Courseiva

CompTIA A+ Core 2 220-1202 (220-1202) — Questions 451–525

687 questions total · 10pages · All types, answers revealed

Page 6

Page 7 of 10

Page 8
451
MCQmedium

A technician needs to copy a directory tree from /home/user/docs to a backup location /backup/docs, preserving all permissions, ownership, and timestamps. Which command should they use?

A.cp -r /home/user/docs /backup/docs
B.cp -a /home/user/docs /backup/docs
C.cp -p /home/user/docs /backup/docs
D.rsync -r /home/user/docs /backup/docs
AnswerB

The `-a` (archive) flag bundles `-dR --preserve=all`, recursing through the tree while retaining permissions, ownership, timestamps, and symlinks. This directly satisfies the stem's requirement to preserve all three attributes during the copy from /home/user/docs to /backup/docs.

Why this answer

The `cp -a` (archive) command preserves all file attributes, including permissions, ownership, and timestamps, while recursively copying the entire directory tree. This is the most comprehensive single command for duplicating a directory with full metadata integrity.

Exam trap

CompTIA often tests the distinction between `-p` and `-a` by making candidates think preserving permissions and timestamps is sufficient, while the key requirement to preserve ownership is only met by `-a` (or running `-p` as root).

How to eliminate wrong answers

Option A is wrong because `cp -r` only performs a recursive copy without preserving ownership or timestamps; it may also alter permissions based on the current umask. Option C is wrong because `cp -p` preserves permissions and timestamps but does not preserve ownership (files will be owned by the copying user unless run as root). Option D is wrong because `rsync -r` recursively copies files but does not preserve ownership or timestamps by default; it requires additional flags like `-a` or `--archive` to achieve full preservation.

452
MCQeasy

A user reports that their Android smartphone is running very slowly and the battery drains quickly, even when the phone is idle. The user recently installed several new apps from a third-party app store. Which of the following should a technician do FIRST to troubleshoot the issue?

A.Update the Android operating system to the latest version.
B.Uninstall all apps installed from the third-party store.
C.Check the battery usage statistics to identify power-hungry apps.
D.Perform a factory reset of the device.
AnswerC

Battery usage statistics show which apps consume the most power. Since the problem started after installing new apps, reviewing this list can quickly pinpoint a malicious or poorly coded app. This is a non-destructive first step that directly addresses the symptom and guides further action.

Why this answer

When a phone slows down and battery drains after installing new apps, the most efficient first step is to review battery usage statistics. This built-in tool identifies which apps are consuming the most power, allowing the technician to target the likely culprit without erasing data or removing all new apps.

Exam trap

The trap here is jumping to a factory reset or mass uninstallation instead of using built-in diagnostic data to identify the specific offending app.

453
MCQmedium

A technician is documenting a configuration change to a firewall rule that allows remote access for a new employee. The technician must ensure the documentation is clear for future audits. Which of the following is the most critical piece of information to include?

A.The exact date and time the rule was added.
B.The IP address of the new employee's remote location.
C.The business justification for the rule.
D.The name of the technician who made the change.
AnswerC

The business justification provides the critical "why" behind any configuration change, linking the technical action directly to an organizational need, policy, or problem resolution. This explanation is paramount for audit compliance, demonstrating adherence to security policies, and facilitating future reviews or troubleshooting by clearly articulating the intended purpose and expected outcome of the modification. It ensures the change aligns with strategic objectives and operational requirements.

Why this answer

Change management documentation must include the business justification to demonstrate that the change was authorized and necessary. Without a clear reason, auditors cannot verify that the firewall rule complies with organizational security policy or regulatory requirements. The business justification provides the context needed to distinguish legitimate changes from unauthorized or malicious modifications.

Exam trap

CompTIA often tests the principle that operational details (who, when, where) are less critical than the business justification in change management documentation, tempting candidates to choose the most concrete or easily recorded detail instead of the most audit-relevant one.

How to eliminate wrong answers

Option A is wrong because while the date and time are useful for tracking, they are not the most critical piece; auditors need the 'why' behind the change, not just the 'when'. Option B is wrong because the remote employee's IP address may be dynamic or subject to change, and including it without the business justification does not prove the rule was authorized; the justification is what validates the rule's purpose. Option D is wrong because the technician's name is secondary to the business justification; knowing who made the change is less important than understanding why the change was made, and auditors focus on authorization and necessity, not just attribution.

454
MCQmedium

A customer reports that their Windows 11 PC is displaying a 'Low Disk Space' warning on the C: drive. You need to quickly free up space by removing temporary files and system cache. Which administrative tool should you use?

A.Defragment and Optimize Drives to consolidate free space.
B.Disk Cleanup to delete temporary files and system cache.
C.Computer Management > Disk Management to shrink the volume.
D.Event Viewer to clear application logs.
AnswerB

Disk Cleanup is the primary Windows utility designed to safely remove various types of unnecessary files that accumulate over time, directly freeing up significant disk space. This includes temporary internet files, system error memory dump files, Recycle Bin contents, temporary application files, and system cache files. By targeting these non-essential data elements, it effectively reclaims storage without impacting system functionality or user data.

Why this answer

Disk Cleanup (cleanmgr.exe) is the built-in Windows tool specifically designed to remove temporary files, system cache, and other unnecessary data to free up disk space. It provides a simple interface to select categories like Temporary Internet Files, Recycle Bin, and Windows Update Cleanup. This directly addresses the customer's need to quickly free space by deleting temp files and cache.

Exam trap

The trap here is confusing disk optimization tools (like Defragment) with disk cleanup tools; candidates might think defragmentation frees space, but it only rearranges files. Similarly, Disk Management and Event Viewer are unrelated to temporary file removal.

How to eliminate wrong answers

Option A is wrong because Defragment and Optimize Drives rearranges files on the disk to improve performance, but it does not delete temporary files or free up significant space; it only consolidates free space. Option C is wrong because Disk Management is used to manage partitions and volumes (e.g., shrink, extend, format), not to delete temporary files; shrinking a volume reduces its size but does not remove files. Option D is wrong because Event Viewer is for viewing and managing event logs, and clearing logs frees minimal space and does not target temporary files or system cache.

455
MCQmedium

During a software deployment, you need to create a script that runs automatically every time a user logs into their Windows 10 domain-joined computer. Which tool should you use to configure this task?

A.Task Scheduler
B.Group Policy Management Console
C.Local Group Policy Editor
D.Windows PowerShell ISE
AnswerA

Task Scheduler is the most appropriate Windows utility for creating a scheduled task that automatically executes a script for any user upon logon. It provides granular control over triggers, allowing for specific conditions like "At log on" for any user or a specific user, and can run with various privilege levels. This flexibility makes it ideal for reliably deploying per-user scripts that need to run during a software deployment, ensuring consistent execution.

Why this answer

Task Scheduler is the correct tool because it allows you to create a task that triggers on a specific event, such as user logon. You can set the trigger to 'At log on' for any user or a specific user, and the task will run automatically each time the user logs into the Windows 10 domain-joined computer. This is the native Windows mechanism for scheduling scripts or programs to run at logon without requiring additional configuration.

Exam trap

CompTIA often tests the distinction between tools that configure local machine behavior (Task Scheduler) versus tools that manage domain-wide policies (Group Policy Management Console), leading candidates to mistakenly choose GPMC for a local logon script task.

How to eliminate wrong answers

Option B (Group Policy Management Console) is wrong because it is used to manage Group Policy Objects (GPOs) across an Active Directory domain, not to schedule a local script to run at user logon; while you could deploy a logon script via GPO, the question specifies configuring the task directly on the computer, not centrally deploying it. Option C (Local Group Policy Editor) is wrong because it edits local Group Policy settings on a single machine, but it does not provide a direct way to schedule a script to run at logon; you would need to assign a logon script via the 'Scripts (Logon/Logoff)' policy, which is less flexible than Task Scheduler and does not allow event-based triggers like 'At logon' with specific conditions. Option D (Windows PowerShell ISE) is wrong because it is an integrated scripting environment for writing and debugging PowerShell scripts, not a tool for scheduling tasks; you would still need to use Task Scheduler or another scheduler to run the script automatically at logon.

456
MCQmedium

A company uses a Remote Desktop Gateway to allow employees to access internal desktops from the internet. Users report that they can connect to the gateway but cannot see any available desktops in the list. Which of the following is the most likely cause?

A.The Remote Desktop Gateway service is not running on the server.
B.The users are not members of the correct Active Directory group that is allowed to access specific desktops.
C.The desktops are powered off or disconnected from the network.
D.The user's RDP client is outdated and cannot display the list.
AnswerB

Remote Desktop Gateway utilizes Connection Authorization Policies (CAPs) and Resource Authorization Policies (RAPs) to manage access. CAPs determine who can connect to the gateway, while RAPs specify which internal network resources (desktops or servers) those authorized users are permitted to access. If users can connect to the gateway but cannot see or access specific desktops, it strongly indicates they are not members of the Active Directory group defined in the relevant RAP that grants permission to those particular resources.

Why this answer

The Remote Desktop Gateway (RD Gateway) acts as a proxy, allowing external RDP connections to internal desktops. When users can connect to the gateway itself but see no desktops, it typically indicates an authorization failure: the RD Gateway uses Resource Authorization Policies (RAPs) to control which desktops a user can access. If the user is not a member of the Active Directory group specified in the RAP, the gateway will deny the list of available desktops, even though the gateway connection succeeds.

Exam trap

CompTIA often tests the distinction between gateway connectivity (CAP) and resource visibility (RAP), tempting candidates to choose generic network or client issues when the real problem is authorization policy misconfiguration.

How to eliminate wrong answers

Option A is wrong because if the RD Gateway service were not running, users would not be able to connect to the gateway at all; the symptom here is a successful connection but no desktop list. Option C is wrong because powered-off or disconnected desktops would still appear in the list (though they might show as unavailable); the RD Gateway does not filter the list based on desktop power state. Option D is wrong because an outdated RDP client might cause display or feature issues, but it would not prevent the gateway from returning the list of desktops; the list is generated server-side based on RAPs.

457
MCQhard

A technician is writing a Python script to automate the cleanup of user profiles on a Windows server. The script must iterate through all user profile folders in 'C:\Users', check the last modified date, and delete profiles older than 90 days. Which scripting concept is essential for this task?

A.Error handling with try-except
B.A for loop to iterate over folders
C.A while loop with a counter
D.A function to calculate date difference
AnswerB

A "for" loop is the most appropriate and Pythonic construct for iterating over a known collection of items, such as a list of folders obtained from a directory listing. It provides a clear and concise way to process each folder sequentially, executing a block of code for every item until the collection is exhausted. This direct iteration over an iterable object is fundamental to systematically examining and acting upon each folder, making it essential for the task.

Why this answer

A for loop is essential for iterating over all user profile folders in 'C:\Users'. The script needs to process each folder one by one to check the last modified date and delete if older than 90 days. A for loop is the standard construct for iterating over a collection of items, such as directories.

Exam trap

The trap is that candidates might overthink and choose error handling or date functions, but the question asks for the essential concept for iterating through folders, which is a for loop.

How to eliminate wrong answers

Option A (Error handling with try-except) is wrong because while error handling is good practice, it is not the essential concept for iterating through folders — the core task requires iteration. Option C (A while loop with a counter) is wrong because a while loop with a counter is a less direct way to iterate over a known collection; a for loop is specifically designed for iterating over items like folders. Option D (A function to calculate date difference) is wrong because while calculating date difference is needed, it is a supporting task, not the essential scripting concept for iterating through all folders.

458
MCQmedium

A user reports that a script they run daily now fails with 'Permission denied' even though they haven't changed any permissions. The script is located in /usr/local/bin/script.sh and has permissions -rwxr-xr-x. The user is in the 'users' group. What is the most likely issue?

A.The script's shebang line is incorrect.
B.The /usr/local/bin partition is mounted with the noexec option.
C.The user does not have read permission on the script.
D.The script has been replaced with a directory.
AnswerB

When a filesystem is mounted with the `noexec` option, the operating system kernel explicitly prevents the execution of any binaries or scripts located on that partition, regardless of their individual file permissions. Even if a script has the execute bit set (e.g., `chmod +x script.sh`), attempting to run it from a `noexec`-mounted filesystem will result in a "Permission denied" error. This security feature is designed to prevent the execution of potentially malicious code from certain partitions.

Why this answer

The script has execute permissions for the user (rwxr-xr-x), so the 'Permission denied' error is not due to missing execute bits. The most likely cause is that the /usr/local/bin filesystem is mounted with the 'noexec' option, which prevents execution of any binary or script regardless of its permission bits. This is a common administrative security measure that blocks execution from specific partitions, and it would cause the script to fail with 'Permission denied' even though the file permissions appear correct.

Exam trap

This question tests the distinction between file permission bits and filesystem mount options, trapping candidates who focus only on chmod or ownership changes when the real issue is a system-wide execution restriction like 'noexec'.

How to eliminate wrong answers

Option A is wrong because an incorrect shebang line would typically cause a 'command not found' or 'bad interpreter' error, not a 'Permission denied' error. Option C is wrong because the script's permissions are -rwxr-xr-x, which grants read permission to the owner, group, and others, so the user in the 'users' group does have read access. Option D is wrong because if the script were replaced with a directory, the error would be 'Is a directory' or similar, not 'Permission denied'.

459
MCQmedium

A technician is configuring a new workstation for a customer who is concerned about energy consumption. Which setting should the technician enable to reduce power usage when the computer is idle?

A.Disable the screensaver and set the display to turn off after 30 minutes.
B.Enable hibernation mode after 1 hour of inactivity.
C.Enable sleep mode after 15 minutes of inactivity.
D.Set the power plan to 'High performance' to reduce power draw.
AnswerC

Enabling sleep mode after 15 minutes of inactivity is the optimal choice for reducing power consumption while maintaining quick system responsiveness. In sleep (S3) mode, the system significantly reduces power to most components, but keeps the RAM powered to retain the current session data. This allows the workstation to resume operation almost instantly, making it ideal for short periods of user absence.

Why this answer

Enabling sleep mode after 15 minutes of inactivity places the computer into a low-power state (S3 sleep, Suspend-to-RAM) where the CPU is powered down but RAM retains data, allowing a quick wake-up. This directly reduces energy consumption during idle periods more effectively than simply turning off the display, as it cuts power to the processor, drives, and most peripherals.

Exam trap

The trap here is that candidates often confuse 'turning off the display' with full system power saving, or they assume that a longer idle timer (like 1 hour for hibernation) is better than a shorter one (15 minutes for sleep), not realizing that sleep mode engages much sooner and thus saves more energy over typical idle periods.

How to eliminate wrong answers

Option A is wrong because disabling the screensaver and setting the display to turn off only reduces power to the monitor; the rest of the system (CPU, RAM, drives) remains fully active, consuming significant power. Option B is wrong because hibernation mode (S4 state) saves the system state to disk and completely powers off, but after 1 hour it is less aggressive than sleep after 15 minutes, meaning the system wastes more energy during the first 45 minutes of idle time. Option D is wrong because the 'High performance' power plan maximizes CPU speed and prevents power-saving features, actually increasing power draw rather than reducing it.

460
MCQeasy

A user reports that their Windows 11 laptop frequently displays a message that the battery is not charging and the system clock keeps resetting to an earlier date. The laptop is plugged into a known-good power outlet. Which of the following should a technician check first?

A.The power adapter
B.The hard drive
C.The RAM
D.The CMOS battery
AnswerD

A failing CMOS battery commonly causes the system clock to reset and can also affect power management, sometimes leading to battery charging issues. Since the laptop is plugged into a good outlet, the CMOS battery is a logical first check. Replacing it often resolves both symptoms. This is the correct answer because the clock reset is a classic indicator of a dead CMOS battery.

Why this answer

The CMOS battery maintains the system clock and BIOS settings when the computer is unplugged. When it fails, the clock resets and sometimes power management settings are lost, which can affect battery charging. The power adapter, hard drive, and RAM do not cause the clock to reset.

Therefore, the CMOS battery is the first component to check.

Exam trap

The trap here is focusing on the battery charging issue and immediately suspecting the power adapter, while overlooking the clock reset as a clear sign of a dead CMOS battery.

461
MCQeasy

A small business wants to ensure that only authorized employees can access the file server from their laptops. Each laptop has a unique MAC address. Which security measure should be implemented on the network switch?

A.Disable SSID broadcast
B.Enable WPA3 encryption
C.Configure MAC filtering
D.Change the default admin password
AnswerC

Configuring MAC (Media Access Control) filtering on the wireless access point or router establishes an access control list (ACL) based on the unique hardware addresses of network interface cards. Only devices whose MAC addresses are explicitly added to this approved list will be permitted to associate with the wireless network and gain access. This method directly addresses the requirement to ensure that only specific, authorized devices can connect, effectively blocking any device with an unlisted MAC address.

Why this answer

MAC filtering on a network switch allows the administrator to create an access control list (ACL) that permits or denies traffic based on the source MAC address. By configuring the switch to allow only the MAC addresses of authorized employee laptops, the small business can restrict file server access to those specific devices, even if they connect via a wired Ethernet port.

Exam trap

The trap here is that candidates confuse wireless security features (SSID, WPA3) with wired network access controls, or they mistakenly think changing the admin password restricts user access to network resources rather than just protecting the switch itself.

How to eliminate wrong answers

Option A is wrong because disabling SSID broadcast is a wireless security measure that hides the network name from beacon frames; it does not control access on a wired switch and does not authenticate individual laptops. Option B is wrong because WPA3 encryption is a Wi-Fi security protocol for wireless networks, not a feature that can be configured on a wired Ethernet switch to filter traffic by MAC address. Option D is wrong because changing the default admin password protects the switch's management interface from unauthorized configuration changes, but it does not enforce per-device access control to the file server.

462
MCQeasy

A user reports that they cannot execute a shell script they wrote in their home directory. The script has permissions -rw-r--r--. Which command should be used to allow the owner to execute the script?

A.chmod 755 script.sh
B.chmod u+x script.sh
C.chmod +r script.sh
D.chmod 644 script.sh
AnswerB

The file mode -rw-r--r-- grants the owner read and write but no execute bit. chmod u+x adds execute permission for the owner only, leaving group and other permissions unchanged, allowing the owner to run the script.

Why this answer

The script currently has permissions -rw-r--r--, meaning the owner has read and write but not execute. The command chmod u+x adds execute permission for the owner (u) without affecting other permissions. This directly addresses the user's inability to execute the script by granting the missing execute bit to the owner.

Exam trap

CompTIA often tests the distinction between adding a specific permission (u+x) versus setting an absolute mode (755), where candidates may choose 755 because it 'works' without recognizing it unnecessarily grants execute to group and others.

How to eliminate wrong answers

Option A is wrong because chmod 755 sets permissions to rwxr-xr-x, which grants execute to owner, group, and others — this is overly permissive and not the minimal change needed. Option C is wrong because chmod +r adds read permission, but the script already has read permission for all; it does not add execute permission. Option D is wrong because chmod 644 sets permissions to rw-r--r--, which is identical to the current permissions and does not add execute permission for anyone.

463
MCQhard

A security incident occurs where an attacker captures the 4-way handshake of a WPA2-PSK network and successfully cracks the passphrase offline. The technician is tasked with preventing this type of attack in the future. Which protocol should the technician implement?

A.WPA2-PSK with a longer passphrase.
B.WPA3-SAE.
C.WPA2-Enterprise with PEAP-MSCHAPv2.
D.WPA2-PSK with TKIP.
AnswerB

WPA3-SAE replaces the WPA2-PSK four-way handshake's offline-crackable exchange with a simultaneous authentication of equals, a dragonfly handshake providing forward secrecy and resisting offline dictionary attacks. This directly prevents the captured-handshake cracking described, satisfying the requirement to stop that attack type.

Why this answer

WPA3-SAE (Simultaneous Authentication of Equals) replaces the pre-shared key (PSK) model with a password-authenticated key exchange that is resistant to offline dictionary attacks. Unlike WPA2-PSK, which transmits a hash of the password in the 4-way handshake that can be captured and cracked offline, SAE uses a zero-knowledge proof protocol that prevents an attacker from deriving the password from captured handshake data, even if they have the full handshake.

Exam trap

A common misconception is that simply increasing passphrase length or switching to enterprise authentication prevents offline cracking of the 4-way handshake, when in fact only a protocol change to SAE (WPA3) eliminates the offline dictionary attack vector.

How to eliminate wrong answers

Option A is wrong because simply lengthening the WPA2-PSK passphrase does not change the underlying protocol vulnerability; the 4-way handshake still transmits a hash that can be captured and cracked offline with sufficient time and resources, making it a mitigation, not a prevention. Option C is wrong because WPA2-Enterprise with PEAP-MSCHAPv2 still uses the same 4-way handshake for the wireless encryption key exchange, and while the authentication is server-based, the handshake itself remains vulnerable to offline cracking if the attacker captures it and the MSCHAPv2 challenge/response is weak. Option D is wrong because WPA2-PSK with TKIP is actually less secure than WPA2-PSK with AES; TKIP is deprecated and vulnerable to multiple attacks, and it does nothing to prevent offline dictionary attacks on the 4-way handshake.

464
MCQhard

A technician is deploying laptops for a sales team that works remotely from coffee shops and client sites. The laptops contain sensitive customer data. Which physical security control is most practical for these mobile devices?

A.Install a laptop tracking software
B.Use a biometric fingerprint reader on the laptop
C.Require a smart card for login
D.Attach a cable lock to the laptop
AnswerD

Attaching a cable lock to the laptop is a direct physical security control designed to deter theft by anchoring the device to an immovable object, such as a desk or table. This physical tether significantly increases the effort and time required for a thief to remove the laptop, making it a less attractive target for opportunistic theft. It provides a tangible barrier against unauthorized physical removal, directly addressing the need for physical theft prevention.

Why this answer

A cable lock is the most practical physical security control for mobile devices used in public spaces because it physically secures the laptop to a fixed object, preventing theft. Unlike software or authentication measures, a cable lock directly addresses the risk of the device being physically taken, which is the primary threat when working in coffee shops or client sites.

Exam trap

The A+ exam often tests the distinction between physical security controls (like cable locks) and logical/authentication controls (like biometrics or smart cards), so the trap here is confusing authentication methods with physical theft prevention.

How to eliminate wrong answers

Option A is wrong because laptop tracking software is a reactive measure that helps locate a stolen device after the fact, but it does not prevent the initial theft or protect sensitive data in the moment. Option B is wrong because a biometric fingerprint reader provides authentication security, not physical security; it can be bypassed if the device is stolen and the attacker uses other methods to access data. Option C is wrong because requiring a smart card for login is an authentication control that protects access to the operating system, but it does not prevent the physical theft of the laptop itself.

465
MCQmedium

A technician is troubleshooting a laser printer that is producing smudged prints. The technician needs to remove the toner cartridge to inspect the drum. What safety precaution should be taken?

A.Wear a respirator mask to avoid inhaling toner particles.
B.Discharge the high-voltage power supply before touching the drum.
C.Avoid touching the drum surface and handle the cartridge carefully to prevent toner spills.
D.Use a vacuum cleaner to clean any spilled toner immediately.
AnswerC

This is correct because the organic photoconductor (OPC) drum is extremely sensitive to light, scratches, and the oils from human skin, so any direct touch can cause print defects such as blank spots or streaks. Additionally, toner is a fine, powdery substance that can easily spill if the cartridge is tipped or shaken, creating a messy and potentially hazardous dust. Therefore, careful handling that avoids the drum and minimizes shock is the single most important safety practice for this procedure.

Why this answer

The primary safety precaution when handling a toner cartridge is to avoid touching the drum surface, which is sensitive to light, oils, and scratches, and to handle the cartridge carefully to prevent toner spills. Toner is a fine powder that can be messy and difficult to clean, but it is not a respiratory hazard under normal handling conditions, so a respirator is not required. The high-voltage power supply in a laser printer is typically discharged automatically when the printer is unplugged, and using a vacuum cleaner for toner spills is dangerous because toner can be electrostatically charged and may cause a fire or explosion in a standard vacuum.

Exam trap

CompTIA often tests the misconception that toner is toxic and requires a respirator, or that high-voltage components need manual discharge, when in fact the immediate risk is physical damage to the drum and the electrostatic fire hazard from improper cleanup.

How to eliminate wrong answers

Option A is wrong because toner particles are not a respiratory hazard under normal handling conditions; a respirator mask is unnecessary and not a standard safety precaution for toner cartridge removal. Option B is wrong because the high-voltage power supply in a laser printer is designed to discharge automatically when the printer is unplugged and the power is removed; there is no need to manually discharge it before touching the drum, and doing so could be dangerous. Option D is wrong because using a standard vacuum cleaner to clean toner spills is a fire and explosion hazard due to the electrostatic charge of toner particles; only a toner-rated or anti-static vacuum should be used.

466
MCQhard

A technician is preparing to deploy a security patch to 50 workstations. The change request has been approved, and the patch has been tested on a pilot group. During the deployment, five workstations fail to install the patch. What should the technician do next according to change management best practices?

A.Continue deploying to the remaining workstations and troubleshoot the failures later
B.Halt the deployment and execute the rollback plan for the failed workstations
C.Force the patch to install using administrative tools
D.Submit a new change request for the failed workstations
AnswerB

Halting the deployment and executing the pre-defined rollback plan for affected workstations is the correct and most responsible course of action. This immediately mitigates further risk by preventing additional systems from being compromised and restores failed systems to a known stable state. It adheres to established change management protocols, allowing for proper investigation of the failure cause without compounding the problem.

Why this answer

According to change management best practices, when a deployment encounters failures, the immediate priority is to halt the deployment to prevent further issues and then execute the rollback plan to restore the failed workstations to their previous known-good state. This ensures stability and minimizes disruption, as the rollback plan was already defined and approved as part of the change request. Continuing or forcing the patch could lead to system instability or security vulnerabilities.

Exam trap

CompTIA often tests the misconception that troubleshooting can be deferred or that a new change request is required for each failure, when in fact the approved change request already covers rollback procedures for failed deployments.

How to eliminate wrong answers

Option A is wrong because continuing the deployment while ignoring failures violates the change management principle of risk mitigation; it could propagate errors or leave systems in an inconsistent state, making later troubleshooting more complex. Option C is wrong because forcing the patch installation with administrative tools bypasses the tested deployment process and could cause system corruption or incompatibility, especially if the failures indicate a deeper issue like driver conflicts or missing dependencies. Option D is wrong because submitting a new change request for only five workstations is unnecessary and inefficient; the existing approved change request already includes a rollback plan for handling failures, and a new request would delay resolution without adding value.

467
MCQeasy

During a routine security audit, a technician discovers that a server was patched out of the approved maintenance window. The patch was applied by a junior admin who was not authorized. What is the most important step to include in the incident documentation?

A.The name of the junior admin who applied the patch.
B.The reason the patch was applied outside the maintenance window.
C.The exact time the patch was applied.
D.The patch's version number and source.
AnswerB

The justification for applying a patch outside the designated maintenance window is paramount for proper change management and risk assessment. This documentation allows the Change Advisory Board (CAB) or security team to evaluate the urgency and necessity of the emergency change, ensuring that procedural deviations are understood, approved retroactively if warranted, and that appropriate controls are in place to minimize future occurrences. It directly addresses the procedural breach identified by the audit.

Why this answer

The most important step in incident documentation is to capture the reason the patch was applied outside the approved maintenance window. This directly addresses the root cause of the unauthorized change, which is critical for post-incident review, process improvement, and preventing recurrence. Without the reason, the documentation fails to support a meaningful root cause analysis (RCA) and corrective action planning.

Exam trap

CompTIA often tests the distinction between documenting what happened versus why it happened, and the trap here is that candidates focus on technical details (time, version, person) instead of the root cause reason that drives corrective action.

How to eliminate wrong answers

Option A is wrong because while the name of the junior admin may be noted for accountability, it is not the most important element for understanding the incident's cause and preventing future occurrences. Option C is wrong because the exact time, though useful for timeline reconstruction, does not explain why the change was made outside policy. Option D is wrong because the patch version and source are technical details that help identify the change but do not address the procedural violation or its underlying motivation.

468
MCQeasy

A user complains that their computer is running very slowly, and they see frequent pop-up ads even when no browser is open. They also notice a new toolbar in their browser that they did not install. What is the most likely security issue?

A.A rootkit has hidden itself in the system's firmware.
B.A worm is spreading through the network, consuming bandwidth.
C.The system is infected with adware that displays unsolicited advertisements.
D.A Trojan horse has stolen the user's banking credentials.
AnswerC

Adware injects unsolicited advertisements and installs browser toolbars without consent, matching the pop-ups appearing outside the browser and the unfamiliar toolbar. Its persistence and system slowdown align with the reported symptoms, distinguishing it from viruses or ransomware.

Why this answer

The symptoms—pop-up ads without a browser open, an unwanted toolbar, and system slowdown—are classic indicators of adware. Adware is a type of potentially unwanted program (PUP) that displays intrusive advertisements, often by injecting ads into system processes or browser sessions, and can degrade performance by consuming CPU and memory resources.

Exam trap

CompTIA often tests the distinction between adware and other malware types by presenting symptoms that seem like a Trojan or rootkit, but the presence of unsolicited pop-ups and an unwanted toolbar specifically points to adware, not credential theft or stealthy persistence.

How to eliminate wrong answers

Option A is wrong because a rootkit is designed to hide its presence and maintain privileged access, not to display pop-up ads or install browser toolbars; firmware rootkits specifically target low-level system firmware (e.g., UEFI) and do not cause visible adware symptoms. Option B is wrong because a worm spreads autonomously across networks to replicate and consume bandwidth, but it does not typically install browser toolbars or generate pop-up ads on a single user's machine. Option D is wrong because a Trojan horse that steals banking credentials would focus on keylogging or form grabbing, not on displaying unsolicited advertisements or adding browser toolbars; those symptoms are unrelated to credential theft.

469
MCQeasy

A school IT administrator needs to remotely lock a lost MacBook and display a custom message with contact information. The MacBook is enrolled in the school’s MDM and has an internet connection. Which macOS feature should they use?

A.Remote Desktop
B.Find My Mac
C.FileVault
D.Terminal command 'sudo pmset'
AnswerB

Find My Mac is the correct solution as it is an integrated Apple service designed specifically for locating and securing lost or stolen macOS devices. When enabled, it leverages iCloud to allow an administrator to remotely lock the device with a passcode, display a custom message on the lock screen, play a sound, or even erase all data to protect sensitive information. This functionality relies on the device having an active internet connection and being linked to an iCloud account, providing essential anti-theft and data protection features.

Why this answer

Find My Mac is the correct feature because it is specifically designed to locate, lock, and display a custom message on a lost Apple device that is enrolled in MDM and connected to the internet. It leverages Apple's Activation Lock and MDM integration to remotely lock the Mac and present a contact message on the Lock screen, fulfilling the administrator's requirement without needing physical access.

Exam trap

The A+ exam often tests the distinction between remote management tools (like Remote Desktop) and dedicated lost-device recovery features (like Find My Mac). Candidates may mistakenly assume that any remote access tool can perform the lock-and-message function, but only Find My Mac provides the specific lost-mode lock with custom message display.

How to eliminate wrong answers

Option A is wrong because Remote Desktop is a screen-sharing and remote management tool that requires the Mac to be online and accessible via VNC, but it cannot remotely lock the device or display a custom message on the Lock screen; it is not designed for lost-device scenarios. Option C is wrong because FileVault provides full-disk encryption to protect data at rest, but it does not include any remote lock or message-display capability; it is a security feature, not a lost-device recovery tool. Option D is wrong because the Terminal command 'sudo pmset' is used to manage power management settings (e.g., sleep, wake, power-saving) and has no function for locking the device or displaying a custom message; it is a common misconception that a command-line tool can substitute for Find My Mac.

470
MCQeasy

A user calls the help desk because their Windows 11 laptop will not boot. The screen displays the message "Bootmgr is missing" immediately after the manufacturer logo. The technician needs to repair the boot configuration data so the system can start normally. Which command should the technician run from the Windows Recovery Environment?

A.bootrec /rebuildbcd
B.bootrec /fixmbr
C.chkdsk /f
D.sfc /scannow
AnswerA

The /rebuildbcd switch scans all disks for Windows installations and lets the technician add missing entries to the Boot Configuration Data store. Because the error indicates that the boot manager cannot locate a valid BCD entry, rebuilding the BCD is the appropriate repair. This command directly addresses the missing or corrupted boot configuration that prevents Windows 11 from starting.

Why this answer

The "Bootmgr is missing" error means the boot manager cannot find a valid Boot Configuration Data entry for the Windows installation. The bootrec /rebuildbcd command scans for Windows installations and rebuilds the BCD store, directly resolving this issue. Other recovery commands address different problems such as MBR corruption, system file damage, or disk errors, and would not restore the missing boot entry.

Exam trap

The trap here is assuming that any bootrec switch will fix any boot error, when each switch targets a specific boot component and only /rebuildbcd rebuilds the BCD store.

471
MCQeasy

A user reports that their Windows 11 laptop display appears very dim even at the highest brightness setting. The technician suspects that the display adapter driver may be causing the issue. Which tool should the technician use to verify the driver version and check for driver errors?

A.Task Manager
B.Device Manager
C.Disk Management
D.System Configuration
AnswerB

Device Manager lists all hardware devices and their drivers, allowing the technician to view driver versions, update drivers, and check for error codes. By expanding Display adapters, the technician can see the current driver and any warning icons that indicate problems. This directly addresses the need to verify the driver version and identify driver-related errors causing the dim display.

Why this answer

Device Manager is the Windows tool that provides a centralized view of hardware devices and their drivers. It allows the technician to check the display adapter's driver version, update it, and see error codes that might explain the dim display. Task Manager, Disk Management, and System Configuration serve different purposes and do not offer driver-level diagnostics for hardware devices.

Exam trap

The trap here is assuming that any system utility can inspect drivers, when only Device Manager provides detailed driver version and error information for hardware devices.

472
MCQmedium

A technician is configuring a kiosk computer that will be used by the public to access a specific website. The technician wants to prevent users from navigating to other sites or changing browser settings. Which browser feature should be enabled?

A.Enable private browsing mode.
B.Enable parental controls.
C.Enable kiosk mode.
D.Disable the address bar via group policy.
AnswerC

Enabling kiosk mode is the most appropriate solution for configuring a dedicated kiosk computer. This specialized operating mode locks down the device, typically running a single application in full-screen, preventing users from accessing the desktop, other applications, or system settings. It restricts navigation to only approved content within the designated application, effectively securing the system against unauthorized use and ensuring the intended user experience.

Why this answer

Kiosk mode is specifically designed to lock a browser or application into a single-purpose session, restricting navigation to only the allowed website and preventing users from changing browser settings, accessing the address bar, or opening new tabs. In Microsoft Edge, kiosk mode can be configured via assigned access or the --kiosk command-line flag, and it enforces a locked-down experience ideal for public terminals. This directly meets the requirement of preventing users from navigating elsewhere or altering configuration.

Exam trap

The trap is choosing 'disable the address bar via group policy' because it sounds like a direct technical control, but it is incomplete and easily bypassed; kiosk mode is the comprehensive, purpose-built solution.

How to eliminate wrong answers

Option A is wrong because private browsing (InPrivate) only prevents local history and cookie storage; it does not restrict navigation or lock down settings. Option B is wrong because parental controls filter content by age rating or blocklist but still allow navigation within allowed sites and do not prevent settings changes. Option D is wrong because disabling the address bar via Group Policy is a partial measure that can be bypassed (e.g., via keyboard shortcuts or developer tools) and does not provide the full lockdown that kiosk mode enforces.

473
MCQeasy

A company is considering moving its email system from an on-premises Exchange server to a cloud-based solution. Which cloud service model would best fit this migration?

A.IaaS (Infrastructure as a Service)
B.PaaS (Platform as a Service)
C.SaaS (Software as a Service)
D.DaaS (Desktop as a Service)
AnswerC

SaaS (Software as a Service) provides fully managed, ready-to-use software applications delivered over the internet on a subscription basis. With SaaS, the cloud provider manages all aspects of the application, including infrastructure, platform, and software maintenance, updates, and security. For an email system, this means the company simply consumes the email service, eliminating the need for any on-premises servers or management of the email application itself, making it the ideal choice for offloading email infrastructure.

Why this answer

SaaS (Software as a Service) is the correct model because it delivers fully functional email applications (e.g., Microsoft 365 Exchange Online) over the internet, eliminating the need for the company to manage the underlying infrastructure, platform, or software. The cloud provider handles all maintenance, updates, and availability, making it ideal for migrating an existing email system without re-architecting the application itself.

Exam trap

The trap here is that candidates often confuse PaaS with SaaS, thinking that 'platform' includes email services, but PaaS requires the customer to deploy and manage the application code, whereas SaaS provides the complete, ready-to-use application.

How to eliminate wrong answers

Option A is wrong because IaaS provides virtualized computing resources (VMs, storage, networking) but requires the company to still install, configure, and manage the Exchange server software and its operating system, which defeats the purpose of a simple migration. Option B is wrong because PaaS offers a development and deployment platform (e.g., runtime environment, database middleware) but does not include pre-built email applications; the company would need to develop or deploy its own email software on the platform. Option D is wrong because DaaS delivers virtual desktops to end-users, not email services; it is designed for remote desktop access, not for replacing an on-premises email server.

474
MCQhard

A user reports that their Windows 11 laptop's battery drains quickly even when idle. They have already checked for background apps and power-hungry processes. Which single Settings page can you use to generate a detailed battery usage report showing which apps and hardware have consumed the most power over the last 24 hours?

A.Settings > System > Power & battery > Battery saver
B.Settings > System > Power & battery > Battery usage
C.Control Panel > Power Options > Edit Plan Settings
D.Settings > Privacy & security > Diagnostics & feedback
AnswerB

The 'Battery usage' section within Windows 11's Power & battery settings is precisely where a user can find a detailed historical report of their laptop's battery consumption. This interface provides a graphical representation and a list breakdown of which applications, system components, and hardware (like the display) have consumed battery power over the last 24 hours or 7 days. This comprehensive data is invaluable for identifying power-hungry processes and diagnosing rapid battery drain.

Why this answer

The correct tool is 'Battery usage' under Settings > System > Power & battery. This page provides a graph and detailed list of app and hardware power consumption, which can help identify the cause of rapid drain.

475
MCQeasy

A small business owner reports that after upgrading their wireless router to a newer model, their older laptops running Windows 7 cannot connect to the Wi-Fi network. The new router is configured with WPA3-Personal. Which of the following is the most likely reason for the connectivity failure?

A.The router's SSID is hidden.
B.The laptops' wireless adapters do not support WPA3.
C.The router is broadcasting on a 5 GHz band only.
D.The laptops have incorrect DNS settings.
AnswerB

WPA3-Personal mandates SAE (Simultaneous Authentication of Equals), a handshake older wireless adapters lack firmware support for. Windows 7 laptops with legacy 802.11n chipsets cannot negotiate SAE, so association fails against the WPA3-only router. This directly satisfies the stem's constraint: the router was upgraded to WPA3-Personal, and the older hardware predates that standard.

Why this answer

WPA3-Personal is a newer wireless security protocol that requires hardware support in the wireless adapter. Older laptops running Windows 7 typically have legacy wireless adapters that only support WPA2 or earlier protocols. Since the router is configured to use WPA3 only, the laptops' adapters cannot negotiate a connection, resulting in failure.

Exam trap

CompTIA often tests the misconception that older Windows 7 laptops can connect to any Wi-Fi network as long as they have the password, but the trap here is that WPA3 requires both hardware and driver-level support, which legacy adapters lack.

How to eliminate wrong answers

Option A is wrong because a hidden SSID does not prevent connection; clients can still connect if they know the SSID and have compatible security settings. Option C is wrong because even if the router broadcasts only on 5 GHz, many older Windows 7 laptops support 5 GHz if they have dual-band adapters; the primary issue is the security protocol mismatch, not the frequency band. Option D is wrong because incorrect DNS settings would prevent name resolution but not the initial Wi-Fi association and authentication; the laptops cannot even connect to the network, indicating a lower-layer issue.

476
MCQeasy

A technician is called to a user's desk where the user has left a sticky note with their password taped to the monitor. The technician needs to document this in the ticket. Which of the following should the technician do FIRST?

A.Report the security violation according to the organization's incident response policy.
B.Ignore it because it is the user's personal workspace and not the technician's concern.
C.Remove the sticky note and discard it, then close the ticket as resolved.
D.Take a photo of the sticky note and post it in the team chat as a joke.
AnswerA

Leaving a password visible is a security violation that must be reported through the proper incident response channel. This ensures the organization can investigate, educate the user, and enforce policies. Documenting and reporting is the first step before taking any corrective action that might destroy evidence or overstep the technician's authority.

Why this answer

The correct action is to report the security violation according to policy. Passwords left in plain sight are a serious security risk that must be escalated through proper channels. This allows the organization to handle the situation consistently, educate the user, and prevent similar incidents.

Taking direct action like removing the note or sharing it could interfere with investigations or violate privacy.

Exam trap

The trap here is assuming the technician should immediately remove the note or handle it informally, rather than following the formal incident reporting procedure.

477
MCQeasy

While upgrading a workstation, you find that the old lithium-ion battery is swollen. What is the safest and most environmentally sound way to handle this battery?

A.Puncture the battery to release the pressure, then throw it in the trash.
B.Place it in a fireproof container and contact a hazardous waste disposal service.
C.Put it in a sealed plastic bag and put it in the regular recycling bin.
D.Freeze the battery to stop the swelling, then dispose of it in the trash.
AnswerB

A swollen lithium-ion cell risks thermal runaway and fire, so it must not be punctured, charged or binned normally. Sealing it in a fireproof container and routing it to a hazardous waste disposal service satisfies both the safety and environmental constraints.

Why this answer

A swollen lithium-ion battery indicates internal damage and potential thermal runaway risk. Placing it in a fireproof container and contacting hazardous waste disposal ensures safe containment and proper recycling, preventing fire hazards and environmental contamination from toxic electrolytes and heavy metals.

Exam trap

CompTIA A+ exams often test the misconception that damaged batteries can be safely disposed of in regular trash or recycling, when in fact they require special handling due to fire and environmental hazards.

How to eliminate wrong answers

Option A is wrong because puncturing a swollen lithium-ion battery can cause a short circuit, leading to fire or explosion, and throwing it in the trash violates environmental regulations. Option C is wrong because placing a damaged lithium-ion battery in a sealed plastic bag in regular recycling can cause fires at recycling facilities due to crushing or shorting, and it is not accepted in standard recycling streams. Option D is wrong because freezing does not stop chemical degradation or swelling, and disposing of it in the trash still poses fire and environmental risks.

478
MCQhard

A user reports that Windows automatically installs a generic driver for a new graphics card that causes display issues. You need to change Windows settings to prevent automatic driver downloads from Windows Update. Which Control Panel tool allows you to change this behavior?

A.Device Manager
B.System > Advanced system settings > Hardware > Device Installation Settings
C.Programs and Features > Turn Windows features on or off
D.Administrative Tools > Services
AnswerB

Device Installation Settings controls whether Windows Update may fetch manufacturer drivers and device metadata automatically. Selecting "No" stops generic driver packages being offered for new hardware, directly satisfying the requirement to prevent automatic driver downloads. This is the only Control Panel path exposing that Windows Update driver-supply policy, so it resolves the display issues caused by the unwanted generic graphics driver.

Why this answer

Windows provides Device Installation Settings under System > Advanced system settings > Hardware, where you can control whether Windows automatically downloads manufacturer apps and custom icons for devices. Changing this setting to 'No' prevents Windows Update from automatically installing drivers, allowing you to install the correct graphics driver manually. This is the Control Panel tool that governs automatic driver downloads.

Exam trap

220-1202 often tests the confusion between Device Manager (per-device driver management) and Device Installation Settings (global automatic driver download control), so candidates who pick A miss the global setting.

How to eliminate wrong answers

Option A is wrong because Device Manager allows you to update, roll back, or uninstall drivers for a specific device, but it does not globally disable automatic driver downloads from Windows Update. Option C is wrong because Programs and Features > Turn Windows features on or off is for enabling/disabling Windows components like .NET Framework or Hyper-V, not driver installation behavior. Option D is wrong because Administrative Tools > Services manages Windows services, not driver download policies.

479
MCQmedium

A user reports that their iPhone 13 is not receiving text messages from Android users, but iMessage conversations with other iPhone users work fine. After checking that the user is not blocked, which step should you take to resolve this issue?

A.Disable iMessage in Settings > Messages.
B.Reset Network Settings from General > Reset.
C.Toggle Airplane Mode on and off.
D.Sign out of iCloud and sign back in.
AnswerD

Signing out of iCloud affects many services but does not directly disable iMessage; the iMessage toggle is the specific control needed.

Why this answer

When an iPhone user cannot receive SMS/MMS from Android users but iMessage works with other iPhones, the issue is typically an iMessage registration conflict. The standard fix is to sign out of iCloud (or Apple ID) and sign back in, which re-registers the phone number with Apple's iMessage servers. Disabling iMessage would stop iMessage functionality entirely and is not the recommended resolution for this specific symptom.

Exam trap

CompTIA often tests the misconception that network-related issues (like SMS not working) must be fixed by resetting network settings or toggling Airplane Mode, when the actual root cause is an iMessage registration conflict with non-Apple senders.

How to eliminate wrong answers

Option B is wrong because resetting network settings clears Wi-Fi passwords, cellular settings, and VPN configurations, but does not address the core issue of iMessage routing SMS/MMS from Android senders. Option C is wrong because toggling Airplane Mode only refreshes the cellular connection temporarily; it does not disable iMessage or force SMS fallback for incoming messages from non-Apple devices. Option D is wrong because signing out of iCloud removes iMessage activation but also disables other iCloud services unnecessarily; the targeted fix is to disable iMessage specifically, not the entire iCloud account.

480
MCQeasy

A technician is configuring a new Windows 10 workstation for a remote employee who will handle sensitive customer data. Which security feature should be enabled to ensure that if the laptop is lost, the data remains protected?

A.Windows Defender Firewall
B.User Account Control (UAC)
C.BitLocker Drive Encryption
D.Windows Hello for Business
AnswerC

BitLocker Drive Encryption is a full-disk encryption feature integrated into Windows that encrypts the entire volume where the operating system and user data reside. It uses a cryptographic key, often stored in a Trusted Platform Module (TPM) chip or provided by the user, to protect all data at rest. This encryption renders the data unreadable and inaccessible without the correct decryption key, making it the ideal solution for protecting sensitive information if the workstation's drive is lost, stolen, or removed from the system.

Why this answer

BitLocker Drive Encryption (C) is the correct choice because it provides full-disk encryption using AES encryption algorithms, ensuring that if the laptop is lost or stolen, the sensitive customer data remains inaccessible without the recovery key or TPM authentication. This directly addresses the requirement to protect data at rest on a lost device.

Exam trap

CompTIA often tests the distinction between authentication/access control features (like UAC or Windows Hello) and data-at-rest encryption (BitLocker), leading candidates to choose a security feature that protects the system while running rather than protecting data when the device is physically compromised.

How to eliminate wrong answers

Option A is wrong because Windows Defender Firewall is a network security feature that monitors and controls incoming/outgoing traffic based on rules, but it does not encrypt data on the drive, so it cannot protect data if the laptop is physically lost. Option B is wrong because User Account Control (UAC) prompts for permission before allowing system-level changes to prevent unauthorized software from making modifications, but it does not encrypt the drive or protect data when the device is offline. Option D is wrong because Windows Hello for Business provides biometric or PIN-based authentication for user sign-in, but it does not encrypt the storage volume, so data remains readable if the drive is removed or the device is accessed via other means.

481
MCQmedium

A technician is troubleshooting why a smart card reader at a secure entrance fails intermittently. Users can sometimes enter, but other times the reader does not respond. What should the technician check first?

A.Update the smart card reader firmware
B.Replace the smart cards for all users
C.Check the cabling and connections to the reader
D.Reconfigure the access control software
AnswerC

Checking the cabling and connections to the reader is the most logical and effective first step for troubleshooting intermittent connectivity issues. Loose or damaged USB cables, network cables (for networked readers), or power connections can cause a device to repeatedly connect and disconnect. Verifying that all physical connections are secure and undamaged often resolves such sporadic problems quickly, aligning with fundamental hardware troubleshooting methodologies.

Why this answer

Intermittent failures in a smart card reader are most often caused by physical connection issues, such as loose or damaged cabling, rather than software or firmware problems. Checking cabling and connections is the first step in a structured troubleshooting approach because it addresses the most common and easily verifiable cause of intermittent behavior.

Exam trap

The 220-1202 exam often tests the principle of 'starting with the simplest and most likely cause' in troubleshooting scenarios, and the trap here is that candidates jump to firmware or software fixes without first verifying the physical layer.

How to eliminate wrong answers

Option A is wrong because updating firmware is a more advanced step that should only be attempted after verifying physical connections and power; firmware issues typically cause consistent failures, not intermittent ones. Option B is wrong because replacing all smart cards is an expensive and disruptive action that assumes a widespread card failure, which is unlikely when the reader itself is unresponsive and the problem is intermittent. Option D is wrong because reconfiguring access control software would not resolve a hardware-level intermittent connection problem; software misconfiguration usually results in consistent access denials or errors, not random unresponsiveness.

482
MCQeasy

A user reports that they cannot execute a custom shell script they created in their home directory. The script is owned by the user and has permissions set to 644. Which command should be used to allow the owner to execute the script?

A.chmod 755 script.sh
B.chmod u+x script.sh
C.chmod 644 script.sh
D.chown user:user script.sh
AnswerB

The command "chmod u+x script.sh" is the most appropriate solution as it precisely adds execute permission solely for the file's owner (user). The 'u' specifies the user (owner), and '+x' adds the execute permission without altering any existing read or write permissions for the owner, group, or others. This ensures the user can execute their script while maintaining the existing, potentially restrictive, permissions for other user categories, adhering to the principle of least privilege.

Why this answer

The script has permissions 644, which means the owner has read/write (6) but not execute. To allow the owner to execute the script, you need to add the execute permission for the owner. The command `chmod u+x script.sh` adds execute permission for the user (owner) only, which is the correct and minimal change to resolve the issue.

Exam trap

The trap here is that candidates often choose `chmod 755` (Option A) because it is a common permission set for scripts, but the question specifically asks to allow only the owner to execute, making `chmod u+x` the precise and correct answer.

How to eliminate wrong answers

Option A is wrong because `chmod 755 script.sh` sets permissions to rwxr-xr-x, which grants execute to the owner, group, and others — this is overly permissive and not the minimal fix required. Option C is wrong because `chmod 644 script.sh` sets permissions to rw-r--r--, which is the current state and does not add execute permission, so it would not solve the problem. Option D is wrong because `chown user:user script.sh` changes the owner and group of the file, but the script is already owned by the user; the issue is about permissions, not ownership.

483
MCQeasy

A customer reports that their Windows 10 computer is running very slowly, and they see frequent pop-up ads even when no browser is open. They also notice a new toolbar in their browser that they did not install. What type of malware is most likely causing these symptoms?

A.Ransomware
B.Adware
C.Virus
D.Worm
AnswerB

Adware is a type of software that automatically displays or downloads advertising material, often in the form of pop-up windows, banner ads, or redirects, after it is installed on a computer. It frequently bundles with free software and can install unwanted browser toolbars, modify browser settings, and track user browsing habits to serve targeted advertisements. These symptoms precisely match the customer's report of pop-ups and toolbars, as adware's main purpose is to generate revenue through advertising.

Why this answer

Adware is the most likely malware type because the symptoms—frequent pop-up ads even when no browser is open, and a new browser toolbar—are classic indicators of adware. Adware is designed to display unwanted advertisements and often bundles additional toolbars or browser extensions without user consent. It can run in the background and inject ads into various applications.

Exam trap

220-1202 often tests symptom-based malware identification; candidates might confuse adware with viruses or worms, but the key differentiator is the presence of unwanted advertisements and toolbars without file encryption or network self-propagation.

How to eliminate wrong answers

Option A is wrong because ransomware encrypts files and demands payment, which is not described; the user's files are not reported as encrypted or inaccessible. Option C is wrong because a virus typically requires user action to spread and may cause a variety of symptoms, but the specific combination of pop-up ads and unwanted toolbar is more characteristic of adware. Option D is wrong because a worm self-propagates across networks and consumes resources, but it does not typically manifest as pop-up ads or browser toolbars; the symptoms point to adware.

484
MCQhard

A user's iPhone is running iOS 16 and they cannot update to the latest iOS 17 because the 'Software Update' section in Settings shows 'Unable to Check for Update'. The device is connected to Wi-Fi and has sufficient storage. Which advanced troubleshooting step should you take to resolve this update issue?

A.Reset All Settings from General > Reset.
B.Restore the iPhone using an iCloud backup.
C.Use a computer with Finder (macOS) or iTunes (Windows) to download and install the update.
D.Disable iCloud Private Relay in iCloud settings.
AnswerC

When over-the-air updates fail despite adequate Wi-Fi and storage, installing via Finder or iTunes forces a full firmware download over USB, bypassing the corrupted update cache or failed OTA check. This resolves the 'Unable to Check for Update' error.

Why this answer

When an iPhone displays 'Unable to Check for Update' despite having Wi-Fi and storage, the issue often lies with the device's inability to contact Apple's update servers directly due to network restrictions or corrupted cached update data. Using a computer with Finder (macOS) or iTunes (Windows) bypasses the iPhone's over-the-air (OTA) update mechanism by downloading the full IPSW firmware directly from Apple's servers and installing it via USB, which is a standard advanced troubleshooting step for OTA update failures.

Exam trap

CompTIA often tests the misconception that 'Reset All Settings' or disabling network features like Private Relay will fix OTA update failures, when in fact the correct advanced step is to use a computer-based restore to bypass the device's broken OTA mechanism.

How to eliminate wrong answers

Option A is wrong because 'Reset All Settings' clears user preferences like Wi-Fi passwords and wallpapers but does not address the underlying communication failure with Apple's update servers or corrupted OTA update assets; it is a general troubleshooting step, not specific to update check failures. Option B is wrong because restoring from an iCloud backup would reapply the same iOS version and settings, potentially reintroducing the same issue, and does not provide a method to install a newer iOS version; it is a data recovery step, not an update solution. Option D is wrong because disabling iCloud Private Relay, while it can affect certain network connections, is not a standard advanced troubleshooting step for OTA update failures; the error 'Unable to Check for Update' typically stems from DNS resolution issues, proxy conflicts, or corrupted update caches, not specifically from Private Relay, and Apple's update servers are generally reachable through Private Relay.

485
MCQhard

During a routine check, a technician finds that a user's Windows 10 computer has an outdated antivirus that hasn't updated in 3 months. The user claims they never saw any update prompts. What is the most likely reason and the appropriate remediation?

A.The antivirus subscription has expired; renew it
B.The Windows Update service is disabled; re-enable it and set to automatic
C.The user has manually set the antivirus to manual update mode
D.The computer is infected with a virus that blocks updates
AnswerA

While possible, the question states no prompts were seen; a disabled update service is a common cause that also explains the lack of prompts.

Why this answer

The most likely reason the antivirus hasn't updated in 3 months, with no prompts seen by the user, is that its subscription/license has expired. When a subscription lapses, the product typically stops receiving definition updates and may suppress or stop showing update prompts. The appropriate remediation is to renew the subscription or replace the antivirus with a supported solution.

Note: Windows Defender does rely on Windows Update for definitions, but the scenario describes a separate antivirus product, which updates through its own update mechanism, not the Windows Update service (wuauserv).

Exam trap

CompTIA A+ often tests the misconception that a disabled Windows Update service is the cause of all antivirus update failures. In reality, third-party antivirus products update through their own services and servers; a disabled wuauserv primarily affects Windows Defender and OS updates. For a third-party AV that has stopped updating with no prompts, suspect an expired subscription/license first.

How to eliminate wrong answers

Option A is wrong because an expired subscription would typically generate visible warnings or prompts within the antivirus interface, not a complete absence of update prompts for 3 months. Option C is wrong because manual update mode would still show update prompts or notifications when updates are available, just requiring user action to install; the user would see prompts. Option D is wrong because while a virus could theoretically block updates, it is far less common than a disabled Windows Update service, and the scenario describes a routine check with no other symptoms of infection.

486
MCQmedium

A user complains that their Android phone's battery drains quickly after installing a new weather app. The phone is warm to the touch even when idle. What should you do to resolve this?

A.Replace the battery immediately.
B.Check battery usage in Settings to see which app is consuming power.
C.Perform a factory reset to remove all apps.
D.Update the phone's operating system to the latest version.
AnswerB

Checking battery usage in Android's Settings provides granular power consumption data, allowing technicians to pinpoint which applications or system processes are consuming the most power. This diagnostic step directly identifies resource-intensive apps, such as a problematic weather application, enabling targeted action like force-stopping, uninstalling, or adjusting app permissions to resolve the drain efficiently.

Why this answer

The symptoms—rapid battery drain and a warm phone even when idle—strongly indicate a rogue app consuming excessive CPU or network resources in the background. Checking battery usage in Settings (typically under Battery > Battery Usage or similar) will identify the exact app responsible, allowing you to force-stop, uninstall, or restrict its background activity. This is the standard first diagnostic step for battery issues on Android, as it provides concrete data rather than guessing.

Exam trap

220-1202 often tests the tendency to jump to drastic solutions like factory reset or battery replacement when a simple diagnostic step (checking battery usage) is the correct first action.

How to eliminate wrong answers

Option A is wrong because replacing the battery is a hardware solution for a software problem; the battery is likely fine, and the drain is caused by an app, so replacement would not fix the issue. Option C is wrong because a factory reset is a drastic, last-resort measure that erases all user data and settings; it is unnecessary when a simple diagnostic can pinpoint the culprit. Option D is wrong because updating the OS is unlikely to resolve a problem caused by a specific third-party app, and it does not address the root cause.

487
MCQeasy

A customer complains that their Windows 11 laptop frequently freezes after waking from sleep. You suspect a driver issue and need to view detailed hardware and driver information to diagnose the problem. Which administrative tool should you open first?

A.Disk Management
B.System Configuration (msconfig)
C.Device Manager
D.Event Viewer
AnswerC

Device Manager exposes each installed device with its driver version, provider, and status, and flags problem devices with warning icons. This lets you identify and roll back or update the faulty driver causing the post-sleep freezes.

Why this answer

Device Manager is the correct tool because it provides a centralized view of all hardware components and their associated drivers. You can expand categories like 'System devices' or 'Batteries' to check for driver conflicts, outdated drivers, or power management settings that could cause freezing after sleep. It also allows you to update, roll back, or disable drivers directly, which is essential for diagnosing wake-from-sleep issues.

Exam trap

CompTIA often tests the distinction between Event Viewer (for logs) and Device Manager (for live driver/hardware status), trapping candidates who think logs are the first step when the question asks for viewing detailed hardware and driver information.

How to eliminate wrong answers

Option A is wrong because Disk Management is used for managing disk partitions, volumes, and file systems, not for viewing hardware or driver details. Option B is wrong because System Configuration (msconfig) controls startup programs, boot options, and services, but does not display hardware or driver information. Option D is wrong because Event Viewer logs system events and errors, which can help after a freeze occurs, but it does not show detailed hardware and driver information directly; Device Manager is the first tool to inspect driver status.

488
MCQeasy

A small business wants to ensure that only authorized employees can access the file server from their laptops. Each laptop has a unique hardware ID. Which logical security method should be implemented to enforce this restriction?

A.Require a complex password for the file server share.
B.Enable MAC address filtering on the network switch or router.
C.Install a host-based firewall on each laptop.
D.Disable the guest account on the file server.
AnswerB

Enabling MAC address filtering on a network switch or router directly addresses the requirement to ensure only authorized laptops can access resources. This method operates at Layer 2 (Data Link Layer) of the OSI model, allowing the network device to inspect the Media Access Control (MAC) address of connecting devices. By creating a whitelist of approved MAC addresses, the switch or router will only permit network connectivity for those specific, authorized laptops, effectively blocking all others.

Why this answer

MAC address filtering on the network switch or router allows the administrator to create an access control list (ACL) that permits only specific hardware MAC addresses to connect to the network. Since each laptop has a unique hardware ID (MAC address), this method directly ties network access to the authorized devices, ensuring only those laptops can reach the file server. This is a logical security control implemented at Layer 2 of the OSI model.

Exam trap

The trap here is that candidates often confuse user authentication (passwords) with device authentication (MAC filtering), assuming that a strong password alone can restrict access to specific hardware, when in fact passwords only verify the user, not the device.

How to eliminate wrong answers

Option A is wrong because requiring a complex password for the file server share authenticates the user, not the device; any user with the password could log in from an unauthorized laptop. Option C is wrong because a host-based firewall on each laptop controls inbound/outbound traffic on that laptop but does not restrict which laptops are allowed to access the file server from the network perspective. Option D is wrong because disabling the guest account on the file server prevents anonymous access but does not enforce device-specific authorization; authorized users could still connect from any laptop.

489
MCQeasy

A user reports that their computer is infected with a virus and they have been trying to remove it using a free online scanner, but the problem persists. The technician suspects the malware may have disabled the antivirus software. Which safe mode should the technician use to run a full system scan?

A.Safe Mode
B.Safe Mode with Command Prompt
C.Safe Mode with Networking
D.Last Known Good Configuration
AnswerC

Safe Mode with Networking is the optimal choice for malware removal because it loads Windows with a minimal set of drivers and services, effectively preventing most malware from loading and executing. Crucially, this mode enables network connectivity, allowing the technician to download the latest antivirus definition updates, specialized malware removal tools, and access online resources for threat analysis. This combination ensures a clean, isolated environment for effective remediation while providing necessary external resources.

Why this answer

Safe Mode with Networking (C) is correct because it loads only essential drivers and services, including network components, which allows the technician to run a full system scan while the malware is likely inactive. Since the malware may have disabled the antivirus software in normal mode, booting into Safe Mode with Networking ensures the antivirus can run and still access the internet for signature updates or cloud-based scanning.

Exam trap

CompTIA often tests the distinction between Safe Mode and Safe Mode with Networking, where candidates mistakenly choose Safe Mode without realizing that antivirus software often requires network access to download updated signatures for effective malware removal.

How to eliminate wrong answers

Option A is wrong because Safe Mode does not load network drivers, which prevents the antivirus from downloading updated virus definitions or connecting to cloud-based scanning services, potentially leaving the scan incomplete. Option B is wrong because Safe Mode with Command Prompt provides a command-line interface but still lacks networking, so it offers no advantage over Safe Mode for running a full system scan with updated definitions. Option D is wrong because Last Known Good Configuration loads the last set of registry and driver settings that worked, but it does not prevent malware from loading, as malware often persists in user profiles or startup locations unaffected by this option.

490
MCQmedium

A technician is cleaning a computer that has been infected with a rootkit. After running a standard antivirus scan, the malware is still detected on reboot. Which step should the technician take next to ensure complete removal?

A.Perform a clean installation of Windows.
B.Boot from a rescue disk and run a malware scan.
C.Disable System Restore and run the antivirus again.
D.Run the antivirus in Safe Mode.
AnswerB

Booting from a rescue disk, also known as a bootable antivirus or recovery environment, loads a clean, trusted operating system directly from external media (USB or CD/DVD). This bypasses any malware, especially rootkits, that might be deeply embedded within the compromised installed operating system and actively hiding its presence or interfering with security software. Operating from an uninfected environment allows the malware scanner to access and remove malicious files and registry entries that would otherwise be protected or invisible.

Why this answer

Rootkits are designed to hide from the operating system and standard antivirus tools by intercepting system calls and loading before the OS security components. Booting from a rescue disk (e.g., a Linux live CD or a dedicated antivirus rescue ISO) bypasses the infected OS entirely, allowing the scanner to access the file system without the rootkit actively masking its presence. This ensures the malware cannot interfere with the scan, enabling complete detection and removal.

Exam trap

The trap here is that candidates assume Safe Mode provides a clean environment for malware removal, but rootkits specifically target kernel-level persistence that persists even in Safe Mode, making a boot-time rescue disk the only reliable method.

How to eliminate wrong answers

Option A is wrong because a clean installation of Windows is a last-resort step that is unnecessarily drastic when a targeted boot-time scan can remove the rootkit without data loss. Option C is wrong because disabling System Restore only removes restore points that might contain malware, but it does not address the rootkit's ability to hide from the antivirus while the OS is running. Option D is wrong because Safe Mode still loads essential Windows drivers and services that a rootkit can hook into, allowing it to remain active and evade detection during the scan.

491
MCQhard

A technician is tasked with securing a legacy web application that only supports HTTP, not HTTPS. The application is critical for internal operations but must be accessible remotely. What is the best way to secure the traffic without modifying the application?

A.Install a self-signed SSL certificate on the server.
B.Use a VPN to access the internal network.
C.Enable HTTP Strict Transport Security (HSTS) on the server.
D.Configure the browser to use a proxy server.
AnswerB

A Virtual Private Network (VPN) establishes an encrypted tunnel between the client and the internal network. All traffic, including unencrypted HTTP requests to the legacy web application, traverses this secure tunnel. This effectively encapsulates and protects the HTTP communication from external eavesdropping and tampering, providing confidentiality and integrity for the data without requiring any modifications to the legacy application or server configuration.

Why this answer

A VPN creates an encrypted tunnel between the remote user and the internal network, securing all HTTP traffic without any modification to the legacy application. Since the application only supports HTTP, it cannot serve HTTPS natively, and a VPN provides transport-layer encryption (e.g., IPsec or TLS-based VPN) that protects data in transit over untrusted networks.

Exam trap

A common misconception is that installing a certificate or enabling a security header can magically convert an HTTP-only application to HTTPS, when in fact the application must natively support TLS termination to use those features.

How to eliminate wrong answers

Option A is wrong because installing a self-signed SSL certificate on the server does not enable HTTPS; the application itself must support HTTPS to use the certificate, and a legacy HTTP-only application cannot serve HTTPS without code changes. Option C is wrong because HSTS is an HTTP response header that enforces HTTPS connections from browsers, but it requires the server to already support HTTPS, which this legacy application does not. Option D is wrong because configuring the browser to use a proxy server only redirects traffic through an intermediary; it does not encrypt the traffic between the client and the proxy, leaving the HTTP data exposed on the network.

492
MCQmedium

A company uses a private cloud for its development environment. A developer complains that they cannot deploy a new application because the cloud management portal shows a 'resource quota exceeded' error. The technician checks the cluster and finds that CPU and memory usage are below 50%. What is the most likely cause of the error?

A.The hypervisor is in maintenance mode
B.The storage pool is full
C.The developer's resource allocation quota has been reached
D.The virtual switch is not configured for the developer's VLAN
AnswerC

CPU and memory sitting below 50% rules out genuine cluster exhaustion, so the portal error stems from a per-user or per-project allocation limit. The developer's assigned quota has been consumed, and raising that quota resolves the deployment failure.

Why this answer

The error 'resource quota exceeded' in a cloud management portal is a quota-based restriction, not a physical capacity issue. Since CPU and memory usage are below 50%, the cluster has available resources, but the developer's individual or project-level allocation quota has been reached. This is a common multi-tenant cloud control mechanism to prevent any single user from consuming all resources.

Exam trap

The CompTIA A+ exam often tests the distinction between physical resource exhaustion (e.g., full storage, high CPU) and administrative quota limits, trapping candidates who assume low cluster utilization means no quota issue exists.

How to eliminate wrong answers

Option A is wrong because if the hypervisor were in maintenance mode, VMs would be migrated or unable to start, but the error would typically be 'host unavailable' or 'maintenance in progress', not a resource quota exceeded message. Option B is wrong because the error specifically mentions 'resource quota exceeded', not 'storage full'; a full storage pool would cause write failures or provisioning errors, not a quota limit notification. Option D is wrong because a misconfigured virtual switch or VLAN would result in network connectivity issues (e.g., 'network not reachable'), not a resource quota error in the cloud portal.

493
MCQhard

A security analyst discovers that an attacker has been using a compromised VPN account to access the corporate network. The account belongs to a former employee who was terminated two weeks ago. Which of the following should the analyst do immediately to prevent further unauthorized access?

A.Review the VPN logs to determine the extent of the breach
B.Disable the former employee's VPN account
C.Change the VPN server's shared secret
D.Notify the former employee about the security incident
AnswerB

Disabling the account immediately revokes authentication, terminating the attacker's active VPN session and blocking reconnection. Since the former employee was terminated two weeks ago, the account should already have been deprovisioned; disabling satisfies the stem's requirement to prevent further unauthorised access without disrupting other users.

Why this answer

Disabling the former employee's VPN account immediately stops the attacker from using the compromised credentials to access the corporate network. This is the most direct and effective action to prevent further unauthorized access, as the account is the vector being exploited. Other steps like log review or server reconfiguration are important but secondary to cutting off the active attack path.

Exam trap

The trap here is that candidates often choose to review logs first (Option A) to understand the breach, but the correct priority is immediate containment over forensic analysis in an active security incident.

How to eliminate wrong answers

Option A is wrong because reviewing VPN logs is a forensic step that does not stop ongoing unauthorized access; it should be performed after the immediate threat is neutralized. Option C is wrong because changing the VPN server's shared secret (a pre-shared key used for IPsec or L2TP) would not affect an attacker using a valid user account, as the shared secret is a server-level authentication parameter, not tied to individual user credentials. Option D is wrong because notifying the former employee is irrelevant and potentially dangerous; the account was compromised, and the former employee may be the attacker or unaware, but notification does not prevent further access and could tip off the attacker.

494
MCQhard

A technician needs to configure a Windows 10 computer to use a static IP address of 192.168.1.100 with subnet mask 255.255.255.0 and default gateway 192.168.1.1. Which command-line tool and syntax should be used?

A.netsh interface ip set address "Ethernet" static 192.168.1.100 255.255.255.0 192.168.1.1 1
B.ipconfig /setaddress 192.168.1.100
C.netstat -r
D.ping 192.168.1.1
AnswerA

netsh sets the address statically through the interface's IP configuration, and the trailing 1 specifies the default gateway metric. The quoted interface name, static address, subnet mask and gateway must appear in that order for the command to apply correctly.

Why this answer

The `netsh interface ip set address` command is the correct Windows command-line tool to configure a static IP address, subnet mask, and default gateway. The syntax is `netsh interface ip set address "<interface name>" static <IP> <subnet mask> <gateway> <metric>`. On Windows 10 the default wired adapter is usually named "Ethernet" (not the legacy "Local Area Connection"), so the interface name must match the actual adapter, which can be confirmed with `netsh interface show interface`.

The metric value (1) is optional and sets the interface metric.

Exam trap

Candidates may confuse `ipconfig` (a display-only tool) with a configuration tool, or assume `netstat` or `ping` can set IP addresses, when only `netsh` provides the correct static IP assignment syntax. Also watch the interface name: on Windows 10 it is typically "Ethernet", not the legacy "Local Area Connection".

How to eliminate wrong answers

Option B is wrong because `ipconfig` is used to display IP configuration, not to set it; there is no `/setaddress` parameter in `ipconfig`. Option C is wrong because `netstat -r` displays the routing table, not configures IP settings. Option D is wrong because `ping 192.168.1.1` tests connectivity to the gateway but does not configure the IP address.

495
MCQmedium

A technician is setting up a remote desktop solution for a small business with five employees who need to access their office PCs from home. The office uses a dynamic public IP address. Which of the following should the technician configure to ensure reliable remote access without requiring users to remember a changing IP?

A.Set up port forwarding on the router
B.Configure a dynamic DNS (DDNS) service
C.Assign each employee a static IP address on the office network
D.Use a VPN with a static IP assigned by the ISP
AnswerB

Dynamic DNS maps a fixed hostname to the office's changing public IP, updating the record automatically when the ISP reassigns it. Users then connect via the stable name, satisfying the requirement that they need not track a changing address.

Why this answer

A dynamic DNS (DDNS) service maps a fixed hostname (e.g., remote.office.com) to the office’s changing public IP address. The technician configures the router or a client to update the DDNS provider automatically whenever the ISP-assigned IP changes, so employees can always connect using the same hostname without tracking the current IP.

Exam trap

The A+ exam often tests the distinction between internal static IPs (which are irrelevant for public access) and external static IPs (which require ISP involvement), leading candidates to mistakenly choose assigning static IPs on the office network as a solution for a dynamic public IP.

How to eliminate wrong answers

Option A is wrong because port forwarding alone does not solve the problem of a changing public IP; it only directs incoming traffic to a specific internal device, but users would still need to know the current IP address. Option C is wrong because assigning static IPs to employees on the office LAN does not affect the public IP address that remote users connect to; the public IP remains dynamic and still changes. Option D is wrong because a VPN with a static IP assigned by the ISP would require the business to purchase a static IP from the ISP, which is not mentioned in the scenario and is an additional cost; the question asks for a solution that works with the existing dynamic IP.

496
MCQmedium

After deploying a group policy update, several users report that their mapped network drives are missing. You need to force an immediate refresh of group policy settings on a remote workstation without rebooting. Which command should you run?

A.net use
B.gpresult
C.gpupdate /force
D.nslookup
AnswerC

This command forces an immediate policy refresh, applying the new drive mappings without reboot.

Why this answer

To force an immediate Group Policy refresh on a remote workstation without rebooting, you must target the remote computer. Running `gpupdate /force` alone only refreshes policy on the local machine. The correct approach is `gpupdate /force /target:computer` (or `Invoke-GPUpdate -Computer <name> -Force`), which forces reapplication of all Group Policy settings, including drive maps, on the specified remote workstation without requiring a reboot.

The `/force` switch re-applies all policies even if they have not changed, which is necessary when users report missing mapped drives after a policy update.

Exam trap

The trap is that candidates confuse `gpupdate` with `gpresult`, thinking that viewing policy results will also apply the changes, but `gpresult` only displays the current applied policy state without initiating a refresh. A second trap is forgetting that `gpupdate /force` by itself is local-only; refreshing a remote workstation requires the `/target:computer` parameter (or a remote-invocation method).

How to eliminate wrong answers

Option A is wrong because `net use` is used to manually connect or disconnect network shares, not to refresh Group Policy settings. Option B is wrong because `gpresult` displays the Resultant Set of Policy (RSoP) for a user or computer, but it does not apply or refresh policies. Option D is wrong because `nslookup` is a DNS query tool used to resolve hostnames to IP addresses, and it has no role in Group Policy processing.

497
MCQmedium

A company deploys a new remote access solution using a VPN concentrator. After setup, users report that they can connect to the VPN but cannot access internal file servers. Other internal resources like email are accessible. Which of the following is the most likely cause?

A.The VPN client is using an incorrect DNS server
B.The file server is not on the same VLAN as the VPN concentrator
C.The VPN concentrator lacks a route to the file server's subnet
D.The users do not have permission to log on locally to the file server
AnswerC

For VPN clients to access resources on an internal network subnet, the VPN concentrator must have a defined route specifying how to reach that particular subnet. If the concentrator lacks a route to the file server's subnet, it will not know where to forward traffic destined for the file server's IP address. Consequently, packets from the VPN clients will be dropped or sent to an incorrect destination, preventing any successful connection to the file server. This is a fundamental layer 3 networking requirement.

Why this answer

The VPN concentrator must have a route to the file server's subnet to forward traffic from VPN clients. Without this route, packets destined for the file server are dropped, while other resources (like email) remain accessible if their subnets are reachable. This is a classic routing issue in remote access VPN deployments.

Exam trap

CompTIA often tests the misconception that VLAN placement or local permissions are the root cause, when the actual issue is a missing route on the VPN concentrator to the specific subnet.

How to eliminate wrong answers

Option A is wrong because an incorrect DNS server would cause name resolution failures for all internal resources, not selectively block file servers while allowing email access. Option B is wrong because VLAN membership is irrelevant for VPN concentrator routing; the concentrator can route to any subnet regardless of VLAN if a route exists. Option D is wrong because local logon permissions are not required for network file access; file server permissions are based on network shares and user credentials, not local logon rights.

498
MCQmedium

A company’s change management policy requires all changes to be approved by the Change Advisory Board (CAB) before implementation. A technician applies an emergency security patch to a critical server without CAB approval because the vulnerability is being actively exploited. What should the technician do after applying the patch?

A.Wait for the next CAB meeting to report the change.
B.Document the change and submit an emergency change request for retroactive approval.
C.Revert the patch and wait for CAB approval.
D.Delete the change log entry to avoid accountability.
AnswerB

For emergency changes, the immediate priority is to implement the necessary fix to restore service or mitigate a critical threat. Following this, the correct procedure mandates thoroughly documenting the change, including its rationale, steps taken, and impact, and then promptly submitting an emergency change request to the Change Advisory Board (CAB) for retroactive review and formal approval. This ensures accountability, maintains the integrity of the change management process, and provides a crucial audit trail.

Why this answer

In change management, emergency changes are allowed when there is an urgent security or operational need, but they must be documented and submitted for retroactive approval by the CAB. The technician should document the change and submit an emergency change request so the change is recorded and reviewed after the fact. This maintains accountability while addressing the active exploit.

Exam trap

220-1202 often tests whether candidates understand that emergency changes still require documentation and retroactive approval, so the trap is choosing to wait for the next CAB meeting or to revert the change, rather than following the emergency change process.

How to eliminate wrong answers

Option A is wrong because waiting for the next CAB meeting delays reporting and violates the principle that emergency changes must be documented promptly, not deferred. Option C is wrong because reverting the patch would leave the critical server vulnerable to an actively exploited vulnerability, which is unacceptable. Option D is wrong because deleting the change log entry is unethical and violates audit and compliance requirements; all changes must be traceable.

499
MCQhard

A technician is troubleshooting an iPhone that repeatedly prompts for the Apple ID password even after entering it correctly. The device is not connected to any corporate MDM. What is the most likely cause?

A.The device is jailbroken and has a tweak interfering with authentication.
B.The Apple ID password was changed recently and not synced to all services.
C.iCloud Keychain is out of sync and needs to be reset by signing out of iCloud and back in.
D.The device has a hardware fault in the secure enclave.
AnswerC

iCloud Keychain securely stores and synchronizes various credentials, including app passwords, Wi-Fi passwords, and authentication tokens across Apple devices. When this keychain becomes desynchronized or corrupted, the device may repeatedly fail to validate authentication requests for iCloud services, leading to persistent password prompts. Signing out and then back into iCloud forces a complete re-authentication and re-establishment of these secure tokens and keychain data, effectively resolving the synchronization issue.

Why this answer

Repeated Apple ID password prompts, even after correct entry, are typically caused by an iCloud Keychain sync conflict. When iCloud Keychain becomes out of sync—often after a password change or device restore—the authentication token chain breaks, forcing the device to re-request the password. Signing out of iCloud and back in resets the local Keychain state and re-establishes a trusted sync relationship with Apple's servers.

Exam trap

CompTIA often tests the misconception that repeated password prompts are always due to a password change or incorrect entry, when in fact iCloud Keychain sync issues are a common cause that requires a sign-out/sign-in cycle to resolve.

How to eliminate wrong answers

Option A is wrong because a jailbroken device with a tweak interfering with authentication would likely cause broader instability or specific app crashes, not a consistent, system-level Apple ID password prompt that persists after correct entry. Option B is wrong because changing the Apple ID password and not syncing to all services would cause authentication failures on services using the old password, not repeated prompts after entering the correct password. Option D is wrong because a hardware fault in the Secure Enclave would manifest as inability to use Touch ID/Face ID or perform cryptographic operations, not as a repeated password prompt that works when entered.

500
MCQeasy

During a software deployment, a technician needs to ensure that a new web application can run in a sandboxed environment to prevent it from accessing other system resources. Which browser feature should be configured?

A.Enable pop-up blocker.
B.Enable private browsing mode.
C.Enable browser sandboxing.
D.Disable JavaScript.
AnswerC

Enabling browser sandboxing is the correct approach because it creates a highly controlled and isolated environment for web applications or specific browser processes. This isolation mechanism restricts the application's access to critical system resources, such as the file system, network interfaces, and memory outside its designated space. By confining the application, sandboxing prevents potential malicious code from affecting the host operating system or other browser tabs, thereby ensuring secure software deployment.

Why this answer

Browser sandboxing is a security mechanism that isolates the web application's processes from the rest of the system, preventing it from accessing other system resources such as the file system, registry, or other processes. This is commonly implemented in modern browsers (e.g., Chrome's multi-process architecture with a sandbox layer) to contain potential exploits from a compromised web application.

Exam trap

CompTIA often tests the distinction between privacy features (like private browsing) and security features (like sandboxing), leading candidates to confuse 'preventing local storage of data' with 'preventing system resource access.'

How to eliminate wrong answers

Option A is wrong because enabling a pop-up blocker only prevents unwanted pop-up windows from appearing; it does not restrict the web application's access to system resources or provide any sandboxing. Option B is wrong because private browsing mode (e.g., Incognito in Chrome) only prevents the browser from storing local history, cookies, and form data; it does not isolate the application from the underlying operating system or other system resources. Option D is wrong because disabling JavaScript would break most modern web applications, but it does not create a sandboxed environment; it merely removes a scripting capability, leaving other attack vectors (e.g., HTML, CSS, or plugin exploits) uncontained.

501
MCQmedium

During a network upgrade, a technician needs to run new Ethernet cables through a drop ceiling. What is the most important safety precaution to take?

A.Wear a hard hat to protect against head injuries.
B.Use a non-contact voltage tester to check for live wires.
C.Ensure the area is well-ventilated.
D.Wear anti-static gloves to prevent ESD.
AnswerB

Using a non-contact voltage tester (NCVT) is the most critical safety precaution because it directly addresses the primary hazard of electrocution when working in areas with existing electrical infrastructure. This device allows a technician to detect the presence of alternating current (AC) voltage in wires, conduits, or outlets without making physical contact, thereby identifying energized circuits before any cable installation or manipulation occurs. Verifying the absence of live wires in the cable path is paramount to prevent severe injury or fatality.

Why this answer

The most important safety precaution when running cables through a drop ceiling is to use a non-contact voltage tester to check for live wires. Drop ceilings often conceal electrical wiring, and accidentally cutting or damaging a live wire can cause electrocution, fire, or equipment damage. A non-contact voltage tester allows the technician to detect the presence of AC voltage without making physical contact, ensuring the area is safe before handling cables.

Exam trap

CompTIA often tests the distinction between general safety equipment (like hard hats) and task-specific electrical safety tools, so the trap here is that candidates may choose a hard hat as a 'common sense' safety item, overlooking the more critical step of verifying that no live electrical wires are present in the drop ceiling.

How to eliminate wrong answers

Option A is wrong because while a hard hat provides head protection against accidental bumps or falling objects, it is not the most critical precaution when working near electrical hazards in a drop ceiling; the primary risk is electrical shock, not head injury. Option C is wrong because ventilation is not a primary concern when running Ethernet cables through a drop ceiling; the main hazards are electrical and physical, not airborne contaminants or lack of oxygen. Option D is wrong because anti-static gloves are used to prevent electrostatic discharge (ESD) damage to sensitive electronic components, but they do not protect against the immediate life-threatening risk of contact with live electrical wires in a drop ceiling environment.

502
MCQmedium

A user reports that their Windows 10 PC is infected with malware that prevents the Task Manager from opening. You need to terminate a suspicious process from the command line. Which command should you use to forcefully end a process by its name?

A.tasklist /v
B.taskkill /IM malware.exe /F
C.shutdown /r /t 0
D.regedit /e backup.reg
AnswerB

taskkill with /IM targets the process by image name and /F forces termination, bypassing the graceful close that malware may block. Running it from an elevated command prompt kills the suspicious process even when Task Manager is disabled.

Why this answer

The `taskkill` command with the `/IM` (image name) parameter targets a process by its executable name, and the `/F` flag forcefully terminates it. This is the appropriate tool when Task Manager is disabled by malware, as it directly ends the process from the command line without relying on GUI interaction.

Exam trap

The trap here is that candidates may confuse `tasklist` (which only lists processes) with `taskkill` (which terminates them), or mistakenly think `shutdown` or `regedit` can end a single process, leading them to choose a non-terminating command.

How to eliminate wrong answers

Option A is wrong because `tasklist /v` only lists running processes with verbose details (e.g., session name, status) but does not terminate any process. Option C is wrong because `shutdown /r /t 0` initiates an immediate system restart, which does not terminate a specific process; it shuts down the entire OS. Option D is wrong because `regedit /e backup.reg` exports the entire registry to a file; it does not interact with running processes and is used for backup, not process termination.

503
MCQhard

A network administrator is configuring a new wireless network for a hospital that requires the highest level of security for patient data. The network must support 802.1X authentication with smart cards. Which combination of security protocols and authentication methods should be used?

A.WPA2-PSK with PEAP-MSCHAPv2.
B.WPA3-Personal with SAE.
C.WPA2-Enterprise with EAP-TLS.
D.WPA3-Enterprise with EAP-TTLS.
AnswerC

WPA2-Enterprise is the appropriate security mode for corporate environments because it leverages the 802.1X framework for robust, centralized authentication against a RADIUS server. EAP-TLS (Extensible Authentication Protocol-Transport Layer Security) is a highly secure EAP method that performs mutual authentication using digital certificates on both the client and the server. This certificate-based authentication is inherently compatible with smart cards, as smart cards securely store the client's private key and certificate, making this the ideal solution for the specified requirements.

Why this answer

WPA2-Enterprise with EAP-TLS provides the highest level of security for a hospital network requiring 802.1X authentication with smart cards. EAP-TLS uses mutual authentication via digital certificates (which can be stored on smart cards), eliminating the risk of credential theft or man-in-the-middle attacks. WPA2-Enterprise is the appropriate underlying encryption framework for this scenario, as it supports the required 802.1X/EAP integration.

Exam trap

The trap here is that candidates often assume WPA3 is always more secure than WPA2, but for enterprise 802.1X with smart cards, WPA2-Enterprise with EAP-TLS is the correct and fully supported combination, while WPA3-Enterprise with EAP-TTLS does not enforce client certificate authentication.

How to eliminate wrong answers

Option A is wrong because WPA2-PSK uses a pre-shared key, which does not support 802.1X authentication or smart cards; PEAP-MSCHAPv2 relies on passwords, not certificates, and is vulnerable to brute-force attacks. Option B is wrong because WPA3-Personal with SAE is designed for password-based authentication in home/small office networks, not for 802.1X enterprise authentication with smart cards. Option D is wrong because while WPA3-Enterprise supports 802.1X, EAP-TTLS typically uses a server-side certificate only and tunnels password-based inner methods (e.g., MSCHAPv2), which does not meet the requirement for smart card (certificate-based) authentication; EAP-TLS is the standard for client certificate authentication.

504
MCQeasy

A user calls the help desk because their workstation is running very slowly and they notice unusual network activity. You suspect ransomware. What should you do first to contain the threat?

A.Run a full antivirus scan on the affected workstation.
B.Disconnect the workstation from the network immediately.
C.Back up all files to an external drive before taking action.
D.Restart the computer and boot into Safe Mode.
AnswerB

Severing the network connection halts command-and-control traffic and lateral movement or encryption of shared resources, containing ransomware before eradication. It is the immediate first action; powering off or remediating in place risks further spread and destroys volatile evidence.

Why this answer

Disconnecting the workstation from the network immediately is the correct first step because ransomware often uses network propagation mechanisms (e.g., SMB, RDP) to encrypt shared drives and spread to other systems. By isolating the machine at the physical or logical layer, you prevent lateral movement and further encryption of network resources, which is the primary containment priority in a suspected ransomware incident.

Exam trap

CompTIA A+ emphasizes that containment (isolation) must precede remediation (scanning, backup, or boot changes) in incident response. The trap here is that candidates mistakenly choose a reactive remediation step like running a scan or backing up files, which can worsen the spread or data loss.

How to eliminate wrong answers

Option A is wrong because running a full antivirus scan on an actively infected system can trigger the ransomware to accelerate encryption or delete files, and it does nothing to stop network propagation. Option C is wrong because backing up files to an external drive risks copying encrypted or infected data, and the act of connecting an external drive could allow the ransomware to encrypt that drive as well. Option D is wrong because restarting the computer and booting into Safe Mode does not disconnect the network interface; the ransomware may still have persistence mechanisms (e.g., scheduled tasks, services) that activate on boot, and the system remains a vector for lateral movement.

505
MCQmedium

A technician is configuring a company-issued Android tablet for a kiosk mode in a retail store. The tablet must only run the store's inventory app and prevent users from accessing other apps or settings. Which built-in Android feature should the technician use?

A.Guest Mode
B.Lock Task mode (dedicated device mode)
C.Developer Options > Force GPU Rendering
D.Do Not Disturb
AnswerB

Screen Pinning locks the device to one app and requires a PIN to unpin, providing the exact kiosk functionality needed.

Why this answer

Android's built-in kiosk mode is Lock Task mode (also called dedicated device mode), which locks the device to a single app or set of apps and prevents users from accessing other apps, the home screen, recent apps, notifications, and system settings. It is typically configured through a device policy controller (e.g., Android Enterprise dedicated device mode). Screen Pinning is a user-level feature that temporarily locks the screen to one app; it can be exited with a PIN/password and does not provide the full system-level restrictions required for a retail kiosk.

Exam trap

CompTIA A+ often tests the distinction between user-level app pinning and system-level kiosk lockdown. Candidates may choose Screen Pinning because it sounds like a single-app lock, but true kiosk mode on Android requires Lock Task mode (dedicated device mode), which enforces restrictions that Screen Pinning does not.

How to eliminate wrong answers

Option A is wrong because Guest Mode creates a separate user profile with limited access but still allows the user to switch profiles or access other apps within the guest session, so it does not lock the device to a single app. Option C is wrong because Developer Options > Force GPU Rendering is a debugging tool that forces apps to use GPU for 2D drawing, which can improve performance but does not restrict app access or prevent users from leaving the inventory app. Option D is wrong because Do Not Disturb only silences notifications and calls; it does not restrict app usage or prevent the user from navigating to other apps or settings.

506
MCQeasy

A technician is tasked with disposing of several old UPS batteries from a server room. What is the most environmentally responsible method?

A.Place them in the regular dumpster for pickup.
B.Take them to a local battery recycling center.
C.Burn them in an incinerator to recover energy.
D.Store them indefinitely in a sealed container.
AnswerB

Taking lead-acid batteries to a certified recycling center is the correct and environmentally responsible disposal method. These specialized facilities are equipped to safely neutralize the sulfuric acid and extract the lead, plastic, and other components for reuse in new batteries or other products. This process significantly reduces the demand for virgin materials, conserves natural resources, and prevents hazardous waste from entering landfills or polluting ecosystems.

Why this answer

UPS batteries contain hazardous materials such as lead and sulfuric acid, which must be handled through specialized recycling processes to prevent environmental contamination. Local battery recycling centers are equipped to safely extract and reuse these materials, complying with regulations like the Resource Conservation and Recovery Act (RCRA) in the U.S.

Exam trap

CompTIA often tests the misconception that 'recycling' is optional or that 'storing indefinitely' is a safe alternative, when in fact proper disposal through certified recycling centers is legally required for hazardous waste like UPS batteries.

How to eliminate wrong answers

Option A is wrong because placing UPS batteries in a regular dumpster violates environmental regulations (e.g., RCRA) and can lead to soil and water contamination from leaked lead and acid. Option C is wrong because burning UPS batteries in an incinerator releases toxic fumes, including lead oxide and sulfur dioxide, and does not safely recover energy due to the hazardous nature of the materials. Option D is wrong because storing batteries indefinitely in a sealed container is not a disposal method and risks eventual leakage, corrosion, and non-compliance with waste management laws.

507
MCQmedium

A technician is configuring a new wireless network for a school. The network must support hundreds of student devices simultaneously and provide strong security. The school wants to use a single SSID with individual logins for students. Which security protocol should the technician choose?

A.WPA2-PSK with a long passphrase.
B.WPA2-Enterprise with 802.1X and RADIUS.
C.WPA3-Enterprise with 192-bit encryption.
D.WPA3-Personal with SAE.
AnswerC

WPA3-Enterprise is the most secure and scalable option for a new wireless network requiring individual user authentication and robust data protection. It utilizes 802.1X and a RADIUS server for per-user access control and accountability, preventing unauthorized access and improving auditing. The inclusion of 192-bit encryption, part of the "Suite B" security profile, provides significantly stronger cryptographic protection against modern threats, ensuring the highest level of confidentiality and integrity for sensitive network traffic.

Why this answer

WPA3-Enterprise with 192-bit encryption is the correct choice because it provides the strongest security for a large-scale deployment with individual logins. It uses 802.1X authentication with a RADIUS server, supporting unique credentials for each student, and mandates 192-bit minimum-strength security suite (CNSA Suite) for encryption, offering enhanced protection against brute-force and dictionary attacks compared to WPA2-Enterprise.

Exam trap

CompTIA A+ emphasizes the distinction between 'Enterprise' and 'Personal' modes. The trap here is that candidates see 'WPA2-Enterprise with 802.1X and RADIUS' and assume it is sufficient for high-security individual logins, overlooking that WPA3-Enterprise with 192-bit encryption is the only option that combines individual authentication with the strongest mandated encryption suite.

How to eliminate wrong answers

Option A is wrong because WPA2-PSK uses a pre-shared key that is shared among all users, making it impossible to provide individual logins and vulnerable to passphrase cracking if the key is compromised. Option B is wrong because while WPA2-Enterprise with 802.1X and RADIUS supports individual logins, it relies on older encryption (CCMP/AES) and is susceptible to KRACK attacks and dictionary attacks on weak EAP methods; it does not mandate the 192-bit security suite required for the highest security. Option D is wrong because WPA3-Personal with SAE (Simultaneous Authentication of Equals) provides strong password-based authentication but still uses a single shared password for the SSID, not individual logins for each student.

508
MCQeasy

A user reports that their Android phone automatically switches from Wi-Fi to cellular data when the Wi-Fi signal is weak, even though they want to stay on Wi-Fi. Which setting should you configure to prevent this behavior?

A.Turn off Bluetooth
B.Disable 'Mobile data always active' in Developer Options
C.Enable Airplane Mode
D.Disable 'Switch to mobile data' in Wi-Fi settings
AnswerD

Disabling the 'Switch to mobile data' (often labeled as 'Wi-Fi Assistant' or 'Smart Network Switch' depending on the Android version and manufacturer) option within the Wi-Fi settings directly addresses the user's reported issue. This feature is specifically designed to automatically transition the device from a weak or unstable Wi-Fi connection to a more reliable cellular data connection to maintain internet access. By deactivating this setting, the Android phone will prioritize staying connected to the Wi-Fi network, even if the signal is poor, preventing the unwanted automatic switch to mobile data.

Why this answer

The 'Switch to mobile data' setting (sometimes called 'Auto-switch to mobile data' or 'Smart network switch') is specifically designed to automatically fall back to cellular when Wi-Fi becomes unreliable. Disabling it forces the phone to stay on Wi-Fi even if the signal is weak, which is exactly what the user wants. This setting is found in the Wi-Fi preferences or advanced Wi-Fi settings on most Android versions.

Exam trap

The trap here is confusing 'Mobile data always active' with the automatic switching feature; candidates often think that disabling mobile data entirely will solve the issue, but that would also prevent cellular fallback when Wi-Fi is truly unavailable.

How to eliminate wrong answers

Option A is wrong because Bluetooth is a separate wireless protocol for peripherals and has no bearing on Wi-Fi to cellular handoff. Option B is wrong because 'Mobile data always active' in Developer Options keeps cellular data connected even when Wi-Fi is on, but it does not control the automatic switching behavior; it only affects whether mobile data remains active in the background. Option C is wrong because Airplane Mode disables all wireless radios, including Wi-Fi, which would prevent the user from staying on Wi-Fi entirely.

509
MCQeasy

A technician is setting up a wireless network for a home office. The client is concerned about neighbors accessing their internet. The technician enables WPA2-PSK with a strong passphrase. Which additional step should the technician take to ensure the network is as secure as possible?

A.Enable WPS for easy device pairing.
B.Disable SSID broadcast.
C.Disable WPS on the router.
D.Enable MAC address filtering.
AnswerC

Disabling Wi-Fi Protected Setup (WPS) on the router is a crucial security best practice for wireless networks. The WPS protocol, particularly its PIN-based method, is susceptible to brute-force attacks that can rapidly determine the network's WPA/WPA2 passphrase. By deactivating WPS, a technician eliminates this significant attack vector, forcing potential intruders to attempt more resource-intensive and time-consuming methods, such as direct brute-forcing of the WPA2 passphrase, which is far more difficult to achieve.

Why this answer

WPA2-PSK with a strong passphrase already provides robust encryption, but WPS (Wi-Fi Protected Setup) introduces a significant vulnerability. WPS allows devices to connect via an 8-digit PIN, which can be brute-forced in a matter of hours using tools like Reaver, exposing the network to unauthorized access. Disabling WPS eliminates this attack vector, making the network as secure as possible.

Exam trap

CompTIA often tests the misconception that hiding the SSID or using MAC filtering provides meaningful security, when in reality the WPS vulnerability is a far more critical and exploitable flaw that must be addressed first.

How to eliminate wrong answers

Option A is wrong because enabling WPS, even for convenience, creates a backdoor that bypasses the strong WPA2-PSK passphrase; the WPS PIN can be brute-forced offline, compromising the network. Option B is wrong because disabling SSID broadcast only hides the network name from casual scans, but it does not prevent determined attackers from discovering it using packet sniffers (e.g., Wireshark) or tools like Kismet, and it can actually cause connectivity issues for legitimate clients. Option D is wrong because MAC address filtering is a weak security measure; MAC addresses can be easily spoofed using tools like SMAC or by modifying the network adapter settings, so it provides no real protection against a skilled attacker.

510
MCQeasy

A small business wants to migrate its on-premises file server to a cloud service to reduce hardware maintenance costs. The data must be accessible from any device with an internet connection and should support real-time collaboration. Which cloud service model best meets these requirements?

A.Infrastructure as a Service (IaaS)
B.Platform as a Service (PaaS)
C.Software as a Service (SaaS)
D.Desktop as a Service (DaaS)
AnswerC

Software as a Service (SaaS) delivers fully managed, ready-to-use applications directly to end-users over the internet, eliminating the need for local installation, maintenance, or infrastructure management. For a small business seeking to migrate its file server, a SaaS solution like cloud-based file storage and collaboration suites provides immediate accessibility, real-time collaboration features, and automatic updates, perfectly aligning with the requirement for a turnkey solution without managing any underlying hardware or software.

Why this answer

SaaS (Software as a Service) is the correct choice because it provides a ready-to-use file-sharing and collaboration application (e.g., Microsoft 365 SharePoint, Google Workspace Drive) that is accessed via a web browser or client over the internet. This eliminates the need to manage underlying hardware or platform, directly meeting the requirements for device-agnostic access and real-time collaboration without any infrastructure overhead.

Exam trap

CompTIA often tests the misconception that IaaS is the best choice for any migration away from on-premises hardware, but the trap here is that IaaS still requires the customer to manage the operating system and application stack, whereas SaaS provides a fully managed, collaboration-ready solution that directly meets the access and real-time editing requirements.

How to eliminate wrong answers

Option A is wrong because IaaS (Infrastructure as a Service) provides only virtualized compute, storage, and networking resources (e.g., Amazon EC2, Azure VMs), requiring the business to still deploy, configure, and manage the file server operating system and collaboration software, which does not reduce hardware maintenance costs to the degree needed. Option B is wrong because PaaS (Platform as a Service) offers a runtime environment for custom application development (e.g., AWS Elastic Beanstalk, Google App Engine), not a ready-to-use file server with built-in real-time collaboration features; the business would still need to build or integrate collaboration logic. Option D is wrong because DaaS (Desktop as a Service) delivers virtual desktops (e.g., Windows 365, Amazon WorkSpaces) that require users to connect to a full desktop environment, not a simple file-sharing service, and it does not inherently provide the real-time collaboration capabilities of a SaaS file-sharing application.

511
MCQmedium

A user reports that their Windows 11 computer is infected with ransomware. Files are encrypted and a ransom note is displayed. The user has a backup from two days ago stored on an external drive that was disconnected after the backup. What is the best course of action to recover the data?

A.Pay the ransom to get the decryption key.
B.Disconnect the computer from the network and restore files from the external backup.
C.Run a full antivirus scan to remove the ransomware and then restore files.
D.Use System Restore to revert the system to a previous state.
AnswerB

Immediately disconnecting the infected computer from the network is critical to prevent the ransomware from spreading to other systems or communicating with its command-and-control server for further instructions or key exfiltration. Once isolated, restoring files from a verified, uninfected external backup is the most reliable and secure method to recover data without succumbing to the ransom demand. This process ensures complete data integrity and system functionality restoration.

Why this answer

The correct action is to isolate the machine from the network to prevent further spread or command-and-control communication, then restore the encrypted files from the offline external backup, which was disconnected after the last good backup and is therefore unaffected by the ransomware. Restoring from a clean, disconnected backup is the only reliable recovery method that does not reward attackers or risk re-infection.

Exam trap

The trap here is that candidates assume antivirus removal or System Restore can undo ransomware encryption, when in fact only a clean, offline backup can restore the encrypted user data.

How to eliminate wrong answers

Option A is wrong because paying the ransom does not guarantee a working decryption key, funds criminal activity, and may result in double extortion or re-encryption. Option C is wrong because antivirus removal of the ransomware binary does not decrypt already-encrypted files, and scanning before isolating may allow the malware to spread or destroy shadow copies. Option D is wrong because System Restore only reverts system files, registry, and installed programs — it does not restore user data files that were encrypted by ransomware, and ransomware often deletes shadow copies to defeat this exact recovery method.

512
MCQeasy

A company policy requires that all sensitive data stored on laptops must be unreadable if the device is lost or stolen. A technician is tasked with implementing a solution that works transparently for users. Which approach should they take?

A.Enable BitLocker drive encryption on each laptop.
B.Set a BIOS password on each laptop.
C.Implement a folder-level password policy using EFS.
D.Configure a screensaver password with a 1-minute timeout.
AnswerA

BitLocker encrypts the entire volume with AES, rendering data unreadable without the recovery key or TPM-bound credentials, satisfying the policy requirement for lost or stolen laptops. Encryption and decryption occur transparently during normal use, so users notice no workflow change. BitLocker also supports Microsoft Entra ID escrow for key recovery.

Why this answer

BitLocker drive encryption provides full-disk encryption that operates transparently to the user, automatically encrypting all data on the system drive. If the laptop is lost or stolen, the data remains unreadable without the decryption key, satisfying the policy requirement without requiring user intervention.

Exam trap

CompTIA often tests the distinction between access control (passwords, screen locks) and data-at-rest encryption; the trap here is confusing a screen lock or BIOS password with actual encryption, which does not protect data if the drive is physically removed.

How to eliminate wrong answers

Option B is wrong because a BIOS password only prevents unauthorized booting of the system, but does not encrypt the data on the drive; an attacker could remove the hard drive and access the data directly. Option C is wrong because EFS (Encrypting File System) encrypts individual files or folders, not the entire drive, and it does not work transparently for all users—it requires user-specific certificates and can leave system files or temporary data unencrypted. Option D is wrong because a screensaver password only locks the screen after inactivity, but does not encrypt any data; an attacker could boot from a live USB or remove the drive to read the data.

513
MCQeasy

A user reports that their system is running very slowly, and they see frequent pop-up ads even when no browser is open. They also notice that their default search engine has changed without their permission. Which type of malware is most likely causing these symptoms?

A.Virus
B.Adware
C.Ransomware
D.Rootkit
AnswerB

Adware is a category of software that automatically displays or downloads advertising material, often in the form of pop-up ads, banner ads, or unsolicited new browser tabs. It frequently modifies web browser settings, such as the homepage or default search engine, to redirect users to advertiser-controlled sites. These symptoms directly align with a user reporting excessive pop-ups and altered search functionality, as adware's primary goal is to generate revenue through advertising impressions.

Why this answer

Adware is software that automatically displays or downloads advertising material, typically in the form of pop-ups, redirects, and browser modifications. The combination of persistent pop-ups outside a browser session plus an unauthorized change to the default search engine is the classic adware signature, often bundled with freeware or browser hijackers.

Exam trap

220-1202 often tests whether candidates can distinguish adware from viruses and rootkits by symptom — the trap is picking 'virus' because the user says the system is slow, when the defining evidence is the persistent ads and search-engine hijack.

How to eliminate wrong answers

Option A is wrong because a virus primarily replicates and damages files or boot sectors; it does not characteristically produce continuous pop-up ads or hijack the search engine as its primary symptom. Option C is wrong because ransomware encrypts files and demands payment — the user would be locked out of data, not seeing ads. Option D is wrong because a rootkit hides malicious presence at the kernel or firmware level; while it may accompany adware, the visible pop-up and search-engine symptoms point directly to adware rather than a stealth rootkit.

514
MCQeasy

During a desktop computer deployment, a technician needs to dispose of several used toner cartridges. What is the most environmentally responsible method?

A.Throw them in the regular trash since they are mostly plastic.
B.Recycle them through a certified e-waste recycler or manufacturer take-back program.
C.Burn them in an incinerator to generate energy.
D.Sell them to a scrap metal dealer.
AnswerB

This is the correct and environmentally responsible method for disposing of used toner cartridges. Certified e-waste recyclers possess the specialized equipment and processes to safely separate and recover valuable materials, such as plastics, metals, and residual toner, preventing hazardous substances from entering the environment. Manufacturer take-back programs further facilitate closed-loop recycling, often remanufacturing cartridges to reduce waste and conserve resources, aligning with best practices for sustainable IT asset disposition.

Why this answer

Toner cartridges contain plastic, metal, and residual toner powder, which are hazardous to the environment if landfilled. Certified e-waste recyclers or manufacturer take-back programs ensure proper disassembly, material recovery, and safe disposal of toxic components, complying with regulations like the EPA's Resource Conservation and Recovery Act (RCRA). This method minimizes environmental harm and supports circular economy principles.

Exam trap

The trap here is that candidates assume 'mostly plastic' means safe for regular trash, ignoring that toner powder is a hazardous substance regulated by environmental agencies.

How to eliminate wrong answers

Option A is wrong because throwing toner cartridges in regular trash violates environmental regulations (e.g., RCRA) as residual toner is classified as hazardous waste, and plastics do not biodegrade in landfills. Option C is wrong because burning toner cartridges in an incinerator releases toxic fumes, including dioxins and heavy metals from the toner powder, and is not a standard energy-recovery method for e-waste. Option D is wrong because toner cartridges are not primarily scrap metal; they contain plastic, foam, and toner, making them unsuitable for scrap metal recycling, and a scrap metal dealer would reject them or improperly dispose of non-metal components.

515
MCQeasy

A customer complains that after a recent Windows update, their default web browser keeps resetting to Microsoft Edge. They want to set Google Chrome as the default. Where in the Settings app would you configure this?

A.Apps > Apps & features
B.Personalization > Start
C.Apps > Default apps
D.Update & Security > Windows Update
AnswerC

The "Apps > Default apps" section in Windows Settings is the precise and intended location for managing and configuring which applications open specific file types, protocols, or perform designated functions like web browsing or email. Users can directly select their preferred default applications for common tasks, such as setting a specific web browser or media player, directly addressing issues where system updates might have inadvertently altered these crucial associations.

Why this answer

The 'Default apps' page under Apps in the Settings app is the specific location where you can change the default web browser from Microsoft Edge to Google Chrome. This setting controls which application handles protocols like HTTP and HTTPS, and it allows you to set Chrome as the default by selecting it from the list of installed browsers.

Exam trap

CompTIA often tests the misconception that 'Apps & features' is the correct location for setting defaults, but candidates must remember that default app configuration is a separate, dedicated section under 'Default apps' within the Apps category.

How to eliminate wrong answers

Option A is wrong because 'Apps & features' is used to manage installed applications (uninstall, modify, or move them) but does not provide any option to set default applications or file associations. Option B is wrong because 'Personalization > Start' controls the appearance and behavior of the Start menu, such as which folders appear and whether to show recently added apps, and has nothing to do with default browser settings. Option D is wrong because 'Update & Security > Windows Update' is solely for managing Windows updates, including checking for, installing, and configuring update settings, and does not include any functionality for configuring default apps.

516
MCQeasy

A company policy requires that all USB flash drives be encrypted before use. A technician needs to configure a new drive for a manager who will store confidential client data. Which built-in Windows tool should the technician use?

A.EFS (Encrypting File System)
B.BitLocker To Go
C.Windows Defender Firewall
D.Device Manager
AnswerB

BitLocker To Go is the correct solution because it is specifically engineered to provide full-disk encryption for removable data drives, such as USB flash drives. This robust security feature ensures that all data on the drive is encrypted, protecting sensitive information from unauthorized access if the device is lost or stolen. It supports various authentication methods, including passwords or smart cards, making it ideal for enforcing corporate security policies on portable storage devices.

Why this answer

BitLocker To Go is the correct built-in Windows tool for encrypting removable drives like USB flash drives. It provides full-disk encryption specifically designed for portable storage, ensuring that the confidential client data on the drive is protected if the drive is lost or stolen.

Exam trap

CompTIA often tests the distinction between EFS (file-level encryption) and BitLocker (full-disk encryption), and the trap here is that candidates may confuse EFS with BitLocker To Go because both involve encryption, but EFS cannot encrypt entire removable drives for portable use.

How to eliminate wrong answers

Option A is wrong because EFS (Encrypting File System) encrypts individual files and folders on NTFS volumes, not entire removable drives, and it does not support encrypting USB flash drives for use on other systems without additional configuration. Option C is wrong because Windows Defender Firewall is a network security tool that filters incoming and outgoing traffic based on rules; it does not provide any data-at-rest encryption for storage devices. Option D is wrong because Device Manager is used to manage hardware drivers and device settings, not to perform encryption or security configurations on storage media.

517
MCQmedium

A technician is troubleshooting a Windows 10 system that fails to boot with a 'Bootmgr is missing' error. They need to repair the boot configuration data (BCD) from the Windows Recovery Environment. Which command should they use?

A.bootrec /fixmbr
B.bootrec /fixboot
C.bootrec /rebuildbcd
D.sfc /scannow
AnswerC

This command is the correct solution because it scans all disks for compatible Windows installations and then allows the user to add them to a newly created Boot Configuration Data (BCD) store. The BCD store contains critical boot information, including the location of the operating system files and boot options. Rebuilding the BCD directly addresses scenarios where the 'Bootmgr is missing' error occurs due to a corrupt, missing, or improperly configured BCD, ensuring the system can locate and load the Windows operating system.

Why this answer

The 'Bootmgr is missing' error indicates that the Boot Configuration Data (BCD) store is corrupted or missing. The `bootrec /rebuildbcd` command scans all disks for Windows installations and allows you to rebuild the BCD store from scratch, which directly resolves this issue. In contrast, `bootrec /fixmbr` and `bootrec /fixboot` repair the master boot record and boot sector, respectively, but do not rebuild the BCD store.

Exam trap

The trap here is that candidates often confuse `bootrec /fixboot` with repairing the boot configuration data, but `fixboot` only repairs the boot sector, not the BCD store, which is the actual cause of the 'Bootmgr is missing' error.

How to eliminate wrong answers

Option A is wrong because `bootrec /fixmbr` rewrites the master boot record (MBR) to the system partition, which addresses boot sector corruption but does not repair the BCD store. Option B is wrong because `bootrec /fixboot` writes a new boot sector to the system partition, which fixes boot sector issues but does not rebuild the BCD store. Option D is wrong because `sfc /scannow` checks and repairs system file integrity, but it does not operate on the BCD store or boot configuration data.

518
MCQmedium

During a security incident investigation, a technician finds that an attacker called the help desk, pretended to be a new employee who forgot their password, and successfully reset it. The attacker knew the employee's name and department. Which social engineering technique was used?

A.Phishing
B.Pretexting
C.Tailgating
D.Shoulder surfing
AnswerB

Pretexting is a sophisticated social engineering tactic where an attacker creates a convincing, fabricated scenario or 'pretext' to manipulate a target into divulging specific information or performing a particular action. This often involves extensive prior research to establish a believable false identity and a compelling story, such as impersonating a high-level executive or a vendor, to gain the target's trust. The attacker's goal is to exploit human psychology and a perceived legitimate need for information, typically through direct interaction like a phone call or in-person conversation.

Why this answer

Pretexting is a social engineering technique where the attacker fabricates a scenario (pretext) to manipulate a target into performing an action. In this case, the attacker called the help desk, assumed the identity of a new employee, and used the known details (name and department) to create a believable story, convincing the help desk to reset the password. This relies on psychological manipulation rather than technical exploitation.

Exam trap

CompTIA often tests the distinction between pretexting and phishing by emphasizing that pretexting involves direct impersonation and a fabricated scenario (often via phone or in person), while phishing relies on electronic communication like email or text messages.

How to eliminate wrong answers

Option A (Phishing) is wrong because phishing involves sending deceptive emails or messages that trick users into revealing sensitive information or clicking malicious links, not directly calling and impersonating someone to reset a password. Option C (Tailgating) is wrong because tailgating is a physical security breach where an unauthorized person follows an authorized individual into a restricted area without proper authentication, not a phone-based impersonation. Option D (Shoulder surfing) is wrong because shoulder surfing involves directly observing someone's screen or keyboard to steal information like passwords, not fabricating a story over the phone.

519
MCQmedium

During a security audit, a technician notices that an unauthorized person is standing just behind an employee at the secure door, waiting for the employee to badge in so they can enter without badging themselves. What type of social engineering attack is being attempted?

A.Pretexting
B.Baiting
C.Tailgating
D.Phishing
AnswerC

Tailgating occurs when an unauthorised person follows an authenticated employee through a secure door without badging themselves, exploiting the employee's legitimate access. This matches the observed behaviour of someone standing behind an employee waiting to slip in.

Why this answer

Tailgating (also known as piggybacking) is a physical social engineering attack where an unauthorized person follows an authorized individual into a secured area without using their own credentials. In this scenario, the attacker waits for the employee to badge in and then slips through the door before it closes, bypassing the access control system. This exploits the trust or politeness of the employee and the physical security gap between the door closing and the authentication check.

Exam trap

CompTIA often tests the distinction between tailgating and pretexting, where candidates mistakenly choose pretexting because they think the attacker is 'pretending' to be authorized, but the key difference is that tailgating requires no verbal deception—just physical proximity and timing.

How to eliminate wrong answers

Option A is wrong because pretexting involves fabricating a false identity or scenario to trick a victim into divulging information or performing an action, not physically following someone through a door. Option B is wrong because baiting relies on offering something enticing (e.g., a free USB drive or download) to lure the victim into a trap, not exploiting physical proximity at a secure door. Option D is wrong because phishing is a digital attack using deceptive emails, messages, or websites to steal credentials or install malware, not a physical entry technique.

520
MCQeasy

A technician is writing a batch script to automate the installation of a software package on multiple Windows workstations. The script needs to check if the software is already installed before attempting installation. Which scripting construct should the technician use?

A.A for loop
B.An if statement
C.A variable
D.A while loop
AnswerB

An `if` statement is the fundamental control structure used to execute commands conditionally based on the evaluation of a specified condition. It checks whether a given condition, such as the existence of a file or the value of a variable, is true or false. If the condition evaluates to true, the associated block of commands is executed exactly once, making it ideal for checking prerequisites like an existing installation before proceeding with a new action.

Why this answer

An if statement is the correct construct to check a condition (whether the software is already installed) and branch the script accordingly. It allows the script to test for the software's presence and skip installation if found. This is fundamental conditional logic in scripting.

Exam trap

220-1202 often tests the difference between loops (for, while) and conditional statements (if), expecting candidates to recognize that checking a condition requires an if statement, not a loop.

How to eliminate wrong answers

Option A is wrong because a for loop is used for iterating over a set of items, not for conditional checks. Option C is wrong because a variable stores data but does not perform conditional logic. Option D is wrong because a while loop repeats actions while a condition is true, but it is not the primary construct for a single conditional check; an if statement is more appropriate.

521
MCQeasy

A user reports that their virtual machine, which is used for testing software, suddenly lost network connectivity. The host machine is connected to the internet and can browse websites. The VM is configured with a bridged network adapter. What is the most likely cause of this issue?

A.The host's firewall is blocking the VM's network traffic.
B.The VM's DHCP lease has expired and it failed to obtain a new IP address.
C.The virtual switch on the host has been disabled.
D.The VM's operating system is corrupted.
AnswerB

When a virtual machine's DHCP lease expires, it loses its assigned IP address, subnet mask, and default gateway configuration. If the VM then fails to successfully renew its lease with the DHCP server, it will no longer have valid network parameters, effectively severing its connection to the network. This is a common occurrence in bridged networking where the VM directly relies on the physical network's DHCP server for its addressing.

Why this answer

In a bridged network configuration, the VM obtains its IP address directly from the same DHCP server as the host (e.g., the home router). If the DHCP lease expires and the VM fails to renew it (due to a network hiccup, DHCP server overload, or misconfigured lease time), the VM will lose its IP address and network connectivity, while the host remains unaffected because it maintains its own active lease. This is the most common cause of isolated VM connectivity loss in a bridged setup.

Exam trap

CompTIA A+ exams often test the misconception that a bridged adapter shares the host's IP address; candidates incorrectly assume the VM inherits the host's connectivity, but in reality, the VM must obtain its own IP via DHCP, and a lease expiration can cause a silent disconnect while the host remains online.

How to eliminate wrong answers

Option A is wrong because a host firewall typically filters traffic based on IP addresses or ports, but since the VM uses a bridged adapter, it appears as a separate device on the network; the host firewall does not inherently block the VM's traffic unless explicitly configured to do so, and the question states the host is connected and browsing, making a host firewall block unlikely. Option C is wrong because if the virtual switch on the host were disabled, the host itself would likely lose network connectivity or the VM would not even start, but the host is working fine; the virtual switch is a software component that remains active as long as the hypervisor is running. Option D is wrong because a corrupted OS would typically cause boot failures, crashes, or application errors, not a sudden, isolated loss of network connectivity while the VM remains running; network stack corruption is possible but far less common than a DHCP lease issue.

522
Multi-Selecthard

A technician is troubleshooting a Windows 10 workstation that is exhibiting symptoms of a malware infection. The technician has already disconnected the computer from the network. Which of the following should the technician do next to remediate the infection? (Choose two.)

Select 2 answers
A.Enable System Restore and create a restore point.
B.Run a full antivirus scan using updated definitions.
C.Boot into Safe Mode and run additional malware removal tools.
D.Reimage the computer immediately without attempting removal.
E.Educate the user on safe browsing habits.
AnswersB, C

After isolating the system, running a full antivirus scan with the latest definitions is essential to detect and remove malware. Updated definitions ensure the scanner recognizes current threats. This step is a core part of malware remediation and should be performed before restoring network access.

Why this answer

After isolating the infected system, the technician should run a full antivirus scan with updated definitions to detect and remove malware. Additionally, booting into Safe Mode and using specialized removal tools helps eliminate persistent infections that might resist normal removal. These two actions directly address the malware, while other options are either preventive, premature, or not directly remedial.

Exam trap

The trap here is choosing reimaging or user education as immediate remediation steps, when they are either too drastic or do not address the active infection.

523
MCQmedium

A help desk technician receives a complaint that a user’s custom software application stopped working after a Windows update was installed automatically overnight. The technician checks the system and finds the update is not in the approved change log. What should the technician do next?

A.Reinstall the custom application immediately
B.Roll back the Windows update and document the incident
C.Leave the update in place and submit a new change request for the application
D.Disable Windows Update on the workstation permanently
AnswerB

Rolling back the Windows update is the most direct and efficient method to restore the system to its last known good configuration, thereby immediately resolving the application's functionality issue caused by the unauthorized change. This action directly addresses the identified root cause. Concurrently, documenting the incident is crucial for maintaining a comprehensive audit trail, identifying the source of the unauthorized update, and implementing preventative measures to ensure future compliance with change management policies.

Why this answer

The update was installed without authorization (not in the approved change log), violating change management policy. The technician should immediately roll back the update to restore application functionality and then document the incident to ensure proper change control procedures are followed. This aligns with the CompTIA A+ change management process: identify the unauthorized change, reverse it, and report it.

Exam trap

The trap here is that candidates may think restoring functionality (Option A) or preventing future updates (Option D) is the priority, but CompTIA emphasizes that following change management documentation and incident reporting is the correct first step, not just fixing the symptom.

How to eliminate wrong answers

Option A is wrong because reinstalling the custom application does not address the root cause (the unauthorized Windows update) and may waste time if the update breaks the application again. Option C is wrong because leaving an unauthorized update in place bypasses change management controls and could cause further instability; a new change request should be submitted before, not after, the change is applied. Option D is wrong because permanently disabling Windows Update leaves the system vulnerable to security patches and is an overreaction; the proper response is to manage updates through an approved change process, not disable the service entirely.

524
MCQhard

A technician is investigating a privilege escalation vulnerability. They need to list all files in /usr/bin that have the SUID or SGID bit set and are owned by root. Which single command will achieve this?

A.find /usr/bin -user root -perm -6000
B.find /usr/bin -user root -perm 4000 -o -perm 2000
C.ls -la /usr/bin | grep '^...s'
D.find /usr/bin -user root -perm /6000
AnswerD

The -perm /6000 test matches files with either the SUID (4000) or SGID (2000) bit set, since the leading slash means any of those bits. Combined with -user root, it lists exactly the root-owned binaries in /usr/bin carrying either privilege bit.

Why this answer

The `find` command with `-perm /6000` matches files where either the SUID (4000) or SGID (2000) bit is set, combined with `-user root` to restrict results to files owned by root. The `/` prefix in the permission mask tells `find` to match any of the specified bits, making it the precise single command for this task.

Exam trap

CompTIA often tests the distinction between `-perm -mode` (all bits must match) and `-perm /mode` (any bit can match), and candidates frequently confuse the minus sign with the forward slash, leading them to pick Option A.

How to eliminate wrong answers

Option A is wrong because `-perm -6000` uses a minus sign, which requires all bits in 6000 (both SUID and SGID) to be set simultaneously, not just one of them; this would miss files with only SUID or only SGID. Option B is wrong because it uses `-o` (OR) without grouping parentheses, causing the `-user root` condition to apply only to the first expression, so it would list files with SGID set regardless of owner. Option C is wrong because `ls -la | grep '^...s'` only matches files with SUID set (the 's' in the owner execute position) and misses files with only SGID set (where the 's' appears in the group execute position), plus it relies on parsing `ls` output which is fragile and not recommended for scripting.

525
MCQmedium

A technician is troubleshooting a PowerShell script that collects system information and writes it to a log file. The script runs without errors but the log file is empty. The script uses Out-File to write data. What is the most likely issue?

A.The script is not running with administrative privileges.
B.The Out-File cmdlet is misspelled.
C.The command before Out-File does not produce any output.
D.The log file path contains a forward slash instead of a backslash.
AnswerC

The Out-File cmdlet functions by taking input from the PowerShell pipeline. If the command preceding Out-File (e.g., Get-Process -Name "NonExistentProcess") returns no objects or an empty collection, Out-File will still execute successfully. In this scenario, Out-File will create the specified log file but write zero bytes of content to it, resulting in an empty file. This is a common cause of empty output files when a filter or query yields no results.

Why this answer

The most likely issue is that the command preceding Out-File does not produce any output. Out-File writes whatever is piped to it; if the preceding command returns nothing (e.g., due to an error, empty result, or incorrect syntax), the log file will be empty even though the script runs without errors.

Exam trap

220-1202 often tests PowerShell pipeline behavior, and candidates may overlook that Out-File only writes what it receives, leading to empty files when preceding commands yield no output.

How to eliminate wrong answers

Option A (The script is not running with administrative privileges) is wrong because lack of admin privileges would typically cause an access denied error when writing to certain locations, not an empty file; if the script runs without errors, it likely has write access. Option B (The Out-File cmdlet is misspelled) is incorrect because a misspelling would cause a command-not-found error, not silent empty output. Option D (The log file path contains a forward slash instead of a backslash) is wrong because PowerShell accepts forward slashes in paths on Windows, and an invalid path would cause an error, not an empty file.

Page 6

Page 7 of 10

Page 8

All pages

Practice 220-1202 by domain

Target a specific domain to shore up weak areas.

See all domains with question counts →