Courseiva
← Back to CompTIA A+ Core 2 220-1202 questions

Scenario-based practice

Hard Difficulty Questions

Practise CompTIA A+ Core 2 220-1202 practice questions — original exam-style scenarios covering every exam domain, with detailed explanations, wrong-answer analysis, and common exam traps.

20
scenario questions
220-1202
exam code
CompTIA
vendor

Scenario guide

How to approach hard difficulty questions

These are the questions most candidates get wrong. They require connecting multiple concepts, reading tricky output, or knowing edge-case behaviour that isn't on most study cards. Practising them trains you to operate under uncertainty — a necessary skill on the real exam.

Quick answer

Hard Difficulty Questions questions test whether you can apply the concept in context, not just recognise a definition.

How the topic appears in realistic exam-style scenarios.

Which detail in the question changes the correct answer.

How to eliminate plausible but wrong options.

How to connect the question back to the wider exam objective.

Related practice questions

Related 220-1202 topic practice pages

Scenario questions usually connect to one or more exam topics. Use these links to review the underlying concepts behind the scenario.

Practice set

Practice scenarios

Question 1hardmultiple choice
Read the full wireless explanation →

A technician is troubleshooting a wireless network where users report intermittent connectivity. The network uses WPA2-Enterprise with a RADIUS server. The technician notices that the RADIUS server logs show frequent authentication failures from one specific access point. What is the most likely cause?

Question 2hardmultiple choice
Full question →

A company is designing a secure entry for a high-security lab. They need to ensure that only one person can enter at a time and that the person must be authenticated before the second door opens. Which physical security control should be used?

Question 3hardmultiple choice
Full question →

A technician needs to deploy a script to 100 Windows 10 computers that will change the local administrator password. The script must run with elevated privileges and not leave the password visible in the script file. Which approach is most secure?

Question 4hardmultiple choice
Full question →

A security incident occurred on a Windows 10 workstation where an attacker gained administrative access and created several hidden user accounts. You need to ensure no unauthorized accounts exist and that the built-in Administrator account is disabled. Which two tools can you use from the command line to list all user accounts and check the status of the Administrator account?

Question 5hardmultiple choice
Read the full VPN explanation →

A company is experiencing a security incident where an attacker gained access to the internal network via a compromised VPN account. The technician must prevent future attacks. Which two-factor authentication method should the technician implement for VPN access?

Question 6hardmultiple choice
Full question →

A user reports that their Windows 10 PC is infected with malware that keeps reinstalling after removal. You need to boot into a minimal environment to run antivirus scans without malware interference. Which advanced startup option should you use?

Question 7hardmultiple choice
Full question →

A data center manager wants to implement a physical security control that can detect if a server chassis has been opened without authorization. Which control should they use?

Question 8hardmultiple choice
Full question →

A technician is performing a routine software update on a finance department server. The change management documentation specifies that the update must be applied during a maintenance window from 2:00 AM to 4:00 AM. At 3:30 AM, the update fails with an error. The technician has no rollback plan documented. What should the technician do?

Question 9hardmultiple choice
Full question →

A company is decommissioning a data center and must destroy 1000 HDDs and 200 SSDs. The policy mandates that all data be destroyed on-site and that the drives be rendered physically unusable. Which combination of methods is most efficient?

Question 10hardmultiple choice
Full question →

A user's Windows 10 laptop is experiencing random restarts, especially under heavy load like gaming or video rendering. The Event Viewer shows multiple 'Kernel-Power 41' critical errors. The CPU temperature is normal, and the power supply is functioning. Which component is most likely causing the issue?

Question 11hardmultiple choice
Full question →

A system administrator needs to change the group ownership of a directory /srv/data and all its contents to 'datagroup'. Which command will accomplish this recursively?

Question 12hardmultiple choice
Full question →

A Windows 11 workstation is infected with ransomware that encrypted user files. The IT security team wants to prevent future infections by restricting which processes can modify files in user profile folders. Which Windows security feature can enforce such restrictions without third-party software?

Question 13hardmultiple choice
Read the full wireless explanation →

A security incident occurs where an attacker captures the 4-way handshake of a WPA2-PSK network and successfully cracks the passphrase offline. The technician is tasked with preventing this type of attack in the future. Which protocol should the technician implement?

Question 14hardmultiple choice
Read the full wireless explanation →

A user's iPhone is running iOS 16 and they cannot update to the latest iOS 17 because the 'Software Update' section in Settings shows 'Unable to Check for Update'. The device is connected to Wi-Fi and has sufficient storage. Which advanced troubleshooting step should you take to resolve this update issue?

Question 15hardmultiple choice
Full question →

During a network upgrade, a technician finds a box of old NICs, cables, and small electronic components that are no longer needed. The company has no formal e-waste policy. What should the technician do?

Question 16hardmulti select
Full question →

A security incident occurred when an employee disposed of a hard drive by throwing it in the trash. The hard drive contained unencrypted customer data. Which two practices should have been followed to prevent this environmental and security breach? (Choose two.)

Question 17hardmultiple choice
Full question →

A technician is installing a new UPS (Uninterruptible Power Supply) in a server rack. The UPS is heavy and must be mounted securely. What is the most important safety consideration during installation?

Question 18hardmultiple choice
Full question →

A user reports that their iPhone's flashlight is not working, and the camera app shows a black screen. Other apps function normally. The device is up-to-date and has been restarted. What is the most likely hardware-related issue?

Question 19hardmultiple choice
Full question →

A technician is preparing to deploy a security patch to 50 workstations. The change request has been approved, and the patch has been tested on a pilot group. During the deployment, five workstations fail to install the patch. What should the technician do next according to change management best practices?

Question 20hardmultiple choice
Full question →

During a security audit, a technician finds that a user's workstation was infected with malware after the user inserted a USB drive found in the parking lot. The drive was labeled 'Employee Salary Info Q4'. What social engineering principle did the attacker exploit?

These 220-1202 practice questions are part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style 220-1202 questions with detailed explanations, topic-based practice, mock exams, readiness tracking, and study analytics.