220-1102 Software Troubleshooting Practice Question
A user reports that a legacy application crashes on Windows 10. Event Viewer shows Event ID 1000 with faulting module 'ntdll.dll'. What should the technician do FIRST to identify potential system file corruption?
⚠ Common exam trap
Watch out — candidates often confuse disk-level errors (checked by chkdsk) with system file corruption (checked by sfc), leading them to choose chkdsk /f when the faulting module points to a Windows DLL issue.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Run sfc /scannow from an elevated command prompt.
Event ID 1000 with faulting module 'ntdll.dll' often indicates system file corruption or a mismatch in critical Windows components. Running sfc /scannow from an elevated command prompt is the appropriate first step because it scans and repairs protected system files, including ntdll.dll, without requiring a reboot or affecting user data.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Run sfc /scannow from an elevated command prompt.
Why this is correct
Running sfc /scannow from an elevated command prompt verifies the integrity of all protected system files and automatically replaces any corrupted or missing versions using cached copies from the Windows component store. When an application crashes with Event ID 1000 and a faulting module of ntdll.dll, this strongly indicates system file corruption rather than a pure application bug, making SFC the most appropriate immediate diagnostic step. Because SFC is fast, non-destructive, and built into Windows, it should be the first thing you try before escalating to image-level repairs.
- ✗
Run chkdsk /f to check the hard drive for errors.
Why it's wrong here
Running chkdsk /f checks the file system structure and scans for bad sectors on the hard drive, but it does not repair corrupted system files within the Windows directory. While disk errors can certainly cause application crashes, a crash specifically mentioning ntdll.dll as the faulting module points to memory-management code inside Windows itself, not to storage problems. Moreover, chkdsk can take a long time on large drives and may require a reboot, so it should not be the first choice when the event log already suggests system file corruption.
- ✗
Run DISM /Online /Cleanup-Image /RestoreHealth.
Why it's wrong here
Running DISM /Online /Cleanup-Image /RestoreHealth repairs the Windows system image itself by pulling fresh files from Windows Update or a specified source, which is more invasive and slower than SFC. DISM is typically used when SFC cannot repair a file because the component store itself is damaged, or when SFC repeatedly fails. Since the question describes a legacy app crashing with ntdll.dll, SFC is quicker and usually sufficient to replace the corrupted system file without needing to rebuild the entire image, so DISM should be reserved as a follow-up if SFC fails.
- ✗
Run Windows Memory Diagnostic to test RAM.
Why it's wrong here
Windows Memory Diagnostic performs a low-level test of physical RAM to detect hardware faults like bad memory cells or timing errors, but the crash signature shown in Event Viewer—ntdll.dll as the faulting module—is far more indicative of corrupted system software than faulty hardware. Memory issues can manifest as random crashes, but they typically do not consistently point to the same system DLL across multiple events. Additionally, a full memory test can take several hours and interrupts normal work, making it a poor first step when SFC directly addresses the most likely software cause and is non-invasive.
Go deeper
Related to this question
Learn chapter
Data Classification Levels
Key term
Event
An event is any identifiable occurrence or action in a computer system, network, or application that can be logged, monitored, or analyzed for security or operational purposes.
Key term
Event Viewer
Event Viewer is a built-in Windows tool that logs system, security, and application events to help administrators monitor and troubleshoot issues.
About these practice questions
Courseiva writes every 220-1102 question from scratch — 925 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.