Courseiva

CompTIA A+ Core 2 220-1202 (220-1202) — Questions 151–225

687 questions total · 10pages · All types, answers revealed

Page 2

Page 3 of 10

Page 4
151
MCQeasy

A technician is deploying a new virtual machine on a Type 1 hypervisor. The VM will run a Linux web server and needs to be isolated from the corporate network except for HTTPS traffic. Which networking configuration should the technician implement?

A.Bridge the VM directly to the physical network adapter
B.Use a virtual switch set to host-only mode and configure port forwarding for HTTPS
C.Attach the VM to a NAT network without any port forwarding
D.Assign the VM an IP from the corporate DHCP scope
AnswerB

Host-only mode creates a private virtual network between the VM and the host machine, completely isolating the VM from the external corporate network. This ensures the VM cannot be directly accessed or discovered by other devices on the corporate network. Configuring port forwarding specifically for HTTPS (port 443) on the host allows only this designated traffic to pass from the host to the isolated VM, precisely meeting the requirement for secure, controlled inbound access while maintaining maximum isolation.

Why this answer

A host-only virtual switch creates an isolated network between the host and the VM, preventing direct access from the corporate network. By configuring port forwarding on the host, the technician can selectively allow only HTTPS traffic (TCP/443) to reach the VM while keeping it otherwise isolated. This meets the requirement of isolation except for HTTPS.

Exam trap

In CompTIA A+ exams, candidates often confuse host-only and NAT networking modes, mistakenly thinking NAT alone provides inbound access, but NAT without port forwarding only allows outbound connections.

How to eliminate wrong answers

Option A is wrong because bridging the VM directly to the physical network adapter would place the VM on the same Layer 2 broadcast domain as the corporate network, providing no isolation. Option C is wrong because a NAT network without port forwarding would allow the VM to initiate outbound connections but would not permit inbound HTTPS traffic from the corporate network, failing the requirement to allow HTTPS. Option D is wrong because assigning the VM an IP from the corporate DHCP scope would give the VM a routable corporate IP address, making it directly accessible from the corporate network and defeating the isolation requirement.

152
MCQmedium

A technician needs to install a 64-bit application on a Windows 11 system. The application requires .NET Framework 3.5. When the technician tries to enable .NET Framework 3.5 through Windows Features, the installation fails with error 0x800F0906. What is the most likely cause?

A.The user does not have administrative privileges.
B.The .NET Framework 3.5 feature is corrupted in the Windows component store.
C.The application is not compatible with Windows 11.
D.The system does not have an internet connection to download the required files.
AnswerD

Error 0x800F0906 typically indicates that Windows cannot download the required files to enable .NET Framework 3.5. By default, Windows tries to download the feature from Windows Update. If there is no internet connection or Windows Update is blocked, the installation fails. The solution is to provide the installation media or enable the feature using DISM with a source path. Thus, lack of internet is the most likely cause.

Why this answer

Error 0x800F0906 occurs when Windows cannot download the necessary files to enable .NET Framework 3.5. This is typically due to no internet connection or Windows Update being unavailable. The correct resolution is to use DISM with a source path pointing to the Windows installation media, or to enable the feature while connected to the internet.

The other options do not match the error code.

Exam trap

The trap here is assuming the error is due to corruption or permissions, when it actually indicates a missing source for the feature files.

153
MCQeasy

A technician receives a complaint from a user that their email account was used to send spam. The user insists they did not send the emails. What is the MOST appropriate first step in handling this security incident professionally?

A.Tell the user they must have clicked on a phishing link and it's their fault.
B.Immediately reset the user's password and check the email logs for unauthorized access.
C.Ignore the complaint because spam is common.
D.Ask the user to change their password and not worry about it.
AnswerB

This is the most appropriate immediate response to a potential account compromise. Resetting the password severs any active unauthorized sessions and prevents further malicious activity from the compromised account, thereby securing it. Concurrently, examining email logs provides critical forensic evidence to identify the source, scope, and timeline of the unauthorized access, which is essential for understanding the attack vector and implementing broader preventative measures.

Why this answer

The immediate reset of the user's password stops further unauthorized use of the account, and checking email logs (e.g., SMTP logs, IMAP/POP3 access logs, or Exchange/Office 365 audit logs) allows the technician to identify the source of the spam, such as a compromised credential or a malicious forwarding rule. This follows the CompTIA A+ incident response procedure of containment first, then investigation, while maintaining professional communication with the user.

Exam trap

CompTIA often tests the candidate's ability to prioritize containment over investigation or blame; the trap here is that many candidates jump to blaming the user (Option A) or taking a passive approach (Option D), when the correct first step is to immediately secure the account by resetting the password.

How to eliminate wrong answers

Option A is wrong because blaming the user without evidence violates professional conduct and may overlook other causes like a compromised password or a malicious script on the client machine. Option C is wrong because ignoring a security incident, especially one involving unauthorized email use, violates security policy and could allow further damage or data breach. Option D is wrong because simply asking the user to change their password without verifying logs or resetting the account leaves the incident uncontained and fails to confirm whether the attacker still has access or has set up persistence mechanisms like forwarding rules.

154
MCQeasy

During a security audit, it is discovered that an old server's hard drives were simply deleted and the server was sold to a recycler. The recycler later reported finding readable files on the drives. Which data disposal standard was violated?

A.NIST SP 800-88
B.PCI DSS
C.HIPAA
D.ISO 27001
AnswerA

NIST SP 800-88 provides comprehensive guidelines for media sanitization, defining methods such as 'Clear,' 'Purge,' and 'Destroy' to ensure data is unrecoverable. A security audit discovering improper data disposal, such as simple file deletion or reformatting, would directly cite a failure to adhere to these specific technical standards. This standard is the authoritative source for secure data destruction practices, making it the most direct and relevant answer for a violation involving inadequate sanitization procedures.

Why this answer

NIST SP 800-88 provides guidelines for media sanitization, including clear, purge, and destroy methods. Simply deleting files only removes directory pointers, leaving data recoverable until overwritten. The recycler's ability to read files indicates that the drives were not sanitized according to NIST SP 800-88 standards, which require overwriting or physical destruction for sensitive data.

Exam trap

CompTIA often tests the distinction between a general security framework (like HIPAA or PCI DSS) and a specific technical disposal standard (NIST SP 800-88), trapping candidates who confuse compliance requirements with the actual sanitization methodology.

How to eliminate wrong answers

Option B (PCI DSS) is wrong because PCI DSS is a security standard for payment card data, not a specific data disposal standard; while it requires secure disposal, it does not define the technical methods like NIST SP 800-88 does. Option C (HIPAA) is wrong because HIPAA governs protected health information (PHI) disposal but does not prescribe the specific sanitization techniques or levels (clear, purge, destroy) that NIST SP 800-88 details. Option D (ISO 27001) is wrong because ISO 27001 is an information security management system (ISMS) standard that requires a disposal policy but does not provide the granular, step-by-step sanitization procedures found in NIST SP 800-88.

155
MCQmedium

A company's server room has a door with a proximity card reader. Employees report that the door sometimes does not close fully, allowing it to be pushed open without a card. What is the best solution?

A.Replace the proximity card reader with a biometric reader
B.Install a door closer mechanism
C.Add a security camera to monitor the door
D.Increase the frequency of badge audits
AnswerB

Installing a door closer mechanism directly resolves the issue of a door not closing properly. This device, typically hydraulic or spring-loaded, automatically pulls the door shut after it has been opened, ensuring it fully latches into the door frame. This physical control is a preventative measure that maintains the security perimeter of the server room by preventing the door from being inadvertently left ajar, thereby blocking unauthorized physical access.

Why this answer

The core issue is that the door fails to close fully, bypassing the proximity card reader's access control. A door closer mechanism is a mechanical device that automatically pulls the door shut, ensuring it latches and requires card authentication to re-enter. This directly addresses the physical vulnerability without changing the authentication method.

Exam trap

The trap here is that candidates focus on the authentication technology (card reader) rather than the physical barrier integrity, mistakenly thinking a stronger authentication method (biometric) will solve a mechanical latching problem.

How to eliminate wrong answers

Option A is wrong because replacing the reader with a biometric reader does not fix the mechanical problem of the door not closing; it only changes the authentication factor, leaving the bypass vulnerability intact. Option C is wrong because adding a security camera only monitors the door after the fact, it does not prevent unauthorized entry when the door is left ajar. Option D is wrong because increasing badge audit frequency is an administrative control that detects misuse but does not physically secure the door from being pushed open without a card.

156
MCQeasy

A customer reports that their old laptop, which they sold online, still contains personal files that the new owner accessed. The customer had only performed a 'Reset this PC' with the 'Remove everything' option. What should the technician recommend to prevent this in the future?

A.Perform a factory reset from the recovery partition.
B.Use a third-party data wiping tool that overwrites the drive multiple times.
C.Remove the hard drive and physically destroy it.
D.Change the user password before selling.
AnswerB

A third-party data wiping tool is the most effective method for securely sanitizing a drive while keeping the hardware reusable. These tools overwrite every sector of the storage device with specific patterns, often multiple times, adhering to standards like DoD 5220.22-M or NIST SP 800-88. This multi-pass overwrite process renders previous data unrecoverable by even advanced forensic techniques, ensuring complete data privacy for resale.

Why this answer

The 'Reset this PC' with 'Remove everything' option in Windows performs a quick format or a single-pass overwrite, which leaves data recoverable by file recovery tools. A third-party data wiping tool that overwrites the drive multiple times (e.g., using the DoD 5220.22-M standard) ensures that the data is irrecoverable by overwriting all sectors with patterns, preventing any future access.

Exam trap

The trap here is that candidates assume 'Remove everything' in Windows performs a secure erase, but it only removes file pointers, not the underlying data, making it vulnerable to recovery.

How to eliminate wrong answers

Option A is wrong because a factory reset from the recovery partition typically performs a similar quick format or reinstallation, not a secure wipe, leaving data recoverable. Option C is wrong because physically destroying the hard drive is an extreme measure that is unnecessary for resale; secure wiping is sufficient and allows the drive to be reused. Option D is wrong because changing the user password does not remove or overwrite the existing personal files; the new owner can still access them via a password reset or by booting from external media.

157
MCQeasy

A user complains that their MacBook Air running macOS Monterey frequently runs out of memory and slows down when they have multiple browser tabs and apps open. They want to see which processes are consuming the most memory without installing third-party software. Which macOS tool should you instruct them to use?

A.Force Quit Applications window (Cmd+Option+Esc).
B.System Preferences > Memory.
C.Terminal with the 'top' command.
D.Activity Monitor from the Utilities folder.
AnswerD

Activity Monitor's Memory tab lists every process with its memory footprint, letting the user sort by usage to identify the heaviest consumers. It ships preinstalled in /Applications/Utilities, satisfying the no-third-party-software constraint, and runs natively on macOS Monterey without additional configuration.

Why this answer

Activity Monitor (option D) is the built-in macOS utility that provides real-time monitoring of CPU, memory, energy, disk, and network usage. It allows users to view memory pressure, list processes sorted by memory consumption, and identify resource hogs without any third-party software. This directly addresses the user's need to see which processes are consuming the most memory.

Exam trap

CompTIA often tests the distinction between a diagnostic tool (Activity Monitor) and a troubleshooting shortcut (Force Quit), leading candidates to mistakenly choose the Force Quit window because it is a common keyboard shortcut for dealing with unresponsive apps, even though it lacks memory monitoring capabilities.

How to eliminate wrong answers

Option A is wrong because the Force Quit Applications window (Cmd+Option+Esc) only lists running applications and allows you to force quit them; it does not show memory usage details or process-level memory consumption. Option B is wrong because System Preferences does not have a 'Memory' pane; macOS Monterey's memory management settings are not exposed in System Preferences, and there is no dedicated memory configuration interface there. Option C is wrong because while the 'top' command in Terminal can display process memory usage, it is a command-line tool that requires familiarity with terminal syntax and does not provide the graphical, user-friendly interface the user would expect for diagnosing memory issues; Activity Monitor is the recommended GUI tool for this task.

158
MCQhard

A technician is performing a routine software update on a finance department server. The change management documentation specifies that the update must be applied during a maintenance window from 2:00 AM to 4:00 AM. At 3:30 AM, the update fails with an error. The technician has no rollback plan documented. What should the technician do?

A.Attempt to roll back the update using the server’s built-in recovery options.
B.Leave the server in its current state and escalate the issue to the change manager.
C.Continue troubleshooting until the maintenance window ends, then document the failure.
D.Reboot the server to clear the error and retry the update.
AnswerB

Leaving the server in its current state is crucial as it preserves the system's exact condition and any error logs for forensic analysis, preventing further unintended changes. Escalating to the change manager ensures adherence to ITIL best practices, allowing for proper incident management and coordination with relevant teams, including the Change Advisory Board (CAB) if necessary. This approach facilitates a controlled resolution, minimizes business impact, and ensures the failure is documented for post-implementation review and process improvement.

Why this answer

The technician has no documented rollback plan, and the change management process requires that any deviation from the approved plan—such as a failed update—must be escalated to the change manager for a decision. Attempting an undocumented rollback or continuing to troubleshoot without authorization risks data corruption, service disruption, or violating compliance policies. The technician’s primary duty is to preserve the server’s current state and follow the escalation path defined in the change management policy.

Exam trap

The trap here is that candidates assume built-in recovery options (Option A) are always safe to use, but the exam tests that without a documented rollback plan, any recovery attempt is an unauthorized change that violates change management procedures.

How to eliminate wrong answers

Option A is wrong because using the server’s built-in recovery options without a documented rollback plan is an unauthorized deviation from the change management process; it could cause irreversible data loss or configuration corruption, and the technician has no approved procedure to validate the recovery steps. Option C is wrong because continuing to troubleshoot past the maintenance window without authorization violates the change window constraints and could extend the outage beyond the approved downtime, increasing risk to the finance department’s operations. Option D is wrong because rebooting the server to clear the error and retrying the update is an unapproved action that may mask the root cause, potentially leading to a partial or inconsistent update state, and it ignores the requirement to escalate when the documented plan fails.

159
MCQhard

A user's Windows 11 PC displays a 'Critical Process Died' blue screen error after a recent Windows Update. The system boots into a recovery loop. Which advanced startup option should be used to remove the problematic update?

A.Boot into Safe Mode from the recovery environment and uninstall the latest update.
B.Use System Restore to revert to a point before the update.
C.Run the Windows Memory Diagnostic tool to check for RAM issues.
D.Perform a clean installation of Windows 11 using the recovery USB.
AnswerA

This is the most direct and least disruptive solution when a critical process crash occurs immediately after an update, strongly indicating an incompatibility or corruption introduced by the patch. Safe Mode, accessed via the Windows Recovery Environment (WinRE), loads only essential system drivers and services, bypassing the problematic components. This allows the technician to boot the system stably and then use the "Uninstall Updates" feature in Windows Settings or Control Panel to remove the offending patch, resolving the critical process error without data loss.

Why this answer

Booting into Safe Mode from the Windows Recovery Environment (WinRE) allows you to access the desktop with minimal drivers and services, then use Settings > Windows Update > Update History > Uninstall updates to remove the problematic cumulative update. This directly addresses the 'Critical Process Died' bugcheck (0x000000EF), which often results from a corrupted system file or driver conflict introduced by a recent update, and Safe Mode bypasses the crash loop to enable the uninstall.

Exam trap

The trap here is that candidates often choose System Restore (Option B) because it sounds like a general 'undo' tool, but they fail to recognize that uninstalling the specific update is faster, more targeted, and does not require a pre-existing restore point, which may not exist after a forced update.

How to eliminate wrong answers

Option B is wrong because System Restore reverts the entire system state (registry, system files, installed applications) to a previous restore point, which is a broader and slower operation than simply uninstalling the specific update; it may also fail if no restore point exists or if the update itself corrupted the restore point data. Option C is wrong because the Windows Memory Diagnostic tool tests for physical RAM defects (e.g., bad memory cells, timing errors) and is irrelevant to a software-caused stop code like 'Critical Process Died' that stems from a Windows Update. Option D is wrong because performing a clean installation of Windows 11 using a recovery USB is a destructive, last-resort process that wipes all data and applications, whereas the problem can be solved non-destructively by simply removing the offending update.

160
MCQmedium

Your company is deploying a new application that requires .NET Framework 3.5 on multiple Windows 10 workstations. You need to enable this feature on a single test machine first. Which tool should you use?

A.Programs and Features
B.Windows Features
C.Device Manager
D.Services
AnswerB

The "Turn Windows features on or off" utility, often accessed through Programs and Features, is the correct and dedicated interface for enabling or disabling optional Windows components. These features, such as Hyper-V, Internet Information Services (IIS), or specific versions of the .NET Framework, are pre-installed but not always active by default. This tool allows administrators to integrate these functionalities directly into the operating system, often without requiring separate installation media, to meet application dependencies.

Why this answer

Windows Features (accessible via 'Turn Windows features on or off' in the Control Panel or Settings) is the correct tool to enable .NET Framework 3.5 on a Windows 10 workstation. This feature includes .NET 2.0 and 3.0, and it can be installed from local sources or Windows Update. Programs and Features is used for uninstalling or changing installed programs, not for enabling Windows roles or features.

Exam trap

The trap here is that candidates confuse 'Programs and Features' (which manages installed applications) with 'Turn Windows features on or off' (which manages Windows components), leading them to select A instead of B.

How to eliminate wrong answers

Option A is wrong because Programs and Features is designed for managing installed applications (e.g., uninstalling, repairing, or changing software), not for enabling Windows OS features like .NET Framework 3.5. Option C is wrong because Device Manager is used to manage hardware devices, drivers, and resources (e.g., updating drivers, disabling devices), not for enabling software features. Option D is wrong because Services (services.msc) manages background Windows services (e.g., starting, stopping, or configuring service startup types), not for installing or enabling Windows features.

161
MCQhard

During a routine security walkthrough, you notice that an employee has propped open a secured door to the server room with a doorstop to allow easy access for a cleaning crew. What is the most immediate action you should take?

A.Remove the doorstop and close the door.
B.Document the incident and report it to the security manager.
C.Reprimand the employee who propped the door.
D.Install a door alarm that sounds if the door is open too long.
AnswerA

Removing the doorstop and closing the door immediately restores the physical control that was defeated, eliminating the exposure before anyone exploits it. Reporting or policy changes follow afterwards; the propped door is the active vulnerability requiring instant remediation.

Why this answer

The immediate priority is to restore the physical security control by removing the doorstop and closing the door. A propped-open door bypasses the access control system (e.g., card reader, electronic lock), allowing unauthorized entry to the server room. This action directly mitigates the active vulnerability without delay.

Exam trap

CompTIA often tests the distinction between immediate corrective action and administrative follow-up, trapping candidates who choose documentation or reprimand over directly closing the security gap.

How to eliminate wrong answers

Option B is wrong because documenting and reporting, while important, is a secondary step; the immediate threat of unauthorized access must be addressed first. Option C is wrong because reprimanding the employee is a managerial or HR action that does not resolve the current security breach. Option D is wrong because installing a door alarm is a long-term corrective control, not an immediate response to an active physical security gap.

162
MCQmedium

After installing a new printer, a user reports that print jobs are stuck in the queue and cannot be deleted. You need to stop and restart the print spooler service to clear the queue. Which administrative tool allows you to manage this service?

A.Task Manager
B.Services.msc
C.Device Manager
D.Event Viewer
AnswerB

Services.msc lists all services, including the Print Spooler, and allows you to stop, start, or restart them.

Why this answer

The Print Spooler is a Windows service that manages print jobs. To stop and restart it, you need the Services management console, which is accessed by running 'services.msc'. This tool allows you to start, stop, pause, and configure services, making it the correct administrative tool for clearing a stuck print queue.

Exam trap

The trap here is that candidates often confuse Task Manager with service management because both can stop processes, but Task Manager cannot manage Windows services directly; only services.msc or the command line can stop and restart the Print Spooler service.

How to eliminate wrong answers

Option A is wrong because Task Manager is used to manage running processes, applications, and system performance, not to control Windows services like the Print Spooler. Option C is wrong because Device Manager is used to manage hardware devices and drivers, not to start or stop services. Option D is wrong because Event Viewer is used to view system, security, and application logs, not to manage services.

163
MCQmedium

A technician is asked to dispose of several old company laptops that contain sensitive customer data. The company wants to ensure the data cannot be recovered while still allowing the laptops to be donated. Which of the following should the technician perform?

A.Run a standard format on the drives.
B.Delete all partitions and create a new one.
C.Perform a secure erase or overwrite the drives.
D.Physically destroy the hard drives.
AnswerC

Secure erase or overwriting writes patterns across the entire drive, making the original data unrecoverable while leaving the drive functional for donation. This satisfies both the security and reuse requirements. It is the appropriate sanitization method when the hardware will remain in service elsewhere.

Why this answer

Secure erase or overwriting renders the original data unrecoverable while keeping the drive usable, so the laptops can be donated. Physical destruction prevents donation, and formatting or repartitioning leaves recoverable data. The technician should choose a sanitization method that meets both the security and reuse goals.

Exam trap

The trap here is treating formatting or deleting partitions as sufficient data destruction, when those methods leave the original data recoverable.

164
MCQeasy

During a routine security audit, a technician discovers that a user's workstation has a program that records keystrokes and periodically sends the data to an external server. The user denies installing any software recently. Which type of malware is this?

A.Trojan horse
B.Worm
C.Keylogger
D.Ransomware
AnswerC

A keylogger is a type of surveillance software or hardware designed to record every keystroke made on a target computer's keyboard. These recorded inputs, which can include sensitive information like usernames, passwords, and credit card numbers, are then typically stored locally or covertly transmitted to a remote attacker's server. This direct and specific functionality of capturing and exfiltrating keystroke data precisely matches the scenario of a security audit discovering a mechanism for recording keystrokes and sending them to a server.

Why this answer

The program described records keystrokes and exfiltrates them to an external server, which is the defining behavior of a keylogger. This type of malware captures user input, such as usernames and passwords, and sends the data to an attacker. The user's denial of installing software suggests the keylogger may have been delivered stealthily, often via a Trojan horse or drive-by download, but the core functionality is keylogging.

Exam trap

The trap here is that candidates may confuse the delivery method (e.g., a Trojan horse) with the malware's primary function, but the question focuses on the observed behavior (keystroke recording and data exfiltration), which directly identifies it as a keylogger, not the method of installation.

How to eliminate wrong answers

Option A is wrong because a Trojan horse is a type of malware that disguises itself as legitimate software to trick users into installing it, but the question specifically describes keystroke recording and data exfiltration, which is the primary function of a keylogger, not the deceptive delivery mechanism of a Trojan. Option B is wrong because a worm is a self-replicating malware that spreads across networks without user interaction, exploiting vulnerabilities to propagate, whereas the described program does not exhibit self-replication or network-spreading behavior. Option D is wrong because ransomware encrypts files or locks the system and demands a ransom for decryption, which is not mentioned; the program here silently records keystrokes and sends data, not extorts the user.

165
MCQmedium

A technician is troubleshooting a PC that repeatedly shuts down. The user mentions the computer is plugged into a power strip that also has a space heater and a laser printer. What is the most likely cause of the shutdowns?

A.The computer's power supply is failing.
B.The power strip is overloaded and cannot supply stable voltage.
C.The space heater is emitting electrical interference.
D.The laser printer needs a toner replacement.
AnswerB

An overloaded power strip occurs when the cumulative current draw of all connected devices exceeds the strip's maximum rated amperage. This excessive demand can lead to a significant voltage drop, known as a brownout, which causes sensitive electronics like a PC to shut down to protect components. Alternatively, the power strip's internal circuit breaker may trip, cutting power to prevent overheating and potential fire hazards.

Why this answer

The most likely cause is that the power strip is overloaded because it is simultaneously supplying power to a space heater (a high-wattage resistive load), a laser printer (which draws significant current during fuser warm-up), and the PC. This overload causes the power strip's circuit breaker to trip or the voltage to sag below the PC's power supply tolerance, resulting in repeated shutdowns. Option B is correct because the combined current draw exceeds the power strip's rated capacity, leading to unstable voltage delivery.

Exam trap

CompTIA often tests the concept that high-wattage peripherals sharing a power strip can cause voltage sags or breaker trips, leading candidates to incorrectly blame the PC's power supply (Option A) or assume electrical interference (Option C) rather than recognizing the simple overload condition.

How to eliminate wrong answers

Option A is wrong because a failing power supply typically causes random shutdowns or failure to power on, but the user's description of a shared power strip with high-draw devices points to an external power issue, not an internal component failure. Option C is wrong because electrical interference from a space heater would cause data corruption or erratic behavior, not systematic shutdowns; space heaters are resistive loads that do not generate significant EMI that would trip a PC's overcurrent protection. Option D is wrong because a laser printer needing a toner replacement would produce faded prints or a 'toner low' warning, but it has no effect on the PC's power stability or shutdown behavior.

166
MCQeasy

A small business owner wants to prevent employees from changing system time, installing printers, and modifying power settings on their Windows 10 workstations. They do not want to remove local admin rights entirely. Which Windows security tool should be used to apply these restrictions?

A.Windows Defender Security Center
B.Local Users and Groups (lusrmgr.msc)
C.Local Group Policy Editor (gpedit.msc)
D.Registry Editor (regedit)
AnswerC

Local Group Policy Editor applies computer-level restrictions to specific settings, including system time changes, printer installation and power configuration, while leaving users' local administrator membership intact. This satisfies the requirement to restrict behaviour without removing admin rights.

Why this answer

The Local Group Policy Editor (gpedit.msc) allows administrators to configure granular security settings for users and computers without removing local admin rights. Specifically, it can enforce restrictions on system time changes (via 'Change the system time' user right), printer installation (via 'Device Installation Restrictions'), and power settings (via 'Power Management' policies) through Computer Configuration or User Configuration nodes. This tool applies these settings via Group Policy objects that are processed locally, making it the correct choice for non-domain workstations.

Exam trap

A common misconception tested in this exam is that Local Users and Groups (lusrmgr.msc) can enforce granular restrictions like printer installation or power settings, when in reality it only manages group membership and cannot apply detailed policy-based controls.

How to eliminate wrong answers

Option A is wrong because Windows Defender Security Center focuses on antivirus, firewall, and device security features (e.g., exploit protection, app & browser control), not on user permission restrictions like system time or printer installation. Option B is wrong because Local Users and Groups (lusrmgr.msc) manages user accounts and group memberships, but it cannot apply granular policy restrictions such as preventing printer installation or modifying power settings; it only controls membership in groups like Administrators or Users. Option D is wrong because Registry Editor (regedit) directly edits the Windows Registry, which is error-prone, unsupported for policy enforcement, and lacks the structured, auditable interface of Group Policy; it is not a security tool designed for applying consistent restrictions across multiple users.

167
MCQmedium

A small office has several old CRT monitors that need to be replaced. The office manager asks the technician to simply place them in the dumpster. What should the technician do?

A.Comply with the manager's request to avoid conflict.
B.Break the monitors down to salvage the copper, then discard the glass.
C.Contact a licensed e-waste recycler to pick up the monitors for proper disposal.
D.Donate the monitors to a local school.
AnswerC

Contacting a licensed e-waste recycler is the correct and legally compliant method for disposing of old CRT monitors. These specialized facilities are equipped to safely handle and process hazardous materials such as leaded glass, cadmium, and mercury found within CRTs. They ensure that toxic components are properly neutralized or contained, and valuable materials are recovered, adhering strictly to environmental protection agency regulations and preventing ecological harm.

Why this answer

CRT monitors contain hazardous materials such as lead, mercury, and cadmium, and are classified as electronic waste (e-waste). Proper disposal requires contacting a licensed e-waste recycler who can handle and recycle the hazardous components in compliance with environmental regulations. Simply dumping them is illegal in most jurisdictions.

Exam trap

The trap is that candidates may think donating old equipment is always the environmentally friendly choice, but for CRTs, hazardous materials make licensed recycling the only compliant option.

How to eliminate wrong answers

Option A is wrong because complying with the manager's request to dump the monitors violates environmental regulations and company policy — technicians must follow legal and ethical disposal procedures, not illegal instructions. Option B is wrong because breaking down monitors to salvage copper exposes the technician to hazardous materials like lead and mercury and still results in improper disposal of the remaining glass and components. Option D is wrong because donating old CRT monitors to a school is not appropriate — they are obsolete, may not work, and still contain hazardous materials that require proper end-of-life management; donation does not absolve disposal responsibilities.

168
MCQeasy

During a software installation, a technician receives a pop-up warning that the application requires administrator privileges. The user is logged in with a standard account. What is the most appropriate action for the technician to take?

A.Ask the user to log in with an administrator account and install the software.
B.Right-click the installer and select 'Run as administrator', then enter admin credentials.
C.Temporarily add the user to the Administrators group, install, then remove them.
D.Cancel the installation and escalate to a senior technician.
AnswerB

This is the most appropriate and secure method for installing software that requires elevated privileges. By right-clicking the installer and selecting 'Run as administrator', the User Account Control (UAC) prompt appears, allowing the technician to input their own administrative credentials. This grants the installer the necessary elevated permissions for the installation without permanently changing the user's account type or exposing administrative passwords to the end-user, thereby adhering to the principle of least privilege.

Why this answer

The technician can use the 'Run as administrator' feature to supply administrative credentials for a one-time elevated installation without changing the user's account type. This adheres to the principle of least privilege, maintaining security by not permanently elevating the standard user's rights.

Exam trap

CompTIA often tests the misconception that temporarily adding a user to the Administrators group is acceptable, when in fact the 'Run as administrator' feature is the proper, secure method for one-time elevation without altering account permissions.

How to eliminate wrong answers

Option A is wrong because asking the user to log in with an administrator account violates security best practices by exposing administrative credentials to a standard user and potentially leaving the system in an elevated state. Option C is wrong because temporarily adding the user to the Administrators group introduces unnecessary risk of privilege escalation and may leave residual group membership changes if not properly reverted. Option D is wrong because escalating to a senior technician is an overreaction for a routine task that the technician can resolve directly using 'Run as administrator'.

169
MCQmedium

A technician is setting up a new wireless network for a small office. They want to ensure that only company-issued devices can connect, and that data transmitted over the air is encrypted. Which combination of settings should they use?

A.WPA2 with TKIP encryption and SSID broadcast disabled.
B.WPA3 with AES encryption and MAC address filtering.
C.WEP with 128-bit key and a strong password.
D.Open network with a captive portal requiring employee login.
AnswerB

WPA3 with AES encrypts over-the-air traffic using the strongest current Wi-Fi cipher, while MAC address filtering restricts association to company-issued device hardware addresses. Together they satisfy both stated constraints: encryption of transmitted data and limiting connectivity to approved devices.

Why this answer

WPA3 with AES encryption provides the strongest wireless security standard, ensuring robust data confidentiality and integrity. MAC address filtering adds an additional layer of access control, allowing only company-issued devices (with pre-approved MAC addresses) to connect, which aligns with the requirement to restrict access to authorized devices.

Exam trap

A common misconception is that disabling SSID broadcast or using MAC filtering alone provides strong security, but the trap here is that encryption (WPA3 with AES) is the primary defense, and MAC filtering is only a supplementary control, not a replacement for encryption.

How to eliminate wrong answers

Option A is wrong because WPA2 with TKIP encryption is outdated and insecure; TKIP is deprecated and vulnerable to attacks like Michael and Beck-Tews, and disabling SSID broadcast only hides the network name, not preventing determined attackers from discovering it. Option C is wrong because WEP with any key length, including 128-bit, is fundamentally broken and can be cracked in minutes using tools like aircrack-ng, providing no real security. Option D is wrong because an open network with a captive portal does not encrypt data transmitted over the air, leaving it vulnerable to eavesdropping and man-in-the-middle attacks, and it does not prevent unauthorized devices from associating with the network.

170
MCQhard

A company is moving to a new office and needs to dispose of 200 fluorescent light tubes from the old ceiling fixtures. What is the legally required and environmentally responsible disposal method?

A.Break them into small pieces and place them in a sealed bag in the trash.
B.Contact a certified universal waste recycler to pick them up.
C.Place them in the regular recycling bin for glass.
D.Burn them in an industrial incinerator.
AnswerB

Contacting a certified universal waste recycler is the correct procedure because these facilities are specifically licensed and equipped to safely process mercury-containing lamps. They employ specialized techniques to capture mercury, separate glass and metal components, and ensure proper containment and recycling, thereby preventing environmental contamination and ensuring compliance with hazardous waste disposal regulations.

Why this answer

Fluorescent light tubes contain mercury, a hazardous substance, so they are classified as universal waste under the Resource Conservation and Recovery Act (RCRA). Option B is correct because certified universal waste recyclers are legally authorized to handle, transport, and recycle mercury-containing lamps, ensuring environmental compliance and safety.

Exam trap

The trap here is that candidates may assume 'recycling' means placing items in a standard bin, but CompTIA A+ 220-1202 tests the specific legal classification of fluorescent lamps as universal waste requiring a certified handler.

How to eliminate wrong answers

Option A is wrong because breaking fluorescent tubes releases toxic mercury vapor and creates hazardous dust, which is illegal under EPA universal waste rules and poses serious health risks. Option C is wrong because regular glass recycling bins cannot process mercury-containing lamps; the mercury would contaminate the recycling stream and violate hazardous waste disposal regulations. Option D is wrong because industrial incinerators are not designed for universal waste lamps; burning them releases mercury into the atmosphere, which is prohibited by the Clean Air Act and RCRA.

171
MCQeasy

A customer calls saying that after installing a new application, their Windows 11 desktop icons are scattered and the taskbar keeps disappearing. They need a quick way to restore the default desktop layout and taskbar behavior without affecting personal files. Which built-in tool should you guide them to use?

A.Reset this PC with the 'Keep my files' option.
B.System Restore from the System Protection tab.
C.Refresh the desktop by right-clicking and selecting 'Refresh'.
D.Use the Deployment Imaging Service and Management Tool (DISM) to repair the system image.
AnswerB

System Restore reverts system files and registry to a prior state, which can fix application-induced problems without affecting personal data.

Why this answer

System Restore reverts system files, registry settings, and installed applications to a previous restore point without affecting personal files. Since the issue began after installing a new application, rolling back to a point before that installation will restore the default desktop layout and taskbar behavior. This is the quickest built-in tool for undoing system changes while preserving user data.

Exam trap

The CompTIA A+ exam often tests the distinction between 'System Restore' and 'Reset this PC' — the trap here is that candidates may choose 'Reset this PC with Keep my files' because it sounds like a safe, quick fix, but it is a full OS reinstallation that removes installed applications and settings (though it keeps personal files), whereas System Restore is a targeted rollback that undoes system changes, including removing applications installed after the restore point, while preserving user data.

How to eliminate wrong answers

Option A is wrong because 'Reset this PC with the Keep my files option' reinstalls Windows and removes all installed applications and settings, which is a more drastic and time-consuming process than needed for a simple layout/taskbar issue. Option C is wrong because right-clicking and selecting 'Refresh' only redraws the current desktop icons and does not restore their original positions or fix taskbar behavior. Option D is wrong because DISM is used to repair the Windows system image (e.g., corrupted component store) and does not revert application-installation changes or restore desktop/taskbar settings.

172
MCQmedium

After a power outage, a Windows 10 computer boots to a black screen with the message 'Bootmgr is missing'. The technician has a Windows installation USB. Which repair command should be used to rebuild the Boot Configuration Data (BCD)?

A.From the recovery command prompt, run 'bootrec /fixmbr'.
B.Run 'bootrec /fixboot'.
C.Run 'bootrec /rebuildbcd'.
D.Run 'sfc /scannow /offbootdir=C:\ /offwindir=C:\Windows'.
AnswerC

The 'bootrec /rebuildbcd' command is the correct solution because it actively scans all disks for compatible Windows installations and then rebuilds the Boot Configuration Data (BCD) store. The BCD store contains crucial boot configuration parameters and entries, including the location of the Windows operating system and its boot options. A 'Bootmgr is missing' error directly points to a corrupted or missing BCD, and this command effectively creates a new, functional BCD, resolving the issue.

Why this answer

The 'Bootmgr is missing' error indicates that the Boot Configuration Data (BCD) store is corrupted or missing. The 'bootrec /rebuildbcd' command scans all disks for Windows installations and prompts you to add them to a new BCD store, directly rebuilding the BCD. This is the correct repair for a missing or corrupt BCD, which is the specific cause of this error.

Exam trap

The trap here is that candidates confuse the purpose of 'bootrec /fixmbr' and 'bootrec /fixboot' (which repair the boot sector and MBR) with rebuilding the BCD store, leading them to choose a wrong option when the specific error is about a missing or corrupt BCD.

How to eliminate wrong answers

Option A is wrong because 'bootrec /fixmbr' repairs the Master Boot Record (MBR) on the system partition, which handles the initial boot process but does not rebuild the BCD store. Option B is wrong because 'bootrec /fixboot' writes a new boot sector to the system partition, which is used for loading the boot manager but does not address a missing or corrupt BCD. Option D is wrong because 'sfc /scannow /offbootdir=C:\ /offwindir=C:\Windows' checks and repairs system file integrity, not the BCD store, and is used for corrupted Windows system files, not boot configuration data.

173
MCQmedium

A technician is tasked with deploying a virtual machine for a new employee. The VM will run a Linux distribution and needs to be isolated from the corporate network but still have internet access for updates. Which network configuration should the technician choose for the VM?

A.Bridged networking
B.NAT (Network Address Translation)
C.Host-only networking
D.Internal networking
AnswerB

NAT lets the VM initiate outbound connections through the host's address for internet updates, while its private address stays unroutable from the corporate network. This satisfies both constraints: isolation from corporate systems and outbound internet access.

Why this answer

NAT (Network Address Translation) allows the VM to access the internet through the host's IP address while keeping the VM on a private subnet, effectively isolating it from the corporate network. The host acts as a router, translating the VM's private IP to the host's external IP for outbound traffic, which meets the requirement of internet access for updates without direct corporate network connectivity.

Exam trap

A common misconception in CompTIA A+ scenarios is that internet access requires a direct network connection, leading candidates to choose bridged networking. However, they overlook the isolation requirement that NAT satisfies by hiding the VM behind the host's IP address.

How to eliminate wrong answers

Option A is wrong because bridged networking places the VM directly on the physical corporate network, giving it its own IP address from the same subnet as the host, which violates the isolation requirement. Option C is wrong because host-only networking creates a private network between the host and VM but does not provide internet access; it lacks a NAT gateway or routing to external networks. Option D is wrong because internal networking only allows communication between VMs on the same host, with no connectivity to the host or the internet, so updates cannot be downloaded.

174
MCQmedium

A small business owner reports that all their Microsoft Office documents are now encrypted with a '.crypt' extension and a ransom note demands payment in cryptocurrency. They have a backup from last week stored on an external drive that was disconnected after the backup. What is the best recovery strategy?

A.Pay the ransom to obtain the decryption key.
B.Restore the files from the disconnected external backup after removing the malware.
C.Run a decryptor tool downloaded from a random website.
D.Use System Restore to revert the system to a previous state.
AnswerB

Restoring files from a disconnected external backup is the most reliable and secure method for data recovery after a ransomware attack. Since the backup medium was offline, it remained immune to the encryption performed by the malware, preserving the integrity of the data. After thoroughly cleaning the infected system to ensure all traces of malware are eradicated, the unencrypted data can be safely restored, minimizing downtime and data loss.

Why this answer

The disconnected external backup is the cleanest recovery path because it was offline when the ransomware executed, so its files are unaffected by the '.crypt' encryption. After removing the malware from the live system (e.g., with Defender offline scan or a known-good AV), the business can restore documents from that backup and resume operations without funding criminals. This is the standard 'restore from known-good backup' remediation taught in CompTIA's malware-removal best practices.

Exam trap

220-1202 often tests the misconception that System Restore or a random online decryptor can undo ransomware encryption, when in fact only a clean, offline backup provides reliable recovery.

How to eliminate wrong answers

Option A is wrong because paying the ransom is discouraged by law enforcement and security best practice — there is no guarantee the attackers will provide a working key, and payment funds further criminal activity. Option C is wrong because downloading a 'decryptor' from a random website is a classic double-extortion or secondary-malware vector; only vendor-published decryptors from trusted sources (e.g., No More Ransom) should ever be considered. Option D is wrong because System Restore only reverts Windows system files, drivers, and registry snapshots — it does not restore user documents, and it will not decrypt files already encrypted by ransomware.

175
MCQeasy

A small office is decommissioning several SSDs from old laptops. The technician needs to ensure data is destroyed securely and the drives can be resold. Which method is most appropriate?

A.Run a multi-pass overwrite with random data.
B.Use the ATA Secure Erase command.
C.Degauss the SSDs to remove magnetic data.
D.Perform a standard delete and empty the recycle bin.
AnswerB

Using the ATA Secure Erase command is the most effective and recommended method for securely decommissioning an SSD. This command is sent directly to the SSD's controller, which then executes an internal, low-level routine to erase all user-addressable NAND flash memory cells to an unprogrammed (empty) state. This process bypasses the file system and wear-leveling logic, ensuring comprehensive data removal and restoring the drive to a factory-like condition, making it safe for reuse or disposal.

Why this answer

The ATA Secure Erase command is the most appropriate method because it is specifically designed for SSDs, issuing a secure erase command at the firmware level that resets all cells to their unprogrammed state, effectively destroying all data in seconds. This method is reliable, fast, and does not wear out the NAND flash cells like multi-pass overwrites would, making it ideal for decommissioning and reselling SSDs.

Exam trap

CompTIA often tests the misconception that degaussing works on all storage media or that multi-pass overwrites are universally secure, when in fact SSDs require a different approach due to their NAND flash architecture and wear-leveling algorithms.

How to eliminate wrong answers

Option A is wrong because multi-pass overwrites are ineffective on SSDs due to wear leveling and the inability to target specific logical blocks; the drive's controller may remap writes to different physical cells, leaving original data intact. Option C is wrong because degaussing uses a strong magnetic field to erase data on magnetic media (HDDs), but SSDs store data electronically in NAND flash cells and are not affected by magnetic fields, so degaussing would not destroy the data and could damage the drive's controller. Option D is wrong because a standard delete and emptying the recycle bin only removes file system pointers, leaving the actual data recoverable with simple software tools, which is not secure destruction.

176
MCQmedium

A user reports that their Windows 11 laptop suddenly shows a blue screen with an error message every time they try to boot. You need to access advanced troubleshooting options to repair the system. Which key should you press during startup to access the Windows Recovery Environment (WinRE)?

A.F8
B.F11
C.F2
D.F12
AnswerB

The F11 key is widely recognized on many modern Windows 11 systems as the hotkey to directly access the Windows Recovery Environment (WinRE). WinRE provides critical troubleshooting and repair options, such as Startup Repair, System Restore, Go back to the previous version, and the ability to access a command prompt for advanced diagnostics. This environment is essential for resolving boot issues or system instability when Windows fails to start normally, making it the correct choice for recovery.

Why this answer

Pressing F11 during the Windows 11 boot process is the standard key to access the Windows Recovery Environment (WinRE) on most modern systems. WinRE provides advanced troubleshooting tools such as System Restore, Startup Repair, Command Prompt, and Safe Mode, which are essential for repairing a system that fails to boot due to a blue screen error.

Exam trap

The trap here is that candidates often confuse the F8 key (used in legacy Windows) with the modern F11 key for WinRE, or they mistakenly think F2 or F12 are used for recovery instead of firmware or boot menu access.

How to eliminate wrong answers

Option A is wrong because F8 was used in older Windows versions (e.g., Windows 7) to access the Advanced Boot Options menu, but in Windows 11, the F8 key is disabled by default for faster boot times and is not the standard key to access WinRE. Option C is wrong because F2 typically enters the system BIOS or UEFI firmware settings, not the Windows Recovery Environment. Option D is wrong because F12 usually opens the one-time boot menu for selecting a boot device (e.g., USB or DVD), not WinRE.

177
MCQeasy

A user is setting up a new Android tablet for a child and wants to restrict access to adult content, limit app purchases, and set screen time limits. Which built-in Android feature should the technician configure?

A.Guest Mode
B.Google Family Link
C.Do Not Disturb
D.Developer Options
AnswerB

Google Family Link satisfies every constraint: it filters adult content, requires approval for purchases, and enforces daily screen time limits on a child's supervised Google account. Unlike Digital Wellbeing, which only tracks usage, Family Link applies enforceable restrictions remotely from the parent's device, matching the tablet setup scenario exactly.

Why this answer

Google Family Link is the built-in Android parental control feature that allows a technician to restrict adult content via SafeSearch filtering, limit app purchases by requiring parental approval, and set screen time limits through daily usage schedules. It operates by linking the child's device to a parent's Google account, enabling remote management of digital ground rules without third-party software.

Exam trap

CompTIA A+ often tests the distinction between general user modes (Guest Mode) and dedicated parental control features (Family Link), leading candidates to mistakenly choose Guest Mode because they confuse temporary user isolation with content and time restrictions.

How to eliminate wrong answers

Option A is wrong because Guest Mode provides a temporary user session with no access to the primary user's apps or data, but it does not include any content filtering, purchase restrictions, or screen time controls. Option C is wrong because Do Not Disturb only silences notifications and calls; it cannot block adult content, limit app purchases, or enforce screen time limits. Option D is wrong because Developer Options are intended for app development and debugging (e.g., USB debugging, GPU rendering) and offer no parental control or content restriction capabilities.

178
MCQeasy

A graphic designer needs to create a bootable macOS installer on an external SSD to deploy macOS Sonoma to multiple iMacs in the office. They have the 'Install macOS Sonoma.app' file. Which built-in macOS tool should they use to create the bootable drive?

A.Disk Utility to restore the .app file to the SSD.
B.System Information to verify the SSD is bootable.
C.Terminal with the 'createinstallmedia' command.
D.Migration Assistant to copy the app to the SSD.
AnswerC

The Terminal, combined with Apple's `createinstallmedia` command, is the official and most reliable method for creating a bootable macOS installer. This command-line utility, located within the macOS installer application bundle, automates the complex process of extracting the necessary boot files, copying the installation packages, and properly configuring a target USB drive or external volume to be bootable. It ensures the resulting media can be used to install macOS on compatible systems, making it the correct tool for this specific task.

Why this answer

The correct tool is Terminal with the 'createinstallmedia' command because it is the built-in macOS utility specifically designed to create a bootable installer from the 'Install macOS Sonoma.app' file. This command writes the necessary boot files and installer data to the target volume, ensuring the external SSD can boot and install macOS on multiple iMacs.

Exam trap

The trap here is that candidates may think Disk Utility can create a bootable installer by simply restoring the .app file, but Disk Utility cannot interpret an application bundle as a bootable source; only the 'createinstallmedia' command properly writes the installer's bootable structure.

How to eliminate wrong answers

Option A is wrong because Disk Utility cannot restore a .app file to create a bootable installer; it is used for formatting, partitioning, and restoring disk images, not for creating bootable macOS installers. Option B is wrong because System Information only reports hardware and software details, such as whether a drive is connected or its partition scheme, but it cannot create a bootable installer. Option D is wrong because Migration Assistant is designed to transfer user data, applications, and settings from one Mac to another, not to create bootable installer media.

179
MCQmedium

A technician is configuring a new server and follows a documented standard operating procedure (SOP). After completion, the technician realizes the SOP is outdated and omits a critical security setting. What should the technician do?

A.Apply the missing setting and update the SOP to include it.
B.Ignore the missing setting since the SOP was followed.
C.Submit a change request to update the SOP without applying the setting.
D.Revert the server configuration and wait for an updated SOP.
AnswerA

Applying the missing security setting closes the vulnerability immediately, and updating the SOP prevents recurrence for future builds. This satisfies both the security requirement and the documentation control, rather than leaving the server misconfigured or the procedure stale.

Why this answer

The technician discovered a security gap in the SOP that could leave the server vulnerable. The proper action is to immediately apply the missing critical security setting to protect the server, then update the SOP to reflect the correct procedure. This aligns with change management best practices where security findings take precedence over outdated documentation, and the SOP must be corrected to prevent future misconfigurations.

Exam trap

The trap here is that candidates may think following the SOP exactly is always correct, but CompTIA A+ tests the principle that security and risk mitigation override strict adherence to outdated documentation when a known vulnerability is identified.

How to eliminate wrong answers

Option B is wrong because ignoring a known security omission violates the principle of due diligence and could expose the server to exploitation; following an outdated SOP does not excuse the technician from applying necessary security controls. Option C is wrong because submitting a change request to update the SOP without applying the setting leaves the server in an insecure state during the approval process, which is unacceptable for critical security configurations. Option D is wrong because reverting the server and waiting for an updated SOP introduces unnecessary downtime and delays, while the technician already knows the correct setting and can apply it immediately to secure the server.

180
MCQeasy

A user is traveling and needs to access a file on their office computer. They have a dynamic IP address at the hotel. Which remote access technology should the technician recommend for a secure connection?

A.Configure a direct RDP connection using the user's home IP address.
B.Set up a Virtual Private Network (VPN) client on the user's laptop to connect to the office network.
C.Use a remote desktop gateway that requires a static IP on the user's end.
D.Email the file to the user as an attachment.
AnswerB

Setting up a Virtual Private Network (VPN) client on the user's laptop is the most secure and flexible solution for remote access. A VPN establishes an encrypted tunnel over any internet connection, allowing the user's laptop to securely become a virtual part of the office network, regardless of the user's current IP address. This provides encrypted access to all authorized internal network resources, such as shared drives, applications, and other services, as if the user were physically in the office.

Why this answer

A VPN client creates an encrypted tunnel between the user's laptop and the office network, allowing secure access to files regardless of the user's dynamic IP address. VPNs authenticate the user and encrypt all traffic, protecting data over untrusted networks like hotel Wi-Fi.

Exam trap

CompTIA often tests the misconception that remote access requires a static IP or that direct RDP is acceptable, but the key is that a VPN handles dynamic IPs and provides encryption, which is essential for secure remote access over public networks.

How to eliminate wrong answers

Option A is wrong because a direct RDP connection using the user's home IP address is irrelevant—the user is at a hotel with a dynamic IP, not at home, and RDP directly exposed to the internet is insecure and not recommended. Option C is wrong because a remote desktop gateway does not require a static IP on the user's end; it typically uses a gateway server that accepts connections from any IP, but the statement incorrectly implies a static IP is mandatory. Option D is wrong because emailing the file as an attachment is not a remote access technology and poses security risks (e.g., interception, lack of encryption in transit) and does not provide ongoing access to the office computer.

181
MCQeasy

A user reports that their Windows 10 computer is displaying a message that 'Windows Defender Antivirus is turned off' even though they have not disabled it. They have also noticed that they cannot open the Windows Security app. What is the most likely cause?

A.Windows Defender is disabled via Group Policy
B.The computer is infected with malware
C.Windows needs a critical update
D.User Account Control is blocking the app
AnswerB

Malware can disable Windows Defender and block the Windows Security app, producing exactly the reported symptoms. This satisfies the stem's constraint: protection switched off without user action, plus an unopenable Security app. Rogue security software and some trojans specifically target these components to evade detection, so infection is the most likely cause.

Why this answer

When a user sees 'Windows Defender Antivirus is turned off' and cannot open the Windows Security app, the most likely cause is malware that has disabled the antivirus and blocked access to security settings to prevent removal. Malware often modifies registry keys or terminates Windows Defender services (e.g., WinDefend) to evade detection, and it may also corrupt or block the Windows Security Center UI (SecurityHealthService.exe). This is a common symptom of ransomware or trojans that specifically target Windows Defender.

Exam trap

Candidates may incorrectly attribute this to Group Policy (Option A) because the symptom resembles a managed environment, but malware can achieve the same effect locally. The inability to open the Windows Security app is a key differentiator that points to infection rather than policy.

How to eliminate wrong answers

Option A is wrong because Group Policy disabling Windows Defender would typically prevent it from running, but the user would still be able to open the Windows Security app (it would show a 'managed by your organization' message). Option C is wrong because a critical update might cause temporary issues, but it would not independently disable Defender and block the Security app; updates do not intentionally break security features. Option D is wrong because User Account Control (UAC) prompts for elevation but does not block the Windows Security app from launching; if UAC were the issue, the user would see a prompt, not a complete inability to open the app.

182
MCQeasy

A user working from home reports that they can no longer connect to the company's internal file server using Remote Desktop. They confirm their internet connection is working. Which remote access technology should the technician verify is still active on the user's VPN client?

A.SSH tunnel
B.Remote Desktop Gateway
C.VPN connection
D.VNC server
AnswerC

A Virtual Private Network (VPN) connection establishes a secure, encrypted tunnel between a remote user's device and the corporate network, effectively extending the internal LAN to the user's location. This connection is essential for routing traffic to internal IP addresses and accessing resources like RDP servers that are protected behind the corporate firewall. Therefore, verifying the operational status of the VPN client is the crucial first step to ensure the user has network connectivity to internal resources.

Why this answer

The user's internet connection is working, but they cannot reach the internal file server via Remote Desktop. This indicates the VPN tunnel, which provides encrypted access to the internal network, has likely dropped or is misconfigured. Without an active VPN connection, the user's client cannot route traffic to the private IP range of the file server, even though general internet access is available.

Exam trap

CompTIA often tests the misconception that Remote Desktop Gateway (RD Gateway) is a VPN client technology, when in fact it is a separate role that proxies RDP connections over HTTPS and does not provide full network-layer access like a VPN tunnel does.

How to eliminate wrong answers

Option A is wrong because an SSH tunnel is a port-forwarding mechanism typically used for secure shell access or specific TCP port forwarding, not for establishing a full network-layer connection to an internal corporate network; it would not be the primary technology verified on a VPN client. Option B is wrong because Remote Desktop Gateway (RD Gateway) is a role service that allows RDP connections over HTTPS from the internet, but it is not a VPN client technology; the question specifically asks about verifying a technology on the user's VPN client. Option D is wrong because a VNC server is a remote desktop sharing protocol that operates over a direct network connection or VPN, but it is not a VPN client technology itself; verifying a VNC server would not restore network-layer access to the internal file server.

183
MCQmedium

During a security incident, you need to identify which processes are listening on specific network ports on a Windows server. Which command-line tool should you use?

A.nslookup
B.tracert
C.netstat -an
D.ipconfig /all
AnswerC

Correct. netstat -an displays all active connections and listening ports with numerical addresses, helping identify suspicious services.

Why this answer

The `netstat -an` command displays all active TCP connections and the TCP/UDP ports on which the computer is listening, with numerical addresses and port numbers. This makes it the correct tool to identify which processes are listening on specific network ports during a security incident on a Windows server.

Exam trap

CompTIA often tests the distinction between commands that show network configuration (ipconfig) versus those that show active connections and listening ports (netstat), leading candidates to confuse ipconfig /all as a tool for port enumeration.

How to eliminate wrong answers

Option A is wrong because `nslookup` is a DNS query tool used to resolve domain names to IP addresses, not to display listening ports or network connections. Option B is wrong because `tracert` (trace route) is used to determine the path packets take to a destination, showing hop-by-hop latency, not local port listening states. Option D is wrong because `ipconfig /all` displays detailed TCP/IP configuration for all network adapters, such as IP addresses, subnet masks, and DNS servers, but does not show listening ports or active connections.

184
MCQhard

A technician is troubleshooting a network switch that has stopped working. Upon arrival, the technician notices a strong smell of burnt plastic and sees that the power cable is melted near the connector. What is the most appropriate safety action?

A.Unplug the power cable from the switch.
B.Turn off the circuit breaker supplying the outlet.
C.Replace the power cable with a new one.
D.Spray the cable with a Class C fire extinguisher.
AnswerB

Turning off the circuit breaker supplying the outlet is the safest and most effective method to de-energize the circuit in this scenario. This action completely isolates the power source from the outlet and the connected switch without requiring the technician to touch the damaged cable or the potentially compromised device. This adheres to fundamental electrical safety protocols, eliminating the immediate risk of electric shock or further damage while allowing for safe inspection.

Why this answer

The strong smell of burnt plastic and melted power cable indicate an electrical fault that could cause a fire or electric shock. Turning off the circuit breaker (Option B) is the most appropriate safety action because it disconnects power at the source, eliminating the risk of arcing or electrocution before any physical contact is made with the damaged equipment.

Exam trap

CompTIA often tests the misconception that unplugging the cable (Option A) is the fastest safe action, but the trap is that touching a melted or damaged connector while the circuit is live can cause electrocution or arc flash, making breaker isolation the correct first step.

How to eliminate wrong answers

Option A is wrong because unplugging the cable from the switch could expose the technician to arcing, electric shock, or burns if the connector is already damaged or shorted. Option C is wrong because replacing the cable without first de-energizing the circuit could cause a short circuit or fire if the outlet or switch power supply is still live. Option D is wrong because a Class C fire extinguisher is designed for electrical fires, but spraying a melted cable that is still energized may not address the underlying electrical hazard and could delay proper de-energization.

185
MCQmedium

A technician is troubleshooting an Android tablet that cannot connect to a corporate Wi-Fi network. Other devices connect fine. The tablet shows 'Saved, secured' but no IP address. What is the most likely cause?

A.The Wi-Fi adapter is faulty.
B.The tablet has a static IP address configured that conflicts with the network.
C.The corporate network requires a VPN profile that is missing.
D.The tablet's MAC address is blocked by the router.
AnswerB

If a tablet is manually configured with a static IP address that conflicts with the network's DHCP range, is already in use by another device, or is on a different subnet than the gateway, it will fail to establish proper network communication. The "Saved, secured" status confirms successful authentication with the access point (Layer 2), but the incorrect static IP prevents the device from communicating at the network layer (Layer 3). This scenario perfectly explains why a device is connected but cannot access network resources or the internet.

Why this answer

The tablet shows 'Saved, secured' but has no IP address, indicating it successfully associated and authenticated with the Wi-Fi network but failed to obtain an IP address via DHCP. A static IP configuration that conflicts with the network's DHCP scope or subnet prevents the device from receiving a valid lease, causing the IP assignment failure while other devices using DHCP connect normally.

Exam trap

CompTIA often tests the distinction between Layer 2 (association/authentication) and Layer 3 (IP assignment) failures, and the trap here is that candidates assume 'Saved, secured' means full connectivity, overlooking that a static IP can cause a Layer 3 issue without any Layer 2 errors.

How to eliminate wrong answers

Option A is wrong because a faulty Wi-Fi adapter would typically prevent association or show 'Saved, secured' at all, and the tablet would likely not see the network or would fail during authentication. Option C is wrong because a missing VPN profile would not prevent IP address assignment; VPNs operate at a higher layer after a network connection is established, and the tablet would still get an IP address from DHCP. Option D is wrong because a MAC address block by the router would prevent association or authentication, resulting in a 'Saved' or 'Authentication error' status, not 'Saved, secured' with no IP address.

186
MCQmedium

A technician is helping a customer configure a new laptop. The customer mentions they received a pop-up on their old computer warning of a virus and a phone number to call for support. The customer called the number and gave remote access to a 'technician' who then installed several programs. What social engineering attack occurred?

A.Shoulder surfing
B.Phishing
C.Tech support scam
D.Dumpster diving
AnswerC

A tech support scam is a form of social engineering where fraudsters impersonate legitimate technical support personnel or companies. They typically use unsolicited pop-up alerts, often displaying alarming security warnings or error messages, to panic users into calling a fake support number. Once contact is established, the scammers then manipulate the victim into granting remote access to their computer or paying for unnecessary "fixes," directly matching the described scenario of a pop-up prompting a phone call.

Why this answer

A tech support scam occurs when attackers impersonate technical support (often via pop-ups with fake virus warnings and phone numbers) to convince victims to call, then persuade them to grant remote access and install malicious software or pay for fake services. The scenario — pop-up warning, phone number, remote access, and installed programs — matches this attack pattern exactly. It is a form of social engineering that exploits fear and urgency.

Exam trap

220-1202 often tests social engineering category confusion — candidates pick phishing because it is the most familiar term, but the exam expects recognition that phone-based impersonation with remote access is specifically a tech support scam.

How to eliminate wrong answers

Option A is wrong because shoulder surfing is physically observing someone's screen or keyboard to steal credentials or data, which does not match the remote-access scam described. Option B is wrong because phishing uses fraudulent emails or messages to trick users into revealing credentials or clicking malicious links; while related, the scenario centers on a phone-based impersonation and remote access, which is specifically a tech support scam. Option D is wrong because dumpster diving involves retrieving discarded documents or media to extract information, unrelated to the pop-up and remote-access scenario.

187
MCQmedium

A user reports that when they connect to the corporate Wi-Fi at a coffee shop, a browser warning appears stating the site's certificate is not trusted. The user is able to browse the internet but sees the warning on every HTTPS site. A technician suspects an on-path attack. Which of the following should the technician check FIRST to confirm the presence of an on-path attack?

A.The DNS server settings on the user's device and compare them to the corporate DNS servers.
B.The certificate chain presented by the browser to see if it is issued by an unknown or self-signed certificate authority.
C.The ARP cache on the user's device to look for duplicate MAC addresses.
D.The Wi-Fi encryption type configured on the user's device to ensure it is using WPA3.
AnswerB

An on-path attack often involves a self-signed or rogue CA certificate to intercept TLS traffic. Inspecting the certificate chain will reveal if the certificate is not issued by a trusted CA, confirming interception. This is the most direct evidence of an on-path attack, as the attacker must present a certificate to decrypt traffic, and it will not be trusted by the user's device.

Why this answer

The certificate chain is the most direct evidence of an on-path attack because the attacker must present a certificate to intercept TLS traffic. If the certificate is self-signed or issued by an untrusted CA, the browser will warn the user. DNS or ARP checks might reveal other attack vectors, but the certificate warning specifically indicates TLS interception, so examining the certificate chain confirms the attack.

Exam trap

The trap here is assuming that a certificate warning always means the website's certificate is expired or misconfigured, rather than considering an on-path attacker presenting a fraudulent certificate.

188
MCQmedium

A customer complains that their Windows 11 laptop cannot connect to the internet, but other devices on the same network work fine. You suspect the IP configuration is incorrect. Which command will release and renew the IP address from the DHCP server?

A.ipconfig /flushdns
B.ipconfig /release then ipconfig /renew
C.ipconfig /all
D.ping 127.0.0.1
AnswerB

This sequence releases the current IP and obtains a new one from DHCP, directly addressing the connectivity issue.

Why this answer

The `ipconfig /release` command releases the current DHCP lease, setting the IP address to 0.0.0.0, and `ipconfig /renew` sends a DHCPDISCOVER broadcast to obtain a new IP configuration from the DHCP server. This is the correct sequence to resolve an incorrect IP configuration that prevents a Windows 11 client from connecting to the internet while other devices work fine.

Exam trap

The exam often tests the exact two-step sequence of `ipconfig /release` then `ipconfig /renew` as a required troubleshooting procedure, and the trap is that candidates may think a single command like `ipconfig /renew` alone is sufficient, or confuse it with other `ipconfig` subcommands like `/flushdns` or `/all`.

How to eliminate wrong answers

Option A is wrong because `ipconfig /flushdns` clears the DNS resolver cache, which resolves hostname-to-IP resolution issues, not IP address configuration problems. Option C is wrong because `ipconfig /all` displays current IP configuration details but does not change or renew the IP address. Option D is wrong because `ping 127.0.0.1` tests the local TCP/IP stack loopback interface and verifies that the protocol is installed, but it does not release or renew the IP address from DHCP.

189
MCQmedium

A company requires that all sensitive data be encrypted when stored on laptops. Which technology should be implemented to ensure data is protected even if a laptop is stolen?

A.File-level encryption using EFS
B.BitLocker Drive Encryption
C.TPM chip only
D.Secure Boot
AnswerB

BitLocker provides full-volume encryption at rest, so data on a stolen laptop remains unreadable without the recovery key or TPM-bound credentials. This directly satisfies the requirement that sensitive stored data stay protected even when the physical device is lost.

Why this answer

BitLocker Drive Encryption provides full-volume encryption that protects all data on the system drive, including the operating system, applications, and user files. Even if a laptop is stolen and the hard drive is removed, the data remains inaccessible without the correct recovery key or authentication credentials, ensuring compliance with data protection requirements.

Exam trap

The trap here is that candidates often confuse file-level encryption (EFS) with full-disk encryption, mistakenly believing that encrypting individual files provides sufficient protection for an entire stolen laptop, when in fact EFS leaves system files, temporary files, and the pagefile unencrypted and vulnerable.

How to eliminate wrong answers

Option A is wrong because file-level encryption using EFS (Encrypting File System) only encrypts individual files or folders and relies on the user's profile and certificate, which can be bypassed if an attacker gains administrative access or extracts the decryption keys from the operating system. Option C is wrong because a TPM chip alone does not encrypt data; it is a hardware component that stores cryptographic keys and can be used with BitLocker to enhance security, but without full-disk encryption software, the data on the drive remains unencrypted and readable. Option D is wrong because Secure Boot is a UEFI feature that verifies the integrity of the boot process to prevent unauthorized operating systems or malware from loading, but it does not encrypt any data on the storage device.

190
MCQmedium

A technician is decommissioning a server that contained highly sensitive financial data. The server has multiple HDDs in a RAID array. The company policy requires data destruction to be certified. Which approach is most efficient and secure?

A.Perform a single overwrite on the RAID logical volume.
B.Remove each drive and wipe them individually using a secure erase tool.
C.Degauss the entire server chassis.
D.Reformat the RAID array and reinstall the OS.
AnswerB

Removing each drive and wiping them individually using a secure erase tool is the most effective method for decommissioning a server with highly sensitive data. This approach bypasses the RAID controller's abstraction layer, allowing direct access to every physical sector on each storage device. A secure erase tool, often implementing standards like NIST SP 800-88, ensures that all data, including hidden sectors and controller-managed areas, is irreversibly overwritten, guaranteeing complete data sanitization.

Why this answer

Secure erase tools (e.g., ATA Secure Erase) perform a cryptographic or full overwrite at the drive firmware level, ensuring each HDD is individually sanitized and can be certified. In a RAID array, the controller may cache or stripe data, so wiping the logical volume (Option A) or reformatting (Option D) does not guarantee all physical sectors on every drive are overwritten, leaving residual data recoverable. Degaussing (Option C) destroys the drives' magnetic media but is impractical for a full chassis and may not provide certified destruction for mixed media.

Exam trap

CompTIA often tests the misconception that wiping a RAID logical volume is equivalent to wiping each physical drive, but the trap is that RAID controllers abstract the physical layout, so logical operations may miss hidden or spare sectors on individual HDDs.

How to eliminate wrong answers

Option A is wrong because a single overwrite on the RAID logical volume only targets the logical block addresses presented by the RAID controller, not the physical sectors on each drive; RAID striping and spare sectors can leave data intact on individual HDDs. Option C is wrong because degaussing the entire server chassis is not feasible—degaussers require close proximity to each drive's platters, and the chassis itself may contain non-magnetic components (e.g., SSDs) that are not affected, plus it does not provide a verifiable certificate for each drive. Option D is wrong because reformatting the RAID array and reinstalling the OS only overwrites file system metadata and a small portion of the data area, leaving the vast majority of financial data recoverable with forensic tools.

191
MCQhard

During a security audit, a technician discovers that a company Android device has an app that can read SMS messages and access contacts without the user's knowledge. The app was sideloaded. What built-in Android security feature could have prevented this?

A.Samsung Knox
B.Google Play Protect
C.Android Device Manager
D.Verified Boot
AnswerB

Google Play Protect scans sideloaded APKs for malware and harmful behaviour before and after installation, satisfying the stem's sideloading constraint. Unlike the Play Store's review process, which only vets distributed apps, Play Protect actively warns or blocks installation of apps requesting dangerous combinations such as SMS and contacts access, preventing silent data harvesting.

Why this answer

Google Play Protect is the correct answer because it is Android's built-in security feature that scans apps for malicious behavior, including those sideloaded from outside the Play Store. It can block or warn about apps that request excessive permissions like reading SMS and accessing contacts without user knowledge. This feature would have prevented the malicious app from being installed or alerted the user before installation.

Exam trap

In this question, the trap is to think that any security feature like Verified Boot or Android Device Manager would prevent sideloading. However, only Play Protect actively scans apps for suspicious behavior and excessive permissions, regardless of installation source.

How to eliminate wrong answers

Option A is wrong because Samsung Knox is a hardware-backed security platform for enterprise devices that provides containerization and secure boot, but it does not scan sideloaded apps for malicious behavior. Option C is wrong because Android Device Manager (now Find My Device) is a remote tracking, locking, and wiping tool, not an app-scanning or permission-control feature. Option D is wrong because Verified Boot ensures the integrity of the system partition at startup by checking cryptographic signatures, but it does not inspect or block sideloaded apps after the device has booted.

192
MCQmedium

A user calls the help desk because their Windows 10 PC is not showing any sound icon in the system tray, and audio is not working. You suspect the audio service is disabled. Which Control Panel applet would you use to check and restart the Windows Audio service?

A.Sound
B.Device Manager
C.Administrative Tools
D.System
AnswerC

Administrative Tools is a folder within the Control Panel (and also accessible via the Start Menu in some Windows versions) that consolidates shortcuts to various system management utilities. Crucially, it provides a direct shortcut to the "Services" console (services.msc), which is the primary graphical interface for viewing, starting, stopping, configuring startup types, and managing dependencies for all Windows services. This makes it the correct path for service management.

Why this answer

The Windows Audio service is a background service that must be running for audio to function. The Administrative Tools applet provides access to the Services console (services.msc), where you can check the status of the Windows Audio service and restart it if it is disabled or stopped. This is the correct tool because the Sound applet only configures playback devices and volume, not service states.

Exam trap

CompTIA often tests the misconception that the Sound applet or Device Manager can manage services, but only Administrative Tools (or directly running services.msc) allows you to check and restart the Windows Audio service.

How to eliminate wrong answers

Option A is wrong because the Sound applet is used to manage playback devices, recording devices, and system sounds, but it does not provide any interface to view or control Windows services. Option B is wrong because Device Manager is used to manage hardware drivers and devices, not to start or stop system services like Windows Audio. Option D is wrong because the System applet displays basic system information, such as OS version and hardware specs, and does not include service management capabilities.

193
MCQmedium

A technician is configuring a new workstation for a user who is blind and uses a screen reader. The user requests that all software be installed with accessibility features enabled. During the setup, the technician encounters an error that requires a command-line fix. What is the most professional approach?

A.Perform the command-line fix silently and inform the user later that everything is working.
B.Explain that a command-line step is needed, ask if they are comfortable with that, and offer to complete it while describing the process.
C.Ask the user to watch the screen and guide you through the command-line steps.
D.Skip the accessibility features to avoid the error, since the screen reader works anyway.
AnswerB

This option demonstrates exemplary professional conduct by prioritizing user communication, consent, and accessibility. Explaining the necessary command-line step and offering to complete it while describing the process ensures the user is fully informed and comfortable with the procedure. This approach respects the user's autonomy and provides transparency, which is crucial for building trust and delivering inclusive technical support, especially when configuring accessibility features.

Why this answer

It respects the user's disability by seeking their consent and providing an accessible description of the command-line process, aligning with both professional communication and the requirement to maintain accessibility. The technician demonstrates empathy and collaboration, ensuring the user remains informed and in control of their workstation setup.

Exam trap

The trap here is that candidates may assume technical proficiency overrides user consent, or they may fail to adapt communication methods for users with disabilities, leading them to choose option A or C instead of the collaborative approach in B.

How to eliminate wrong answers

Option A is wrong because performing the fix silently violates professional ethics by withholding information from the user, especially one who relies on assistive technology and may need to understand the change for future troubleshooting. Option C is wrong because asking a blind user to watch the screen is insensitive and impractical, as screen readers provide auditory output, not visual guidance; this option shows a lack of understanding of accessibility needs. Option D is wrong because skipping accessibility features to avoid an error undermines the user's explicit request and could leave the system non-compliant with accessibility standards, potentially causing issues with the screen reader's functionality.

194
MCQeasy

A user at a small office reports that whenever they connect to the corporate Wi-Fi in the break room, their laptop warns that the network is unsecured and other devices on the same network can see their traffic. The access point in the break room broadcasts an open SSID with no password. Which of the following should a technician configure on the access point to protect wireless traffic while keeping the SSID available to employees?

A.Enable WPA3-Personal with SAE
B.Change the access point to operate on the 5 GHz band only
C.Disable SSID broadcast on the access point
D.Enable MAC address filtering for known employee devices
AnswerA

WPA3-Personal with Simultaneous Authentication of Equals replaces the WPA2 pre-shared key handshake with a password-authenticated key exchange, protecting the wireless traffic and preventing offline dictionary attacks. It keeps a single shared passphrase for employees while encrypting each session, directly addressing the open, unencrypted break-room network described.

Why this answer

The reported problem is an open wireless network where traffic is visible to other devices. The fix must add authentication and encryption to the wireless link. WPA3-Personal with SAE provides strong per-session encryption using a shared passphrase, which fits a small office that wants employees to connect with one password while keeping the SSID broadcast for easy discovery.

Exam trap

The trap here is assuming that hiding the SSID or filtering MAC addresses secures a wireless network, when neither provides encryption for the traffic.

195
MCQmedium

During a security incident, a technician discovers that a user's computer has a program that hides its processes from Task Manager and allows an attacker to remotely control the system. The technician suspects a rootkit. Which removal method is most effective for a rootkit?

A.Run a system restore to a point before the infection.
B.Use an antivirus boot disk to scan and remove the rootkit.
C.Reinstall the operating system from a trusted source.
D.Delete the rootkit's files manually in Safe Mode.
AnswerC

Reinstalling from trusted media eliminates the rootkit because kernel-level malware persists below the operating system, surviving standard antivirus scans and in-place repairs. Since the rootkit hides processes and grants remote control, only overwriting the compromised OS removes the malicious kernel components the attacker embedded.

Why this answer

Rootkits operate at a deep level within the operating system, often hooking kernel-mode functions or modifying system files to hide their presence. Reinstalling the OS from a trusted source ensures that all rootkit components, including those embedded in the boot sector or kernel, are completely removed, as no residual malicious code remains. This method is the only guaranteed way to eliminate a rootkit that has compromised the system's integrity.

Exam trap

CompTIA A+ often tests the misconception that Safe Mode or boot-time scans are sufficient for rootkit removal, but the trap here is that rootkits operate at a lower level than these methods can reliably clean, making a full OS reinstall the only definitive solution.

How to eliminate wrong answers

Option A is wrong because System Restore does not remove rootkits; it only reverts system files and registry settings to a previous state, but rootkits often persist in the Master Boot Record (MBR) or kernel memory, which System Restore does not touch. Option B is wrong because while an antivirus boot disk can detect and remove many rootkits, sophisticated rootkits may employ techniques such as direct kernel object manipulation (DKOM) or fileless persistence that evade even boot-time scans, leaving remnants behind. Option D is wrong because manually deleting rootkit files in Safe Mode is ineffective, as rootkits often load before the Safe Mode boot process or hide their files and processes from standard file system enumeration, and they may have already modified critical system components that require a clean installation to restore.

196
MCQmedium

A technician is asked to dispose of several old company laptops that contain customer records on their internal drives. The drives are traditional spinning magnetic disks, and the company wants to reuse the laptops internally after the data is removed. Which of the following is the BEST method to ensure the customer data cannot be recovered?

A.Run a standard format of the drive from the operating system installer
B.Degauss the drive and then reinstall the operating system
C.Delete all partitions and leave the drive unallocated
D.Perform a low-level wipe by overwriting the entire drive with multiple passes of random data
AnswerD

Overwriting every sector of a magnetic hard disk with random data destroys the original bit patterns, and multiple passes add assurance. This sanitizes the drive while leaving it functional for internal reuse, which matches the requirement to remove customer records and keep the laptops in service. It is the appropriate method for spinning magnetic media.

Why this answer

The laptops will be reused internally, so the storage must remain functional while the customer data becomes unrecoverable. Overwriting every sector of a magnetic hard disk with random data removes the original bit patterns and defeats forensic recovery. Partition deletion and quick formatting leave recoverable remnants, and degaussing renders the drive unusable.

Exam trap

The trap here is treating deletion or quick formatting as sufficient sanitization, when only overwriting the full media removes the data while preserving the drive for reuse.

197
MCQmedium

A user calls the help desk because their Windows 10 laptop will not connect to any Wi-Fi network. The Wi-Fi adapter is enabled in Device Manager and shows no errors, but the network list is empty. Other devices connect fine. Which command should be run first to reset the network stack?

A.Run 'ipconfig /release' followed by 'ipconfig /renew'.
B.Run 'netsh winsock reset' from an elevated Command Prompt.
C.Run 'sfc /scannow' to check system files.
D.Run 'net start wlansvc' to start the WLAN AutoConfig service.
AnswerB

The 'netsh winsock reset' command is the appropriate solution because it rebuilds the Winsock catalog, which is a critical component of the Windows network stack. Winsock provides a standard interface for Windows applications to interact with network protocols, and corruption within this catalog can prevent the system from properly detecting and displaying available networks. By resetting Winsock, the command effectively restores the network communication interface to its default, functional state, allowing networks to be visible again.

Why this answer

The 'netsh winsock reset' command is the correct first step because it resets the Winsock catalog, which manages network I/O and API calls. When the Wi-Fi adapter shows no errors but the network list is empty, the issue is often a corrupted Winsock configuration rather than a driver or service failure. This command restores the Winsock stack to a clean state without requiring a reboot, making it the most direct fix for this specific symptom.

Exam trap

CompTIA often tests the distinction between resetting the network stack (Winsock) versus restarting a service or refreshing an IP lease, and the trap here is that candidates mistakenly choose 'ipconfig /renew' because they think the issue is DHCP-related, when the empty network list indicates a lower-level Winsock corruption.

How to eliminate wrong answers

Option A is wrong because 'ipconfig /release' and 'ipconfig /renew' only refresh DHCP leases and IP addresses; they do not reset the network stack or fix a corrupted Winsock catalog, and they require an active connection to a network, which the user lacks. Option C is wrong because 'sfc /scannow' checks and repairs system file integrity, not the network stack; while a corrupted system file could theoretically cause network issues, it is not the first-line diagnostic for an empty Wi-Fi list with a functional adapter. Option D is wrong because 'net start wlansvc' starts the WLAN AutoConfig service, but the scenario states the adapter is enabled and shows no errors, implying the service is already running; forcing a start would either fail or be redundant, and it does not address Winsock corruption.

198
MCQhard

A system administrator needs to add a new user 'jdoe' to the system and ensure that their home directory is created with restrictive permissions so that no other users can access it. Which command sequence achieves this?

A.useradd -m jdoe && chmod 700 /home/jdoe
B.useradd jdoe && chmod 755 /home/jdoe
C.adduser jdoe --private
D.useradd -m -g jdoe jdoe
AnswerA

The -m flag makes useradd create /home/jdoe, then chmod 700 strips all group and other permissions, leaving read, write and execute for the owner alone. This satisfies the requirement that no other users can access the home directory.

Why this answer

`useradd -m jdoe` creates the user and their home directory `/home/jdoe`, and `chmod 700 /home/jdoe` sets the directory permissions to `rwx------`, which grants full access only to the owner (jdoe) and denies all access to group and others. This meets the requirement of restrictive permissions so that no other users can access the home directory.

Exam trap

CompTIA often tests the distinction between creating a user with default permissions versus explicitly setting restrictive permissions, and the trap here is that candidates may assume `useradd -m` alone or a group-based option (like `-g`) automatically enforces privacy, when in fact the umask or default settings can leave the home directory accessible to others.

How to eliminate wrong answers

Option B is wrong because `chmod 755 /home/jdoe` sets permissions to `rwxr-xr-x`, which allows other users to read and execute (i.e., traverse) the home directory, violating the requirement for no other user access. Option C is wrong because `adduser jdoe --private` is not a valid command in standard Linux distributions; `adduser` is a Perl script that does not support a `--private` flag, and even if it did, it would not guarantee the specific restrictive permission of 700. Option D is wrong because `useradd -m -g jdoe jdoe` creates the user with a primary group named `jdoe` (which is typically the same as the username) but does not set any restrictive permissions on the home directory; the default umask (often 022) would result in permissions like 755, allowing other users access.

199
MCQhard

An administrator needs to deploy a standardized Windows 11 image to 40 new workstations and must remove the built-in consumer applications while preserving the Start layout and driver set. Which deployment approach best meets these requirements with the least manual effort per machine?

A.Install Windows manually on each PC, then run a PowerShell script to remove applications
B.Perform an in-place upgrade on each workstation using a mounted ISO
C.Use Windows Backup to restore a reference workstation's files to each new PC
D.Create a Windows system image with DISM and deploy it with an unattend.xml answer file
AnswerD

Capturing a generalized image with DISM and applying it through an answer file lets the administrator strip unwanted built-in applications, inject drivers, and apply a standard Start layout in one automated pass. The unattend.xml handles computer naming, domain join, and locale settings, so each of the 40 workstations receives an identical configuration without manual per-machine steps.

Why this answer

A DISM-captured image applied with an unattend.xml answer file delivers a consistent, automated deployment. The administrator can remove built-in applications during image preparation, inject drivers, and define the Start layout once, then apply the same image to all 40 workstations with minimal per-machine interaction.

Exam trap

The trap here is treating a file backup or a post-install cleanup script as a deployment method, when true standardization requires a captured operating system image with an answer file.

200
MCQhard

A technician is troubleshooting an Android device that is unable to connect to a corporate Wi-Fi network using WPA2-Enterprise with a username and password. The device connects successfully to other open Wi-Fi networks. Which Android setting should the technician check first to resolve the authentication failure?

A.Verify that the device's IP address is set to DHCP.
B.Check if a CA certificate is installed and selected in the Wi-Fi network's advanced settings.
C.Disable the proxy settings for that Wi-Fi network.
D.Configure a static MAC address on the device.
AnswerB

In WPA2-Enterprise (802.1X) networks, a Certificate Authority (CA) certificate is essential for the client device to verify the authenticity of the RADIUS authentication server. This server validation prevents man-in-the-middle attacks by ensuring the client is communicating with a legitimate network component. If the required CA certificate is not installed on the Android device or is not correctly selected within the Wi-Fi network's advanced EAP settings, the authentication process will fail, preventing network access.

Why this answer

WPA2-Enterprise with username/password authentication typically requires a CA certificate to validate the RADIUS server's identity. Without a trusted CA certificate installed and selected in the Wi-Fi network's advanced security settings, the Android device will reject the connection attempt, even though the credentials are correct. This is the most common cause of authentication failure in enterprise Wi-Fi environments.

Exam trap

A common trap is that candidates think credential issues (wrong username/password) are the primary cause of WPA2-Enterprise failures, but the real issue is that Android requires explicit CA certificate selection for enterprise networks, unlike some other OSes that may use system certificates automatically.

How to eliminate wrong answers

Option A is wrong because DHCP vs. static IP addressing affects IP layer connectivity, not 802.1X/EAP authentication; the device can successfully obtain an IP address after authentication completes. Option C is wrong because proxy settings control application-layer traffic routing, not the underlying WPA2-Enterprise authentication handshake. Option D is wrong because configuring a static MAC address is unrelated to 802.1X certificate validation; MAC addresses are used for device identification, not for EAP-TLS or PEAP authentication.

201
MCQmedium

During a routine security audit, you find that several workstations have the same local administrator password. The company policy requires unique passwords for each machine. Which tool or method should you use to enforce unique local administrator passwords across the domain?

A.Use Group Policy to set a standard local admin password.
B.Enable BitLocker on each workstation.
C.Deploy Microsoft LAPS (Local Administrator Password Solution).
D.Disable the local administrator account on all workstations.
AnswerC

Microsoft LAPS is specifically designed to address the challenge of managing local administrator account passwords across an organization. It automatically generates a unique, complex password for the local administrator account on each domain-joined computer, stores it securely in Active Directory, and can enforce password rotation policies. This solution ensures that each workstation has a distinct local admin password, significantly enhancing security and simplifying management.

Why this answer

Microsoft LAPS (Local Administrator Password Solution) is the correct tool because it automatically manages local administrator passwords on domain-joined computers, storing them in Active Directory and rotating them to unique values per machine. This directly enforces the policy of unique local admin passwords without manual intervention, using the `AdmPwd` extension and Group Policy to configure password complexity and rotation intervals.

Exam trap

CompTIA often tests the misconception that Group Policy can enforce unique passwords, but candidates must remember that Group Policy applies the same setting to all objects in its scope, making it unsuitable for uniqueness; LAPS is the specific Microsoft solution designed for this exact requirement.

How to eliminate wrong answers

Option A is wrong because using Group Policy to set a standard local admin password would enforce the same password on all workstations, directly violating the requirement for unique passwords per machine. Option B is wrong because BitLocker is a full-disk encryption technology that protects data at rest, not a mechanism for managing or rotating local administrator passwords. Option D is wrong because disabling the local administrator account is a security hardening measure but does not address the requirement for unique passwords; it avoids the password uniqueness issue rather than solving it, and some applications or scenarios may require the local admin account to remain enabled.

202
MCQeasy

A user reports that their Android phone is running slowly and the battery drains quickly. They have many apps installed. Which built-in Android feature should you use to identify and stop a misbehaving app that is consuming excessive CPU and battery resources?

A.Use a third-party Task Killer app to automatically close background processes.
B.Check the Battery Usage menu in Settings to see which app is using the most power.
C.Perform a factory reset from the Recovery Mode menu.
D.Enable Developer Options and increase the background process limit.
AnswerB

The Battery Usage menu in Settings attributes power drain to individual apps, exposing the misbehaving process consuming excessive CPU. This directly satisfies the stem's requirement to identify the culprit before stopping it, since Android's per-app consumption data pinpoints the offender rather than merely showing overall battery level.

Why this answer

The Battery Usage menu in Android Settings (Settings > Battery > Battery Usage) provides a breakdown of power consumption by app and system component, letting you identify an app that is draining the battery or consuming excessive resources. From this screen you can select the offending app and force stop it, or open its App Info page to clear its cache or uninstall it. This is the correct built-in, non-destructive way to diagnose and stop a resource-hungry app without third-party tools or a factory reset.

Exam trap

CompTIA often tests the misconception that third-party task killers or developer options are appropriate troubleshooting tools, when in fact Android's built-in Battery Usage menu is the correct, non-destructive method to identify resource-hungry apps.

How to eliminate wrong answers

Option A is wrong because third-party Task Killer apps are unnecessary on modern Android (6.0+) and can actually worsen performance by killing apps that the system would otherwise manage efficiently, leading to increased CPU usage as apps restart. Option C is wrong because a factory reset is a drastic, data-destructive measure that should only be used as a last resort for systemic issues like malware or OS corruption, not for identifying a single misbehaving app. Option D is wrong because increasing the background process limit in Developer Options would allow more apps to run in the background, potentially worsening battery drain and slowdowns, rather than helping identify or stop the problematic app.

203
MCQmedium

A technician is troubleshooting an Android phone that cannot send or receive SMS messages, but can make and receive calls and use mobile data. The phone is on a corporate plan with a new SIM card. What is the most likely cause?

A.The phone's IMEI is blacklisted.
B.The SMS message center number is incorrect or missing.
C.The mobile data APN settings are incorrect.
D.The phone is in airplane mode.
AnswerB

The Short Message Service Center (SMSC) number is a crucial setting that directs outgoing SMS messages to the correct network gateway for delivery. If this number is either incorrectly configured, corrupted, or entirely absent from the phone's messaging settings, the device will be unable to send or properly route SMS messages. Critically, the SMSC only pertains to standard SMS, meaning other cellular functions like voice calls and mobile data would remain fully operational, aligning with a scenario where only SMS fails.

Why this answer

The SMS message center number (SMSC) is a required parameter stored on the SIM card or phone that tells the device where to route outgoing SMS messages for delivery. If this number is incorrect or missing, the phone cannot send or receive SMS, but voice calls and mobile data remain unaffected because they use separate signaling paths (CSFB for calls and packet-switched data for mobile data). A new SIM card may have a misconfigured or missing SMSC, which is the most likely cause given the symptom pattern.

Exam trap

CompTIA often tests the distinction between services that use the control plane (SMS, voice) versus the data plane (mobile data), leading candidates to incorrectly blame APN settings (Option C) when the issue is actually a missing SMSC number.

How to eliminate wrong answers

Option A is wrong because an IMEI blacklist blocks all cellular services (calls, SMS, data) on the network, not just SMS, and the phone can still make calls and use data. Option C is wrong because incorrect APN settings affect mobile data connectivity, not SMS; SMS uses the control channel (SS7 or SIP) and does not rely on APN configuration. Option D is wrong because airplane mode disables all radios, preventing calls, data, and SMS, which contradicts the symptom that calls and data work.

204
MCQhard

A security incident response team needs to find all files in /var/www that have the SUID bit set, which may indicate a privilege escalation risk. Which command should they use?

A.find /var/www -type f -perm 4000
B.find /var/www -type f -perm /4000
C.ls -la /var/www | grep '^...s'
D.chmod -R u+s /var/www
AnswerB

The correct `find` command utilizes the `-type f -perm /4000` syntax, which signifies a 'bitwise OR' or 'any of' match for the specified permission bits. This ensures that any file with the SUID bit (4000) set, regardless of other standard read, write, or execute permissions, will be successfully identified. This method accurately targets all files where the SUID flag is active, fulfilling the requirement to locate them.

Why this answer

The `find` command with `-perm /4000` matches any file that has the SUID bit set (the 4000 octal permission), regardless of other permission bits. The `/` prefix tells `find` to match if any of the specified permission bits are set, which is the precise way to locate files with the SUID bit enabled. This command will recursively search `/var/www` for regular files (`-type f`) with the SUID bit, helping identify potential privilege escalation risks.

Exam trap

CompTIA often tests the distinction between `-perm 4000` (exact match) and `-perm /4000` (any match), where candidates mistakenly choose the exact match option, not realizing it will miss files with additional permission bits set.

How to eliminate wrong answers

Option A is wrong because `-perm 4000` matches files with exactly the permission 4000 (i.e., only the SUID bit set and no other bits), which would miss files that have the SUID bit set along with other permissions like 4755. Option C is wrong because `ls -la /var/www | grep '^...s'` only checks the first level of `/var/www` and does not search recursively, so it would miss files in subdirectories; also, the grep pattern is incorrect as it expects the SUID indicator in the owner execute position but does not account for other permission patterns. Option D is wrong because `chmod -R u+s /var/www` sets the SUID bit on all files and directories recursively, which is a dangerous action that would create privilege escalation risks, not find them.

205
MCQmedium

A user on a corporate iOS device complains that they cannot install a required business app from the App Store because the device is 'supervised' and shows a message that installation is blocked. What is the most likely reason and solution?

A.The user needs to sign out of iCloud and sign back in
B.The device has a configuration profile that disables App Store installs; update the MDM policy
C.Perform a factory reset to remove supervision
D.Enable 'Allow Untrusted Shortcuts' in Settings
AnswerB

Supervised devices accept MDM restrictions, and a configuration profile can disable App Store installation. The block is policy-driven, not hardware, so updating the MDM policy to permit the app restores installation without unsupervising the device.

Why this answer

The 'supervised' status on iOS devices is an MDM-enforced mode that allows granular restrictions. The error message about installation being blocked indicates a configuration profile or MDM policy specifically disables App Store installations. Updating the MDM policy to allow installs is the correct solution, as it directly addresses the restriction without compromising supervision.

Exam trap

CompTIA often tests the misconception that 'supervised' means the device is locked down permanently, leading candidates to suggest a factory reset, when in fact supervision is a management state that can be adjusted via MDM policies without wiping the device.

How to eliminate wrong answers

Option A is wrong because signing out of iCloud does not affect MDM-enforced restrictions like App Store installation blocks; iCloud is for personal data sync, not device management policies. Option C is wrong because a factory reset removes supervision but also wipes all data and defeats the purpose of corporate management; it is an extreme measure that does not solve the policy issue. Option D is wrong because 'Allow Untrusted Shortcuts' is a setting for running unsigned shortcuts, not for App Store installation permissions; it is unrelated to MDM restrictions.

206
MCQmedium

A user reports that their Windows 11 laptop takes several minutes to reach the desktop after signing in, and the desktop icons and taskbar appear one by one. No error messages are displayed. You open Task Manager and see that disk usage is at 100% for several minutes after logon. Which Windows tool should you use first to identify the specific startup program causing the delay?

A.System Configuration (msconfig) > Services tab
B.Task Manager > Startup tab
C.Event Viewer > Windows Logs > Application
D.Performance Monitor with a Data Collector Set
AnswerB

The Startup tab in Task Manager lists all programs configured to launch at user logon and shows an impact rating for each. Disabling or investigating high-impact entries directly addresses the slow post-logon behavior. It is the quickest built-in tool to identify which startup app is saturating disk I/O during sign-in.

Why this answer

Task Manager's Startup tab is the built-in tool that specifically lists programs set to run at logon and provides an impact rating based on resource usage. Since the symptom is slow logon with high disk usage, checking this tab lets you quickly identify and disable the offending startup app. Other tools are either too broad or focus on the wrong object.

Exam trap

The trap here is assuming that Event Viewer will pinpoint the slow startup app because it logs system events, when in fact it does not enumerate startup programs or their performance impact.

207
MCQmedium

A company uses a login script that sets environment variables and maps drives based on the user's department. The script works for most users, but some report that the drive mappings are missing. The script is written in batch and uses 'if' statements to check department codes. What is the most likely cause of the intermittent failures?

A.The script runs too early before the network is fully initialized
B.The department codes in the script do not match the actual codes due to case sensitivity
C.The script is using 'setx' instead of 'set' for environment variables
D.The user accounts lack permission to run login scripts
AnswerB

Batch script 'IF' comparisons, by default, are case-sensitive. If a login script uses a conditional statement like 'IF "%DEPARTMENT%"=="Sales"' to map a drive, but a user's actual department attribute is stored as "sales" or "SALES" in Active Directory, the condition will evaluate as false. This mismatch prevents the drive mapping for those specific users, explaining why some users experience successful mappings while others, whose department codes differ only in case, do not, leading to intermittent failures across the user base.

Why this answer

Batch file 'if' statements are case-sensitive by default when comparing strings. If the script checks for department codes like 'SALES' but the actual environment variable or user input contains 'sales' or 'Sales', the comparison fails and the drive mapping block is skipped. This explains why the issue is intermittent — it depends on how the department code is stored or passed.

Exam trap

CompTIA often tests the case sensitivity of batch file string comparisons, knowing that candidates assume string comparisons are case-insensitive by default, leading them to overlook this subtle but critical behavior.

How to eliminate wrong answers

Option A is wrong because network initialization issues would affect all users or cause complete failure, not just drive mappings for specific departments, and the script works for most users. Option C is wrong because 'setx' sets persistent environment variables, which would not cause intermittent drive mapping failures; the script uses 'set' for temporary variables, and the issue is with conditional logic, not variable persistence. Option D is wrong because if user accounts lacked permission to run login scripts, the script would fail entirely for those users, not just skip drive mappings intermittently.

208
MCQhard

A technician is troubleshooting a Windows 10 computer that randomly restarts without any error message. The system does not create a minidump file. Which advanced startup option should be disabled in the System Properties to help capture the error for analysis?

A.Fast Startup
B.Automatic restart
C.Write an event to the system log
D.Small memory dump (256 KB)
AnswerB

The 'Automatic restart' option, found within the 'Startup and Recovery' settings under System Properties, directly governs the system's behavior immediately following a critical error like a Blue Screen of Death (BSOD). When this setting is enabled, Windows automatically reboots, often too quickly for a user to read the error message or for a complete memory dump file to be written. Disabling this feature is crucial for troubleshooting, as it forces the system to halt on the error screen, allowing technicians to gather vital diagnostic information and ensuring the memory dump process can successfully complete.

Why this answer

Disabling 'Automatically restart' in System Properties > Advanced > Startup and Recovery ensures that when a bug check (BSOD) occurs, Windows stays on the blue screen instead of rebooting, giving the technician time to read the stop code and allowing the dump file to be written. This is the standard step when a machine reboots without leaving a minidump.

Exam trap

The trap is confusing the dump-type setting (Small memory dump) with the reboot behavior setting (Automatic restart) — the exam tests whether you know that 'Automatically restart' is what hides the BSOD and must be disabled to capture the error.

How to eliminate wrong answers

Option A is wrong because Fast Startup is a hybrid hibernation feature that speeds boot — it does not suppress dump creation or cause silent reboots during operation. Option C is wrong because 'Write an event to the system log' is a logging option that should be enabled, not disabled, and it doesn't prevent the reboot. Option D is wrong because 'Small memory dump (256 KB)' is the dump type setting — you would want to verify it's selected (or choose a larger dump), not disable it, to capture the error.

209
MCQhard

During a security audit, a technician discovers that an unauthorized person accessed a restricted server room by pretending to be a fire inspector. The person had a fake ID and clipboard. Which social engineering technique was used, and what is the best mitigation?

A.Tailgating; install mantraps at entrances.
B.Phishing; implement email filtering.
C.Pretexting; enforce visitor check-in and verification procedures.
D.Baiting; disable USB ports on workstations.
AnswerC

Pretexting is a social engineering tactic where an attacker invents a fabricated scenario or identity to manipulate a target into divulging information or granting access. Enforcing strict visitor check-in and verification procedures directly counters pretexting by requiring visitors to present valid identification and verifying their stated purpose against official records or scheduled appointments. This process, often combined with requiring escorts for all visitors, prevents unauthorized individuals from gaining physical access under false pretenses.

Why this answer

The attacker used a fabricated identity (fake ID and clipboard) to create a false scenario—pretending to be a fire inspector—which is the hallmark of pretexting. The best mitigation is to enforce visitor check-in and verification procedures, such as requiring government-issued ID validation and escort policies, to prevent unauthorized access based on fabricated roles.

Exam trap

CompTIA often tests the distinction between pretexting and tailgating, where candidates confuse impersonation with simply following someone through a door; the trap here is that the fake ID and clipboard clearly indicate a fabricated identity (pretexting), not physical piggybacking.

How to eliminate wrong answers

Option A is wrong because tailgating involves an unauthorized person following an authorized person through a secured door without consent, not using a fake identity or pretext. Option B is wrong because phishing is a digital attack using fraudulent emails or messages to steal credentials, not an in-person impersonation with a fake ID. Option D is wrong because baiting involves offering something enticing (e.g., a free USB drive) to trick a victim into installing malware, not impersonating an authority figure to gain physical access.

210
MCQmedium

A small business owner wants to allow their remote employees to securely access a specific internal application without giving them full network access. Which remote access technology should the technician recommend?

A.Site-to-site VPN
B.Remote Desktop Services
C.Application gateway
D.SSH tunneling
AnswerC

An application gateway, often functioning as a reverse proxy, provides secure and controlled access to specific web applications. It sits in front of the application servers, inspecting incoming traffic and forwarding legitimate requests to the appropriate backend application while blocking malicious attempts. This method allows remote users to securely access a single application without exposing the entire internal network or requiring a full VPN connection, aligning perfectly with the need for granular, application-level access.

Why this answer

An application gateway (reverse proxy) is the correct choice because it provides granular, application-layer access control, allowing remote employees to reach a specific internal application without granting them full network-level access. Unlike VPNs that create a tunnel to the entire network, an application gateway authenticates and proxies only the designated application traffic, often using protocols like HTTPS and enforcing policies at Layer 7.

Exam trap

The trap here is that candidates often confuse 'remote access' with 'full network connectivity' and choose a VPN (site-to-site or client-based) because they think encryption alone solves the access control problem, overlooking the need for application-specific, least-privilege access.

How to eliminate wrong answers

Option A is wrong because a site-to-site VPN connects entire networks (e.g., branch office to headquarters), giving remote employees full network access, not just to a single application. Option B is wrong because Remote Desktop Services provides a full desktop session or individual applications via RDP, but it exposes the entire desktop environment or multiple apps, not a single internal application with granular access control. Option D is wrong because SSH tunneling creates an encrypted tunnel for specific TCP ports, but it requires manual configuration, exposes the underlying network if misconfigured, and does not provide application-layer filtering or authentication for a single web application.

211
MCQmedium

A user reports that their Windows 10 PC frequently crashes with a blue screen error. You want to analyze the memory dump files to identify the faulty driver. Which tool should you use to view and analyze these dump files?

A.Event Viewer
B.Windows Memory Diagnostic
C.Performance Monitor
D.Task Manager
AnswerA

Event Viewer logs system errors, including blue screen events, and provides details about the crash, including the dump file path.

Why this answer

Event Viewer is the correct tool because it logs system events, including blue screen errors (BugCheck events), and provides access to memory dump files. You can view the details of a crash under 'Windows Logs > System' and filter by event ID 1001, which includes the path to the dump file and the module that caused the failure. This allows you to identify the faulty driver by analyzing the dump file directly or by using additional tools like WinDbg.

Exam trap

The trap here is that candidates often confuse Windows Memory Diagnostic (a RAM tester) with a tool for analyzing crash dumps, or they assume Task Manager or Performance Monitor can provide crash analysis, but only Event Viewer logs the crash event and points to the dump file location.

How to eliminate wrong answers

Option B is wrong because Windows Memory Diagnostic is a tool for testing physical RAM for hardware errors, not for analyzing memory dump files from crashes. Option C is wrong because Performance Monitor is used to collect and analyze real-time performance data (e.g., CPU, disk usage) over time, not to view or analyze crash dump files. Option D is wrong because Task Manager provides a snapshot of running processes, performance metrics, and startup programs, but it cannot display or analyze memory dump files from blue screen errors.

212
MCQmedium

A technician is configuring a company-issued Android phone for a new employee. The employee will use the phone for both work (email, calendar) and personal activities. The company requires that work data be securely containerized and managed without affecting the employee's personal apps. Which Android feature should the technician enable?

A.Set up a separate User account for work.
B.Enable the Work Profile via the device's Settings under Accounts.
C.Use Screen Pinning to lock the device to the email app.
D.Install a third-party MDM agent only.
AnswerB

Enabling the Work Profile via the device's Settings under Accounts is the correct and most efficient method for configuring a company-issued Android phone. This feature creates a secure, managed container for all work-related applications, data, and accounts, keeping them entirely separate from personal content on the same device. IT administrators can enforce specific security policies and manage applications within this profile without intruding on the user's personal data or privacy, offering a seamless and secure experience.

Why this answer

Android Work Profile (part of Android for Work / managed profiles) creates a separate, encrypted container for corporate apps and data that is managed by an EMM/MDM, while leaving the personal profile untouched. This is exactly the BYOD containerization requirement described.

Exam trap

The trap is confusing full user isolation (separate User account) or kiosk mode (Screen Pinning) with the Android Enterprise Work Profile — the exam tests whether you know Work Profile is the containerization feature for BYOD.

How to eliminate wrong answers

Option A is wrong because a separate User account creates a fully isolated user session that the employee must switch into — it does not provide the integrated, policy-managed work container that Work Profile offers, and it's cumbersome for BYOD. Option C is wrong because Screen Pinning locks the device to a single app for kiosk-style use; it provides no data containerization or management. Option D is wrong because installing a third-party MDM agent alone does not create the OS-level work container — the MDM must leverage the Work Profile (managed profile) APIs, and the question asks for the Android feature to enable.

213
MCQeasy

A technician is troubleshooting a Windows 10 workstation that repeatedly shows a message stating the operating system could not be found. The drive is detected in UEFI/BIOS, and the technician suspects the boot configuration is damaged. Which command should the technician run from the Windows Recovery Environment to rebuild the Boot Configuration Data store?

A.chkdsk /r
B.bootrec /rebuildbcd
C.diskpart /clean
D.bootrec /fixmbr
AnswerB

This command scans all disks for Windows installations and rebuilds the Boot Configuration Data store, which is exactly what is needed when the BCD is damaged and the OS cannot be located at boot. It is the targeted repair for this symptom on both BIOS and UEFI systems.

Why this answer

When the Boot Configuration Data store is damaged, Windows cannot locate the operating system even though the disk is healthy. The bootrec /rebuildbcd command scans for installations and reconstructs the BCD, directly addressing the symptom. The other commands either repair the wrong boot component, destroy data, or check disk surface errors rather than the boot database.

Exam trap

The trap here is confusing MBR repair with BCD repair, since both are bootrec subcommands but affect different boot architectures and components.

214
MCQmedium

A technician is tasked with installing a new hard drive in a server rack. The rack is located in a cramped, dusty storage room with poor lighting. Which safety practice should the technician prioritize before beginning the installation?

A.Use a step stool to reach the server rack safely.
B.Wear a dust mask and use a flashlight to improve visibility.
C.Remove the server from the rack and place it on the floor for easier access.
D.Disconnect all power cables in the rack to eliminate electrical hazards.
AnswerB

Wearing a dust mask is crucial Personal Protective Equipment (PPE) to prevent respiratory irritation and potential long-term health issues from inhaling airborne dust particles common in server environments. Simultaneously, using a flashlight directly counters the "poor lighting" condition, ensuring the technician has clear visibility of intricate components and connections. This combination minimizes the risk of installation errors, accidental damage, and personal injury, promoting a safe and accurate installation.

Why this answer

The scenario describes a cramped, dusty storage room with poor lighting, which creates two immediate hazards: inhalation of dust particles and reduced visibility. Wearing a dust mask protects the technician's respiratory system from airborne particulates, while using a flashlight ensures they can see clearly to avoid accidental contact with components or cables. These measures directly address the environmental risks before any work begins.

Exam trap

CompTIA often tests the candidate's ability to prioritize environmental and personal safety over convenience or overkill measures, and the trap here is that test-takers may choose Option D (disconnecting all power) thinking it is the safest approach, but it is excessive and not the most immediate priority given the specific conditions described.

How to eliminate wrong answers

Option A is wrong because using a step stool does not address the primary hazards of dust inhalation and poor visibility; it only helps with height, which is not the main concern in a cramped space. Option C is wrong because removing the server from the rack and placing it on the floor increases the risk of physical damage to the server and creates a tripping hazard, and it does not mitigate the dust or lighting issues. Option D is wrong because disconnecting all power cables in the rack is an extreme and unnecessary step that could disrupt other critical systems; the technician should only isolate the specific device they are working on, following proper lockout/tagout procedures.

215
MCQeasy

A technician is deploying 20 new laptops to a department. The manager asks the technician to install the software quickly, but the technician knows that a full deployment includes user training and data migration. Which action BEST demonstrates professional communication?

A.Agree to the manager's request and rush the installation to avoid conflict.
B.Explain the standard deployment process and offer a revised timeline that includes training.
C.Install the software and let the users figure out the rest on their own.
D.Tell the manager that training is not part of the technician's job.
AnswerB

This is the most professional and effective approach. By clearly articulating the standard deployment process, which includes critical steps like imaging, software installation, data migration, and user training, the technician manages the manager's expectations realistically. Proposing a revised timeline that incorporates adequate training ensures users can effectively utilize the new equipment, minimizing post-deployment support issues and maximizing productivity from the outset, leading to a smoother transition.

Why this answer

It demonstrates professional communication by clearly explaining the standard deployment process—which includes user training and data migration—and offering a revised timeline. This aligns with the CompTIA A+ objective of managing expectations and ensuring a complete, effective rollout rather than a rushed, incomplete installation.

Exam trap

The trap here is that candidates may think agreeing to the manager's request (Option A) avoids conflict, but CompTIA often tests that professional communication requires setting realistic expectations and explaining the full scope of work, not just immediate compliance.

How to eliminate wrong answers

Option A is wrong because agreeing to rush the installation ignores the necessary steps of user training and data migration, leading to potential user confusion and data loss, which violates professional responsibility. Option C is wrong because installing software without training or support leaves users to figure out the system on their own, which is unprofessional and can cause productivity loss and security risks. Option D is wrong because telling the manager that training is not part of the technician's job dismisses a core component of a full deployment and fails to communicate the technician's role in ensuring successful adoption.

216
MCQeasy

A user complains that their Windows 11 laptop's battery drains quickly even when idle. They have checked the Task Manager and no unusual processes are running. Which built-in tool should you use to generate a detailed report of battery usage and health?

A.Resource Monitor
B.Performance Monitor
C.Powercfg /batteryreport
D.Windows Memory Diagnostic
AnswerC

The `powercfg /batteryreport` command is specifically designed to generate a detailed HTML report containing critical battery information. This report includes the battery's design capacity, its last full charge capacity, recent usage history, and estimated battery life, providing essential data to identify degradation, excessive drain, or other battery-related issues.

Why this answer

Powercfg /batteryreport is the correct built-in tool because it generates a comprehensive HTML report detailing battery capacity history, usage patterns, and estimated life. This command analyzes the system's power efficiency and battery health, which directly addresses the user's complaint of rapid drain even when idle, without relying on running processes visible in Task Manager.

Exam trap

The trap here is that candidates often confuse Resource Monitor or Performance Monitor as tools for battery analysis, but neither provides the specific battery health and usage history that powercfg /batteryreport does.

How to eliminate wrong answers

Option A is wrong because Resource Monitor provides real-time monitoring of CPU, memory, disk, and network usage, but it does not generate a historical or health-focused battery report. Option B is wrong because Performance Monitor tracks system performance counters over time, but it lacks specific battery health and usage reporting capabilities. Option D is wrong because Windows Memory Diagnostic is designed to test RAM for errors, not to analyze battery performance or health.

217
MCQhard

During a forensic investigation, a technician needs to recover files that a user deleted from their Mac's internal SSD several days ago. The Trash has been emptied. Which macOS feature or tool should be attempted first to recover these files?

A.Use the Terminal command 'fs_usage' to locate the deleted files
B.Restore from a Time Machine backup
C.Run Disk Utility First Aid on the SSD
D.Use a third-party file recovery tool immediately
AnswerB

Time Machine preserves earlier snapshots of the SSD's contents, so a backup taken before deletion still holds the files. On APFS SSDs, TRIM typically erases deleted blocks quickly, making file-carving recovery tools unreliable; restoring from backup is therefore the most dependable first attempt.

Why this answer

Time Machine is the built-in macOS backup feature that automatically creates incremental backups of the system. If a Time Machine backup was made before the files were deleted, the user can browse the backup timeline and restore the deleted files directly, even after the Trash has been emptied. This is the simplest and most reliable first step because it does not require specialized tools or risk overwriting data.

Exam trap

The exam often tests the misconception that a built-in utility like Disk Utility First Aid can recover deleted files, when in fact it only repairs volume metadata and has no file recovery capability.

How to eliminate wrong answers

Option A is wrong because 'fs_usage' is a real-time file system monitoring tool that logs current system calls; it cannot locate or recover previously deleted files. Option C is wrong because Disk Utility First Aid repairs file system structure errors (e.g., directory corruption) but does not recover deleted files; it has no undelete capability. Option D is wrong because while third-party tools can sometimes recover deleted files from an SSD, they should not be attempted first if a Time Machine backup exists, as they may overwrite the very data they aim to recover and are less reliable on SSDs due to TRIM.

218
MCQhard

A technician is configuring a remote desktop solution for a user who needs to access a Linux server from a Windows 10 workstation. The technician wants to use a secure, encrypted connection. Which remote access technology should the technician configure on the Linux server?

A.RDP
B.VNC
C.SSH
D.Telnet
AnswerC

Secure Shell (SSH) is the industry standard for secure remote command-line access and administration of Linux servers. It establishes an encrypted connection between the client and server, protecting data integrity and confidentiality through strong cryptographic algorithms. SSH also provides robust authentication mechanisms, such as password or public-key authentication, making it the most appropriate and secure choice for managing Linux systems remotely. This protocol is fundamental for secure system administration in professional environments.

Why this answer

SSH (Secure Shell) is the correct choice because it provides encrypted, authenticated remote shell access to Linux/Unix servers over an insecure network. It uses TCP port 22 and supports strong encryption algorithms (e.g., AES, ChaCha20) and public-key authentication, making it the standard secure remote access protocol for Linux systems.

Exam trap

The trap here is that candidates often confuse RDP (a Windows-centric GUI protocol) with SSH (a Linux-centric secure shell protocol), or mistakenly think VNC is inherently secure, when in fact SSH is the only option that provides built-in encryption and is the standard for secure Linux remote access.

How to eliminate wrong answers

Option A is wrong because RDP (Remote Desktop Protocol) is a proprietary Microsoft protocol primarily used for remote GUI access to Windows systems, not Linux servers, and while it can be encrypted, it is not the native secure remote access method for Linux. Option B is wrong because VNC (Virtual Network Computing) typically transmits data in cleartext by default and requires additional tunneling (e.g., over SSH) to be secure; it is not inherently encrypted and is not the standard secure remote access technology for Linux servers. Option D is wrong because Telnet transmits all data, including credentials, in plaintext over TCP port 23, providing no encryption or security, and is obsolete for secure remote administration.

219
MCQhard

A technician is tasked with removing malware from a Windows 10 computer that has a Trojan horse that downloaded additional payloads. The technician has already run a full antivirus scan and removed the Trojan, but the computer still exhibits suspicious network activity. What should the technician do next?

A.Reimage the computer immediately.
B.Run a second opinion malware scanner such as Malwarebytes.
C.Reset the web browser settings to default.
D.Disable all startup programs in Task Manager.
AnswerB

A second-opinion scanner such as Malwarebytes uses different detection engines and signatures, catching persistent threats, rootkits or dropped payloads the first antivirus missed. Running it addresses the residual suspicious network activity, satisfying the need to remove remaining malware after the initial scan.

Why this answer

Even after removing the Trojan with a full antivirus scan, the computer may still have residual malware components (e.g., backdoors, keyloggers, or downloaders) that the primary scanner missed. Running a second opinion scanner like Malwarebytes uses a different detection engine and signature database, increasing the chance of identifying and removing these hidden threats. This step is critical because the suspicious network activity indicates an active infection that the first scan failed to fully eradicate.

Exam trap

CompTIA often tests the misconception that a single antivirus scan is sufficient for complete malware removal, when in fact residual components or stealthy payloads require a second opinion scanner to fully clean the system.

How to eliminate wrong answers

Option A is wrong because reimaging the computer immediately is a drastic step that should only be taken after less destructive remediation methods have failed, and it would destroy any forensic evidence needed to understand the infection. Option C is wrong because resetting browser settings only addresses browser-based symptoms like changed homepages or toolbars, but does not remove the underlying malware that is causing network activity. Option D is wrong because disabling startup programs in Task Manager only prevents known programs from launching at boot, but does not remove or disable the malware process that is already running or hidden from the startup list.

220
MCQmedium

During a software deployment, a technician must dispose of 50 unused software license CDs. The CDs are still sealed. What is the most environmentally friendly way to handle them?

A.Throw them in the general office trash bin.
B.Shred them and put the pieces in the recycling bin.
C.Donate them to a local school or non-profit that can use them.
D.Burn them in an incinerator to generate energy.
AnswerC

Donating functional optical media, such as software installation discs or educational content, to local schools or non-profit organizations is an excellent and environmentally responsible disposal method. This practice promotes reuse, significantly extending the lifecycle of the media and reducing the demand for new manufacturing. It directly minimizes electronic waste (e-waste) by diverting items from landfills and provides valuable resources to organizations that can benefit from them, aligning with sustainability principles.

Why this answer

Donating still-sealed, unused software license CDs to a school or non-profit is the most environmentally friendly option because it extends the product's useful life and avoids generating waste entirely. Reuse sits at the top of the EPA's waste hierarchy — above recycling and far above disposal or incineration. Since the media is sealed and licensed, it retains full value for a recipient organization.

Exam trap

220-1202 often tests the waste hierarchy by presenting recycling or energy recovery as 'green' answers, when reuse is actually the most environmentally preferred option.

How to eliminate wrong answers

Option A is wrong because placing sealed, usable media in general office trash sends reusable resources to a landfill and may violate e-waste or licensing disposal policies. Option B is wrong because shredding destroys a still-usable product and only recovers the plastic substrate, which is a lower-tier waste-handling method than reuse. Option D is wrong because incineration destroys the media and releases combustion byproducts, making it the least environmentally friendly option despite energy recovery.

221
MCQhard

A company is migrating from Windows 10 to Windows 11 on 50 computers. After the upgrade, several users report that a critical line-of-business application no longer works. The application ran fine on Windows 10. You need to get it working without rolling back the entire OS. What is the most efficient solution?

A.Roll back all 50 computers to Windows 10 using the recovery partition.
B.Reinstall the application on each computer in Windows 10 compatibility mode.
C.Enable Hyper-V on each computer and run the application in a Windows 10 virtual machine.
D.Use the Windows 11 'Reset this PC' feature to reinstall Windows 11 and then reinstall the application.
AnswerB

Reinstalling the application and configuring it to run in Windows 10 compatibility mode is the most efficient and least disruptive solution. This built-in Windows feature uses compatibility shims to emulate the environment of an older operating system, often resolving minor API calls or system behavior differences that cause issues. It allows the company to retain the benefits of Windows 11 while addressing the specific application's needs without a full OS downgrade.

Why this answer

Windows 11 includes a Windows 10 compatibility mode that can be applied to individual applications. Using the Application Compatibility Toolkit (ACT) or the built-in compatibility troubleshooter to set the application to run in Windows 10 compatibility mode is the most efficient fix, as it does not require a full OS rollback.

222
MCQmedium

A company policy requires that all web traffic be filtered to block known malicious sites. You need to implement this on the network without installing software on each client. What should you configure?

A.Enable Windows Defender Firewall on each workstation
B.Configure a DNS filtering service on the router or DNS server
C.Install a browser extension on all computers
D.Set the browser security level to high
AnswerB

Configuring a DNS filtering service on the router or a dedicated DNS server is the most effective and scalable solution for enforcing company web traffic policies. This service intercepts DNS requests, resolving known malicious or policy-violating domains to a block page or non-existent IP address before the connection can even be established. By centralizing this control, all devices on the network automatically adhere to the policy without individual client configuration, making it difficult for users to bypass.

Why this answer

A DNS filtering service works at the network level by resolving domain names against a blocklist of known malicious sites. By configuring this on the router or DNS server, all client traffic is filtered transparently without requiring any software installation on individual workstations, which satisfies the policy requirement.

Exam trap

A common trap on the CompTIA A+ exam is confusing host-based and network-based security controls. Candidates may choose a host-based solution (like firewall or browser settings) instead of recognizing that DNS filtering is a network-level, agentless method that meets the 'no client software' constraint.

How to eliminate wrong answers

Option A is wrong because Windows Defender Firewall filters traffic based on ports and IP addresses, not domain names, and it cannot block specific malicious websites by URL. Option C is wrong because installing a browser extension requires software installation on each client, which violates the 'without installing software on each client' requirement. Option D is wrong because setting the browser security level to high only restricts browser features (e.g., scripts, ActiveX) and does not block access to specific malicious sites by domain or URL.

223
MCQmedium

A small business uses a shared iMac for customer check-ins. The manager wants to restrict which apps users can open and prevent changes to system settings without creating separate user accounts. Which macOS feature should you configure to meet this requirement?

A.Enable FileVault full-disk encryption
B.Configure Parental Controls (Screen Time) for the user account
C.Use the Guest User account
D.Apply a firmware password
AnswerB

Configuring Parental Controls, now integrated within Screen Time in macOS, is the most effective solution for this scenario. This feature allows an administrator to precisely define which applications a standard user account can access, block specific apps entirely, set time limits for app usage, and restrict modifications to critical system settings. By applying these granular restrictions to the shared customer account, the business can ensure customers only interact with approved applications and cannot alter the system configuration.

Why this answer

Parental Controls (Screen Time) allows administrators to restrict app usage and system settings changes on a per-user basis without creating separate user accounts. This feature can limit which applications a user can open and prevent modifications to system preferences, meeting the manager's requirement directly.

Exam trap

The trap here is that candidates often confuse Guest User accounts with managed restrictions, not realizing that Guest User only provides a clean session without persistent data but no app or settings controls.

How to eliminate wrong answers

Option A is wrong because FileVault provides full-disk encryption to protect data at rest, not application or settings restrictions. Option C is wrong because the Guest User account allows temporary access with no persistent data but does not provide granular controls to restrict specific apps or prevent system setting changes. Option D is wrong because a firmware password prevents unauthorized users from booting from external devices or accessing recovery mode, but it does not restrict app usage or system settings within macOS.

224
MCQeasy

A user reports that their laser printer is producing faint, streaky prints and has a strong ozone smell. The printer has been in use for three years. What is the most important safety procedure to follow before attempting to service the printer?

A.Replace the toner cartridge immediately.
B.Unplug the printer and discharge the high-voltage power supply.
C.Clean the corona wire with isopropyl alcohol.
D.Reset the printer to factory defaults.
AnswerB

This is the paramount safety procedure when working inside a laser printer. Laser printers utilize high-voltage components, such as the fuser assembly and transfer corona, which can store dangerous electrical charges in capacitors even after the device is powered down. Unplugging the printer removes the primary power source, and discharging the high-voltage power supply ensures that residual charges are safely dissipated, preventing severe electric shock during subsequent troubleshooting or maintenance.

Why this answer

The strong ozone smell indicates a high-voltage issue, likely with the corona wire or power supply. Before servicing, you must unplug the printer and discharge the high-voltage power supply to prevent electric shock, as laser printers store lethal voltages in capacitors even when powered off.

Exam trap

CompTIA often tests the distinction between troubleshooting steps and mandatory safety procedures, trapping candidates who confuse cleaning or replacing parts with the prerequisite of power isolation and discharge.

How to eliminate wrong answers

Option A is wrong because replacing the toner cartridge does not address the safety hazard of high-voltage discharge and is a troubleshooting step, not a safety procedure. Option C is wrong because cleaning the corona wire with isopropyl alcohol is a maintenance task that should only be performed after power is disconnected and high voltage is discharged; doing it first risks electric shock. Option D is wrong because resetting to factory defaults is a software configuration step that does not eliminate the risk of high-voltage shock and does not resolve the physical safety concern.

225
MCQeasy

During a security audit, a Linux server is found to have a configuration file that is world-writable. The file /etc/app/config.cfg must only be readable and writable by the root user. Which command should the administrator run?

A.chmod 777 /etc/app/config.cfg
B.chmod 644 /etc/app/config.cfg
C.chmod 600 /etc/app/config.cfg
D.chmod 400 /etc/app/config.cfg
AnswerC

Octal 600 assigns read and write permissions exclusively to the file's owner, typically the 'root' user for system configuration files. Crucially, it explicitly revokes all permissions – read, write, and execute – for both the file's group and all other users on the system. This configuration ensures that only the designated administrator can view or modify the file's contents, providing the highest level of confidentiality and integrity for a critical configuration file.

Why this answer

`chmod 600` sets the file permissions to read and write for the owner (root) and no permissions for group or others. This satisfies the requirement that only root can read and write `/etc/app/config.cfg`, as root is the owner of the file.

Exam trap

The trap here is that candidates may confuse the numeric permission values, often picking `644` (thinking it restricts write access) or `400` (thinking read-only is sufficient), while overlooking the explicit requirement for both read and write by root.

How to eliminate wrong answers

Option A is wrong because `chmod 777` grants read, write, and execute permissions to everyone (owner, group, others), making the file world-writable and world-executable, which violates the security requirement. Option B is wrong because `chmod 644` grants read and write to the owner but read-only to group and others, meaning non-root users can still read the file, which does not meet the 'only root' condition. Option D is wrong because `chmod 400` grants read-only to the owner (root) and no permissions to group or others, but the requirement explicitly states the file must be both readable and writable by root, so write permission is missing.

Page 2

Page 3 of 10

Page 4

All pages

Practice 220-1202 by domain

Target a specific domain to shore up weak areas.

See all domains with question counts →