220-1102 Software Troubleshooting Practice Question
A user reports that after a Windows Update, a line-of-business application crashes on startup. The technician has verified that the application was working before the update and that no other changes were made. Which built-in Windows tool should the technician use to identify the specific error or fault causing the crash?
⚠ Common exam trap
Test-takers frequently choose Event Viewer (B) because they know it logs errors, but they overlook that Reliability Monitor (C) is the built-in tool specifically designed to present a user-friendly, timeline-based view of application crashes and their relationship to system changes like Windows Updates.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Reliability Monitor
Reliability Monitor (C) is the correct tool because it provides a timeline of system stability, including application crashes, Windows Update events, and specific error codes. It aggregates data from Event Viewer into an easy-to-read graph, allowing the technician to quickly correlate the crash with the update and view the faulting module or exception code. This makes it ideal for diagnosing a post-update application crash without manually filtering through hundreds of Event Viewer logs.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Task Manager
Why it's wrong here
Task Manager displays currently running applications, background processes, CPU/memory/disk utilization, and network activity in real time. It is not a diagnostic log viewer: it has no record of historical crashes, no faulting module details, and no event data. While it can show an application as 'Not responding' or allow you to end the process, it cannot help you determine why the line-of-business app crashed after a Windows Update.
- ✗
Event Viewer
Why it's wrong here
Event Viewer records application crashes, making it a tempting initial step to confirm an issue or identify general system errors. However, while it logs that an application crashed, it often provides only a generic error code or faulting module, not the specific diagnostic detail required to pinpoint the root cause of the crash in relation to a Windows Update, such as API conflicts or dependency issues. It is excellent for confirming an event or identifying service failures, but not for deep application-level fault analysis.
- ✓
Reliability Monitor
Why this is correct
Reliability Monitor is the correct choice because it is purpose-built to show a stable, time-based stability index along with application failures, Windows Update events, and other significant system events. It presents the crash date, the problematic software, and a faulting module or exception code in a user-friendly timeline, making it ideal for connecting an update's installation to an app's sudden crash behavior. Unlike Event Viewer, it organizes related reliability events visually, so the correlation between the update and the app crash stands out immediately.
- ✗
Performance Monitor
Why it's wrong here
Performance Monitor collects real-time and logged performance data using counters such as CPU time, memory pages/sec, disk queue length, and process-specific metrics. It can monitor resource usage trends or trigger alerts when a counter threshold is exceeded, but it does not capture application crash events, error codes, or faulting modules. Therefore, it would not reveal why the application crashed or whether a Windows Update introduced a conflict; it only helps analyze system load and resource behavior after the fact.
Go deeper
Related to this question
Learn chapter
Troubleshoot: Application Crashes and Hangs
Key term
Windows
Windows is a family of operating systems developed by Microsoft that manages computer hardware and software, providing a graphical user interface for users to interact with their devices.
Key term
Event
An event is any identifiable occurrence or action in a computer system, network, or application that can be logged, monitored, or analyzed for security or operational purposes.
About these practice questions
One of 925 original 220-1102 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.