easyMultiple Choice
220-1201 Practice Question: That their computer's clock is consistently off…
A user reports that their computer's clock is consistently off by several minutes, causing authentication failures with the domain. The network uses Active Directory. Which service should be checked first?
⚠ Common exam trap
It's easy for candidates to confuse time synchronization with DHCP or DNS, assuming those services handle all network configuration, but NTP is the root cause for Kerberos authentication failures due to time skew.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
NTP
NTP (Network Time Protocol) is the correct service to check first because the symptom—a clock consistently off by several minutes causing authentication failures with an Active Directory domain—is a classic sign of time synchronization issues. Active Directory uses Kerberos for authentication, which requires the client and domain controller clocks to be within a default skew of 5 minutes (RFC 4120). If the time is off, Kerberos tickets are rejected, leading to authentication failures.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
DHCP
Why it's wrong here
DHCP supplies IP configuration, not time synchronisation; clock drift persists regardless of lease settings. It is tempting because DHCP options can carry NTP server addresses, so it would be the right place to check if clients were failing to receive any time source at all, rather than drifting from a working one.
- ✗
DNS
Why it's wrong here
DNS resolves names to addresses and has no role in setting system time, so it cannot cause consistent clock drift. It is tempting because DNS failures do cause domain authentication errors, making it the correct check when logons fail due to unresolvable domain controller names rather than Kerberos time skew.
- ✓
NTP
Why this is correct
Kerberos authentication in Active Directory rejects tickets when client and domain controller clocks drift beyond five minutes. Network Time Protocol synchronises the workstation clock to the domain hierarchy, so checking NTP first resolves the skew causing authentication failures.
- ✗
RADIUS
Why it's wrong here
RADIUS provides centralised authentication for network access, not workstation time, so it cannot explain a drifting clock. It is tempting because RADIUS also rejects authentication, making it the right service to inspect when VPN or Wi-Fi logons fail on credential grounds rather than Kerberos timestamp tolerance.
Go deeper
Related to this question
Learn chapter
Troubleshoot: USB Device Issues
Key term
Synchronization
Synchronization is the process of making sure two or more systems, devices, or pieces of data stay exactly matched and up-to-date with each other.
Key term
Precision Time Protocol
Precision Time Protocol is a network protocol used to synchronize clocks across devices with extremely high accuracy, often within microseconds or nanoseconds.
About these practice questions
Courseiva writes every 220-1201 question from scratch — 871 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 220-1201 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1201 exam.