Courseiva

CompTIA A+ Core 2 220-1202 (220-1202) — Questions 301–375

687 questions total · 10pages · All types, answers revealed

Page 4

Page 5 of 10

Page 6
301
MCQmedium

A user cannot run a command because they get 'permission denied' even though they are in the sudoers file. The command is located in /opt/custom/bin. Which command will list the file in long format, showing its permissions, owner, group, size, and modification date?

A.stat /opt/custom/bin/command
B.ls -l /opt/custom/bin/command
C.file /opt/custom/bin/command
D.chmod /opt/custom/bin/command
AnswerB

This is the standard command to view permissions, owner, and group in a concise format.

Why this answer

The 'ls -l' command displays the file's permissions (e.g., -rwxr-xr-x), ownership (user and group), and other metadata in a long-format listing. This directly shows whether the file is executable and who owns it, which is essential for diagnosing a 'permission denied' error despite sudoers membership. While 'stat' also reports permissions and ownership, it does not produce a long-format listing, so it does not satisfy the question's requirement.

Exam trap

CompTIA often tests the distinction between viewing permissions ('ls -l' or 'stat') and modifying them ('chmod'), and candidates may confuse 'file' (type detection) with 'ls -l' (permission display). The question specifies a long-format listing, which 'stat' does not produce; only 'ls -l' meets that requirement.

How to eliminate wrong answers

Option A is wrong because 'stat' shows detailed file metadata (inode, timestamps, etc.) but does not display permissions and ownership in a concise, human-readable format like 'ls -l'. Option C is wrong because 'file' determines the file type (e.g., ELF binary, script) but does not show permissions or ownership. Option D is wrong because 'chmod' is used to change permissions, not to view them; running it without a mode argument will produce an error.

302
MCQeasy

A help desk technician receives a complaint that a shared file in /opt/app/data cannot be read by any user except root. The file permissions are -rw-------, and the file's group is already set to developers. Which command will allow the group 'developers' to read the file?

A.chmod o+r /opt/app/data
B.chmod 644 /opt/app/data
C.chmod g+r /opt/app/data
D.chown :developers /opt/app/data
AnswerC

This adds read permission specifically for the group, which is the minimal required change.

Why this answer

The file currently has permissions `-rw-------`, meaning only the owner (root) has read and write access. To allow the group 'developers' to read the file, you need to add read permission for the group. The command `chmod g+r /opt/app/data` adds read permission for the group, which is the correct approach.

This directly addresses the requirement without altering other permissions unnecessarily.

Exam trap

The trap here is that examinees often confuse changing group ownership (`chown :developers`) with granting group permissions (`chmod g+r`), or they mistakenly apply permissions to 'others' (`o+r`) instead of the group, failing to realize that the group must have explicit read permission to access the file.

How to eliminate wrong answers

Option A is wrong because `chmod o+r` adds read permission for 'others' (users not the owner and not in the group), not for the group 'developers'. Option B is wrong because `chmod 644` sets permissions to `-rw-r--r--`, which gives read access to both group and others, but it also removes any existing special permissions (like setuid/setgid) and does not specifically target only the group; it is overly broad and changes the owner's permissions unnecessarily. Option D is wrong because `chown :developers /opt/app/data` changes the group ownership of the file to 'developers', but it does not change the file's permissions; the file still has `-rw-------`, so even after changing the group, members of 'developers' still cannot read the file because no group read permission is set.

303
MCQeasy

A small business owner wants to ensure that employees cannot install unauthorized browser extensions on company-managed Windows 10 computers. Which method should you use to enforce this restriction?

A.Enable private browsing mode in each browser
B.Configure Group Policy to block extension installation
C.Set the browser homepage to a company-approved site
D.Install an ad-blocker extension
AnswerB

Configuring Group Policy to block extension installation is the most effective administrative control for domain-joined computers. Group Policy Objects (GPOs) allow network administrators to centrally define and enforce specific browser settings, including disabling the ability to install extensions, across all user accounts and machines within an Microsoft Active Directory domain. This ensures consistent security and compliance by preventing unauthorized software from being added to browsers.

Why this answer

Group Policy allows administrators to centrally manage Windows settings, including browser policies. By configuring the 'Block installation of extensions' policy under Administrative Templates for each browser (e.g., Chrome, Edge), you can prevent users from installing unauthorized extensions on company-managed Windows 10 computers.

Exam trap

The trap here is that candidates may confuse browser security features (like private browsing or homepage settings) with actual policy-based controls, overlooking that only Group Policy or registry-based policies can centrally enforce restrictions on extension installation in a managed environment.

How to eliminate wrong answers

Option A is wrong because enabling private browsing mode only prevents the browser from storing history, cookies, and form data; it does not restrict extension installation. Option C is wrong because setting the browser homepage to a company-approved site only controls the default startup page, not the ability to install extensions. Option D is wrong because installing an ad-blocker extension does not enforce a restriction; it is itself an extension and does not prevent other extensions from being installed.

304
MCQhard

A technician is decommissioning a server room and finds several old cathode ray tube (CRT) monitors that still work. The company wants to dispose of them responsibly. What should the technician do?

A.Sell the monitors to a local thrift store for reuse.
B.Break the glass tubes to reduce volume and then place them in a dumpster.
C.Contact a certified CRT recycler for pickup and recycling.
D.Donate the monitors to a school art department for projects.
AnswerC

Contacting a certified CRT recycler for pickup and recycling is the correct and environmentally responsible action. Certified recyclers adhere to stringent environmental standards, such as R2 or e-Stewards, and possess specialized equipment and processes to safely dismantle CRTs. They can properly separate leaded glass for specific processing, recover valuable metals, and manage other hazardous components, ensuring compliance with environmental laws and preventing pollution.

Why this answer

CRT monitors contain leaded glass and other hazardous materials (e.g., phosphors, barium) that are classified as universal waste under the Resource Conservation and Recovery Act (RCRA). Disposing of them in a dumpster or donating them for non-certified reuse can violate environmental regulations. A certified CRT recycler ensures the monitors are dismantled safely, with leaded glass separated and recycled in compliance with EPA guidelines.

Exam trap

The trap here is that candidates assume 'reuse' or 'donation' is always environmentally friendly, but CompTIA tests that CRTs are hazardous e-waste requiring certified recycling, not just any second-hand use.

How to eliminate wrong answers

Option A is wrong because thrift stores typically lack the certification to handle hazardous e-waste; selling CRTs for reuse may still lead to improper disposal later and does not guarantee responsible end-of-life management. Option B is wrong because breaking the glass tubes releases toxic lead dust and phosphor powder, creating an immediate health hazard and violating RCRA rules against land disposal of hazardous waste. Option D is wrong because school art departments are not equipped to safely handle or dispose of leaded glass; using CRTs for art projects still results in eventual improper disposal and potential environmental contamination.

305
MCQeasy

During a security incident, a technician needs to verify whether a specific application was granted camera and microphone permissions on a macOS computer. Which macOS tool should they use to check these privacy settings?

A.Keychain Access
B.System Settings > Privacy & Security
C.Console
D.Terminal with 'tccutil' command
AnswerB

System Settings > Privacy & Security is the definitive macOS interface for managing application access to sensitive system resources, including the camera and microphone. During a security incident, a technician can directly navigate to this centralized control panel to view which applications have been explicitly granted or denied these critical permissions. This allows for immediate identification and modification of potentially unauthorized access, making it the primary tool for such verification.

Why this answer

System Settings > Privacy & Security is the correct tool because macOS centralizes all privacy-related permissions—including camera and microphone access—in this GUI panel. The technician can navigate to the specific application under the Camera and Microphone sub-sections to verify granted permissions. This is the standard, user-facing interface for managing privacy controls on macOS.

Exam trap

The trap here is that candidates may confuse the 'tccutil' command (Option D) as a tool for checking permissions, when in fact it is only used for resetting or modifying the TCC database, not for viewing current permissions.

How to eliminate wrong answers

Option A is wrong because Keychain Access manages passwords, certificates, and secure notes, not application permissions for hardware like the camera or microphone. Option C is wrong because Console displays system logs and diagnostic messages, not privacy settings or permission states. Option D is wrong because while the 'tccutil' command can reset privacy permissions via Terminal, it is not designed to simply check or view current permissions; it requires administrative privileges and is used for bulk resets, not verification.

306
MCQeasy

A technician is configuring a Windows 11 workstation for a small business that handles credit card payments. The owner wants to ensure that stored cardholder data cannot be read if the drive is removed and attached to another computer. Which Windows feature should the technician enable?

A.BitLocker
B.Encrypting File System (EFS)
C.Windows Defender Firewall
D.User Account Control (UAC)
AnswerA

BitLocker provides full volume encryption for Windows 11, protecting data at rest so a removed drive cannot be read on another system. Enabling it on the OS drive with a TPM satisfies the requirement to render cardholder data unreadable if the disk is physically stolen. It is the built-in Windows feature that directly addresses this scenario.

Why this answer

BitLocker encrypts the entire volume, so if the drive is removed and connected to another computer, the data remains unreadable without the recovery key or the original TPM. EFS, firewall rules, and UAC do not provide full-volume encryption, so they fail the physical-theft requirement. BitLocker is the correct built-in Windows feature for protecting data at rest.

Exam trap

The trap here is confusing file-level encryption such as EFS with full-disk encryption such as BitLocker, which leads to choosing a partial solution that leaves most data exposed.

307
MCQhard

A user reports that their cloud-based virtual desktop (VDI) is disconnecting frequently. The user's internet connection is stable, and other cloud services work fine. The technician checks the VDI's resource usage and finds that the virtual machine's RAM is consistently at 95% usage. What should the technician do to resolve the disconnections?

A.Reduce the amount of RAM allocated to the VDI.
B.Increase the amount of RAM allocated to the VDI.
C.Reinstall the VDI client software on the user's device.
D.Enable GPU acceleration for the VDI.
AnswerB

Increasing the amount of RAM allocated to the VDI directly addresses memory-related performance bottlenecks. Providing more physical memory to the virtual machine allows the operating system and applications to run more efficiently, reducing the need for disk-based paging. This improves overall system responsiveness, prevents applications from crashing or becoming unresponsive due to memory exhaustion, and significantly enhances session stability, thereby mitigating disconnections.

Why this answer

This scenario tests advanced troubleshooting of VDI performance. High memory usage can cause the VM to become unresponsive, leading to disconnections. Increasing the VM's RAM allocation directly addresses the resource bottleneck.

Reducing RAM would worsen the problem, and network or GPU issues are not indicated.

308
MCQmedium

A technician is troubleshooting a user's inability to access a specific website. The user can access other websites without issue. The technician wants to check the route packets take to the problematic server and identify where the connection fails. Which command should be used?

A.ping -t example.com
B.tracert example.com
C.nslookup example.com
D.netstat -an
AnswerB

tracert sends ICMP or UDP probes with incrementing TTL values, revealing each hop and pinpointing where packets stop or time out en route to the server. This isolates whether the failure lies locally, at an intermediate router, or at the destination.

Why this answer

The `tracert` command (short for 'trace route') is the correct tool because it sends ICMP Echo Request packets with incrementally increasing TTL (Time to Live) values, causing each router along the path to reply with an ICMP Time Exceeded message. This reveals the exact hop-by-hop path to the destination and pinpoints where the connection fails, which is precisely what the technician needs to diagnose a site-specific outage.

Exam trap

CompTIA A+ often tests the distinction between connectivity testing (`ping`) and path discovery (`tracert`), trapping candidates who think `ping -t` is sufficient for route analysis, when it only verifies end-to-end reachability without hop-by-hop detail.

How to eliminate wrong answers

Option A is wrong because `ping -t` continuously sends ICMP Echo Requests to the target; it only confirms reachability or loss, but does not show the route or identify which hop is failing. Option C is wrong because `nslookup` is a DNS query tool that resolves a domain name to an IP address; it does not test network path or routing. Option D is wrong because `netstat -an` displays active network connections, listening ports, and protocol statistics on the local machine; it provides no information about the path packets take to a remote server.

309
MCQmedium

A technician receives an angry email from a user claiming that the technician's previous fix made their computer worse. The technician knows the fix was correct. Which response is MOST professional?

A.Reply with a detailed technical explanation proving the fix was right.
B.Ignore the email to avoid an argument.
C.Apologize for the inconvenience and schedule a time to revisit the issue.
D.Forward the email to the user's manager to complain about the user's tone.
AnswerC

Apologizing for the inconvenience, even if the technician believes the initial fix was correct, is a crucial de-escalation technique that validates the user's frustration without admitting fault. Scheduling a follow-up demonstrates a commitment to resolving the user's perceived problem and provides an opportunity for further diagnosis, ensuring the user feels heard and supported. This approach prioritizes customer satisfaction and effective problem management over immediate technical vindication.

Why this answer

The most professional response in this scenario is to de-escalate the situation by acknowledging the user's frustration and offering to re-engage on the issue. Even if the technician's fix was technically correct, the user's perception of a problem is a valid concern that must be addressed to maintain trust and service quality. Scheduling a follow-up allows the technician to re-evaluate the system, verify that no other changes have affected the computer, and provide reassurance, which aligns with ITIL best practices for incident management and customer service.

Exam trap

CompTIA often tests the candidate's ability to prioritize emotional intelligence and de-escalation over technical accuracy, trapping those who think proving the fix was right (Option A) is the most professional response, when in fact it ignores the user's perspective and can damage the customer relationship.

How to eliminate wrong answers

Option A is wrong because replying with a detailed technical explanation, while factually accurate, is likely to be perceived as defensive and condescending, escalating the conflict rather than resolving the user's emotional concern; professionalism requires empathy over technical correctness. Option B is wrong because ignoring the email is a form of avoidance that neglects the user's complaint, potentially damaging the technician's reputation and the IT department's credibility, and it fails to address any underlying issue that may have arisen from the fix or subsequent changes. Option D is wrong because forwarding the email to the user's manager to complain about the user's tone is unprofessional, violates confidentiality, and shifts blame instead of focusing on problem resolution; it undermines the technician's role as a service provider and could create unnecessary workplace conflict.

310
MCQhard

A company deploys a fleet of Android tablets that need to be configured so that only pre-approved apps can be installed, and the Google Play Store must be hidden from users. The tablets are not enrolled in an MDM. Which Android feature can be used to achieve this without third-party software?

A.Enable Guest Mode and restrict app installation via parental controls.
B.Use a free kiosk app that utilizes Android's Lock Task Mode to pin approved apps and hide the launcher.
C.Boot the device into Safe Mode and disable the Play Store from there.
D.Remove the Google account from the device and disable the Play Store via Settings > Apps.
AnswerB

Using a free kiosk app constitutes third-party software, which contradicts the 'without third-party software' requirement. The underlying Lock Task Mode is native, but the option explicitly suggests using an app, making it incorrect.

Why this answer

None of the provided options achieve the desired configuration without third-party software. Option B mentions using a free kiosk app, which is a third-party software, thus violating the requirement. The correct approach would be to use Android's native Lock Task Mode directly via Developer Options or Android Management APIs, which does not require any third-party app.

The other options (A, C, D) do not restrict app installation to pre-approved apps or are reversible.

Exam trap

Candidates may assume that using a kiosk app is necessary for Lock Task Mode, but the feature is native and can be configured directly without additional software.

How to eliminate wrong answers

Option A is wrong because Guest Mode and parental controls do not hide the Play Store or prevent installation of new apps; they only limit certain actions and can be bypassed by the user. Option C is wrong because Safe Mode is a diagnostic mode that disables third-party apps, not a configuration tool for permanently hiding the Play Store or restricting app installations. Option D is wrong because simply removing the Google account and disabling the Play Store via Settings > Apps does not prevent the user from re-enabling the Play Store or installing apps from other sources; it is a reversible user-level setting, not a locked-down configuration.

311
MCQmedium

A technician is setting up a wireless network for a small office that handles sensitive client data. The office has a mix of modern laptops and a few legacy printers that only support WEP. What should the technician do to maintain security while keeping the printers functional?

A.Enable WEP on the main router and set a complex 128-bit key.
B.Replace the printers with modern ones that support WPA2.
C.Create a separate VLAN for the printers using WEP and a strong passphrase, and keep the main network on WPA2.
D.Set the router to mixed mode (WEP + WPA2) and use a single SSID.
AnswerC

Creating a separate Virtual Local Area Network (VLAN) for the legacy WEP printers effectively segments the network, isolating the inherent security weaknesses of WEP to a dedicated subnet. This ensures that the main network, which carries sensitive data, can maintain robust WPA2 encryption without being compromised by the less secure WEP traffic. Network segmentation prevents an attacker who might compromise the WEP VLAN from easily accessing resources on the more secure WPA2 network, thus mitigating risk while accommodating legacy hardware.

Why this answer

It isolates the insecure WEP-based printers on a separate VLAN, preventing their weak encryption from compromising the main network which uses WPA2. This allows the legacy printers to remain functional while sensitive client data on the main network is protected by the stronger WPA2 protocol.

Exam trap

The trap here is that candidates often think mixed mode (WEP + WPA2) is a valid compromise, but CompTIA A+ tests the understanding that mixed mode on a single SSID downgrades security for all devices, whereas VLAN segmentation isolates the weak protocol without affecting the secure network.

How to eliminate wrong answers

Option A is wrong because WEP is fundamentally broken and can be cracked in minutes using tools like aircrack-ng, regardless of key length; a complex 128-bit key does not fix the underlying RC4 cipher weaknesses. Option B is wrong because replacing functional printers is an unnecessary cost and not a network configuration solution; the question asks how to maintain security while keeping the printers functional. Option D is wrong because mixed mode (WEP + WPA2) on a single SSID forces all clients to use the lowest common denominator security, allowing attackers to downgrade modern clients to WEP and compromise the entire network.

312
MCQeasy

A technician is configuring a company-issued iPhone for a new employee. After setting up the email account, the employee says they cannot receive emails, but they can send them. Which setting should the technician check first?

A.The outgoing mail server (SMTP) settings.
B.The incoming mail server (IMAP/POP3) settings.
C.The device's date and time settings.
D.The phone's VPN configuration.
AnswerB

The Incoming Mail Server settings, utilizing protocols like IMAP (Internet Message Access Protocol) or POP3 (Post Office Protocol version 3), are directly responsible for retrieving emails from the mail server to the device. If these settings, such as the server address, port number, or authentication credentials, are misconfigured, the iPhone will be unable to connect to the mail server to download new messages. This directly explains why the user can send but not receive emails.

Why this answer

The symptom—able to send but not receive emails—indicates a problem with the incoming mail server configuration. Sending uses SMTP (outgoing), while receiving uses IMAP or POP3 (incoming). The technician should first verify the incoming mail server settings (server hostname, port, SSL/TLS, and authentication) because a misconfiguration there would prevent the device from downloading new messages.

Exam trap

CompTIA often tests the distinction between incoming and outgoing mail protocols, and the trap here is that candidates mistakenly focus on SMTP (outgoing) because they think 'send' and 'receive' are handled by the same server, when in fact they use separate protocols and settings.

How to eliminate wrong answers

Option A is wrong because the outgoing mail server (SMTP) settings are responsible for sending emails, which the employee can already do successfully, so checking SMTP would not resolve the receive issue. Option C is wrong because incorrect date and time settings can cause SSL/TLS certificate validation failures for both sending and receiving, but the employee can send emails, indicating that the device's time is likely correct or at least not the primary cause of the receive-only failure. Option D is wrong because a VPN configuration issue would typically affect all network traffic or specific app connectivity, not selectively block incoming email while allowing outgoing email; email protocols operate independently of VPN unless the VPN is misconfigured to block specific ports.

313
MCQhard

You are troubleshooting a Windows 10 PC that fails to boot with the error 'Boot Configuration Data is missing.' Which built-in tool can you use from the Windows Recovery Environment to rebuild the BCD store?

A.System File Checker (sfc /scannow)
B.Diskpart
C.Bootrec.exe
D.CHKDSK
AnswerC

Bootrec.exe is a specialized command-line tool specifically engineered for troubleshooting and repairing boot-related issues in Windows operating systems. When invoked with the `/rebuildbcd` switch, it performs a comprehensive scan of all disks for compatible Windows installations. It then allows the user to select which identified installations to add to a newly created Boot Configuration Data (BCD) store, effectively reconstructing the BCD and resolving critical errors such as a missing or corrupted BCD that prevent the system from booting.

Why this answer

Bootrec.exe is the correct built-in tool for rebuilding the Boot Configuration Data (BCD) store from the Windows Recovery Environment (WinRE). The specific command 'bootrec /rebuildbcd' scans all disks for Windows installations and allows you to rebuild the BCD store, directly addressing the 'Boot Configuration Data is missing' error. Other tools like SFC, Diskpart, and CHKDSK do not have the capability to reconstruct the BCD store.

Exam trap

The trap here is that candidates often confuse System File Checker (SFC) as a universal repair tool, but it cannot fix boot configuration issues because the BCD store is not a system file protected by Windows File Protection.

How to eliminate wrong answers

Option A is wrong because System File Checker (sfc /scannow) scans and repairs protected system files, but it does not interact with or rebuild the BCD store, which is a separate boot configuration database. Option B is wrong because Diskpart is a disk partitioning tool used to manage volumes and partitions, not to repair boot configuration data; it cannot rebuild the BCD store. Option D is wrong because CHKDSK checks the file system for integrity and fixes logical disk errors, but it has no mechanism to rebuild or repair the BCD store, which is stored in a hidden system partition.

314
MCQmedium

During a security audit, a technician discovers that an employee has been using a third-party remote desktop tool without IT approval. The employee claims it was necessary to access a legacy application. Which security risk is most directly associated with unauthorized remote access tools?

A.Increased bandwidth usage
B.Man-in-the-middle attacks
C.Compatibility issues with the operating system
D.Increased licensing costs
AnswerB

Unauthorized tools, especially those not properly vetted or configured, often lack robust security features such as strong encryption protocols (e.g., TLS 1.3) or proper certificate validation. This deficiency creates vulnerabilities where an attacker can intercept communications between two parties, read sensitive data, or even alter messages in transit without either party being aware. Such tools provide an ideal vector for man-in-the-middle attacks, directly compromising the confidentiality and integrity of data exchanged and potentially leading to unauthorized access or system manipulation.

Why this answer

Unauthorized remote desktop tools often lack the encryption and authentication controls found in approved solutions like SSH or RDP with Network Level Authentication. This exposes the connection to man-in-the-middle attacks, where an attacker can intercept, decrypt, or modify the traffic between the employee's workstation and the legacy application server, potentially capturing credentials or sensitive data.

Exam trap

CompTIA often tests the distinction between operational issues (bandwidth, compatibility, cost) and actual security threats, so candidates mistakenly choose a non-security answer like increased bandwidth usage because it sounds like a plausible downside of remote access tools.

How to eliminate wrong answers

Option A is wrong because increased bandwidth usage is a performance concern, not a direct security risk, and unauthorized remote tools may actually use less bandwidth than approved ones. Option C is wrong because compatibility issues with the operating system are a functional problem, not a security risk, and the employee's claim of needing access to a legacy application suggests compatibility was achieved, not a risk. Option D is wrong because increased licensing costs are a financial or compliance issue, not a security risk, and unauthorized tools typically avoid licensing fees altogether.

315
MCQhard

A technician is updating the documentation for a server that had its RAID controller replaced. The technician must ensure that future technicians can quickly identify the new hardware configuration. Which type of documentation should be updated?

A.The network topology diagram.
B.The change management log.
C.The server's asset inventory record.
D.The knowledge base article for RAID troubleshooting.
AnswerC

The server's asset inventory record, often integrated into a Configuration Management Database (CMDB), is the definitive source for detailed hardware and software specifications of an IT asset. This record precisely documents components like the RAID controller model, firmware version, installed memory, and storage configuration. Maintaining this information ensures that technicians can quickly identify, troubleshoot, and replace specific hardware components, facilitating efficient maintenance and support.

Why this answer

The server's asset inventory record (Option C) is the correct documentation to update because it contains the detailed hardware configuration of the server, including the RAID controller model, firmware version, and disk layout. Future technicians rely on this record to quickly identify the exact hardware components without having to physically inspect the server or dig through logs. Updating the asset inventory ensures that the documented configuration matches the actual hardware, which is critical for troubleshooting, warranty claims, and future upgrades.

Exam trap

CompTIA often tests the distinction between operational documentation (like asset inventory) and process documentation (like change logs or knowledge bases), and the trap here is that candidates confuse the change management log (which tracks the change event) with the hardware configuration record (which documents the resulting state).

How to eliminate wrong answers

Option A is wrong because a network topology diagram shows how devices are connected on the network (e.g., switches, routers, IP subnets), not the internal hardware components of a server like a RAID controller. Option B is wrong because the change management log records the approval and timeline of changes (e.g., who authorized the replacement, when it occurred), but it does not serve as a quick-reference for the new hardware configuration. Option D is wrong because a knowledge base article for RAID troubleshooting provides generic guidance on resolving RAID issues, not the specific hardware details of this particular server's RAID controller.

316
MCQhard

A technician is troubleshooting a network issue for a remote employee. The employee's internet connection is unstable, and the technician suspects the home router. The employee is not technical and becomes defensive when the technician asks about their router setup. Which approach is MOST effective?

A.Tell the employee that their router is probably cheap and needs replacement.
B.Say, 'Let's work together to check a few things on your router to improve your connection.'
C.Ask the employee to run a command prompt command without explanation.
D.Escalate the issue to a senior technician without further attempts.
AnswerB

Collaborative phrasing frames the router check as shared troubleshooting rather than an interrogation, reducing the employee's defensiveness and securing cooperation. The technician still gathers the needed information, but the inclusive wording keeps the non-technical user engaged.

Why this answer

It uses a collaborative, non-confrontational approach that respects the employee's lack of technical knowledge and defuses defensiveness. By saying 'Let's work together,' the technician invites the employee to participate without blame, making it easier to guide them through checking the router's configuration (e.g., verifying Wi-Fi channel congestion, checking for firmware updates, or reviewing DHCP lease times) without requiring the employee to understand technical details. This aligns with CompTIA's emphasis on professionalism and effective communication in remote troubleshooting.

Exam trap

CompTIA often tests the candidate's ability to choose the most professional and effective communication strategy in a stressful or non-technical user scenario, where the trap is that candidates may select a technically correct but socially inappropriate option (like A or C) because they focus on the technical fix rather than the human interaction required to achieve it.

How to eliminate wrong answers

Option A is wrong because telling the employee their router is 'probably cheap and needs replacement' is dismissive, insulting, and fails to diagnose the actual issue; it assumes hardware fault without evidence and can damage trust, making the employee less cooperative. Option C is wrong because asking a non-technical employee to run a command prompt command without explanation (e.g., 'ipconfig /flushdns' or 'ping 8.8.8.8') creates confusion and anxiety, and the employee may misinterpret or incorrectly execute the command, leading to wasted time or further issues. Option D is wrong because escalating to a senior technician without attempting any troubleshooting abdicates the technician's responsibility and fails to leverage the opportunity to resolve the issue with basic communication and guidance, which is inefficient and unprofessional.

317
MCQmedium

A technician is troubleshooting an Android device that cannot receive SMS messages, though data and calls work fine. The user recently installed a messaging app from an unknown source. Which mobile OS feature should be checked first?

A.Verify that the device is not in Airplane Mode
B.Check the 'Default SMS app' setting in Apps & Notifications
C.Clear the cache of the Phone app
D.Disable Google Play Protect
AnswerB

A sideloaded messaging app can register itself as the default SMS handler, hijacking incoming messages so the native app never receives them. Checking the 'Default SMS app' setting in Apps & Notifications directly addresses the constraint that data and calls work while SMS fails after an unknown-source install.

Why this answer

The core issue is that SMS messages are not being received, while data and calls work fine. On Android, SMS routing is handled by a designated 'Default SMS app.' If a third-party messaging app from an unknown source was recently installed, it may have claimed this role, but misconfigured or lacks the necessary permissions (e.g., SMS permissions) to properly receive messages. Checking the 'Default SMS app' setting under Apps & Notifications is the first logical step to ensure the correct app is assigned to handle SMS, as Android will only deliver incoming SMS to the designated default app.

Exam trap

CompTIA often tests the misconception that SMS issues are always related to network connectivity or Airplane Mode, but the real trap here is that Android's SMS routing is app-dependent, and a third-party app can hijack the default SMS role without the user's awareness, causing SMS to fail while other services work.

How to eliminate wrong answers

Option A is wrong because Airplane Mode disables all cellular radios, which would also prevent data and calls from working; since data and calls are functioning, Airplane Mode is not the cause. Option C is wrong because the Phone app handles voice calls and its cache is unrelated to SMS message routing or reception; clearing it would not resolve a missing default SMS app issue. Option D is wrong because Google Play Protect scans apps for malware but does not control SMS routing or permissions; disabling it would not fix the SMS delivery problem and could actually reduce security.

318
MCQeasy

A small business owner calls for support because all of their files on the server have been renamed with a .encrypted extension, and a text file named 'README_TO_DECRYPT.txt' appears on the desktop demanding a Bitcoin payment. What is the first step the technician should take?

A.Pay the ransom to get the decryption key immediately.
B.Disconnect the server from the network.
C.Run a full antivirus scan on the server.
D.Restore files from a recent backup immediately.
AnswerB

Immediately disconnecting the infected server from the network is the critical first step in containing a ransomware incident. This action prevents the ransomware from encrypting additional files on the local system, halts its ability to spread to other network shares, connected devices, or backup systems, and isolates the threat. By containing the infection, IT personnel can safely begin investigation, eradication, and recovery procedures without risking wider organizational impact.

Why this answer

Ransomware encrypts files and often maintains a command-and-control channel to spread laterally across the network. Disconnecting the server from the network immediately isolates it, preventing further encryption of shared drives and blocking communication with the attacker's infrastructure. This containment step must precede any scanning, restoration, or negotiation.

Exam trap

220-1202 often tests the order of incident response steps — candidates pick 'restore from backup' or 'run antivirus' because those feel productive, but containment (network isolation) must always be the first action to stop active spread.

How to eliminate wrong answers

Option A is wrong because paying the ransom does not guarantee a working decryption key, funds criminal activity, and may mark the organization as a willing payer for future attacks. Option C is wrong because running an antivirus scan while the machine is still networked allows the ransomware to continue encrypting files and potentially spread to other hosts — containment must come first. Option D is wrong because restoring from backup before isolating the threat can result in re-infection if the ransomware payload or persistence mechanism is still active on the network.

319
MCQmedium

Your company's security policy requires that all workstations have the latest Windows security updates installed. You need to verify the update history on a user's Windows 10 PC to ensure no critical updates are missing. Which tool should you use?

A.Windows Update
B.Event Viewer
C.System Information
D.Reliability Monitor
AnswerA

Windows Update is the dedicated and primary interface within the operating system for managing and reviewing the status of security patches, feature updates, and driver installations. It provides a comprehensive history of all installed updates, allowing administrators to verify compliance with security policies and identify any missing or pending updates. This tool is essential for ensuring a workstation remains secure and up-to-date against known vulnerabilities.

Why this answer

Windows Update is the correct tool because it maintains the authoritative update history for the OS, showing installed updates, failed installs, and pending updates. In Windows 10, the Settings > Update & Security > Windows Update > Update history view (and the legacy wuapp/wuauclt interfaces) lists KB numbers, install dates, and update categories, letting you confirm whether critical security patches are present. This directly satisfies the policy requirement to verify that no critical updates are missing.

Exam trap

220-1202 often tests the distinction between tools that log events (Event Viewer, Reliability Monitor) and tools that present a consolidated update inventory (Windows Update), so candidates who equate 'logs' with 'update history' pick Event Viewer.

How to eliminate wrong answers

Option B is wrong because Event Viewer logs Windows Update service events (e.g., source 'WindowsUpdateClient') but does not present a consolidated, human-readable update history with KB numbers and install status — it is a diagnostic log, not an update inventory. Option C is wrong because System Information (msinfo32) reports hardware, OS build, and component details but does not list individual installed updates or their history. Option D is wrong because Reliability Monitor tracks system stability events, application crashes, and driver failures over time; it does not enumerate installed Windows updates.

320
MCQmedium

A user's iPhone 13 suddenly shows a black screen with a spinning gear icon after an iOS update. The device does not respond to touch or button presses. What is the most likely cause and the correct first step?

A.The battery is dead; connect to a charger and wait.
B.Force restart the iPhone by pressing and releasing Volume Up, then Volume Down, then holding the Side button until the Apple logo appears.
C.Place the device in DFU mode and restore via Finder.
D.The screen is damaged; replace the display assembly.
AnswerB

This specific button sequence (press and release Volume Up, then press and release Volume Down, then press and hold the Side button) is the standard force restart procedure for iPhone 8 and newer models, including the iPhone 13. It performs a hardware-level reset, interrupting any hung software processes, such as a frozen operating system or a stalled update. This action often resolves issues like a black screen with a spinning gear by forcing the device to reboot cleanly without data loss.

Why this answer

The black screen with a spinning gear icon after an iOS update indicates the device is stuck in a boot loop or update process, not a hardware failure. A force restart (Volume Up, Volume Down, hold Side button) is the correct first step because it forces the iPhone to reboot without erasing data, often resolving temporary software hangs. This sequence is specific to iPhone 7 and later models, including the iPhone 13, and bypasses unresponsive touch or button inputs.

Exam trap

CompTIA often tests the distinction between a force restart and DFU mode, where candidates mistakenly jump to DFU restore (Option C) as the first step, not realizing that a force restart is a non-destructive recovery method that resolves most post-update boot loops.

How to eliminate wrong answers

Option A is wrong because a dead battery would show a black screen without the spinning gear icon, and the device would respond to a charger by displaying a low-battery indicator; the gear icon indicates the OS is partially active. Option C is wrong because DFU mode and restore via Finder is a more drastic step that erases all data and should only be attempted after simpler recovery methods like force restart fail; it is not the first step. Option D is wrong because a damaged display would typically show physical cracks, discoloration, or no image at all, not a spinning gear icon, and the device would still respond to button presses or sounds.

321
MCQhard

A security audit reveals that a Windows 10 workstation has an unauthorized local user account. You need to remove this account from the command line without using the GUI. Which command should you use?

A.net localgroup Administrators UnauthorizedUser /delete
B.net user UnauthorizedUser /delete
C.wmic useraccount where name='UnauthorizedUser' delete
D.gpresult /r
AnswerB

The net user command with the /delete switch removes a local account directly from the command line, satisfying the stem's no-GUI constraint. It targets the local SAM database on the workstation, unlike domain-level tools such as Remove-ADUser, which would not affect a local account.

Why this answer

The `net user UnauthorizedUser /delete` command correctly removes a local user account from the command line. The `net user` command is designed to manage local user accounts, and the `/delete` switch removes the specified account from the local Security Accounts Manager (SAM) database. This is the standard Windows CLI tool for deleting a local user without using the GUI.

Exam trap

CompTIA often tests the distinction between deleting a user account (`net user /delete`) and removing a user from a group (`net localgroup /delete`), trapping candidates who confuse group membership removal with account deletion.

How to eliminate wrong answers

Option A is wrong because `net localgroup Administrators UnauthorizedUser /delete` removes the user from the Administrators group, not the user account itself; the account remains on the system. Option C is wrong because `wmic useraccount where name='UnauthorizedUser' delete` is a valid command for deleting a user account via WMI, but the question specifically asks for a command that removes the account, and `net user /delete` is the more direct and commonly tested CLI method; however, the primary reason it is not the best answer is that the exam expects `net user` for this task, and `wmic` is deprecated in newer Windows versions. Option D is wrong because `gpresult /r` displays Resultant Set of Policy (RSoP) data for Group Policy, not user account management.

322
MCQeasy

A company wants to allow external contractors to access a specific internal web application without installing any client software. Which remote access technology best meets this requirement?

A.VPN with a client
B.Remote Desktop Protocol
C.Reverse proxy
D.SSH
AnswerC

A reverse proxy acts as an intermediary server that sits in front of one or more web servers, forwarding client requests to the appropriate backend server and returning the server's response to the client. For external contractors, this means they can access internal web applications simply by using a standard web browser, as the reverse proxy handles the routing, security, and potentially SSL termination without requiring any special client software or configuration on their devices. This method centralizes access control and enhances security by shielding internal servers from direct internet exposure.

Why this answer

A reverse proxy is the correct choice because it allows external contractors to access a specific internal web application through a public-facing proxy server without requiring any client software installation. The reverse proxy terminates the external connection and forwards requests to the internal web server, handling authentication and encryption at the proxy layer, which meets the requirement of zero client-side setup.

Exam trap

The trap here is that candidates often confuse 'remote access' with VPN or RDP, assuming any secure remote connection requires a client, but the question specifically tests the understanding that a reverse proxy provides application-layer access without client software, unlike VPN or RDP which require dedicated clients.

How to eliminate wrong answers

Option A is wrong because a VPN with a client requires installing and configuring VPN client software on the contractor's device, which violates the 'without installing any client software' requirement. Option B is wrong because Remote Desktop Protocol (RDP) requires a client application (such as Microsoft Remote Desktop Client) to be installed on the accessing device, and it provides full desktop access rather than access to a specific web application. Option D is wrong because SSH is a protocol for secure command-line access to remote systems, typically requiring an SSH client (like PuTTY or OpenSSH) to be installed, and it does not natively provide web application access without additional tunneling or port forwarding.

323
MCQmedium

A user's browser is displaying a warning that the website's certificate is not trusted, even though the URL is correct. The technician checks the date and time on the computer and finds it is set to 2019. What is the most likely cause of the certificate warning?

A.The website's SSL certificate has been revoked.
B.The browser's certificate store is corrupted.
C.The system date is incorrect, causing certificate validation to fail.
D.The user is connected to a malicious proxy.
AnswerC

SSL/TLS certificates contain specific 'valid from' and 'valid to' date ranges, which are cryptographically signed by the Certificate Authority. If the client system's date and time fall outside this defined validity period, the browser's cryptographic validation process will fail, as it cannot confirm the certificate is currently legitimate. An incorrect system date, such as being set to 2019 when the certificate is valid for a later period, directly causes this validation failure and triggers a security warning.

Why this answer

The system date is set to 2019, which is outside the certificate's validity period. SSL/TLS certificates have a specific notBefore and notAfter date range; when the client's clock is outside this range, the browser rejects the certificate as untrusted. This is the most direct and common cause of the warning given the symptom and the technician's finding.

Exam trap

CompTIA A+ often tests the candidate's ability to distinguish between certificate revocation, corruption, and simple date/time misconfiguration, trapping those who overthink the problem or assume a security breach (like a proxy) when the most basic setting is wrong.

How to eliminate wrong answers

Option A is wrong because a revoked certificate would trigger a different warning (e.g., 'certificate revoked') and is not caused by an incorrect system date; revocation is checked via CRL or OCSP, not local clock. Option B is wrong because a corrupted certificate store would cause failures across many sites, not just one, and the date issue is a specific, isolated cause. Option D is wrong because a malicious proxy would typically present a different certificate or cause a different error (e.g., name mismatch or untrusted root), not a date-related warning, and the technician already found the date is incorrect.

324
MCQeasy

A user on an Android tablet reports that the Google Play Store is not downloading any apps, showing an error message about insufficient storage. The device's storage settings show 2GB free. What should you do first?

A.Factory reset the tablet.
B.Clear the cache and data of the Google Play Store app.
C.Uninstall large apps to free up more storage.
D.Check for a system update.
AnswerB

Clearing the cache and data for the Google Play Store app is a primary troubleshooting step because it removes any corrupted temporary files or outdated configuration data that the app has stored. These files can interfere with the Play Store's ability to download or install applications correctly, even when ample device storage is available. This action forces the app to rebuild its operational data, often resolving transient download errors without affecting other user data or system settings.

Why this answer

Clearing the cache and data of the Google Play Store app is the correct first step because the error message about insufficient storage, despite 2GB free, often indicates a corrupted cache or data within the Play Store itself. This corruption can cause the Play Store to misreport storage availability or fail to initialize downloads. Clearing these app-specific files forces the Play Store to rebuild its state, resolving the false positive without affecting user data or requiring additional free space.

Exam trap

CompTIA often tests the misconception that 'insufficient storage' errors always require freeing up physical space, when in reality the error can stem from a corrupted app cache that misreports storage, making clearing the cache the correct first step rather than deleting apps.

How to eliminate wrong answers

Option A is wrong because a factory reset is a drastic, last-resort measure that wipes all user data and settings; it is not appropriate for a software-level issue like a corrupted Play Store cache, which can be resolved with a targeted app data clear. Option C is wrong because uninstalling large apps to free up more storage addresses a genuine lack of space, but the device already shows 2GB free, which should be sufficient for most app downloads; the problem is a false storage detection, not actual insufficient capacity. Option D is wrong because checking for a system update is a general maintenance step that does not directly fix a corrupted Play Store cache or data; while updates can resolve bugs, the immediate symptom of a false storage error is best addressed by clearing the app's local data first.

325
MCQhard

A company's network was breached, and forensic analysis reveals that an attacker used a pass-the-hash attack to move laterally. Which security measure would most effectively prevent this type of attack in the future?

A.Require all users to change passwords every 30 days.
B.Implement network segmentation and firewall rules.
C.Enable Windows Defender Credential Guard.
D.Disable NTLM authentication entirely.
AnswerC

Enabling Windows Defender Credential Guard is a highly effective countermeasure specifically designed to mitigate pass-the-hash attacks by isolating credential material. It uses virtualization-based security to store NTLM password hashes and Kerberos Ticket Granting Tickets (TGTs) in a secure, isolated container, making them inaccessible to malware even if the operating system kernel is compromised. This isolation prevents attackers from extracting and reusing these critical credentials for lateral movement, directly addressing the core mechanism of pass-the-hash.

Why this answer

Windows Defender Credential Guard uses virtualization-based security (VBS) to isolate and protect NTLM password hashes and Kerberos tickets in a secure container, preventing attackers from extracting them from LSASS memory even if they have administrative access. This directly stops pass-the-hash attacks because the hashes are never accessible to the operating system or tools like Mimikatz.

Exam trap

CompTIA often tests the misconception that network segmentation or disabling NTLM alone stops pass-the-hash, but the core issue is protecting the hash in memory, which only Credential Guard (or equivalent) addresses.

How to eliminate wrong answers

Option A is wrong because frequent password changes do not prevent pass-the-hash attacks; the attacker uses the hash of the current password, and changing passwords every 30 days does not protect the hash stored in memory during an active session. Option B is wrong because network segmentation and firewall rules can limit lateral movement but do not prevent the extraction or reuse of password hashes from a compromised host; the attacker can still move within the allowed segment. Option D is wrong because disabling NTLM authentication entirely is often impractical due to legacy application dependencies, and pass-the-hash attacks can also target Kerberos tickets (pass-the-ticket), so this measure is not comprehensive and may break critical services.

326
MCQmedium

A small office has a UPS that emits a loud beeping sound and a burning smell. The technician suspects the battery is overheating. What is the correct immediate action?

A.Replace the battery while the UPS is still plugged in.
B.Unplug the UPS and move it to an open, well-ventilated area.
C.Reset the UPS by pressing the power button.
D.Spray the UPS with a fire extinguisher.
AnswerB

An overheating UPS, especially one emitting a burning smell, indicates a critical internal fault, most commonly a failing battery experiencing thermal runaway. Unplugging the unit immediately removes all power input, preventing further charging or discharge that could exacerbate the thermal event. Moving it to a well-ventilated area helps dissipate any hazardous fumes or heat, significantly mitigating the risk of fire, explosion, or inhalation exposure to toxic gases.

Why this answer

The correct immediate action is to unplug the UPS and move it to an open, well-ventilated area. A burning smell combined with loud beeping indicates a critical thermal runaway condition in the battery, which can lead to fire or explosion. Disconnecting the UPS from mains power stops the charging current that is likely exacerbating the overheating, and moving it to a ventilated area reduces the risk of toxic gas accumulation and fire spread.

Exam trap

CompTIA often tests the misconception that resetting the UPS or replacing the battery while powered on is a safe troubleshooting step, when in fact the immediate priority is to isolate the hazard by disconnecting power and ventilating the area.

How to eliminate wrong answers

Option A is wrong because replacing a battery while the UPS is still plugged in exposes the technician to high DC voltage (typically 12V–48V) and the risk of short circuits or electric shock, and the continued charging current could accelerate thermal runaway. Option C is wrong because resetting the UPS by pressing the power button does not address the underlying overheating battery; it may briefly silence the alarm but will not stop the chemical reaction causing the burning smell, and could even restart charging. Option D is wrong because spraying a UPS with a fire extinguisher, especially a CO2 or dry chemical type, can damage sensitive electronics, create a conductive residue, and is not the correct first response; the priority is to disconnect power and ventilate, not to apply an extinguisher to a device that is not yet on fire.

327
MCQhard

During a network upgrade, a technician finds a box of old NICs, cables, and small electronic components that are no longer needed. The company has no formal e-waste policy. What should the technician do?

A.Throw the items in the dumpster since they are small and the company has no policy.
B.Store the items indefinitely in a closet until a policy is created.
C.Research local e-waste recycling facilities and present a disposal plan to the manager for approval.
D.Sell the items online as a lot to a recycler.
AnswerC

This option demonstrates proactive problem-solving, professional responsibility, and environmental stewardship. By researching local e-waste recycling facilities, the technician identifies compliant and environmentally sound disposal methods for electronic waste. Presenting a formal disposal plan to management ensures proper authorization, facilitates the establishment of company-wide e-waste policies, and mitigates legal and environmental risks associated with improper disposal.

Why this answer

In the absence of a formal e-waste policy, the technician must act responsibly by researching local e-waste recycling facilities and presenting a disposal plan to the manager for approval. This aligns with environmental best practices and regulatory compliance, as improper disposal of electronic components can violate local laws and harm the environment. The technician should not unilaterally dispose of or sell the items without management authorization.

Exam trap

CompTIA often tests the trap that 'no policy means no rules,' leading candidates to choose Option A or B, but the correct approach is to proactively research and propose a compliant disposal plan rather than ignoring the issue or taking unilateral action.

How to eliminate wrong answers

Option A is wrong because throwing e-waste in a dumpster is illegal in many jurisdictions due to hazardous materials like lead, mercury, and cadmium found in NICs and electronic components; it also violates environmental responsibility even without a formal policy. Option B is wrong because storing items indefinitely in a closet is not a sustainable solution and can lead to safety hazards, space issues, and potential regulatory non-compliance if the items contain hazardous materials. Option D is wrong because selling e-waste online to a recycler without management approval and without vetting the recycler's compliance with environmental regulations could expose the company to liability and data security risks, as NICs may retain network configuration data.

328
MCQmedium

A user reports that their cloud-synced files are not appearing on their laptop after a recent OS reinstall. The technician verifies that the cloud storage account is active and the internet connection works. Which of the following is the most likely reason for the missing files?

A.The cloud storage provider has deleted the files due to inactivity
B.The user's account is not licensed for the cloud service
C.The local sync client is configured for selective sync and not downloading all folders
D.The laptop's hard drive is full
AnswerC

Many cloud synchronization clients, especially following a fresh installation or reset, default to a selective sync configuration. This setting allows users to manually specify which folders and files from the cloud should be downloaded and stored locally on the device. If the user did not explicitly select all desired folders for local synchronization, those unselected folders would appear missing on the laptop, despite being fully present and accessible in the cloud.

Why this answer

The most likely reason is that the cloud sync client is configured for selective sync, which allows the user to choose which folders are synced locally. After an OS reinstall, the client may default to selective sync or the user may have previously set it to not download all folders, so files appear missing. Other options are less likely because the account is active and internet works, and hard drive full would typically cause errors, not silent missing files.

Exam trap

The trap here is assuming that missing files after reinstall indicate data loss or account issues, when often it's a simple sync configuration like selective sync.

How to eliminate wrong answers

Option A is wrong because cloud providers do not delete files due to inactivity unless specified in terms of service, and the account is active. Option B is wrong because the account is verified as active, implying it is licensed. Option D is wrong because a full hard drive would prevent syncing and likely generate error messages, not cause files to be missing without indication.

329
MCQmedium

A company's IT policy requires that all wireless connections use certificate-based authentication to prevent unauthorized access. The network is currently using WPA2-PSK. Which configuration change is necessary to meet this policy?

A.Enable MAC address filtering on the access point.
B.Upgrade to WPA3-Personal.
C.Switch to WPA2-Enterprise and configure a RADIUS server.
D.Change the encryption from AES to TKIP.
AnswerC

WPA2-Enterprise is the appropriate solution because it leverages the 802.1X authentication framework, which is designed for robust, centralized user and device authentication. This framework integrates with a RADIUS (Remote Authentication Dial-In User Service) server, allowing for authentication against various credentials, including digital certificates. By configuring a RADIUS server to issue and validate certificates, the company can effectively enforce its policy for certificate-based authentication on wireless connections.

Why this answer

The policy requires certificate-based authentication, which is a feature of WPA2-Enterprise (802.1X). WPA2-Enterprise uses a RADIUS server to validate certificates and authenticate users individually, replacing the pre-shared key (PSK) model. This meets the requirement for certificate-based authentication to prevent unauthorized access.

Exam trap

The 220-1202 exam often tests the distinction between Personal and Enterprise modes, where candidates mistakenly think upgrading to WPA3-Personal (Option B) adds certificate support, but only the Enterprise mode with a RADIUS server enables certificate-based authentication.

How to eliminate wrong answers

Option A is wrong because MAC address filtering is not a form of authentication and can be easily spoofed; it does not use certificates. Option B is wrong because WPA3-Personal still uses a shared passphrase (SAE handshake), not certificate-based authentication; it is the Personal mode, not Enterprise. Option D is wrong because changing encryption from AES to TKIP would weaken security and does not introduce certificate-based authentication; TKIP is deprecated and not compatible with 802.1X in this context.

330
MCQmedium

A retail store wants to protect its point-of-sale (POS) terminals from unauthorized physical access during off-hours. The terminals are in an open area with no lockable cabinets. Which control should be prioritized?

A.Install a privacy screen on each POS terminal.
B.Use tamper-evident seals on the terminal casings.
C.Require a smart card to power on the terminal.
D.Enable a screensaver with a password.
AnswerB

Tamper-evident seals are physical security devices designed to provide a clear visual indication if a device's casing has been opened or manipulated. These seals typically break, tear, or display a "void" message upon removal, immediately alerting staff to potential unauthorized physical access. This proactive detection mechanism allows for timely investigation and mitigation of risks associated with internal hardware modifications or the installation of skimming devices, directly addressing the need to protect against physical tampering.

Why this answer

Tamper-evident seals on POS terminal casings are the most appropriate control because they provide a physical indication if someone has opened or accessed the terminal's internal components during off-hours. Since the terminals are in an open area with no lockable cabinets, seals offer a low-cost, immediately deployable deterrent and detection mechanism. They alert staff the next morning if tampering occurred, enabling investigation and preventing skimming attacks.

Exam trap

The trap here is confusing logical access controls (smart cards, screensavers, privacy screens) with physical security controls — candidates must recognize that the scenario specifically asks about unauthorized physical access, which only tamper-evident seals address.

How to eliminate wrong answers

Option A is wrong because a privacy screen only prevents visual eavesdropping (shoulder surfing) and does nothing to stop physical access or tampering with the terminal hardware. Option C is wrong because requiring a smart card to power on the terminal controls logical access to the operating system but does not prevent an attacker from physically opening the casing to install a skimmer or modify hardware. Option D is wrong because a password-protected screensaver is a logical access control that locks the screen after inactivity, but it does not prevent physical tampering with the terminal's internals when the device is powered off or the screen is locked.

331
MCQmedium

During a security audit, you discover that a user's browser has multiple pop-up windows appearing, even when no websites are open. The user denies installing any software. Which tool should you use to identify and remove the underlying cause?

A.Reset the browser settings to default
B.Run a full scan with Windows Defender or another anti-malware tool
C.Disable JavaScript in the browser
D.Clear the browser cache and cookies
AnswerB

Running a full scan with Windows Defender or another reputable anti-malware tool is the most effective solution because these tools are specifically designed to detect, quarantine, and remove malicious software, including adware and Potentially Unwanted Programs (PUPs). They scan the entire file system, registry, and running processes for known signatures and behavioral patterns associated with such threats, providing comprehensive remediation. This directly addresses the root cause of the pop-ups by eliminating the adware.

Why this answer

Pop-up windows appearing with no browser open is a classic symptom of adware, a browser hijacker, or a malicious browser extension — all of which are forms of malware. A full anti-malware scan with Windows Defender or a comparable tool is the correct action because it detects and removes the underlying malicious program rather than just masking its symptoms. Browser-level fixes only address surface behavior and will not remove the persistent infection.

Exam trap

220-1202 often tests the distinction between symptom relief (resetting browser, clearing cache) and root-cause remediation (anti-malware scan), tempting candidates to pick the quickest-sounding fix instead of the one that actually removes the infection.

How to eliminate wrong answers

Option A is wrong because resetting browser settings may temporarily suppress pop-ups but does not remove the malware that is generating them, so the behavior will return. Option C is wrong because disabling JavaScript breaks legitimate websites and does not address the root cause — the malicious program will still be present and may use other vectors. Option D is wrong because clearing cache and cookies only removes stored browsing data; it has no effect on installed malware or malicious extensions.

332
MCQmedium

A technician is tasked with replacing a failed power supply in a desktop computer. The old power supply is labeled with a RoHS compliance mark. How should the technician handle the old unit?

A.Place it in the regular trash because RoHS means it's non-hazardous.
B.Return it to the manufacturer for recycling or dispose of it through a certified e-waste recycler.
C.Sell it as scrap metal.
D.Store it indefinitely in case it is needed later.
AnswerB

The most environmentally responsible and legally compliant method for disposing of a failed power supply is to return it to the original manufacturer, many of whom operate take-back or recycling programs. Alternatively, utilizing a certified e-waste recycler ensures that the device is disassembled, hazardous materials are safely managed, and valuable components are recovered in accordance with local, state, and federal environmental regulations. This approach minimizes ecological impact and promotes resource sustainability.

Why this answer

The RoHS (Restriction of Hazardous Substances) compliance mark indicates the power supply was manufactured without certain hazardous materials, but it does not make the unit non-hazardous for disposal. Electronic waste (e-waste) like power supplies still contains materials such as lead solder, capacitors, and other components that require proper handling. The correct procedure is to return it to the manufacturer for recycling or dispose of it through a certified e-waste recycler to comply with environmental regulations and avoid legal penalties.

Exam trap

The trap here is that candidates mistakenly believe RoHS compliance means the device is completely non-hazardous and can be thrown in regular trash, ignoring that e-waste disposal laws apply regardless of RoHS status.

How to eliminate wrong answers

Option A is wrong because RoHS compliance only restricts the use of specific hazardous substances in manufacturing; it does not render the unit non-hazardous for disposal, and placing it in regular trash violates e-waste regulations. Option C is wrong because selling a failed power supply as scrap metal is not a standard disposal method and may expose the technician to liability if the unit contains hazardous components that are not properly handled. Option D is wrong because storing a failed power supply indefinitely is impractical, takes up space, and does not comply with environmental policies that require proper recycling or disposal of e-waste.

333
MCQhard

A company's security policy requires that all Windows 10 workstations automatically lock the screen after 5 minutes of inactivity. However, users in the sales department often leave their desks for extended periods. A technician configures the 'Interactive logon: Machine inactivity limit' policy to 300 seconds. Despite this, the screensaver does not activate. What is the most likely reason?

A.The 'Screen saver timeout' policy is set to a longer duration
B.The 'Password protect the screensaver' setting is disabled
C.The screensaver is not enabled or configured on the workstations
D.The 'Turn off the display' power setting is set to 'Never'
AnswerC

This is the correct answer because the 'Interactive logon: Machine inactivity limit' policy, while enforcing a workstation lock after a specified period of inactivity, does not inherently activate a screensaver. For a screensaver to appear before or concurrent with the lock, it must be explicitly enabled and configured, either through local display settings or via a Group Policy Object (GPO) like 'Enable screen saver' and 'Screen saver timeout'. If the screensaver is not enabled, the system will simply go to a blank screen or lock without displaying a screensaver.

Why this answer

The 'Interactive logon: Machine inactivity limit' policy locks the machine after the specified inactivity period, but it does not activate the screensaver. If the screensaver is not enabled or configured via Group Policy or local settings, the screen will not show a screensaver even though the machine locks. The policy and screensaver settings are separate mechanisms.

Exam trap

220-1202 often tests the misconception that the machine inactivity limit automatically enables the screensaver, so candidates blame the screensaver timeout or password protection instead of the missing screensaver configuration.

How to eliminate wrong answers

Option A is wrong because the 'Screen saver timeout' policy controls how long before the screensaver starts, but if the screensaver itself is not enabled, the timeout is irrelevant. Option B is wrong because 'Password protect the screensaver' only controls whether the screensaver requires a password on resume; it does not determine whether the screensaver activates. Option D is wrong because the 'Turn off the display' power setting controls monitor power, not screensaver activation; the display may turn off while the screensaver never runs.

334
MCQhard

A technician discovers that a Windows 10 workstation has been infected with a fileless malware that resides in memory. Traditional antivirus scans have not detected it. Which approach should the technician use to remove this type of malware?

A.Run a full antivirus scan in normal mode.
B.Use the Windows Malicious Software Removal Tool (MSRT) in Safe Mode.
C.Boot from a rescue disk and perform an offline scan.
D.Restore the system from a backup taken before the infection.
AnswerC

Booting from a rescue disk (such as Windows Defender Offline or a Linux-based AV live CD) starts from a trusted, read-only environment outside the infected operating system, preventing malware from loading or masking itself. The AV engine can then scan the offline Windows partition, registry hives, and even memory artifacts without interference from active malicious processes. This is the correct approach because fileless malware loses its hiding place when the original OS is not booted.

Why this answer

Fileless malware resides entirely in memory (RAM) and does not write persistent files to disk, so traditional antivirus scans that rely on file signatures cannot detect it. Booting from a rescue disk (e.g., a bootable USB or CD with an offline scanner) loads a clean operating system that bypasses the infected Windows environment, allowing the scanner to inspect memory and terminate the malware without the malware being able to hide or protect itself. This offline approach ensures the malware's process cannot interfere with the scan, making it the correct remediation method.

Exam trap

The trap here is that candidates often assume Safe Mode or a signature-based removal tool like MSRT can handle all malware types, but fileless malware specifically evades these by not writing to disk and by running within trusted system processes.

How to eliminate wrong answers

Option A is wrong because running a full antivirus scan in normal mode still operates within the compromised Windows environment, where the fileless malware can actively hide its processes or memory artifacts from the scanner. Option B is wrong because the Windows Malicious Software Removal Tool (MSRT) is a signature-based tool that targets persistent malware on disk, not memory-resident fileless threats, and Safe Mode does not prevent the malware from running if it loads via a legitimate service or driver. Option D is wrong because restoring from a backup taken before the infection would remove the malware only if the backup predates the infection, but this approach is reactive and may not be feasible if no clean backup exists; it also does not address the immediate need to remove the active memory-resident malware without data loss.

335
MCQeasy

A customer reports that their computer shuts down unexpectedly after a few minutes of use. The system feels hot to the touch, and the fan is running loudly. What is the most appropriate first step for a technician to take to ensure safety while diagnosing the issue?

A.Immediately open the case and touch the CPU heatsink to check temperature.
B.Unplug the computer, let it cool for 30 minutes, then inspect for dust or fan failure.
C.Spray compressed air into the vents while the system is running to clear dust.
D.Replace the power supply unit immediately to fix the overheating.
AnswerB

This is the safest and most logical initial troubleshooting step for an overheating issue. Unplugging the computer completely removes all power, eliminating the risk of electrical shock and minimizing ESD potential during physical interaction. Allowing the system to cool for 30 minutes ensures that internal components, especially heatsinks, reach a safe handling temperature, preventing burns. After cooling, a thorough visual inspection can safely identify common culprits like excessive dust accumulation on heatsinks and fans, or a non-spinning/faulty cooling fan.

Why this answer

The system is overheating, so the safe first step is to remove power and allow the components to cool before opening the case. Touching or working on a hot CPU/heatsink risks burns and can damage components. Once cooled, the technician can inspect for dust buildup, fan failure, or blocked airflow — the most common causes of the described symptoms.

Exam trap

The trap here is that candidates want to 'diagnose immediately' by opening the case or touching components, but CompTIA 220-1202 always prioritizes safety (power off, cool down) before any physical inspection.

How to eliminate wrong answers

Option A is wrong because touching a CPU heatsink on a system that has been running hot risks serious burns and ESD damage, and it does not address the root cause. Option C is wrong because spraying compressed air into a running system can push dust deeper, cause fan overspin, create static discharge, and expose the technician to moving parts. Option D is wrong because replacing the PSU is a guess that does not match the symptoms (loud fan, hot chassis) and ignores the actual likely cause of dust or fan failure.

336
MCQmedium

A customer complains that their computer is running slowly and they keep seeing pop-ups offering free antivirus software. They admit they clicked 'OK' on one pop-up. Which type of social engineering attack has likely occurred?

A.Phishing
B.Baiting
C.Pretexting
D.Shoulder surfing
AnswerB

Baiting is a social engineering attack that leverages a user's curiosity or greed by offering something desirable, such as "free" software, music, or a game, often advertised through a deceptive pop-up or left on a physical medium like a USB drive. The enticing offer serves as "bait" to trick the victim into installing or executing malware on their system. In this scenario, a pop-up offering "free antivirus" to a user with a slow computer directly aligns with baiting's modus operandi of exploiting a perceived need with a malicious solution.

Why this answer

Aiting. In this scenario, the user clicked 'OK' on a pop-up offering free antivirus software, which is a classic baiting attack. Baiting lures victims with a false promise (e.g., free software) to trick them into executing malware or revealing credentials.

Unlike phishing, which typically uses deceptive emails or websites to steal sensitive information, baiting relies on the allure of a free item or service to trigger a malicious download.

Exam trap

CompTIA often tests the distinction between phishing and baiting by presenting a scenario where a user is tricked by a free offer or physical media (like a USB drive), leading candidates to mistakenly choose phishing because both involve deception, but baiting specifically relies on the promise of a reward or free item.

How to eliminate wrong answers

Option A (Phishing) is wrong because phishing usually involves fraudulent emails or websites that impersonate legitimate entities to steal credentials or financial data, not pop-ups offering free software. Option C (Pretexting) is wrong because pretexting involves fabricating a scenario or identity to gain trust and extract information, not offering a free download. Option D (Shoulder surfing) is wrong because shoulder surfing is the direct observation of a user's screen or keyboard to capture sensitive data, such as passwords, and does not involve pop-ups or downloads.

337
MCQhard

During a security incident response, you discover that a user's browser has a rogue extension that exfiltrates data to a remote server. The extension was installed after the user clicked a fake update prompt on a website. What vulnerability was exploited?

A.A zero-day vulnerability in the browser.
B.An insecure direct object reference (IDOR) vulnerability.
C.Social engineering.
D.A cross-site request forgery (CSRF) attack.
AnswerC

Social engineering exploits human trust rather than a software flaw, which matches the fake update prompt that tricked the user into installing the rogue extension. The browser itself was not compromised; the user's decision to click and approve installation enabled the exfiltration, satisfying the stem's requirement for the exploited vulnerability.

Why this answer

The attack exploited the user's trust and lack of caution, not a technical flaw in the browser or web application. The user was tricked into installing a rogue extension by clicking a fake update prompt, which is a classic social engineering technique that manipulates human psychology rather than exploiting code vulnerabilities.

Exam trap

The A+ exam often tests the distinction between technical exploits and human-factor attacks, and the trap here is that candidates may assume any browser-related compromise must involve a technical vulnerability like a zero-day, overlooking that social engineering bypasses technical controls entirely.

How to eliminate wrong answers

Option A is wrong because a zero-day vulnerability is an unknown, unpatched flaw in software code that allows an attacker to compromise a system without user interaction; here, the browser itself was not exploited—the user willingly installed the extension. Option B is wrong because an insecure direct object reference (IDOR) vulnerability involves exposing a direct reference to an internal object (like a file or database record) without proper access control, which is unrelated to tricking a user into installing a malicious extension. Option D is wrong because a cross-site request forgery (CSRF) attack forces an authenticated user to execute unwanted actions on a web application where they are logged in, typically via a crafted link or form; this scenario involves no forged requests—the user actively clicked a fake prompt.

338
MCQhard

A technician is configuring power settings for a server room that houses critical equipment. The UPS battery backup needs to be tested monthly. What is the most environmentally sound way to conduct the test?

A.Unplug the server from the UPS to simulate a power failure.
B.Use the UPS management software to run a self-test that checks battery health without full discharge.
C.Disconnect the UPS from mains power and let the battery drain completely.
D.Replace the UPS battery every month to avoid testing.
AnswerB

Modern UPS units include management software that allows technicians to initiate a self-test. This diagnostic procedure typically applies a brief load to the battery and measures its voltage drop and recovery characteristics to assess its health and remaining capacity. It is a non-disruptive, efficient method that verifies battery functionality without requiring a full discharge cycle, thereby preserving battery lifespan and ensuring server uptime. This is the recommended best practice for routine battery health checks.

Why this answer

Using UPS management software to run a self-test checks battery health without a full discharge, which conserves battery cycle life and avoids unnecessary waste. This method typically performs a brief impedance or load test that verifies the battery's ability to hold a charge without stressing it, aligning with environmental best practices by reducing battery replacement frequency and energy consumption.

Exam trap

CompTIA often tests the misconception that a full discharge is the only way to verify battery health, but the environmentally sound approach is to use a software-based self-test that avoids unnecessary battery wear and waste.

How to eliminate wrong answers

Option A is wrong because unplugging the server from the UPS simulates a power failure but does not test the battery's ability to provide backup power; it only tests the UPS's transfer to battery mode, which can cause unnecessary wear on the battery and risk data loss if the server shuts down improperly. Option C is wrong because disconnecting the UPS from mains power and letting the battery drain completely subjects the battery to a deep discharge cycle, which significantly reduces its lifespan and is not environmentally sound due to increased waste and energy loss. Option D is wrong because replacing the UPS battery every month is wasteful, costly, and environmentally harmful, as batteries contain hazardous materials and should only be replaced when their capacity degrades below acceptable thresholds.

339
MCQhard

A technician is called to a warehouse where a forklift accidentally struck a rack containing several desktop PCs. The rack is leaning, and one PC has fallen and is sparking. What is the technician's first priority for safety?

A.Quickly unplug the sparking PC to prevent a fire.
B.Evacuate the area and report the incident to the safety officer or call 911.
C.Use a fire extinguisher on the sparking PC to prevent ignition.
D.Stabilize the rack with a nearby pallet to prevent further collapse.
AnswerB

The paramount concern in any hazardous situation is the safety of all personnel, making evacuation the correct initial response. A technician's primary responsibility is to remove themselves and others from immediate danger, not to attempt to mitigate a complex hazard without proper training or equipment. Reporting the incident to a safety officer or emergency services like 911 ensures that trained professionals, equipped to handle electrical fires and structural collapses, can safely secure the area and address the root cause.

Why this answer

The immediate priority when a PC is sparking and a rack is unstable is life safety. Evacuating the area and reporting the incident (to a safety officer or by calling 911) ensures no one is exposed to potential electrical fire, arc flash, or structural collapse. Attempting to unplug or extinguish the sparking PC while the rack is leaning could result in electrocution, burns, or being struck by falling equipment.

Exam trap

CompTIA often tests the principle that life safety (evacuation and reporting) always takes precedence over equipment preservation or firefighting, tempting candidates to choose a hands-on action like unplugging or extinguishing the sparking PC.

How to eliminate wrong answers

Option A is wrong because attempting to unplug a sparking PC while the rack is unstable puts the technician at risk of electric shock or arc flash, and the spark may indicate a live short that could ignite flammable materials. Option C is wrong because using a fire extinguisher on a sparking PC before evacuating and assessing the situation wastes critical time and may not address the underlying electrical hazard; the spark could be from a capacitor or power supply that could reignite. Option D is wrong because stabilizing the rack with a pallet is a secondary action that should only be performed after the area is safe and the immediate electrical hazard is controlled; it does not address the sparking PC or the risk of fire.

340
MCQmedium

A user reports that their Windows 10 laptop shows a blue screen with an error message about 'Driver IRQL not less or equal' after connecting a new external hard drive. They need to use the drive for work. Which security setting should you check to ensure driver installation is not blocked?

A.Check if Secure Boot is enabled in UEFI.
B.Verify that User Account Control is set to 'Notify me only when apps try to make changes.'
C.Disable Driver Signature Enforcement temporarily.
D.Run Windows Update to find a signed driver.
AnswerC

Disabling Driver Signature Enforcement temporarily allows the Windows operating system to load drivers that lack a valid digital signature or have an invalid one. If a blue screen error is occurring because Windows is actively blocking a newly installed or updated driver due to a signature verification failure, this action provides a crucial diagnostic step. By bypassing the enforcement, the system can potentially boot, allowing the problematic driver to load and confirming whether an unsigned or improperly signed driver is the direct cause of the system instability.

Why this answer

The 'Driver IRQL not less or equal' blue screen error typically indicates a faulty or unsigned driver. Disabling Driver Signature Enforcement (Option C) allows the installation of an unsigned driver, which is often necessary for older or third-party hardware like an external hard drive. This directly addresses the driver installation being blocked by Windows' driver signature requirements.

Exam trap

CompTIA A+ often tests the confusion between Secure Boot and Driver Signature Enforcement, as both involve driver integrity but operate at different stages (boot-time vs. runtime) and serve distinct purposes.

How to eliminate wrong answers

Option A is wrong because Secure Boot ensures that only trusted bootloaders and drivers are loaded during startup, but it does not block the installation of a driver after the OS is running; the error occurs post-boot. Option B is wrong because User Account Control (UAC) controls administrative consent for software changes, not driver signature enforcement; UAC prompts for elevation but does not block unsigned drivers specifically. Option D is wrong because running Windows Update to find a signed driver assumes a signed driver exists for the device, but the user needs to use the drive immediately, and the error indicates the current driver is problematic; this is a long-term fix, not a direct solution to the installation block.

341
MCQeasy

A user complains that every time they open their web browser, the homepage has changed to an unfamiliar search site and new toolbars appear. They did not change these settings. Which of the following is the MOST likely cause?

A.The browser has been infected with a potentially unwanted program (PUP).
B.The DNS server is returning incorrect results.
C.The user's roaming profile is corrupt.
D.The browser needs to be updated to the latest version.
AnswerA

Unwanted changes to the homepage and the appearance of new toolbars without user action are classic signs of a potentially unwanted program, often bundled with free software. PUPs modify browser settings and can redirect searches. Removing the PUP and resetting the browser settings addresses the root cause.

Why this answer

The sudden appearance of toolbars and homepage changes without user action is characteristic of a potentially unwanted program. These are often bundled with free downloads and modify browser settings. The correct response is to identify and uninstall the PUP, then reset the browser to its default configuration to remove any remaining changes.

Exam trap

The trap here is attributing browser hijacking symptoms to network or profile issues instead of recognizing the hallmark signs of unwanted software.

342
MCQmedium

A technician is troubleshooting a Windows 10 PC that was infected with a rootkit. After booting from a rescue disk and running a scan, the rootkit is removed, but the system is still unstable. What should the technician do next to ensure the system is fully remediated?

A.Reinstall the operating system from scratch.
B.Run the System File Checker (SFC) tool to repair corrupted files.
C.Disable System Restore and delete all restore points.
D.Perform a disk cleanup to remove temporary files.
AnswerB

A rootkit often replaces or corrupts protected Windows system files, so removal alone leaves the OS unstable. SFC scans and restores those files from the cached WinSxS copy, repairing the damage the rootkit caused and returning the system to a stable, fully remediated state.

Why this answer

After removing a rootkit, the system may have corrupted system files that cause instability. Running the System File Checker (SFC) tool with the 'sfc /scannow' command scans protected system files and replaces corrupted versions with cached copies from the Windows side-by-side store, directly addressing file integrity issues left by the rootkit.

Exam trap

The trap here is that candidates may choose to reinstall the OS (Option A) because they assume any rootkit infection requires a full wipe, but the question specifies the rootkit is already removed and the remaining issue is instability from file corruption, making SFC the targeted remediation step.

How to eliminate wrong answers

Option A is wrong because reinstalling the OS from scratch is an overly drastic step that is unnecessary when the rootkit has already been removed and the issue is limited to file corruption; it would also waste time and user data. Option C is wrong because disabling System Restore and deleting restore points removes potentially useful recovery snapshots but does not repair the corrupted system files causing instability. Option D is wrong because disk cleanup only removes temporary files and frees disk space, which has no effect on corrupted system files or system stability.

343
MCQmedium

A technician is troubleshooting a Windows 10 PC that fails to boot with a 'Bootmgr is missing' error. They need to repair the boot configuration. Which administrative tool should be used from the Windows Recovery Environment (WinRE)?

A.System Restore to revert to a previous restore point.
B.Command Prompt to run bootrec /rebuildbcd.
C.Device Manager to update the disk driver.
D.Local Security Policy to adjust boot options.
AnswerB

When a Windows PC fails to boot due to a missing or corrupted `bootmgr` (Boot Manager) or Boot Configuration Data (BCD), accessing the Command Prompt in the Windows Recovery Environment (WinRE) is the correct approach. The `bootrec /rebuildbcd` command specifically scans for Windows installations on the disk and allows the user to add them to a newly created BCD store, effectively repairing the boot configuration and resolving critical boot errors like "bootmgr is missing."

Why this answer

The correct tool is Command Prompt to run 'bootrec /rebuildbcd' (B). The 'Bootmgr is missing' error indicates that the Boot Configuration Data (BCD) store is missing or corrupted. The 'bootrec /rebuildbcd' command scans for Windows installations and rebuilds the BCD, which is the appropriate repair step from WinRE.

Exam trap

220-1202 often tests the specific bootrec command for BCD repair — candidates may confuse /rebuildbcd with /fixmbr or /fixboot, but /rebuildbcd is the correct choice for a missing or corrupted BCD store.

How to eliminate wrong answers

Option A is wrong because System Restore reverts system files and settings to a previous restore point, but it does not specifically repair the BCD; it may not resolve a missing bootmgr if the BCD is corrupted. Option C is wrong because Device Manager is used to manage hardware drivers, not boot configuration; updating a disk driver would not fix a missing bootmgr. Option D is wrong because Local Security Policy is for security settings, not boot configuration repair.

344
MCQeasy

A user reports that their web browser frequently redirects to an unfamiliar search engine and displays pop-up ads even when no tabs are open. What is the most likely cause of this behavior?

A.The browser needs to be updated to the latest version.
B.The user has accidentally enabled a malicious browser extension.
C.The internet connection is unstable and causing DNS errors.
D.The browser cache is full and needs to be cleared.
AnswerB

Malicious browser extensions are a primary cause of unwanted redirects and pop-ups because they operate with elevated permissions within the browser environment. These extensions can modify browser settings, intercept network requests, and inject scripts to force redirects to advertising or phishing sites. Users often install them unknowingly, bundled with other software or disguised as legitimate tools, granting them the necessary permissions to hijack browsing sessions.

Why this answer

The described behavior—unwanted redirects to an unfamiliar search engine and pop-up ads appearing even with no tabs open—is a classic symptom of adware or a malicious browser extension. Such extensions hijack browser settings, inject ads, and redirect search queries without the user's consent. Unlike a simple update or cache issue, this requires a malicious add-on that has been granted permissions to modify web content and navigation.

Exam trap

CompTIA often tests the misconception that browser issues are always caused by outdated software or cache problems, when in fact malicious extensions are a common source of persistent adware behavior that updates and cache clearing cannot fix.

How to eliminate wrong answers

Option A is wrong because updating the browser version patches security vulnerabilities but does not remove already-installed malicious extensions or undo their configuration changes. Option C is wrong because unstable internet connections or DNS errors cause timeouts or failure to load pages, not persistent redirects to a specific unfamiliar search engine or pop-up ads when no tabs are open. Option D is wrong because a full browser cache may slow performance or cause stale content to display, but it cannot generate pop-up ads or redirects to an unknown search engine; those actions require active code execution, not cached data.

345
MCQhard

A change advisory board (CAB) approves a network switch replacement, but the technician discovers during implementation that the new switch requires a different firmware version than documented. The change plan does not include a rollback for this scenario. What is the best course of action?

A.Proceed with the firmware update and document the change afterward.
B.Stop the implementation and contact the CAB for a revised change plan.
C.Use the old switch firmware on the new switch to match the documentation.
D.Implement the switch and create a separate change request for the firmware.
AnswerB

Halting the implementation and immediately contacting the Change Advisory Board (CAB) is the correct procedure when a deviation from the approved change plan is identified. This ensures that the proposed firmware update undergoes proper review, risk assessment, and formal approval, allowing the CAB to revise the change plan to include the new firmware, testing protocols, and a comprehensive rollback strategy.

Why this answer

When implementation reveals a deviation from the approved change plan and no rollback exists for the new condition, the technician must stop and return to the CAB for a revised plan. Change management requires that work proceed only within the approved scope with a defined backout; proceeding without one violates the process and risks an unrecoverable outage.

Exam trap

220-1202 often tests the misconception that documenting after the fact or filing a follow-up change request is acceptable; candidates pick 'proceed and document' or 'separate change request' options, missing that change control requires stopping and getting revised approval before proceeding.

How to eliminate wrong answers

Option A is wrong because proceeding with an unapproved firmware update and documenting afterward bypasses the CAB and leaves no rollback, violating change control. Option C is wrong because forcing old firmware onto new hardware may be incompatible or unsupported and does not address the missing rollback plan. Option D is wrong because implementing the switch first and filing a separate change request afterward is retroactive change management, which defeats the purpose of the CAB.

346
MCQeasy

During a security audit, you find that a user's browser has an outdated version of Adobe Flash Player installed. What is the primary security risk associated with this finding?

A.The browser will run slower and may crash frequently.
B.The user will be unable to view some web content.
C.Attackers can exploit known vulnerabilities in the plugin to install malware.
D.The browser will automatically disable the plugin.
AnswerC

Outdated plugins frequently contain publicly documented security vulnerabilities that have been identified and subsequently patched in newer versions. Attackers actively scan for systems running these vulnerable plugin versions and can craft malicious web pages or network requests specifically designed to trigger these known flaws. Successful exploitation can grant the attacker remote code execution privileges, enabling them to install various forms of malware, such as ransomware, keyloggers, or backdoors, directly onto the user's system without their knowledge.

Why this answer

Outdated Adobe Flash Player versions contain publicly known vulnerabilities (CVEs) that attackers can exploit via drive-by downloads or malicious advertisements. Exploiting these flaws allows arbitrary code execution, enabling malware installation without user interaction. This is the primary security risk because unpatched plugins are a common entry point for ransomware, spyware, and botnets.

Exam trap

CompTIA often tests the distinction between operational issues (performance, compatibility) and actual security vulnerabilities, trapping candidates who confuse 'annoying' with 'dangerous'.

How to eliminate wrong answers

Option A is wrong because performance issues like slower browsing or crashes are operational annoyances, not the primary security risk; outdated Flash may cause instability, but the core concern is exploitation. Option B is wrong because inability to view content is a compatibility issue, not a security risk; while some sites may require newer Flash, the audit focuses on vulnerabilities, not functionality. Option D is wrong because modern browsers (e.g., Chrome, Edge) may block or disable outdated Flash by default, but this is a mitigation, not the risk itself; the risk exists before the browser takes action.

347
MCQhard

A technician needs to deploy a custom configuration profile to 50 macOS devices in a lab. The profile must restrict access to System Settings and disable iCloud. Which tool is most appropriate for this task?

A.Terminal with 'profiles' command
B.Apple Configurator
C.System Preferences > Profiles
D.Remote Desktop
AnswerB

Apple Configurator is the correct and dedicated tool for creating and exporting custom configuration profiles (.mobileconfig files) for Apple devices, including macOS, iOS, and iPadOS. This application provides a graphical interface to define various settings, restrictions, and payloads, such as Wi-Fi, VPN, email accounts, and security policies. Once configured, the profile can be exported and then deployed to target devices, either manually or via a Mobile Device Management (MDM) solution.

Why this answer

Apple Configurator is the correct tool because it is designed for bulk deployment and management of configuration profiles on macOS and iOS devices. It allows a technician to create a single profile that restricts System Settings and disables iCloud, then apply it to multiple devices simultaneously via USB or network, making it ideal for lab environments with 50 machines.

Exam trap

A common pitfall in the A+ exam is thinking that the 'profiles' command in Terminal is sufficient for bulk deployment, but candidates overlook that it requires per-device execution and lacks the centralized management capabilities of Apple Configurator.

How to eliminate wrong answers

Option A is wrong because the 'profiles' command in Terminal is used for installing, removing, or managing configuration profiles on a single device, not for deploying to multiple devices in bulk without additional scripting or MDM infrastructure. Option C is wrong because System Preferences > Profiles is a user interface for viewing or manually installing profiles on a single Mac, not a tool for deploying profiles to multiple devices. Option D is wrong because Remote Desktop is primarily for remote control, screen sharing, and software distribution, but it lacks native support for creating or deploying configuration profiles; it would require manual profile installation on each device.

348
MCQeasy

A customer reports that their laptop battery drains quickly and the device gets very hot. They want to know the safest way to dispose of the old battery after replacement. What should you advise?

A.Throw the battery in the regular trash bin.
B.Take the battery to a certified e-waste recycling center.
C.Burn the battery in an open area to neutralize it.
D.Store the battery in a metal container until it stops holding a charge.
AnswerB

Taking a laptop battery to a certified e-waste recycling center is the correct and responsible method for disposal. These specialized facilities employ processes like mechanical separation, hydrometallurgy, or pyrometallurgy to safely dismantle batteries and recover valuable materials such as lithium, cobalt, and copper. This practice not only conserves natural resources and reduces the demand for new mining but also prevents hazardous chemicals from polluting the environment, ensuring compliance with environmental regulations.

Why this answer

Lithium-ion and lithium-polymer batteries contain hazardous materials that can leak and cause environmental damage if disposed of improperly. Certified e-waste recycling centers have the specialized equipment and processes to safely extract and recycle these materials, preventing toxic exposure and complying with environmental regulations like the Resource Conservation and Recovery Act (RCRA).

Exam trap

CompTIA often tests the misconception that storing a battery in a metal container or waiting until it fully discharges makes it safe for regular disposal, but the chemical hazard remains regardless of charge state.

How to eliminate wrong answers

Option A is wrong because throwing the battery in regular trash violates hazardous waste disposal laws and can lead to fires in landfills or recycling facilities due to lithium's reactivity with moisture and other materials. Option C is wrong because burning a lithium-ion battery can cause a violent thermal runaway reaction, releasing toxic fumes and potentially causing an explosion. Option D is wrong because storing a battery in a metal container does not neutralize the chemical hazard; it only contains the risk temporarily, and the battery remains dangerous until properly recycled.

349
MCQeasy

A technician is configuring a new Windows 11 workstation for a user who frequently downloads free software. To reduce the risk of malware infections from bundled applications, which security setting should be enabled?

A.Enable Windows Defender Application Guard.
B.Set User Account Control to always notify.
C.Turn on Windows Firewall with advanced logging.
D.Enable BitLocker drive encryption.
AnswerB

Setting User Account Control (UAC) to "Always notify" ensures that the user is prompted for explicit consent before any program makes changes that require administrative privileges, including software installations. This prompt provides a crucial opportunity to review and reject installations, effectively preventing unwanted bundled software from being installed alongside a desired application. It acts as a critical gatekeeper for system-wide changes, empowering the user to control what gets installed.

Why this answer

User Account Control (UAC) set to 'Always notify' is the correct choice because it prompts the user for consent or credentials whenever an application (including bundled installers) attempts to make system-level changes. This gives the user a chance to review and block unauthorized installations, directly reducing the risk of malware from bundled freeware. The other options address different security concerns: Application Guard isolates browser sessions, Firewall controls network traffic, and BitLocker encrypts data at rest.

Exam trap

CompTIA A+ exams often test the distinction between malware prevention (UAC prompts) and other security features like isolation (Application Guard) or encryption (BitLocker), leading candidates to choose a more advanced-sounding option that does not address the specific threat of bundled software installations.

How to eliminate wrong answers

Option A is wrong because Windows Defender Application Guard is designed to isolate untrusted web browsing sessions in a Hyper-V container, not to block bundled software installations or prompt user consent during local application setup. Option C is wrong because Windows Firewall with advanced logging only records network traffic events for analysis; it does not prevent or alert on software installation attempts. Option D is wrong because BitLocker drive encryption protects data confidentiality if the device is lost or stolen, but it does not prevent malware from being installed or executed on the system.

350
MCQeasy

A customer reports that their computer is running very slowly after they installed a new screensaver. The technician suspects the screensaver may be consuming excessive resources. Which of the following is the most professional way to address this?

A.Tell the customer that the screensaver is likely the problem and they should uninstall it.
B.Explain that you will check the system resources to identify the cause of the slowness.
C.Blame the screensaver and suggest the customer stop using decorative software.
D.Ignore the screensaver and run a full virus scan.
AnswerB

This is the most appropriate and professional response as it outlines a logical and systematic diagnostic approach. Checking system resources, such as CPU utilization, RAM usage, disk I/O, and network activity, is fundamental to identifying bottlenecks that cause general system slowness. This approach demonstrates a commitment to evidence-based troubleshooting and sets realistic expectations with the customer, indicating that a thorough investigation will be conducted to pinpoint the root cause before implementing solutions.

Why this answer

It demonstrates a professional, systematic troubleshooting approach. Instead of prematurely blaming the screensaver, the technician will use Task Manager (or Resource Monitor) to verify if the screensaver process is consuming excessive CPU, memory, or disk resources. This aligns with CompTIA's troubleshooting methodology: identify the problem by gathering data before forming a conclusion.

Exam trap

CompTIA often tests the candidate's ability to choose a professional, evidence-based response over a quick-fix or blame-oriented answer, trapping those who assume the reported change is definitely the root cause without verification.

How to eliminate wrong answers

Option A is wrong because it jumps to a conclusion without verifying the cause, which is unprofessional and could lead to unnecessary software removal if the slowness is due to another issue like a background update or malware. Option C is wrong because it blames the screensaver without evidence, which damages customer trust and violates professional communication standards. Option D is wrong because ignoring the reported change (the screensaver) and running a full virus scan is inefficient; it wastes time and may miss the actual cause if the screensaver is indeed the problem.

351
MCQmedium

A technician needs to search for any file in /etc that contains the string 'Password' (case-insensitive). Which command should be used?

A.grep -r 'Password' /etc
B.grep -ri 'Password' /etc
C.find /etc -name '*Password*'
D.locate Password | grep /etc
AnswerB

The `-r` flag makes grep recurse through every subdirectory of /etc, while `-i` ignores case so 'Password', 'password' and 'PASSWORD' all match. This satisfies both stem constraints — searching all files under /etc and matching the string case-insensitively — in a single command.

Why this answer

The `grep -ri` command performs a recursive (`-r`) case-insensitive (`-i`) search for the string 'Password' across all files under the `/etc` directory. This matches the requirement exactly: case-insensitive search for any file containing the string.

Exam trap

CompTIA often tests the distinction between searching file contents (`grep`) versus searching filenames (`find`, `locate`), and the trap here is that candidates may forget the `-i` flag for case-insensitivity or confuse `grep` with `find`.

How to eliminate wrong answers

Option A is wrong because `grep -r 'Password' /etc` performs a case-sensitive search, which would miss files containing 'password', 'PASSWORD', etc. Option C is wrong because `find /etc -name '*Password*'` searches for filenames containing 'Password', not file contents. Option D is wrong because `locate Password | grep /etc` uses the `locate` database to find files with 'Password' in their path, then filters for `/etc`, but this searches filenames, not file contents, and is case-sensitive by default.

352
MCQhard

A user reports that their Windows 10 computer is infected with ransomware that has encrypted their files. The technician boots into the Windows Recovery Environment and wants to restore the system to a previous restore point. Which command should be used?

A.rstrui.exe
B.vssadmin list shadows
C.wbadmin start recovery
D.bootrec /fixboot
AnswerA

Launches the System Restore utility, allowing restoration to a previous point.

Why this answer

The correct command is `rstrui.exe`, which launches the System Restore utility. In the Windows Recovery Environment (WinRE), this command opens System Restore so you can revert system files, registry settings, drivers, and installed programs to a previous restore point. However, System Restore does not restore or decrypt personal files that ransomware has encrypted; it only affects the operating system state.

The other options are incorrect: `vssadmin list shadows` lists existing shadow copies, `wbadmin start recovery` performs recovery from Windows Backup volumes, and `bootrec /fixboot` repairs the boot sector.

Exam trap

The trap here is that candidates confuse `vssadmin list shadows` (a query command) with an actual restoration command, or they mistakenly think `wbadmin start recovery` is for System Restore points. Another common mistake is assuming System Restore will recover ransomware-encrypted user files, which it does not.

How to eliminate wrong answers

Option B is wrong because `vssadmin list shadows` only lists existing Volume Shadow Copies (snapshots) but does not perform a restoration; it is a query command, not a recovery action. Option C is wrong because `wbadmin start recovery` is used for restoring from a Windows Server Backup, not for System Restore points, and requires a preconfigured backup set, which is not the scenario here. Option D is wrong because `bootrec /fixboot` repairs the boot sector or boot configuration data (BCD) and has no ability to restore system files or revert to a restore point; it addresses boot failures, not ransomware file encryption.

353
MCQhard

A company is designing a secure entry for a high-security lab. They need to ensure that only one person can enter at a time and that the person must be authenticated before the second door opens. Which physical security control should be used?

A.Turnstile with biometric reader
B.Security guard with logbook
C.Mantrap with smart card and biometric authentication
D.Cipher lock with door alarm
AnswerC

A mantrap's interlocking doors physically admit one person at a time, satisfying the single-entry constraint. Smart card plus biometric authentication provides two independent factors before the inner door releases, ensuring authentication precedes entry. This directly meets the stem's requirement that the person be authenticated before the second door opens.

Why this answer

A mantrap (also called an interlocking door system) is the correct physical security control because it creates a small vestibule with two interlocking doors that prevent more than one person from entering at a time. The requirement for smart card and biometric authentication ensures that the person must be authenticated before the second door opens, providing both identity verification and access control. This design enforces a strict one-person entry sequence and prevents tailgating or piggybacking.

Exam trap

CompTIA A+ often tests the distinction between a turnstile (which only prevents tailgating but does not enforce a two-door interlock with authentication) and a mantrap (which provides a secure vestibule with interlocking doors and mandatory authentication before the second door opens).

How to eliminate wrong answers

Option A is wrong because a turnstile with a biometric reader allows one person to pass at a time but does not create a secure holding area with interlocking doors; it cannot prevent a second person from following closely behind (tailgating) and does not enforce authentication before a second door opens. Option B is wrong because a security guard with a logbook relies on human observation and manual logging, which is prone to error, does not provide automated interlocking door control, and cannot guarantee that only one authenticated person enters at a time. Option D is wrong because a cipher lock with a door alarm provides only a single door with a keypad code and an alarm, lacking the two-door interlock mechanism and the multi-factor authentication (smart card + biometric) required to ensure one-person entry and authentication before the second door opens.

354
MCQeasy

A customer reports that their Android phone's screen is unresponsive to touch after a drop. They can still hear notifications and see the display. Which built-in tool should you use to test the touchscreen functionality without relying on third-party apps?

A.Safe Mode
B.Developer Options
C.Diagnostics Mode (e.g., *#0*#)
D.Factory Reset
AnswerC

Many Android manufacturers embed a hidden Diagnostics Mode, often accessible via specific dialer codes like *#0*#, which provides a suite of hardware tests. This mode allows technicians to systematically check various components, including the touchscreen for dead zones or unresponsive areas, the display for pixel issues, and sensors like the accelerometer or gyroscope. It is the ideal tool for precisely verifying if a reported screen issue stems from a hardware malfunction rather than a software glitch.

Why this answer

Diagnostics Mode (accessed via codes like *#0*# on Samsung devices) is a built-in hardware test menu that includes a dedicated touchscreen test where you draw on a grid to verify every region of the digitizer responds. It runs at the firmware level, independent of the Android OS and any third-party apps, so it isolates whether the unresponsiveness is a hardware fault (digitizer damage from the drop) versus a software issue. Because the display and audio still work, the drop likely damaged the touch digitizer specifically, and Diagnostics Mode is the correct tool to confirm that.

Exam trap

The trap here is confusing Safe Mode (a software-conflict troubleshooting boot state) with a true hardware diagnostic mode — candidates often pick Safe Mode because it sounds like a low-level 'safe' test environment, but it does nothing to test the digitizer.

How to eliminate wrong answers

Option A is wrong because Safe Mode only disables third-party apps to troubleshoot software conflicts; it does not provide any hardware test for the touchscreen and would not confirm digitizer damage. Option B is wrong because Developer Options exposes debugging and USB/UI tweaks (like pointer location overlays) but is not a hardware diagnostic suite and requires the touchscreen to already work to navigate. Option D is wrong because a Factory Reset wipes user data and reinstalls the OS — it is a destructive last-resort troubleshooting step, not a diagnostic tool, and would not test the digitizer.

355
MCQmedium

A technician is configuring a new Windows 10 kiosk computer that will run a single application for public use. They need to prevent users from accessing the desktop, taskbar, or other system functions. Which Windows security feature should be used?

A.User Account Control (UAC) set to highest level
B.Local Group Policy – Software Restriction Policies
C.Windows Defender Application Guard
D.Assigned Access (Kiosk Mode)
AnswerD

Assigned Access locks a Windows 10 account to a single Universal Windows Platform app, hiding the desktop, taskbar, and system functions from public users. This satisfies the kiosk requirement by restricting the session to one application.

Why this answer

Assigned Access (Kiosk Mode) is the correct feature because it locks down the Windows 10 device to run only a single Universal Windows Platform (UWP) app or a classic Win32 app in full-screen mode, completely hiding the desktop, taskbar, Start menu, and other system interfaces. This is specifically designed for public-facing kiosk scenarios where users must not be able to exit the application or access any other system functions.

Exam trap

A common misconception is that UAC or Software Restriction Policies can provide a full kiosk lockdown, but these features lack the ability to hide the desktop and taskbar or prevent users from launching other applications via keyboard shortcuts or the Start menu.

How to eliminate wrong answers

Option A is wrong because User Account Control (UAC) set to highest level only prompts for consent or credentials when system-level changes are attempted; it does not restrict access to the desktop, taskbar, or other system functions, nor does it enforce a single-app environment. Option B is wrong because Local Group Policy – Software Restriction Policies can block or allow specific executables but does not prevent users from accessing the desktop, taskbar, or system UI; it is a software execution control, not a kiosk lockdown mechanism. Option C is wrong because Windows Defender Application Guard is a hardware-isolated container for running untrusted applications (typically Microsoft Edge) to protect the host OS from malware; it does not restrict user access to the desktop or taskbar and is not designed for kiosk single-app scenarios.

356
MCQeasy

A help desk technician receives a Windows 11 laptop that displays a message that the operating system cannot be found at startup. The drive is detected in firmware, and the technician wants to rebuild the boot configuration without reinstalling Windows. Which command should be run from the Windows Recovery Environment?

A.chkdsk C: /f /r
B.sfc /scannow
C.bootrec /fixmbr
D.bootrec /rebuildbcd
AnswerD

bootrec /rebuildbcd scans all disks for Windows installations and rebuilds the Boot Configuration Data store, re-creating the missing boot entry that produces the operating system not found error. Running it from the Windows Recovery Environment restores the ability to boot without reinstalling, and it works with both BIOS/MBR and UEFI/GPT configurations.

Why this answer

The missing operating system message on a detected drive usually means the Boot Configuration Data store lacks a valid entry. Rebuilding it with bootrec /rebuildbcd from the recovery environment re-creates the Windows Boot Manager entry and restores startup without a full reinstall.

Exam trap

The trap here is reaching for fixmbr on a UEFI system, where the master boot record is not the component that launches Windows.

357
MCQmedium

A technician is updating the documentation for a network printer that was moved to a different floor. The technician updates the asset tag in the inventory system. Which additional documentation should the technician also update to ensure accurate records?

A.The user manual for the printer
B.The network diagram showing device locations and connections
C.The company’s acceptable use policy
D.The printer’s warranty information
AnswerB

The network diagram is a critical piece of documentation that visually represents the physical and logical topology of a network, including the precise location of devices, their connections to switches, routers, and other infrastructure components, and often their assigned IP addresses or VLANs. When a device like a printer is moved, the diagram must be updated to reflect its new physical placement, the specific network port it now utilizes, and any associated cabling changes, ensuring accurate records for troubleshooting, security audits, and future network planning. This ensures technicians can quickly locate and manage the device.

Why this answer

When a network printer is moved to a different floor, its physical location and network connectivity change. The network diagram is the authoritative document that records device locations, switch ports, IP addresses, and cabling paths. Updating it ensures that troubleshooting, asset tracking, and future moves remain accurate, directly supporting change management and documentation best practices.

Exam trap

CompTIA often tests the distinction between operational documentation (network diagrams, rack layouts, IP address management) and administrative or policy documents (user manuals, warranties, acceptable use policies) to see if candidates understand which records are directly impacted by a physical move.

How to eliminate wrong answers

Option A is wrong because the user manual is a generic reference document that does not change when a device is relocated; it contains operational instructions, not location or connectivity records. Option C is wrong because the acceptable use policy governs how employees may use company resources, not the physical or logical placement of hardware. Option D is wrong because warranty information is tied to the device's serial number and purchase date, not its physical location; moving the printer does not affect warranty terms.

358
MCQmedium

During a security audit, an administrator discovers that several employees have written their domain passwords on sticky notes attached to their monitors. The company policy requires strong passwords and prohibits sharing credentials. Which security principle is being violated?

A.Principle of least privilege
B.Account lockout policy
C.Password confidentiality
D.Multi-factor authentication
AnswerC

Writing passwords where others can read them exposes credentials to anyone passing the workstation, breaching the requirement that authentication secrets remain known only to their owner. Confidentiality of the password itself, not its complexity, is what the sticky notes defeat.

Why this answer

Password confidentiality is the principle that passwords must be kept secret and known only to the authorized user. By writing domain passwords on sticky notes attached to monitors, employees are exposing credentials to anyone with physical access, directly violating this principle. The company policy explicitly prohibits sharing credentials, and this practice undermines the security of the domain authentication system.

Exam trap

CompTIA A+ often tests the distinction between password confidentiality (keeping passwords secret) and other security controls like least privilege or MFA, leading candidates to confuse the principle of not sharing credentials with access restriction or authentication methods.

How to eliminate wrong answers

Option A is wrong because the principle of least privilege restricts user access rights to only what is necessary for their job functions, not how passwords are stored or shared. Option B is wrong because an account lockout policy defines the number of failed login attempts before an account is temporarily disabled, which is unrelated to the physical exposure of passwords. Option D is wrong because multi-factor authentication (MFA) requires two or more verification factors (e.g., password plus token), but the violation here is the failure to keep the password confidential, not the absence of additional authentication layers.

359
MCQmedium

A user wants to share a folder on their Windows 11 PC so that other users on the local network can access files without a password. They have already enabled network discovery and file sharing. Which additional setting must they configure in the Advanced Sharing settings to allow password-less access?

A.Turn on Public folder sharing
B.Turn off password protected sharing
C.Enable 128-bit encryption
D.Set up a homegroup
AnswerB

Disabling password protected sharing removes the credential prompt for inbound SMB connections, so local-network users access the share anonymously. Network discovery and file sharing alone still require authentication; this setting satisfies the password-less access requirement.

Why this answer

To allow password-less access to shared folders on a local network, you must disable password protected sharing. When this setting is turned off, Windows 11 does not require users to have a local account and password on the host machine; instead, it grants access based on the 'Everyone' group permissions. This is configured in the 'Advanced sharing settings' under 'All Networks'.

Exam trap

CompTIA often tests the misconception that enabling Public folder sharing or encryption settings will remove the password requirement, when in fact only disabling password protected sharing directly controls authentication for all shared folders.

How to eliminate wrong answers

Option A is wrong because 'Turn on Public folder sharing' only enables access to the specific 'Public' folder, not any arbitrary folder the user wants to share, and it still respects password protected sharing if enabled. Option C is wrong because 'Enable 128-bit encryption' is a security setting for file sharing connections (to enforce encryption), but it does not control whether a password is required; it can be used with or without password protected sharing. Option D is wrong because HomeGroup was removed from Windows 10 (version 1803) and later, including Windows 11; it is no longer a valid feature for sharing files on a local network.

360
MCQmedium

A customer complains that their computer emits a strong chemical smell and is unusually hot. After inspection, you find the power supply is failing and leaking a brown, oily substance. How should you handle the power supply disposal?

A.Place the power supply in a standard trash bag and throw it in the dumpster.
B.Put the power supply in an anti-static bag, seal it, and label it as hazardous e-waste.
C.Clean the power supply with isopropyl alcohol and then recycle it normally.
D.Disassemble the power supply to remove the leaking capacitor and then dispose of the rest.
AnswerB

This is the correct and safest procedure for handling a compromised power supply. An anti-static bag provides a protective barrier, containing any further leakage of potentially corrosive or toxic capacitor electrolytes and preventing contamination of the surrounding environment. Sealing and clearly labeling it as hazardous e-waste ensures that specialized recycling facilities can process it according to environmental regulations, safely neutralizing or reclaiming its components.

Why this answer

A failing power supply leaking a brown, oily substance (typically from swollen or ruptured capacitors) is classified as hazardous e-waste due to toxic materials like lead, cadmium, and electrolyte fluids. Placing it in an anti-static bag prevents short circuits during transport, and labeling it as hazardous ensures proper disposal per environmental regulations such as the Resource Conservation and Recovery Act (RCRA) or local e-waste directives.

Exam trap

CompTIA often tests the misconception that cleaning or disassembling e-waste makes it safe for normal disposal, when in fact any leaking or damaged power supply must be treated as hazardous e-waste and never opened by a technician.

How to eliminate wrong answers

Option A is wrong because throwing the power supply in a standard trash bag and dumpster violates environmental regulations; the leaking chemicals can contaminate soil and groundwater, and the power supply contains heavy metals that require special handling. Option C is wrong because cleaning with isopropyl alcohol does not neutralize the toxic electrolyte or render the unit safe for normal recycling; the power supply still contains hazardous components that must be processed through certified e-waste facilities. Option D is wrong because disassembling a leaking, potentially charged power supply poses a high risk of electric shock, chemical exposure, and further leakage; technicians should never open a failing PSU—disposal must be handled as a sealed unit.

361
MCQmedium

A user calls the help desk saying they cannot access a shared folder on the network. They can access other shares on the same server. The technician verifies the user's account is active and the folder exists. What should the technician check next to resolve the access issue?

A.Check if the user's password has expired.
B.Verify the user has been added to the local Administrators group.
C.Review the NTFS permissions on the shared folder.
D.Reboot the file server to clear any cached permissions.
AnswerC

Share permissions and NTFS permissions combine, and the most restrictive wins. Since the user reaches other shares on the same server, share-level access is likely granted, so the folder's NTFS access control entries are the next thing to inspect.

Why this answer

Since the user can access other shares on the same server, the issue is isolated to a specific shared folder. NTFS permissions control access at the folder level independently of share permissions, and a missing or incorrect NTFS entry for the user would block access even if the share permissions are open. The technician should review the NTFS permissions on that folder to ensure the user or their group has at least Read access.

Exam trap

A common trap is to assume that share permissions alone control access, but NTFS permissions are the granular layer that can block a user even when share permissions are permissive and other folders work.

How to eliminate wrong answers

Option A is wrong because the user can access other shares on the same server, so an expired password would block all network access, not just one folder. Option B is wrong because adding a user to the local Administrators group grants excessive privileges and is not required for folder access; it would not resolve a missing NTFS permission entry. Option D is wrong because rebooting the server clears cached permissions only temporarily and does not fix the underlying permission configuration; the issue will recur after the reboot.

362
MCQmedium

After a recent Windows update, a user's printer stopped working. You suspect the update changed the default print spooler service startup type. Which Control Panel tool should you use to verify and correct the service startup type?

A.Device Manager
B.Printers & scanners
C.Administrative Tools > Services
D.System > Advanced system settings
AnswerC

The "Services" snap-in, accessible via Administrative Tools or directly through `services.msc`, is the definitive utility for managing all Windows services. It provides a comprehensive list of services, their current status (running, stopped), and their configured startup type (Automatic, Manual, Disabled). To resolve a printer issue caused by the Print Spooler service not starting, an administrator would navigate here to locate the "Print Spooler" service, ensure its startup type is set to "Automatic," and then manually start it if it is not already running.

Why this answer

The Print Spooler service is a Windows service that manages print jobs sent to the printer. Its startup type (e.g., Automatic, Manual, Disabled) is configured in the Services console, which is accessed via Administrative Tools > Services. Device Manager and Printers & scanners do not provide service startup type settings, and System > Advanced system settings deals with performance and user profiles, not services.

Exam trap

The trap here is that candidates often confuse Device Manager (for driver issues) with the Services console, not realizing that the startup type of a service is managed exclusively through the Services snap-in, not through hardware or printer-specific settings.

How to eliminate wrong answers

Option A is wrong because Device Manager is used to manage hardware drivers and device properties, not Windows service startup types. Option B is wrong because Printers & scanners is for adding, removing, and configuring printer devices, not for changing the spooler service startup type. Option D is wrong because System > Advanced system settings provides access to performance options, user profiles, and startup and recovery settings, not service management.

363
MCQeasy

During a routine security audit, you find that an employee has taped their door lock open to avoid using their badge every time they leave for a break. What is the most immediate security concern with this practice?

A.The employee might lose their badge
B.It violates company badge policy
C.Unauthorized persons can enter without credentials
D.The door lock may break from being forced open
AnswerC

Taping the latch defeats the lock's authentication function, so anyone walking past can enter the restricted area without a badge. The immediate concern is unauthorised entry; audit trails and accountability are lost too, but physical access is the direct risk.

Why this answer

Propping a door lock open bypasses the physical access control system (PACS), allowing anyone—including unauthorized individuals—to enter the secured area without presenting valid credentials (e.g., a proximity card or PIN). This directly defeats the purpose of the access control mechanism, which is to authenticate and log each entry. The most immediate risk is that an attacker or tailgater can gain unrestricted physical access to sensitive assets, systems, or data.

Exam trap

The CompTIA A+ exam often tests the distinction between a policy violation and an actual security vulnerability—candidates may pick Option B because they focus on compliance rather than the immediate operational risk of unauthorized physical access.

How to eliminate wrong answers

Option A is wrong because losing a badge is a secondary concern that can be mitigated by deactivating the lost badge, whereas the open door creates an immediate, ongoing vulnerability. Option B is wrong because while violating badge policy is a compliance issue, the core security concern is the operational bypass of access control, not the policy violation itself. Option D is wrong because the door lock breaking from being forced open is a mechanical maintenance issue, not an immediate security threat—the primary risk is unauthorized entry, not equipment damage.

364
Multi-Selecthard

A security administrator is reviewing authentication methods for a company that wants to reduce the risk of credential theft while allowing employees to log in from personal mobile devices. Which two of the following should the administrator implement? (Choose two.)

Select 2 answers
A.Biometric authentication
B.Role-based access control (RBAC)
C.Single sign-on (SSO)
D.Password manager
E.Multifactor authentication (MFA)
AnswersA, E

Biometric authentication uses a fingerprint, face, or other physical trait as a factor. When used as part of MFA or as a strong authenticator on mobile devices, it makes stolen passwords insufficient for access. It directly reduces the risk of credential theft because the attacker cannot easily replicate the biometric factor.

Why this answer

MFA and biometric authentication both add factors that a stolen password alone cannot satisfy, directly reducing the risk of credential theft. SSO, password managers, and RBAC are useful but do not prevent an attacker with stolen credentials from logging in. The administrator should implement MFA and biometric authentication to strengthen login security for personal mobile devices.

Exam trap

The trap here is selecting SSO or a password manager because they improve password hygiene, while missing that only additional authentication factors stop a stolen password from being used.

365
MCQhard

A user's Windows 11 laptop has become extremely slow, and Task Manager shows constant 100% disk usage with very low actual read/write throughput. The drive is a SATA SSD, and the system is fully updated. A technician notices the drive is using the standard Microsoft AHCI driver. Which of the following is the MOST likely cause?

A.The paging file is disabled, forcing excessive disk access.
B.The SSD is failing and should be replaced immediately.
C.Windows Search indexing is still building its initial index.
D.The drive is using the wrong storage controller driver, causing high latency.
AnswerD

When a SATA SSD runs on the generic Microsoft AHCI driver instead of the vendor's optimized driver, or when the controller mode changed after an update, latency can spike and queue depth suffers, producing 100% active time with minimal throughput. Installing the correct chipset or storage driver from the manufacturer typically resolves this.

Why this answer

High disk active time with almost no throughput on a SATA SSD often stems from the storage controller driver. The generic Microsoft AHCI driver may not handle the drive's queuing and power features efficiently, causing latency. Installing the correct chipset or storage driver from the system or motherboard vendor is the most likely fix, after confirming SMART health is good.

Exam trap

The trap here is jumping to hardware failure when the symptom of high active time with low throughput more specifically points to a storage driver or controller configuration issue.

366
MCQhard

A company laptop was stolen, and the IT department needs to ensure that the data on the device cannot be accessed. The laptop had BitLocker enabled, but the drive was unlocked when stolen. What additional security measure could have prevented data access in this scenario?

A.Enable Windows Defender Firewall
B.Configure BitLocker with a startup PIN
C.Use a strong user password
D.Enable System Restore
AnswerB

Configuring BitLocker with a startup PIN provides robust full disk encryption, ensuring that all data on the drive is unreadable without the correct authentication. The startup PIN acts as a pre-boot authentication factor, requiring the user to enter it before the operating system can even begin to load and before the encryption keys are released by the Trusted Platform Module (TPM). This prevents unauthorized access to data even if the drive is removed and placed into another computer or if the device is booted from an external medium.

Why this answer

BitLocker with a startup PIN requires the user to enter a PIN before the OS loads, even if the drive was previously unlocked. Since the laptop was stolen while unlocked, the PIN would have prevented the drive from being decrypted after a reboot or power loss, protecting the data from unauthorized access.

Exam trap

CompTIA often tests the misconception that a strong user password or firewall is sufficient to protect data on a stolen device, but the key point is that BitLocker's pre-boot authentication (like a startup PIN) is the only measure that protects data when the drive is unlocked at the time of theft.

How to eliminate wrong answers

Option A is wrong because Windows Defender Firewall controls network traffic and does not encrypt or protect data at rest on the drive; it cannot prevent access to data if the drive is physically stolen. Option C is wrong because a strong user password protects the user account at the OS level, but if the drive is already unlocked (as in this scenario), the password does not encrypt the data—an attacker could bypass the login screen by booting from external media or accessing the drive directly. Option D is wrong because System Restore creates restore points for system files and settings, not encryption; it has no mechanism to prevent data access from a stolen, unlocked drive.

367
MCQeasy

A user reports that their Windows 10 desktop is running very slowly, especially when opening multiple applications. They have 8 GB of RAM and a traditional hard drive. Task Manager shows that memory usage is consistently at 90% or higher. Which component is most likely the bottleneck and what is the best upgrade?

A.The CPU is the bottleneck; upgrade to a faster processor.
B.The hard drive is the bottleneck; upgrade to an SSD.
C.The RAM is the bottleneck; add more RAM.
D.The graphics card is the bottleneck; upgrade to a dedicated GPU.
AnswerC

Insufficient Random Access Memory (RAM) forces the operating system to frequently move data between physical RAM and the much slower virtual memory (paging file) located on the storage drive. This constant swapping of data, often referred to as 'thrashing,' drastically reduces overall system performance and responsiveness, making applications feel sluggish and causing delays. Adding more physical RAM directly alleviates this by providing more fast memory for active processes, thereby minimizing the system's reliance on the significantly slower virtual memory.

Why this answer

Task Manager showing memory usage consistently at 90% or higher with 8 GB of RAM indicates the system is memory-constrained, causing excessive paging to the traditional hard drive and slowing application launches. Adding more RAM directly addresses the bottleneck by reducing paging and allowing multiple applications to reside in memory simultaneously.

Exam trap

220-1202 often tests whether candidates chase the most dramatic-sounding upgrade, so the trap is selecting an SSD upgrade because it improves general speed, when the measured 90%+ memory usage clearly identifies RAM as the actual bottleneck.

How to eliminate wrong answers

Option A is wrong because the CPU is not identified as the bottleneck; the symptom of high memory usage points to RAM, and a faster processor would not relieve memory pressure. Option B is wrong because while an SSD would improve overall responsiveness, the primary bottleneck indicated by 90%+ memory usage is RAM, and an SSD does not reduce memory consumption. Option D is wrong because graphics card bottlenecks manifest as rendering or gaming performance issues, not slow application opening with high memory utilization.

368
MCQmedium

A small business is deploying Windows 11 to 20 new workstations. During the setup, you need to ensure that each computer receives a unique computer name and joins the domain automatically. Which Windows deployment tool should you use to automate this process?

A.Windows System Image Manager (Windows SIM)
B.Windows Deployment Services (WDS)
C.Microsoft Deployment Toolkit (MDT)
D.Sysprep
AnswerB

Windows Deployment Services (WDS) is the correct choice for network-based deployment of Windows operating systems, especially in scenarios involving multiple machines. WDS enables PXE booting, allowing client computers to start the installation process over the network without local media. It serves Windows images (WIM files) and can integrate seamlessly with answer files (unattend.xml) to automate post-installation tasks such as computer naming, joining an Active Directory domain, and installing drivers, making it highly efficient for deploying Windows 11 to 20 machines.

Why this answer

Windows Deployment Services (WDS) is the correct tool because it is designed to deploy Windows operating systems over a network using Preboot Execution Environment (PXE) boot. It can be configured with answer files to automatically assign unique computer names (via naming policies or a prestaged computer accounts in Active Directory) and join the domain without manual intervention, making it ideal for deploying 20 workstations simultaneously.

Exam trap

The trap here is that candidates often confuse MDT as a standalone deployment tool, but MDT requires a deployment mechanism like WDS or bootable media to initiate the network boot, whereas WDS directly handles PXE boot and can automate domain join and naming without MDT.

How to eliminate wrong answers

Option A is wrong because Windows System Image Manager (Windows SIM) is used to create and manage unattended answer files (Unattend.xml), not to perform network-based deployments or automate domain join and naming during deployment. Option C is wrong because Microsoft Deployment Toolkit (MDT) is a deployment solution that can automate domain join and naming, but it is not a deployment tool itself; it relies on WDS or other media for network boot and is typically used for more complex task sequences, not for simple automated domain join and naming. Option D is wrong because Sysprep is a system preparation tool used to generalize a Windows image (remove unique identifiers like SID and computer name) so it can be imaged to multiple computers; it does not automate domain join or assign unique names during deployment.

369
MCQmedium

A technician needs to write a script that runs a specific command only if a Windows service is running. If the service is stopped, the script should start it first. Which scripting method is most appropriate?

A.Use a for loop to iterate over all services.
B.Use an if-else statement to check the service status.
C.Use a switch statement with multiple conditions.
D.Use a try-catch block to handle errors if the command fails.
AnswerB

An 'if-else' statement is the most appropriate control structure for evaluating a specific condition, such as whether a service's status is 'Running' or 'Stopped'. It enables the script to execute one block of commands if the condition is true and a different block if it's false. This direct conditional logic perfectly addresses the need to check a service's state and then perform specific actions based on that binary outcome.

Why this answer

An if-else statement is the most appropriate scripting method to check the status of a specific Windows service and conditionally execute a command or start the service. In PowerShell, you can use `Get-Service` to retrieve the service status and then an if-else block to evaluate whether the `Status` property equals 'Running'. This provides clear, linear logic that directly matches the requirement without unnecessary complexity.

Exam trap

CompTIA often tests the distinction between conditional logic (if-else) and error handling (try-catch), leading candidates to mistakenly choose try-catch because they think it can 'handle' a stopped service, but it cannot evaluate the service state before the command runs.

How to eliminate wrong answers

Option A is wrong because a for loop that iterates over all services is inefficient and unnecessary; the requirement is to check only one specific service, not all services. Option C is wrong because a switch statement is designed for multiple discrete value matches, not for a simple binary check of a service status (running vs. stopped), and it would overcomplicate the logic. Option D is wrong because a try-catch block handles runtime errors (e.g., service not found or access denied) but does not provide conditional logic to check the service status before deciding whether to start it.

370
MCQmedium

A technician is configuring a new Windows 10 workstation for a user who is visually impaired. The user needs the screen magnifier to start automatically when they log in, and they want high-contrast themes. Which Control Panel tool should the technician use to enable these accessibility features?

A.System > Advanced system settings
B.Ease of Access Center
C.Personalization
D.Display
AnswerB

The Ease of Access Center, now often integrated into the broader Accessibility settings in Windows 10, is the dedicated control panel for configuring features that assist users with various needs. This centralized hub provides direct access to essential accessibility tools, including Magnifier for screen enlargement, Narrator for screen reading, the On-Screen Keyboard for alternative input, and high-contrast themes to improve text visibility. These options are specifically grouped here to enhance usability and support for individuals with visual, auditory, or motor impairments.

Why this answer

The Ease of Access Center in Windows 10 is the dedicated Control Panel tool for configuring accessibility features, including Magnifier and high-contrast themes. It provides settings to enable Magnifier to start automatically at login and to apply high-contrast themes system-wide, directly addressing the user's needs.

Exam trap

CompTIA often tests the distinction between the Ease of Access Center and the Personalization or Display settings, trapping candidates who assume high-contrast themes are only in Personalization or that Magnifier auto-start is a Display setting.

How to eliminate wrong answers

Option A is wrong because System > Advanced system settings is used for performance options, user profiles, and startup and recovery settings, not for accessibility features like Magnifier or high-contrast themes. Option C is wrong because Personalization allows changing themes and colors, but it does not provide the option to set Magnifier to start automatically at login; high-contrast themes can be applied there, but the automatic startup of Magnifier is exclusive to the Ease of Access Center. Option D is wrong because Display settings manage screen resolution, orientation, and multiple displays, but do not include accessibility features such as Magnifier auto-start or high-contrast theme configuration.

371
MCQeasy

A small business wants to reduce its environmental footprint by properly managing old computer equipment. They ask which components must be handled separately due to hazardous materials. What should you identify?

A.LCD monitors
B.CRT monitors
C.Keyboard and mouse
D.Ethernet cables
AnswerB

CRT (Cathode Ray Tube) monitors are a primary concern for environmental footprint reduction due to their significant content of hazardous materials. The glass in the CRT funnel and neck contains a substantial amount of lead, often several pounds per unit, which is highly toxic and can leach into soil and groundwater if improperly disposed of in landfills. Additionally, CRTs may contain cadmium, mercury, and phosphors, all of which necessitate specialized recycling processes to safely extract and neutralize these substances, preventing severe environmental contamination.

Why this answer

CRT monitors contain leaded glass in the cathode ray tube and significant amounts of lead in the solder and phosphor coating, making them hazardous electronic waste that must be handled separately under regulations like the EPA's RCRA and the EU's WEEE Directive. Unlike LCDs, which may contain mercury in backlights but are often managed differently, CRTs require specialized recycling to prevent lead leaching into groundwater.

Exam trap

CompTIA often tests the distinction between CRT and LCD monitors, trapping candidates who assume all monitors are equally hazardous, when in fact CRTs are uniquely regulated due to lead content while LCDs are generally treated as standard e-waste unless mercury backlights are present.

How to eliminate wrong answers

Option A is wrong because LCD monitors may contain small amounts of mercury in cold-cathode fluorescent lamp (CCFL) backlights, but they are not universally classified as requiring separate hazardous handling in the same way as CRTs; many jurisdictions allow them in general e-waste streams if mercury is removed. Option C is wrong because keyboards and mice are typically non-hazardous electronic waste composed of plastic and low-voltage circuitry, with no regulated hazardous materials like lead, mercury, or cadmium. Option D is wrong because Ethernet cables are copper or fiber optic cabling with no hazardous materials; they are recyclable as standard e-waste or scrap metal.

372
MCQeasy

A user reports that their virtual desktop in a VDI environment is extremely slow during peak hours. The technician checks the host server and sees that memory utilization is at 95% and CPU is at 80%. Which of the following is the most likely cause of the performance issue?

A.The virtual switch is misconfigured
B.The host has insufficient memory for the number of VMs
C.The guest OS needs a driver update
D.The virtual hard disks are not thin-provisioned
AnswerB

Memory at 95% on the host is the bottleneck: each VM's configured RAM is reserved, so oversubscription forces hypervisor swapping to disk, degrading every guest during peak load. CPU at 80% remains below saturation, so memory contention, not processing capacity, explains the slowness.

Why this answer

The host's memory utilization at 95% indicates severe memory overcommitment, which forces the hypervisor to use excessive swapping or ballooning to reclaim memory from VMs. This directly causes extreme slowness for all virtual desktops, especially during peak hours when demand is highest. CPU at 80% is high but not as critical as memory exhaustion, which is the primary bottleneck in VDI environments.

Exam trap

CompTIA often tests the distinction between memory exhaustion (which causes swapping and severe slowdowns) versus high CPU usage (which causes processing delays but is less impactful on VDI responsiveness), leading candidates to incorrectly focus on CPU as the primary bottleneck.

How to eliminate wrong answers

Option A is wrong because a misconfigured virtual switch would cause network connectivity issues (e.g., dropped packets, inability to reach resources), not generalized slowness across all VMs due to high memory pressure. Option C is wrong because a guest OS driver update might improve device performance or fix specific hardware compatibility issues, but it would not resolve host-level memory exhaustion affecting all VMs simultaneously. Option D is wrong because thin provisioning affects storage space utilization and can lead to performance issues if the datastore runs out of space, but it does not directly cause high host memory utilization or CPU usage; the reported metrics point to memory, not storage.

373
MCQmedium

A user reports that after a recent Windows update, they can no longer install a legacy application that requires write access to the Program Files folder. The user is a local administrator. What Windows security setting is most likely blocking the installation?

A.BitLocker Drive Encryption
B.User Account Control (UAC)
C.Windows Defender Firewall
D.Group Policy Software Restrictions
AnswerB

User Account Control (UAC) is a core Windows security feature designed to prevent unauthorized changes to the operating system by requiring explicit consent for actions that could affect system integrity. When a user, even an administrator, attempts to install software or make system-level changes, UAC prompts for elevation, displaying a "permission denied" or "administrator privileges required" message if elevation is not granted. A recent Windows update could have tightened UAC policies or reset them to a more secure default, causing previously unprompted installations to now trigger UAC.

Why this answer

User Account Control (UAC) is the Windows security feature that prompts for consent or credentials before allowing actions that require administrative privileges, even for local administrators. By default, UAC virtualizes write attempts to protected system locations like Program Files, redirecting them to a per-user virtual store, which can cause legacy applications that expect direct write access to fail. Disabling UAC or running the installer with explicit administrative rights (e.g., right-click 'Run as administrator') typically resolves the issue.

Exam trap

CompTIA often tests the misconception that local administrators always run with full administrative privileges, but UAC's default behavior means even admins operate with a filtered token until they explicitly elevate, causing legacy installers to fail when they attempt to write to protected folders like Program Files.

How to eliminate wrong answers

Option A is wrong because BitLocker Drive Encryption provides full-disk encryption to protect data at rest and does not block write access to the Program Files folder; it operates at the disk level, not the file system permission level. Option C is wrong because Windows Defender Firewall controls network traffic based on rules and does not restrict local file system write operations. Option D is wrong because Group Policy Software Restrictions can block installation of specific software based on path, hash, or certificate rules, but the scenario describes a generic inability to write to Program Files after an update, which is a classic symptom of UAC virtualization behavior, not a targeted restriction policy.

374
MCQeasy

A user on iOS 17 complains that their iPhone's battery drains quickly and the phone gets warm during normal use. They have not installed any new apps recently. Which built-in tool should you use first to identify the cause?

A.Settings > General > iPhone Storage
B.Settings > Battery
C.Settings > Privacy > Analytics & Improvements
D.Settings > Display & Brightness
AnswerB

Settings > Battery shows battery usage by app and activity, making it the first tool to identify what is consuming power.

Why this answer

The user reports rapid battery drain and heat during normal use, which usually indicates an app or process consuming excessive power. The first built-in diagnostic step is Settings > Battery, which shows battery usage by app and activity over the last 24 hours or 10 days, allowing you to identify the specific cause. Battery Health only reports maximum capacity and peak performance capability; it can reveal degradation but does not identify which app or process is causing the drain.

Exam trap

CompTIA often tests the misconception that battery drain is always caused by screen brightness or storage, leading candidates to choose Display & Brightness or iPhone Storage. Another common trap is choosing Battery Health when the goal is to identify the cause of drain; Battery Health shows capacity and throttling, while Settings > Battery shows per-app usage.

How to eliminate wrong answers

Option A is wrong because Settings > General > iPhone Storage manages storage space, not battery performance or thermal behavior, and would not identify a battery health issue. Option C is wrong because Settings > Privacy > Analytics & Improvements contains diagnostic logs for developers and Apple, not a user-facing tool for immediate battery drain troubleshooting. Option D is wrong because Settings > Display & Brightness controls screen brightness, auto-lock, and True Tone, which affect battery life indirectly but do not diagnose the root cause of unexpected drain or overheating.

375
MCQhard

A technician is dealing with a zero-day malware infection that has evaded all signature-based antivirus scans. The malware is polymorphic, changing its code each time it infects a new system. Which approach is most likely to detect and remove this type of malware?

A.Update the antivirus to the latest signature definitions and run a full scan.
B.Use a bootable antivirus rescue disk to scan the system before the OS loads.
C.Employ a heuristic-based or behavior-based malware removal tool.
D.Reinstall the operating system from a known-good backup.
AnswerC

Heuristic and behaviour-based tools detect malicious actions and structural traits rather than fixed signatures, so polymorphic code that rewrites itself each infection still exhibits the same runtime behaviour and is caught. Signature scanning fails because no stable byte pattern persists.

Why this answer

Heuristic and behavior-based detection tools analyze the actions and code patterns of malware rather than relying on static signatures. Since polymorphic malware changes its code with each infection, signature-based detection fails, but behavioral analysis can identify malicious activity such as registry modifications, process injection, or network anomalies. This approach is effective against zero-day threats because it detects anomalies without needing prior knowledge of the specific malware variant.

Exam trap

CompTIA often tests the misconception that bootable rescue disks or signature updates can overcome polymorphic or zero-day malware, when in reality only behavior-based or heuristic methods can detect such threats.

How to eliminate wrong answers

Option A is wrong because updating antivirus signatures only adds known malware hashes or patterns, which cannot match the constantly changing code of polymorphic malware; signature-based detection is inherently ineffective against zero-day threats. Option B is wrong because a bootable rescue disk still relies on the same signature database or heuristic engine of the installed antivirus; if the malware evades signature scans, booting from a rescue disk does not change the detection methodology. Option D is wrong because reinstalling the OS from a backup is a recovery measure, not a detection or removal technique; it does not identify or remove the malware and may reintroduce the infection if the backup is compromised.

Page 4

Page 5 of 10

Page 6

All pages

Practice 220-1202 by domain

Target a specific domain to shore up weak areas.

See all domains with question counts →