Courseiva

CompTIA A+ Core 2 220-1202 (220-1202) — Questions 76–150

687 questions total · 10pages · All types, answers revealed

Page 1

Page 2 of 10

Page 3
76
MCQeasy

During a security audit, you find that a company's server room door is propped open with a trash can to allow airflow. What is the most immediate physical security risk in this scenario?

A.Increased dust entering the server room
B.Fire suppression system may not work
C.Unauthorized personnel can enter the server room
D.The door closer will wear out faster
AnswerC

Propping the door defeats the access-control boundary, so anyone walking past can physically reach servers without authentication. The immediate risk is unauthorised entry, enabling theft, tampering or console access; airflow concerns are secondary and should be solved by cooling, not by leaving the perimeter open.

Why this answer

The most immediate physical security risk of a propped-open server room door is that it completely bypasses access control mechanisms (e.g., badge readers, PIN pads, biometric scanners). This allows any unauthorized person—whether an employee without clearance, a visitor, or an intruder—to enter the server room undetected, potentially leading to theft, vandalism, or data breaches. Physical security controls are the first line of defense, and an open door nullifies them instantly.

Exam trap

This question tests the ability to prioritize immediate security risks over environmental or maintenance issues; the trap is choosing a plausible but less critical concern (like dust or fire suppression) instead of the direct breach of physical access control.

How to eliminate wrong answers

Option A is wrong because while increased dust can be a concern for equipment longevity, it is not the most immediate security risk; dust accumulation is a gradual environmental issue, not an instant security breach. Option B is wrong because a propped-open door does not directly affect the fire suppression system (e.g., FM-200 or inert gas systems) unless the door is part of the room's containment strategy, but the immediate risk is still unauthorized access, not suppression failure. Option D is wrong because door closer wear is a maintenance concern, not a security risk; it is a long-term mechanical issue that does not pose an immediate threat to assets or data.

77
MCQhard

A company's security policy requires that all USB storage devices be blocked on company workstations to prevent data exfiltration. A manager needs to temporarily use a USB drive for a presentation. What is the best way to remediate this while maintaining security?

A.Disable the USB blocking Group Policy for the entire domain
B.Use a Group Policy to allow only the specific USB device by hardware ID, then remove the allowance after use
C.Give the manager a company-approved USB drive and tell them to use it only once
D.Create a local admin account on the manager's workstation and disable the USB block locally
AnswerB

Group Policy can target a device by its hardware ID, so the block remains enforced for all other USB storage while the manager's specific drive is permitted. Removing the allowance afterwards restores the original security posture, satisfying both the temporary need and the exfiltration policy.

Why this answer

It uses Group Policy to enforce a device installation restriction by hardware ID, allowing only the specific USB device while blocking all others. This maintains the security policy's intent by preventing unauthorized devices while granting temporary, auditable access. After use, removing the allowance restores the full block without domain-wide disruption.

Exam trap

The trap here is that candidates may choose Option A or D because they think disabling the block domain-wide or using a local admin account is simpler, but CompTIA A+ tests the principle of least privilege and maintaining centralized security controls through Group Policy.

How to eliminate wrong answers

Option A is wrong because disabling the USB blocking Group Policy for the entire domain removes protection from all workstations, violating the security policy and exposing the organization to data exfiltration. Option C is wrong because giving a company-approved USB drive without technical controls does not enforce the block; the manager could still use other USB devices, and the policy relies on user compliance rather than technical enforcement. Option D is wrong because creating a local admin account bypasses Group Policy and weakens security by allowing the manager to disable the block locally, which could be exploited or persist after use.

78
MCQeasy

A user reports that their Android phone will not connect to their corporate Wi-Fi network, but other devices connect fine. They have forgotten the network and re-entered the password, but it still fails. What should you check first?

A.Check if the router is using MAC address filtering.
B.Verify the Wi-Fi password is being entered correctly.
C.Reset the phone's network settings to default.
D.Update the phone's operating system to the latest version.
AnswerB

Incorrectly entering the Wi-Fi password is the most frequent cause of connection failures for wireless devices. Wireless networks, especially those secured with WPA2/WPA3-Personal, rely on a pre-shared key (PSK) for authentication. A single typo, incorrect capitalization, or an extra space will result in an authentication failure, preventing the Android phone from associating with the access point and obtaining an IP address. This simple verification should always be the initial troubleshooting step before investigating more complex network or device-specific issues.

Why this answer

The most common cause of a single device failing to connect after forgetting and re-entering the network is a typo or case-sensitive error in the Wi-Fi password. Since other devices connect fine, the issue is isolated to the phone, and verifying the password is the quickest, least intrusive step before escalating to more complex troubleshooting.

Exam trap

CompTIA often tests the candidate's ability to follow a logical troubleshooting methodology (OSI model layer by layer), and the trap here is that many candidates jump to advanced settings like MAC filtering or network resets instead of starting with the most basic, user-error-prone step of verifying the password.

How to eliminate wrong answers

Option A is wrong because MAC address filtering would affect all devices not on the allowlist, not just this one phone; since other devices connect fine, the router is not blocking this phone by MAC. Option C is wrong because resetting network settings is a drastic step that should only be taken after simpler checks like password verification, and it would erase saved Wi-Fi networks, Bluetooth pairings, and VPN configurations unnecessarily. Option D is wrong because an OS update is a time-consuming, system-level change that addresses bugs or security flaws, not a password entry issue; the phone's current OS version is unlikely to prevent connection if the password is correct.

79
MCQhard

A user's Windows 10 PC is experiencing random freezes and application crashes. You suspect a corrupted system file. You run sfc /scannow but it reports that it cannot repair some files. What is the next best step to repair the system files using a DISM command?

A.Run chkdsk /f
B.Run DISM /Online /Cleanup-Image /RestoreHealth
C.Run System Restore
D.Run Windows Update
AnswerB

The DISM /Online /Cleanup-Image /RestoreHealth command is the correct solution because it scans the Windows component store for corruption and repairs it using healthy files from Windows Update or a specified source. This process ensures the integrity of the system image, which is crucial for the proper functioning of system files and often resolves deep-seated instability like random freezes. Repairing the component store also enables the System File Checker (sfc /scannow) to successfully replace corrupted system files.

Why this answer

The correct next step is to run DISM /Online /Cleanup-Image /RestoreHealth because SFC (System File Checker) relies on a healthy component store (WinSxS) to replace corrupted files. When SFC cannot repair files, it indicates the component store itself may be damaged. DISM repairs the component store by using Windows Update as the source, or a specified repair source, thereby enabling SFC to succeed on a subsequent scan.

Exam trap

The trap here is that candidates often assume SFC is the ultimate repair tool and overlook that DISM must fix the underlying component store first, leading them to choose chkdsk or System Restore as a quick fix.

How to eliminate wrong answers

Option A is wrong because chkdsk /f checks and repairs file system integrity and disk errors, not system file corruption; it addresses issues like bad sectors or MFT corruption, not the Windows component store. Option C is wrong because System Restore reverts system files and registry settings to a previous restore point, but it does not directly repair the component store or replace corrupted system files from a known good source; it may also fail if the restore point itself is corrupted. Option D is wrong because Windows Update installs updates and patches but does not repair existing corrupted system files in the component store; DISM is the tool designed for that purpose.

80
MCQhard

A user reports that their iPhone's flashlight is not working, and the camera app shows a black screen. Other apps function normally. The device is up-to-date and has been restarted. What is the most likely hardware-related issue?

A.The battery is failing and cannot provide enough power.
B.The camera app is corrupted; reinstall it.
C.The camera module or its flex cable is damaged.
D.The iOS has a bug that affects the camera and flashlight.
AnswerC

On iPhones, the LED flash (flashlight) is physically integrated into the rear camera module assembly or connected via the same delicate flex cable. Therefore, physical damage to the camera module itself, or a compromised connection via its flex cable to the logic board, would simultaneously disable both the camera's imaging capabilities and the LED flash's illumination function. This common point of failure accurately explains the simultaneous loss of both features.

Why this answer

The simultaneous failure of the flashlight and camera strongly points to a shared hardware component failure. Both the camera module and the LED flash are typically integrated on the same flex cable assembly or share a common power management IC. Since other apps function normally and the device has been restarted, a hardware fault in the camera module or its flex cable is the most likely cause.

Exam trap

CompTIA often tests the concept of shared hardware dependencies, where candidates mistakenly attribute a dual-component failure to a software bug or battery issue instead of recognizing the common physical connection.

How to eliminate wrong answers

Option A is wrong because a failing battery would cause system-wide power issues, not isolate the camera and flashlight; the device would likely show a low-battery warning or shut down under load. Option B is wrong because the camera app is a system app that cannot be reinstalled by the user, and a corrupted app would not affect the flashlight, which is controlled by a separate daemon. Option D is wrong because a software bug affecting both camera and flashlight would typically be patched in an up-to-date iOS version, and a restart would not resolve a persistent hardware fault.

81
MCQmedium

A user calls the help desk saying that every time they click a link in an email, their browser opens a page that says 'Your computer is infected! Call this number.' They are unable to close the page normally. What type of attack is this, and what is the first step you should take?

A.Phishing attack; immediately change the user's email password
B.Browser hijacker; run a full antivirus scan immediately
C.Tech support scam; force close the browser using Task Manager, then run a security scan
D.Drive-by download; disconnect the computer from the network
AnswerC

This option accurately identifies the threat as a tech support scam, which typically involves displaying a persistent, unclosable browser alert designed to panic the user into calling a fraudulent "support" number. The immediate and effective first step is to force close the browser using Task Manager (Ctrl+Shift+Esc on Windows) to stop the active scam page from locking the browser. Subsequently, running a comprehensive security scan is crucial to detect and remove any underlying malware or adware that might have facilitated the scam page's appearance.

Why this answer

The symptoms — a browser page claiming the computer is infected and demanding a phone call, plus inability to close the page normally — are classic indicators of a tech support scam, often delivered via malvertising or malicious ads. The immediate first step is to force-close the browser (e.g., via Task Manager) to stop the script, then run a security scan to check for any payload or persistence. Changing passwords or disconnecting the network may be appropriate later, but the question asks for the first step.

Exam trap

220-1202 often tests whether candidates can distinguish between similar-sounding attack types (phishing, browser hijacker, tech support scam, drive-by download) and identify the correct first response, so the trap is choosing a plausible-sounding attack type or a response that is not the immediate first step.

How to eliminate wrong answers

Option A is wrong because while phishing may have delivered the link, the described behavior is a tech support scam page, and changing the email password does not address the immediate browser lock or the scam page itself. Option B is wrong because a browser hijacker typically redirects searches or changes the homepage persistently; the described fake infection warning with a phone number is a tech support scam, and running a scan without first closing the locked browser is not the correct first step. Option D is wrong because a drive-by download refers to automatic installation of malware without user interaction; the scenario describes a scam page demanding a call, and disconnecting the network is not the first step when the browser is simply locked by a script.

82
MCQhard

During a routine security scan, a technician finds that a user's workstation has an open port 3389 that is accessible from the internet. The user denies enabling Remote Desktop. What is the most likely security implication and immediate action?

A.The port is likely used by a legitimate application; no action is needed.
B.Disable the Remote Desktop service and block port 3389 at the firewall immediately.
C.Change the RDP listening port to a non-standard port to hide it.
D.Enable Network Level Authentication (NLA) on the workstation.
AnswerB

An internet-reachable port 3389 indicates Remote Desktop was enabled, possibly by malware or unauthorised configuration, exposing the workstation to brute-force and exploitation. Disabling the service and blocking the port at the firewall immediately removes that exposure.

Why this answer

Port 3389 is the default port for Remote Desktop Protocol (RDP). An open RDP port accessible from the internet is a critical security risk because it exposes the workstation to brute-force attacks, credential theft, and remote exploitation (e.g., BlueKeep, CVE-2019-0708). The immediate action is to disable the Remote Desktop service and block port 3389 at the firewall, as the user denies enabling it, indicating possible unauthorized activation or malware.

Exam trap

CompTIA A+ exams often test the misconception that changing a default port or enabling additional authentication is sufficient to secure an exposed service, when the correct immediate action is to close the port and disable the service entirely.

How to eliminate wrong answers

Option A is wrong because port 3389 is exclusively assigned to RDP by IANA; no legitimate internet-facing application uses this port by default, and leaving it open invites exploitation. Option C is wrong because changing the listening port to a non-standard port is security through obscurity and does not address the root cause; attackers can still discover the port via scanning and the service remains vulnerable. Option D is wrong because enabling Network Level Authentication (NLA) only adds an authentication layer but does not prevent exposure to the internet; the port remains open and accessible, still allowing brute-force or vulnerability-based attacks.

83
MCQhard

A technician is troubleshooting a server that repeatedly trips the circuit breaker in the data center. The server is plugged into a power strip that is also serving two other high-power devices. What is the most appropriate safety and troubleshooting step?

A.Replace the power strip with a higher-rated one and reset the breaker.
B.Move one of the other high-power devices to a different circuit and plug the server directly into a wall outlet on its own circuit.
C.Reset the breaker and use a UPS with a higher wattage rating.
D.Install a larger circuit breaker in the panel to handle the load.
AnswerB

Repeated circuit breaker trips indicate an overload on the circuit. By moving one or more high-power devices to a different electrical circuit, the total current draw on the original circuit is significantly reduced, preventing it from exceeding its rated capacity. Plugging the server directly into a wall outlet on its own dedicated circuit ensures it receives stable power without competing with other heavy loads, resolving the overload issue.

Why this answer

The repeated tripping indicates the circuit is overloaded. The safest and most effective step is to redistribute the load by moving one high-power device to a different circuit and plugging the server directly into a dedicated wall outlet. This isolates the server's power draw and prevents overloading the shared circuit, addressing the root cause without bypassing safety limits.

Exam trap

CompTIA often tests the misconception that upgrading the power strip or breaker is a valid fix, when in fact the correct approach is to redistribute the load to separate circuits to stay within safe electrical limits.

How to eliminate wrong answers

Option A is wrong because replacing the power strip with a higher-rated one does not change the circuit's maximum current capacity (typically 15A or 20A in a data center); the breaker will still trip if the total load exceeds that limit. Option C is wrong because resetting the breaker and using a higher-wattage UPS does not solve the overload; the UPS itself draws power from the same circuit and could still cause tripping if the total load exceeds the breaker rating. Option D is wrong because installing a larger circuit breaker without verifying the wiring gauge and outlet ratings is a fire hazard; the wiring may not be rated for higher current, violating electrical code and safety standards.

84
MCQmedium

A technician is troubleshooting a Windows 10 computer that exhibits strange behavior: system files are missing, and the computer fails to boot normally. A boot-time virus scan detects a virus that infected the Master Boot Record (MBR). Which tool should the technician use to repair the MBR?

A.System Restore
B.Bootrec.exe /FixMbr
C.SFC /Scannow
D.CHKDSK /F
AnswerB

The Bootrec.exe /FixMbr command is specifically used from the Windows Recovery Environment (WinRE) to write a new Master Boot Record to the system partition without overwriting the existing partition table. This action effectively repairs corruption or damage to the MBR, which is crucial for the system to locate and load the operating system. It is particularly effective against boot sector viruses or other MBR-related boot failures, making the drive bootable again.

Why this answer

The Bootrec.exe /FixMbr command writes a new Master Boot Record (MBR) to the system partition, overwriting the infected boot code without affecting the existing partition table. This is the correct tool for repairing a virus-compromised MBR that prevents normal booting on Windows 10.

Exam trap

The trap here is that candidates confuse SFC /Scannow with a boot repair tool, but SFC only works on the installed OS and cannot touch the MBR, which is outside the file system.

How to eliminate wrong answers

Option A is wrong because System Restore restores system files and registry settings from a restore point, but it does not repair the MBR, which resides outside the file system in the first sector of the disk. Option C is wrong because SFC /Scannow scans and repairs protected system files within the Windows installation, but it cannot fix the MBR, which is a low-level boot structure not managed by the Windows File Protection mechanism. Option D is wrong because CHKDSK /F checks the file system integrity and fixes logical errors on the disk volume, but it does not write or repair the MBR boot code.

85
MCQhard

A user reports that their Windows 10 PC suddenly shows a 'Your IT administrator has limited access' message when trying to change the desktop background. The user has local administrator rights. Which Group Policy or registry setting is most likely misconfigured?

A.The 'Prevent changing desktop background' policy is enabled in Local Group Policy.
B.The user's account is not part of the Administrators group.
C.The desktop background file is corrupted.
D.The Windows license has expired.
AnswerA

This is the correct answer. The 'Prevent changing desktop background' policy, found under User Configuration > Administrative Templates > Control Panel > Personalization in the Local Group Policy Editor (gpedit.msc), specifically restricts users from modifying their desktop background. When enabled, this policy overrides any user permissions, including local administrator rights, and typically displays a message indicating that an administrator has disabled the option, directly matching the reported symptom.

Why this answer

The 'Prevent changing desktop background' policy, when enabled in Local Group Policy Editor (gpedit.msc) under User Configuration > Administrative Templates > Control Panel > Personalization, explicitly blocks background changes regardless of local administrator rights. Since the user has local admin rights but still sees the restriction, this policy is the most likely cause, as it overrides user permissions.

Exam trap

CompTIA often tests the misconception that local administrator rights bypass all Group Policy restrictions, but in reality, many administrative templates apply to all users, including administrators, unless specifically configured otherwise.

How to eliminate wrong answers

Option B is wrong because the user already has local administrator rights, so not being part of the Administrators group is contradictory to the scenario. Option C is wrong because a corrupted background file would cause a display issue (e.g., black screen or error), not a specific 'IT administrator has limited access' message. Option D is wrong because an expired Windows license triggers activation warnings (e.g., 'Windows is not activated') and may disable personalization features, but it does not produce the exact 'Your IT administrator has limited access' message, which is specific to Group Policy restrictions.

86
MCQmedium

A graphic designer reports that their MacBook Pro running macOS Monterey suddenly shows a gray screen with a folder icon containing a question mark at startup. They have important client files on the internal SSD. What is the most likely cause of this issue?

A.The user’s Time Machine backup has failed
B.The firmware password is enabled
C.macOS cannot locate a valid boot volume or system folder
D.The user’s login keychain is corrupted
AnswerC

The flashing folder with a question mark indicates the firmware cannot find a bootable system folder on any attached volume. This typically follows corruption of the startup disk's directory or loss of the macOS system installation.

Why this answer

The gray screen with a folder icon containing a question mark indicates that the Mac's startup process cannot locate a valid boot volume or system folder. This is a classic symptom of a missing or corrupted boot loader, damaged system files, or a disconnected internal SSD, which prevents macOS from finding the required bootable system.

Exam trap

The A+ exam often tests the distinction between boot-level failures (folder icon) and post-boot authentication issues (keychain), so candidates mistakenly choose a corrupted login keychain because they associate question marks with 'missing' items without understanding the boot sequence.

How to eliminate wrong answers

Option A is wrong because a failed Time Machine backup does not affect the startup process; it only impacts the ability to restore files from a backup. Option B is wrong because a firmware password prevents unauthorized booting from external drives or recovery mode but does not cause a folder-with-question-mark icon; that icon specifically indicates no bootable system is found. Option D is wrong because a corrupted login keychain prevents user authentication after macOS loads, not the initial boot process; the folder icon appears before any user login occurs.

87
MCQeasy

An employee finds a USB drive labeled 'Employee Salary Info Q4' in the parking lot. Out of curiosity, they plug it into their work computer to see the contents. What type of social engineering attack is this an example of?

A.Phishing
B.Tailgating
C.Baiting
D.Pretexting
AnswerC

Baiting exploits curiosity by leaving physical media, such as a labelled USB drive, for a victim to plug in, delivering malware or enabling credential theft. The salary-labelled drive in the car park is a textbook baiting lure.

Why this answer

Baiting is a social engineering attack that exploits human curiosity or greed by offering something enticing, such as a USB drive labeled 'Employee Salary Info Q4.' When the employee plugs the USB into their work computer, they may inadvertently install malware (e.g., a keylogger or backdoor) that compromises the system. This attack relies on physical media as the delivery vector, distinguishing it from other social engineering methods.

Exam trap

CompTIA A+ often tests the distinction between baiting and phishing by emphasizing that baiting involves a physical lure (like a USB drive) while phishing is purely digital, causing candidates to confuse the two when the attack involves a digital payload.

How to eliminate wrong answers

Option A is wrong because phishing is a digital attack that uses deceptive emails, messages, or websites to trick users into revealing sensitive information, not physical USB drives. Option B is wrong because tailgating involves an unauthorized person physically following an authorized individual into a restricted area without proper authentication, not the use of a dropped USB drive. Option D is wrong because pretexting involves fabricating a scenario or identity (e.g., impersonating IT support) to obtain information, not leaving a physical device to exploit curiosity.

88
MCQhard

A technician is reviewing a PowerShell script that was used in a ransomware attack. The script contains a line that downloads and executes a payload from a remote server. The script uses a technique to bypass execution policy. Which scripting technique is most likely used to bypass the execution policy?

A.Using the 'Set-ExecutionPolicy' cmdlet to change the policy to Unrestricted
B.Using the '-ExecutionPolicy Bypass' parameter when launching PowerShell
C.Using the 'powershell.exe -Command' syntax with an encoded command
D.Signing the script with a self-signed certificate
AnswerB

The '-ExecutionPolicy Bypass' parameter is a highly effective and stealthy method because it overrides the system's execution policy for the current PowerShell session only. This means the script can execute without requiring administrative privileges to alter system settings or leaving a permanent change on the system. It's a preferred technique for attackers as it allows immediate script execution without triggering system-wide security alerts or leaving persistent forensic artifacts.

Why this answer

The '-ExecutionPolicy Bypass' parameter when launching PowerShell tells the PowerShell engine to bypass the execution policy for that session only, allowing any script to run without restriction. This is a common technique used by attackers because it does not require administrative privileges or permanent policy changes, making it stealthy and effective for executing malicious payloads.

Exam trap

CompTIA often tests the distinction between permanently changing the execution policy (which requires admin rights and is detectable) versus using a session-level parameter to bypass it (which is stealthy and does not require admin rights), leading candidates to mistakenly choose the 'Set-ExecutionPolicy' option.

How to eliminate wrong answers

Option A is wrong because using the 'Set-ExecutionPolicy' cmdlet to change the policy to Unrestricted requires administrative privileges and leaves a persistent change that can be detected by security tools; it is not a stealthy bypass technique. Option C is wrong because using 'powershell.exe -Command' with an encoded command is a method to obfuscate the command or avoid character restrictions, but it does not bypass the execution policy—if the policy blocks script execution, the encoded command will still be blocked unless the policy is bypassed separately. Option D is wrong because signing the script with a self-signed certificate does not bypass execution policy; it only allows the script to run if the execution policy is set to AllSigned or RemoteSigned and the certificate is trusted, which is not a bypass technique and requires additional configuration.

89
MCQhard

A technician is troubleshooting a wireless network where users report intermittent connectivity and slow speeds. The network uses WPA2-Enterprise with EAP-TLS and certificate-based authentication. The technician notices that the RADIUS server logs show frequent certificate validation failures. What is the most likely root cause?

A.The access point's firmware is outdated, causing packet loss.
B.The RADIUS server's certificate has expired.
C.Client devices have expired or untrusted certificates.
D.The wireless channel is overlapping with neighboring networks.
AnswerC

When client devices possess expired or untrusted certificates, their authentication attempts against the RADIUS server will intermittently fail. Some authentication protocols, like EAP-TLS, rely on client-side certificates for identity verification. If a client's certificate is no longer valid or not trusted by the authentication server, the connection will be rejected, leading to disconnects and subsequent re-attempts, which aligns with intermittent issues for some users.

Why this answer

The RADIUS server logs show frequent certificate validation failures, which directly points to an issue with the certificates presented by the clients during EAP-TLS authentication. In WPA2-Enterprise with EAP-TLS, both the server and client must present valid certificates; if client certificates are expired or untrusted, the RADIUS server will reject the authentication, causing intermittent connectivity and slow speeds as clients fail to re-authenticate or roam.

Exam trap

The 220-1202 exam often tests the distinction between server-side and client-side certificate issues; the trap here is that candidates may assume the RADIUS server's certificate is the problem (Option B) because it is the central authentication point, but the logs specifically show 'validation failures' which in EAP-TLS typically refer to the client certificate failing validation by the server.

How to eliminate wrong answers

Option A is wrong because outdated access point firmware could cause packet loss or performance issues, but it would not produce certificate validation failures in the RADIUS server logs; certificate errors are specific to the authentication process. Option B is wrong because if the RADIUS server's certificate had expired, clients would fail to validate the server, and the logs would show server certificate errors, not frequent client certificate validation failures; the question states the logs show certificate validation failures, which are client-side. Option D is wrong because overlapping wireless channels cause interference, leading to slow speeds and disconnections, but they do not generate certificate validation failures in RADIUS logs; those logs are authentication-specific.

90
MCQhard

A security incident occurred where an unauthorized user gained access to a workstation. The security team needs to review detailed logs of all user logon attempts, including successful and failed logins, for the past 48 hours. Which administrative tool and specific log should you access to provide this information?

A.Event Viewer > Windows Logs > System
B.Event Viewer > Windows Logs > Security
C.Event Viewer > Applications and Services Logs > Microsoft > Windows > TerminalServices-LocalSessionManager
D.Computer Management > System Tools > Shared Folders > Sessions
AnswerB

The Security log is the designated repository for audit events on a Windows system, including successful and failed user logon attempts, account management operations, object access, and policy changes. To effectively track an unauthorized user gaining access, administrators would configure audit policies to record these specific security events, making this log crucial for forensic analysis and incident response. This log provides the detailed audit trail necessary to investigate security breaches.

Why this answer

Windows records all authentication events — successful and failed logons, logoffs, and account changes — in the Security log, accessible via Event Viewer under Windows Logs > Security. Key event IDs include 4624 (successful logon), 4625 (failed logon), 4634 (logoff), and 4648 (logon using explicit credentials). Reviewing this log for the past 48 hours gives the analyst the complete authentication timeline needed for the incident investigation.

Exam trap

220-1202 often tests whether candidates know which Event Viewer log holds authentication data — many pick the System log or a service-specific log, missing that only the Security log contains 4624/4625 events.

How to eliminate wrong answers

Option A is wrong because the System log records OS-level events (service start/stop, driver failures, hardware errors) — it does not contain logon audit records. Option C is wrong because TerminalServices-LocalSessionManager logs RDP session lifecycle events (session connect/disconnect), not general interactive or network logon attempts, and it would miss non-RDP logons. Option D is wrong because Shared Folders > Sessions shows currently connected SMB sessions and open files in real time — it is not a historical log and cannot show the past 48 hours of logon attempts.

91
MCQeasy

A customer complains that their iOS device's screen orientation is stuck in portrait mode and will not rotate to landscape when they turn the phone sideways. What is the most likely cause and solution?

A.Enable Display Zoom in Settings
B.Toggle the Rotation Lock in Control Center
C.Restart the device
D.Adjust the text size in Accessibility
AnswerB

The Rotation Lock feature, accessible via the Control Center on iOS devices, directly controls whether the screen automatically rotates based on the device's physical orientation. When enabled (indicated by a padlock icon), it overrides the accelerometer and gyroscope input, forcing the display into a specific orientation, typically portrait mode. Toggling this setting off releases the lock, allowing the screen to rotate freely according to the device's current physical position, thereby resolving the customer's complaint.

Why this answer

The most likely cause is that the Rotation Lock is enabled, which prevents the iOS device from switching between portrait and landscape orientations. Toggling the Rotation Lock off in Control Center directly resolves this issue, as it is a common user-accessible setting that can be accidentally activated.

Exam trap

The CompTIA A+ exam often tests the distinction between a user-configurable setting (Rotation Lock) and a system-level troubleshooting step (restart), leading candidates to choose the more generic 'Restart the device' option instead of the specific, correct solution.

How to eliminate wrong answers

Option A is wrong because Display Zoom adjusts the overall screen resolution and icon size, not the orientation lock behavior. Option C is wrong because restarting the device is a generic troubleshooting step that does not address the specific setting causing the orientation lock; it would only be effective if the issue were a temporary software glitch, which is less likely than an enabled lock. Option D is wrong because adjusting text size in Accessibility changes font scaling, not the screen rotation functionality.

92
MCQeasy

During a software deployment, you need to configure a Windows 10 workstation to automatically start a legacy application every time a specific user logs on. Which tool should you use to add this startup entry for that user only?

A.Services.msc
B.Task Manager
C.Computer Management
D.Local Group Policy Editor
AnswerC

Computer Management includes Local Users and Groups, where you can set a per-user logon script in the user's Profile tab (or use Task Scheduler) to start the legacy application only when that user logs on.

Why this answer

Computer Management (compmgmt.msc) contains Local Users and Groups, where you can open the target user's properties and set a logon script on the Profile tab. That script runs only for that user at logon, satisfying the requirement. Services.msc manages system services and is not user-specific.

Task Manager's Startup tab only enables or disables existing startup entries; it cannot add new ones. Local Group Policy Editor applies User Configuration policies, including logon scripts, to all users of the computer, so it is not the primary tool for a single specified user.

Exam trap

CompTIA often tests the distinction between per-user logon scripts (configured via Local Users and Groups in Computer Management) and machine-wide policies or services. The trap is to confuse the Startup tab in Task Manager with the ability to add startup entries, or to assume Local Group Policy Editor can target an individual user by itself.

How to eliminate wrong answers

Option A is wrong because Services.msc manages Windows services that run in the background under the SYSTEM account or a specified service account, not per-user interactive startup applications. Option C is wrong because Computer Management is a consolidated console for system tools (e.g., Disk Management, Event Viewer, Local Users and Groups) but does not include a per-user startup entry editor; it lacks the granularity to add a startup program for a single user. Option D is wrong because the Local Group Policy Editor (gpedit.msc) can configure startup scripts via Computer Configuration or User Configuration, but those are processed during Group Policy refresh and are intended for domain-managed or local policy-based script execution, not for simply adding a legacy application to the user's Run registry key or Startup folder; it is overkill and not the direct tool for this task.

93
MCQmedium

A customer reports that their Windows 10 desktop shows a black screen with a movable cursor after logging in. They can press Ctrl+Alt+Del and open Task Manager. Which process should be restarted from Task Manager to restore the desktop and taskbar?

A.Restart the 'Windows Explorer' process in Task Manager.
B.End the 'svchost.exe' process group.
C.Start the 'winlogon.exe' process.
D.Run 'msconfig' from the Run dialog to enable normal startup.
AnswerA

Restarting the 'Windows Explorer' (explorer.exe) process is the correct solution because this process is responsible for rendering the graphical user interface, including the desktop, taskbar, and file management windows. When the desktop appears black but the system is otherwise running, it often indicates that the explorer.exe shell has crashed or become unresponsive. Terminating and then restarting this specific process via Task Manager effectively reloads the entire desktop environment, typically resolving the visual display issue without requiring a full system reboot.

Why this answer

The black screen with a movable cursor after login, combined with the ability to open Task Manager via Ctrl+Alt+Del, indicates that the Windows shell (explorer.exe) has crashed or is not running. Restarting the 'Windows Explorer' process from Task Manager (File > Run new task > 'explorer.exe') reloads the desktop, taskbar, and File Explorer, restoring the graphical user interface. This is the standard recovery step for a missing shell in Windows 10.

Exam trap

The trap here is that candidates confuse the 'Windows Explorer' process with Internet Explorer or assume that 'svchost.exe' is the correct service host to restart, when in fact the shell process (explorer.exe) is the specific component responsible for the desktop and taskbar.

How to eliminate wrong answers

Option B is wrong because ending the 'svchost.exe' process group would terminate critical Windows services (e.g., RPC, DHCP, DNS), potentially causing system instability or a blue screen, not restoring the desktop. Option C is wrong because 'winlogon.exe' is a system process that handles interactive logon and cannot be started manually from Task Manager; it is already running if the user can log in, and restarting it would force a logoff. Option D is wrong because 'msconfig' is a system configuration utility used to change boot options or startup mode, not a tool to restart a crashed shell process; running it from the Run dialog would not fix the immediate black screen issue.

94
MCQmedium

A technician receives a ticket from a user who says their email is not working. The technician remotely connects and sees that the user's Outlook profile is corrupt. The user is in the middle of an important project. What is the best way to communicate the necessary steps?

A.Explain that the Outlook profile is corrupt and needs to be rebuilt, which may cause a brief interruption.
B.Tell the user that you will fix it and they should not worry about the details.
C.Use technical terms like 'PST file corruption' and 'registry repair' to sound knowledgeable.
D.Rebuild the profile without informing the user to avoid worrying them.
AnswerA

Explaining that the Outlook profile is corrupt and needs to be rebuilt, along with the potential for a brief interruption, is the most professional and effective communication strategy. This approach fosters trust by being transparent about the issue and its resolution, managing the user's expectations regarding downtime. It allows the user to prepare for the interruption, ensuring their workflow is minimally impacted while demonstrating the technician's competence and respect for their time.

Why this answer

It balances transparency with professionalism: the technician clearly explains the issue (corrupt Outlook profile) and the necessary action (rebuild), while proactively managing expectations about a brief interruption. This approach respects the user's need to stay informed during an important project, aligning with ITIL best practices for incident management and user communication.

Exam trap

CompTIA often tests the distinction between technical accuracy and professional communication, trapping candidates who think using technical jargon or acting without consent demonstrates expertise, when in fact the exam emphasizes clear, respectful, and transparent user interaction.

How to eliminate wrong answers

Option B is wrong because it dismisses the user's need for situational awareness; withholding details can erode trust and leave the user unprepared for the interruption. Option C is wrong because using jargon like 'PST file corruption' and 'registry repair' without explanation confuses the user and violates the principle of communicating at the user's technical level. Option D is wrong because rebuilding the profile without informing the user is unethical and unprofessional; it denies the user the opportunity to save work or prepare for downtime, potentially causing data loss or workflow disruption.

95
MCQmedium

A new employee receives an email that appears to be from the company's HR department, asking them to click a link to verify their direct deposit information for payroll. The email contains the company logo and looks professional. What is the most likely social engineering attack?

A.Whaling
B.Phishing
C.Vishing
D.Shoulder surfing
AnswerB

Phishing uses a spoofed, professional-looking email impersonating a trusted internal sender such as HR to trick the recipient into clicking a link and surrendering credentials or financial details. The direct deposit lure and forged branding match this attack precisely.

Why this answer

Phishing is the correct answer because the attack uses a deceptive email that impersonates a legitimate entity (HR department) to trick the recipient into clicking a malicious link. This is a classic example of a broad, untargeted social engineering attack delivered via email, which is the defining characteristic of phishing.

Exam trap

The trap is that candidates may confuse phishing with whaling because both use email, but the key differentiator is the target: phishing is broad and untargeted, while whaling specifically targets high-level executives or individuals with privileged access. For example, an email targeting a CEO about a wire transfer is whaling, while an email targeting many employees about updating HR info is phishing.

How to eliminate wrong answers

Option A is wrong because whaling is a highly targeted form of phishing aimed at senior executives or high-value individuals, not a general employee receiving a mass-distributed email. Option C is wrong because vishing (voice phishing) is conducted over the phone using voice calls or VoIP, not through email. Option D is wrong because shoulder surfing involves directly observing someone's screen or keyboard to steal information, such as passwords, without any electronic communication.

96
MCQmedium

A customer reports that their Windows 11 PC is experiencing intermittent application crashes and you suspect file corruption. You need to run a system file check without using the full Windows interface. Which administrative tool can you launch from the Run dialog to open a command prompt with the necessary permissions?

A.Type 'cmd' in the Run dialog and press Enter
B.Type 'powershell' in the Run dialog and press Enter
C.Type 'cmd' in the Run dialog and press Ctrl+Shift+Enter
D.Type 'msconfig' in the Run dialog and press Enter
AnswerC

Typing 'cmd' in the Run dialog and pressing Ctrl+Shift+Enter is the correct method to launch an elevated command prompt. This key combination specifically triggers the User Account Control (UAC) prompt, requesting administrative consent from the user. An elevated command prompt provides the necessary administrator privileges for the System File Checker (SFC) tool to access and repair protected Windows system files effectively, ensuring a comprehensive scan and restoration process.

Why this answer

Pressing Ctrl+Shift+Enter while typing 'cmd' in the Run dialog launches Command Prompt with administrator privileges, which is required to run the System File Checker (sfc /scannow) to repair file corruption. This bypasses the full Windows interface and provides the necessary elevated permissions.

Exam trap

The 220-1202 exam often tests the distinction between launching a tool with standard permissions versus elevated permissions, and the trap here is that candidates assume typing 'cmd' alone is sufficient, forgetting that administrative tasks like sfc require the Ctrl+Shift+Enter shortcut to run as administrator.

How to eliminate wrong answers

Option A is wrong because typing 'cmd' and pressing Enter opens Command Prompt with standard user permissions, which lacks the administrative rights needed to run sfc /scannow. Option B is wrong because typing 'powershell' and pressing Enter opens PowerShell with standard user permissions, not elevated, and the question specifically asks for a command prompt, not PowerShell. Option D is wrong because 'msconfig' opens the System Configuration utility, which is a graphical tool for boot settings and services, not a command-line interface for running system file checks.

97
MCQmedium

A customer calls saying that after installing a new printer, their Windows 10 computer now takes much longer to shut down. They have uninstalled the printer software, but the slow shutdown persists. Which tool should you use to identify the cause of the shutdown delay?

A.Task Manager
B.Performance Monitor
C.Event Viewer
D.Disk Cleanup
AnswerC

Event Viewer records system, application, and security logs. During a slow shutdown, the System log often contains warnings or errors from services or drivers that are delaying the process, allowing you to identify the culprit.

Why this answer

Event Viewer is the correct tool because Windows logs shutdown and service-stop events (including the notorious 'The program X stopped responding' and service timeout entries) in the System log, which reveals which driver, service, or application is delaying shutdown. The printer software likely left a service or driver that times out during shutdown, and Event Viewer's System and Application logs record those timeouts.

Exam trap

The trap is reaching for a live-monitoring tool (Task Manager, Performance Monitor) when the problem is a historical, logged event — the exam wants you to know that Event Viewer is the tool for post-incident shutdown/startup diagnostics.

How to eliminate wrong answers

Option A is wrong because Task Manager shows current running processes and resource usage in real time — it cannot show historical shutdown delays or which service blocked shutdown. Option B is wrong because Performance Monitor collects real-time and logged performance counters (CPU, disk, memory) but does not record shutdown sequence events or identify blocking services. Option D is wrong because Disk Cleanup removes temporary files to free disk space and has nothing to do with diagnosing shutdown timing.

98
MCQeasy

A client brings in a laptop that was used by an employee who left the company. The manager wants to ensure all data is unrecoverable before recycling the laptop. The laptop has a traditional HDD. Which method should be used?

A.Perform a quick format of the drive.
B.Use a degausser to demagnetize the drive.
C.Run a full overwrite using disk-wiping software.
D.Physically shred the drive with a hard drive shredder.
AnswerC

Running a full overwrite with specialized disk-wiping software systematically writes new data, typically zeros or random patterns, across every sector of the drive. This process ensures that all previous data is completely obliterated and unrecoverable, even with advanced forensic techniques. Crucially, this method allows the drive to be subsequently reformatted and reused, making it an ideal balance between data security and hardware longevity.

Why this answer

Disk-wiping software performs a full overwrite of every sector on the HDD with patterns (e.g., zeros, random data), making the original data unrecoverable even with advanced forensic tools. This method is specifically designed for secure data destruction on functional drives, ensuring compliance with data sanitization standards like NIST SP 800-88.

Exam trap

The A+ exam often tests the misconception that a degausser is the best option for data destruction on HDDs, but candidates forget that degaussing destroys the drive's functionality and is not a secure sanitization method for reuse, whereas disk-wiping software allows the drive to be repurposed while ensuring data is unrecoverable.

How to eliminate wrong answers

Option A is wrong because a quick format only clears the file system metadata (e.g., MFT or FAT) and marks sectors as available, leaving the actual data intact and easily recoverable with tools like Recuva or TestDisk. Option B is wrong because a degausser destroys the magnetic field of the platters, rendering the drive unusable, but it does not guarantee data unrecoverability on modern high-coercivity HDDs and may leave residual data that can be recovered with specialized equipment. Option D is wrong because physically shredding the drive destroys the hardware, making data recovery impossible, but it is an overkill for a functional laptop that the manager may want to reuse or donate; the question asks for a method to ensure data is unrecoverable before recycling, and shredding is a disposal method, not a data sanitization method for reuse.

99
MCQeasy

A small business is deploying a new time-tracking application to five workstations. The technician needs to ensure the installation is standardized and repeatable. Which documentation should the technician create before starting the deployment?

A.A list of user passwords for the application.
B.A detailed network topology diagram.
C.A step-by-step installation guide with screenshots.
D.A copy of the software license agreement.
AnswerC

A comprehensive step-by-step installation guide, especially when augmented with screenshots, is paramount for ensuring consistent and standardized deployment of a new application across multiple workstations. This document provides clear, unambiguous instructions for technicians, minimizing errors and variations in configuration. It also serves as an invaluable reference for future installations, onboarding new IT staff, and efficient troubleshooting by establishing a known good configuration baseline.

Why this answer

A step-by-step installation guide with screenshots is the correct documentation because it makes the deployment standardized and repeatable across all five workstations. It captures exact settings, order of operations, and expected screens so any technician can reproduce the install identically. This directly satisfies the requirement for consistency and reduces configuration drift.

Exam trap

220-1202 often tests whether candidates confuse 'documentation' with 'security artifacts' or 'network diagrams' — the key is matching the documentation type to the stated goal of standardization and repeatability.

How to eliminate wrong answers

Option A is wrong because a list of user passwords is a security liability and does nothing to standardize the installation process. Option B is wrong because a network topology diagram documents connectivity, not application installation steps, and is irrelevant to a five-workstation software rollout. Option D is wrong because a license agreement is a legal document, not a procedural guide, and provides no installation instructions.

100
MCQmedium

A technician is helping a remote user configure a VPN connection. The user is not very technical and is getting frustrated. The technician uses jargon like 'authentication protocol' and 'tunnel endpoint'. Which of the following is the BEST way to improve communication?

A.Continue using technical terms to educate the user.
B.Ask the user to share their screen so the technician can do it remotely.
C.Use simple analogies like 'a secure tunnel for your data' and guide them step by step.
D.Send the user a written guide and end the call.
AnswerC

Employing simple analogies, such as describing a VPN as 'a secure tunnel for your data,' effectively demystifies complex technical concepts for non-technical users. This approach, combined with clear, step-by-step instructions, empowers the user to actively participate in the configuration process, reducing anxiety and increasing the likelihood of successful completion. It fosters understanding and builds confidence, aligning with best practices for remote technical support.

Why this answer

It replaces confusing jargon with a simple analogy ('secure tunnel') and provides step-by-step guidance, which directly addresses the user's frustration and lack of technical knowledge. This approach aligns with the CompTIA A+ objective of adapting communication style to the audience, ensuring the user understands the VPN concept without needing to know terms like 'authentication protocol' or 'tunnel endpoint'.

Exam trap

CompTIA often tests the trap that candidates think educating the user with technical terms (Option A) is helpful, but the correct approach is to simplify language and use analogies to match the user's skill level, as per CompTIA's emphasis on customer service and effective communication.

How to eliminate wrong answers

Option A is wrong because continuing to use technical terms like 'authentication protocol' and 'tunnel endpoint' will likely increase the user's frustration and confusion, as they are not technical and need simplified explanations, not education on jargon. Option B is wrong because asking the user to share their screen assumes they can navigate the sharing process, which may be as confusing as the VPN setup itself; it also shifts the burden to the user without improving their understanding. Option D is wrong because sending a written guide and ending the call abandons the user, leaving them to struggle alone with technical documentation, which contradicts the goal of providing effective remote support.

101
MCQmedium

A security incident occurs where an unauthorized PowerShell script was executed on a server, exfiltrating data. The IT manager wants to prevent any unsigned PowerShell scripts from running on all domain computers. Which scripting security measure should be implemented?

A.Set the execution policy to Restricted
B.Set the execution policy to AllSigned
C.Set the execution policy to RemoteSigned
D.Disable PowerShell using Group Policy
AnswerB

The `AllSigned` execution policy mandates that all PowerShell scripts, whether created locally or downloaded from the internet, must be digitally signed by a trusted publisher before they can execute. This effectively blocks the unauthorized unsigned script, preventing its execution, while simultaneously permitting legitimate, signed administrative scripts to run. This policy strikes an optimal balance between security and operational functionality by ensuring script integrity and authenticity.

Why this answer

Setting the execution policy to AllSigned requires that all PowerShell scripts, including those written locally, be digitally signed by a trusted publisher before they can run. This directly addresses the requirement to prevent any unsigned PowerShell scripts from executing on domain computers, as it blocks both remote and local unsigned scripts.

Exam trap

The trap here is that candidates often confuse RemoteSigned with AllSigned, assuming that blocking internet-sourced scripts is sufficient, but they overlook that locally created unsigned scripts (e.g., written by an attacker after gaining access) remain a threat.

How to eliminate wrong answers

Option A is wrong because setting the execution policy to Restricted prevents all PowerShell scripts from running, which is overly restrictive and would block legitimate administrative scripts, not just unsigned ones. Option C is wrong because RemoteSigned only requires scripts downloaded from the internet to be signed; locally created scripts can run unsigned, leaving a gap for attackers to execute locally crafted malicious scripts. Option D is wrong because disabling PowerShell entirely via Group Policy is a heavy-handed approach that breaks legitimate administrative tasks and automation, whereas the requirement is specifically to control script execution, not remove the tool.

102
MCQmedium

A user's Windows 10 PC is infected with ransomware that has encrypted their Documents folder. You need to restore the files from a previous version that was saved by File History. Where do you access the 'Previous Versions' feature to restore these files?

A.File Explorer > Properties > Previous Versions tab
B.Control Panel > File History > Restore personal files
C.Settings > Update & Security > Backup
D.Computer Management > Storage > Disk Management
AnswerA

Accessing the 'Previous Versions' tab via File Explorer properties for a specific file or folder directly leverages the Volume Shadow Copy Service (VSS) or File History backups. This interface allows users to browse and restore older, unencrypted iterations of files, making it the primary method for recovering data from ransomware without paying the ransom. It provides granular control to select and restore individual files or entire folders to a state prior to encryption.

Why this answer

The 'Previous Versions' tab is accessible via File Explorer by right-clicking a file or folder, selecting Properties, and then clicking the Previous Versions tab. This tab lists shadow copies or File History backups of the selected item, allowing you to restore an earlier version. In this scenario, since File History was enabled, the previous versions of the Documents folder will appear here for restoration.

Exam trap

The trap here is that candidates confuse the File History restore interface (accessed via Control Panel) with the 'Previous Versions' tab in File Explorer, but the question explicitly asks for the location of the 'Previous Versions' feature, which is found in the file or folder's Properties dialog.

How to eliminate wrong answers

Option B is wrong because Control Panel > File History > Restore personal files opens the File History restore interface, which is used to browse and restore files from File History backups, but it does not directly access the 'Previous Versions' tab; the question specifically asks where to access the 'Previous Versions' feature, not the File History restore wizard. Option C is wrong because Settings > Update & Security > Backup is the modern UI for configuring backup settings, including File History, but it does not provide a direct 'Previous Versions' tab for restoring individual files; it only offers options to add a drive or more options. Option D is wrong because Computer Management > Storage > Disk Management is used for managing disk partitions, volumes, and drives, and has no relation to file versioning or restoration from File History.

103
MCQmedium

A technician is decommissioning a server that contained encrypted patient health records. The organization's policy requires data to be destroyed beyond recovery, but the server must be returned to the leasing company. Which method should the technician use?

A.Perform a full format of all drives.
B.Use a degausser on the entire server chassis.
C.Remove the hard drives and physically shred them, then return the server without drives.
D.Run a disk cleanup and delete all files.
AnswerC

Physical destruction, such as shredding or pulverizing hard drives, is the most secure and irreversible method for data sanitization, especially for encrypted data. This method ensures that the platters containing the data are completely destroyed, making any data recovery impossible, even with advanced forensic techniques. Removing the drives and then returning the server chassis without them also directly addresses the common scenario of leased equipment where the data-bearing components must be retained or destroyed by the organization, while the hardware itself is returned to the lessor.

Why this answer

Physically shredding the hard drives ensures the encrypted patient health records are destroyed beyond any possible recovery, which satisfies the organization's policy. Returning the server without drives complies with the leasing company's requirement to return the server chassis, as the drives are typically owned by the organization or can be removed per lease terms. This method is the only one that guarantees data destruction at the physical media level, bypassing any residual data on the encrypted drives.

Exam trap

The trap here is that candidates may choose degaussing (Option B) because it effectively destroys magnetic data, but they overlook the requirement to return the server to the leasing company, which degaussing would render inoperable by damaging non-storage electronics.

How to eliminate wrong answers

Option A is wrong because a full format of all drives only overwrites file system metadata and may not securely erase all sectors, especially on SSDs where wear-leveling can leave residual data; encrypted data could still be recoverable with forensic tools. Option B is wrong because using a degausser on the entire server chassis would destroy the magnetic media on HDDs but would also damage or destroy other electronic components (e.g., motherboard, RAM, power supply), making the server non-functional and violating the lease return requirement. Option D is wrong because disk cleanup and deleting files only removes file system pointers, leaving the actual data intact on the storage media, which can be easily recovered with undelete utilities or forensic software.

104
MCQmedium

After deploying a new Windows 11 workstation, a user complains that their screens turn off after 3 minutes of inactivity, even though they are reading documents. They want the display to stay on for at least 15 minutes. Which Settings page should you navigate to in order to change this power setting?

A.Settings > Personalization > Lock screen
B.Control Panel > Power Options > Edit Plan Settings
C.Settings > System > Power & battery > Screen and sleep
D.Settings > Accessibility > Display
AnswerC

Settings > System > Power & battery > Screen and sleep exposes the display timeout slider directly, letting you extend the screen-off interval from 3 to 15 minutes. This satisfies the stem's requirement to change the power setting controlling when the display turns off after inactivity, without touching sleep or lock behaviour.

Why this answer

The modern Windows 11 Settings app consolidates power management under System > Power & battery, where the 'Screen and sleep' section allows you to adjust the 'On battery power, turn off my screen after' and 'When plugged in, turn off my screen after' drop-downs. This directly addresses the user's complaint about the display turning off after 3 minutes of inactivity, enabling a change to 15 minutes.

Exam trap

CompTIA A+ often tests the distinction between the modern Windows 11 Settings app and the legacy Control Panel, trapping candidates who default to the familiar Control Panel path (Option B) instead of recognizing that the question explicitly asks for the 'Settings page' in Windows 11.

How to eliminate wrong answers

Option A is wrong because the Lock screen settings page controls the lock screen timeout and screen saver behavior, not the power-saving display-off timeout; it does not provide the granular 'Screen and sleep' power plan settings. Option B is wrong because while Control Panel > Power Options > Edit Plan Settings does allow changing the 'Turn off the display' timeout, the question specifies 'Which Settings page' (referring to the modern Windows 11 Settings app), and the Control Panel is a legacy interface; the exam expects the modern Settings path for Windows 11. Option D is wrong because Accessibility > Display manages visual accessibility features like text size, color filters, and contrast themes, not power-related screen-off timers.

105
MCQhard

A technician is helping a user who accidentally installed a potentially unwanted program (PUP) that changed their browser homepage and search engine. The user is embarrassed and asks the technician not to tell their manager. What is the most ethical response?

A.Agree not to tell the manager and remove the PUP quietly.
B.Explain that you will remove the PUP but must document the incident per company policy, though you will not share unnecessary details.
C.Tell the user that this is a serious security breach and you have to report it immediately.
D.Ignore the request and report the user to HR for violating IT policy.
AnswerB

This approach demonstrates both empathy for the user's honest mistake and adherence to professional IT protocols. Documenting the incident, even for a Potentially Unwanted Program (PUP), is crucial for tracking potential vulnerabilities, identifying training needs, and maintaining an accurate security log, which is often a compliance requirement. Reassuring the user that unnecessary details will not be shared helps maintain trust while fulfilling technical and policy obligations.

Why this answer

It balances the user's privacy concern with the technician's professional obligation to follow company policy. Documenting the incident (e.g., in a help desk ticket) is standard procedure for tracking PUP infections, which may indicate broader security issues like drive-by downloads or social engineering. The technician can remove the PUP using tools like Malwarebytes or AdwCleaner while omitting the user's name from unnecessary reports, preserving trust without violating policy.

Exam trap

CompTIA often tests the distinction between a 'security incident' (e.g., malware with C2 traffic) and a 'policy violation' (e.g., PUP installation), tempting candidates to overreact with option C or underreact with option A.

How to eliminate wrong answers

Option A is wrong because agreeing to hide the incident violates most corporate IT security policies, which require documentation of any unauthorized software changes to maintain an audit trail and prevent future breaches. Option C is wrong because a PUP changing browser settings is not a 'serious security breach' (e.g., no data exfiltration or privilege escalation); over-reporting it could cause unnecessary panic and damage the user-manager relationship. Option D is wrong because ignoring the user's request and immediately reporting to HR bypasses the proper escalation path (IT should handle the technical fix and documentation first) and is disproportionate for a non-malicious PUP installation.

106
MCQmedium

A user complains that their Mac running macOS Big Sur suddenly shows a message 'Your system has run out of application memory' and applications crash frequently. Activity Monitor shows high memory pressure. What is the most effective built-in tool to diagnose the cause?

A.Console
B.Disk Utility
C.Activity Monitor
D.System Information
AnswerC

Activity Monitor's Memory tab exposes memory pressure and per-process footprints, letting the technician identify which app or process is consuming RAM and causing the crashes. This directly satisfies the need to diagnose the cause of the 'out of application memory' error on macOS Big Sur.

Why this answer

Activity Monitor is the correct tool because it provides real-time metrics on memory pressure, including the 'Memory Pressure' graph, which indicates whether the system is efficiently using memory or thrashing. High memory pressure, combined with the 'Your system has run out of application memory' alert, points to excessive memory usage or a memory leak, which Activity Monitor can pinpoint by sorting processes by memory consumption.

Exam trap

CompTIA often tests whether candidates confuse 'Console' (log viewer) with 'Activity Monitor' (performance monitor), assuming that error messages logged in Console would be the primary diagnostic tool for a memory issue.

How to eliminate wrong answers

Option A is wrong because Console is used for viewing system logs and diagnostic messages, not for real-time memory pressure analysis or identifying which processes are consuming excessive memory. Option B is wrong because Disk Utility is designed for managing and repairing storage volumes, not for diagnosing memory or application memory issues. Option D is wrong because System Information provides a static overview of hardware and software configuration, but lacks the dynamic, process-level memory usage data needed to diagnose a memory pressure problem.

107
MCQeasy

A user reports that their browser frequently redirects to a different search engine, and a new toolbar has appeared. After checking the browser settings, you find the homepage has been changed and there are unknown extensions enabled. What is the most likely cause of this issue?

A.A corrupted browser cache
B.A browser hijacker installed via a malicious extension
C.An outdated browser version
D.A misconfigured proxy server
AnswerB

A browser hijacker is a specific type of malware designed to alter a web browser's settings without the user's permission. These hijackers frequently install themselves as malicious extensions, which then modify the default homepage, search engine, and crucially, inject code that forces frequent redirects to unwanted advertising, phishing sites, or other malicious domains, directly causing the reported symptom.

Why this answer

The symptoms—browser redirects, new toolbar, changed homepage, and unknown extensions—are classic signs of a browser hijacker, which is often installed via malicious extensions. These extensions modify browser settings to redirect traffic and inject ads.

Exam trap

220-1202 often tests the ability to differentiate between malware symptoms (hijacker) and benign issues (cache, outdated browser, proxy), with the trap being to attribute redirects to proxy misconfiguration when the evidence points to a malicious extension.

How to eliminate wrong answers

Option A is wrong because a corrupted browser cache typically causes rendering issues or stale content, not persistent homepage changes and new toolbars. Option C is wrong because an outdated browser version may have security vulnerabilities but does not by itself change homepage or install toolbars. Option D is wrong because a misconfigured proxy server would affect all network traffic, not just browser search redirects and toolbars.

108
MCQmedium

A company is implementing a remote access solution for employees using personal smartphones. They need to ensure that corporate email and documents are accessible but that no corporate data remains on the device if it is lost or wiped. Which technology should they use?

A.Virtual Private Network (VPN) with split tunneling.
B.Remote Desktop Protocol (RDP) to a virtual desktop.
C.Mobile Device Management (MDM) with a containerized work profile.
D.Third-party remote access software like LogMeIn.
AnswerC

Mobile Device Management (MDM) is the ideal solution as it allows IT to centrally manage, secure, and monitor mobile devices used for corporate access. A containerized work profile creates a separate, encrypted partition on the device for corporate applications and data, isolating it from personal content. This enables IT to enforce specific security policies, manage corporate applications, and perform a selective wipe of only the corporate data in the event of loss or employee departure, without affecting personal information.

Why this answer

Mobile Device Management (MDM) with a containerized work profile creates a separate, encrypted sandbox on the smartphone that stores corporate email and documents. This container can be remotely wiped by the administrator without affecting the user's personal data, ensuring no corporate data remains on a lost or wiped device.

Exam trap

CompTIA often tests the distinction between remote access technologies that only provide connectivity (VPN, RDP) versus those that enforce data separation and selective wipe (MDM containerization), leading candidates to mistakenly choose VPN or RDP for data protection requirements.

How to eliminate wrong answers

Option A is wrong because a VPN with split tunneling only encrypts traffic to the corporate network but does not prevent corporate data from being stored locally on the device; it offers no containerization or selective wipe capability. Option B is wrong because RDP to a virtual desktop streams the desktop interface but still allows data to be downloaded or copied to the local device unless strict clipboard and drive redirection policies are enforced, and it does not inherently provide a containerized work profile for mobile devices. Option D is wrong because third-party remote access software like LogMeIn provides remote control of a PC but does not isolate corporate data in a sandbox on the smartphone; data can be transferred to the device and remains there after the session ends.

109
MCQhard

A security incident occurred where an unauthorized user accessed a workstation. You need to review the event logs to determine when the breach happened. Which Control Panel applet would you use to launch the Event Viewer?

A.System
B.Security and Maintenance
C.Administrative Tools
D.Device Manager
AnswerC

The 'Administrative Tools' folder is the designated location within Windows for a collection of advanced system utilities and management consoles, specifically designed for administrators and power users. This comprehensive suite includes essential tools like Event Viewer, Performance Monitor, Services, and Computer Management, which are critical for diagnosing system issues, monitoring performance, and investigating security incidents. Accessing Event Viewer through Administrative Tools provides the necessary interface to review detailed security logs for unauthorized access.

Why this answer

Administrative Tools is the Control Panel applet that provides access to advanced system tools, including Event Viewer. To investigate a security breach, you would open Administrative Tools and then launch Event Viewer to review security logs for unauthorized access events. This is the correct path because Event Viewer is not directly listed in the main Control Panel categories; it is nested within Administrative Tools.

Exam trap

CompTIA often tests the distinction between the Security and Maintenance applet (which shows security status but not logs) and Administrative Tools (which contains Event Viewer), leading candidates to mistakenly choose Security and Maintenance because of the word 'Security' in the name.

How to eliminate wrong answers

Option A is wrong because System applet displays basic system information, hardware properties, and performance settings, but does not include a direct link to Event Viewer. Option B is wrong because Security and Maintenance provides system health reports and security status summaries, but it does not host Event Viewer; it may link to troubleshooting tools but not the event log viewer itself. Option D is wrong because Device Manager is used to manage hardware devices and drivers, not to review system or security event logs.

110
MCQmedium

A customer calls the help desk stating that their computer displays 'Bootmgr is missing' and will not start Windows. You suspect the Boot Configuration Data (BCD) is corrupted. Which command-line tool should you use from the Windows Recovery Environment to repair the BCD?

A.chkdsk /r
B.bootrec /rebuildbcd
C.sfc /scannow
D.diskpart
AnswerB

The `bootrec /rebuildbcd` command is the appropriate solution for repairing boot configuration issues, as it specifically scans all hard drives for compatible Windows installations and then adds them to the Boot Configuration Data (BCD) store. This process effectively reconstructs a corrupted or missing BCD, resolving common boot errors such as 'Bootmgr is missing' or when the system fails to locate the operating system. It ensures the boot loader has the correct entries to successfully start Windows.

Why this answer

'Bootmgr is missing' indicates the Windows Boot Manager cannot locate the Boot Configuration Data (BCD) store, and 'bootrec /rebuildbcd' is the dedicated Windows RE command that scans for Windows installations and rebuilds the BCD from scratch. Running it from the Recovery Environment's command prompt restores the boot entries needed to start Windows. This is the standard CompTIA-prescribed fix for BCD corruption.

Exam trap

220-1202 often tests the confusion between boot-repair tools (bootrec, bcdboot) and system-file tools (sfc, chkdsk), causing candidates to pick sfc /scannow for boot errors it cannot fix.

How to eliminate wrong answers

Option A is wrong because 'chkdsk /r' repairs file-system and bad-sector errors on a volume; it does not rebuild boot configuration data and will not resolve a missing boot manager. Option C is wrong because 'sfc /scannow' repairs protected Windows system files but cannot run against an offline, unbootable OS and does not touch the BCD store. Option D is wrong because 'diskpart' is a disk-partitioning utility for creating, deleting, and managing volumes; it has no role in repairing boot configuration.

111
MCQeasy

A user reports that their workstation is running slowly and they see a pop-up claiming their files are encrypted and a ransom must be paid. They cannot open any documents. What type of malware is most likely responsible?

A.Spyware
B.Ransomware
C.Trojan horse
D.Rootkit
AnswerB

Ransomware is a type of malicious software that encrypts a victim's files, rendering them inaccessible, and then demands a ransom payment, typically in cryptocurrency, for the decryption key. The initial encryption process can significantly slow down a workstation, and the subsequent display of a ransom note directly matches the described symptoms of a system running slowly and demanding payment. This attack directly targets data availability and extorts payment.

Why this answer

Ransomware encrypts files and demands payment for decryption. This scenario describes classic ransomware behavior, where the user is locked out of their data and a ransom note is displayed.

112
MCQmedium

A company is deploying new laptops to remote workers. They need to ensure that if a laptop is stolen, the data on it cannot be accessed. Which two physical security controls should be configured before shipment?

A.Cable lock and privacy filter.
B.Full-disk encryption and a BIOS/UEFI password.
C.Smart card reader and biometric scanner.
D.Asset tracking tag and a Kensington lock slot.
AnswerB

Full-disk encryption (FDE) renders all data on the laptop's storage unreadable without the correct decryption key, effectively protecting sensitive information even if the physical device is lost or stolen and the drive is removed. A BIOS/UEFI password prevents unauthorized users from booting the system from external media, disabling security features, or altering critical boot settings, thereby reinforcing the FDE by preventing bypass attempts. This combination directly addresses both data confidentiality and system integrity for remote workers.

Why this answer

Full-disk encryption protects data at rest, and a BIOS/UEFI password prevents unauthorized booting or tampering with boot settings. This question tests the combination of controls needed for remote device security.

113
MCQhard

A technician is troubleshooting an Android device that has a corporate email account configured. The user can send emails but cannot receive any. The email server uses IMAP. The technician has verified the username and password are correct. What should the technician check next?

A.Check if the device's date and time are correct.
B.Check the incoming mail server settings (IMAP).
C.Check if the email account has exceeded its storage quota.
D.Check if the device is in power-saving mode.
AnswerB

Since the technician has confirmed that sending emails (SMTP) functions correctly, the problem is isolated to the incoming mail service. This strongly suggests an issue with the device's configuration for the incoming mail server, typically IMAP (Internet Message Access Protocol). Common misconfigurations include an incorrect server hostname, an incorrect port number (e.g., 993 for IMAPS, 143 for IMAP), or incorrect security type (SSL/TLS).

Why this answer

Since the user can send emails but not receive them, the issue is isolated to the incoming mail path. IMAP uses port 143 (or 993 for SSL/TLS) to retrieve messages, and the incoming server settings (server address, port, security type) must match the corporate email configuration. Incorrect IMAP settings would prevent the device from connecting to the server to download new emails, while SMTP (outgoing) settings remain unaffected, explaining the send-only symptom.

Exam trap

CompTIA often tests the distinction between incoming and outgoing mail protocols (IMAP vs. SMTP) to see if candidates understand that a send-only failure points to the incoming server settings, not authentication or device-level issues.

How to eliminate wrong answers

Option A is wrong because incorrect date and time typically cause SSL/TLS certificate validation failures, which would affect both sending and receiving if the device cannot establish a secure connection; it would not selectively block only incoming mail. Option C is wrong because exceeding the storage quota would prevent the server from accepting new incoming messages, but the client would still be able to connect and see the mailbox (possibly with an error), and the user would also likely be unable to send if the quota is full on the server side. Option D is wrong because power-saving mode may delay background sync or reduce network activity, but it would not permanently prevent receiving emails; the user could still manually refresh or receive emails when the device exits power-saving mode, and sending would also be affected if network access is restricted.

114
MCQmedium

A technician is troubleshooting a batch script that is supposed to delete temporary files older than 30 days. The script runs without errors but does not delete any files. The technician suspects the script's logic is flawed. Which part of the script is most likely incorrect?

A.The script uses the 'del' command without a path
B.The script uses 'forfiles' with the wrong date syntax
C.The script runs as a standard user without admin rights
D.The script uses 'echo' instead of 'del'
AnswerB

Correct. Forfiles uses the '/d' parameter with a date string like '-30' for days. If the syntax is wrong (e.g., using '30' instead of '-30'), it will not match any files.

Why this answer

The 'forfiles' command in Windows uses a specific date syntax with the `/d` parameter. The correct syntax for files older than 30 days is `forfiles /d -30` (negative number means older than). If the script uses a positive number or an incorrect date format like `+30` or `30 days ago`, it will not match any files, resulting in no deletions.

This is the most likely flaw given the symptom of no errors but no action.

Exam trap

CompTIA A+ often tests the subtle difference between positive and negative date offsets in the 'forfiles' command, knowing that candidates may assume a positive number means 'older than' based on experience with other tools like Linux 'find'.

How to eliminate wrong answers

Option A is wrong because the 'del' command without a path would default to the current directory, which could still delete files if the script is in the correct folder; the issue is not about missing a path but about the selection logic. Option C is wrong because deleting temporary files in user-writable locations (like %TEMP%) does not require admin rights; standard users can delete their own temp files. Option D is wrong because if the script used 'echo' instead of 'del', it would output the file names but not delete them, which would be noticeable to the technician; the symptom states the script runs without errors but does not delete files, implying the deletion command is present but not targeting the correct files.

115
MCQeasy

A small business wants to ensure that only authorized personnel can access the server room. The budget is limited, and they need a simple, cost-effective solution. Which logical security control should they implement first?

A.Install a biometric fingerprint scanner on the door.
B.Require a smart card or key fob to unlock the door.
C.Implement a strong password policy for all user accounts.
D.Hire a security guard to check IDs at the entrance.
AnswerB

Smart cards and key fobs provide a logical access control mechanism by requiring a physical token for authentication to an electronic door system. These devices are relatively inexpensive to implement and manage, offering a scalable solution for a small business to ensure only authorized personnel can physically access a restricted area. Their access privileges can be centrally managed and quickly revoked or modified, enhancing both security and operational efficiency.

Why this answer

A smart card or key fob provides a simple, cost-effective logical access control for the server room door. It authenticates users via a physical token and a PIN or proximity reader, which is far cheaper than biometric systems and more reliable than a password policy that doesn't control physical entry. This directly restricts physical access to authorized personnel without ongoing costs like a security guard.

Exam trap

CompTIA often tests the distinction between logical and physical security controls, and the trap here is that candidates confuse a strong password policy (a logical control for user accounts) with a physical access control mechanism for a server room door.

How to eliminate wrong answers

Option A is wrong because biometric fingerprint scanners are significantly more expensive to purchase, install, and maintain, and they often require ongoing calibration and user enrollment, making them unsuitable for a limited budget. Option C is wrong because a strong password policy controls logical access to user accounts and network resources, not physical entry to a server room; it does not prevent an unauthorized person from walking through the door. Option D is wrong because hiring a security guard is a recurring, high-cost solution that exceeds the limited budget and is not a logical security control—it is a physical security measure.

116
MCQmedium

You are configuring a new Windows 10 workstation for a remote employee who will connect to the corporate VPN. The user should not be able to install software or change system settings. Which tool should you use to enforce these restrictions?

A.User Account Control (UAC) settings
B.Local Group Policy Editor
C.Device Manager
D.Registry Editor
AnswerB

The Local Group Policy Editor (gpedit.msc) is a powerful administrative tool available in Windows Pro and Enterprise editions, enabling administrators to configure security settings, software installation policies, and user environment settings for the local computer or specific users/groups. It provides granular control, including the ability to restrict access to the Control Panel and prevent users from installing software. These policies are persistent and apply across user sessions and reboots, making it an effective method for workstation hardening and enforcing compliance.

Why this answer

Local Group Policy Editor is the correct tool because it allows an administrator to enforce restrictions on user accounts, such as preventing software installation and system settings changes. It provides granular control over user rights and permissions through Group Policy Objects (GPOs). This is the standard method for applying such restrictions in a Windows environment.

Exam trap

220-1202 often tests the difference between UAC and Group Policy; candidates may think UAC can enforce restrictions, but UAC only controls elevation, not permissions.

How to eliminate wrong answers

Option A is wrong because User Account Control (UAC) settings manage elevation prompts but do not prevent users from installing software or changing settings if they have administrative rights. Option C is wrong because Device Manager is used to manage hardware devices, not to enforce software installation or system settings restrictions. Option D is wrong because Registry Editor is a tool for editing the registry directly, but it is not a policy enforcement tool; using it to restrict users is cumbersome and not recommended.

117
MCQhard

A technician is configuring a kiosk mode on a company-owned Android tablet for customer use. After enabling the dedicated device management app, the tablet still allows users to exit the kiosk app by pressing the home button. Which setting did the technician MOST likely overlook?

A.The tablet's screen timeout setting.
B.The 'Lock task mode' or 'Pin app' feature.
C.The tablet's Wi-Fi configuration.
D.The device's date and time settings.
AnswerB

The 'Lock task mode' on Android, often referred to as 'App Pinning' or 'Screen Pinning,' is the fundamental feature used to configure a device for kiosk mode. This functionality prevents users from exiting a designated application, disabling navigation buttons like Home, Back, and Recent Apps, and restricting access to notifications or quick settings. It effectively locks the device into a single application, ensuring the intended kiosk experience without unauthorized access to other device features.

Why this answer

The technician enabled the dedicated device management app but did not activate Android's 'Lock task mode' (or 'Pin app' feature). This mode is required to pin the kiosk app to the foreground and block system navigation keys (Home, Recent Apps), preventing users from exiting the app. Without it, the Home button remains functional, allowing escape from the kiosk environment.

Exam trap

CompTIA often tests the distinction between enabling a dedicated device management app and actually locking the device into kiosk mode, leading candidates to overlook the mandatory 'Lock task mode' or 'Pin app' configuration step.

How to eliminate wrong answers

Option A is wrong because screen timeout settings control display sleep duration, not the ability to exit a kiosk app via the Home button. Option C is wrong because Wi-Fi configuration affects network connectivity, not the enforcement of app pinning or navigation blocking. Option D is wrong because date and time settings are unrelated to kiosk mode behavior; they do not prevent the Home button from exiting the app.

118
Multi-Selectmedium

A technician is troubleshooting a Windows 10 workstation that fails to boot. The technician suspects a problem with the boot configuration data (BCD). Which two commands can be used to rebuild the BCD? (Choose two.)

Select 2 answers
A.bootrec /fixboot
B.bootrec /fixmbr
C.bootrec /rebuildbcd
D.bcdedit /export
E.bcdboot C:\Windows
AnswersC, E

bootrec /rebuildbcd scans the disk for Windows installations and allows you to select which ones to add to the BCD store. It is a standard command in the Windows Recovery Environment to repair boot issues. This command directly addresses rebuilding the BCD, making it a correct choice.

Why this answer

The two commands that rebuild the BCD are bootrec /rebuildbcd and bcdboot. bootrec /rebuildbcd scans for Windows installations and rebuilds the BCD store, while bcdboot creates or repairs the BCD and boot files from a specified Windows directory. The other commands either back up, fix the boot sector, or fix the MBR, but do not rebuild the BCD.

Exam trap

The trap here is confusing bootrec /fixboot or /fixmbr with BCD repair, when they address different boot components.

119
MCQhard

A company policy requires that all web traffic from employee computers be filtered to block known malicious sites. You need to implement this without installing client software on each machine. Which approach should you use?

A.Configure each browser's proxy settings to use a filtering proxy server.
B.Enable Windows Defender SmartScreen on each computer via Group Policy.
C.Implement a DNS-based content filtering service on the network's DNS server.
D.Install a third-party browser extension on all browsers to block malicious sites.
AnswerC

A DNS-based content filtering service intercepts and evaluates all DNS queries originating from devices on the network at the DNS server level. If a query attempts to resolve a domain categorized as malicious or undesirable, the DNS server can block the resolution or redirect it to a safe page, effectively preventing access to the site. This method operates transparently at the network infrastructure layer, requiring no client-side software installation or configuration on individual user devices to enforce its policies across all web traffic.

Why this answer

DNS-based content filtering operates at the network level, blocking resolution of domains known to host malicious content. This approach requires no client software, as all DNS queries from employee computers are intercepted and filtered by the network's DNS server, enforcing the policy transparently.

Exam trap

The 220-1202 exam often tests the distinction between client-side and network-level security controls, and the trap here is assuming that proxy settings or browser extensions are acceptable when the question explicitly prohibits installing client software.

How to eliminate wrong answers

Option A is wrong because configuring each browser's proxy settings manually is not a scalable, clientless solution; it requires per-machine configuration and can be bypassed if users change proxy settings. Option B is wrong because Windows Defender SmartScreen is a client-side feature that must be enabled via Group Policy, which still relies on the Windows operating system on each machine and does not meet the 'without installing client software' requirement. Option D is wrong because installing a third-party browser extension requires client-side installation on each browser, violating the no-client-software constraint.

120
MCQhard

A technician is troubleshooting a Windows 10 workstation that repeatedly displays a message stating "The User Profile Service failed the logon. User profile cannot be loaded." The user can log in with a different account. Which of the following should the technician do to allow the user to log in with their original profile while preserving their data?

A.Delete the user's profile folder from C:\Users and have the user log in again.
B.Recreate the user's account and copy the contents of the old profile folder to the new one.
C.Run the System File Checker (SFC) utility to repair corrupted system files.
D.Use the Registry Editor to modify the ProfileList key and remove the .bak extension from the user's SID.
AnswerD

This error often occurs when the user's profile is corrupted, and the ProfileList registry key may have a .bak extension appended to the user's SID. Removing the .bak extension and ensuring the correct profile path is set can restore the profile without losing data. This is a standard fix for this specific error.

Why this answer

The "User Profile Service failed the logon" error typically stems from a corrupted user profile, often indicated by a .bak extension on the user's SID in the ProfileList registry key. Removing the .bak extension and correcting the profile path restores the original profile without data loss. Other methods either delete data or are less direct.

Exam trap

The trap here is jumping to profile deletion or recreation when a simple registry edit can resolve the issue while preserving user data.

121
MCQmedium

A technician is configuring a VPN for a remote user. The user's home router uses NAT, and the technician wants to ensure the VPN traffic is encapsulated and encrypted. Which VPN protocol should the technician choose for the best balance of security and compatibility?

A.PPTP
B.L2TP/IPsec
C.OpenVPN
D.SSTP
AnswerC

OpenVPN is an open-source VPN solution that leverages the OpenSSL library for robust encryption and authentication, supporting a wide range of cryptographic algorithms. It is highly flexible, capable of operating over both UDP and TCP protocols, which allows it to effectively traverse firewalls and Network Address Translation (NAT) devices by encapsulating traffic within standard ports like 443. Its strong security, cross-platform compatibility, and extensive configurability make it an excellent and reliable choice for secure remote access.

Why this answer

OpenVPN is the correct choice because it provides a robust balance of security and compatibility, especially for remote users behind NAT. It uses SSL/TLS for encryption and can operate over a single UDP or TCP port (typically 1194), which easily traverses NAT without requiring additional configuration. Unlike L2TP/IPsec, OpenVPN does not rely on IPsec's NAT-sensitive protocols like ESP, making it more reliable across home routers.

Exam trap

CompTIA often tests the misconception that L2TP/IPsec is always the best for security and compatibility, but the trap here is that IPsec's ESP protocol can fail with NAT unless NAT-T is enabled, making OpenVPN a more practical choice for remote users behind home routers.

How to eliminate wrong answers

Option A is wrong because PPTP uses outdated MPPE encryption (RC4) and has known vulnerabilities, making it insecure for modern use. Option B is wrong because L2TP/IPsec can have issues with NAT traversal due to IPsec's ESP protocol, often requiring NAT-T or additional router configuration, which reduces compatibility with home routers. Option D is wrong because SSTP is primarily designed for Windows environments and uses TCP port 443, which can be blocked or throttled by some firewalls, and it lacks the cross-platform compatibility of OpenVPN.

122
MCQhard

A company uses a private cloud for its internal applications. The IT team wants to ensure that if one physical host fails, the virtual machines running on it can be automatically restarted on another host with minimal downtime. Which feature should they implement?

A.Fault tolerance
B.High availability
C.Live migration
D.Snapshots
AnswerB

High availability continuously monitors host health and automatically restarts affected virtual machines on surviving hosts within the cluster, satisfying the requirement for automatic recovery with minimal downtime when a physical host fails. Unlike fault tolerance, which maintains a live mirrored instance, high availability accepts brief restart interruption.

Why this answer

High availability (HA) is the correct feature because it is designed to automatically restart virtual machines on a surviving host within a cluster when a physical host fails. HA uses heartbeat monitoring between hosts and a resource manager to detect failures and trigger VM restarts, minimizing downtime without requiring manual intervention.

Exam trap

CompTIA A+ candidates often confuse High Availability (automatic restart after failure) with Fault Tolerance (continuous uptime with a secondary VM), leading them to mistakenly choose FT when the question asks for automatic restart with minimal downtime rather than zero downtime.

How to eliminate wrong answers

Option A is wrong because Fault Tolerance (FT) provides continuous availability by maintaining a secondary VM in lockstep with the primary, but it is not designed for automatic restart after host failure—it requires a secondary host to be pre-configured and has high resource overhead. Option C is wrong because Live Migration (vMotion) moves a running VM from one host to another with zero downtime, but it is a manual or scheduled process and does not automatically respond to a host failure. Option D is wrong because Snapshots capture the state of a VM at a point in time for backup or rollback purposes, but they do not provide any automatic restart or failover capability when a host fails.

123
MCQmedium

A user reports that their web browser's homepage has changed to an unfamiliar search engine, and new toolbars have appeared without their consent. They have not installed any new software recently. Which type of malware is most likely responsible?

A.Trojan horse
B.Worm
C.Browser hijacker
D.Ransomware
AnswerC

A browser hijacker is a type of unwanted software that modifies a web browser's settings without the user's permission. This typically includes changing the default homepage, search engine, or installing unwanted toolbars and extensions. The objective is often to redirect traffic to specific websites, display advertisements, or collect browsing data, significantly impacting the user's browsing experience and privacy.

Why this answer

The symptoms—unwanted homepage changes, unfamiliar search engine, and new toolbars—are classic signs of a browser hijacker. This malware modifies browser settings (e.g., via registry keys or extension policies) without user consent, often bundled with freeware or installed through drive-by downloads. Unlike other malware types, it specifically targets the browser's configuration to redirect traffic and generate ad revenue.

Exam trap

CompTIA often tests the distinction between malware types by focusing on specific symptoms—here, the trap is that candidates confuse a browser hijacker with a Trojan horse because both can be installed without consent, but only the hijacker directly targets browser settings.

How to eliminate wrong answers

Option A is wrong because a Trojan horse masquerades as legitimate software to perform malicious actions (e.g., data theft or backdoor access), but it does not specifically alter browser settings or add toolbars as its primary function. Option B is wrong because a worm self-replicates across networks to spread, often exploiting vulnerabilities, but it does not typically modify browser homepages or install toolbars. Option D is wrong because ransomware encrypts files or locks the system to demand payment, not change browser settings or add toolbars.

124
MCQeasy

A small business uses a cloud-based accounting application. Several employees report that they can no longer access the application, and they receive a message stating that the service is temporarily unavailable. The business's internet connection is working, and other cloud services are accessible. What is the most likely cause of this issue?

A.The user's browser cache is corrupted.
B.The cloud service provider is experiencing an outage.
C.The business's firewall is blocking the accounting application.
D.The employees' user accounts have been disabled.
AnswerB

Other cloud services work and the local internet link is fine, so the fault lies beyond the business network. A provider-side outage makes the accounting service itself unreachable while everything else remains accessible, matching the temporary unavailability message.

Why this answer

The scenario describes a service-specific outage: the cloud-based accounting application is inaccessible while other cloud services and the internet connection remain functional. This pattern—one application failing while others work—strongly indicates that the issue is isolated to that particular cloud service provider, not the local network or user accounts. A provider outage would cause the 'temporarily unavailable' message, as the application's servers are unreachable.

Exam trap

CompTIA A+ often tests the distinction between client-side issues (cache, firewall, account status) and provider-side outages by presenting a scenario where only one service fails, tempting candidates to blame local configuration rather than recognizing the service-specific outage pattern.

How to eliminate wrong answers

Option A is wrong because a corrupted browser cache would typically cause display or loading issues for a single user, not a service-wide 'temporarily unavailable' message affecting multiple employees simultaneously; clearing the cache might resolve local rendering problems but cannot block access to a remote server. Option C is wrong because if the business's firewall were blocking the accounting application, it would affect all cloud services or at least produce a different error (e.g., connection timeout or access denied), not a provider-side 'temporarily unavailable' message, and other cloud services remain accessible. Option D is wrong because disabled user accounts would result in authentication failures (e.g., 'invalid credentials' or 'account locked') for each affected employee, not a generic 'service temporarily unavailable' message that appears before login.

125
MCQmedium

A user reports that when visiting a banking website, the browser displays a warning that the site's certificate is not trusted, even though the site worked yesterday. The technician verifies the system clock is correct and the network is functioning. Which of the following is the MOST likely cause?

A.The user's account password has expired.
B.The root certificate for the issuing CA was removed from the Trusted Root Certification Authorities store.
C.The website's TLS certificate has expired.
D.The DNS server is resolving the banking site to an incorrect IP address.
AnswerB

If the root CA certificate is missing from the Trusted Root Certification Authorities store, the browser cannot build a chain of trust to the site's certificate, producing an untrusted warning. Since the clock and network are fine, removal of the root certificate is the most likely cause. Reinstalling the root CA or using a trusted root update resolves the issue.

Why this answer

A browser trusts a TLS certificate only if it can chain it to a root CA in the Trusted Root Certification Authorities store. If that root was removed, the chain breaks and the browser warns that the certificate is not trusted. An expired certificate or DNS problem could also cause warnings, but the sudden failure with a correct clock points to a missing root certificate.

Exam trap

The trap here is assuming any certificate warning means the site's certificate expired, without considering that a missing root CA also breaks the trust chain.

126
MCQmedium

A technician is troubleshooting a Windows 10 workstation that is running very slowly. The technician suspects a malware infection. Which of the following should the technician do FIRST according to best practices for malware removal?

A.Quarantine the system by disconnecting it from the network.
B.Restore the system from a known good backup.
C.Educate the end user about safe browsing habits.
D.Run a full antivirus scan immediately.
AnswerA

Disconnecting the system from the network prevents the malware from spreading or communicating with command-and-control servers. This is the first step in the malware removal process to contain the infection. It also preserves evidence and prevents further damage while the technician investigates. Quarantining is a critical initial action before attempting removal.

Why this answer

The first step in malware removal is to quarantine the infected system by disconnecting it from the network. This prevents the malware from spreading to other systems and stops any remote communication. Only after isolation should the technician proceed with scanning, removal, and recovery.

Educating the user and restoring from backup are subsequent steps.

Exam trap

The trap here is jumping straight to scanning or restoring, but containment must come first to prevent the malware from spreading.

127
MCQhard

A technician is investigating a data breach and discovers that an attacker obtained sensitive files by searching through the company's recycling bins. The bins contained printed reports with customer names and account numbers. What social engineering attack was used?

A.Tailgating
B.Shoulder surfing
C.Dumpster diving
D.Phishing
AnswerC

Dumpster diving is a social engineering and physical security vulnerability exploitation technique where an attacker sifts through an organization's or individual's discarded trash to find sensitive information. This can include anything from financial statements, employee records, network diagrams, or even sticky notes with passwords, all of which could be used to facilitate further attacks or breaches. It directly involves the recovery of improperly disposed physical documents or media.

Why this answer

Dumpster diving is the social engineering attack where an attacker retrieves discarded materials, such as printed documents, to obtain sensitive information. In this scenario, the attacker searched through recycling bins and found printed reports with customer data, which is a classic example of dumpster diving.

Exam trap

220-1202 often tests the confusion between dumpster diving and other physical social engineering attacks like tailgating or shoulder surfing, but the key differentiator is the retrieval of discarded materials.

How to eliminate wrong answers

Option A is wrong because tailgating involves following an authorized person into a secure area, not searching through trash. Option B is wrong because shoulder surfing involves directly observing someone entering sensitive information, not retrieving discarded documents. Option D is wrong because phishing involves deceptive emails or messages to trick users into revealing information, not physical retrieval of trash.

128
MCQmedium

A system administrator needs to find all files in /var/log that have been modified in the last 24 hours to check for recent activity. Which command accomplishes this?

A.find /var/log -mtime -1
B.find /var/log -atime -1
C.find /var/log -ctime -1
D.find /var/log -mmin -1440
AnswerA

This correctly finds files modified within the last 24 hours using -mtime -1.

Why this answer

The `find` command with `-mtime -1` searches for files whose content (modification time) was changed within the last 24 hours. This is exactly what the administrator needs to check for recent activity in /var/log.

Exam trap

CompTIA often tests the distinction between `-mtime` (modification), `-atime` (access), and `-ctime` (inode change), and candidates frequently confuse `-ctime` with content modification or pick `-atime` thinking 'activity' includes reads.

How to eliminate wrong answers

Option B is wrong because `-atime -1` checks access time (last read), not modification time, so it would include files that were only read but not changed. Option C is wrong because `-ctime -1` checks inode change time (metadata changes like permissions or ownership), not file content modification. Option D is wrong because `-mmin -1440` checks for files modified within the last 1440 minutes (24 hours), which is functionally equivalent to `-mtime -1`, but the question asks for a command that 'accomplishes this' and option A is the standard, correct syntax; option D uses minutes instead of days and is less common, but more importantly, the exam expects `-mtime -1` as the precise answer.

129
MCQeasy

A user in the accounting department cannot print to a network printer that other users can access. They are running Windows 10. When they try to print, they get a message: 'Windows cannot connect to the printer. Access is denied.' What is the most likely cause of this issue?

A.The printer driver is corrupt on the user's computer.
B.The network cable is unplugged from the user's computer.
C.The user does not have permission to use the printer.
D.The printer is out of paper or toner.
AnswerC

An access-denied error when connecting to a shared printer indicates the print server is rejecting the user's credentials, so the account lacks print permission on that printer. Other users succeed because their accounts are granted access through the printer's security settings.

Why this answer

The error message 'Access is denied' specifically indicates a permissions issue at the printer or print server level, not a connectivity or hardware problem. Since other users can print successfully, the printer and network are functional, isolating the cause to the user's lack of permission to use the printer. In Windows, printer permissions are managed via the Security tab in printer properties, where the 'Print' permission must be granted to the user or their group.

Exam trap

The trap here is that candidates may assume a generic 'cannot connect' error implies a network or driver problem, ignoring the specific 'Access is denied' wording that points directly to permissions.

How to eliminate wrong answers

Option A is wrong because a corrupt printer driver would typically cause a different error, such as 'Driver is unavailable' or print job failures, not an 'Access is denied' message. Option B is wrong because an unplugged network cable would result in a 'No network connection' or 'Printer not found' error, not an access-denied message, and other users would also be affected if the network were down. Option D is wrong because an out-of-paper or toner condition generates printer-specific status messages (e.g., 'Out of paper' or 'Toner low') on the printer display or in the print queue, not an 'Access is denied' error on the client computer.

130
MCQhard

A user's Windows 10 laptop fails to boot and shows 'INACCESSIBLE_BOOT_DEVICE' blue screen error. The technician suspects a recent driver update for the storage controller. Which recovery environment command can be used to disable the problematic driver from loading?

A.Run 'bcdedit /set {default} safeboot minimal' from the recovery command prompt.
B.Run 'diskpart' and then 'clean' to wipe the disk.
C.Run 'chkdsk /f' to fix file system errors.
D.Run 'bootrec /fixboot' to repair the boot sector.
AnswerA

The 'bcdedit /set {default} safeboot minimal' command modifies the Boot Configuration Data (BCD) store, instructing the Windows Boot Manager to load the operating system in Safe Mode on the next startup. Safe Mode loads only essential drivers and services, effectively bypassing potentially corrupted or incompatible drivers that are preventing a normal boot. This allows a technician to access the system, diagnose the problematic driver, and perform necessary repairs like driver rollback, uninstallation, or system restore.

Why this answer

The 'INACCESSIBLE_BOOT_DEVICE' error often occurs after a faulty storage controller driver update. Booting into Safe Mode with minimal drivers can bypass the problematic driver. The command 'bcdedit /set {default} safeboot minimal' configures the boot loader to start Windows in Safe Mode on the next restart, loading only essential drivers and services, which allows the technician to roll back or uninstall the offending driver.

Exam trap

The trap here is that candidates often confuse 'bcdedit' with 'bootrec' commands, assuming 'bootrec /fixboot' or 'chkdsk' can resolve driver-related boot failures, when in fact only Safe Mode or driver rollback via the recovery environment addresses the root cause.

How to eliminate wrong answers

Option B is wrong because 'diskpart clean' wipes the entire disk partition table, destroying all data and making the system unbootable — it does not disable a driver. Option C is wrong because 'chkdsk /f' repairs file system corruption, not driver-related boot failures; it cannot disable a storage controller driver. Option D is wrong because 'bootrec /fixboot' rewrites the boot sector code, which addresses bootloader corruption but does not prevent a specific driver from loading.

131
MCQmedium

A system administrator configures a new VPN server for remote employees. The requirement is that all traffic from the remote user's device must be routed through the corporate network to enforce security policies. Which VPN protocol setting should the administrator enable?

A.Enable split tunneling
B.Disable split tunneling
C.Use PPTP instead of L2TP
D.Increase the MTU size
AnswerB

Disabling split tunneling, also known as implementing a full tunnel VPN, forces all network traffic originating from the client device to traverse the secure VPN tunnel to the corporate network before reaching any destination, including the public internet. This ensures that every packet is subjected to the organization's security controls, such as firewalls, intrusion detection systems, and content filters, thereby enforcing comprehensive corporate security policies on all user activity. This configuration is essential when the objective is to secure and monitor all outbound traffic.

Why this answer

Disabling split tunneling ensures that all traffic from the remote user's device is routed through the corporate VPN tunnel, enforcing security policies such as content filtering and intrusion detection. When split tunneling is enabled, only traffic destined for the corporate network goes through the VPN, while internet-bound traffic bypasses it, violating the requirement. This setting is typically configured in the VPN client or server profile (e.g., using the 'DisableSplitTunneling' registry key on Windows or the 'tunnel-all' directive in OpenVPN).

Exam trap

CompTIA often tests the misconception that the choice of VPN protocol (PPTP vs. L2TP) determines traffic routing behavior, when in fact split tunneling is a separate policy setting that must be explicitly enabled or disabled.

How to eliminate wrong answers

Option A is wrong because enabling split tunneling would allow remote users to access the internet directly without traversing the corporate network, which directly contradicts the requirement to route all traffic through the corporate network. Option C is wrong because using PPTP instead of L2TP does not affect traffic routing behavior; PPTP and L2TP are tunneling protocols that encapsulate data, but split tunneling is a separate routing policy that must be configured regardless of the protocol chosen. Option D is wrong because increasing the MTU size addresses packet fragmentation issues, not traffic routing; it can improve performance but does not enforce that all traffic is sent through the VPN tunnel.

132
MCQeasy

A small business wants to prevent unauthorized individuals from following employees through a secure entrance after badge access is granted. Which physical security control is specifically designed to address this threat?

A.Install a biometric fingerprint scanner
B.Use a proximity card reader
C.Deploy a mantrap
D.Add a security guard
AnswerC

A mantrap, also known as an access control vestibule, consists of two interlocking doors where only one door can be open at a time. An individual enters the first door, which then closes and locks behind them, creating a secure chamber for authentication. Their identity is verified within this chamber, and only then does the second door open, allowing them to proceed. This physical isolation mechanism effectively prevents tailgating or piggybacking by ensuring only one person can pass through the controlled area per authentication cycle.

Why this answer

A mantrap is a physical security control consisting of two interlocking doors with a small vestibule between them. It prevents tailgating by allowing only one person to enter at a time; the first door must close and lock before the second door can open, ensuring that only the authenticated individual passes through.

Exam trap

The trap here is that candidates confuse authentication controls (biometrics, card readers) with access control mechanisms that prevent tailgating, failing to recognize that authentication alone does not enforce single-person entry.

How to eliminate wrong answers

Option A is wrong because a biometric fingerprint scanner authenticates identity but does not prevent an unauthorized person from following an authorized user through the door after access is granted. Option B is wrong because a proximity card reader grants access based on a card but offers no mechanism to stop tailgating once the door is opened. Option D is wrong because a security guard can monitor and intervene, but the question asks for a control specifically designed to address tailgating; a mantrap is a dedicated engineered solution, whereas a guard is a human control that may be inconsistent or bypassed.

133
MCQmedium

A user reports that their Android phone's Bluetooth keeps disconnecting from their car's hands-free system. The technician has already cleared the Bluetooth cache and re-paired the devices. What should the technician do NEXT?

A.Perform a factory reset on the phone.
B.Update the car's infotainment system firmware.
C.Replace the phone's Bluetooth antenna.
D.Disable Bluetooth power saving mode on the phone.
AnswerB

Updating the car's infotainment system firmware is often the most effective and targeted solution for Bluetooth connectivity issues with specific phone models. Car manufacturers frequently release firmware revisions that include updated Bluetooth profiles, codecs, and drivers to improve compatibility with newer smartphone operating systems and hardware. This addresses potential discrepancies in Bluetooth protocol implementations between the car and the Android phone, which is a common cause of such problems.

Why this answer

After basic troubleshooting (cache clear and re-pair) fails, the next logical step is to check for firmware updates on the car's infotainment system. Bluetooth connectivity issues between a phone and a car are often caused by incompatibilities or bugs in the car's Bluetooth stack, which can be resolved by updating the car's firmware. The technician should prioritize updating the car's system before considering hardware replacement or more drastic phone resets.

Exam trap

The trap here is that candidates may assume the phone is always at fault and jump to a factory reset (Option A) or hardware replacement (Option C), when in reality the car's infotainment firmware is a frequent source of Bluetooth instability that should be addressed first.

How to eliminate wrong answers

Option A is wrong because a factory reset on the phone is a drastic step that should only be taken after exhausting all other software-based troubleshooting; it would delete all user data and is unlikely to fix a Bluetooth issue that persists after cache clearing and re-pairing, especially if the problem is on the car side. Option C is wrong because replacing the phone's Bluetooth antenna is a hardware repair that is premature at this stage; Bluetooth disconnections are rarely caused by a faulty antenna, and the technician has not yet ruled out software or firmware issues on either device. Option D is wrong because disabling Bluetooth power saving mode on the phone is a valid step but should have been considered earlier in the troubleshooting process (e.g., before or alongside cache clearing); it is not the next best step after cache clearing and re-pairing, and the question implies those steps have already been done without success.

134
MCQeasy

A help desk technician receives a complaint that a shared network printer is no longer accessible after a scheduled firmware update was applied to the print server last night. The change was documented but no rollback plan was included. What should the technician do first?

A.Reboot the print server to clear any temporary errors.
B.Restore the print server to its previous firmware version.
C.Submit a new change request to update the firmware again.
D.Disable the printer in Active Directory and re-add it.
AnswerB

When a recent firmware update is identified as the cause of an outage, rolling back to the previous stable firmware version is the most direct and effective remediation. This action directly reverses the problematic change, restoring the server to its last known working state and resolving the incompatibility. Although a proper rollback plan should have been established prior to the update, performing the rollback now is critical for immediate service restoration.

Why this answer

The scheduled firmware update directly caused the printer to become inaccessible, and without a documented rollback plan, reverting to the previous firmware version is the safest and most immediate way to restore service. This aligns with change management best practices, which prioritize backing out a failed change before troubleshooting further, as the root cause is clearly the firmware update.

Exam trap

The trap here is that candidates often choose to reboot the server (Option A) as a generic troubleshooting step, but the question specifies the change was a firmware update, so the only effective first action is to revert that specific change.

How to eliminate wrong answers

Option A is wrong because rebooting the print server may clear temporary errors but will not revert the firmware version, so if the new firmware is incompatible or buggy, the issue will persist after the reboot. Option C is wrong because submitting a new change request to update the firmware again would repeat the same action that caused the outage, which is illogical and violates change management principles. Option D is wrong because disabling and re-adding the printer in Active Directory addresses only the printer object and driver mapping, not the underlying firmware incompatibility on the print server.

135
MCQhard

A user reports that their browser crashes every time they visit a particular website. Other websites work fine. The technician tries the same website on another computer and it works normally. What is the most likely cause on the user's computer?

A.The website has been blacklisted by the company's firewall.
B.A browser extension is incompatible with that website.
C.The user's network adapter driver is outdated.
D.The website is using a newer version of TLS that the browser doesn't support.
AnswerB

Browser extensions inject their own code, scripts, or styles into web pages, modifying the browser's behavior or the page's content. An incompatibility arises when an extension's code conflicts with the specific JavaScript, CSS, or HTML structure of a particular website, leading to unexpected errors or memory access violations within the browser process. This conflict can destabilize the browser, causing it to freeze or crash when attempting to render or interact with the problematic site, while other sites remain unaffected.

Why this answer

The issue is isolated to a single website on one computer, and the same website works on another computer. This rules out network-wide or server-side problems. Browser extensions can inject scripts, modify headers, or block resources that a specific website requires, causing crashes.

Disabling extensions or testing in incognito mode (which typically disables extensions) can confirm this.

Exam trap

CompTIA often tests the principle of isolation—candidates mistakenly attribute a single-site issue to network-wide or driver problems, but the key is that the problem follows the user's browser configuration, not the network or hardware.

How to eliminate wrong answers

Option A is wrong because if the website were blacklisted by the company's firewall, it would not load on any computer in the network, not just the user's. Option C is wrong because an outdated network adapter driver would cause connectivity issues across all websites, not a single site. Option D is wrong because TLS version incompatibility would result in a connection error or a 'secure connection failed' message, not a browser crash; additionally, if the browser didn't support the TLS version, the other computer would also fail unless it had a different browser or updated TLS stack.

136
MCQeasy

A helpdesk technician is assisting a user who is unable to find a file named 'notes.txt' they saved earlier. The user is in their home directory. Which command will search the entire filesystem for this file?

A.locate notes.txt
B.grep notes.txt /
C.find ~ -name notes.txt
D.find / -name notes.txt
AnswerD

This searches the entire filesystem from root, making it the correct command for a full system search.

Why this answer

The `find / -name notes.txt` command starts at the root directory (`/`) and recursively searches the entire filesystem for a file named exactly 'notes.txt'. The `-name` option performs a case-sensitive match on the filename, and the starting point `/` ensures all mounted filesystems are included.

Exam trap

The exam often tests the distinction between `find` and `locate`, where candidates mistakenly choose `locate` for a real-time search without considering that the database may not be current, or they confuse the starting directory argument (e.g., `~` vs. `/`).

How to eliminate wrong answers

Option A is wrong because `locate` relies on a pre-built database (usually updated daily via `updatedb`) and may not find a file saved recently if the database hasn't been refreshed; it also does not search the live filesystem in real-time. Option B is wrong because `grep notes.txt /` attempts to search the root directory as a file for the pattern 'notes.txt', but `/` is a directory, not a regular file, so `grep` will either fail with an error or produce no meaningful results; `grep` is designed for searching file contents, not filenames. Option C is wrong because `find ~ -name notes.txt` limits the search to the user's home directory (`~`), not the entire filesystem, so it will miss the file if it was saved elsewhere.

137
MCQeasy

A small office wants to dispose of 20 old CRT monitors. The local landfill does not accept e-waste. Which disposal method is both legal and environmentally responsible?

A.Place them in the dumpster behind the office after hours.
B.Contact a certified e-waste recycling company to pick them up.
C.Break them down and put the plastic and metal in separate recycling bins.
D.Sell them to a scrap metal dealer.
AnswerB

Contacting a certified e-waste recycling company is the correct and most responsible method for disposing of old CRT monitors. Certified recyclers (e.g., R2 or e-Stewards certified) possess the specialized equipment, permits, and trained personnel required to safely dismantle electronic waste. They ensure hazardous components, such as leaded glass, are properly separated and neutralized, while valuable materials like copper, plastics, and precious metals are recovered and recycled, minimizing environmental impact and ensuring regulatory compliance.

Why this answer

CRT monitors contain hazardous materials like lead and phosphor, making them e-waste that cannot be disposed of in regular trash. Certified e-waste recycling companies follow environmental regulations to safely dismantle and recycle these components, ensuring legal compliance and responsible handling.

Exam trap

CompTIA often tests the misconception that recycling bins or scrap dealers are acceptable for e-waste, when in fact only certified e-waste recyclers can legally and safely handle hazardous materials like those in CRTs.

How to eliminate wrong answers

Option A is wrong because placing e-waste in a dumpster is illegal in most jurisdictions and environmentally irresponsible due to toxic materials like lead leaching into landfills. Option C is wrong because breaking down CRTs without proper equipment releases hazardous dust and requires specialized handling; general recycling bins do not accept e-waste components. Option D is wrong because scrap metal dealers typically lack certification for handling hazardous e-waste, and selling CRTs for scrap may violate environmental laws if the materials are not processed safely.

138
MCQmedium

A technician needs to write a batch script that will copy a configuration file from a network share to the local system32 directory only if the file on the share is newer than the local copy. Which command should the technician use to perform this conditional copy?

A.copy /y \\server\share\config.txt C:\Windows\System32\
B.xcopy \\server\share\config.txt C:\Windows\System32\ /d /y
C.robocopy \\server\share C:\Windows\System32 config.txt /mir
D.move /y \\server\share\config.txt C:\Windows\System32\
AnswerB

The /d switch makes xcopy copy only source files newer than the destination, satisfying the conditional requirement, while /y suppresses the overwrite prompt. This reliably updates config.txt in System32 only when the network share version is newer.

Why this answer

The `xcopy` command with the `/d` switch copies files only if the source file is newer than the destination file, and `/y` suppresses confirmation prompts. This meets the requirement of a conditional copy based on file timestamp comparison.

Exam trap

CompTIA A+ often tests the distinction between `copy`, `xcopy`, and `robocopy` switches, and the trap here is that candidates may choose `copy /y` thinking it is sufficient, overlooking the need for a timestamp-based conditional check that only `xcopy /d` provides.

How to eliminate wrong answers

Option A is wrong because `copy /y` always overwrites the destination without any timestamp check, so it does not conditionally copy only when the source is newer. Option C is wrong because `robocopy /mir` mirrors an entire directory tree, including deleting files in the destination that no longer exist in the source, which is excessive and destructive for a single-file copy task. Option D is wrong because `move` relocates the file from the network share to the local system, removing it from the source, which is not a copy operation and does not perform any timestamp-based condition.

139
MCQmedium

A user reports that after installing a free PDF converter from an advertisement, their browser homepage changed and they see constant pop-ups for antivirus software. A malware scan found PUPs (Potentially Unwanted Programs). What is the best next step to fully remove the unwanted software and restore browser settings?

A.Run System Restore to a point before installation.
B.Use a dedicated adware removal tool and then reset the browser.
C.Manually delete the program from Program Files.
D.Disable the browser's JavaScript and ActiveX.
AnswerB

Using a dedicated adware removal tool is crucial because these utilities are specifically designed to detect and eradicate PUPs, which often evade standard antivirus software due to their 'grayware' nature. These tools employ heuristics and extensive databases to locate deeply embedded components, including browser hijackers, unwanted extensions, and persistent registry entries. Subsequently, resetting the browser ensures all lingering modifications, such as altered homepages, search engines, and pop-up settings, are completely reverted to default, providing a clean slate.

Why this answer

PUPs often embed deeply into browser settings and registry entries that a standard uninstall or System Restore may not fully remove. A dedicated adware removal tool targets these specific traces, and resetting the browser ensures all malicious extensions, search providers, and homepage hijacks are cleared, restoring default security configurations.

Exam trap

CompTIA often tests the misconception that System Restore (Option A) is a comprehensive fix for malware, when in reality it may not remove PUPs that persist in user profile folders or browser data that are excluded from restore points.

How to eliminate wrong answers

Option A is wrong because System Restore may not revert changes made by PUPs that modify user-specific registry hives or browser profile data, and it can leave behind residual files that continue to cause pop-ups. Option C is wrong because manually deleting the program from Program Files does not remove the associated registry entries, scheduled tasks, or browser extensions that maintain the unwanted behavior. Option D is wrong because disabling JavaScript and ActiveX only prevents some script-based pop-ups but does not remove the underlying PUP files, registry modifications, or browser hijack settings.

140
MCQeasy

A customer reports that their desktop computer is running extremely slowly, and they see frequent pop-up advertisements even when no browser is open. Task Manager shows a process named 'svch0st.exe' consuming 95% CPU. Which type of malware is most likely causing these symptoms?

A.Ransomware
B.Adware
C.Rootkit
D.Spyware
AnswerB

Adware is specifically designed to display unwanted advertisements, often through pop-up windows, banners, or injected content into web pages, directly matching the symptom of pop-up ads. A common tactic for adware to maintain persistence and avoid detection is to create processes that deliberately impersonate legitimate system services or applications. This behavior allows it to run unnoticed in the background, making it difficult for users to identify and remove, aligning perfectly with the described symptoms.

Why this answer

The combination of frequent pop-up advertisements appearing even when no browser is open, plus a suspicious process named 'svch0st.exe' (a typosquat of the legitimate svchost.exe) consuming 95% CPU, is the classic signature of adware. Adware is designed to inject and display unwanted advertisements, often through background processes that masquerade as system files. The misspelled process name is a deliberate attempt to evade detection by blending in with legitimate Windows services.

Exam trap

The trap here is confusing adware with spyware because both are unwanted and both can run in the background; candidates must focus on the visible pop-up advertisements as the defining symptom of adware, while spyware is stealthy data collection.

How to eliminate wrong answers

Option A is wrong because ransomware encrypts files and demands payment, and would present ransom notes rather than pop-up ads. Option C is wrong because a rootkit is designed for stealth persistence and privilege escalation, not for displaying advertisements; it would hide itself rather than consume 95% CPU visibly. Option D is wrong because spyware silently collects user data (keystrokes, browsing habits) and exfiltrates it, without the visible symptom of pop-up advertisements.

141
MCQmedium

A user reports that after a technician recycled an old computer by simply deleting the user profile, the next user found personal documents in the 'Recycle Bin'. Which step was missed in the data disposal process?

A.The technician should have performed a quick format.
B.The technician should have used a data wiping tool that overwrites the free space.
C.The technician should have removed the hard drive and stored it.
D.The technician should have disabled the Recycle Bin.
AnswerB

The technician should have used a data wiping tool that overwrites the free space to ensure data unrecoverability. Such tools systematically write patterns of data, often multiple passes of zeros or random characters, across all sectors of the storage device, including those previously occupied by deleted files. This process physically obliterates the original data, making it impossible to recover using standard or even advanced forensic techniques, thus achieving proper data sanitization.

Why this answer

Deleting a user profile only removes the user's registry and profile folder, but personal documents remain in the Recycle Bin because the Recycle Bin is a system-protected hidden folder that is not cleared by profile deletion. A data wiping tool that overwrites free space is required to securely erase the contents of the Recycle Bin and any other residual data, ensuring that deleted files cannot be recovered.

Exam trap

CompTIA often tests the misconception that deleting a user profile or emptying the Recycle Bin is sufficient for data disposal, when in fact both actions leave recoverable data on the free space that requires overwriting to be secure.

How to eliminate wrong answers

Option A is wrong because a quick format only clears the file system metadata (e.g., the MFT or FAT table) and does not overwrite the actual data sectors, leaving the Recycle Bin contents intact and recoverable. Option C is wrong because removing and storing the hard drive is a physical security measure for decommissioning, not a data disposal step for a recycled computer that will be reused by another user. Option D is wrong because disabling the Recycle Bin only prevents future files from being stored there; it does not erase existing files already in the Recycle Bin, so the personal documents would remain.

142
MCQhard

A company's IT policy requires that all disposed hard drives be physically destroyed to prevent data breaches. Which method has the least environmental impact while ensuring data destruction?

A.Use a degausser to erase the drive and then recycle it.
B.Drill holes through the platters and then dispose of the drive in e-waste.
C.Shred the hard drive using an industrial shredder and then recycle the metal fragments.
D.Overwrite the drive with zeros multiple times and then donate it.
AnswerC

Shredding hard drives with an industrial shredder provides the highest level of physical data destruction, reducing the drive into small, unrecognizable fragments. This method ensures that no data can be recovered, satisfying stringent IT security policies for complete sanitization. Subsequently, separating and recycling the resulting metal fragments (e.g., aluminum, steel) minimizes electronic waste, conserves resources, and aligns with environmental best practices, making it a comprehensive and compliant solution.

Why this answer

Industrial shredding physically destroys the platters into small fragments, making data recovery impossible, and the resulting metal fragments can be recycled, minimizing environmental impact. Unlike degaussing or drilling, shredding ensures complete destruction without leaving large e-waste components, and the recycling of ferrous and non-ferrous metals reduces raw material extraction.

Exam trap

CompTIA often tests the misconception that degaussing or overwriting is sufficient for physical destruction policies, but the key distinction is that physical destruction requires the drive to be rendered physically unusable and unrecoverable, not just magnetically or logically erased.

How to eliminate wrong answers

Option A is wrong because degaussing destroys the magnetic domains on the platters, making the drive unusable, but the drive itself remains a bulky e-waste item that must be disposed of; recycling a degaussed drive still requires energy and processing, and degaussing does not physically destroy the drive, so it may not meet a policy requiring physical destruction. Option B is wrong because drilling holes through the platters leaves large portions of the platters intact, and data may still be recoverable from undamaged areas using specialized forensic tools; additionally, disposing of the drive in e-waste without recycling the metal components has a higher environmental impact than shredding and recycling. Option D is wrong because overwriting with zeros multiple times does not physically destroy the drive, and donating it violates the policy requiring physical destruction; even with multiple overwrites, advanced recovery techniques (e.g., magnetic force microscopy) might recover residual data, and the drive is not disposed of as required.

143
MCQeasy

During a printer toner replacement, a technician accidentally spills toner powder on the carpet. What is the proper cleanup procedure?

A.Use a vacuum cleaner with a standard bag to suck up the toner.
B.Wipe the toner with a damp cloth using hot water.
C.Blot the toner with a cold, damp cloth and then use a HEPA-filter vacuum.
D.Sweep the toner into a dustpan and dispose of it in the trash.
AnswerC

Blotting with a cold, damp cloth is crucial as cold water prevents the thermoplastic toner from melting and bonding to surfaces, while blotting avoids spreading the fine powder. Subsequently, a HEPA-filter vacuum is essential because its high-efficiency particulate air filter captures 99.97% of airborne particles 0.3 microns or larger. This ensures effective removal of the fine toner particles without re-releasing them into the environment, protecting both health and equipment.

Why this answer

Toner powder is extremely fine and can become airborne if mishandled. Blotting with a cold, damp cloth prevents the toner from spreading, and using a HEPA-filter vacuum ensures that microscopic toner particles are trapped without being exhausted back into the environment. Standard vacuum cleaners lack HEPA filtration and can release toner dust into the air, causing respiratory hazards.

Exam trap

CompTIA often tests the misconception that any vacuum or damp cloth is acceptable for toner cleanup, but the trap is that only a HEPA-filter vacuum combined with cold water blotting prevents particle dispersion and permanent staining.

How to eliminate wrong answers

Option A is wrong because using a vacuum cleaner with a standard bag does not trap ultrafine toner particles; the vacuum's exhaust can blow toner dust into the air, creating a health risk and further contamination. Option B is wrong because wiping toner with a damp cloth using hot water can cause the toner to melt or fuse into the carpet fibers, making permanent stains and releasing fumes. Option D is wrong because sweeping toner with a dustpan generates airborne dust, and disposing of it in regular trash is unsafe as toner is a fine particulate that can become airborne in landfills.

144
MCQeasy

During a printer toner replacement, a technician accidentally spills toner powder on the carpet. What is the correct procedure for cleaning up the spill?

A.Use a standard household vacuum cleaner to quickly remove the toner.
B.Wipe up the toner with a dry paper towel and dispose of it in the trash.
C.Use a toner-rated vacuum or a damp cloth to carefully collect the spill.
D.Pour water on the spill to dissolve the toner, then mop it up.
AnswerC

A toner-rated vacuum is the safest and most effective method because it features a HEPA filter specifically designed to capture the extremely fine toner particles, preventing them from recirculating into the air. Alternatively, a lightly damp cloth can be used to carefully blot and lift the toner, as the moisture helps to bind the particles together and prevents them from becoming airborne, significantly reducing inhalation risks.

Why this answer

Toner powder is a fine, electrically charged plastic dust that can be hazardous if inhaled or if it melts into carpet fibers. Using a toner-rated vacuum with a HEPA filter safely captures the particles without dispersing them, or a damp cloth can be used to gently lift the toner without smearing it deeper into the carpet. This procedure follows manufacturer safety guidelines and prevents damage to standard vacuums, which can ignite or spread the toner.

Exam trap

CompTIA often tests the misconception that water can dissolve toner because it resembles ink, but toner is a dry plastic powder that requires specialized cleanup to avoid static ignition or permanent carpet damage.

How to eliminate wrong answers

Option A is wrong because standard household vacuum cleaners lack HEPA filtration and can cause the fine toner particles to be expelled into the air, creating an inhalation hazard; additionally, the static buildup inside the vacuum can ignite the toner dust. Option B is wrong because wiping toner with a dry paper towel will grind the particles into the carpet fibers, making removal more difficult and potentially damaging the carpet. Option D is wrong because toner is a plastic-based powder that does not dissolve in water; adding water will create a sticky, paste-like mess that is harder to clean and can stain the carpet permanently.

145
MCQmedium

A small business wants to ensure that all employees use strong passwords that include uppercase, lowercase, numbers, and special characters, and that passwords expire every 60 days. Which tool should be used to enforce these settings on a standalone Windows 10 workstation?

A.Local Users and Groups (lusrmgr.msc)
B.Local Security Policy (secpol.msc)
C.Windows Defender Firewall with Advanced Security
D.Device Manager
AnswerB

Local Security Policy enforces password complexity and maximum password age directly through the workstation's local account database, satisfying the standalone constraint without domain infrastructure. Configure the Password Policy node's "Password must meet complexity requirements" and "Maximum password age" (60 days) settings, which apply to local accounts on that Windows 10 device.

Why this answer

The Local Security Policy (secpol.msc) is the correct tool because it provides a centralized interface to configure password policies, such as minimum password length, complexity requirements (uppercase, lowercase, numbers, special characters), and maximum password age (e.g., 60 days). These settings are enforced locally on a standalone Windows 10 workstation through the Security Settings node under Account Policies.

Exam trap

CompTIA A+ often tests the distinction between user account management tools (lusrmgr.msc) and security policy enforcement tools (secpol.msc), leading candidates to mistakenly choose Local Users and Groups for password policy configuration.

How to eliminate wrong answers

Option A is wrong because Local Users and Groups (lusrmgr.msc) is used to manage user accounts and group memberships, not to enforce password complexity or expiration policies. Option C is wrong because Windows Defender Firewall with Advanced Security is designed to control inbound and outbound network traffic rules, not to configure password policies. Option D is wrong because Device Manager is used to manage hardware devices and drivers, not to enforce security settings like password policies.

146
MCQmedium

A technician is investigating a security incident where a user's credentials were stolen. The user says they only logged into their email from a coffee shop Wi-Fi. The technician notices that the browser was not using HTTPS for the login page. What is the most likely attack method used?

A.Cross-site scripting (XSS) attack.
B.Man-in-the-middle attack.
C.DNS spoofing attack.
D.Brute force attack.
AnswerB

A Man-in-the-middle (MITM) attack is precisely what occurs when an attacker intercepts communication between two parties without their knowledge. In a Wi-Fi environment, an attacker can position themselves between a user and a legitimate login page, capturing all unencrypted HTTP traffic. Since HTTP does not encrypt data, any login credentials transmitted over it are exposed in plain text, allowing the attacker to easily steal them.

Why this answer

A man-in-the-middle (MITM) attack occurs when an attacker intercepts communications between the user and the server, often on unsecured public Wi-Fi. Because the login page was not using HTTPS, credentials were transmitted in cleartext, allowing the attacker to capture them. This is the classic scenario for credential theft on open networks.

Exam trap

The trap is selecting DNS spoofing because it also involves network manipulation, but the key clue is 'no HTTPS' and 'credentials stolen'—which directly points to cleartext interception via MITM.

How to eliminate wrong answers

Option A is wrong because XSS attacks target vulnerabilities in web applications to execute scripts in a victim's browser—they do not directly intercept network traffic on public Wi-Fi. Option C is wrong because DNS spoofing redirects users to fraudulent sites by corrupting DNS resolution; while it can be part of a MITM chain, the question specifically points to cleartext credential interception, which is MITM. Option D is wrong because brute force involves repeatedly guessing credentials, not stealing them from an unencrypted session.

147
MCQhard

A company is experiencing a security incident where an attacker gained access to the internal network via a compromised VPN account. The technician must prevent future attacks. Which two-factor authentication method should the technician implement for VPN access?

A.Require a complex password with a minimum length of 20 characters
B.Implement a time-based one-time password (TOTP) via an authenticator app
C.Restrict VPN access to specific IP addresses
D.Enable single sign-on (SSO) with Active Directory
AnswerB

Implementing a time-based one-time password (TOTP) via an authenticator app significantly enhances security by introducing a second, independent authentication factor ('something you have'). This method generates a unique, ephemeral code that changes typically every 30-60 seconds, which must be entered in addition to the user's password. Even if an attacker compromises the user's password, they cannot gain access without also possessing the physical device generating the current TOTP code, making credential reuse extremely difficult.

Why this answer

Two-factor authentication (2FA) adds a second factor beyond the password, such as a one-time code from an authenticator app. This significantly reduces the risk of account compromise even if the password is stolen.

148
MCQhard

During a security audit, you need to identify all user accounts that have been created or modified in the last 24 hours on a Windows Server. Which command-line tool can parse security event logs to extract this information?

A.wevtutil qe Security /q:"*[System[TimeCreated[timediff(@SystemTime) <= 86400000]]]"
B.eventvwr
C.net user
D.diskpart
AnswerA

wevtutil's query flag parses the Security log using XPath, and the timediff filter compares each event's TimeCreated against the current system time in milliseconds, so 86400000 restricts results to the last 24 hours. This directly satisfies the audit's requirement to extract recently created or modified accounts.

Why this answer

The wevtutil command with the 'qe' (query-events) parameter and an XPath filter can directly query the Security event log for events created within a specific time window. The filter '*[System[TimeCreated[timediff(@SystemTime) <= 86400000]]]' retrieves events whose creation time is within the last 86,400,000 milliseconds (24 hours), allowing you to identify user accounts created or modified via event IDs such as 4720 (user created) or 4738 (user changed).

Exam trap

CompTIA exams often test the distinction between graphical tools (eventvwr) and command-line tools (wevtutil), and candidates may confuse 'net user' as a log-parsing tool when it only shows current account state, not historical changes.

How to eliminate wrong answers

Option B (eventvwr) is wrong because it is a graphical Event Viewer tool, not a command-line tool, and cannot be used in scripts or automated audits without additional interaction. Option C (net user) is wrong because it only displays current user account properties or modifies accounts, but it cannot parse historical security event logs to show accounts created or modified in the last 24 hours. Option D (diskpart) is wrong because it is a disk partitioning utility and has no capability to query event logs or user account information.

149
MCQeasy

A receptionist holds the door for a person carrying a large box, assuming they work in the building. Later, that person is seen plugging a USB drive into a workstation in the finance department. Which social engineering technique was most likely used to gain initial access?

A.Phishing
B.Pretexting
C.Tailgating
D.Baiting
AnswerC

Tailgating occurs when an attacker follows an authorised person through a controlled entrance without presenting credentials. The receptionist's assumption that the box-carrier belonged in the building let them bypass access controls, enabling the subsequent USB attack.

Why this answer

Tailgating involves an unauthorized person gaining physical access to a secure area by following an authorized individual. In this scenario, the receptionist held the door for the person carrying a large box, assuming they worked in the building, which allowed the attacker to bypass physical security controls without authentication.

Exam trap

The trap here is that candidates confuse tailgating with pretexting, as both involve deception, but tailgating specifically relies on physical proximity and social norms rather than a fabricated story or identity.

How to eliminate wrong answers

Option A is wrong because phishing is a digital social engineering technique that uses deceptive emails or messages to trick victims into revealing credentials or installing malware, not physical access. Option B is wrong because pretexting involves creating a fabricated scenario or identity to obtain information, such as impersonating IT support, but here the attacker simply followed someone in without a detailed story. Option D is wrong because baiting involves offering something enticing (e.g., a free USB drive) to lure a victim into compromising security, but the attacker in this case used physical proximity, not a lure.

150
MCQmedium

A user complains that their computer is running slowly and they see a USB drive they don't recognize plugged into the front port. What is the first step a technician should take to address this potential security issue?

A.Run a full antivirus scan on the computer.
B.Check the USB drive's contents to see what it contains.
C.Ask the user to unplug the USB drive immediately.
D.Disable the USB ports in the BIOS.
AnswerC

Removing the device stops any ongoing malicious activity and is the first step in containment.

Why this answer

The immediate priority is to contain the potential security threat by physically removing the unknown USB drive. This follows the principle of least privilege and incident response best practices: isolate the suspect device before performing any analysis or remediation. Unplugging the drive stops any ongoing data exfiltration or malware installation, which is the first step in a security incident response.

Exam trap

The trap here is that candidates often jump to scanning or investigating the drive (options A or B) because they focus on detection rather than containment, but the CompTIA A+ 220-1102 exam emphasizes immediate isolation as the first step in security incident response.

How to eliminate wrong answers

Option A is wrong because running a full antivirus scan while the unknown USB drive is still connected could allow malware to execute or spread during the scan, and antivirus may not detect all threats (e.g., zero-day exploits or fileless malware). Option B is wrong because checking the USB drive's contents exposes the technician to potential malware (e.g., autorun.inf triggering a payload) and could compromise the system further; forensic analysis should be done in a controlled environment. Option D is wrong because disabling USB ports in the BIOS is a long-term administrative control that takes time and may affect legitimate devices; it does not address the immediate threat of the already-connected unknown drive.

Page 1

Page 2 of 10

Page 3

All pages

Practice 220-1202 by domain

Target a specific domain to shore up weak areas.

See all domains with question counts →