CompTIA's emphasis on effective communication and professionalism.

Exam trap

CompTIA often tests the misconception that respecting a user's time means avoiding all questions, when in fact asking a few targeted, efficient questions demonstrates professionalism and prevents larger issues.

How to eliminate wrong answers

Option A is wrong because proceeding without any questions risks installing incompatible software or misconfiguring settings, which could lead to system instability or data loss, ultimately wasting more of the manager's time. Option C is wrong because insisting on a full meeting is unnecessarily disruptive and fails to respect the manager's stated time constraints, creating a negative user experience. Option D is wrong because installing the software and leaving a note with questions for later may result in the manager ignoring the note, leading to unresolved issues that could require a second visit or cause operational delays.

288
MCQeasy

A user reports that they can no longer access their encrypted files after a recent password change. The files were encrypted using EFS on a Windows 10 Pro workstation. What is the most likely cause of this issue?

A.The user changed the password via Ctrl+Alt+Del, which invalidates the EFS certificate.
B.The user did not back up their EFS certificate before changing the password.
C.The user's account was removed from the local Administrators group during the password change.
D.The hard drive has a hardware failure that corrupted the encrypted files.
AnswerB

EFS encrypts files with a symmetric File Encryption Key (FEK) that is wrapped by the user's public key, and the corresponding private key is stored under the user's password-protected master key. Without a backup of the EFS certificate, a password change can leave the master key unrecoverable, because the private key is no longer decryptable with the new password. Backing up the certificate to a .PFX file lets you re-import it after a password change, restoring access; otherwise, you may need a designated recovery agent.

Why this answer

EFS (Encrypting File System) uses a per-user certificate that is tied to the user's password hash. When a user changes their password without first backing up the EFS certificate, the system may lose access to the private key because the certificate's master key is encrypted with the old password hash. Without a backup of the certificate and private key, the encrypted files become permanently inaccessible.

Exam trap

The trap here is that candidates often think password changes via Ctrl+Alt+Del are safe or that EFS certificates are automatically updated, when in fact the critical step is backing up the EFS certificate before any password change to avoid permanent data loss.

How to eliminate wrong answers

Option A is wrong because changing the password via Ctrl+Alt+Del does not invalidate the EFS certificate; the certificate remains valid, but the system may fail to decrypt the master key if the password change is not handled properly (e.g., via a domain controller or with a password reset disk). Option C is wrong because removing a user from the local Administrators group does not affect EFS decryption capabilities; EFS permissions are based on the user's certificate and private key, not group membership. Option D is wrong because a hardware failure would typically cause read/write errors or data corruption visible at the file system level, not a specific inability to decrypt files after a password change; EFS encryption is independent of physical disk health.

289
MCQmedium

A user has accidentally deleted several important files from their Documents folder on their Mac running macOS Ventura. They need to recover them immediately. Which built-in macOS tool should you guide them to use first?

A.Time Machine from the menu bar.
B.The Trash folder in the Dock.
C.Terminal with the 'cd' and 'ls' commands.
D.System Settings > General > Storage.
AnswerB

Files deleted in Finder move to the Trash rather than being erased, so the Trash folder in the Dock is the first place to check. Dragging items out restores them instantly, before considering Terminal or recovery software.

Why this answer

When files are deleted from the Documents folder on macOS, they are first moved to the Trash, not permanently erased. The Trash folder in the Dock provides immediate access to these files, allowing the user to drag them back to their original location or use the 'Put Back' context menu option. This is the fastest and simplest recovery method before considering any backup or advanced tools.

Exam trap

The trap here is that candidates may overthink the question and jump to Time Machine as a recovery tool, forgetting that macOS first moves deleted files to the Trash, making it the immediate and correct first step.

How to eliminate wrong answers

Option A is wrong because Time Machine is a backup restoration tool that requires a previously configured backup destination and is not the first step for recovering recently deleted files that are still in the Trash. Option C is wrong because Terminal commands like 'cd' and 'ls' are used for navigating directories and listing files, not for recovering deleted files from the Trash or any other location. Option D is wrong because System Settings > General > Storage provides a storage management overview and recommendations, but it does not offer a direct file recovery mechanism for recently deleted files.

290
MCQmedium

A technician is cleaning the inside of a desktop computer that has accumulated a large amount of dust. What is the safest method to remove the dust?

A.Use a standard household vacuum cleaner with a brush attachment.
B.Use compressed air to blow the dust out of the case.
C.Use a damp cloth to wipe down the components.
D.Use a soft brush to sweep the dust out.
AnswerB

Compressed air is the industry-standard and recommended method for removing dust from computer interiors because it effectively dislodges particulate matter from intricate components without physical contact. When used correctly, holding the can upright and in short, controlled bursts, it prevents propellant discharge and minimizes static buildup. It is crucial to hold fan blades stationary while blowing to prevent over-spinning, which can damage bearings or generate back-electromotive force (back-EMF) that could harm the motherboard's fan controller circuitry.

Why this answer

Compressed air is the safest method because it dislodges dust without physical contact, avoiding electrostatic discharge (ESD) or mechanical damage to sensitive components. Unlike other methods, it does not introduce moisture or static buildup, and it can reach tight spaces between heatsinks and circuit boards.

Exam trap

The trap here is that candidates assume a vacuum cleaner is safe because it 'sucks' dust away, but CompTIA tests the understanding that vacuum cleaners generate dangerous static charges and lack the precision needed for delicate electronics.

How to eliminate wrong answers

Option A is wrong because household vacuum cleaners generate static electricity and can create ESD that damages sensitive electronics; they also lack sufficient filtration to prevent recirculation of fine dust. Option C is wrong because a damp cloth introduces moisture, which can cause short circuits, corrosion, or oxidation on exposed contacts and PCB traces. Option D is wrong because a soft brush can generate static charge through friction and may dislodge components or bend delicate pins if not used with extreme care.

291
Multi-Selectmedium

A technician is preparing to replace a faulty power supply in a desktop computer. Which of the following safety precautions should the technician take? (Choose two.)

Select 2 answers
A.Disconnect the power cord from the wall outlet before opening the case.
B.Leave the power cord connected but turn off the power supply switch.
C.Wear an antistatic wrist strap connected to a grounded surface.
D.Use a magnetic screwdriver to retrieve screws from inside the power supply.
E.Work on a carpeted floor to cushion the components.
AnswersA, C

Disconnecting the power cord removes the risk of electric shock and prevents the system from powering on accidentally. It is a fundamental safety step before working inside any computer. This precaution also allows the power supply to discharge residual power, reducing the chance of damage to components.

Why this answer

Disconnecting the power cord and wearing an antistatic wrist strap are essential safety precautions when working inside a computer. These steps prevent electric shock and electrostatic discharge, protecting both the technician and the components. The other options introduce risks such as magnetic interference, electrical hazards, or static buildup.

Exam trap

The trap here is thinking that turning off the power supply switch is sufficient, but the cord must be unplugged to ensure no power is present.

292
Multi-Selectmedium

A technician is troubleshooting a Windows 11 desktop that randomly freezes and displays a blue screen with the stop code DRIVER_IRQL_NOT_LESS_OR_EQUAL. The technician suspects a recently updated device driver. Which two tools or artifacts should the technician examine to identify the offending driver? (Choose two.)

Select 2 answers
A.The memory dump file analyzed with WinDbg
B.Driver Verifier
C.Reliability Monitor
D.Event Viewer's System log
E.Performance Monitor's counter logs
AnswersA, B

A kernel memory dump records the state of the system at the crash, and WinDbg's !analyze -v command parses the bug check to name the faulting module, often the exact driver file. For DRIVER_IRQL_NOT_LESS_OR_EQUAL, the analysis typically points to the driver that accessed invalid memory, making this the most direct identification method.

Why this answer

The memory dump analyzed with WinDbg names the faulting module directly, and Driver Verifier forces the misbehaving driver to crash deterministically so it can be identified. Together they move the investigation from a general bug check to a specific driver file that can be updated, rolled back, or removed.

Exam trap

The trap here is relying on logs that report that a crash happened rather than logs and tools that name the driver responsible for the crash.

293
MCQmedium

A user reports that their computer's hard drive is making clicking noises and they cannot access certain files. You want to check the disk for errors and attempt to repair any bad sectors. Which command should you run from an elevated command prompt?

A.chkdsk /f
B.chkdsk /r
C.sfc /scannow
D.diskpart
AnswerB

The chkdsk /r command is specifically engineered to locate bad sectors on the hard drive's physical surface and attempt to recover any readable information from those sectors. It then marks these identified bad sectors, preventing the operating system from writing data to them in the future. This comprehensive scan is crucial for a drive exhibiting physical symptoms like clicking, as it directly addresses the integrity of the disk's storage media.

Why this answer

The correct command is `chkdsk /r` because it locates bad sectors on the hard drive and recovers readable information from them. The `/r` switch implies `/f` (which fixes file system errors) and additionally performs a surface scan to identify and mark bad sectors, directly addressing the clicking noise and file access issue.

Exam trap

The trap here is that candidates confuse `/f` (file system repair) with `/r` (bad sector recovery), assuming that fixing file system errors also addresses physical disk damage, but `/r` is the only switch that performs a surface scan for bad sectors.

How to eliminate wrong answers

Option A is wrong because `chkdsk /f` only fixes file system errors (e.g., in the MFT or directory structure) without scanning for or repairing bad sectors on the disk surface; it does not address physical media damage indicated by clicking noises. Option C is wrong because `sfc /scannow` (System File Checker) verifies and repairs protected system files, such as Windows DLLs and executables, not the hard drive's physical sectors or file system integrity. Option D is wrong because `diskpart` is a disk partitioning tool used to manage volumes and partitions (create, delete, extend) and has no capability to check for errors or repair bad sectors.

294
MCQmedium

A technician needs to create a bootable USB drive that can run Windows PE to deploy a custom Windows 10 image to multiple laptops. Which Windows tool should they use to create this bootable media?

A.Windows Media Creation Tool
B.Windows System Image Manager (Windows SIM)
C.Windows ADK (Assessment and Deployment Kit)
D.Disk Management
AnswerC

The Windows Assessment and Deployment Kit (ADK) is the correct toolset for this task, as it includes Windows Preinstallation Environment (Windows PE) and the Deployment and Imaging Tools Environment. Within the ADK, technicians can use tools like DISM (Deployment Image Servicing and Management) to customize a Windows PE image with necessary drivers and applications, and then utilize scripts or commands to create a bootable USB drive specifically tailored for system imaging and deployment operations.

Why this answer

The Windows Assessment and Deployment Kit (Windows ADK) includes the Deployment Tools, which contain the necessary utilities (such as `copype.cmd` and `MakeWinPEMedia`) to create a bootable Windows PE USB drive. This is the correct tool for building custom WinPE media to deploy a Windows 10 image to multiple laptops, as it provides the full environment for customizing and generating the bootable image.

Exam trap

The trap here is that candidates often confuse the Windows Media Creation Tool (which creates standard Windows installation media) with the ADK's tools for creating custom WinPE bootable media, leading them to select option A.

How to eliminate wrong answers

Option A is wrong because the Windows Media Creation Tool is designed to download and create installation media for Windows 10 (e.g., for clean installs or upgrades), not to generate a custom Windows PE environment for imaging. Option B is wrong because Windows System Image Manager (Windows SIM) is used to create and manage unattended answer files (Unattend.xml) for automated installations, not to create bootable media. Option D is wrong because Disk Management is a utility for managing disk partitions and volumes (e.g., formatting, shrinking volumes), and it cannot create a bootable Windows PE USB drive.

295
MCQmedium

A technician is configuring a Windows 11 workstation that will be shared by multiple users in a lab. The requirement is that each user's documents and settings remain separate, and that the disk space used by each user's profile is limited to 500 MB. Which Windows feature should the technician use to enforce the storage limit?

A.Storage Spaces
B.Folder Redirection
C.Disk Quotas
D.User Account Control
AnswerC

Disk Quotas in Windows allow an administrator to set a limit on the amount of disk space each user can consume on a volume. By enabling quotas on the volume that hosts user profiles and setting a 500 MB limit per user, the technician enforces the requirement. This feature tracks usage per user and can deny writes when the limit is exceeded, directly meeting the lab's storage restriction.

Why this answer

Disk Quotas are the Windows feature designed to limit the amount of disk space individual users can consume on a volume. By enabling quotas on the volume storing user profiles and setting a 500 MB limit per user, the technician ensures each user's profile cannot exceed the specified size. Other options address data redirection, storage pooling, or privilege elevation, none of which enforce per-user storage limits.

Exam trap

The trap here is confusing data management features like Folder Redirection with actual storage enforcement, when only Disk Quotas track and limit per-user disk consumption.

296
MCQmedium

A technician is troubleshooting a Mac that fails to boot and displays a prohibitory symbol (a circle with a slash). The user had recently installed a new third-party SSD. What is the most likely cause?

A.The SSD is formatted as NTFS
B.The SSD is not properly connected or is incompatible with the Mac’s storage controller
C.The user’s home folder is corrupted
D.The Mac’s NVRAM needs resetting
AnswerB

A prohibitory symbol means the Mac cannot locate a bootable system, typically because the new third-party SSD is either physically loose or uses a controller the Mac firmware does not recognise. Reseating or replacing it with a compatible drive resolves the boot failure.

Why this answer

The prohibitory symbol indicates that the Mac cannot locate a valid operating system on the startup disk. Since the user recently installed a third-party SSD, the most likely cause is that the drive is either not properly connected (e.g., loose SATA or NVMe cable) or is incompatible with the Mac's storage controller (e.g., using a PCIe 4.0 SSD in a Mac that only supports PCIe 3.0, or a non-Apple NVMe drive lacking the required firmware for macOS). This prevents the Mac from reading the boot loader or system files.

Exam trap

Candidates often mistakenly think the prohibitory symbol is caused by file system format (like NTFS) or software corruption, when in fact it is almost always a hardware or firmware-level incompatibility preventing the drive from being recognized as bootable.

How to eliminate wrong answers

Option A is wrong because NTFS is a Windows file system, but macOS can read NTFS volumes; the prohibitory symbol is not caused by the file system format—it appears when the drive is not recognized as bootable, regardless of format. Option C is wrong because a corrupted home folder would prevent the user from logging in after the system boots, not stop the boot process itself; the prohibitory symbol appears before the login window. Option D is wrong because resetting NVRAM clears certain hardware settings but cannot fix a physical connection issue or an incompatible SSD; if the drive were properly connected and compatible, NVRAM reset might help with boot selection, but it is not the root cause here.

297
MCQmedium

A technician is setting up a new workstation in a cubicle. The cubicle has multiple power strips daisy-chained together to provide enough outlets. What is the correct safety action the technician should take?

A.Continue using the daisy-chained setup since it is convenient and all strips are rated for 15 amps.
B.Remove the daisy chain and plug each device directly into a wall outlet using a single power strip with surge protection.
C.Replace all power strips with heavy-duty extension cords rated for the total load.
D.Install a UPS at the end of the daisy chain to regulate power.
AnswerB

Removing the daisy chain and plugging each device directly into a wall outlet using a single power strip with surge protection is the safest and most compliant solution. This ensures that each power strip draws power from a properly protected circuit, preventing cumulative overload on a single point of connection. The integrated circuit breaker in the power strip provides overcurrent protection, while surge protection safeguards connected equipment from voltage spikes.

Why this answer

Daisy-chaining power strips is a fire hazard because it can exceed the ampacity of the circuit, leading to overheating and potential electrical fires. The correct safety action is to remove the daisy chain and plug each device directly into a wall outlet, using a single power strip with surge protection to safely distribute power without overloading the circuit.

Exam trap

CompTIA often tests the misconception that using multiple high-rated power strips in series is safe as long as each strip's rating is not exceeded, ignoring the cumulative load on the upstream circuit and the fire risk from daisy-chaining.

How to eliminate wrong answers

Option A is wrong because daisy-chaining power strips, even if each is rated for 15 amps, can still overload the wall outlet circuit (typically 15 or 20 amps) and violates OSHA and NEC safety standards. Option C is wrong because heavy-duty extension cords are not designed for permanent use and can still cause voltage drop or overheating if the total load exceeds the cord's rating; they also lack surge protection. Option D is wrong because installing a UPS at the end of a daisy chain does not address the root hazard of overloading the circuit; it only adds battery backup and surge protection, but the daisy chain itself remains a fire risk.

298
MCQmedium

A technician is replacing a power supply in a desktop computer. After unplugging the unit, what additional step should be taken to ensure personal safety before touching internal components?

A.Wear an anti-static wrist strap.
B.Press and hold the power button for 10 seconds.
C.Remove the CMOS battery.
D.Unplug all peripheral cables.
AnswerB

Pressing and holding the power button for approximately 10 seconds is the correct and safest procedure to discharge residual electrical energy stored within the power supply's capacitors. Even after a computer is unplugged from its AC power source, these capacitors can retain a significant and dangerous voltage for an extended period. This action provides a discharge path through the system's internal circuitry, allowing the stored energy to dissipate safely, thereby eliminating the risk of electrical shock when handling the power supply.

Why this answer

After unplugging the power supply, pressing and holding the power button for 10 seconds discharges residual electrical charge stored in the system's capacitors (especially in the power supply and motherboard). This step, often called a 'parasitic drain,' ensures that no stored voltage remains that could cause an electric shock or damage components when touched. It is a standard safety practice before working inside a desktop computer.

Exam trap

CompTIA often tests the distinction between ESD protection (anti-static wrist strap) and electrical safety (discharging capacitors), causing candidates to mistakenly choose the wrist strap as the primary safety step after unplugging.

How to eliminate wrong answers

Option A is wrong because an anti-static wrist strap protects against electrostatic discharge (ESD) damage to components, not against electric shock from stored charge; it does not discharge the power supply's capacitors. Option C is wrong because removing the CMOS battery clears BIOS settings and may help drain some motherboard capacitors, but it does not discharge the main power supply capacitors, which hold the highest risk of shock. Option D is wrong because unplugging peripheral cables reduces cable clutter but does not discharge the internal capacitors that pose a shock hazard.

299
MCQhard

A technician is creating a PowerShell script that must be deployed via Group Policy to all workstations. The script should run in the user context and display a message if the user's password is about to expire within 7 days. The script must not show any PowerShell console window. Which scripting technique should be used?

A.Use the 'Write-Host' cmdlet to display the message
B.Use a VBScript with a pop-up message box
C.Use the '-NoProfile' parameter when starting PowerShell
D.Use a scheduled task with 'Run whether user is logged on or not'
AnswerB

A VBScript can effectively display a pop-up message box using the 'MsgBox' function, which creates a graphical dialog independent of any console window. When executed via 'wscript.exe' (Windows Script Host), the VBScript process can be launched with a hidden window style (e.g., using `Start-Process -WindowStyle Hidden` in PowerShell or `WScript.Shell.Run` with a '0' parameter), allowing the message to appear without the script's execution window being visible. This method perfectly satisfies both the hidden window and user notification requirements.

Why this answer

VBScript's `MsgBox` function creates a pop-up message box that runs in the user context without a console window, making it ideal for displaying password-expiry warnings via Group Policy. PowerShell scripts, even with `-WindowStyle Hidden`, briefly flash a console window unless compiled into an executable, which violates the requirement to show no console window. VBScript natively integrates with Windows Script Host (WSH) to produce a GUI pop-up without any console overhead.

Exam trap

The trap here is that candidates assume PowerShell's `-WindowStyle Hidden` or `-NoProfile` eliminates the console window entirely, but they overlook that PowerShell.exe is inherently a console application and will still flash a window, whereas VBScript's `wscript.exe` host runs without any console.

How to eliminate wrong answers

Option A is wrong because `Write-Host` outputs text to the PowerShell console, which would display a console window, contradicting the requirement to show no console. Option C is wrong because `-NoProfile` only prevents loading PowerShell profiles, but does not suppress the console window itself; the script would still launch a visible PowerShell window. Option D is wrong because a scheduled task with 'Run whether user is logged on or not' runs in the system context, not the user context, and would not display a message to the logged-on user.

300
MCQmedium

A user reports that they received a voicemail from the company's HR director asking them to call back a number to verify their account details for payroll. The user is suspicious because the HR director is on vacation. What type of social engineering attack is this?

A.Smishing
B.Vishing
C.Pretexting
D.Pharming
AnswerB

Vishing uses voice communication, here a phone call and voicemail, to manipulate the target into disclosing account details. The callback number and payroll pretext exploit trust in the HR director, matching the stem's voice-channel social engineering scenario rather than phishing or smishing.

Why this answer

Vishing (voice phishing) is the correct classification because the attack uses a phone call—specifically a voicemail—to trick the user into calling back and divulging sensitive payroll information. Unlike phishing via email or SMS, vishing exploits voice communication channels to bypass text-based security filters and create a false sense of urgency or authority.

Exam trap

The key differentiator between vishing and pretexting is the communication channel—vishing specifically involves voice (phone/voicemail), while pretexting can occur via any medium (email, in-person, etc.).

How to eliminate wrong answers

Option A is wrong because smishing uses SMS text messages, not voicemail or phone calls. Option C is wrong because pretexting is a broader social engineering technique that involves fabricating a scenario (pretext) to steal information, but the specific delivery method here—a voicemail requesting a callback—makes vishing the more precise term. Option D is wrong because pharming redirects users from legitimate websites to fraudulent ones by poisoning DNS caches or modifying host files, which does not involve direct voice communication.

Page 3

Page 4 of 10

Page 5

All pages

Practice 220-1202 by domain

Target a specific domain to shore up weak areas.

See all domains with question counts →