220-1102 Software Troubleshooting Practice Question
A user reports that a legacy application crashes on Windows 10 with an access violation error (exception code 0xc0000005). The application worked on Windows 7. Event Viewer shows DEP (Data Execution Prevention) related events. What is the most likely cause?
⚠ Common exam trap
A common mix-up: candidates confuse the access violation error (0xc0000005) with a generic 'application crash' and incorrectly attribute it to file corruption or permissions, rather than recognizing the specific DEP-related Event Viewer entries as the key diagnostic clue.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
DEP is blocking the application from executing code in marked memory regions.
The access violation error (0xc0000005) combined with DEP-related events in Event Viewer directly indicates that Data Execution Prevention (DEP) is terminating the application. DEP marks certain memory regions as non-executable, and if the legacy application attempts to execute code from such a region (common with older software that uses techniques like self-modifying code or just-in-time compilation), Windows 10's DEP enforcement causes the crash. This is a known compatibility issue when moving from Windows 7 to Windows 10, as DEP is more strictly enforced in newer OS versions.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The application is incompatible with Windows 10's 64-bit architecture.
Why it's wrong here
Windows 10 64-bit runs 32-bit applications seamlessly through its WOW64 compatibility layer, so a legacy 32-bit app would not crash solely because of the OS architecture. If bitness incompatibility were to blame, the failure would typically occur at process startup as a "not a valid Win32 application" error or a missing 16-bit subsystem, not as a runtime access violation. The Event Viewer entry referencing DEP confirms the crash is a memory-protection violation, not a bitness mismatch.
- ✓
DEP is blocking the application from executing code in marked memory regions.
Why this is correct
DEP (Data Execution Prevention) enforces hardware-based NX (No-eXecute) protections by marking memory pages as non-executable unless they are explicitly flagged for code execution. When a legacy application attempts to execute instructions from a data page, such as the stack or heap, Windows raises an access-violation exception and terminates the process. The Event Viewer log showing a DEP exception (typically Event ID 1000 or 1001) directly identifies this protection mechanism as the root cause. Therefore, the crash occurs because DEP blocks execution from a marked memory region, not because of a path, permission, or file-integrity issue.
- ✗
The application's system files are corrupted.
Why it's wrong here
Corrupted system files typically manifest as missing DLL errors, startup failures, or broader Windows component faults rather than an isolated access violation in one legacy application. While a corrupted dependency might crash a program, the Event Viewer record of a DEP-generated exception (STATUS_ACCESS_VIOLATION / 0xC0000005) is produced by the memory manager at runtime, not by damaged data read from disk. Running `sfc /scannow` or reinstalling the application would not alter DEP policy, so file corruption does not explain why the crash is specifically caused by a non-executable memory page fault.
- ✗
The user does not have administrator privileges.
Why it's wrong here
DEP policies are enforced system-wide by the CPU and kernel, applying identically to all users who launch the application, regardless of whether they hold administrator privileges. A lack of administrator rights could prevent installation or modification of DEP settings, but it would not cause a runtime access violation in an already-installed program, because executable-page validation happens at the process level. Since DEP is a hardware/software memory-protection mechanism, UAC elevation or granting admin rights would not change which pages are marked executable, so insufficient privileges cannot be the cause of this DEP-specific crash.
Go deeper
Related to this question
Learn chapter
User Privacy Considerations
Key term
Windows
Windows is a family of operating systems developed by Microsoft that manages computer hardware and software, providing a graphical user interface for users to interact with their devices.
Key term
Event
An event is any identifiable occurrence or action in a computer system, network, or application that can be logged, monitored, or analyzed for security or operational purposes.
About these practice questions
Courseiva writes every 220-1102 question from scratch — 925 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.