Courseiva

CompTIA A+ Core 2 220-1202 (220-1202) — Questions 376–450

687 questions total · 10pages · All types, answers revealed

Page 5

Page 6 of 10

Page 7
376
MCQeasy

A user reports that their corporate email app on an Android device is not syncing. They can browse the internet and use other apps normally. The account was working yesterday. What should you check first?

A.Perform a factory reset of the device.
B.Verify the account username and password in the email app.
C.Replace the device's SIM card.
D.Reinstall the operating system.
AnswerB

Verifying the account username and password within the corporate email application is a primary and often overlooked troubleshooting step. Even if the user believes the credentials are correct, a recent password change on the server, a typo during initial setup, or an expired session token can prevent successful authentication and data synchronization. This simple check directly addresses the most common cause of email access issues without impacting other device functions, making it the most efficient first step.

Why this answer

The most common cause of a previously working email account suddenly failing to sync is an authentication issue, such as a changed password or expired credentials. Since other internet services work, the network connectivity is fine, so the problem is isolated to the email app's authentication. Verifying the username and password in the app's account settings is the quickest, least disruptive first step before escalating to more drastic measures.

Exam trap

The trap here is that candidates may assume a network or hardware issue (SIM card) because the email 'isn't syncing,' but the question explicitly states other apps work, isolating the problem to the email app's configuration or authentication.

How to eliminate wrong answers

Option A is wrong because performing a factory reset is a destructive, last-resort step that would erase all user data and settings, and it is not justified when the issue is isolated to a single app and the device otherwise functions normally. Option C is wrong because replacing the SIM card would only affect cellular network authentication and provisioning, not the email app's credentials or connectivity over Wi-Fi or mobile data; since other apps work, the SIM is not the cause. Option D is wrong because reinstalling the operating system is an extreme measure that would wipe the entire device and is completely unnecessary for a single app's sync failure that likely stems from a simple credential mismatch.

377
MCQmedium

A user receives an email that appears to be from their bank, asking them to click a link and verify their account information due to 'suspicious activity.' The email address looks legitimate, but the link points to a different domain. What type of attack is this?

A.Spear phishing
B.Phishing
C.Whaling
D.Vishing
AnswerB

Phishing deceives the recipient into clicking a link or divulging data by impersonating a trusted entity. The spoofed bank sender combined with a link resolving to an unrelated domain is the defining mechanism, distinguishing it from other social-engineering or technical attacks.

Why this answer

This is a classic phishing attack because the email uses social engineering to trick the user into clicking a link that leads to a fraudulent domain, even though the sender's address appears legitimate. Phishing is a broad category of social engineering where attackers impersonate a trusted entity to steal credentials or sensitive information, and the mismatched link is the key indicator.

Exam trap

CompTIA A+ often tests the distinction between generic phishing and targeted variants like spear phishing or whaling, and the trap here is that candidates see a legitimate-looking sender address and assume it's spear phishing, missing the broad, unsolicited nature of the attack.

How to eliminate wrong answers

Option A is wrong because spear phishing targets a specific individual or organization with personalized details, whereas this scenario describes a generic email sent to any user. Option C is wrong because whaling targets high-profile executives or senior management, not a general user. Option D is wrong because vishing (voice phishing) uses phone calls or voicemail, not email, to deceive victims.

378
MCQmedium

A user reports that their Windows 10 PC fails to boot and displays a 'Boot Configuration Data is missing' error. You need to repair the boot configuration using the Windows Recovery Environment. Which administrative tool should you run from the command prompt in the recovery environment?

A.sfc /scannow
B.bootrec /rebuildbcd
C.DISM /Online /Cleanup-Image /RestoreHealth
D.chkdsk /f
AnswerB

The `bootrec /rebuildbcd` command is specifically engineered to scan all disks for compatible Windows installations and then create a new Boot Configuration Data (BCD) store. This process effectively reconstructs the critical boot information that Windows uses to start up, resolving common boot-related issues such as "Boot BCD missing" or "Boot BCD corrupt" errors. It is the primary tool for repairing a damaged or missing BCD, making the system bootable again by correctly identifying the OS location.

Why this answer

The 'Boot Configuration Data is missing' error indicates that the BCD store, which contains boot-time configuration parameters, is corrupted or missing. The `bootrec /rebuildbcd` command scans all disks for Windows installations and allows you to rebuild the BCD store from scratch, directly addressing the missing or corrupt boot configuration data.

Exam trap

The 220-1202 exam often tests the distinction between file-level repair tools (sfc, DISM) and boot-level repair tools (bootrec), so the trap here is that candidates confuse 'system file corruption' with 'boot configuration corruption' and choose sfc or DISM instead of the correct bootrec command.

How to eliminate wrong answers

Option A is wrong because `sfc /scannow` (System File Checker) scans and repairs protected system files, but it does not rebuild the Boot Configuration Data store, which is a separate boot-critical component. Option C is wrong because `DISM /Online /Cleanup-Image /RestoreHealth` repairs the Windows system image and component store corruption, but it requires the OS to be online and cannot be used from the Windows Recovery Environment command prompt to fix a missing BCD. Option D is wrong because `chkdsk /f` checks the file system for logical and physical errors on the disk, but it does not create or repair the boot configuration data store.

379
MCQhard

After resolving a user's issue, the user says, "Thank you, you're a lifesaver!" and offers the technician a $50 gift card as a token of appreciation. Company policy strictly prohibits accepting gifts over $20. How should the technician respond?

A."I appreciate that, but our policy doesn't allow me to accept gifts over $20. Thank you for the thought, though."
B."Thank you! That's very kind. I'll accept it, but please don't tell anyone."
C."I can't accept this. Please don't offer gifts to IT staff."
D."You can give it to my manager if you want, but I can't take it directly."
AnswerA

This response demonstrates exemplary professional conduct by politely declining the gift while clearly referencing company policy. It maintains a positive customer relationship by expressing appreciation for the gesture ("I appreciate that... Thank you for the thought") and educates the user on the established ethical guidelines regarding gratuities. Adhering to the $20 limit specified by policy ensures integrity and prevents potential conflicts of interest or perceptions of favoritism.

Why this answer

It politely declines the gift while citing the specific company policy limit of $20, which aligns with professional conduct and ethical guidelines. This response maintains trust and integrity without offending the user, as required by the CompTIA A+ 220-1202 exam objectives on professionalism and communication.

Exam trap

CompTIA often tests the candidate's ability to balance professionalism with customer appreciation, trapping those who choose a response that either violates policy (B, D) or damages the relationship (C) instead of a polite, policy-compliant refusal (A).

How to eliminate wrong answers

Option B is wrong because accepting the gift and asking the user to keep it secret violates company policy and ethical standards, potentially leading to disciplinary action or loss of trust. Option C is wrong because it is overly abrupt and dismissive, failing to acknowledge the user's gratitude and potentially damaging the customer relationship; a polite refusal is more appropriate. Option D is wrong because redirecting the gift to a manager still involves accepting a prohibited item indirectly, which does not comply with the policy and could be seen as an attempt to circumvent the rules.

380
MCQmedium

A security incident occurred where an attacker modified a PowerShell script on a file server to include malicious commands. The script is executed daily by a scheduled task. Which scripting security best practice could have prevented this attack?

A.Store the script in a hidden folder
B.Set the script file to read-only
C.Use a digital signature to sign the script and enforce execution policy
D.Compile the script into an executable
AnswerC

Signing the script with a code-signing certificate and enforcing an AllSigned execution policy makes PowerShell reject any tampered or unsigned script before it runs. An attacker modifying the scheduled script invalidates the signature, so the daily task fails safely instead of executing malicious commands.

Why this answer

Enforcing an execution policy that requires scripts to be digitally signed ensures that only scripts signed by a trusted publisher can run. If the attacker modified the script, the digital signature would become invalid, and the execution policy would block the script from running, preventing the malicious commands from executing.

Exam trap

The trap here is that candidates often choose 'Set the script file to read-only' because they think file permissions alone are sufficient, but CompTIA tests that integrity verification (via digital signatures) is the only way to detect unauthorized modifications in a script that is executed automatically.

How to eliminate wrong answers

Option A is wrong because storing the script in a hidden folder does not prevent modification; hidden folders are easily revealed via File Explorer settings or command-line tools like `dir /a`. Option B is wrong because setting the script file to read-only can be bypassed by an attacker with sufficient privileges (e.g., taking ownership or modifying permissions), and it does not verify the script's integrity. Option D is wrong because compiling a PowerShell script into an executable does not prevent modification; the executable can still be decompiled or replaced, and it does not enforce integrity checks like a digital signature.

381
MCQhard

A technician receives an email from what appears to be the company's CEO, asking for a list of all employee passwords for a 'security audit'. The email address is correct, but the tone and request are unusual. The technician suspects a social engineering attack. What is the best course of action?

A.Reply to the email asking for more details to confirm the request.
B.Forward the email to the security team and do not respond.
C.Provide the list as requested, since the CEO has authority.
D.Call the CEO immediately to verify the request.
AnswerB

This is the correct response because forwarding the suspicious message to the security team preserves the original headers and metadata, enabling forensic analysis of sender authentication (SPF, DKIM, DMARC) and malicious indicators like phishing links or attached payloads. It also establishes a written record for incident response timelines and ensures no action is taken that could enable credential theft or data exposure. Do not click any links, open attachments, or reply before security triage.

Why this answer

Forwarding the email to the security team ensures that the incident is handled by the appropriate personnel who can investigate the potential phishing or social engineering attack without engaging the attacker. Responding to the email, even for confirmation, could validate the technician's email address as active and potentially expose the organization to further attacks. The security team can analyze headers, links, and attachments using tools like email security gateways or SIEM systems to determine the legitimacy of the request.

Exam trap

CompTIA often tests the misconception that verifying with the CEO by phone is the best immediate action, but the correct priority is to report to the security team first to ensure proper incident response and evidence preservation.

How to eliminate wrong answers

Option A is wrong because replying to the email, even for clarification, confirms to the attacker that the email address is monitored and may trigger follow-up social engineering attempts; it also risks accidental disclosure of sensitive information. Option C is wrong because providing passwords violates security policy and best practices; no legitimate security audit would request plaintext passwords, as they should be hashed and never transmitted. Option D is wrong because while calling the CEO is a good verification step, it delays immediate reporting to the security team, who should be notified first to preserve evidence and coordinate a response; the technician should not act on the request until the security team confirms it is legitimate.

382
MCQhard

A network administrator is investigating a security incident where an attacker captured the 4-way handshake of a WPA2-PSK network and successfully cracked the passphrase. Which protocol change would most effectively prevent this type of attack in the future?

A.Switch to WPA2-Enterprise with 802.1X and a RADIUS server.
B.Increase the WPA2-PSK passphrase length to 63 characters.
C.Upgrade to WPA3-SAE.
D.Enable MAC address filtering on the access point.
AnswerC

Upgrading to WPA3-SAE (Simultaneous Authentication of Equals) directly addresses and eliminates the possibility of offline dictionary attacks against the Wi-Fi passphrase. WPA3-SAE utilizes a robust key exchange protocol, often referred to as 'Dragonfly,' which ensures that each authentication attempt is unique and interactive. This design prevents an attacker from capturing a handshake and performing precomputed, offline brute-force or dictionary attacks, even if the password is weak, by making each guess an interactive process that cannot be precomputed.

Why this answer

WPA3-SAE (Simultaneous Authentication of Equals) replaces the WPA2-PSK 4-way handshake with a protocol that uses a Diffie-Hellman key exchange, making it resistant to offline dictionary attacks. Even if an attacker captures the SAE handshake, they cannot crack the passphrase offline because the key exchange provides forward secrecy and prevents brute-force attempts without interacting with the network.

Exam trap

The 220-1202 exam often tests the misconception that simply strengthening WPA2-PSK (e.g., longer passphrase) or adding MAC filtering is sufficient, when the core vulnerability is the offline-crackable 4-way handshake itself, which only WPA3-SAE fundamentally addresses.

How to eliminate wrong answers

Option A is wrong because switching to WPA2-Enterprise with 802.1X and a RADIUS server still uses the same 4-way handshake for key derivation; the handshake can still be captured and, if the RADIUS server uses a weak password or certificate, offline attacks remain possible. Option B is wrong because increasing the WPA2-PSK passphrase length to 63 characters only makes cracking harder but does not change the fundamental vulnerability: the 4-way handshake can still be captured and subjected to offline dictionary or brute-force attacks given enough time and resources. Option D is wrong because MAC address filtering is a trivial security measure that can be easily bypassed by spoofing an allowed MAC address; it does not prevent handshake capture or cracking of the passphrase.

383
MCQmedium

A technician is configuring a new Windows 10 workstation for a user who requires access to files stored on an encrypted USB drive. The drive uses BitLocker To Go. What must the technician do to ensure the user can access the drive on this computer?

A.Enable BitLocker on the workstation's internal drive
B.Provide the user with the drive's password or recovery key
C.Format the USB drive to NTFS
D.Install the BitLocker Drive Encryption feature from Control Panel
AnswerB

To access data on a BitLocker-protected external drive, the user *must* provide the correct password or the 48-digit recovery key associated with that specific encrypted volume. BitLocker To Go, designed for removable drives, requires this authentication step to decrypt the data and mount the drive for use, ensuring data confidentiality even if the physical drive is lost or stolen. Without these credentials, the drive remains inaccessible, regardless of the workstation's configuration.

Why this answer

BitLocker To Go encrypts removable drives with a password or recovery key. To access the drive on a new Windows 10 workstation, the technician must provide the user with the drive's password or recovery key, as the drive is already encrypted and requires authentication at mount time. No additional configuration is needed on the workstation beyond entering the correct credentials.

Exam trap

The trap here is that candidates may think additional software or feature installation is required, but BitLocker To Go is a built-in capability of Windows 10 Pro/Enterprise that only needs the correct authentication credential to unlock the drive.

How to eliminate wrong answers

Option A is wrong because enabling BitLocker on the workstation's internal drive is unrelated to accessing an already-encrypted BitLocker To Go USB drive; the internal drive encryption does not affect removable drive access. Option C is wrong because formatting the USB drive to NTFS would erase all data and remove the existing BitLocker encryption, which is counterproductive since the user needs to access existing encrypted files. Option D is wrong because the BitLocker Drive Encryption feature is already included in Windows 10 Pro and Enterprise editions; it does not need to be installed separately, and the technician only needs to provide the password or recovery key.

384
MCQhard

A system administrator needs to change the group ownership of a directory /srv/data and all its contents to 'datagroup'. Which command will accomplish this recursively?

A.chgrp -R datagroup /srv/data
B.chown datagroup: /srv/data
C.chmod -R g+rw /srv/data
D.groupmod -R datagroup /srv/data
AnswerA

The -R flag applies the ownership change recursively, so chgrp descends through /srv/data and alters the group of every file and subdirectory to datagroup. Without -R, only the directory itself would change, leaving its contents untouched and failing the recursive requirement.

Why this answer

The correct command is `chgrp -R datagroup /srv/data`. The `-R` (or `--recursive`) flag tells `chgrp` to operate on the directory and all its contents, changing the group ownership to 'datagroup'. This directly fulfills the requirement to change group ownership recursively.

Exam trap

The trap here is that candidates often confuse `chgrp` with `chown` or `chmod`, mistakenly thinking that `chown datagroup:` or `chmod -R g+rw` will change group ownership, when in fact they change user ownership or permissions, respectively.

How to eliminate wrong answers

Option B is wrong because `chown datagroup: /srv/data` changes the user owner to 'datagroup' (with an empty group field), not the group ownership, and it does not operate recursively. Option C is wrong because `chmod -R g+rw /srv/data` modifies file permissions (adding read and write for the group), not group ownership. Option D is wrong because `groupmod` is used to modify the properties of a group (e.g., its name or GID) in the system's group database, not to change ownership of files or directories, and it does not accept a `-R` flag for recursion.

385
MCQmedium

A technician is tasked with securing a shared office printer that stores sensitive documents on its hard drive. The printer is in an open area. Which physical security measure should be prioritized to protect the data on the printer?

A.Enable secure print release with a PIN
B.Encrypt the printer's hard drive
C.Place the printer in a locked room
D.Use a cable lock on the printer
AnswerC

Relocating the printer into a locked room restricts physical access to its hard drive, preventing unauthorised removal or theft of stored sensitive documents. This directly addresses the open-area exposure, unlike encryption or firmware settings, which are logical rather than physical controls.

Why this answer

The most effective physical security measure to protect sensitive data on a printer's hard drive in an open area is to control physical access to the device itself. Placing the printer in a locked room prevents unauthorized individuals from physically removing the hard drive or accessing the printer's internal components, which is the primary threat in an open area. While encryption and secure release are important, they do not mitigate the risk of physical theft or tampering with the storage medium.

Exam trap

CompTIA often tests the principle that physical security controls must address the most direct threat vector; the trap here is that candidates confuse data-at-rest protections (encryption) with physical access controls, failing to recognize that encryption does not prevent physical theft or tampering with the storage medium.

How to eliminate wrong answers

Option A is wrong because enabling secure print release with a PIN only controls the release of print jobs, not the data already stored on the printer's hard drive; an attacker could still physically steal the drive and extract data offline. Option B is wrong because encrypting the printer's hard drive protects data at rest but does not prevent physical theft of the drive or the printer itself; encryption is a complementary control, not a substitute for physical access control. Option D is wrong because using a cable lock on the printer only prevents the printer from being easily carried away, but it does not prevent an attacker from opening the printer's casing and removing the hard drive or accessing the data directly.

386
MCQmedium

A user calls the help desk because their MacBook Pro running macOS Sonoma suddenly shows a folder with a flashing question mark when booting. They were not performing any system updates. Which macOS tool or feature should you use to attempt to repair the startup volume?

A.Boot to Recovery mode and run Disk Utility First Aid
B.Use the Terminal command 'sudo fsck -fy' at boot
C.Reinstall macOS from Internet Recovery
D.Enable Target Disk Mode on the Mac
AnswerA

A flashing question mark means the Mac cannot locate a bootable startup volume. Booting to Recovery mode and running Disk Utility First Aid verifies and repairs the volume's directory structure, directly addressing the startup volume fault without erasing data.

Why this answer

A flashing question mark folder at boot on a Mac indicates that the startup volume is not found or is corrupt. Booting to Recovery mode (by holding Command-R at startup) and running Disk Utility First Aid allows you to verify and repair the volume's directory structure and file system, which is the appropriate first step to resolve this issue without reinstalling macOS.

Exam trap

CompTIA often tests the misconception that 'fsck' is the modern repair tool for macOS, but candidates must know that Disk Utility First Aid is the correct GUI tool for APFS volumes, and the deprecated 'fsck -fy' command is no longer the standard approach.

How to eliminate wrong answers

Option B is wrong because 'sudo fsck -fy' is a legacy Unix command for checking file systems, but on modern macOS with APFS, Disk Utility First Aid is the recommended tool; additionally, you cannot run 'sudo' in single-user mode without proper syntax, and the correct command would be '/sbin/fsck -fy' in single-user mode, which is deprecated. Option C is wrong because reinstalling macOS from Internet Recovery is a more drastic step that should only be attempted after Disk Utility First Aid fails to repair the volume, as it erases the current system and user data. Option D is wrong because Target Disk Mode makes the Mac act as an external drive for another computer, which does not repair the startup volume; it only provides access to the drive for data transfer or diagnostics from another Mac.

387
MCQmedium

A security incident response team needs to identify all files on a system that have the SUID bit set, as these may pose a security risk. Which command should they use?

A.find / -type f -perm 0777
B.find / -type f -perm 4000
C.find / -type f -perm -4000
D.find / -type f -perm /4000
AnswerC, D

The -perm -4000 test matches files whose permission bits include the SUID bit, and -type f restricts results to regular files. Searching from / scans the whole filesystem, letting the team enumerate every SUID binary that could grant elevated privileges during incident triage.

Why this answer

The `-perm -4000` syntax in the `find` command matches files that have the SUID bit set (the 4000 octal permission), regardless of other permission bits. The leading dash (`-`) means 'at least these bits must be set,' so it correctly identifies all files where the SUID bit is enabled. Note that GNU find's `-perm /4000` also matches files with the SUID bit set, since the slash means 'any of these bits must be set' and only one bit is specified; however, `-perm -4000` is the traditional and most widely recognized form for this task.

Exam trap

This question tests the distinction between exact permission matching (`-perm 4000`) and 'at least these bits' matching (`-perm -4000`). Candidates may incorrectly choose exact matching, which only finds files whose permissions are exactly 4000 and misses files with additional bits set. Be aware that on GNU find, `-perm /4000` is functionally equivalent to `-perm -4000` for a single bit, so both can identify SUID files.

How to eliminate wrong answers

Option A is wrong because `-perm 0777` matches files with exact permissions of 0777 (all read, write, execute for owner, group, and others), not files with the SUID bit set. Option B is wrong because `-perm 4000` matches files with exactly the permission 4000 (only the SUID bit, no other permissions), which is unrealistic and would miss files that have the SUID bit combined with other permissions like 4755. Option D is wrong because `-perm /4000` uses the `/` prefix, which in GNU find matches files where any of the specified bits are set (logical OR), but this is not the standard POSIX syntax and may not be available on all systems; the correct POSIX-compliant syntax for matching the SUID bit is `-perm -4000`.

388
MCQmedium

A security incident is reported where a user accidentally deleted a critical script in /usr/local/bin. The script was owned by root and had permissions 755. Which command will restore the script from a backup located in /backup?

A.mv /backup/script.sh /usr/local/bin/
B.cp /backup/script.sh /usr/local/bin/
C.cp -p /backup/script.sh /usr/local/bin/
D.rsync -a /backup/script.sh /usr/local/bin/
AnswerD

rsync -a preserves attributes but is overkill for a single file; it would work but is not the simplest command.

Why this answer

The `rsync -a` command uses archive mode, which preserves ownership, permissions, timestamps, and other attributes when restoring the script from /backup to /usr/local/bin. Since the script was owned by root and had permissions 755, `-a` ensures these attributes are retained, which is critical for a system script in /usr/local/bin. A plain `cp` (Option B) would not preserve ownership or permissions, and `cp -p` (Option C) only preserves attributes when the user has sufficient privilege to set them; it is not the standard tool for restoring a root-owned file. `mv` (Option A) simply moves the backup file and does not restore it while preserving the original attributes.

Exam trap

The trap here is that candidates often choose `cp` without `-p` (Option B) because they assume a simple copy is sufficient, overlooking that file ownership and permissions are not preserved by default. A second trap is choosing `cp -p` (Option C) assuming it always preserves root ownership, when in fact a non-root user cannot set ownership to root; `rsync -a` is the reliable restoration command.

How to eliminate wrong answers

Option A is wrong because `mv` moves the file from /backup to /usr/local/bin, which removes the backup copy entirely, leaving no fallback if the restore fails or is incorrect. Option B is wrong because `cp` without the `-p` flag does not preserve the original file's ownership (root) and permissions (755); the restored script would be owned by the user running the command and have permissions based on the current umask, potentially breaking system functionality. Option D is wrong because `rsync -a` (archive mode) preserves permissions, ownership, and timestamps, but it is designed for synchronizing directories and may introduce unnecessary overhead or unintended behavior (e.g., deleting files in the destination if used with `--delete`), and it is not the standard simple restore command for a single file in this context.

389
MCQhard

A Windows 11 workstation is infected with ransomware that encrypted user files. The IT security team wants to prevent future infections by restricting which processes can modify files in user profile folders. Which Windows security feature can enforce such restrictions without third-party software?

A.NTFS permissions set to 'Read-only' for all users.
B.AppLocker with a deny rule for unknown executables.
C.Controlled Folder Access
D.BitLocker with TPM protection
AnswerC

Controlled Folder Access uses Windows Defender Exploit Guard to maintain an allowlist of trusted applications permitted to write to protected user profile folders. Any unauthorised process attempting modification is blocked, directly satisfying the stem's requirement to restrict file-modifying processes without installing third-party software.

Why this answer

Controlled Folder Access (CFA) is a Windows Defender Exploit Guard feature that restricts which applications can modify files in protected folders, such as user profile directories. By default, CFA blocks untrusted or unknown processes from writing to or encrypting files in these folders, directly preventing ransomware from encrypting user data without requiring third-party software.

Exam trap

The trap here is that candidates confuse AppLocker's application control with file-level write restrictions, assuming that blocking unknown executables from running is equivalent to preventing file modification, but AppLocker does not control file system operations after execution.

How to eliminate wrong answers

Option A is wrong because setting NTFS permissions to 'Read-only' for all users would prevent legitimate user applications (like Microsoft Word or Notepad) from saving files, breaking normal workflow, and it does not selectively block only malicious processes. Option B is wrong because AppLocker controls which executables can run, not which processes can modify files; it can block unknown executables from launching, but it does not restrict file write operations by already-running trusted processes. Option D is wrong because BitLocker with TPM protection provides full-disk encryption to protect data at rest from offline attacks, but it does not enforce runtime restrictions on which processes can modify files after the system is booted.

390
MCQmedium

A security incident occurs when an unauthorized user gains access to a server because a technician left a default password unchanged after a system rebuild. The rebuild was documented, but the password change was not. What documentation failure does this highlight?

A.The change log did not include a rollback plan.
B.The change log did not list the specific configuration changes made.
C.The change request was not approved by the change advisory board.
D.The technician did not perform a post-implementation review.
AnswerB

A comprehensive change log is absolutely fundamental for maintaining system security, integrity, and accountability within an IT environment. Omitting specific configuration details, such as a password update, creates a critical security vulnerability by leaving an undocumented credential or 'backdoor.' This lack of transparency directly enables unauthorized access because the change cannot be tracked, audited, or properly managed by authorized personnel.

Why this answer

The documentation failure is that the change log did not list the specific configuration changes made. In this scenario, the system rebuild was documented, but the critical detail of changing the default password was omitted. Proper change management requires that every configuration change, including password updates, be explicitly recorded in the change log to ensure accountability and traceability.

Without this record, the security incident occurred due to an undocumented deviation from security best practices.

Exam trap

CompTIA often tests the distinction between a change log's requirement to list specific changes versus broader change management processes like approval or review, leading candidates to confuse a documentation failure with a procedural one.

How to eliminate wrong answers

Option A is wrong because a rollback plan is not the primary issue here; the failure is the omission of the password change from the documentation, not the absence of a procedure to revert changes. Option C is wrong because the question does not indicate that the change request lacked approval from the change advisory board (CAB); the issue is the incomplete documentation of the change itself. Option D is wrong because a post-implementation review (PIR) would occur after the change is completed, but the core failure is that the password change was never recorded in the change log, which is a documentation failure that precedes any review.

391
MCQhard

A user reports that their Windows 10 PC is infected with malware that keeps reinstalling after removal. You need to boot into a minimal environment to run antivirus scans without malware interference. Which advanced startup option should you use?

A.Enable Boot Logging
B.Safe Mode
C.Last Known Good Configuration
D.Debugging Mode
AnswerB

Safe Mode loads only core drivers and services, preventing malware configured as a startup service or driver from launching. This gives a minimal environment where antivirus scans can run without the infection reinstalling itself during normal boot.

Why this answer

Safe Mode (B) loads Windows with a minimal set of drivers and services, preventing malware that runs as a startup program or service from loading. This allows antivirus software to scan and remove the infection without interference, addressing the scenario where malware reinstalls after removal in a normal boot.

Exam trap

CompTIA A+ candidates often mistakenly think that Last Known Good Configuration (C) can remove malware, but it only reverts driver/registry changes and does not clean infections that persist across boots. Safe Mode is the correct choice for malware removal.

How to eliminate wrong answers

Option A is wrong because Enable Boot Logging creates a log of drivers loaded during boot (ntbtlog.txt) but does not restrict malware from loading, so it does not provide a minimal environment for antivirus scans. Option C is wrong because Last Known Good Configuration reverts to the last successful registry and driver configuration after a failed boot, but it does not prevent malware from loading if the malware was present in that configuration; it is designed for driver or configuration issues, not persistent malware. Option D is wrong because Debugging Mode enables kernel debugging over serial or IEEE 1394 for advanced troubleshooting, but it loads all normal drivers and services, allowing malware to run and interfere with scans.

392
MCQmedium

A technician is upgrading a Windows 11 Pro workstation from a SATA SSD to a larger NVMe drive. The user needs to retain installed applications, user profiles, and the existing domain join. Which tool should the technician use to move the installation to the new drive without reinstalling Windows?

A.Disk Management's Extend Volume on the new disk after cloning
B.Windows System Image Backup (wbadmin) restore to the new disk
C.Third-party drive cloning software, such as Macrium Reflect or Clonezilla
D.Windows Recovery Environment's Reset this PC with Keep my files
AnswerC

Cloning software copies the entire partition structure and boot files from the SATA SSD to the NVMe drive, preserving Windows, installed applications, user profiles, and the domain join. After cloning, the technician can extend the system partition into remaining space. This is the standard method for a like-for-like drive upgrade when reinstalling is not acceptable.

Why this answer

Cloning is the correct migration path because it duplicates the source disk's partitions and boot configuration onto the new NVMe drive, so the installed applications, profiles, and domain membership continue to work. Image-based restore and reset operations either rebuild the layout or strip applications, and Extend Volume cannot populate a blank disk.

Exam trap

The trap here is assuming that any backup or image tool performs a same-hardware drive upgrade, when cloning is the only method that preserves the installation and boot files on a new disk.

393
MCQhard

A company’s change management policy states that all changes must be reviewed by the CAB. An urgent security vulnerability is discovered that requires an immediate patch to a critical database server. The CAB is not available for 24 hours. What is the best course of action?

A.Wait for the CAB to meet and approve the change
B.Apply the patch immediately and document it as an emergency change
C.Apply the patch but do not document it to avoid policy violation
D.Disconnect the server from the network until the CAB meets
AnswerB

Applying the patch immediately and documenting it as an emergency change is the correct procedure for critical vulnerabilities. Emergency change processes are specifically designed for situations requiring immediate action to prevent or mitigate severe business impact or security threats. This approach allows for rapid deployment of the fix, followed by retrospective documentation and approval, ensuring both prompt risk mitigation and adherence to change management governance.

Why this answer

The change management policy includes an emergency change process for urgent security vulnerabilities. Applying the patch immediately and documenting it as an emergency change aligns with ITIL best practices and the company's policy, ensuring the vulnerability is mitigated without delay while maintaining compliance through post-implementation review.

Exam trap

CompTIA often tests the misconception that all changes must wait for CAB approval, ignoring the emergency change process explicitly defined in ITIL and many corporate policies.

How to eliminate wrong answers

Option A is wrong because waiting 24 hours for the CAB leaves the critical database server exposed to the security vulnerability, which could lead to data breach or system compromise. Option C is wrong because applying the patch without documentation violates the change management policy and creates an audit trail gap, potentially leading to compliance issues and inability to track changes. Option D is wrong because disconnecting the server from the network disrupts business operations and does not resolve the vulnerability; the patch must still be applied, and the server remains vulnerable when reconnected.

394
MCQhard

During a remote troubleshooting session, a technician uses a tool that allows them to view the user's screen and control the mouse and keyboard. The user reports that the session is extremely laggy, with noticeable delay between the technician's actions and the screen update. Which of the following is the most likely cause of this lag?

A.The remote desktop software is using an outdated encryption protocol.
B.The user's computer has insufficient RAM to handle remote desktop sessions.
C.The network connection between the technician and the user has high latency or low bandwidth.
D.The technician's computer is running a different operating system than the user's.
AnswerC

Remote desktop protocols rely on constant, low-latency communication to provide a responsive user experience. High latency, measured by round-trip time (RTT), directly translates to a noticeable delay between the technician's input (mouse clicks, keystrokes) and the corresponding visual update on their screen. Conversely, low bandwidth restricts the amount of screen data that can be transmitted per second, resulting in a choppy, pixelated, or slow-to-refresh display, both of which are perceived as significant lag.

Why this answer

The lag described is a classic symptom of network latency or insufficient bandwidth, which directly impacts the responsiveness of remote desktop protocols like RDP or VNC. These protocols transmit screen updates and input events in real time; high latency delays the round-trip of packets, while low bandwidth can cause frame drops or compression artifacts, resulting in the noticeable delay between the technician's actions and the screen update.

Exam trap

CompTIA often tests the concept that remote desktop lag is primarily a network issue (latency/bandwidth), not a hardware or OS compatibility problem, and the trap here is that candidates may incorrectly attribute the lag to the user's local hardware (RAM) or encryption overhead instead of recognizing the network as the most likely culprit.

How to eliminate wrong answers

Option A is wrong because outdated encryption protocols (e.g., SSL 3.0 vs. TLS 1.2) affect security, not responsiveness; they may add negligible overhead but are not the primary cause of severe lag. Option B is wrong because insufficient RAM on the user's computer would typically cause local application crashes, swapping, or slow local performance, not a specific delay between remote input and screen updates; remote desktop protocols are more sensitive to CPU and network than to RAM.

Option D is wrong because different operating systems between technician and user are handled transparently by cross-platform remote desktop tools (e.g., RDP client on Windows connecting to Linux via xrdp); the OS mismatch does not inherently introduce lag.

395
MCQmedium

A user reports that their iPhone's battery drains quickly and the phone feels warm. After checking, you find that several apps are using Location Services in the background. What is the most efficient way to manage this without disabling location for all apps?

A.Turn off Location Services entirely in Privacy settings
B.Set each app's location permission to 'While Using the App'
C.Enable Low Power Mode
D.Reset all settings on the iPhone
AnswerB

Changing each app's permission to 'While Using the App' stops background location access while preserving location when the app is open, reducing battery drain and heat. It manages the offending apps individually rather than disabling location globally.

Why this answer

Setting each app's location permission to 'While Using the App' is the most efficient solution because it prevents apps from accessing location services in the background, which is the primary cause of battery drain and heat generation. This granular control allows critical apps (e.g., Maps) to still function when actively used, while stopping unnecessary background location polling that consumes GPS and cellular resources.

Exam trap

CompTIA often tests the distinction between system-wide toggles and per-app granular controls, trapping candidates who choose a global solution (like disabling Location Services entirely) instead of the targeted, efficient fix that addresses the specific symptom of background location usage.

How to eliminate wrong answers

Option A is wrong because turning off Location Services entirely disables location for all apps, including those that need it for core functionality (e.g., navigation, weather), which is an overreaction and not efficient. Option C is wrong because Low Power Mode reduces overall performance and background activity but does not specifically address the root cause of background location services; it may temporarily mask the issue without stopping the location polling that drains the battery. Option D is wrong because resetting all settings is a drastic, time-consuming step that erases personalized configurations (e.g., Wi-Fi passwords, wallpapers) and does not directly target the location permissions causing the drain.

396
MCQmedium

A technician needs to create a virtual machine that will host a legacy application requiring Windows XP. The host runs Windows 11. After creating the VM and installing Windows XP, the technician notices that the mouse cursor is lagging and the screen resolution is stuck at 800x600. What should the technician do to resolve this?

A.Increase the amount of RAM allocated to the VM.
B.Install the guest additions for the VM.
C.Update the host operating system to the latest version.
D.Change the VM's network adapter from NAT to bridged.
AnswerB

Installing guest additions supplies the virtualised display and mouse drivers Windows XP lacks, enabling higher resolutions and removing cursor lag. Without them the VM falls back to generic drivers, which explains the 800x600 limit and sluggish pointer.

Why this answer

The mouse lag and limited screen resolution (800x600) indicate that the VM lacks proper integration with the host, which is resolved by installing guest additions. Guest additions provide optimized drivers for video, mouse, and other hardware, enabling smooth cursor movement and higher resolutions. This is a standard step after installing any guest OS in a hypervisor like Hyper-V or VirtualBox.

Exam trap

The trap here is that candidates often confuse performance issues with resource allocation (RAM) or network settings, overlooking the fundamental requirement for guest additions (or integration services) to enable proper hardware support in the guest OS.

How to eliminate wrong answers

Option A is wrong because increasing RAM addresses performance issues related to memory pressure, not video driver or integration problems; the symptoms described are driver-specific, not memory-related. Option C is wrong because updating the host OS does not affect the guest's video drivers or integration services; the host OS version is irrelevant to the guest's display capabilities. Option D is wrong because changing the network adapter type affects network connectivity, not video output or mouse input; NAT vs. bridged has no impact on screen resolution or cursor lag.

397
MCQeasy

A customer says that when they click a link in an email, it opens a website that looks exactly like their bank's login page, but the URL starts with 'http://' instead of 'https://'. What is the most likely security concern?

A.The website is using an expired SSL certificate.
B.The user's browser is infected with adware.
C.The email contains a phishing link.
D.The user's DNS server has been compromised.
AnswerC

Phishing attacks are a form of social engineering where attackers send fraudulent communications, often emails, to trick individuals into revealing sensitive information. The combination of a deceptive email link leading to a website that visually mimics a legitimate service but uses an insecure HTTP connection is a hallmark of a phishing attempt. This method aims to steal credentials by presenting a convincing, yet fake, login portal.

Why this answer

A website that mimics a bank's login page but uses 'http://' instead of 'https://' is a classic phishing indicator, as legitimate banks always use HTTPS with a valid certificate. The lack of TLS means credentials submitted would be sent in cleartext to attackers. This is the most likely security concern in the scenario.

Exam trap

220-1202 often tests phishing indicators, so the trap is overthinking the scenario and choosing DNS compromise or SSL issues instead of recognizing the simple HTTP + fake login page combination as phishing.

How to eliminate wrong answers

Option A is wrong because an expired SSL certificate would still show 'https://' with a browser warning, not 'http://'. Option B is wrong because adware typically injects ads or redirects, not create convincing bank login replicas. Option D is wrong because a compromised DNS server could redirect to a fake site, but the 'http://' indicator more directly points to phishing rather than DNS compromise.

398
MCQhard

An organization uses Windows 10 and wants to prevent users from installing unauthorized software. They have configured Software Restriction Policies via Group Policy. However, a user bypassed the policy by renaming the executable. What additional measure should be taken to enforce the restriction?

A.Enable Windows Defender Real-time Protection
B.Use AppLocker with publisher rules
C.Set User Account Control to Always Notify
D.Enable BitLocker
AnswerB

AppLocker with publisher rules provides robust application control by allowing only digitally signed software from trusted publishers to execute. These rules validate an application's digital signature and certificate chain, ensuring its authenticity and integrity, making it highly resistant to circumvention by simply renaming or relocating executable files. This method effectively prevents the execution of unauthorized software that lacks a valid, approved digital signature, regardless of its file name or path.

Why this answer

AppLocker with publisher rules is the correct additional measure because Software Restriction Policies (SRP) can be bypassed by renaming executables, as SRP relies on file path or hash rules. AppLocker's publisher rules use digital signatures to identify software, making it immune to filename changes. This provides a more robust enforcement mechanism for preventing unauthorized software installation.

Exam trap

CompTIA often tests the distinction between Software Restriction Policies and AppLocker, where candidates mistakenly think SRP's hash rules are sufficient, but the trap is that renaming bypasses path rules, and hash rules require updates after each software update, whereas AppLocker publisher rules are more resilient.

How to eliminate wrong answers

Option A is wrong because Windows Defender Real-time Protection is an antimalware feature that detects and blocks malicious software, but it does not prevent users from installing or running unauthorized software based on policy rules. Option C is wrong because User Account Control (UAC) set to Always Notify prompts for administrative consent but does not block execution of unauthorized software if the user has administrative rights or bypasses the prompt. Option D is wrong because BitLocker is a full-disk encryption technology that protects data at rest, not a software restriction or execution control mechanism.

399
MCQeasy

A small business owner wants to ensure that only authorized USB storage devices can be used on company laptops running Windows 10 Pro. They have a list of approved device hardware IDs. Which security policy should be configured to enforce this restriction?

A.Enable the 'Removable Storage Access' policy under Windows Components
B.Configure the 'Devices: Restrict CD-ROM access to locally logged-on user only' policy
C.Set the 'Deny all devices' policy under Device Installation Restrictions
D.Configure the 'Allow installation of devices that match any of these device IDs' policy under Device Installation Restrictions
AnswerD

Device Installation Restrictions with the allow-list policy permits only hardware IDs on the approved list to install, blocking all other USB storage. This enforces the owner's allow-list requirement directly, since the policy evaluates device IDs at installation rather than blocking the USB class wholesale.

Why this answer

The 'Allow installation of devices that match any of these device IDs' policy under Device Installation Restrictions allows an administrator to specify a whitelist of approved hardware IDs. When configured, only USB storage devices whose hardware IDs match the list will be installed, effectively blocking all unauthorized devices. This directly enforces the requirement to restrict USB storage to approved devices only.

Exam trap

CompTIA often tests the distinction between access control policies (like Removable Storage Access) and device installation restriction policies, leading candidates to confuse permission-based controls with hardware-based whitelisting.

How to eliminate wrong answers

Option A is wrong because the 'Removable Storage Access' policy under Windows Components controls read/write permissions for removable media (e.g., deny write access) but does not filter by hardware ID or prevent installation of unauthorized devices. Option B is wrong because the 'Devices: Restrict CD-ROM access to locally logged-on user only' policy is a legacy setting that limits CD-ROM access to the interactive user, not USB storage devices, and does not enforce a hardware ID whitelist. Option C is wrong because the 'Deny all devices' policy under Device Installation Restrictions would block all device installations, including approved USB storage devices, which contradicts the requirement to allow authorized devices.

400
MCQeasy

A small business owner wants to ensure that only authorized users can access their iMac. They need to set up separate accounts for three employees, each with a username and password, and restrict one employee from installing software. Which macOS feature should they use to create and manage these user accounts?

A.System Settings > Users & Groups.
B.Terminal with the 'dscl' command.
C.System Information > Software > Installations.
D.Keychain Access to create user passwords.
AnswerA

This is the primary graphical interface in macOS for managing local user accounts and their associated privileges. To restrict an employee from installing software, an administrator would create or modify their account to be a "Standard" user, which inherently prevents system-wide software installations without administrator authentication. Additionally, more granular restrictions on app installation can be configured via Screen Time settings, often accessible or managed in conjunction with user accounts, providing robust control over user capabilities.

Why this answer

The 'Users & Groups' pane in System Settings (macOS Ventura and later) is the native graphical interface for creating, editing, and managing local user accounts, including setting passwords and controlling administrative privileges. It allows the owner to create separate accounts for each employee and restrict one from installing software by setting that account as a 'Standard' user rather than an 'Administrator'.

Exam trap

The trap here is that candidates may confuse the 'Users & Groups' GUI with the command-line 'dscl' tool, thinking both are equally appropriate for a non-technical business owner, but the exam expects you to recognize that the GUI is the correct and intended method for typical user management scenarios.

How to eliminate wrong answers

Option B is wrong because while the 'dscl' command in Terminal can create and manage user accounts, it is a command-line tool intended for advanced administration and scripting, not the recommended or primary method for a small business owner who needs a straightforward GUI. Option C is wrong because 'System Information > Software > Installations' only displays a list of installed software and their installation dates; it cannot create or manage user accounts. Option D is wrong because Keychain Access is used to store and manage passwords, certificates, and secure notes, not to create user accounts or set account-level restrictions.

401
MCQmedium

A technician is configuring a new employee's laptop and needs to ensure that only approved applications can run. The company wants to prevent users from installing unauthorized software. Which security control should be implemented?

A.Enable Windows Defender real-time protection.
B.Set the user account as a Standard User.
C.Configure an application whitelist using AppLocker.
D.Disable the Windows Store.
AnswerC

AppLocker enforces a whitelist, allowing only specified applications to run, directly meeting the requirement.

Why this answer

AppLocker is a Windows security feature that allows administrators to create rules that explicitly permit only approved applications to run, effectively blocking all others. This is the correct control for preventing unauthorized software installation because it enforces an application whitelist at the kernel level, overriding user permissions. Standard User accounts or antivirus alone cannot prevent execution of approved-but-unauthorized binaries, making AppLocker the precise solution for this requirement.

Exam trap

CompTIA expects you to recognize that while Standard User accounts limit some installations, AppLocker is the specific control for application whitelisting. The common pitfall is assuming user permissions alone can block all unauthorized software.

How to eliminate wrong answers

Option A is wrong because Windows Defender real-time protection is an antivirus/antimalware solution that detects and blocks malicious software based on signatures and behavior, not a mechanism to restrict execution to only approved applications; it does not prevent a user from running a non-malicious but unauthorized application. Option B is wrong because setting the user account as a Standard User limits system-level changes but does not prevent the user from running any executable they have access to; a standard user can still launch unauthorized applications from their profile or removable media. Option D is wrong because disabling the Windows Store only blocks installation of Store apps, but does not prevent installation or execution of traditional Win32 executables, scripts, or other software from any other source.

402
MCQhard

A technician is asked to install a new accounting application on a user's computer. The user mentions that a coworker told them the software is known to cause conflicts with antivirus programs. What should the technician do?

A.Ignore the user's comment because it is hearsay and proceed with the installation.
B.Research the software's compatibility with the antivirus and test in a sandbox if possible.
C.Disable the antivirus temporarily and install the software.
D.Tell the user that the coworker is mistaken and install the software anyway.
AnswerB

Researching software compatibility with existing antivirus solutions and testing in a sandbox environment is the most professional and thorough approach. This proactive measure ensures that the new accounting software will not conflict with critical security software, preventing system instability, data corruption, or security vulnerabilities. A sandbox provides an isolated testing ground, minimizing risk to the production system before full deployment.

Why this answer

The technician must validate the user's concern through proper research rather than dismissing it. Checking the software's documented compatibility with the specific antivirus program and testing in an isolated sandbox environment prevents potential system instability or security bypasses without risking the production system.

Exam trap

CompTIA often tests the candidate's ability to balance user input with professional verification, trapping those who either dismiss user concerns outright or take risky shortcuts like disabling security software.

How to eliminate wrong answers

Option A is wrong because ignoring the user's comment violates professional due diligence; hearsay can still indicate a real compatibility issue that could cause application crashes or antivirus false positives. Option C is wrong because disabling antivirus temporarily exposes the system to malware during installation and does not resolve the underlying conflict; the software might still malfunction or trigger alerts when antivirus is re-enabled. Option D is wrong because dismissing the coworker's claim without evidence is unprofessional and could lead to a failed installation or system compromise if the conflict is real.

403
MCQeasy

A user reports that their smartphone cannot connect to the office Wi-Fi, but other devices can. The network uses WPA2-Enterprise with PEAP-MSCHAPv2. The technician checks the phone's settings and sees that it is configured for WPA2-PSK. What is the most likely reason for the connection failure?

A.The phone's Wi-Fi antenna is damaged.
B.The phone is using the wrong security protocol.
C.The router's SSID is hidden.
D.The phone's MAC address is filtered.
AnswerB

WPA2-Enterprise with PEAP-MSCHAPv2 requires 802.1X authentication against a RADIUS server using user credentials and a server certificate. The phone is configured for WPA2-PSK, a preshared-key method, so the authentication exchange fails before association completes, explaining why only this device cannot connect.

Why this answer

The phone is configured for WPA2-PSK (Pre-Shared Key), but the office network uses WPA2-Enterprise with PEAP-MSCHAPv2. WPA2-Enterprise requires 802.1X authentication with a RADIUS server, using EAP methods like PEAP-MSCHAPv2, while WPA2-PSK uses a single shared passphrase. The mismatch in security protocols prevents the phone from completing the 4-way handshake, causing the connection failure.

Exam trap

CompTIA often tests the distinction between WPA2-PSK and WPA2-Enterprise, trapping candidates who assume all WPA2 configurations are interchangeable or that the issue is a simple connectivity problem like a hidden SSID or MAC filter.

How to eliminate wrong answers

Option A is wrong because a damaged Wi-Fi antenna would prevent connection to any network, not just this specific one, and other devices are connecting successfully. Option C is wrong because a hidden SSID does not affect the security protocol negotiation; the phone would still attempt to connect using the wrong protocol (WPA2-PSK) and fail. Option D is wrong because MAC address filtering would block the phone regardless of the security protocol setting, and the issue is specifically a protocol mismatch, not a MAC-based block.

404
MCQmedium

During a security audit, you discover that a user's workstation has an unauthorized application running. You need to terminate the process immediately from the command line. The process name is 'malware.exe'. Which command should you use?

A.tasklist /FI "IMAGENAME eq malware.exe"
B.taskkill /IM malware.exe /F
C.net stop malware
D.shutdown /r /t 0
AnswerB

`taskkill /IM malware.exe /F` targets the process by image name and forces termination, satisfying the requirement to end the unauthorised application immediately from the command line. The `/IM` switch matches `malware.exe` regardless of its process identifier, while `/F` overrides any refusal to close, ensuring the process stops without interactive prompts.

Why this answer

The `taskkill` command with the `/IM` (image name) and `/F` (force) flags is the standard Windows CLI method to forcibly terminate a process by its executable name. This directly stops 'malware.exe' without requiring the process ID, making it the appropriate tool for immediate termination during a security incident.

Exam trap

The trap here is that candidates confuse `tasklist` (a listing tool) with `taskkill` (a termination tool), or assume `net stop` can stop any running program, when in fact it only applies to Windows services.

How to eliminate wrong answers

Option A is wrong because `tasklist` only lists running processes and does not terminate them; it is a diagnostic tool, not a termination command. Option C is wrong because `net stop` is used to stop Windows services, not user-mode processes like 'malware.exe'; it would fail unless the malware is registered as a service. Option D is wrong because `shutdown /r /t 0` restarts the entire system, which is an overly disruptive action that does not specifically target the unauthorized process and may allow the malware to persist or re-launch on reboot.

405
MCQeasy

A user reports that after a recent Windows update, their computer now boots to a blue screen with the error 'INACCESSIBLE_BOOT_DEVICE'. They need to get back to work quickly. Which Windows recovery tool should you use first to attempt a repair?

A.System Restore
B.Reset this PC
C.Startup Repair
D.Command Prompt (chkdsk /f)
AnswerC

Startup Repair is the most appropriate initial troubleshooting step for boot failures, especially after a Windows update, as it automatically diagnoses and attempts to fix common issues preventing the operating system from loading. It scans for corrupted system files, incorrect Boot Configuration Data (BCD), problematic drivers, and disk errors that might cause stop codes like INACCESSIBLE_BOOT_DEVICE. This automated tool is designed to restore boot functionality without requiring manual intervention in the command line, making it the primary first-response utility.

Why this answer

Startup Repair is the correct first tool because INACCESSIBLE_BOOT_DEVICE is a boot-level failure typically caused by a missing or misconfigured boot device driver, corrupted BCD, or changed storage controller mode after an update. Startup Repair automatically scans for and fixes these boot configuration and driver issues without user intervention, making it the fastest first attempt.

Exam trap

The trap is assuming System Restore is always the fastest fix for boot errors; candidates must recognize that INACCESSIBLE_BOOT_DEVICE is a boot configuration/driver issue best handled by Startup Repair, not a general system rollback.

How to eliminate wrong answers

Option A is wrong because System Restore reverts system files and registry to a prior restore point but does not specifically repair boot configuration data or boot device drivers, and it may not have a recent restore point. Option B is wrong because Reset this PC is a destructive last-resort option that removes apps and potentially user data, far too heavy for a first repair attempt. Option D is wrong because chkdsk /f repairs file system and disk errors, not boot device driver or BCD misconfiguration, so it addresses the wrong layer of the problem.

406
MCQeasy

A small business owner wants to ensure that only authorized users can log into their Windows 10 workstations. They need a tool to create and manage user accounts and set password policies. Which administrative tool should you use?

A.Computer Management
B.Local Users and Groups
C.Group Policy Editor
D.Task Scheduler
AnswerB

The Local Users and Groups snap-in (lusrmgr.msc) is the dedicated administrative tool within Windows for managing user accounts and groups on a standalone, non-domain-joined computer. It provides direct functionality to create, modify, and delete local user accounts, assign them to local groups, and configure specific password policies such as password expiration, complexity requirements, and account lockout thresholds. This tool is precisely designed for granular control over local user security settings.

Why this answer

Local Users and Groups (lusrmgr.msc) is the snap-in for managing user accounts, groups, and local security policies on a standalone Windows system. It allows creating, modifying, and deleting users and setting password requirements.

407
MCQmedium

A user reports that their application crashes with an 'Access Denied' error when trying to write to a specific folder. You have verified the user has Full Control NTFS permissions. Which administrative tool should you use to check for any file encryption or compression that might be blocking the write?

A.Computer Management > Shared Folders to view open files.
B.Local Security Policy to check user rights assignments.
C.File Explorer > right-click folder > Properties > Advanced to view encryption and compression attributes.
D.Registry Editor to modify the folder's security descriptor.
AnswerC

Navigating to a folder in File Explorer, right-clicking, selecting "Properties," and then clicking the "Advanced..." button reveals the "Advanced Attributes" dialog. This interface directly displays critical file system attributes, including whether the folder's contents are encrypted using Encrypting File System (EFS) or compressed. These attributes can directly impact application access and functionality, making this the precise location to diagnose such issues.

Why this answer

The 'Access Denied' error despite Full Control NTFS permissions indicates a file-level attribute conflict. File encryption (EFS) or compression attributes are stored in the folder's Advanced Attributes dialog, accessible via File Explorer > Properties > Advanced. These attributes can block write access even when NTFS permissions are permissive, as encryption requires the user's EFS certificate and compression changes the file's physical layout.

Exam trap

The trap here is that candidates assume 'Access Denied' always means insufficient NTFS permissions, so they focus on permission tools (like Shared Folders or Security Policy) instead of checking file attributes like encryption or compression that override permission-based access.

How to eliminate wrong answers

Option A is wrong because Computer Management > Shared Folders > Open Files shows which files are currently locked by network sessions, not encryption or compression attributes; it cannot diagnose attribute-based write blocks. Option B is wrong because Local Security Policy manages user rights assignments (e.g., 'Log on locally', 'Shut down the system'), not file-level encryption or compression settings. Option D is wrong because Registry Editor modifies system-wide security descriptors in the registry, not per-folder encryption or compression attributes; folder attributes are stored in the NTFS master file table (MFT), not the registry.

408
MCQeasy

A customer is frustrated because every time they plug in a USB flash drive, Windows automatically opens the folder and plays any media files. They want to stop this behavior. Which Control Panel tool should you use to change the default action?

A.File Explorer Options
B.AutoPlay
C.Device Manager
D.Default Programs
AnswerB

AutoPlay is a Windows feature specifically designed to detect the connection of removable media, including USB drives, external hard drives, and optical discs, and then present the user with a choice of predefined actions. These actions can range from opening the device's folder to playing media content or initiating a specific program. Users can customize or completely disable AutoPlay for various device types through the Control Panel or Settings app, directly resolving issues where unwanted automatic actions occur upon device connection.

Why this answer

AutoPlay is the Windows Control Panel tool specifically designed to manage the default behavior when removable media like USB flash drives are connected. By configuring AutoPlay, you can set the system to 'Take no action' instead of automatically opening the folder and playing media files. This directly addresses the customer's frustration by stopping the automatic playback and folder opening.

Exam trap

CompTIA often tests the distinction between AutoPlay (which controls automatic actions upon device insertion) and Default Programs (which controls file type associations), leading candidates to mistakenly choose Default Programs because they confuse 'default action for a device' with 'default program for a file extension'.

How to eliminate wrong answers

Option A is wrong because File Explorer Options (formerly Folder Options) manages folder views, search settings, and file associations for browsing, not the automatic actions triggered by connecting removable media. Option C is wrong because Device Manager is used to manage hardware drivers, update firmware, and troubleshoot device conflicts, not to configure software-level default actions for media insertion. Option D is wrong because Default Programs sets which application opens a specific file type (e.g., .mp3 with VLC), but it does not control the system's automatic response when a device is plugged in, which is the role of AutoPlay.

409
MCQeasy

A customer reports that their workstation is running slowly after a recent group policy update. The change log indicates the update added new security settings. What is the most appropriate documentation step for the technician to take after resolving the issue?

A.Note the resolution in the change log and close the ticket.
B.Delete the change log entry to avoid confusion.
C.Send an email to the user explaining the fix.
D.Create a new change request to revert the group policy.
AnswerA

Noting the resolution in the change log and closing the ticket is the correct procedure following a successful fix. This action ensures proper documentation of the incident, the steps taken to resolve it, and the final outcome, which is crucial for audit trails, knowledge management, and future troubleshooting. Closing the ticket formally marks the completion of the incident management process, moving it from an active to a resolved status.

Why this answer

After resolving the issue, the technician must document the resolution in the change log to maintain an accurate audit trail of changes and their outcomes. This aligns with change management best practices, ensuring that future technicians can see what was done to fix the problem and avoid repeating the same troubleshooting steps. Closing the ticket after documenting the resolution completes the incident management lifecycle.

Exam trap

The trap here is that candidates may confuse the informal step of notifying the user (Option C) with the formal documentation requirement, or they may think that reverting the policy (Option D) is necessary without first verifying that the issue is fully resolved and documented.

How to eliminate wrong answers

Option B is wrong because deleting the change log entry violates change management policy by destroying the audit trail, making it impossible to track what changes were made and why. Option C is wrong because while notifying the user is courteous, it is not the most appropriate documentation step; the primary documentation requirement is updating the formal change log, not sending an informal email. Option D is wrong because creating a new change request to revert the group policy is premature and unnecessary; the issue has already been resolved, and reverting the policy without analysis could reintroduce security vulnerabilities or break other configurations.

410
MCQmedium

During a corporate device deployment, a technician configures an iPhone for a new employee. The employee later reports that they cannot receive emails on the native Mail app, but can access the webmail interface in Safari. What is the most likely misconfiguration?

A.The email account password was entered incorrectly.
B.The outgoing mail server (SMTP) settings are wrong.
C.The incoming mail server settings are incorrect.
D.The device's date and time are set incorrectly.
AnswerC

If the incoming mail server settings (such as the POP3 or IMAP server address, port number, or security protocol) are misconfigured in the device's email application, the app will be unable to establish a connection and download new emails. Webmail, conversely, accesses the mailbox directly on the server using a completely different interface and configuration, explaining why it functions correctly while the device's app fails to receive mail. This points directly to a client-side configuration error specific to the receiving mail function.

Why this answer

The user can access webmail via Safari but cannot receive emails in the native Mail app. This indicates the email account credentials are valid and the network connection is working, but the incoming mail server (POP3/IMAP) settings are misconfigured. Incorrect incoming server hostname, port, or SSL/TLS settings would prevent the Mail app from downloading new messages while leaving webmail unaffected.

Exam trap

The trap here is that candidates confuse incoming and outgoing mail server roles, assuming any email problem must be SMTP-related, when the symptom of being able to send but not receive points directly to the incoming server settings.

How to eliminate wrong answers

Option A is wrong because if the password were incorrect, the user would also be unable to log in to webmail, which they can access successfully. Option B is wrong because incorrect SMTP settings would prevent sending emails, not receiving them; the issue is specifically about not receiving emails. Option D is wrong because incorrect date and time would typically cause SSL/TLS certificate validation failures affecting both sending and receiving, and would also impact webmail access over HTTPS, which is working.

411
MCQmedium

A technician is configuring a new server rack in a shared office space. Which physical security measure should be applied to prevent unauthorized physical access to the servers?

A.Install a door alarm on the office entrance
B.Use rack-mount locks on each server chassis
C.Enable BitLocker on all server drives
D.Configure a strong BIOS password
AnswerB

Rack-mount locks are designed to physically secure individual server chassis within the rack, preventing them from being slid out, removed, or opened without authorization. These specialized locks directly attach to the server's mounting rails or front panel, creating a physical barrier against theft or internal component tampering. This measure provides direct hardware security, making it the most effective option for preventing unauthorized physical access to the server units themselves.

Why this answer

Rack-mount locks provide a direct physical barrier that prevents unauthorized individuals from opening the server chassis and accessing internal components, such as hard drives, memory, or cables. In a shared office space, this is the most effective measure to deter tampering, theft, or accidental damage at the rack level.

Exam trap

The trap here is that candidates often confuse logical security controls (like BitLocker or BIOS passwords) with physical security controls, failing to recognize that only a physical barrier like a lock prevents direct hardware access.

How to eliminate wrong answers

Option A is wrong because a door alarm on the office entrance only alerts to unauthorized entry into the room but does not prevent direct physical access to the server chassis once inside; it is a perimeter control, not a server-level control. Option C is wrong because BitLocker is a full-disk encryption technology that protects data at rest if a drive is removed, but it does not prevent physical access to the server itself or its components. Option D is wrong because a BIOS password controls boot-level access and prevents unauthorized changes to firmware settings, but it does not prevent someone from physically opening the chassis, removing drives, or tampering with hardware.

412
MCQmedium

A user reports that they cannot access a shared folder on the network, but other users can. The folder is on a Windows 10 Pro workstation. What should you check first to resolve this issue?

A.Check the Windows Defender Firewall settings
B.Check the NTFS permissions on the folder
C.Check the user’s password expiration status
D.Check the User Account Control settings
AnswerB

NTFS permissions govern access per user account, so if only this user is denied while others succeed, their account likely lacks the required Allow entries or is explicitly denied. Checking these permissions first isolates an account-specific rights problem rather than a share-level or network fault.

Why this answer

Since other users can access the shared folder, the network share and firewall are functioning correctly. The issue is specific to one user, which points to a permission problem at the file system level. NTFS permissions control user-level access to folders, and a misconfigured or missing ACE (Access Control Entry) for that user would prevent access while allowing others.

Checking NTFS permissions is the logical first step because it directly governs per-user access to the resource.

Exam trap

CompTIA A+ often tests the distinction between share-level permissions and NTFS permissions, trapping candidates who assume a firewall or password issue is the cause when the problem is user-specific and the resource is accessible to others.

How to eliminate wrong answers

Option A is wrong because the Windows Defender Firewall applies to all network traffic to the machine; if it were blocking access, no user would be able to reach the shared folder, contradicting the scenario where other users can access it. Option C is wrong because password expiration affects the ability to log into the domain or local account, not the ability to access a specific shared folder once the user is already authenticated and connected to the network. Option D is wrong because User Account Control (UAC) settings control administrative privilege elevation prompts and do not affect standard network file sharing access for authenticated users.

413
MCQmedium

A company is implementing a new policy that requires all employee laptops to have full-disk encryption enabled. A technician is asked to verify compliance on a Windows 11 Pro laptop. Which of the following tools should the technician use to check the encryption status?

A.Device Manager
B.Disk Management console
C.Task Manager
D.BitLocker Drive Encryption Control Panel applet
AnswerD

The BitLocker Drive Encryption Control Panel applet provides a straightforward interface to view the encryption status of each drive. It shows whether BitLocker is on or off, and the encryption method used. This is the correct tool for quickly verifying compliance with the full-disk encryption policy on a Windows 11 Pro system.

Why this answer

The BitLocker Drive Encryption Control Panel applet is the correct tool to check encryption status. It provides a clear indication of whether BitLocker is enabled and the encryption progress. Other tools like Device Manager, Disk Management, and Task Manager do not offer this specific information.

Using the correct tool ensures accurate compliance verification.

Exam trap

The trap here is confusing disk management tools with encryption status tools; only the BitLocker applet directly shows encryption state.

414
MCQhard

After a security incident, a Windows 10 workstation is suspected of having malware that prevents the Task Manager and Command Prompt from opening. You need to run a system scan. Which tool can you use from the Windows Recovery Environment (WinRE) to perform an offline antivirus scan?

A.System File Checker (sfc /scannow /offbootdir=C:\ /offwindir=C:\Windows)
B.Windows Memory Diagnostic
C.Microsoft Defender Offline Scan
D.Diskpart
AnswerC

Microsoft Defender Offline Scan is an essential tool for addressing persistent or deeply embedded malware infections, such as rootkits. It reboots the system into a secure, minimal environment, typically Windows Recovery Environment (WinRE), where it can perform a comprehensive scan using the latest virus definitions without loading the potentially compromised Windows operating system. This isolation prevents malware from actively interfering with the scanning process, allowing for more effective detection and removal of sophisticated threats.

Why this answer

Microsoft Defender Offline Scan is designed to run from the Windows Recovery Environment (WinRE) to scan the system before Windows starts, which bypasses malware that blocks tools like Task Manager or Command Prompt. It uses the same antivirus engine as Windows Defender but runs in a pre-boot environment, allowing it to detect and remove persistent threats that load early or hide from the normal OS. This makes it the correct tool for an offline antivirus scan when the system is suspected of being compromised.

Exam trap

The trap here is confusing system repair tools (like SFC) with antivirus tools, or assuming that any command-line tool in WinRE can perform an offline scan; candidates must recognize that only Microsoft Defender Offline is specifically designed for offline malware removal.

How to eliminate wrong answers

Option A is wrong because System File Checker (sfc) is not an antivirus tool; it only verifies and repairs corrupted system files, and the /offbootdir and /offwindir switches are used for offline repair, not malware scanning. Option B is wrong because Windows Memory Diagnostic tests RAM for hardware errors, not malware. Option D is wrong because Diskpart is a disk partitioning utility, not a security scanning tool.

415
MCQmedium

A help desk ticket states that a user cannot write to a shared directory /data/projects. The directory permissions are drwxr-xr-x and the user is in the 'staff' group. The directory's group owner is 'staff'. What is the most likely cause?

A.The user does not have read permission on the directory.
B.The directory lacks group write permission.
C.The user is not the owner of the directory.
D.The sticky bit is set on the directory.
AnswerB

The 'r-x' permission set for the group on the directory explicitly grants read and execute (traverse) permissions but conspicuously lacks the 'w' (write) permission. For a user to create, delete, or rename files within a directory, they must have write permission on that directory. Since the user is likely a member of the group, and the group lacks the necessary write permission, they are unable to perform write operations within the directory.

Why this answer

The directory permissions are drwxr-xr-x, which means the owner has read, write, and execute (rwx), the group has read and execute (r-x), and others have read and execute (r-x). Since the user is in the 'staff' group and the directory's group owner is 'staff', the user's effective permissions are the group permissions, which lack write (w). Therefore, the user cannot write to the directory.

Option B correctly identifies that the directory lacks group write permission.

Exam trap

The CompTIA A+ exam often tests the misconception that being a member of the group that owns a directory automatically grants write access, but candidates overlook that the group permissions must explicitly include the write bit (w) for the user to write to the directory.

How to eliminate wrong answers

Option A is wrong because the user has read permission via the group's 'r-x' permissions (the 'r' allows listing contents). Option C is wrong because ownership is not required to write to a directory; group write permission would suffice if present. Option D is wrong because the sticky bit (indicated by a 't' in the execute position) is not set in the displayed permissions (drwxr-xr-x), and even if it were, it restricts deletion of files by non-owners, not the ability to write new files.

416
MCQeasy

A customer reports that their computer is emitting a loud, continuous beep and the monitor shows no display. The technician suspects a hardware issue. What is the most important safety step to take before opening the case?

A.Put on anti-static wrist strap and grounding mat.
B.Unplug the power cord from the wall outlet.
C.Press the power button to discharge residual power.
D.Wear safety goggles to protect eyes from debris.
AnswerB

Unplugging the power cord from the wall outlet creates a physical air gap between the computer's internal power supply and the AC mains, eliminating the risk of a live 120V/230V line. This is the definitive first step because a soft-off via the power button or a switch on the PSU may still leave standby voltage present on the motherboard. Even though some capacitors can retain a dangerous charge, removing the cord is essential before any other safety procedure, such as discharging or opening the case.

Why this answer

The most important safety step before opening a computer case is to unplug the power cord from the wall outlet. This ensures complete disconnection from the AC mains, eliminating the risk of electric shock from exposed internal components, such as the power supply unit (PSU) capacitors, which can hold a dangerous charge even when the system is off. While other steps like wearing an anti-static wrist strap are good practices, they do not address the primary hazard of lethal voltage.

Exam trap

The trap here is that candidates often confuse ESD prevention (anti-static wrist strap) with electrical safety, or they think pressing the power button is a substitute for unplugging the power cord, when in fact the power button discharge step is only safe after the cord is removed.

How to eliminate wrong answers

Option A is wrong because, while an anti-static wrist strap and grounding mat protect against electrostatic discharge (ESD) damage to sensitive components, they do not prevent electric shock from the power supply; the technician could still be electrocuted if the system is plugged in. Option C is wrong because pressing the power button to discharge residual power is a step performed after unplugging the power cord to drain the capacitors, but it is not a safety step that removes the primary AC power hazard; attempting this while the cord is still plugged in can cause arcing or shock. Option D is wrong because safety goggles protect against physical debris like dust or loose screws, but they do not address the immediate electrical safety risk of opening a live system.

417
MCQmedium

A technician is configuring a new Mac mini for a kiosk application. The kiosk should run only a single web browser in full-screen mode, and users should not be able to exit the app or access the desktop. Which macOS feature should be used to enforce this?

A.Enable Guided Access in Accessibility settings
B.Configure a user account with Parental Controls set to allow only the browser app
C.Use the 'Single App Mode' setting in System Settings
D.Set the browser as a Login Item for a standard user
AnswerB

macOS Parental Controls, now integrated into Screen Time settings, allow administrators to precisely manage application access for specific user accounts. By configuring these controls, a technician can restrict a user account to launch and use only a designated application, such as a web browser, preventing access to the desktop, other applications, or system settings. When combined with auto-login for this restricted user and setting the browser as a login item, this effectively creates a robust single-application kiosk environment.

Why this answer

MacOS Parental Controls (now part of Screen Time) can restrict a standard user account to a single app, such as a web browser. When configured to 'Allow only this app,' the system prevents the user from switching apps, accessing the desktop, or exiting the browser, which is exactly what a kiosk requires.

Exam trap

The trap here is that candidates confuse macOS Parental Controls with iOS Guided Access, or assume a nonexistent 'Single App Mode' setting exists in System Settings, leading them to pick A or C.

How to eliminate wrong answers

Option A is wrong because Guided Access is an iOS/iPadOS feature, not available on macOS; it cannot be used to lock a Mac into a single app. Option C is wrong because 'Single App Mode' is not a setting in macOS System Settings; macOS uses Parental Controls or Managed Apple IDs for this purpose, not a dedicated toggle. Option D is wrong because setting the browser as a Login Item only launches it at login, but does not prevent the user from switching to other apps or accessing the desktop.

418
MCQeasy

A technician is configuring a remote desktop solution for a user who needs to access a Windows 10 Pro workstation from a Linux laptop. Which protocol should the technician ensure is enabled on the Windows machine?

A.VNC
B.RDP
C.SSH
D.Telnet
AnswerB

RDP (Remote Desktop Protocol) is Microsoft's proprietary protocol specifically designed for remote access to Windows desktops. It provides a full graphical user interface (GUI) experience, allowing users to interact with the remote machine as if they were sitting directly in front of it. Its native integration with Windows operating systems makes it the most straightforward and efficient solution for configuring a remote desktop for Windows machines, with robust client software available across various platforms, including Linux.

Why this answer

RDP (Remote Desktop Protocol) is the native protocol used by Windows for remote desktop connections. Windows 10 Pro includes an RDP server that listens on TCP port 3389, allowing clients such as the Microsoft Remote Desktop client on Linux to connect and provide a full graphical desktop experience. The technician must ensure the 'Allow remote connections to this computer' setting is enabled and that the Windows Firewall permits inbound RDP traffic.

Exam trap

CompTIA often tests the distinction between native Windows remote desktop (RDP) and cross-platform or command-line protocols, leading candidates to confuse VNC (which is also graphical but not native to Windows) or SSH (which is secure but not graphical) with the correct answer.

How to eliminate wrong answers

Option A is wrong because VNC (Virtual Network Computing) is a cross-platform remote desktop protocol but is not native to Windows; it requires third-party software on both ends and typically uses RFB (Remote Framebuffer) protocol on port 5900, not the built-in Windows solution. Option C is wrong because SSH (Secure Shell) provides encrypted command-line access and file transfer (using port 22) but does not natively support a full graphical desktop environment on Windows without additional components like X11 forwarding or third-party tools. Option D is wrong because Telnet is an unencrypted, text-only protocol (port 23) that offers no graphical interface and is deprecated due to security vulnerabilities; it is not suitable for remote desktop access.

419
MCQmedium

During a security audit, you find that several employees have been using the same weak password for their domain accounts. Which remediation should you implement first?

A.Disable the user accounts and require a manager to re-enable them
B.Configure a password policy in Group Policy requiring complexity and minimum length
C.Send a company-wide email reminding users to choose strong passwords
D.Install a third-party password manager for all employees
AnswerB

Implementing a password policy via Group Policy Objects (GPOs) centrally enforces security requirements across all domain-joined user accounts. This technical control mandates specific criteria, such as minimum length, character complexity (e.g., uppercase, lowercase, numbers, symbols), and password history, ensuring that users create and maintain strong, unique passwords consistently throughout the organization, preventing future weak password usage.

Why this answer

The most effective first step to prevent weak passwords is to enforce a strong password policy via Group Policy. This centrally mandates complexity requirements (e.g., uppercase, lowercase, digits, special characters) and a minimum length (typically 8–14 characters), which directly blocks the use of simple, common passwords at the domain level. Unlike awareness campaigns or reactive measures, this technical control proactively enforces security standards across all domain accounts.

Exam trap

CompTIA often tests the distinction between administrative controls (like emails or account disabling) and technical controls (like Group Policy), where candidates mistakenly choose a non-technical, awareness-based option (C) over a policy-enforced technical solution (B).

How to eliminate wrong answers

Option A is wrong because disabling accounts and requiring manager re-enablement is a reactive, disruptive measure that does not address the root cause—employees will likely continue using weak passwords once re-enabled. Option C is wrong because a company-wide email is a non-technical, awareness-only approach that relies on voluntary compliance and does not prevent users from choosing weak passwords; it lacks enforcement. Option D is wrong because installing a third-party password manager, while helpful for password storage and generation, does not enforce a minimum password complexity or length policy on the domain accounts themselves and is a secondary measure, not the first remediation step.

420
MCQhard

A security analyst discovers that a user's workstation has been compromised by a rootkit that hides its processes from Task Manager. The rootkit is not detected by the installed antivirus. Which step is most effective for remediation?

A.Run a full antivirus scan in Safe Mode.
B.Use System Restore to revert to a previous state.
C.Boot from a rescue disk and perform an offline antivirus scan.
D.Reinstall the operating system from the recovery partition.
AnswerC

A rootkit hiding processes from Task Manager operates at kernel level, so the running antivirus cannot see it. Booting from a rescue disk mounts the system offline, exposing the dormant rootkit files to scanning without the compromised kernel interfering, which is why offline remediation is effective.

Why this answer

A rootkit that hides its processes from Task Manager and evades the installed antivirus operates at a deep level within the operating system, often in kernel mode. Booting from a rescue disk (e.g., a live CD/USB with an offline scanner) loads a clean operating system environment, preventing the rootkit from loading and allowing the antivirus to scan the infected system's files without interference. This offline approach is the most effective remediation step when the rootkit is actively hiding from the installed AV in the normal OS context.

Exam trap

The trap here is that candidates often assume Safe Mode or System Restore can bypass rootkit persistence, but CompTIA tests the understanding that rootkits operate below the OS layer and require a clean, offline environment to be reliably detected and removed.

How to eliminate wrong answers

Option A is wrong because running a full antivirus scan in Safe Mode may still allow some rootkits to load if they hook into kernel drivers that are loaded even in Safe Mode, and the rootkit's evasion techniques can persist, leading to a missed detection. Option B is wrong because System Restore does not remove rootkits; it only reverts system files and registry settings to a previous state, while the rootkit's files and persistence mechanisms (e.g., in boot sectors or kernel drivers) often remain intact and can re-infect the system. Option D is wrong because reinstalling from the recovery partition may not fully remove a rootkit if it has infected the Master Boot Record (MBR) or firmware, as the recovery partition itself could be compromised or the rootkit may persist across a standard reinstall that does not wipe all partitions.

421
MCQmedium

A user needs to connect to a work VPN but cannot find the VPN settings in the network tray. You need to guide them to the correct location to add a VPN connection. Where in Windows Settings would you direct them?

A.Network & Internet > Status
B.Network & Internet > Ethernet
C.Network & Internet > VPN
D.Network & Internet > Proxy
AnswerC

The "Network & Internet > VPN" section is the correct and dedicated interface within Windows settings for managing Virtual Private Network connections. This page allows users to add new VPN profiles, configure essential connection details such as the VPN server address, select the appropriate VPN type (e.g., IKEv2, L2TP/IPsec), specify authentication methods, and then initiate or disconnect from these secure tunnels. It provides the comprehensive controls necessary for establishing secure remote access to a private network.

Why this answer

The VPN settings in Windows are located under Network & Internet > VPN. This is the dedicated section where users can add, configure, and manage VPN connections, including setting up a new VPN profile with the server address, authentication method, and protocol (e.g., IKEv2, SSTP, or L2TP/IPsec). The network tray only shows existing connections; to add a new VPN, you must navigate to this specific settings page.

Exam trap

The trap here is that candidates may confuse the network tray's quick-access VPN list with the actual settings location, or assume VPN configuration is under Status or Ethernet due to its association with network connectivity, but Windows isolates VPN setup under a dedicated VPN page.

How to eliminate wrong answers

Option A is wrong because Network & Internet > Status displays the current network status, data usage, and network properties, but does not provide options to add or configure VPN connections. Option B is wrong because Network & Internet > Ethernet is used for managing wired Ethernet adapter settings, such as IP configuration and DNS, and has no VPN-related functionality. Option D is wrong because Network & Internet > Proxy is for configuring proxy server settings (e.g., automatic or manual proxy setup), which is unrelated to VPN connection management.

422
MCQmedium

During a security audit, you discover that a supply closet containing spare hard drives has a door that can be opened with a standard paperclip. What is the most appropriate recommendation to address this vulnerability?

A.Replace the door with a solid-core door and install a deadbolt.
B.Install a privacy filter on the closet door window.
C.Upgrade the lock to a tamper-resistant electronic lock.
D.Place a sign on the door warning of security cameras.
AnswerC

Upgrading to a tamper-resistant electronic lock directly addresses the 'paperclip vulnerability' by replacing or augmenting the susceptible mechanical components with secure electronic mechanisms. These locks often utilize digital authentication methods (e.g., keypads, RFID, biometrics) and are engineered to resist manipulation and bypass attempts that exploit traditional lock-picking techniques. This solution provides a robust physical security control specifically designed to prevent unauthorized access through lock compromise.

Why this answer

The vulnerability is a weak physical lock that can be bypassed with a simple tool. Upgrading to a tamper-resistant electronic lock, such as one with a keypad or biometric reader, significantly increases the difficulty of unauthorized entry. This directly addresses the core issue of inadequate access control for sensitive assets like spare hard drives.

Exam trap

CompTIA A+ often tests the distinction between deterrent controls (signs, cameras) and preventive controls (locks, access control systems), leading candidates to choose a visible but ineffective option like a warning sign instead of a technical fix.

How to eliminate wrong answers

Option A is wrong because replacing the door and installing a deadbolt is an over-engineered solution that does not specifically address the lock vulnerability; a deadbolt can still be picked or bypassed with a paperclip if the lock cylinder is weak. Option B is wrong because a privacy filter on the window only prevents visual observation, not physical access, and does nothing to secure the door lock. Option D is wrong because a warning sign is a deterrent, not a physical control; it does not prevent an attacker from using a paperclip to open the door.

423
MCQmedium

After a security incident, a forensic analyst needs to ensure that Windows 10 audit logs capture all successful and failed attempts to access the 'Confidential' folder on a file server. Which audit policy configuration is required?

A.Enable 'Audit account logon events' for success and failure
B.Enable 'Audit object access' and configure the SACL on the folder
C.Enable 'Audit privilege use' for success and failure
D.Enable 'Audit process tracking' for success and failure
AnswerB

Object access auditing requires two elements: the Audit object access policy enabled in Group Policy or Local Security Policy, and a system access control list (SACL) set on the folder itself specifying success and failure events. Both together capture the required access attempts.

Why this answer

To audit access attempts to a specific folder, you must enable the 'Audit object access' policy in the Advanced Audit Policy Configuration (or the legacy 'Audit object access' under Local Policies). This policy alone does not audit anything; you must also configure a System Access Control List (SACL) on the 'Confidential' folder itself, specifying which access types (e.g., Read, Write) for which users or groups to audit for success and failure. Without the SACL, no object access events are generated.

Exam trap

CompTIA often tests the misconception that enabling 'Audit object access' alone is sufficient, but candidates forget that a SACL must also be explicitly configured on the target object for any audit events to be generated.

How to eliminate wrong answers

Option A is wrong because 'Audit account logon events' audits authentication events (logon/logoff) on the domain controller or local machine, not file or folder access. Option C is wrong because 'Audit privilege use' tracks the exercise of user rights (e.g., 'SeBackupPrivilege'), not object-level access like reading a folder. Option D is wrong because 'Audit process tracking' monitors process creation and termination events, which is unrelated to auditing file system access.

424
MCQmedium

A user reports that their Windows 10 PC displays a 'Low Disk Space' warning on the C: drive. You want to use a built-in tool to delete temporary files and empty the Recycle Bin. Which Settings page should you open?

A.System > Storage
B.System > About
C.Apps > Apps & features
D.Update & Security > Windows Update
AnswerA

The "System > Storage" section in Windows 10 Settings is the correct location for managing disk space. It provides a comprehensive overview of how storage is being utilized by different content categories, such as apps, temporary files, and documents. Crucially, this page offers direct access to initiate Storage Sense for automatic cleanup or to manually review and delete temporary files, system logs, and previous Windows installation files, directly addressing the need to free up disk space.

Why this answer

The 'Low Disk Space' warning on the C: drive can be resolved by using the built-in Storage Sense or the manual 'Free up space now' feature, both accessible under System > Storage. This page provides tools to delete temporary files, empty the Recycle Bin, and remove other unnecessary data to reclaim disk space without third-party software.

Exam trap

The trap here is that candidates may confuse the 'System > About' page (which shows system info) with the 'System > Storage' page (which manages disk space), or think that 'Apps & features' can delete temporary files, when it only uninstalls applications.

How to eliminate wrong answers

Option B (System > About) is wrong because it displays system information such as device specifications, Windows edition, and OS build, but does not include any tools for disk cleanup or file management. Option C (Apps > Apps & features) is wrong because it allows users to uninstall or manage installed applications, but does not provide direct access to delete temporary files or empty the Recycle Bin. Option D (Update & Security > Windows Update) is wrong because it manages Windows updates and recovery options, not temporary file cleanup or Recycle Bin management.

425
MCQhard

A user reports that they cannot access a shared folder on a file server. You suspect the network path is incorrect or the share is unavailable. Which command can you use to test connectivity to the server and the share simultaneously?

A.ping \\ServerName
B.net view \\ServerName
C.net use Z: \\ServerName\Share
D.tracert \\ServerName
AnswerB

This command lists all shared resources on the server, confirming both connectivity and share availability.

Why this answer

The `net view \\ServerName` command lists all shared resources on the specified server, confirming both network connectivity to the server and the availability of shares. If the server is unreachable or has no shares, the command will fail, directly testing the user's reported issue.

Exam trap

The trap here is that candidates often choose `ping` (Option A) because it is the most common connectivity test, but it does not verify SMB share availability or the correct network path to the share.

How to eliminate wrong answers

Option A is wrong because `ping` tests only ICMP-based network layer connectivity to the server's IP address, not the availability of the SMB share or the correct network path. Option C is wrong because `net use` attempts to map a drive to a specific share, which will fail if the share name is incorrect or the server is unreachable, but it does not simultaneously test connectivity to the server and list available shares. Option D is wrong because `tracert` traces the route to the server's IP address, verifying network path hops but not the SMB share availability or the server's NetBIOS name resolution.

426
MCQeasy

A customer reports that after a recent software update, their accounting application crashes every time they try to generate a report. The technician checks the change log and finds no record of any update being approved for that application. What should the technician do first?

A.Restore the application from the last known good backup.
B.Document the unauthorized change and escalate it to the change advisory board.
C.Uninstall the update and reinstall the previous version of the application.
D.Contact the software vendor to request a patch for the crash.
AnswerB

Documenting the unauthorized change and escalating it to the Change Advisory Board (CAB) is the correct initial step according to CompTIA A+ and ITIL best practices. This ensures that the unapproved modification is formally recorded, allowing for proper review, impact assessment, and a structured decision-making process before any corrective actions are implemented. This approach maintains accountability, reinforces change control policies, and helps prevent similar incidents in the future by addressing the process failure.

Why this answer

The technician found an unauthorized change (the update) with no approval record. The first step in change management is to document and escalate the unauthorized change to the Change Advisory Board (CAB) to assess impact, determine root cause, and authorize remediation. Restoring or reinstalling without CAB approval could violate change control policies and introduce additional risks.

Exam trap

CompTIA often tests the distinction between technical troubleshooting and process compliance, trapping candidates who jump to a technical fix (restore, uninstall, or patch) instead of following the documented change management procedure.

How to eliminate wrong answers

Option A is wrong because restoring from backup without first documenting and escalating the unauthorized change bypasses the change management process and could reintroduce the same issue if the backup also contains the unauthorized update. Option C is wrong because uninstalling the update and reinstalling the previous version is a technical action that should only be performed after the CAB has reviewed and approved the remediation plan, as it may affect other dependencies or compliance. Option D is wrong because contacting the vendor for a patch assumes the crash is a known software defect, but the root cause is an unauthorized change that must be addressed through change management first, not a vendor-supported fix.

427
MCQmedium

A company is upgrading its network switches and has 10 old switches that still work. The local school district has requested donations of working equipment. What should the technician do?

A.Throw the switches in the company dumpster.
B.Donate the switches to the school district.
C.Send the switches to a recycler even though they work.
D.Keep the switches in storage indefinitely.
AnswerB

Donating satisfies the school's request while the switches remain functional, but data-bearing network devices require secure sanitisation before transfer. Switches retain configuration files, VLAN details, credentials and management addresses; factory-reset each unit and document the wipe. Without this, the donation leaks sensitive network information, so sanitise first, then donate.

Why this answer

Donating the switches to the school district aligns with the principle of reuse, which is the most environmentally responsible option before recycling or disposal. The switches are still functional, so extending their lifecycle reduces e-waste and benefits the community. This practice supports the waste hierarchy: reduce, reuse, recycle.

Exam trap

CompTIA often tests the distinction between recycling and reuse, where candidates mistakenly choose recycling as the 'green' option, but the exam emphasizes that reuse is always preferable for still-functional equipment.

How to eliminate wrong answers

Option A is wrong because throwing functional switches in a dumpster violates environmental regulations and contributes to e-waste, which can leach hazardous materials like lead and mercury into the soil. Option C is wrong because sending working switches directly to a recycler bypasses the preferred option of reuse, which is more environmentally sustainable and energy-efficient than recycling. Option D is wrong because keeping the switches in storage indefinitely wastes potential utility and space, and does not align with responsible asset disposition or environmental stewardship.

428
MCQmedium

During a security audit, a technician discovers that an employee used a hammer to destroy several old hard drives. The drives are now in pieces, but the organization's policy mandates 'secure data destruction' for compliance. Which additional step should the technician take?

A.Document the destruction and consider it complete.
B.Use a degausser on the remaining pieces.
C.Visually inspect the platters for scratches and breaks, then shred any intact platters.
D.Run a data recovery tool on the pieces to see if data remains.
AnswerC

Visually inspecting the platters is a crucial step to confirm that the data-bearing surfaces have been sufficiently damaged, such as by deep scratches or complete breakage. If any platters remain intact or only partially compromised, data recovery could still be possible. Shredding any remaining intact platters ensures complete physical destruction, rendering data unrecoverable and providing undeniable proof of destruction, which is essential for meeting stringent security and compliance standards.

Why this answer

Physical destruction via hammering may leave intact platters or fragments that still hold readable data, so the technician must verify the platters are actually damaged and shred any that remain intact. This ensures the destruction is truly secure and compliant with the 'secure data destruction' policy. Documentation alone does not guarantee data is unrecoverable.

Exam trap

The trap is assuming that any physical damage (hammering) equals secure destruction; the exam tests whether you know that intact platters or fragments can retain recoverable data and must be verified and shredded.

How to eliminate wrong answers

Option A is wrong because simply documenting the hammer destruction does not verify that all platters are destroyed; intact fragments could still be recovered. Option B is wrong because degaussing is ineffective on the remaining pieces — degaussers work on intact magnetic media, and shattered fragments may not be properly erased, plus some drives are SSDs where degaussing does nothing. Option D is wrong because running data recovery on the pieces is counterproductive and does not constitute destruction; it also risks exposing residual data rather than ensuring it is unrecoverable.

429
MCQmedium

A company's security policy mandates that all USB flash drives must be encrypted before use. A user inserts a new USB drive and wants to encrypt it on a Windows 10 Pro workstation. Which built-in tool should be used?

A.Use EFS (Encrypting File System) on the USB drive.
B.Enable BitLocker To Go on the USB drive.
C.Format the drive as exFAT and set a password.
D.Use the cipher command to encrypt the drive.
AnswerB

Enabling BitLocker To Go on the USB drive is the most appropriate solution for encrypting removable media to meet a company's security policy. BitLocker To Go provides full-disk encryption specifically designed for portable storage devices, ensuring all data on the drive is encrypted at rest. It is a robust, built-in feature of Windows Pro and Enterprise editions, offering strong protection and requiring a password or smart card for access, even if the drive is lost or stolen.

Why this answer

BitLocker To Go is the built-in Windows 10 Pro feature specifically designed to encrypt removable drives such as USB flash drives. It uses AES encryption to protect the entire volume, and the drive can be accessed only with a password, smart card, or recovery key. This directly satisfies the company's mandate for encrypting USB drives before use.

Exam trap

CompTIA often tests the distinction between EFS (file-level encryption) and BitLocker (full-volume encryption), and the trap here is that candidates mistakenly choose EFS because they associate 'encryption' with file-level protection, not realizing that EFS cannot encrypt an entire removable drive and is not designed for USB flash drives.

How to eliminate wrong answers

Option A is wrong because EFS (Encrypting File System) encrypts individual files and folders on NTFS volumes, but it does not encrypt entire removable drives and is not supported on USB flash drives formatted with FAT32 or exFAT. Option C is wrong because formatting as exFAT and setting a password is not a built-in Windows encryption feature; exFAT does not natively support password-based encryption, and any such password would be implemented by third-party software, not Windows. Option D is wrong because the cipher command is used to manage EFS encryption on NTFS volumes and to overwrite deleted data; it cannot encrypt an entire USB drive or enable BitLocker To Go.

430
MCQeasy

A user reports that their Windows 10 laptop shows a 'Your license will expire soon' watermark on the desktop. They recently replaced the motherboard. Which Control Panel applet should you use to re-activate Windows?

A.Device Manager
B.System
C.User Accounts
D.Network and Sharing Center
AnswerB

The 'System' section, accessible via Control Panel or the Settings app in Windows 10, is the definitive location for viewing the operating system's core information. Here, users can find details about their Windows edition, processor, installed RAM, and crucially, the Windows activation status. It provides direct links to change the product key, activate Windows using a digital license, or troubleshoot activation issues, making it the correct utility for this task.

Why this answer

The System applet (also known as 'System Properties' or 'About' in Settings) is the correct Control Panel location to view and manage Windows activation status. After replacing the motherboard, Windows 10 detects a significant hardware change and may require re-activation. The System applet provides a 'Change product key' or 'Activate Windows' link to enter a new or existing license key, or to use the activation troubleshooter to re-activate with a digital license tied to a Microsoft account.

Exam trap

CompTIA often tests the misconception that Device Manager is used for activation because it deals with hardware changes, but Device Manager only manages drivers, not licensing.

How to eliminate wrong answers

Option A (Device Manager) is wrong because it is used to manage hardware drivers and devices, not to handle Windows licensing or activation. Option C (User Accounts) is wrong because it manages user profiles, passwords, and credentials, not the operating system's license activation. Option D (Network and Sharing Center) is wrong because it configures network adapters, sharing settings, and internet connections, none of which are involved in the Windows activation process.

431
MCQeasy

A small business owner asks you to configure their office computers so that employees cannot install unauthorized browser extensions. Which policy setting should you implement?

A.Disable the browser's developer mode in the settings.
B.Set the browser to always use private browsing mode.
C.Use Group Policy to block extension installation and whitelist approved extensions.
D.Install a pop-up blocker on each computer.
AnswerC

Utilizing Group Policy (GPO) provides a robust, centralized management solution for Windows environments, allowing administrators to precisely control browser settings across multiple machines. By configuring specific GPO settings, an administrator can enforce policies that block all extension installations by default, while simultaneously whitelisting only approved extensions necessary for business operations. This method ensures consistent security and compliance by preventing unauthorized software from being introduced into the browser environment.

Why this answer

Group Policy allows centralized management of browser settings in a domain environment. By configuring the 'Configure the list of force-installed extensions' and 'Block external extensions' policies, an administrator can whitelist approved extensions and prevent users from installing any others. This directly addresses the requirement to block unauthorized browser extensions.

Exam trap

CompTIA often tests the distinction between user-configurable browser settings (like disabling developer mode or enabling private browsing) and centrally enforced Group Policy settings that cannot be overridden by the user.

How to eliminate wrong answers

Option A is wrong because disabling developer mode only prevents access to developer tools and does not block extension installation; extensions can still be installed via the Chrome Web Store or other methods. Option B is wrong because private browsing mode (Incognito) does not restrict extension installation; it only prevents browsing history from being saved locally. Option D is wrong because a pop-up blocker only suppresses unwanted pop-up windows and has no effect on the installation or management of browser extensions.

432
MCQeasy

A user is unable to install a new app on their Android tablet because the device claims there is 'insufficient storage,' even though they have deleted several large files. What is the most likely reason for this error?

A.The device's SD card is corrupted.
B.The app is incompatible with the Android version.
C.The deleted files are still in the recycle bin or trash folder, taking up space.
D.The tablet's battery is too low to complete the installation.
AnswerC

Many contemporary Android versions and third-party file management applications incorporate a "recycle bin" or "trash" feature, akin to desktop operating systems. When files are initially "deleted," they are often moved to this temporary holding area instead of being permanently erased from storage immediately. These files continue to occupy valuable storage space until the recycle bin is manually emptied, which is a critical step to truly free up the necessary space for new application installations.

Why this answer

On Android devices, deleted files are moved to a recycle bin or trash folder (e.g., in the Files by Google app or the Gallery app's trash), not permanently erased. The system still counts these files as occupied storage until the trash is emptied, so even after deleting large files, the available space remains unchanged, causing the 'insufficient storage' error during app installation.

Exam trap

CompTIA often tests the misconception that deleting files immediately frees up space, ignoring the recycle bin/trash mechanism that is standard on modern Android devices.

How to eliminate wrong answers

Option A is wrong because a corrupted SD card would typically cause read/write errors or the card to be unmountable, not a specific 'insufficient storage' message; the error is about space, not card integrity. Option B is wrong because app incompatibility with the Android version usually triggers a 'not compatible' or 'app not installed' error, not a storage-related message. Option D is wrong because low battery prevents installation due to power-saving policies, but the error message would be about battery level, not storage space.

433
MCQmedium

A technician is tasked with disposing of a large batch of optical discs (CD-Rs and DVD-Rs) that contain archived customer records. The company policy requires data to be unrecoverable. Which disposal method is most appropriate?

A.Use a degausser to demagnetize the discs.
B.Overwrite the discs with a disk-wiping tool.
C.Shred the discs using an industrial cross-cut shredder.
D.Perform a quick format on the discs.
AnswerC

Shredding optical discs with an industrial cross-cut shredder is a highly effective and secure method for data destruction. This process physically breaks the disc into numerous small, irregular fragments, completely destroying the data layer where information is stored as pits and lands. The cross-cut action ensures that no large contiguous sections of the data track remain intact, making any attempt at data recovery practically impossible and extremely cost-prohibitive. This method provides irreversible physical destruction.

Why this answer

Industrial cross-cut shredding physically destroys the optical discs (CD-Rs and DVD-Rs), rendering the data unrecoverable. Unlike magnetic media, optical discs store data as physical pits in a dye layer, so degaussing or overwriting is ineffective. Shredding ensures compliance with data destruction policies requiring unrecoverable data.

Exam trap

The trap here is that candidates confuse optical discs with magnetic media and assume degaussing or overwriting works, but the CompTIA A+ exam tests the fundamental difference that optical storage is physically permanent and requires physical destruction.

How to eliminate wrong answers

Option A is wrong because degaussers work by disrupting magnetic fields on magnetic media (e.g., hard drives, tapes), but optical discs like CD-Rs and DVD-Rs store data optically, not magnetically, so demagnetization has no effect. Option B is wrong because overwriting with a disk-wiping tool is designed for rewritable media (e.g., CD-RW, DVD-RW) and cannot alter the read-only dye layer of CD-Rs or DVD-Rs; the data remains physically intact. Option D is wrong because a quick format only removes the file system index, leaving the actual data on the disc fully recoverable with forensic tools.

434
MCQhard

A security audit reveals that a company's remote access solution uses a VPN with pre-shared keys (PSK) for authentication. The auditor recommends upgrading to certificate-based authentication. Which of the following is the primary security advantage of certificate-based authentication over PSK?

A.Certificates are easier to configure and manage than PSK.
B.Certificates provide mutual authentication and are unique per device, reducing the risk of a single compromised key affecting all users.
C.Certificates eliminate the need for a VPN server.
D.Certificates are faster than PSK for establishing VPN connections.
AnswerB

Certificate-based authentication provides robust mutual authentication, where both the client and the VPN server verify each other's identities using digital certificates issued by a trusted Certificate Authority. Each certificate is unique to a specific device or user, meaning that if one device's certificate is compromised, only that single certificate needs to be revoked. This prevents a widespread security breach that would occur if a shared pre-shared key (PSK) were compromised, which would affect all users.

Why this answer

Certificate-based authentication provides mutual authentication, meaning both the VPN client and server verify each other's identity using digital certificates issued by a trusted Certificate Authority (CA). Unlike PSK, which is a shared secret that can be leaked and reused across all devices, each certificate is unique per device, so compromise of one certificate does not expose the entire VPN infrastructure. This significantly reduces the blast radius of a security breach and aligns with the principle of least privilege.

Exam trap

CompTIA often tests the misconception that certificates are 'easier' or 'faster' than PSK, when in reality the primary security advantage is mutual authentication and per-device uniqueness, not operational simplicity or performance.

How to eliminate wrong answers

Option A is wrong because certificates are generally more complex to configure and manage than PSK, requiring a PKI infrastructure, CA servers, and certificate lifecycle management, whereas PSK is a simple shared string. Option C is wrong because certificates do not eliminate the need for a VPN server; the VPN server is still required to terminate the tunnel and enforce policies, regardless of the authentication method. Option D is wrong because certificate-based authentication often introduces additional latency due to certificate validation, CRL checks, and OCSP lookups, making it typically slower than PSK for establishing VPN connections.

435
MCQmedium

A technician is replacing the thermal paste on a CPU. After cleaning the old paste, the technician accidentally touches the CPU contacts with bare fingers. What is the primary concern?

A.The CPU may be damaged by electrostatic discharge (ESD).
B.The CPU may overheat due to improper thermal paste application.
C.The CPU contacts may become contaminated with oils from the skin.
D.The CPU may be physically damaged by the pressure of the touch.
AnswerC

Human skin naturally produces oils, salts, and other residues that can easily transfer to the delicate electrical contacts of a CPU when touched with bare fingers. These contaminants can create an insulating layer, impeding proper electrical conductivity between the CPU and its socket. Over time, these residues can also lead to corrosion of the metallic contacts, resulting in intermittent connections, system instability, or complete failure of the CPU or motherboard.

Why this answer

Touching the CPU contacts with bare fingers transfers natural oils and contaminants from the skin onto the gold-plated contact pads. These oils can cause corrosion over time or create an insulating layer that impedes proper electrical connectivity, leading to intermittent failures or permanent damage. The primary concern is contamination, not ESD, overheating, or physical pressure.

Exam trap

CompTIA often tests the distinction between immediate ESD damage and long-term contamination risks, trapping candidates who assume any physical contact with components must be an ESD concern rather than recognizing the specific hazard of skin oils on electrical contacts.

How to eliminate wrong answers

Option A is wrong because while ESD is a general risk when handling components, the question specifies that the technician touched the contacts after cleaning, and the primary concern from skin contact is oil contamination, not ESD (which is mitigated by grounding). Option B is wrong because improper thermal paste application affects heat transfer from the IHS to the cooler, not the CPU contacts; touching contacts does not directly cause overheating. Option D is wrong because the pressure from a light touch is negligible and far below the force required to physically damage the CPU contacts or substrate.

436
MCQeasy

A receptionist at a company receives a call from someone claiming to be from the IT department. The caller says they need her password to perform an urgent server update. The receptionist provides the password. What type of social engineering attack is this?

A.Tailgating
B.Pretexting
C.Phishing
D.Baiting
AnswerB

Pretexting fits because the caller fabricates an IT-department identity and an urgent server-update scenario to justify requesting credentials. This invented context, or pretext, exploits the receptionist's trust in authority and time pressure, satisfying the stem's constraint of a plausible false narrative used to extract the password.

Why this answer

Pretexting is a social engineering attack where the attacker fabricates a scenario (the pretext) to manipulate the target into divulging sensitive information. In this case, the caller falsely claims to be from the IT department and invokes an urgent server update to trick the receptionist into revealing her password. This is not a technical exploit but a psychological manipulation that relies on the target's trust in authority and urgency.

Exam trap

CompTIA often tests the distinction between pretexting and phishing by emphasizing that pretexting relies on a fabricated scenario (often via phone or in-person) rather than a technical lure or electronic message, so candidates mistakenly choose phishing when the attack vector is a voice call.

How to eliminate wrong answers

Option A is wrong because tailgating involves an unauthorized person physically following an authorized individual into a restricted area, not a phone-based request for credentials. Option C is wrong because phishing typically uses deceptive electronic communications (e.g., email, fake websites) to harvest credentials, not a direct voice call with a fabricated story. Option D is wrong because baiting lures victims with a promise of a reward (e.g., free USB drive) or a digital trap (e.g., infected download), not a false claim of authority and urgency.

437
MCQeasy

A user reports that a scheduled backup script on their Windows 10 workstation runs every day but fails to complete. The script uses PowerShell to copy files to a network share. When the user runs the script manually from an elevated PowerShell prompt, it works. What is the most likely cause of the failure?

A.The script file extension is .ps1 instead of .bat.
B.The scheduled task is not set to run with highest privileges.
C.The network share is mapped as a drive letter, which is not available during system startup.
D.PowerShell execution policy is set to Restricted for the SYSTEM account.
AnswerB

If the script needs admin rights, the task must be configured to run with highest privileges; otherwise it fails.

Why this answer

The scheduled task runs under the SYSTEM account by default, which lacks the necessary permissions to access network resources or perform administrative file operations. Running the script manually from an elevated PowerShell prompt works because the user has the required privileges. Setting the task to 'Run with highest privileges' elevates the SYSTEM account to have the same rights as an administrator, resolving the access issue.

Exam trap

CompTIA A+ often tests the misconception that the SYSTEM account inherently has full administrative rights, when in fact scheduled tasks default to running without elevation unless explicitly configured.

How to eliminate wrong answers

Option A is wrong because the file extension (.ps1 vs .bat) does not affect the ability to run a PowerShell script; the task can be configured to execute PowerShell.exe with the script as an argument. Option C is wrong because the failure occurs even when the script runs daily (not just at startup), and mapped drive letters are available to the SYSTEM account only if the task is configured to run with the user's credentials or the drive is reconnected. Option D is wrong because the PowerShell execution policy for the SYSTEM account is not the issue; the script runs successfully when executed manually from an elevated prompt, indicating the policy is permissive enough for that context, and the scheduled task can be configured to bypass the policy using the -ExecutionPolicy Bypass flag.

438
MCQmedium

A small business has a shared Windows 10 workstation that multiple employees use. They want to ensure that each user's desktop settings, files, and application data are completely isolated and that users cannot access each other's data. Which feature should you configure to achieve this?

A.Enable the built-in Guest account for all users.
B.Create standard local user accounts and set NTFS permissions on each user's profile folder.
C.Join the computer to a domain and use roaming profiles.
D.Enable BitLocker on the system drive.
AnswerB

Creating standard local user accounts ensures each user has a distinct profile, preventing them from making system-wide changes that could affect other users or the operating system's stability. Crucially, setting explicit NTFS permissions on each user's profile folder (e.g., C:\Users\<username>) restricts access so that only the respective user and administrators can read or modify their data. This combination effectively isolates each user's files and settings, providing the necessary data privacy on a shared workstation.

Why this answer

Creating standard local user accounts and setting NTFS permissions on each user's profile folder ensures that each user has a separate profile and that file system ACLs prevent users from accessing each other's data. Windows automatically creates a separate user profile directory under C:\Users for each account, and NTFS permissions by default restrict access to the owner and administrators.

Exam trap

The trap is confusing disk encryption (BitLocker) or domain features with user-level data isolation, when the actual mechanism is separate user accounts combined with NTFS permissions.

How to eliminate wrong answers

Option A is wrong because enabling the Guest account provides a shared, non-password-protected account with no isolation between users, defeating the requirement. Option C is wrong because joining a domain and using roaming profiles centralizes profile storage but does not inherently isolate users on a shared workstation beyond what local accounts already provide, and it adds unnecessary complexity for a small business. Option D is wrong because BitLocker encrypts the entire drive at rest but does not provide user-level isolation; all users on the running system can still access each other's files.

439
MCQhard

A security incident is reported: an employee's company-issued Android phone is displaying persistent pop-up ads, even when no browser is open. The employee admits to side-loading a game from an unknown website. What is the most likely cause and best immediate action?

A.The phone has a virus; perform a factory reset immediately.
B.The side-loaded app is adware; boot into safe mode and uninstall it.
C.The browser is infected; clear the browser cache and data.
D.The phone's firmware is compromised; reflash the stock ROM.
AnswerB

Side-loaded applications, especially from untrusted sources, are a common vector for adware and other potentially unwanted programs on Android devices. Booting an Android device into safe mode temporarily disables all third-party applications, preventing the adware from running and interfering with its removal. This allows the user to safely navigate to the device's application settings and uninstall the malicious side-loaded app without it actively resisting or re-installing itself.

Why this answer

The persistent pop-up ads, even without a browser open, indicate adware behavior typical of malicious apps. Since the employee side-loaded a game from an unknown website, the most likely cause is that the side-loaded app contains adware. Booting into safe mode (which disables third-party apps) and uninstalling the suspicious app is the best immediate action because it removes the adware without data loss, unlike a factory reset.

Exam trap

CompTIA often tests the distinction between adware and a general virus, and the trap here is that candidates may jump to a factory reset (Option A) without considering the less destructive safe-mode uninstall, or they may incorrectly attribute the pop-ups to the browser (Option C) when the behavior occurs system-wide.

How to eliminate wrong answers

Option A is wrong because a 'virus' is a broad term; the specific symptom of pop-up ads points to adware, not a general virus, and a factory reset is an overly drastic first step that wipes all data unnecessarily. Option C is wrong because the pop-ups occur even when no browser is open, indicating the issue is not browser-based; clearing browser cache and data would not affect a system-level adware app. Option D is wrong because firmware compromise is rare and typically requires persistent root-level access; side-loading a game does not typically flash firmware, and reflashing the stock ROM is a last-resort measure that would wipe the device and is not the best immediate action.

440
MCQhard

A user's Android phone is running extremely slowly after installing a new launcher app. They want to revert to the default launcher without losing data. What is the correct procedure?

A.Uninstall the new launcher app via the Play Store.
B.Perform a factory reset from Recovery Mode.
C.Go to Settings > Apps > Default apps > Home app and select the default launcher.
D.Clear the cache partition from Recovery Mode.
AnswerC

Android stores the default launcher as a user-selectable Home app preference, so switching it under Settings > Apps > Default apps > Home app reassigns the role without uninstalling the launcher or touching user data, satisfying the no-data-loss constraint.

Why this answer

Android allows users to change the default home app via Settings > Apps > Default apps > Home app without uninstalling the new launcher or losing any data. This procedure simply reassigns the default launcher to the system's built-in launcher, preserving all installed apps, settings, and user data.

Exam trap

A common misconception is that uninstalling the new launcher is required to revert to the default launcher. In Android, uninstalling a launcher automatically reverts to the system default, but this removes the launcher app. The correct procedure to keep the launcher installed but not active is to change the default home app in Settings.

How to eliminate wrong answers

Option A is wrong because uninstalling the new launcher app via the Play Store will remove the app but does not automatically revert the default home app assignment; the system may still try to use the missing launcher, causing instability or requiring a manual default reset. Option B is wrong because performing a factory reset from Recovery Mode wipes all user data, including apps, settings, and personal files, which is unnecessary and destructive when the goal is only to change the default launcher without data loss. Option D is wrong because clearing the cache partition from Recovery Mode removes temporary system cache files, which does not affect the default launcher assignment or resolve the performance issue caused by the new launcher app.

441
MCQmedium

A technician is troubleshooting an iPhone that fails to activate after a software update. The phone displays 'Activation Error' and the SIM card is known to be working. Which of the following steps should the technician perform FIRST?

A.Replace the SIM card with a new one.
B.Restore the iPhone using iTunes or Finder.
C.Check Apple's System Status page for activation server outages.
D.Reset the iPhone's network settings.
AnswerC

Checking Apple's System Status page is the most logical and efficient first step because iPhone activation fundamentally relies on communication with Apple's dedicated activation servers. If these servers are experiencing an outage or maintenance, no iPhone, regardless of its local condition, will be able to complete the activation process. Verifying server status quickly confirms whether the problem is external to the device, saving significant troubleshooting time and effort.

Why this answer

The 'Activation Error' after a software update typically indicates that the iPhone cannot reach Apple's activation servers to verify its eligibility. Since the SIM card is known to be working, the most logical first step is to check Apple's System Status page to rule out a server-side outage, which is a common cause of activation failures and can be resolved without any device-side intervention.

Exam trap

CompTIA often tests the candidate's ability to prioritize simple, non-invasive checks (like server status) over more disruptive troubleshooting steps, and the trap here is that many candidates jump to restoring the device or replacing hardware without first verifying external dependencies.

How to eliminate wrong answers

Option A is wrong because the SIM card is already confirmed to be working, so replacing it would be unnecessary and would not address a server-side activation issue. Option B is wrong because restoring the iPhone using iTunes or Finder is a more drastic step that should be taken only after confirming that Apple's activation servers are online; a restore could also fail if the servers are down. Option D is wrong because resetting network settings would not help if the activation servers themselves are unavailable; this step is more appropriate for connectivity issues unrelated to server outages.

442
MCQmedium

A user's laptop running Windows 10 Pro connects to the corporate Wi-Fi but cannot access internal resources. The network uses WPA2-Enterprise with PEAP-MSCHAPv2. The laptop's wireless profile is configured correctly. Other users in the same office can access resources. What is the most likely cause?

A.The laptop's wireless adapter is faulty.
B.The user's domain account is locked or the password has expired.
C.The access point is broadcasting on a congested channel.
D.The laptop has an incorrect IP address from DHCP.
AnswerB

In an enterprise environment, Wi-Fi authentication often leverages 802.1X, which typically uses protocols like PEAP-MSCHAPv2 to validate user credentials against a central directory service, such as Active Directory. If the user's domain account is locked or their password has expired, the authentication server (e.g., a RADIUS server) will reject the authentication request. This prevents the user from gaining full network access and obtaining a valid IP address, even if the laptop successfully associates with the access point's signal.

Why this answer

The user can connect to Wi-Fi but cannot access internal resources, and other users are unaffected. Since the wireless profile is correct and WPA2-Enterprise uses PEAP-MSCHAPv2 for authentication, the most likely cause is that the user's domain account is locked or the password has expired. This would prevent successful authentication against the RADIUS server, blocking access to internal resources even though the client associates with the access point.

Exam trap

The 220-1202 exam often tests the distinction between Layer 2 association and Layer 3 authentication; the trap here is that candidates assume a successful Wi-Fi connection implies full network access, overlooking that WPA2-Enterprise requires valid domain credentials for RADIUS-based authentication to grant access to internal resources.

How to eliminate wrong answers

Option A is wrong because a faulty wireless adapter would typically prevent association or cause intermittent connectivity, not allow a successful connection to the Wi-Fi network while blocking internal resource access. Option C is wrong because a congested channel would affect all users in the area, not just one user, and would manifest as poor performance or disconnections, not a complete inability to access internal resources. Option D is wrong because an incorrect IP address from DHCP would prevent network communication entirely, but the user can connect to the Wi-Fi and likely obtain an IP address; the issue is at the authentication layer, not the IP layer.

443
MCQmedium

A technician is tasked with replacing a faulty power supply in a desktop computer that is part of a critical patient record system at a clinic. Before starting, the technician reviews the change management policy. Which step should the technician perform first?

A.Power off the workstation and disconnect all cables
B.Submit a change request to the change advisory board (CAB)
C.Back up the patient records to an external drive
D.Notify the clinic staff that the system will be offline
AnswerB

Submitting a change request to the Change Advisory Board (CAB) is the correct initial step in a formal IT change management process. This ensures that the proposed replacement of a faulty component is properly documented, reviewed for potential risks and impacts, and scheduled to minimize disruption. The CAB's approval provides the necessary authorization and coordination before any physical work or further planning commences.

Why this answer

The change management policy requires that any modification to a system handling critical patient records must first be formally approved via a change request submitted to the Change Advisory Board (CAB). This ensures that risks are assessed, downtime is scheduled, and compliance with healthcare data regulations (e.g., HIPAA) is maintained before any physical work begins.

Exam trap

CompTIA often tests the misconception that immediate physical safety steps (like powering off) or data backup should come first, but the exam emphasizes that change management approval is the mandatory initial step in any planned maintenance on a critical system.

How to eliminate wrong answers

Option A is wrong because powering off and disconnecting cables before obtaining change approval violates the change management process, potentially causing unauthorized downtime and data access risks. Option C is wrong because backing up patient records is a data protection step that should be performed after the change is approved, not before; the technician must first secure authorization to proceed. Option D is wrong because notifying clinic staff of an outage without prior CAB approval could disrupt critical operations and bypass the formal communication and scheduling protocols required by the change management policy.

444
MCQmedium

A small business owner wants to prevent employees from installing any software on their Windows 10 workstations without administrator approval. Which Control Panel or Settings feature should you configure to enforce this restriction?

A.Windows Defender Firewall
B.User Accounts > Change User Account Control settings
C.System > Advanced system settings > Performance
D.Ease of Access > Make the keyboard easier to use
AnswerB

User Account Control (UAC) is a critical security feature in Windows designed to prevent unauthorized changes to the operating system. By setting UAC to 'Always notify' or a similar elevated level, any attempt to install software, modify system files, or alter settings that require administrative privileges will trigger a prompt. This prompt requires an administrator's explicit consent, effectively blocking standard users from installing applications without approval.

Why this answer

User Account Control (UAC) settings, accessed via User Accounts in Control Panel, allow you to control when and how users are prompted for permission before making system changes, including software installations. By setting UAC to the highest level, you ensure that any installation attempt triggers an administrator approval prompt, effectively preventing unauthorized software installations on Windows 10 workstations.

Exam trap

The trap here is that candidates often confuse Windows Defender Firewall with general security controls, mistakenly thinking it can block software installations, when in fact it only filters network traffic and has no mechanism to prevent local software execution.

How to eliminate wrong answers

Option A is wrong because Windows Defender Firewall is designed to control inbound and outbound network traffic based on rules, not to manage software installation permissions or user privilege elevation. Option C is wrong because System > Advanced system settings > Performance configures visual effects, processor scheduling, and virtual memory, which have no bearing on software installation restrictions. Option D is wrong because Ease of Access > Make the keyboard easier to use provides accessibility features like Sticky Keys and Filter Keys, which do not enforce software installation policies.

445
MCQhard

A user reports that their computer is sending out a large amount of network traffic even when they are not using the internet. The antivirus detects a file named 'expl0rer.exe' in the startup folder. What type of malware is most likely causing this behavior?

A.Spyware
B.Botnet
C.Virus
D.Trojan
AnswerB

A botnet infection turns a user's computer into a "bot" or "zombie" machine, remotely controlled by an attacker. These bots are then used to participate in coordinated malicious activities, such as Distributed Denial of Service (DDoS) attacks, sending spam emails, or cryptocurrency mining. These activities inherently generate significant and sustained outbound network traffic as the compromised machine actively engages in these operations, making it the most fitting answer for a computer 'sending out' a lot of data.

Why this answer

The file name 'expl0rer.exe' mimics the legitimate 'explorer.exe' but uses a zero in place of the 'o', a common obfuscation technique. The symptom of high outbound network traffic without user activity, combined with the file's presence in the startup folder, strongly indicates the computer is part of a botnet. Botnet malware connects to a command-and-control (C2) server to receive instructions, often used for DDoS attacks or spam relays, which generates constant network activity.

Exam trap

The trap here is that candidates may confuse 'botnet' with 'trojan' because both can be installed stealthily, but the question's emphasis on sustained network activity is the key differentiator for botnet behavior.

How to eliminate wrong answers

Option A is wrong because spyware primarily focuses on stealthily collecting personal information (e.g., keystrokes, browsing habits) and typically does not generate large volumes of outbound traffic unless exfiltrating data, which is not the primary symptom here. Option C is wrong because a virus requires a host file to attach to and usually spreads by infecting other files, not by placing a standalone executable in the startup folder; the high network traffic is more characteristic of C2 communication than viral replication. Option D is wrong because a Trojan disguises itself as legitimate software to trick users into installing it, but the key behavior of sustained, high-volume outbound traffic is a hallmark of botnet activity, not a typical Trojan payload.

446
MCQmedium

A user reports that their Android smartphone is running very slowly, the battery drains quickly, and they see frequent pop-up ads even when not using the browser. The user installed several apps from a third-party app store recently. Which of the following is the MOST likely cause of these symptoms?

A.The device needs a factory reset to clear cache.
B.The device has been infected with malware.
C.The device's storage is nearly full.
D.The battery is failing and needs replacement.
AnswerB

The combination of slow performance, battery drain, and pop-up ads outside the browser is classic malware behavior on Android. Third-party app stores are common sources of malicious apps. Malware can run background processes, display ads, and steal resources, causing these exact symptoms.

Why this answer

The symptoms of slow performance, battery drain, and pop-up ads appearing outside the browser are indicative of malware, especially adware. Installing apps from third-party stores increases the risk. While other issues like full storage or battery problems can cause some symptoms, they do not explain the ads.

Malware is the most likely cause.

Exam trap

The trap here is attributing all performance issues to hardware or storage when the presence of pop-up ads strongly suggests malware.

447
MCQeasy

A small business is upgrading its workstations and needs to dispose of 20 old hard drives that contain confidential payroll records. The company wants the lowest-cost method that ensures data cannot be recovered. Which disposal method should be recommended?

A.Use a degausser on each drive.
B.Perform a standard format on each drive.
C.Drill holes through the platters of each drive.
D.Reformat the drives and install a fresh OS.
AnswerC

Drilling holes directly through the platters of a hard disk drive causes irreversible physical damage to the magnetic surfaces where data is stored. This action physically destroys the integrity of the data tracks and sectors, rendering the data unreadable and unrecoverable by any means, including specialized forensic techniques. It is a highly effective and very low-cost method for secure data destruction, especially for a small business on a budget.

Why this answer

Drilling holes through the platters physically destroys the magnetic surfaces, making data recovery impossible without specialized cleanroom equipment. This is the lowest-cost method that guarantees destruction because it directly damages the storage medium beyond repair, unlike degaussing which may not work on modern SSDs or high-coercivity drives.

Exam trap

CompTIA A+ often tests the misconception that a standard format or OS reinstall permanently erases data, when in fact only a secure wipe (e.g., overwriting with zeros multiple times) or physical destruction ensures data is unrecoverable.

How to eliminate wrong answers

Option A is wrong because degaussers are expensive and may not effectively erase data from modern high-coercivity hard drives or SSDs, and they can damage the drive's electronics without guaranteeing complete data destruction. Option B is wrong because a standard format only removes the file system pointers, leaving the actual data intact on the platters, which can be easily recovered with data recovery software. Option D is wrong because reformatting and installing a fresh OS similarly only overwrites the file system metadata, not the underlying data, and does not prevent recovery using forensic tools.

448
MCQmedium

A customer reports that their browser shows a 'Your connection is not private' warning when visiting their online banking site, but other websites work fine. What is the most likely cause?

A.The user's system date and time are incorrect.
B.The bank's SSL certificate has expired or is misconfigured.
C.The user's browser is infected with a man-in-the-middle proxy.
D.The user's anti-virus is blocking the connection.
AnswerB

An expired or misconfigured certificate on the bank's server triggers a trust failure for that specific host, producing the browser warning. Other sites remain unaffected because their certificates still validate normally. This matches the stem's constraint: the fault is isolated to one site, not the browser or general connectivity.

Why this answer

The 'Your connection is not private' warning indicates a TLS/SSL certificate validation failure. Since only the banking site is affected, the issue is specific to that site's certificate, not a system-wide problem. The most common cause is that the bank's SSL certificate has expired, is self-signed, or does not match the domain name, triggering the browser's certificate trust check.

Exam trap

The CompTIA A+ exam often tests the distinction between a site-specific certificate issue (affecting one site) versus a client-side configuration problem (affecting all sites), leading candidates to incorrectly choose the date/time or proxy options.

How to eliminate wrong answers

Option A is wrong because an incorrect system date/time would cause certificate validation failures for all HTTPS sites, not just the banking site. Option C is wrong because a man-in-the-middle proxy would intercept all HTTPS traffic, causing warnings on multiple sites, not just one. Option D is wrong because anti-virus software typically blocks connections entirely or injects its own certificate, which would affect all HTTPS sites, not a single site.

449
MCQeasy

A technician is tasked with disposing of several old CRT monitors from a client's office. What is the correct disposal method for these monitors?

A.Place them in the regular office trash for pickup.
B.Sell them to a scrap metal dealer.
C.Take them to a certified e-waste recycling facility.
D.Disassemble them and recycle the plastic and metal separately.
AnswerC

Taking old CRT monitors to a certified e-waste recycling facility is the correct and legally compliant method for disposal. These facilities possess the specialized equipment, trained personnel, and regulatory permits required to safely de-manufacture CRTs. They meticulously separate hazardous materials, such as leaded glass, mercury-containing components, and other heavy metals, ensuring they are processed or disposed of in an environmentally sound manner, preventing contamination and promoting material recovery.

Why this answer

CRT monitors contain hazardous materials such as lead, phosphor, and other heavy metals that pose environmental and health risks. Certified e-waste recycling facilities are equipped to safely dismantle and process these components in compliance with environmental regulations like the EPA's Resource Conservation and Recovery Act (RCRA). Option C is the correct disposal method because it ensures legal and environmentally responsible handling of e-waste.

Exam trap

CompTIA often tests the misconception that disassembling e-waste for recycling is acceptable for a technician, but the trap is that without proper training and equipment, disassembly of CRTs is dangerous and non-compliant with safety procedures.

How to eliminate wrong answers

Option A is wrong because placing CRT monitors in regular office trash violates hazardous waste disposal laws and can lead to environmental contamination from lead and other toxins. Option B is wrong because scrap metal dealers typically lack the certification and equipment to safely handle hazardous CRT components, and selling them may result in illegal export or improper disposal. Option D is wrong because disassembling CRT monitors without proper training and equipment can expose the technician to high-voltage capacitors, implosion risks, and toxic dust, and it is not a recommended or compliant disposal method for individuals without specialized certification.

450
MCQhard

A technician is tasked with migrating a physical server running a legacy OS that does not support virtualization drivers. The technician needs to ensure the OS can boot and run in a virtual machine. Which of the following steps is most critical before performing the physical-to-virtual (P2V) conversion?

A.Increase the physical server's RAM before conversion
B.Ensure the legacy OS has the latest service pack installed
C.Use a P2V tool that can inject the correct HAL and storage drivers for the hypervisor
D.Create a full backup of the physical server
AnswerC

This is the critical step for a successful P2V migration, especially for legacy operating systems. A specialized P2V tool can inject the appropriate Hardware Abstraction Layer (HAL) and virtualized storage drivers directly into the captured disk image before the first boot on the hypervisor. This ensures the operating system can correctly identify and interact with the virtualized hardware components, such as the virtual disk controller, enabling it to boot successfully without encountering blue screens or boot device errors. Without these injected drivers, the OS would attempt to load drivers for the original physical hardware, leading to a boot failure.

Why this answer

Legacy operating systems that predate virtualization support lack the HAL (Hardware Abstraction Layer) and mass-storage drivers needed to boot on a hypervisor's virtual hardware. A P2V tool with driver-injection capability (such as VMware vCenter Converter or Microsoft Disk2vhd paired with offline driver injection) rewrites the HAL and installs the correct virtual SCSI/IDE/NIC drivers so the OS can start inside the VM. Without this step the converted image typically blue-screens with a STOP 0x0000007B INACCESSIBLE_BOOT_DEVICE error.

Exam trap

220-1202 often tests the misconception that a backup or OS patch is the 'most critical' pre-conversion step, when the exam is really probing whether you understand that legacy OSes need HAL and storage driver injection to boot on virtual hardware.

How to eliminate wrong answers

Option A is wrong because adding RAM to the source server does nothing to solve the missing virtual hardware drivers — the VM's virtual RAM is configured independently at conversion time. Option B is wrong because installing a service pack does not add hypervisor-aware HAL or storage drivers to a legacy OS; the abstraction layer must be replaced. Option D is wrong because a backup is a prudent safety measure but is not the critical technical step that makes the OS bootable in a VM — it protects data, not bootability.

Page 5

Page 6 of 10

Page 7

All pages

Practice 220-1202 by domain

Target a specific domain to shore up weak areas.

See all domains with question counts →