Courseiva
Software Troubleshooting →mediumMultiple Choice

220-1102 Software Troubleshooting Practice Question

A user reports that after a recent Windows Update, a business application crashes on startup. The technician has already run System File Checker (SFC) and DISM tools, which found no corruption. Which of the following tools should the technician use NEXT to help identify the cause of the crash?

⚠ Common exam trap

The trap here is that candidates often jump to Performance Monitor or Resource Monitor for 'performance' issues, but the question specifically asks about identifying the cause of a crash, which requires error logs, not real-time metrics.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Event Viewer

Event Viewer is the correct next step because it logs detailed application and system errors, including crash events with error codes, module names, and timestamps. Since SFC and DISM found no corruption, the crash likely stems from a compatibility or configuration issue triggered by the update, which Event Viewer's Application and System logs can pinpoint.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Event Viewer

    Why this is correct

    Event Viewer (eventvwr.msc) is the correct first stop because it logs application error events to the Windows Application log. A crash after a Windows update will typically produce an Event ID 1000 entry containing the faulting module filename, exception code (e.g., 0xc0000005, ACCESS_VIOLATION), and faulting module path. These details let you determine whether the update replaced a shared DLL or introduced an incompatibility, which is exactly the diagnostic evidence needed.

  • ✗

    Task Manager

    Why it's wrong here

    Task Manager (taskmgr.exe) shows only live process state—CPU, memory, disk, and network utilization—and the current status such as "Running" or "Not Responding." It has no persistent log of past application faults, so once the crashing process terminates, the diagnostic details are lost. It cannot reveal the exception code, faulting module, or the stack trace that Event Viewer records.

  • ✗

    Resource Monitor

    Why it's wrong here

    Resource Monitor (resmon.exe) is a real-time troubleshooting tool that drills into per-process CPU, memory, disk, and network activity, and can display open handles and loaded modules. While it could show a crash candidate's spike in handle count or memory bytes just before it dies, it captures no history and never logs the error event. It lacks any event-driven record of why a process failed.

  • ✗

    Performance Monitor

    Why it's wrong here

    Performance Monitor (perfmon.exe) tracks performance counters—like % Processor Time, Available Memory, or specific application counters—over time, and Data Collector Sets can persist this baseline data for later review. However, it measures system health and resource trends; it does not subscribe to the Windows Event Log for application errors, so it cannot report a crash's faulting module or exception code. It is used for bottleneck analysis, not fault diagnosis.

About these practice questions

This 220-1102 question is part of Courseiva's 925-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.