220-1102 Software Troubleshooting Practice Question
A user reports that a specific application crashes on Windows 10 with error '0xc0000005 (Access Violation)'. The technician has already updated the application and graphics drivers, tested memory with Windows Memory Diagnostic, and performed a clean boot to isolate software conflicts. The error still occurs. Which of the following should the technician do NEXT?
⚠ Common exam trap
The trap here is that candidates often jump to SFC or reinstallation as generic troubleshooting steps, failing to recognize that 0xc0000005 is a memory access violation specifically tied to DEP or memory protection settings, not general corruption or missing files.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
C) Configure Data Execution Prevention (DEP) to add an exception for the application.
Error 0xc0000005 (Access Violation) often indicates that Data Execution Prevention (DEP) is blocking the application from executing code in a memory region marked as non-executable. Since the technician has already updated drivers, tested memory, and performed a clean boot without resolving the issue, adding a DEP exception for the application is the logical next step to allow the application to run while maintaining system protection.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
A) Run System File Checker (SFC) to check for system file corruption.
Why it's wrong here
SFC scans for and repairs corrupted or missing Windows system files, but the crash is isolated to a single application, and there's no indication of system-level file corruption. An Access Violation triggered by DEP originates from a security policy that blocks execution from a non-executable memory page, not from a corrupted kernel component. Running SFC would not alter DEP's exception list, so even if it completes successfully, the application would still be blocked. It's a reasonable diagnostic step only after a targeted solution like a DEP exception fails.
- ✗
B) Reinstall the application.
Why it's wrong here
Reinstalling the application replaces its program files and resets local settings, but it does not change how Windows' DEP treats the executable. Since you already updated to the latest version, a reinstall would simply reapply the same binaries, and the same DEP check would still fail with an Access Violation. The real issue is the security policy configuration at the operating system level, which requires adding an exception for the application in the Data Execution Prevention tab. Without that configuration change, a fresh installation will encounter the identical crash.
- ✓
C) Configure Data Execution Prevention (DEP) to add an exception for the application.
Why this is correct
DEP (Data Execution Prevention) marks certain memory regions as non-executable to prevent malware from running code in data areas, but legitimate applications sometimes attempt to execute code in these regions, causing an Access Violation (0xC0000005). By adding the application to the DEP exception list in System Properties (or via Set-ProcessMitigation), you permit that specific executable to bypass the enforcement while keeping DEP active for all other programs. This is the correct targeted fix because the problem is application-specific and the diagnostic path has already ruled out other common causes such as file corruption or outdated software. The exception is stored per executable, so it persists across reboots and does not disable system-wide DEP protections.
- ✗
D) Update the BIOS/UEFI firmware.
Why it's wrong here
A BIOS/UEFI update can resolve hardware compatibility issues, microcode bugs, or missing firmware features, but it does not directly alter Windows' DEP policy. On modern systems, the CPU's NX bit is already enabled by default, and an Access Violation for one application is almost always a software-configuration issue, not a firmware deficiency. Updating firmware carries a risk of bricking the board and should only be considered when the system exhibits broader hardware or boot-related symptoms. For a single application crash, configuring a DEP exception is the safer and more logical next step.
Visual reference
Go deeper
Related to this question
Learn chapter
Data Destruction and Disposal
Key term
Region
A region is a distinct geographic location where a cloud provider operates multiple data centers that are connected by low-latency networks and provide cloud services.
Key term
Windows
Windows is a family of operating systems developed by Microsoft that manages computer hardware and software, providing a graphical user interface for users to interact with their devices.
About these practice questions
This 220-1102 question is part of Courseiva's 925-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.