220-1102 Operating Systems Practice Question
A user's MacBook Pro running macOS Ventura is experiencing random freezes. The technician has already booted into Safe Mode and the issue still occurs. The technician suspects a faulty third-party kernel extension. Which built-in macOS tool should the technician use to view kernel panic logs and identify the problematic extension?
⚠ Common exam trap
Test-takers frequently confuse Console with Activity Monitor, assuming real-time monitoring can diagnose historical crashes, but Console is the dedicated log viewer for both system and kernel logs.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Console
Console is the correct tool because it aggregates all system logs, including kernel panic logs, which are stored under /Library/Logs/DiagnosticReports. By filtering for 'panic' in Console, the technician can view the panic string and identify the faulty third-party kernel extension (kext) by its bundle identifier or module name.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Activity Monitor
Why it's wrong here
Activity Monitor is a live system resource monitor that displays real-time metrics for CPU, memory, energy, disk I/O, and network activity for every running process. It does not provide a persistent, searchable history of system events, nor does it surface kernel panic reports. Panics are recorded to the unified log and diagnostic reports, which Activity Monitor cannot access, so it could not help identify a faulty kernel extension. For that, you need a log viewer.
- ✓
Console
Why this is correct
Console is the correct tool because it aggregates logs from the macOS unified logging system, including kernel diagnostics and crash reports from `/Library/Logs/DiagnosticReports`. In Ventura, you can filter for panic reports either by browsing the Diagnostic Reports section or by using the search predicate to locate kernel panic entries in the unified log. Reading these logs often reveals the offending kernel extension (.kext) or driver causing the restarts. Therefore, Console directly points to the cause of the problem.
- ✗
System Information
Why it's wrong here
System Information (formerly system_profiler) is an inventory utility that reports static hardware and software configuration, such as GPU model, installed RAM, serial number, and OS build version. It does not capture runtime logs or historical crash/panic records, because its database is a snapshot of the current configuration, not an event timeline. While it can show installed kexts and their versions, it cannot tell you which one panicked or when, making it unsuitable for diagnosing the cause of recurring restarts.
- ✗
Disk Utility
Why it's wrong here
Disk Utility performs scans and repairs on the filesystem, handles partitioning, and runs First Aid to verify and fix disk volume structures. It does not read or display the unified system log, and it does not interpret panic reports, which live in the diagnostic log store. A kernel panic caused by a faulty extension is unrelated to filesystem corruptions that Disk Utility might repair; thus, even if the disk is fine, Disk Utility yields no information about the kernel extension at fault.
Go deeper
Related to this question
Learn chapter
User Account Control (UAC)
Key term
macOS
macOS is the operating system that powers Apple's Mac computers, providing a graphical interface, system management, and security features for users and IT professionals.
Key term
Safe Mode
Safe Mode is a diagnostic startup mode in operating systems that loads only essential drivers and services, allowing users to troubleshoot and fix problems caused by non-critical software or hardware.
About these practice questions
Courseiva writes every 220-1102 question from scratch — 925 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.