Courseiva

CCNA Operational Procedures Questions

8 questions · Operational Procedures topic · All types, answers revealed

1
Multi-Selecthard

A technician is preparing to replace a failed hard drive in a user's desktop PC. The drive contains sensitive company data. The technician wants to ensure proper disposal of the old drive and maintain data security. Which of the following TWO actions should the technician take? (Choose two.)

Select 2 answers
A.Use a software tool to perform a secure erase or wipe.
B.Run a standard format on the drive before disposal.
C.Delete all partitions and recreate a single empty partition.
D.Physically destroy the drive by shredding or degaussing.
E.Store the drive in a secure cabinet until it can be reused.
AnswersA, D

A secure erase or wipe overwrites the entire drive with random data, making recovery extremely difficult. This is a valid method for sanitizing storage media before disposal or reuse. It complies with data security policies and is appropriate when physical destruction is not feasible. The technician should verify the wipe completed successfully.

Why this answer

The correct actions are to physically destroy the drive or use a software tool to perform a secure erase/wipe. Both methods ensure that sensitive data cannot be recovered. Standard format, partition deletion, or storage alone do not provide adequate data sanitization.

These steps align with data security best practices for storage media disposal.

Exam trap

The trap here is assuming that deleting partitions or performing a standard format is sufficient to protect data, when in fact those methods leave recoverable data on the drive.

2
MCQeasy

A user calls the help desk stating that their laptop screen is cracked and they need it replaced. The company policy requires that all hardware repairs be performed by the IT department. The user is remote and cannot come to the office. Which of the following should the technician do FIRST?

A.Instruct the user to purchase a replacement screen online and install it themselves.
B.Remote into the laptop and run diagnostics to confirm the screen is cracked.
C.Create a ticket, document the damage, and arrange for a depot repair or onsite service.
D.Ship the user a replacement laptop and have them return the damaged one.
AnswerC

Following standard operating procedures, the technician should first create a ticket to document the issue, then arrange for repair according to company policy. Since the user is remote, a depot repair or authorized onsite service is appropriate. This ensures accountability and proper asset tracking. It also aligns with the requirement that IT performs all hardware repairs.

Why this answer

The first action is to create a ticket, document the damage, and arrange for repair via depot or onsite service. This complies with company policy, ensures proper asset tracking, and addresses the remote user's needs. Other options either bypass policy, delay the process, or fail to follow standard operating procedures.

Proper documentation and authorized repair channels are essential.

Exam trap

The trap here is focusing on the physical repair or replacement immediately, while overlooking the required first step of documenting the issue and following the organization's incident management process.

3
MCQmedium

A technician is troubleshooting a Windows 10 workstation that is running very slowly. The technician suspects a malware infection. Which of the following should the technician do FIRST according to best practices for malware removal?

A.Quarantine the system by disconnecting it from the network.
B.Restore the system from a known good backup.
C.Educate the end user about safe browsing habits.
D.Run a full antivirus scan immediately.
AnswerA

Disconnecting the system from the network prevents the malware from spreading or communicating with command-and-control servers. This is the first step in the malware removal process to contain the infection. It also preserves evidence and prevents further damage while the technician investigates. Quarantining is a critical initial action before attempting removal.

Why this answer

The first step in malware removal is to quarantine the infected system by disconnecting it from the network. This prevents the malware from spreading to other systems and stops any remote communication. Only after isolation should the technician proceed with scanning, removal, and recovery.

Educating the user and restoring from backup are subsequent steps.

Exam trap

The trap here is jumping straight to scanning or restoring, but containment must come first to prevent the malware from spreading.

4
Multi-Selectmedium

A technician is preparing to replace a faulty power supply in a desktop computer. Which of the following safety precautions should the technician take? (Choose two.)

Select 2 answers
A.Disconnect the power cord from the wall outlet before opening the case.
B.Leave the power cord connected but turn off the power supply switch.
C.Wear an antistatic wrist strap connected to a grounded surface.
D.Use a magnetic screwdriver to retrieve screws from inside the power supply.
E.Work on a carpeted floor to cushion the components.
AnswersA, C

Disconnecting the power cord removes the risk of electric shock and prevents the system from powering on accidentally. It is a fundamental safety step before working inside any computer. This precaution also allows the power supply to discharge residual power, reducing the chance of damage to components.

Why this answer

Disconnecting the power cord and wearing an antistatic wrist strap are essential safety precautions when working inside a computer. These steps prevent electric shock and electrostatic discharge, protecting both the technician and the components. The other options introduce risks such as magnetic interference, electrical hazards, or static buildup.

Exam trap

The trap here is thinking that turning off the power supply switch is sufficient, but the cord must be unplugged to ensure no power is present.

5
MCQmedium

A company is implementing a new policy that requires all employee laptops to have full-disk encryption enabled. A technician is asked to verify compliance on a Windows 11 Pro laptop. Which of the following tools should the technician use to check the encryption status?

A.Device Manager
B.Disk Management console
C.Task Manager
D.BitLocker Drive Encryption Control Panel applet
AnswerD

The BitLocker Drive Encryption Control Panel applet provides a straightforward interface to view the encryption status of each drive. It shows whether BitLocker is on or off, and the encryption method used. This is the correct tool for quickly verifying compliance with the full-disk encryption policy on a Windows 11 Pro system.

Why this answer

The BitLocker Drive Encryption Control Panel applet is the correct tool to check encryption status. It provides a clear indication of whether BitLocker is enabled and the encryption progress. Other tools like Device Manager, Disk Management, and Task Manager do not offer this specific information.

Using the correct tool ensures accurate compliance verification.

Exam trap

The trap here is confusing disk management tools with encryption status tools; only the BitLocker applet directly shows encryption state.

6
MCQeasy

A technician is called to a user's desk where the user has left a sticky note with their password taped to the monitor. The technician needs to document this in the ticket. Which of the following should the technician do FIRST?

A.Report the security violation according to the organization's incident response policy.
B.Ignore it because it is the user's personal workspace and not the technician's concern.
C.Remove the sticky note and discard it, then close the ticket as resolved.
D.Take a photo of the sticky note and post it in the team chat as a joke.
AnswerA

Leaving a password visible is a security violation that must be reported through the proper incident response channel. This ensures the organization can investigate, educate the user, and enforce policies. Documenting and reporting is the first step before taking any corrective action that might destroy evidence or overstep the technician's authority.

Why this answer

The correct action is to report the security violation according to policy. Passwords left in plain sight are a serious security risk that must be escalated through proper channels. This allows the organization to handle the situation consistently, educate the user, and prevent similar incidents.

Taking direct action like removing the note or sharing it could interfere with investigations or violate privacy.

Exam trap

The trap here is assuming the technician should immediately remove the note or handle it informally, rather than following the formal incident reporting procedure.

7
Multi-Selecthard

A technician is preparing to dispose of several old hard drives that contain sensitive company data. The organization's data destruction policy requires physical destruction. Which of the following methods are appropriate for physically destroying the drives? (Choose two.)

Select 2 answers
A.Incineration
B.Shredding
C.Low-level formatting
D.Overwriting
E.Degaussing
AnswersA, B

Incineration burns the drive at high temperatures, completely destroying the media and any data. This is a form of physical destruction that ensures no recoverable data remains. It must be performed in a controlled environment that meets environmental regulations. For organizations with strict data destruction policies, incineration is an appropriate method.

Why this answer

Shredding and incineration are both physical destruction methods that render the drive unusable and data unrecoverable. Degaussing, overwriting, and low-level formatting are logical or magnetic erasure methods that do not physically destroy the media. Therefore, only shredding and incineration satisfy the policy requirement for physical destruction.

Exam trap

The trap here is equating data erasure methods like degaussing or overwriting with physical destruction, which the policy specifically demands.

8
MCQeasy

A user reports that their Windows 10 laptop is running very slowly and the hard drive light is constantly active. The technician suspects a malware infection. Which of the following should the technician perform FIRST according to best practices?

A.Restart the laptop in Safe Mode with Networking.
B.Disconnect the laptop from the network.
C.Run a full antivirus scan on the laptop.
D.Use System Restore to revert to a previous restore point.
AnswerB

Disconnecting from the network immediately contains the potential infection, preventing malware from spreading to other systems or communicating with command-and-control servers. This is the first step in the incident response process for a suspected malware infection. It also preserves evidence for later analysis.

Why this answer

The first step in malware incident response is containment, which means disconnecting the device from the network to prevent the malware from spreading or communicating externally. Running scans, restarting in Safe Mode, or using System Restore are remediation steps that should follow containment. Isolation also preserves evidence for analysis.

Exam trap

The trap here is jumping to remediation like running a scan or using System Restore before isolating the system, which can allow malware to spread.

Ready to test yourself?

Try a timed practice session using only Operational Procedures questions.