Courseiva
easyMultiple Choice

220-1201 Practice Question: That their computer's clock is consistently off…

A user reports that their computer's clock is consistently off by several minutes, causing authentication failures with the domain. The network uses Active Directory. Which service should be checked first?

⚠ Common exam trap

It's easy for candidates to confuse time synchronization with DHCP or DNS, assuming those services handle all network configuration, but NTP is the root cause for Kerberos authentication failures due to time skew.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

NTP

NTP (Network Time Protocol) is the correct service to check first because the symptom—a clock consistently off by several minutes causing authentication failures with an Active Directory domain—is a classic sign of time synchronization issues. Active Directory uses Kerberos for authentication, which requires the client and domain controller clocks to be within a default skew of 5 minutes (RFC 4120). If the time is off, Kerberos tickets are rejected, leading to authentication failures.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    DHCP

    Why it's wrong here

    DHCP supplies IP configuration, not time synchronisation; clock drift persists regardless of lease settings. It is tempting because DHCP options can carry NTP server addresses, so it would be the right place to check if clients were failing to receive any time source at all, rather than drifting from a working one.

  • ✗

    DNS

    Why it's wrong here

    DNS resolves names to addresses and has no role in setting system time, so it cannot cause consistent clock drift. It is tempting because DNS failures do cause domain authentication errors, making it the correct check when logons fail due to unresolvable domain controller names rather than Kerberos time skew.

  • ✓

    NTP

    Why this is correct

    Kerberos authentication in Active Directory rejects tickets when client and domain controller clocks drift beyond five minutes. Network Time Protocol synchronises the workstation clock to the domain hierarchy, so checking NTP first resolves the skew causing authentication failures.

  • ✗

    RADIUS

    Why it's wrong here

    RADIUS provides centralised authentication for network access, not workstation time, so it cannot explain a drifting clock. It is tempting because RADIUS also rejects authentication, making it the right service to inspect when VPN or Wi-Fi logons fail on credential grounds rather than Kerberos timestamp tolerance.

About these practice questions

Courseiva writes every 220-1201 question from scratch — 871 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 220-1201 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1201 exam.