Courseiva

CompTIA A+ Core 2 220-1202 (220-1202) — Questions 526–600

687 questions total · 10pages · All types, answers revealed

Page 7

Page 8 of 10

Page 9
526
MCQhard

A user reports that their Windows 11 laptop's search bar is not returning results for local files, though web searches work. You suspect the indexing service is not running or the index is corrupted. Which tool should you use to rebuild the search index?

A.Services.msc
B.Indexing Options in Control Panel
C.Task Manager
D.Windows Settings > Privacy & security > Searching Windows
AnswerB

Indexing Options, accessible via the Control Panel, is the dedicated utility for managing the Windows search index. Within this tool, users can click the 'Advanced' button, which reveals an option to 'Rebuild' the index. This action completely deletes the existing search index database and then re-scans all specified locations to create a new, fresh index, effectively resolving corruption or inconsistencies that impair search functionality. This is the precise method for a full index reconstruction.

Why this answer

The Indexing Options control panel (accessible via Control Panel or by searching 'indexing options') provides a direct interface to manage the Windows Search index, including the ability to rebuild it. Rebuilding the index is the appropriate fix when the index is corrupted or not functioning, as it forces Windows to re-scan all indexed locations and create a fresh index database, resolving issues where local file searches fail but web searches (which do not rely on the local index) still work.

Exam trap

The trap here is that candidates confuse the 'Searching Windows' settings in the modern Windows Settings app (which controls privacy and cloud search options) with the legacy Indexing Options control panel that actually contains the rebuild function.

How to eliminate wrong answers

Option A is wrong because Services.msc allows you to start, stop, or restart the Windows Search service, but it does not provide a direct option to rebuild the search index; rebuilding requires the Indexing Options interface. Option C is wrong because Task Manager is used to manage running processes, monitor performance, and start/stop applications, but it has no capability to manage or rebuild the search index. Option D is wrong because Windows Settings > Privacy & security > Searching Windows controls privacy-related search settings (e.g., whether to include cloud content or history), but it does not include a rebuild option for the local search index; the rebuild function is exclusively in the legacy Indexing Options control panel.

527
MCQeasy

A customer calls saying their home Wi-Fi network suddenly stopped working after they changed the router's security mode from WPA2-PSK to WPA2-Enterprise. All their devices previously connected fine. What is the most likely cause of the problem?

A.The router's firmware is outdated.
B.The devices do not support the new encryption cipher.
C.The router is now requiring a username and password from a RADIUS server, which the home network lacks.
D.The SSID was changed during the configuration.
AnswerC

WPA2-Enterprise mode is designed for corporate or institutional environments, leveraging 802.1X authentication to provide centralized user management and stronger security. This mode requires a Remote Authentication Dial-In User Service (RADIUS) server to validate user credentials (username and password) for each device attempting to connect. Standard home networks lack the complex infrastructure of a dedicated RADIUS server, meaning client devices cannot complete the required authentication handshake, leading to connection failures.

Why this answer

WPA2-Enterprise uses 802.1X authentication, which requires a RADIUS server to validate credentials (username and password). Home routers typically lack a built-in RADIUS server, so after changing to WPA2-Enterprise, the router cannot authenticate any client, causing all devices to fail to connect. The previous WPA2-PSK mode used a simple pre-shared key, which worked without any external server.

Exam trap

In the CompTIA A+ exam, it's important to distinguish between WPA2-PSK (pre-shared key, no server) and WPA2-Enterprise (requires a RADIUS/AAA server). The trap here is that candidates may assume all WPA2 modes work identically or blame encryption cipher support instead of the missing authentication infrastructure.

How to eliminate wrong answers

Option A is wrong because an outdated firmware would not cause a sudden failure immediately after changing the security mode; the issue is directly tied to the authentication method change, not firmware version. Option B is wrong because WPA2-Enterprise can use the same encryption ciphers (AES/CCMP) as WPA2-PSK; device support for the cipher is not the problem—the problem is the missing authentication server. Option D is wrong because the SSID was not changed according to the question; the customer only changed the security mode, and an SSID change would cause devices to not see the network, not fail authentication.

528
MCQmedium

A technician receives a ticket from a user who says their email is 'broken.' Upon investigation, the technician finds that the user's mailbox is full. The user is known for being confrontational. Which response best demonstrates professionalism?

A."Your mailbox is full. Delete some emails and empty your trash. Let me know if that fixes it."
B."This is a common issue when people don't manage their inbox. Please clean it up."
C."I'll increase your mailbox quota so you don't have to delete anything."
D."Your email isn't broken; you just have too many messages."
AnswerA

This response exemplifies professional IT support by providing a clear, actionable solution without assigning blame. It directly addresses the technical symptom of a full mailbox and offers standard user-level remediation steps: deleting unnecessary emails and emptying the trash. Furthermore, it includes a crucial follow-up request, "Let me know if that fixes it," which ensures the issue is fully resolved and demonstrates commitment to user satisfaction, aligning with best practices for incident management.

Why this answer

It directly addresses the root cause (full mailbox) with a clear, actionable solution (delete emails and empty trash) while maintaining a neutral, professional tone. The technician avoids blaming the user or escalating the situation, which is critical when dealing with a confrontational user. This response focuses on resolving the issue without unnecessary commentary, aligning with CompTIA's emphasis on professionalism and effective communication.

Exam trap

CompTIA often tests the trap of choosing a technically expedient solution (like increasing quota) over a professional communication approach, leading candidates to overlook the importance of de-escalating a confrontational user by providing a clear, non-judgmental resolution.

How to eliminate wrong answers

Option B is wrong because it includes a judgmental phrase ('people don't manage their inbox') that can be perceived as condescending, which may provoke a confrontational user and violates professional communication standards. Option C is wrong because increasing the mailbox quota without addressing the underlying storage issue is a temporary workaround that could lead to future problems (e.g., exceeding server limits or violating organizational email retention policies), and it fails to educate the user on proper mailbox management. Option D is wrong because it dismisses the user's concern by stating 'your email isn't broken,' which invalidates their experience and can escalate tension; the technician should acknowledge the issue while explaining the cause professionally.

529
MCQhard

A company's cloud-based CRM application is experiencing intermittent outages. The IT team suspects a distributed denial-of-service (DDoS) attack. Which cloud characteristic is most directly impacted by such an attack?

A.On-demand self-service
B.Broad network access
C.Availability
D.Resource pooling
AnswerC

A DDoS attack floods the CRM with malicious traffic, exhausting resources so legitimate users cannot connect. Availability, the guarantee that a system remains accessible when required, is therefore directly degraded. The stem's intermittent outages are the symptom of this characteristic being undermined, whereas elasticity, scalability and pay-as-you-go pricing remain unaffected.

Why this answer

A DDoS attack floods the CRM application with malicious traffic, overwhelming its resources and causing service disruption. This directly impacts the cloud characteristic of availability, which ensures that services remain accessible to authorized users when needed. In cloud computing, availability is often measured by uptime percentages and is critical for business continuity.

Exam trap

CompTIA A+ often tests the distinction between availability and other cloud characteristics, and the trap here is that candidates confuse 'broad network access' (which involves network connectivity) with 'availability' (which is about service uptime and accessibility), leading them to incorrectly select Option B.

How to eliminate wrong answers

Option A is wrong because on-demand self-service refers to a user's ability to provision computing resources automatically without human interaction, which is not directly affected by a DDoS attack. Option B is wrong because broad network access describes the ability to access cloud services over standard network protocols (e.g., HTTP/HTTPS) from various devices, and while the attack uses the network, it does not directly impact this characteristic. Option D is wrong because resource pooling involves the provider's ability to serve multiple customers from shared physical resources using multi-tenancy, which is a cost-efficiency model, not a measure of service accessibility.

530
MCQeasy

A small business owner reports that after upgrading their wireless router to a newer model, several older laptops running Windows 7 can no longer connect to the Wi-Fi network. The new router is configured to use WPA3. What is the most likely reason for the connection failures?

A.The laptops have outdated wireless drivers that do not support WPA3.
B.The router's firewall is blocking the older laptops' MAC addresses.
C.The laptops are using an incompatible encryption cipher like TKIP.
D.The router's SSID is hidden, and the laptops cannot discover it.
AnswerA

This is the correct answer. WPA3 introduces significant cryptographic enhancements, including the Simultaneous Authentication of Equals (SAE) handshake, which requires specific hardware capabilities in the wireless adapter and corresponding driver support, as well as updated operating system components. Older laptops, particularly those running Windows 7, predate WPA3 standardization and therefore lack the necessary drivers and OS support to implement these advanced security protocols, preventing them from authenticating with a WPA3-only network.

Why this answer

WPA3 is a newer security protocol that requires both the router and the client device to support it. Older laptops running Windows 7 typically have wireless network adapters and drivers that were designed before WPA3 was standardized (2018), so they only support WPA2 or earlier protocols. Without updated drivers that include WPA3 support, these laptops cannot authenticate with the router, causing the connection failures.

Exam trap

The 220-1202 exam often tests the misconception that encryption ciphers (like TKIP) are the primary cause of incompatibility, when in fact the core issue is the security protocol version (WPA3 vs. WPA2) and the driver's lack of support for the new authentication handshake.

How to eliminate wrong answers

Option B is wrong because MAC address filtering is a separate feature from security protocol support; if the router's firewall were blocking MAC addresses, the laptops would not even see the network or would be explicitly denied, but the issue is specifically about authentication after the upgrade to WPA3. Option C is wrong because TKIP is an encryption cipher used with WPA and WPA2, not WPA3; WPA3 uses AES-CCMP or GCMP-256, and while older laptops might use TKIP with WPA2, the core incompatibility here is the protocol version itself, not the cipher. Option D is wrong because a hidden SSID does not prevent a client from connecting if the SSID is manually entered; the problem is the authentication handshake failure due to WPA3 incompatibility, not network discovery.

531
MCQhard

After a failed Windows Update, a Windows 10 system repeatedly attempts to install the update and fails. You need to stop the Windows Update service and delete the temporary update files from the command line. Which two commands, in order, should you use? (Select the first command from the options.)

A.net stop wuauserv
B.sfc /scannow
C.dism /online /cleanup-image /restorehealth
D.taskkill /IM svchost.exe /F
AnswerA

Stopping the Windows Update service with `net stop wuauserv` releases the file locks that `wuauserv` holds on the temporary update store, allowing the subsequent deletion of `C:\Windows\SoftwareDistribution\Download` contents. This directly satisfies the stem's requirement to halt the service before removing the failed update's cached files.

Why this answer

The correct first command is 'net stop wuauserv' because it stops the Windows Update service (wuauserv), which prevents the system from continuing to attempt the failed update installation. After stopping the service, you can then delete the temporary update files from the SoftwareDistribution folder using commands like 'del /f /s /q %systemroot%\SoftwareDistribution\*' or 'rmdir /s /q %systemroot%\SoftwareDistribution'. This two-step process is the standard method to clear a stuck update state.

Exam trap

CompTIA often tests the misconception that 'taskkill /IM svchost.exe /F' is a valid way to stop the Windows Update service, but this command kills all svchost instances indiscriminately, which can crash other critical services and is not the proper method for safely stopping a specific service.

How to eliminate wrong answers

Option B is wrong because 'sfc /scannow' scans and repairs protected system files, but it does not stop the Windows Update service or delete temporary update files; it addresses file corruption, not update stuck states. Option C is wrong because 'dism /online /cleanup-image /restorehealth' repairs the Windows system image and component store corruption, but it does not stop the update service or remove the temporary update files that cause repeated failed attempts. Option D is wrong because 'taskkill /IM svchost.exe /F' forcefully terminates all svchost.exe processes, which would crash critical system services including the Windows Update service, but it is a brute-force method that can destabilize the system and does not safely stop the service or clean up the temporary files.

532
MCQhard

A user reports that their computer is infected with a virus that has encrypted all their personal files and left a text file with instructions to pay a ransom. The technician has verified the infection is ransomware. The company has a backup policy. What is the best course of action to recover the data?

A.Pay the ransom and hope the decryption key is provided.
B.Use a ransomware decryption tool from a reputable source.
C.Restore the files from a recent backup after removing the malware.
D.Reinstall the operating system and hope the files become accessible.
AnswerC

Restoring files from a recent, clean backup is the most effective and recommended method for recovering from a ransomware attack without engaging with the attackers. After ensuring the malware has been completely removed from the infected system, a technician can confidently overwrite the encrypted files with unencrypted versions from a verified backup. This approach bypasses the need for decryption, guarantees data integrity (assuming the backup is sound), and avoids supporting criminal enterprises.

Why this answer

The company has a backup policy, meaning a recent, clean backup should exist. Restoring from backup after removing the ransomware ensures data recovery without paying criminals or relying on unreliable decryption tools. This aligns with best practices for ransomware incidents: isolate, remove, then restore from verified backups.

Exam trap

CompTIA often tests the misconception that paying the ransom or using a decryption tool is a viable recovery method, when the correct answer is always to restore from a known-good backup after malware removal.

How to eliminate wrong answers

Option A is wrong because paying the ransom does not guarantee the decryption key will be provided; attackers often take the money and disappear, and paying funds further criminal activity. Option B is wrong because ransomware decryption tools from reputable sources are only effective for specific, known ransomware variants; the infection could use a unique or custom encryption algorithm, making such tools useless. Option D is wrong because reinstalling the operating system only wipes the system drive; it does not decrypt or recover the encrypted personal files, which remain encrypted on the storage media.

533
MCQmedium

A technician is troubleshooting a VM that fails to boot with the error 'Operating system not found'. The VM was working yesterday. The technician checks the virtual machine settings and sees that the virtual hard disk is attached to the IDE controller. What should the technician do first?

A.Reattach the virtual hard disk to the SCSI controller
B.Check the VM's boot order in the BIOS and ensure the virtual hard disk is first
C.Increase the VM's memory allocation
D.Restore the VM from a recent snapshot
AnswerB

Checking the VM's boot order in the virtual BIOS/UEFI and ensuring the virtual hard disk is the primary boot device is the most appropriate action. An "Operating system not found" error frequently indicates that the VM is attempting to boot from a non-bootable device, such as a virtual CD-ROM drive, network adapter, or another empty virtual disk, before it tries the virtual hard disk containing the operating system. This common misconfiguration can easily occur accidentally or after certain VM operations.

Why this answer

The error 'Operating system not found' indicates that the VM is attempting to boot from a device that does not contain a bootable operating system. Since the VM was working yesterday, the most likely cause is that the boot order in the VM's BIOS has been changed or reset, causing it to try booting from a non-bootable device (e.g., network or CD-ROM) before the virtual hard disk. Checking and correcting the boot order in the BIOS to prioritize the virtual hard disk is the logical first step before making configuration changes.

Exam trap

The trap here is that candidates assume the IDE controller is the problem and immediately try to change it to SCSI, but the error is actually caused by the boot order, not the storage controller type.

How to eliminate wrong answers

Option A is wrong because reattaching the virtual hard disk to the SCSI controller is unnecessary; the IDE controller is fully capable of booting a VM, and the error is not caused by the controller type. Option C is wrong because increasing memory allocation addresses performance or out-of-memory issues, not boot failures related to missing operating system detection. Option D is wrong because restoring from a snapshot should be a last resort after simpler checks like boot order, as snapshots can cause data loss and the issue may be a simple configuration change.

534
MCQmedium

A user on a Windows 10 Pro workstation complains that they cannot change their desktop background or theme, and several personalization settings are grayed out. The computer is not joined to a domain. Which Group Policy or local policy setting is most likely causing this restriction?

A.The 'Remove and prevent access to the Shut Down, Restart, Sleep, and Hibernate commands' policy.
B.The 'Prohibit access to Control Panel and PC settings' policy.
C.The 'Prevent changing desktop background' policy.
D.The 'Turn off all Windows Spotlight features' policy.
AnswerC

This Group Policy setting directly addresses the user's complaint by specifically disabling the functionality to modify the desktop background. When this policy is enabled, it effectively grays out the options within the Personalization settings that allow users to select or change their desktop image, preventing any alterations. This targeted policy ensures that the desktop background remains static without affecting other customization or system settings.

Why this answer

The 'Prevent changing desktop background' policy is the correct answer because it specifically blocks users from modifying the desktop wallpaper, which matches the symptom of grayed-out personalization settings. This policy is found under User Configuration > Administrative Templates > Control Panel > Personalization and directly disables the Desktop Background option in Settings. When enabled, the user cannot change the background image, solid color, or slideshow, even on a non-domain-joined machine via local Group Policy.

Exam trap

220-1202 often tests the difference between policies that block entire Control Panel access versus those that only gray out specific personalization options, causing candidates to over-select the broader 'Prohibit access to Control Panel' policy.

How to eliminate wrong answers

Option A is wrong because the shutdown/restart/sleep/hibernate removal policy only affects power options in the Start menu and does not touch personalization settings. Option B is wrong because prohibiting access to Control Panel and PC settings would block the entire Settings app, not just gray out background options—the user would not be able to open Personalization at all. Option D is wrong because turning off Windows Spotlight features affects lock screen and wallpaper suggestions from Microsoft, not the ability to manually change the desktop background.

535
MCQmedium

A technician is troubleshooting a Windows 11 computer that fails to boot with a 'Bootmgr is missing' error. They have a Windows installation USB. Which tool from the Windows Recovery Environment should they use to repair the boot configuration data (BCD)?

A.System File Checker (sfc /scannow)
B.Bootrec (bootrec /rebuildbcd)
C.DISM (DISM /Online /Cleanup-Image /RestoreHealth)
D.Diskpart (diskpart /s script.txt)
AnswerB

The `bootrec` command-line utility, specifically with the `/rebuildbcd` switch, is the dedicated tool for diagnosing and repairing boot environment problems in Windows. This command scans all disks for compatible Windows installations and allows the user to add them to a newly created or repaired Boot Configuration Data (BCD) store. It directly addresses scenarios where the BCD is missing or corrupted, preventing the system from locating and loading the operating system.

Why this answer

The 'Bootmgr is missing' error indicates that the Boot Configuration Data (BCD) store is corrupted or missing. The `bootrec /rebuildbcd` command scans all disks for Windows installations and rebuilds the BCD store from scratch, directly addressing the missing or corrupted boot configuration. This is the correct tool in the Windows Recovery Environment for repairing BCD issues.

Exam trap

The trap here is that candidates confuse `bootrec /rebuildbcd` with `sfc /scannow` or `DISM`, thinking any 'repair' tool can fix boot issues, but only `bootrec` specifically targets the BCD store required for the boot manager to locate the Windows loader.

How to eliminate wrong answers

Option A is wrong because System File Checker (sfc /scannow) repairs corrupted system files, not the boot configuration data (BCD) store; it operates on protected system files like DLLs and executables, not boot manager metadata. Option C is wrong because DISM /Online /Cleanup-Image /RestoreHealth repairs the Windows image (component store) for servicing issues, such as corruption in the system files used by Windows Update, and does not interact with the BCD store or boot sector. Option D is wrong because Diskpart is a disk partitioning tool used to manage volumes and partitions (e.g., create, delete, format), not to repair boot configuration data; running a script with `diskpart /s script.txt` would execute partition commands, not fix the BCD.

536
MCQeasy

After installing a new application, a user's Windows 10 system fails to boot and displays a 'Bootmgr is missing' error. Which command-line tool should you use from the Windows Recovery Environment to repair the boot configuration?

A.diskpart
B.bootrec
C.sfc /scannow
D.chkdsk /f
AnswerB

bootrec rebuilds and repairs the boot configuration data and master boot record from the Windows Recovery Environment, directly resolving the 'Bootmgr is missing' error described in the stem. It targets the boot configuration store rather than file-system or disk-partition corruption.

Why this answer

The 'Bootmgr is missing' error indicates that the Boot Manager (bootmgr) is corrupted or the Boot Configuration Data (BCD) is damaged. The bootrec command, specifically with the /FixBoot, /FixMbr, and /RebuildBcd switches, is designed to repair the boot configuration and restore the boot manager from the Windows Recovery Environment.

Exam trap

CompTIA often tests the distinction between file system repair (chkdsk) and boot configuration repair (bootrec), leading candidates to mistakenly choose chkdsk when the error is clearly a boot manager issue.

How to eliminate wrong answers

Option A is wrong because diskpart is a disk partitioning tool used to manage volumes and partitions, not to repair boot configuration files. Option C is wrong because sfc /scannow scans and repairs protected system files, but it cannot fix boot manager or BCD issues when the system cannot boot. Option D is wrong because chkdsk /f checks and repairs file system integrity on a volume, but it does not address boot configuration corruption.

537
MCQhard

A user on a Mac running macOS Big Sur needs to share a folder on their local network with a Windows colleague. The user wants the folder to appear as a network drive on the Windows machine without installing additional software. Which macOS feature should they enable and configure?

A.Screen Sharing in System Settings > Sharing.
B.File Sharing in System Settings > Sharing, and ensure SMB is enabled.
C.Internet Sharing in System Settings > Sharing.
D.Remote Login in System Settings > Sharing.
AnswerB

File Sharing (System Settings > Sharing) with SMB enabled is the correct method. This pairs the built-in Samba-compatible server (smbd) with SMB 2/3, allowing Windows PCs to authenticate and mount designated Shared Folders as network drives. You must both add the folder to the Shared Folders list and check the 'On' box for Windows File Sharing to ensure SMB is actually advertised on port 445, plus set the appropriate read/write permissions for the user or group.

Why this answer

File Sharing in macOS Big Sur includes the ability to enable SMB (Server Message Block) sharing, which is the native file-sharing protocol used by Windows. By turning on File Sharing and checking the SMB option, the Mac acts as an SMB server, allowing the Windows colleague to map the shared folder as a network drive without any additional software.

Exam trap

The 220-1202 exam often tests the misconception that Screen Sharing or Remote Login can be used for file sharing, but the trap here is that only File Sharing with SMB enabled provides the cross-platform network drive functionality required for Windows clients.

How to eliminate wrong answers

Option A is wrong because Screen Sharing enables remote desktop access (VNC protocol), not file sharing, and would not allow the folder to appear as a network drive on Windows. Option C is wrong because Internet Sharing allows the Mac to share its internet connection with other devices (e.g., via NAT or bridging), not to share files as a network drive. Option D is wrong because Remote Login enables SSH access for command-line connections, not SMB-based file sharing, and Windows cannot natively mount a folder via SSH as a network drive.

538
MCQhard

A technician is reviewing the change management log and finds that a previous change to the email server was marked as 'completed' but the email service has been intermittent since then. The technician suspects the change was not fully tested. Which step in the change management process was most likely skipped?

A.The change request was not submitted
B.The change was not approved by the CAB
C.A post-implementation review was not conducted
D.The rollback plan was not documented
AnswerC

A post-implementation review would have caught the intermittent issue and prevented the change from being marked as completed.

Why this answer

A post-implementation review (PIR) is the step where the change is verified to have met its objectives without causing adverse effects. Since the email service became intermittent after the change was marked 'completed', the lack of a PIR means the change was not validated in production, allowing the underlying issue to go undetected. In the CompTIA change management process, the PIR ensures that the change has been fully tested and that any residual problems are identified and addressed before the change is closed.

Exam trap

CompTIA often tests the distinction between the approval step and the validation step, trapping candidates who assume that a completed change must have been approved, when the real issue is the failure to verify the change's success through a post-implementation review.

How to eliminate wrong answers

Option A is wrong because the change was logged in the change management log as 'completed', which implies a change request was submitted and processed; the issue is not the absence of a request but the lack of validation after implementation. Option B is wrong because CAB approval is typically required for high-risk or significant changes, but the email server change was already approved and implemented; the skipped step is the verification of success, not the approval itself. Option D is wrong because while a rollback plan is important for reverting a failed change, the problem here is that the change was not fully tested and its impact was not assessed post-implementation; a documented rollback plan would not have prevented the intermittent service if the root cause was not identified during testing.

539
MCQeasy

A technician receives a call from someone claiming to be from the company's IT security team, asking for the administrator password to 'run a critical update.' The caller's voice sounds stressed and they mention a data breach. What should the technician do?

A.Provide the password immediately to prevent a data breach.
B.Ask for a callback number and verify it against the company directory.
C.Ignore the call because IT never calls about updates.
D.Change the password and give them the new one.
AnswerB

Verifying the caller independently through the company directory defeats pretexting and vishing, since a genuine IT security team member can be confirmed through official channels. Never disclose the administrator password based on an unverified inbound call.

Why this answer

It follows the principle of verifying identity through a trusted channel before disclosing sensitive information. The technician should ask for a callback number and cross-reference it against the company directory to ensure the caller is legitimate, as social engineering attacks often use urgency and impersonation to bypass security protocols.

Exam trap

This question tests the candidate's ability to resist urgency and authority-based social engineering by presenting a scenario where the caller seems legitimate and the threat appears imminent, leading candidates to prioritize speed over verification.

How to eliminate wrong answers

Option A is wrong because providing the password immediately without verification would violate security policies and could lead to a data breach by enabling an attacker. Option C is wrong because IT security teams may legitimately call about updates, especially during a breach, so ignoring the call could delay a critical response. Option D is wrong because changing the password and giving the new one still discloses credentials to an unverified caller, which does not mitigate the social engineering risk.

540
Multi-Selecthard

A technician is preparing to dispose of several old hard drives that contain sensitive company data. The organization's data destruction policy requires physical destruction. Which of the following methods are appropriate for physically destroying the drives? (Choose two.)

Select 2 answers
A.Incineration
B.Shredding
C.Low-level formatting
D.Overwriting
E.Degaussing
AnswersA, B

Incineration burns the drive at high temperatures, completely destroying the media and any data. This is a form of physical destruction that ensures no recoverable data remains. It must be performed in a controlled environment that meets environmental regulations. For organizations with strict data destruction policies, incineration is an appropriate method.

Why this answer

Shredding and incineration are both physical destruction methods that render the drive unusable and data unrecoverable. Degaussing, overwriting, and low-level formatting are logical or magnetic erasure methods that do not physically destroy the media. Therefore, only shredding and incineration satisfy the policy requirement for physical destruction.

Exam trap

The trap here is equating data erasure methods like degaussing or overwriting with physical destruction, which the policy specifically demands.

541
MCQeasy

A customer is returning a leased laptop that contains sensitive client data. The lease agreement requires that the data be irrecoverably destroyed, but the laptop must remain functional for the next lessee. Which method should you use?

A.Perform a quick format of the hard drive.
B.Use a degausser to demagnetize the drive.
C.Run a secure erase utility that overwrites all sectors with zeros.
D.Physically shred the hard drive.
AnswerC

A secure erase utility, often compliant with standards like NIST SP 800-88, systematically overwrites every addressable sector on the storage device, typically with zeros or a specific pattern, multiple times. This process effectively renders all previous data unrecoverable by standard and even advanced forensic methods, while crucially preserving the drive's physical integrity and functionality. The drive remains fully operational and ready for re-provisioning to the next user.

Why this answer

A secure erase utility that overwrites all sectors with zeros (e.g., using ATA Secure Erase or a tool like DBAN) renders the data irrecoverable by standard forensic methods while leaving the drive functional for the next lessee. This satisfies the lease agreement's requirement for data destruction without damaging the hardware. Quick formats only remove file system pointers, leaving data recoverable, while degaussing or physical destruction would render the laptop non-functional.

Exam trap

On the CompTIA A+ exam, candidates often confuse a quick format with a secure erase, assuming it removes data when it only removes the index. The key distinction is that a secure overwrite (e.g., zero-fill) preserves hardware functionality while making data irrecoverable.

How to eliminate wrong answers

Option A is wrong because a quick format only clears the file system metadata (e.g., MFT or FAT) and does not overwrite the actual data sectors, leaving all client data recoverable with simple file recovery tools. Option B is wrong because a degausser uses a strong magnetic field to demagnetize the platters, which destroys the drive's ability to store data permanently, making the laptop non-functional for the next lessee. Option D is wrong because physically shredding the hard drive destroys the hardware entirely, which violates the requirement that the laptop remain functional for the next lessee.

542
MCQeasy

A user reports that they cannot connect to the company's internal file server from home using the provided VPN client. They can access the internet without issues. Which of the following is the most likely cause of this problem?

A.The user's home router is blocking VPN traffic on port 443.
B.The VPN client is configured for split tunneling, and the file server's IP range is not in the allowed routes.
C.The file server is powered off or experiencing a hardware failure.
D.The user's VPN client software is outdated and needs to be reinstalled.
AnswerB

Split tunneling is a VPN configuration where only traffic destined for specific corporate network subnets is routed through the VPN tunnel, while all other traffic, such as general internet browsing, is sent directly from the user's local network. If the file server's IP range or subnet is not explicitly included in the VPN client's routing table for the tunnel, the client will attempt to reach it directly via the local network. This attempt will fail as the server is on the corporate network, explaining why internet access works but internal resources are unreachable.

Why this answer

Split tunneling allows the VPN client to route only specific traffic (e.g., corporate subnets) through the encrypted tunnel, while all other traffic goes directly to the internet. If the file server's IP range is not included in the allowed routes, traffic to that server will bypass the VPN and be sent unencrypted to the user's local gateway, which cannot reach the internal server. This matches the symptom: internet works, but the file server is unreachable.

Exam trap

The trap here is that candidates often assume any remote access issue is due to firewall blocking or server failure, overlooking the specific split tunneling misconfiguration that allows internet but blocks internal resources.

How to eliminate wrong answers

Option A is wrong because port 443 is typically used for HTTPS or SSL/TLS-based VPNs (e.g., OpenVPN, SSTP), and if the home router were blocking it, the VPN client would fail to establish any connection at all, not just fail to reach the file server. Option C is wrong because a powered-off or failed file server would affect all users, not just a remote VPN user, and the user can access the internet, indicating the VPN tunnel itself is up. Option D is wrong because outdated VPN client software would typically cause connection failures or authentication errors, not a selective inability to reach a specific internal resource while internet access works.

543
MCQeasy

A user reports that their Windows 10 PC shows a 'Low Disk Space' warning on the C: drive. You need to free up space by removing temporary files, system cache, and previous Windows installations. Which tool provides a guided cleanup for these items?

A.Disk Management
B.Defragment and Optimize Drives
C.Disk Cleanup
D.Storage Spaces
AnswerC

Disk Cleanup scans the C: drive and presents tick-box categories covering temporary files, system cache and previous Windows installations, letting the user select what to remove. This directly satisfies the stem's requirement for a guided cleanup tool targeting those three item types, unlike manual deletion or Storage Sense's limited automatic scope.

Why this answer

Disk Cleanup (cleanmgr.exe) is the built-in Windows tool specifically designed to free disk space by removing temporary files, system cache, and previous Windows installations. It provides a guided, checkbox-driven interface that lets users select categories such as 'Temporary Internet Files', 'Delivery Optimization Files', and 'Windows Update Cleanup' (which includes previous Windows installations). This makes it the correct choice for the described scenario.

Exam trap

The A+ exam often tests the distinction between tools that manage disk space (Disk Cleanup) versus tools that manage disk structure (Disk Management) or performance (Defragment), so the trap is that candidates may confuse 'freeing up space' with 'optimizing' or 'managing' the drive.

How to eliminate wrong answers

Option A is wrong because Disk Management is used for partitioning, formatting, and managing drive letters, not for cleaning temporary files or system caches. Option B is wrong because Defragment and Optimize Drives (dfrgui.exe) reorganizes file fragments on a drive to improve performance but does not remove any files or free up space. Option D is wrong because Storage Spaces is a storage virtualization feature that pools physical drives into logical storage pools, and it does not provide a cleanup interface for temporary files or previous Windows installations.

544
MCQmedium

A technician is troubleshooting a remote user's inability to connect to the office network via VPN. The user can ping the VPN server's public IP address but the VPN connection fails after entering credentials. The VPN logs show an authentication error. What should the technician check next?

A.Verify that the VPN server's firewall is allowing UDP port 500 and 4500.
B.Check if the user's account is locked out or if the password has expired.
C.Reinstall the VPN client software on the user's computer.
D.Configure the VPN to use a different encryption protocol.
AnswerB

An "authentication error" directly signifies that the credentials provided by the user, such as the username, password, or certificate, were rejected by the authentication server. Common and immediate reasons for such rejection include the user's account being administratively locked out due to too many failed login attempts, or the password having reached its expiration date and requiring a mandatory reset. Addressing these account-specific issues is the most direct and logical troubleshooting step for an authentication failure.

Why this answer

The VPN logs show an authentication error, which indicates the failure occurs during the credential validation phase, not during network connectivity. Since the user can ping the VPN server's public IP, Layer 3 connectivity is intact, and the issue is likely with the user's account status. Checking if the account is locked out or the password has expired directly addresses the authentication failure.

Exam trap

CompTIA often tests the distinction between connectivity issues (Layer 3 reachability) and authentication issues (Layer 7 credential validation), leading candidates to incorrectly focus on firewall ports or client software when the logs clearly point to an authentication failure.

How to eliminate wrong answers

Option A is wrong because UDP ports 500 and 4500 are used for IPsec IKE traffic, and the user can already ping the VPN server, so firewall rules are not the immediate cause of an authentication error. Option C is wrong because reinstalling the VPN client software would not resolve an authentication error that occurs after credentials are entered; the client is functioning enough to reach the server. Option D is wrong because changing the encryption protocol would not fix an authentication error; it would only alter how data is secured after authentication succeeds.

545
MCQeasy

A user reports that their laptop was stolen from their desk overnight. The security team reviews badge logs and finds no after-hours access to the floor. What physical security control should be implemented to prevent this from recurring?

A.Install a biometric fingerprint reader on the laptop.
B.Require a smart card to log in to the laptop.
C.Use a cable lock to secure the laptop to the desk.
D.Enable full-disk encryption on the laptop.
AnswerC

A cable lock physically tethers the laptop to the desk, directly addressing the theft scenario where badge logs showed no after-hours floor access. Since the thief likely entered during business hours or tailgated, an access-control review would not help; anchoring the device prevents opportunistic removal regardless of building entry.

Why this answer

A cable lock physically secures the laptop to a fixed object like a desk, directly preventing theft by requiring physical force or tool removal. Since the breach occurred overnight with no after-hours access, the threat was unauthorized physical removal, not logical access. A cable lock is the only control that addresses the physical theft vector by tethering the device to an immovable anchor.

Exam trap

CompTIA often tests the distinction between physical security controls (preventing theft/damage) and logical/data security controls (preventing unauthorized access or data loss), leading candidates to choose encryption or authentication options when the scenario clearly describes physical removal.

How to eliminate wrong answers

Option A is wrong because a biometric fingerprint reader authenticates the user at login, but does not prevent the laptop from being physically taken from the desk; it only controls logical access after power-on. Option B is wrong because requiring a smart card to log in controls authentication, not physical theft; the laptop can still be stolen regardless of login requirements. Option D is wrong because full-disk encryption protects data confidentiality if the laptop is stolen, but does not prevent the theft itself; it is a data protection control, not a physical security control.

546
MCQmedium

A technician is configuring a new Windows 10 workstation for a remote employee. The employee will use the laptop to access company resources via VPN. Which security setting should be configured to ensure the VPN connection is always used when accessing the internet?

A.Enable split tunneling to improve performance.
B.Disable split tunneling to force all traffic through the VPN.
C.Configure the VPN to use PPTP protocol.
D.Set the VPN to connect only when accessing internal websites.
AnswerB

Disabling split tunneling, also known as "full tunnel" VPN, ensures that all network traffic originating from the workstation, regardless of its destination (internal corporate network or external internet), is routed through the encrypted VPN tunnel to the corporate network. This forces all traffic to be inspected and filtered by corporate security appliances before reaching its final destination. This configuration is crucial for maintaining a consistent security posture and enforcing corporate policies, as it prevents any traffic from bypassing the secure corporate perimeter.

Why this answer

Disabling split tunneling ensures that all network traffic, including internet-bound traffic, is routed through the VPN tunnel. This forces the VPN connection to be always used when accessing the internet, which is essential for enforcing security policies and ensuring that company resources are protected even when the remote employee accesses external websites.

Exam trap

CompTIA often tests the misconception that enabling split tunneling improves security by reducing VPN load, when in fact it creates a security risk by allowing non-VPN traffic to bypass corporate security controls.

How to eliminate wrong answers

Option A is wrong because enabling split tunneling would allow internet-bound traffic to bypass the VPN, directly contradicting the requirement to always use the VPN for internet access. Option C is wrong because PPTP is an outdated and insecure protocol; the question asks about a security setting to force traffic through the VPN, not about the protocol choice. Option D is wrong because setting the VPN to connect only when accessing internal websites would not force all internet traffic through the VPN; it would only trigger the VPN for internal resource requests, leaving other internet traffic unprotected.

547
MCQmedium

A user receives an email from what appears to be their bank, asking them to click a link and verify their account due to suspicious activity. The email contains several spelling errors and the link points to an unfamiliar domain. What type of attack is this?

A.Spear phishing
B.Phishing
C.Whaling
D.Vishing
AnswerB

Phishing uses spoofed sender identity, a fraudulent link to an unfamiliar domain, and poor spelling to trick the recipient into revealing credentials. The bank impersonation plus urgency about suspicious activity matches this social-engineering pattern precisely.

Why this answer

This is a classic phishing attack because the email is a mass, unsolicited message that impersonates a trusted entity (the bank) and uses social engineering to trick the recipient into clicking a malicious link. The presence of spelling errors and an unfamiliar domain are hallmark indicators of a generic phishing attempt, not a targeted attack. Phishing typically relies on volume and deception rather than personalized reconnaissance.

Exam trap

The CompTIA A+ exam often tests the distinction between generic phishing and spear phishing by including a scenario with obvious errors and no personalization, tricking candidates into overthinking and selecting 'spear phishing' because they misidentify the bank context as targeted.

How to eliminate wrong answers

Option A is wrong because spear phishing is a highly targeted attack that uses personalized information (e.g., the recipient's name, job title, or specific account details) to increase credibility, whereas this email lacks any such personalization and contains generic errors. Option C is wrong because whaling is a specific form of spear phishing that targets high-profile executives or individuals with authority, not a general user receiving a mass email. Option D is wrong because vishing (voice phishing) is conducted over voice calls or VoIP, not via email with a clickable link.

548
MCQeasy

A small business owner wants to deploy a custom inventory app to five company-owned iPads. The app is not available on the App Store. Which method should you use to install it?

A.Use Apple Configurator to install the app directly.
B.Download the app from a third-party website and open it in Safari.
C.Email the app file to each user and have them install it.
D.Enable sideloading in Settings and install via iTunes.
AnswerA

Apple Configurator is a macOS application designed for mass deployment and management of iOS devices in an organizational setting. It enables IT administrators to supervise devices, install custom in-house applications (often referred to as Line of Business apps) directly onto them, provided these apps are properly signed with an Apple Enterprise Developer Program certificate. This method bypasses the App Store, making it ideal for proprietary business tools not intended for public distribution.

Why this answer

Apple Configurator allows IT administrators to install enterprise or custom in-house apps directly onto supervised iOS devices without requiring the App Store. Since the app is not available on the App Store and the iPads are company-owned, Apple Configurator provides a supported, secure method for direct installation using a Mac.

Exam trap

CompTIA often tests the misconception that iOS supports general sideloading or direct file installation like Android, when in reality iOS strictly controls app installation through the App Store, enterprise distribution, or supervised device management tools like Apple Configurator.

How to eliminate wrong answers

Option B is wrong because downloading an app from a third-party website and opening it in Safari is not a supported installation method on iOS; iOS does not allow direct installation from arbitrary websites without enterprise distribution certificates or jailbreaking. Option C is wrong because emailing an app file (.ipa) to users does not work on iOS; the operating system blocks installation of apps from email attachments due to security restrictions. Option D is wrong because iOS does not have a general 'sideloading' toggle in Settings; sideloading via iTunes is limited to free Apple Developer accounts with a 7-day expiry and requires the app to be signed, making it impractical for permanent deployment to five company-owned iPads.

549
MCQmedium

A technician is troubleshooting a DNS resolution issue on a Windows 10 workstation. The user can ping an IP address but not a domain name. Which command should be used to clear the local DNS cache?

A.nslookup example.com
B.ipconfig /flushdns
C.netstat -r
D.ping -a 192.168.1.1
AnswerB

'ipconfig /flushdns' purges the workstation's local DNS resolver cache, forcing fresh queries to the configured DNS servers. Since IP connectivity works, the stale or corrupted cached entry is the fault; flushing it satisfies the requirement to clear the local cache without altering IP configuration.

Why this answer

The `ipconfig /flushdns` command clears the local DNS resolver cache on a Windows 10 workstation. When a user can ping an IP address but not a domain name, it often indicates a stale or corrupted DNS cache entry. Flushing the cache forces the system to query the DNS server for fresh resolution, resolving the issue.

Exam trap

The trap here is that candidates confuse `nslookup` (which queries the DNS server) with a cache-clearing command, not realizing that `nslookup` does not affect the local cache and may return a correct result even when the cache is corrupted.

How to eliminate wrong answers

Option A is wrong because `nslookup example.com` queries an external DNS server directly, bypassing the local cache, and does not clear the cache. Option C is wrong because `netstat -r` displays the IP routing table, not DNS cache information. Option D is wrong because `ping -a 192.168.1.1` performs a reverse DNS lookup to resolve an IP address to a hostname, but it does not clear the DNS cache.

550
MCQeasy

A user calls the help desk, frustrated because their computer is running slowly after installing a new antivirus program. The technician suspects the antivirus is causing high CPU usage. Which of the following is the MOST appropriate initial response?

A.Tell the user to uninstall the antivirus immediately.
B.Explain that antivirus programs always slow down computers and there's nothing to be done.
C.Apologize for the frustration and ask the user to describe when the slowness started.
D.Immediately remote into the computer to check CPU usage.
AnswerC

This is the most appropriate first step as it demonstrates empathy, which is crucial for building user trust and de-escalating frustration. By asking when the slowness started, the technician begins to gather vital diagnostic information, establishing a timeline that can help identify recent changes, software installations, or updates that might correlate with the performance degradation. This approach prioritizes user experience while initiating a structured troubleshooting process.

Why this answer

It follows the CompTIA A+ troubleshooting methodology by first gathering information and showing empathy. The technician needs to confirm the timeline of the slowness relative to the antivirus installation, as other factors (e.g., a Windows update, disk I/O bottleneck, or malware) could be the root cause. Jumping to conclusions without verifying the symptom onset violates the 'identify the problem' step and risks misdiagnosis.

Exam trap

CompTIA often tests the candidate's ability to prioritize the troubleshooting methodology over technical action—the trap here is that many candidates choose Option D because they think immediate remote access is efficient, but the exam emphasizes gathering information and showing empathy as the first step.

How to eliminate wrong answers

Option A is wrong because uninstalling the antivirus immediately removes security protection without confirming it is the cause, and the slowness could stem from a different issue like a pending update or driver conflict. Option B is wrong because it dismisses the user's frustration and is factually incorrect—modern antivirus programs can be tuned (e.g., excluding scheduled scans during peak usage, adjusting real-time protection settings) to minimize performance impact. Option D is wrong because remotely accessing the computer without first explaining the action and obtaining consent violates professional conduct and the user's privacy; the technician should first ask questions to narrow down the problem before taking invasive steps.

551
MCQeasy

A customer reports that their computer is running slowly and they see pop-up ads even when no browser is open. They suspect malware. Which of the following should you perform first to remediate this issue?

A.Run a full antivirus scan
B.Disconnect the computer from the network
C.Reboot the computer in Safe Mode
D.Restore from a recent backup
AnswerB

Disconnecting the computer from the network is the critical first step in malware remediation because it immediately isolates the infected system. This action prevents the malware from communicating with external command-and-control servers, stops data exfiltration, and halts any attempts to spread laterally to other devices on the local network. Containment is paramount before attempting any diagnostic or removal procedures, creating a safe environment for subsequent steps.

Why this answer

Disconnecting the computer from the network is the first step because it immediately stops the malware from communicating with its command-and-control (C2) server, preventing further data exfiltration, additional payload downloads, or remote control. This containment step is critical before any remediation (like scanning or rebooting) to avoid the malware spreading or causing more damage.

Exam trap

The trap here is that candidates often jump to running an antivirus scan (Option A) as the immediate action, but CompTIA emphasizes containment first to prevent further damage or data loss, especially when active C2 communication is suspected.

How to eliminate wrong answers

Option A is wrong because running a full antivirus scan while the computer is still connected to the network allows active malware to continue communicating with its C2 server, potentially downloading more malicious code or exfiltrating data during the scan. Option C is wrong because rebooting into Safe Mode does not immediately stop network-based threats; the malware may still have network access in Safe Mode with networking, and the reboot itself could trigger destructive payloads. Option D is wrong because restoring from a recent backup should only be performed after confirming the backup is clean and the current infection is contained; doing it first risks reinfecting the system from the backup or missing active malware still on the network.

552
MCQmedium

A user reports that their computer has been acting strangely: files are missing, and the mouse cursor moves on its own, opening programs and typing messages. The technician suspects a remote access Trojan (RAT). What is the most effective immediate action to stop the unauthorized access?

A.Run a full antivirus scan while the user is logged off.
B.Disconnect the Ethernet cable and disable Wi-Fi.
C.Change the user's password and log off.
D.Restore the system to a previous restore point.
AnswerB

Immediately disconnecting the Ethernet cable and disabling Wi-Fi is the most crucial initial step when a system is suspected of being compromised by a remote attacker. This action severs the command and control (C2) communication channel, preventing the attacker from issuing further commands, exfiltrating data, or deploying additional malicious payloads. Network isolation effectively quarantines the infected system, stopping the active threat and allowing for safer forensic analysis and remediation.

Why this answer

Disconnecting the Ethernet cable and disabling Wi-Fi immediately severs the remote attacker's connection to the machine, stopping the unauthorized access. This is the most effective immediate action because it cuts off the command-and-control channel that a RAT relies on. Other actions like antivirus scans or password changes may take time and do not immediately stop an active intruder.

Exam trap

The trap is choosing a remediation step (like antivirus scan or password change) that sounds thorough but does not immediately stop an active remote session; candidates must prioritize containment over recovery.

How to eliminate wrong answers

Option A is wrong because running a full antivirus scan, even while logged off, does not immediately terminate the remote session; the RAT may still be active and the scan may not detect it, especially if it's a zero-day or polymorphic. Option C is wrong because changing the password and logging off does not necessarily kill the remote session; the attacker may have established persistence and could reconnect using other credentials or backdoors. Option D is wrong because restoring to a previous restore point is a recovery step, not an immediate containment action, and it may not remove the RAT if the restore point is after infection; also, it does not stop the current unauthorized access.

553
MCQhard

A technician is tasked with decommissioning a server that contains a RAID array of hard drives. The drives are still functional, but the data must be securely erased. What is the most secure method to ensure data cannot be recovered?

A.Perform a quick format of each drive.
B.Overwrite the drives with zeros using a low-level format.
C.Use a degausser to erase the magnetic data on the drives.
D.Physically destroy the drives with a hammer.
AnswerD

Physical destruction is secure but not efficient for multiple drives. Degaussing is faster and equally secure.

Why this answer

Physically destroying the drives (e.g., shredding or hammering the platters) is the most secure method to ensure data cannot be recovered because it makes the magnetic media physically unreadable. Degaussing can randomize magnetic domains but is not guaranteed to work on all modern drives (especially high-coercivity or helium-filled drives) and does not work on SSDs. A quick format only removes logical references to data, and a zero-fill overwrite can leave residual data recoverable.

For decommissioning functional drives where the goal is absolute unrecoverability, physical destruction is the strongest option.

Exam trap

CompTIA tests the misconception that logical erasure methods (quick format, zero-fill) are sufficient for secure data destruction. The trap is recognizing that physical destruction is the most secure method, while degaussing is a strong magnetic sanitization method but not universally guaranteed.

How to eliminate wrong answers

Option A is wrong because a quick format only clears the file system metadata (e.g., the partition table and directory structure) and does not overwrite the actual data on the drives, leaving the data recoverable with data recovery software. Option B is wrong because overwriting with zeros using a low-level format is a logical overwrite that may not reach all sectors on modern drives with internal remapping (e.g., G-List sectors), and it is less effective than degaussing for ensuring unrecoverability, especially against advanced recovery techniques. Option D is wrong because physically destroying drives with a hammer is not the most secure method—it can leave platter fragments from which data might be recovered using specialized equipment, and it is less reliable than degaussing for complete magnetic erasure.

554
MCQeasy

A company is implementing a new policy to prevent tailgating at the main entrance. Which physical security control should they deploy?

A.Security cameras
B.Biometric reader
C.Mantrap
D.Badge reader
AnswerC

A mantrap is a security vestibule featuring two interlocking doors, where only one door can be open at any given time. After an authorized individual authenticates and enters the first door, it closes behind them, and they are then verified again before the second door opens, allowing exit into the secure area. This design physically isolates individuals, ensuring that only one person can pass through the controlled access point at a time, thereby directly and effectively preventing tailgating.

Why this answer

A mantrap is a physical security control consisting of a small space with two sets of interlocking doors, designed to allow only one person through at a time and prevent tailgating. It is the specific control deployed to stop unauthorized individuals from following an authorized person through an entrance. Cameras, biometric readers, and badge readers do not by themselves prevent tailgating.

Exam trap

220-1202 often tests whether candidates can distinguish between detective controls (cameras), authentication controls (biometrics, badges), and preventive physical controls (mantraps), so the trap is choosing an authentication or monitoring device when the question asks for a tailgating prevention control.

How to eliminate wrong answers

Option A is wrong because security cameras are detective controls that record activity but do not physically prevent someone from following another person through a door. Option B is wrong because a biometric reader is an authentication control that verifies identity but does not stop a second person from entering behind an authenticated user. Option D is wrong because a badge reader is also an authentication control and is vulnerable to tailgating when someone slips in behind a badge-holder.

555
MCQeasy

A customer reports that their Windows 10 PC is slow and displays pop-up ads even when no browser is open. They suspect malware. After running a full antivirus scan, the symptoms persist. Which step should you take next to remediate the issue?

A.Reinstall the operating system.
B.Run a scan with a dedicated anti-malware tool like Malwarebytes.
C.Disable Windows Defender permanently.
D.Clear the browser cache and cookies.
AnswerB

Dedicated anti-malware tools, such as Malwarebytes, specialize in detecting and removing Potentially Unwanted Programs (PUPs) and adware that often bypass traditional antivirus software. These utilities employ more aggressive heuristics and signature databases specifically tailored to identify intrusive browser extensions, unwanted toolbars, and persistent pop-up generators, effectively cleaning the system without resorting to more drastic measures.

Why this answer

Standard antivirus software often misses potentially unwanted programs (PUPs) and adware that inject pop-ups into the system. A dedicated anti-malware tool like Malwarebytes uses heuristic analysis and signature databases specifically tuned to detect and remove adware, browser hijackers, and other low-level threats that traditional AV engines may overlook.

Exam trap

CompTIA often tests the distinction between standard antivirus and specialized anti-malware tools, trapping candidates who assume that a full antivirus scan is sufficient to remove all types of malware, especially adware and PUPs.

How to eliminate wrong answers

Option A is wrong because reinstalling the operating system is an extreme, time-consuming step that should only be taken after all other remediation methods have failed, and it does not address the root cause of the infection. Option C is wrong because disabling Windows Defender permanently would remove a critical layer of real-time protection, leaving the system vulnerable to further infections and violating best practices for security. Option D is wrong because clearing browser cache and cookies only removes temporary web data and cannot eliminate adware or malware that is running as a background process or service on the system.

556
MCQmedium

A user reports that their Windows 10 laptop will not boot and displays the error 'Bootmgr is missing'. They have a valid Windows installation USB. Which steps should you take to repair the boot manager?

A.Boot from the USB, go to Troubleshoot > Advanced Options > Command Prompt, and run 'bootrec /rebuildbcd' and 'bootrec /fixmbr'.
B.Boot from the USB and select 'Repair your computer' > 'Startup Repair'.
C.Boot from the USB and run 'sfc /scannow' from the Command Prompt.
D.Boot from the USB and perform a system restore to a previous point.
AnswerA

This is the correct approach because the 'bootrec /fixmbr' command writes a new Master Boot Record (MBR) to the system partition, which is essential if the MBR is corrupted or missing. Subsequently, 'bootrec /rebuildbcd' scans for Windows installations and allows them to be added to the Boot Configuration Data (BCD) store. This combination directly repairs the foundational boot components necessary for the Windows Boot Manager to load, effectively resolving the 'Bootmgr is missing' error.

Why this answer

The 'Bootmgr is missing' error indicates that the Boot Manager (bootmgr) is either corrupted or missing, or the BCD (Boot Configuration Data) store is damaged. Booting from a Windows installation USB and using the Command Prompt via Troubleshoot > Advanced Options allows you to run 'bootrec /rebuildbcd' to scan for Windows installations and rebuild the BCD store, and 'bootrec /fixmbr' to repair the Master Boot Record (MBR) on the system partition. This directly addresses the boot manager issue by restoring the boot configuration and ensuring the MBR points to the correct boot sector.

Exam trap

CompTIA often tests the distinction between automated tools like Startup Repair and manual command-line utilities, leading candidates to choose the simpler option (B) without realizing that specific boot manager errors require targeted commands like 'bootrec' to rebuild the BCD and repair the MBR.

How to eliminate wrong answers

Option B is wrong because Startup Repair is a more automated tool that attempts to fix common boot issues, but it may not specifically rebuild the BCD or repair the MBR in all cases, and it often fails when the BCD is severely corrupted or missing. Option C is wrong because 'sfc /scannow' (System File Checker) scans and repairs protected system files, but it does not repair the boot manager, MBR, or BCD store, which are the root cause of the 'Bootmgr is missing' error. Option D is wrong because System Restore reverts system files, settings, and registry to a previous restore point, but it does not repair the boot manager or BCD; if the boot configuration is corrupted, System Restore may not even run successfully without a functional boot loader.

557
MCQeasy

A user reports that their Windows 10 laptop takes an unusually long time to boot and frequently shows a 'Preparing Automatic Repair' screen before finally loading the desktop. Which Windows tool should be used first to diagnose and potentially fix the boot process?

A.Run the System File Checker (SFC) from an elevated Command Prompt.
B.Perform a full system restore from a backup made last month.
C.Use the Disk Cleanup tool to remove temporary files.
D.Reinstall Windows using the 'Reset this PC' option.
AnswerA

SFC scans and repairs corrupted system files, which can resolve boot delays and automatic repair loops.

Why this answer

The 'Preparing Automatic Repair' loop and slow boot often indicate corruption in critical boot files, such as the Boot Configuration Data (BCD) or system files. Running System File Checker (SFC) from an elevated Command Prompt scans and repairs protected system files, addressing the root cause without data loss. This is the first-line diagnostic tool for boot integrity issues before escalating to more destructive methods.

Exam trap

CompTIA often tests the misconception that Disk Cleanup or a full restore is the appropriate first step for boot issues, when in fact SFC is the correct initial diagnostic tool for file corruption without data loss.

How to eliminate wrong answers

Option B is wrong because performing a full system restore from a backup is a reactive, data-loss-prone step that should only be used after less invasive repairs fail; it does not diagnose the specific boot file corruption. Option C is wrong because Disk Cleanup only removes temporary files and does not repair system files or boot configuration, making it irrelevant to boot loops. Option D is wrong because reinstalling Windows via 'Reset this PC' is a last-resort destructive recovery that wipes applications and settings, and is not the first tool to use for boot file corruption.

558
MCQeasy

During a routine security audit, a technician finds that a user's computer has an unknown program running that is sending keystrokes and screenshots to a remote server. The user did not install this program. Which type of malware is this?

A.Rootkit
B.Worm
C.Keylogger
D.Ransomware
AnswerC

A keylogger, also known as a keystroke logger, is a type of surveillance technology used to monitor and record each keystroke typed on a specific computer's keyboard. Many advanced keyloggers also incorporate additional data capture features, such as periodically taking screenshots, recording clipboard contents, or monitoring web browser activity. This direct and covert capture of both keystrokes and visual information precisely matches the described findings of the security audit.

Why this answer

The described behavior—capturing keystrokes and screenshots and sending them to a remote server—is the defining characteristic of a keylogger. This type of malware specifically records user input and screen activity to steal sensitive data like passwords and personal information, and it often runs without the user's knowledge or consent.

Exam trap

The trap here is that candidates often confuse a keylogger with a rootkit because both can operate stealthily, but the rootkit's primary function is hiding itself and other malware, not capturing keystrokes or screenshots.

How to eliminate wrong answers

Option A is wrong because a rootkit is designed to hide its presence and other malware from the operating system by modifying kernel-level functions, not to capture keystrokes or screenshots. Option B is wrong because a worm is a self-replicating malware that spreads across networks without user interaction, focusing on propagation rather than data theft via keystroke logging. Option D is wrong because ransomware encrypts files or locks the system to demand a ransom, and it does not typically exfiltrate keystrokes or screenshots to a remote server.

559
MCQhard

A company's login script uses a batch file that calls multiple other scripts. Recently, the script stopped working after a Windows update. The technician discovers that the script uses 'call' to run sub-scripts, but one of the sub-scripts contains an 'exit' command that terminates the entire batch process. How should the technician modify the sub-script to prevent this?

A.Replace 'exit' with 'goto :eof'
B.Change 'exit' to 'exit /b'
C.Remove the 'exit' command entirely
D.Use 'endlocal' before 'exit'
AnswerB

The 'exit /b' command is crucial for proper script execution within a larger context, such as a login script called by a system process or another batch file. It terminates only the current batch script, returning control to the calling script or process without closing the command interpreter window. This preserves the execution environment and allows subsequent commands in the calling process to run, which is essential for maintaining the integrity of a multi-stage login process.

Why this answer

The 'exit' command without parameters terminates the entire command interpreter (cmd.exe), which kills the parent batch file as well. Using 'exit /b' instead exits only the current batch script or subroutine, returning control to the calling script. This preserves the intended flow when sub-scripts are invoked via 'call'.

Exam trap

CompTIA often tests the difference between 'exit' (terminates the entire command shell) and 'exit /b' (exits only the current batch script), leading candidates to mistakenly think 'exit' is always safe in sub-scripts.

How to eliminate wrong answers

Option A is wrong because 'goto :eof' is used to jump to the end of the current batch file, but it does not exit a subroutine that was called; it simply transfers control, which may not stop execution of the sub-script if there are more commands after the label. Option C is wrong because removing the 'exit' command entirely would leave the sub-script to continue executing any subsequent commands, potentially causing unintended behavior or an infinite loop. Option D is wrong because 'endlocal' only ends local variable scope set by 'setlocal'; it does not affect the termination behavior of the 'exit' command and does not prevent the parent batch from being terminated.

560
MCQhard

A company deploys a custom app via MDM to Android devices. Users report that the app crashes immediately upon launch. The app works fine on the developer's test device. What is the most likely cause?

A.The MDM profile is corrupt and needs to be re-pushed.
B.The app requires a specific Android API level that is not present on the deployed devices.
C.The devices have insufficient storage space.
D.The app is not signed with the correct enterprise certificate.
AnswerB

Android apps declare a minimum SDK version in their manifest. If deployed devices run an older API level than that minimum, the app cannot load its required runtime components and crashes at launch, whereas the developer's newer test device meets the threshold.

Why this answer

The most likely cause is that the app requires a specific Android API level (e.g., a minimum SDK version) that is not present on the deployed devices. Since the app works on the developer's test device (which likely has a newer or matching API level), but crashes on the target devices, this indicates a compatibility mismatch. MDM deployment does not alter the device's API level, so the app's manifest-defined requirements are not met, leading to an immediate crash on launch.

Exam trap

The CompTIA A+ exam often tests the distinction between installation-time failures (certificate, storage) and runtime failures (API level, missing libraries). The trap here is that candidates may incorrectly attribute a crash to MDM profile corruption or certificate issues, when the actual root cause is an API level mismatch that only manifests at launch.

How to eliminate wrong answers

Option A is wrong because a corrupt MDM profile would typically cause deployment failures (e.g., app not installing or configuration not applying), not a crash upon launch of an already-installed app. Option C is wrong because insufficient storage space would prevent installation or cause a different error (e.g., 'insufficient storage' message), not an immediate crash after the app is already installed and launched. Option D is wrong because an incorrect enterprise certificate would prevent the app from installing at all (due to signature verification failure), not cause a crash after successful installation and launch.

561
MCQmedium

A user reports that their MacBook Pro running macOS Monterey frequently displays a message saying 'Your system has run out of application memory.' They have 16 GB of RAM and are only using Safari and Mail. Which macOS tool should you use to investigate the cause?

A.System Information
B.Terminal with 'vm_stat' command
C.Activity Monitor
D.Console
AnswerC

Activity Monitor is the definitive graphical utility for real-time system resource monitoring on macOS, and its Memory tab is specifically engineered for diagnosing memory-related performance issues. It prominently displays a "Memory Pressure" graph, which visually indicates how efficiently the system is utilizing its RAM, alongside a detailed breakdown of memory usage per process, including "Compressed Memory" and "Swap Used." This comprehensive, user-friendly view empowers technicians to swiftly identify memory-intensive applications, memory leaks, or system-wide memory contention.

Why this answer

Activity Monitor is the correct tool because it provides real-time, graphical monitoring of memory pressure, process-specific memory usage, and the 'Memory' tab's 'Memory Pressure' graph directly indicates whether the system is under memory strain. Since the user has 16 GB of RAM and is only using Safari and Mail, the 'out of application memory' error typically indicates a memory leak or excessive memory consumption by a specific process, which Activity Monitor can pinpoint by sorting processes by memory usage.

Exam trap

The A+ exam often tests the distinction between diagnostic tools by making candidates confuse a static information tool (System Information) or a log viewer (Console) with a real-time performance monitor (Activity Monitor), especially when the symptom is a dynamic resource exhaustion issue.

How to eliminate wrong answers

Option A is wrong because System Information provides a static hardware and software inventory (e.g., RAM type, serial numbers) but does not show real-time memory usage or process-level memory consumption, so it cannot diagnose the cause of a memory pressure event. Option B is wrong because while 'vm_stat' in Terminal shows virtual memory statistics (e.g., page-ins, page-outs), it does not provide a user-friendly, process-level view of memory usage or the 'Memory Pressure' graph, making it less practical for quickly identifying the offending application. Option D is wrong because Console displays system logs and diagnostic messages, which can show kernel panics or app crashes, but it does not offer a live, graphical overview of memory usage or process memory footprints, so it is not the primary tool for investigating memory pressure.

562
MCQhard

A technician is tasked with creating a PowerShell script that will parse a CSV file containing user information and create local user accounts on a Windows 10 machine. The CSV has columns: 'Username', 'FullName', 'Password'. The script must skip any row where the 'Username' is empty. Which control structure should the technician use to handle this requirement?

A.A 'for' loop with a counter to skip empty rows
B.A 'switch' statement to match usernames
C.An 'if' statement to test whether the Username property is not empty
D.A 'try/catch' block to handle errors when creating the account
AnswerC

An 'if' statement is the most direct and appropriate control flow construct for evaluating a specific condition and executing code only if that condition is true. By testing whether the 'Username' property is not null or empty, the script can precisely determine if valid data exists. This allows the script to prevent account creation attempts for incomplete entries, ensuring data integrity and preventing unnecessary errors.

Why this answer

The requirement is to conditionally skip rows based on a property value. An 'if' statement in PowerShell allows you to test whether the 'Username' property is empty or null using a condition like `if ($_.Username -ne '')` and then skip the row with `continue` or simply not process it. This is the most direct and efficient control structure for a simple boolean check on each row.

Exam trap

CompTIA often tests the distinction between control structures used for conditional logic versus iteration or error handling, and the trap here is that candidates may overcomplicate the solution by choosing a loop or switch when a simple conditional check is the most appropriate and efficient choice.

How to eliminate wrong answers

Option A is wrong because a 'for' loop with a counter is unnecessary; it would require manual index tracking and does not inherently skip empty rows without an additional conditional check, making it less efficient and more error-prone than a direct property test. Option B is wrong because a 'switch' statement is designed to match a single value against multiple patterns, not to test whether a property is empty or not; it would be overcomplicated and not the idiomatic choice for a simple null/empty check. Option D is wrong because a 'try/catch' block is used for exception handling during runtime errors (e.g., account creation failure), not for skipping rows based on data validation before processing.

563
MCQeasy

A user reports that their Windows 10 PC is running slowly and they suspect too many programs start automatically. Which tool in the Settings app would you use to disable unnecessary startup programs?

A.System > About
B.Devices > Bluetooth & other devices
C.Update & Security > Troubleshoot
D.Apps > Startup
AnswerD

The "Apps > Startup" section within Windows Settings is the designated interface for users to manage applications configured to launch automatically when the operating system starts. This page provides a clear list of all such programs, often indicating their impact on startup time, and features simple toggle switches next to each entry. Users can easily enable or disable specific applications from starting with Windows, directly addressing the need to control startup items.

Why this answer

The Apps > Startup page in the Windows 10 Settings app provides a list of all startup programs with toggle switches to enable or disable them. This directly addresses the user's issue of too many programs launching automatically, which can slow down boot time and overall performance. The tool shows the impact of each startup item (e.g., 'High', 'Medium', 'Low') to help prioritize which to disable.

Exam trap

The trap here is that candidates often confuse the Apps > Startup page with the Task Manager's Startup tab (accessible via Ctrl+Shift+Esc), but the question specifically asks for a tool 'in the Settings app,' making Apps > Startup the correct choice.

How to eliminate wrong answers

Option A is wrong because System > About displays basic device specifications (e.g., processor, RAM, Windows edition) and does not manage startup programs. Option B is wrong because Devices > Bluetooth & other devices is used to pair and manage Bluetooth peripherals, not to control startup applications. Option C is wrong because Update & Security > Troubleshoot runs automated diagnostic tools for system issues like internet connectivity or audio, but it cannot disable startup programs.

564
MCQeasy

A technician is installing a new power supply in a desktop computer. After connecting all cables, the computer will not power on. What is the most likely safety-related oversight?

A.The power supply is not compatible with the motherboard.
B.The power cord is not securely plugged into the power supply.
C.The voltage selector switch on the power supply is set to the wrong voltage.
D.The power supply fan is blocked by debris.
AnswerC

Many power supplies include a manual voltage selector switch (typically 115V for North America/Japan or 230V for Europe/most other regions) to accommodate different regional electrical standards. Setting this switch incorrectly, such as to 115V in a 230V region, can cause immediate and severe damage to the power supply due to overcurrent, potentially leading to smoke, sparks, or even fire, making it a critical safety oversight during installation. Conversely, setting it to 230V in a 115V region would likely prevent the system from powering on due to insufficient voltage.

Why this answer

The voltage selector switch on the power supply must match the local mains voltage (typically 115V in North America or 230V in Europe). If set to 230V while plugged into a 115V outlet, the power supply will receive insufficient voltage to start, causing the computer to appear completely dead. This is a common safety-related oversight because the switch is often overlooked during installation.

Exam trap

CompTIA often tests the voltage selector switch as a safety-related oversight because candidates mistakenly focus on physical connection issues (like a loose power cord) or component compatibility, overlooking the critical step of matching the power supply to the local mains voltage.

How to eliminate wrong answers

Option A is wrong because power supply compatibility with the motherboard is determined by the form factor (e.g., ATX) and connector types, not by the ability to power on; an incompatible power supply would still typically power on but might not fit or provide correct voltages. Option B is wrong because if the power cord were not securely plugged in, the computer would not power on, but this is a physical connection issue, not a safety-related oversight—the question specifically asks for a safety-related oversight. Option D is wrong because a blocked fan would cause overheating after the system is powered on, not prevent the computer from powering on entirely; the power supply would still start and spin the fan briefly before thermal protection might kick in.

565
MCQeasy

During a security audit, a technician discovers that a company's wireless network uses WEP encryption. The network has been in place for 10 years and still uses the original router. What is the most immediate security risk?

A.The router may not support modern encryption protocols.
B.WEP keys can be easily cracked using tools like Aircrack-ng.
C.The router's firmware is likely outdated and vulnerable to exploits.
D.WEP does not support WPA2-PSK, so clients must use a different protocol.
AnswerB

WEP's RC4 stream cipher with short, reused initialisation vectors allows key recovery from captured traffic in minutes using tools such as Aircrack-ng. This makes the wireless network's confidentiality effectively broken, the most immediate risk given the decade-old router still running WEP.

Why this answer

WEP encryption is fundamentally flawed because it uses the RC4 cipher with a weak initialization vector (IV) that is transmitted in plaintext. Tools like Aircrack-ng can capture enough IVs (typically 20,000–40,000) to derive the WEP key within minutes, regardless of key length. This makes the network trivially vulnerable to unauthorized access and data decryption, which is the most immediate and exploitable risk.

Exam trap

CompTIA often tests the distinction between a hardware limitation (e.g., outdated firmware or lack of protocol support) and a protocol-level cryptographic weakness, where candidates may incorrectly choose a less direct risk instead of the immediate, proven exploitability of WEP.

How to eliminate wrong answers

Option A is wrong because while the router may not support modern protocols, that is a limitation of the hardware, not an immediate security risk—the immediate risk is that WEP itself is broken. Option C is wrong because outdated firmware is a potential vulnerability, but it is not as immediate or certain as the guaranteed cryptographic weakness of WEP, which can be exploited without any firmware bugs. Option D is wrong because WEP does not need to support WPA2-PSK; clients can connect using WEP, and the issue is that WEP is insecure, not that it lacks compatibility with a different protocol.

566
MCQeasy

A user reports that after a recent Windows update, their laptop takes significantly longer to boot and they see a message about 'Preparing Automatic Repair' before the login screen appears. You need to access the advanced startup options to disable automatic restart on system failure. Which tool or feature should you use to boot into the Windows Recovery Environment (WinRE) from a running system?

A.Boot from a Windows installation USB and select 'Repair your computer'.
B.Press F8 repeatedly during boot to access advanced boot options.
C.Hold the Shift key while clicking Restart from the Start menu power options.
D.Open the System Configuration tool (msconfig) and set the boot to 'Safe Mode' under the Boot tab.
AnswerC

Holding the Shift key while clicking 'Restart' from the Start menu's power options is the primary and most direct method to access the Windows Recovery Environment (WinRE) from a running Windows operating system. This action immediately initiates a reboot into WinRE, providing access to troubleshooting tools like System Restore, Startup Repair, and Safe Mode options without requiring any external bootable media. It is the most convenient and intended built-in pathway for users to self-diagnose and repair system issues.

Why this answer

Holding the Shift key while clicking Restart forces the system to boot directly into the Windows Recovery Environment (WinRE) without needing installation media. This method leverages the built-in boot configuration data (BCD) to load the recovery tools, including the option to disable automatic restart on system failure under advanced startup settings.

Exam trap

The trap here is that candidates may confuse the deprecated F8 method (Option B) with the modern Shift+Restart method, or assume that msconfig (Option D) can directly launch WinRE, when in fact it only configures Safe Mode boot options.

How to eliminate wrong answers

Option A is wrong because booting from a Windows installation USB and selecting 'Repair your computer' is a valid way to access WinRE, but it requires external media and is not the most direct method from a running system; the question specifies 'from a running system,' making this an unnecessary extra step. Option B is wrong because pressing F8 during boot to access advanced boot options was deprecated in Windows 8 and later; modern Windows systems use a fast startup process that makes F8 unreliable, and it does not reliably lead to WinRE. Option D is wrong because opening the System Configuration tool (msconfig) and setting the boot to 'Safe Mode' under the Boot tab only configures the system to boot into Safe Mode on the next restart, not into WinRE, and it does not provide access to the advanced startup options needed to disable automatic restart on system failure.

567
MCQmedium

A user calls the help desk because they received a pop-up on their screen claiming their computer is infected with a virus and to call a toll-free number for immediate support. The user did not call the number. What should the technician advise the user to do?

A.Call the number to see if it's legitimate.
B.Ignore the pop-up and continue working.
C.Close the pop-up and run a full antivirus scan.
D.Reboot the computer immediately.
AnswerC

The pop-up is a tech-support scam using scareware, not a genuine infection alert, so the user must not call the number. Closing the browser window and running a full antivirus scan removes any dropped payload and confirms the machine's state.

Why this answer

The pop-up is a classic tech support scam, a form of social engineering. The user should close the pop-up (e.g., using Task Manager or Alt+F4) and immediately run a full antivirus scan to detect and remove any potential malware that may have triggered the pop-up or been downloaded in the background. This ensures the system is cleaned and prevents further compromise.

Exam trap

The trap here is that candidates may confuse a tech support scam pop-up with a legitimate security warning and think calling the number or rebooting is the correct response, but CompTIA emphasizes that the proper procedure is to never engage with the scam and to run a security scan to ensure the system is clean.

How to eliminate wrong answers

Option A is wrong because calling the toll-free number would connect the user to a malicious actor who would attempt to gain remote access or extract payment, directly falling for the social engineering attack. Option B is wrong because ignoring the pop-up and continuing working leaves the system vulnerable; the pop-up may be a symptom of an active infection or a drive-by download, and ignoring it does not address the underlying threat. Option D is wrong because rebooting the computer immediately may allow persistent malware (e.g., a rootkit or scheduled task) to reinitiate the scam pop-up upon startup, and it does not remove the malicious software.

568
MCQmedium

After installing a new application, a user reports that their default web browser keeps changing to a different one without their consent. Which Windows feature can you use to prevent applications from changing file associations and default programs?

A.Programs and Features
B.Default Programs (Control Panel)
C.Local Group Policy Editor
D.Registry Editor
AnswerC

The Local Group Policy Editor (gpedit.msc) provides administrative control to enforce system-wide settings, including default application associations. By configuring the 'Set a default associations configuration file' policy, an administrator can specify an XML file that dictates precise file type and protocol handlers. This policy then actively prevents users or newly installed applications from altering these defined associations, ensuring consistent behavior across the system.

Why this answer

The Local Group Policy Editor (gpedit.msc) allows administrators to configure the 'Set a default associations configuration file' policy under Computer Configuration > Administrative Templates > Windows Components > File Explorer. When enabled, this policy prevents applications from changing file associations and default programs by locking the association file, overriding any user or application changes. This is the correct tool for enforcing system-wide control over default programs in Windows 10/11 Pro, Enterprise, or Education editions.

Exam trap

CompTIA often tests the misconception that Default Programs in Control Panel can lock associations, but it only provides a manual interface for setting them without any enforcement mechanism against application changes.

How to eliminate wrong answers

Option A is wrong because Programs and Features is used to uninstall, change, or repair installed programs, not to prevent applications from changing file associations or default programs. Option B is wrong because Default Programs in Control Panel allows users to manually set file associations and default programs, but it does not prevent other applications from changing them afterward. Option D is wrong because Registry Editor (regedit) can be used to manually modify association keys (e.g., HKEY_CURRENT_USER\Software\Microsoft\Windows\Shell\Associations), but it does not provide a built-in mechanism to lock or prevent changes by other applications.

569
MCQmedium

A user reports that they clicked a link in a text message that appeared to be from their bank, warning of suspicious activity. The link led to a realistic-looking login page, but the user realized it was fake after entering their credentials. What type of social engineering attack is this?

A.Vishing
B.Smishing
C.Pharming
D.Pretexting
AnswerB

Smishing is a specific form of phishing that leverages Short Message Service (SMS), commonly known as text messages, to deliver malicious links or solicit sensitive information. In a smishing attack, users receive a deceptive text message, often impersonating a legitimate entity like a bank or delivery service, which prompts them to click a fraudulent link. This link typically leads to a fake website designed to capture credentials or install malware, directly matching the scenario where a user clicked a link in a text message.

Why this answer

Smishing (SMS phishing) is the correct classification because the attack vector is a text message (SMS) containing a link to a fraudulent website. The user received the message on their mobile device, clicked the link, and entered credentials on a fake login page, which is the hallmark of smishing. Unlike vishing (voice phishing), this attack uses text-based messaging to deliver the malicious link.

Exam trap

The CompTIA A+ exam often tests the distinction between smishing and vishing by focusing on the delivery method (SMS vs. voice), so candidates mistakenly choose vishing when they see 'text message' but focus on the 'warning of suspicious activity' pretext rather than the medium.

How to eliminate wrong answers

Option A (Vishing) is wrong because vishing involves voice calls or voicemail messages that trick victims into revealing information, not text messages with links. Option C (Pharming) is wrong because pharming redirects users from legitimate websites to fraudulent ones via DNS poisoning or local host file manipulation, without requiring the user to click a link in a message. Option D (Pretexting) is wrong because pretexting relies on fabricating a scenario (pretext) to obtain information, typically through direct conversation or impersonation, not via a link in a text message.

570
MCQhard

A company's security policy mandates that all wireless traffic must be encrypted using a protocol that is resistant to KRACK attacks. The current network uses WPA2-PSK with AES. Which of the following upgrades should be implemented to meet this requirement?

A.Change the encryption from AES to TKIP.
B.Enable WPA2-Enterprise with 802.1X.
C.Upgrade to WPA3-Personal.
D.Implement MAC address filtering.
AnswerC

Upgrading to WPA3-Personal is the correct solution because it introduces Simultaneous Authentication of Equals (SAE) as a robust replacement for the WPA2 four-way handshake. SAE provides stronger cryptographic assurances, including forward secrecy, which prevents an attacker from decrypting past traffic even if the session key is compromised. This new handshake design inherently prevents the key reinstallation attacks that KRACK exploits, thereby securing wireless traffic against this specific vulnerability.

Why this answer

WPA3-Personal replaces the Pre-Shared Key (PSK) handshake with Simultaneous Authentication of Equals (SAE), which is resistant to offline dictionary attacks and the KRACK vulnerability that exploits the 4-way handshake in WPA2. Since the policy requires encryption resistant to KRACK attacks, upgrading to WPA3-Personal directly addresses this requirement.

Exam trap

The 220-1202 exam often tests the misconception that changing authentication methods (e.g., from PSK to 802.1X) fixes protocol-level vulnerabilities like KRACK, when in fact the underlying handshake protocol (WPA2) remains the same and still vulnerable.

How to eliminate wrong answers

Option A is wrong because TKIP is an older, less secure encryption protocol that is also vulnerable to KRACK attacks and is deprecated in favor of AES. Option B is wrong because WPA2-Enterprise with 802.1X still uses the same WPA2 4-way handshake, which is susceptible to KRACK attacks; it changes authentication but not the underlying handshake vulnerability. Option D is wrong because MAC address filtering is a basic access control mechanism that does not encrypt traffic and provides no protection against KRACK or any encryption-based attack.

571
MCQmedium

A user reports that their Windows 11 laptop can see the office Wi-Fi network but fails to connect, displaying 'Can't connect to this network'. Other users with the same laptop model connect without issues. The network uses WPA2-PSK with AES. What should you check first?

A.Update the wireless adapter driver.
B.Change the router's security protocol to WPA3.
C.Forget the network on the laptop and reconnect by entering the passphrase again.
D.Disable the firewall on the laptop.
AnswerC

Forgetting the network on the laptop purges the stored Wi-Fi profile, which includes any potentially corrupted or incorrect security keys, SSIDs, and network settings cached by the operating system. Reconnecting forces the laptop to perform a fresh authentication handshake with the access point, prompting the user to re-enter the passphrase. This action is crucial for resolving issues stemming from an incorrect or expired saved credential, effectively resetting the client-side network configuration for that specific SSID.

Why this answer

When a Windows 11 laptop can see the SSID but fails with 'Can't connect to this network' while identical hardware works fine, the most likely cause is a corrupted saved profile or a stale/wrong passphrase cached on that specific machine. Forgetting the network and re-entering the passphrase clears the stored credentials and forces a fresh WPA2-PSK 4-way handshake, which resolves the majority of these single-device failures.

Exam trap

The trap is jumping to driver or hardware fixes when the symptom is isolated to one device — CompTIA tests whether you recognize that a single-device failure with identical hardware points to a configuration/profile issue, not a systemic driver or router problem.

How to eliminate wrong answers

Option A is wrong as a first step because other laptops of the same model connect successfully, which rules out a model-wide driver incompatibility — updating the driver is a valid later step but not the first check. Option B is wrong because changing the router to WPA3 would affect all users and could break compatibility with older devices; it also does not address a single-laptop failure. Option D is wrong because the Windows firewall does not block Wi-Fi association — it filters traffic after the connection is established, so disabling it would not fix a 'can't connect' error.

572
MCQhard

A user's browser is infected with a malicious extension that steals credentials. The extension was installed via a drive-by download from a compromised website. After removing the extension, what additional step should you take to ensure the credentials are not compromised?

A.Clear the browser cache and cookies
B.Run a full antivirus scan
C.Reset the browser settings to default
D.Change all passwords that were entered while the extension was active
AnswerD

Changing all passwords that were entered while the malicious extension was active is the most critical and direct action to mitigate the immediate risk of unauthorized account access. Malicious browser extensions designed for credential harvesting often log keystrokes, intercept form submissions, or read data from web pages. By changing these passwords, the user invalidates any credentials that the extension may have already captured and transmitted, thereby preventing attackers from using the stolen information to log into affected accounts.

Why this answer

A malicious browser extension that steals credentials has already exfiltrated any passwords entered while it was active. Removing the extension stops further theft, but the compromised credentials remain exposed. Changing all passwords ensures that stolen credentials are invalidated, preventing unauthorized access to accounts.

Exam trap

CompTIA often tests the misconception that removing the malicious component or clearing local data is sufficient, when in fact the attacker already has the stolen credentials and only changing passwords remediates the actual compromise.

How to eliminate wrong answers

Option A is wrong because clearing the browser cache and cookies removes local data like session tokens or stored form entries, but does not address credentials that were already sent to an attacker via the extension. Option B is wrong because running a full antivirus scan targets malware on the system, but the malicious extension has already been removed; the core issue is the theft of credentials, not persistent malware. Option C is wrong because resetting browser settings to default removes configurations and extensions, which is redundant after removal, but does not change passwords that were already compromised.

573
Multi-Selecthard

A security incident occurred when an employee disposed of a hard drive by throwing it in the trash. The hard drive contained unencrypted customer data. Which two practices should have been followed to prevent this environmental and security breach? (Choose two.)

Select 2 answers
A.Degauss the hard drive before disposal.
B.Place the hard drive in a secure shredding bin for e-waste.
C.Perform a quick format of the drive before disposal.
D.Delete the files and empty the Recycle Bin.
AnswersA, B

Degaussing involves exposing the hard drive to a powerful, rapidly fluctuating magnetic field. This process randomizes the magnetic domains on the platters, effectively scrambling all stored data beyond any practical means of recovery. It renders the drive permanently inoperable and is a highly effective method for ensuring data sanitization on magnetic media, making it a proper and secure disposal technique.

Why this answer

Option A is correct because degaussing exposes the drive to a strong magnetic field that destroys the magnetic domains holding the data, rendering the hard drive's contents unrecoverable before disposal. Option B is correct because placing the drive in a secure shredding bin for e-waste ensures the media is physically destroyed by an approved vendor, preventing both data remanence and improper environmental disposal. Option C is not sufficient because a quick format only rewrites file system metadata and leaves the underlying data blocks recoverable with forensic tools.

Option D is also inadequate because deleting files and emptying the Recycle Bin only removes references to the data, not the data itself, so the unencrypted customer information would still be recoverable from the discarded drive.

Exam trap

CompTIA often tests the misconception that a quick format or file deletion is sufficient for data sanitization, when in reality these actions only remove logical pointers and leave the underlying data fully recoverable.

574
MCQmedium

A small business owner wants to ensure that all company laptops are protected in case of theft. They need a solution that encrypts the entire hard drive and requires a pre-boot PIN. Which security feature should you implement?

A.Enable EFS (Encrypting File System) on the Documents folder.
B.Set a BIOS password.
C.Enable BitLocker with a TPM + startup PIN.
D.Install a third-party antivirus with encryption.
AnswerC

Enabling BitLocker with a Trusted Platform Module (TPM) and a startup PIN provides robust full disk encryption. The TPM securely stores the encryption keys and verifies the system's boot integrity, while the startup PIN adds a crucial second factor of authentication. This configuration ensures that the entire drive's contents remain encrypted and inaccessible until the correct PIN is entered *before* the operating system even begins to load, effectively protecting all data even if the drive is physically removed.

Why this answer

BitLocker with a TPM + startup PIN provides full-disk encryption and requires a pre-boot authentication PIN, meeting the requirement to protect the entire hard drive in case of theft. The TPM validates system integrity, and the PIN must be entered before the OS loads, preventing unauthorized access even if the drive is removed.

Exam trap

The trap here is that candidates often confuse EFS with full-disk encryption or assume a BIOS password alone secures data, but only BitLocker with TPM + startup PIN provides the required pre-boot authentication and full-drive encryption.

How to eliminate wrong answers

Option A is wrong because EFS encrypts individual files or folders, not the entire hard drive, and does not require a pre-boot PIN; it operates at the file system level after the OS loads. Option B is wrong because a BIOS password only prevents unauthorized users from changing BIOS settings or booting the system, but it does not encrypt the hard drive, leaving data accessible if the drive is removed. Option D is wrong because third-party antivirus with encryption typically offers file-level or folder-level encryption, not full-disk encryption with pre-boot authentication, and antivirus software focuses on malware detection, not drive encryption.

575
MCQeasy

A customer reports that their office printer is emitting a strong, acrid smell and producing distorted prints. The printer uses a fuser unit that has been in service for five years. What should you recommend as the most environmentally responsible action?

A.Replace the entire printer with a new Energy Star model.
B.Replace only the fuser unit and recycle the old one through a certified e-waste recycler.
C.Continue using the printer until it fails completely.
D.Disassemble the printer and dispose of all parts in the general trash.
AnswerB

Replacing only the fuser unit is the correct and most efficient solution, as a burning smell often indicates a failing fuser, which is responsible for fusing toner to paper using heat and pressure. This targeted repair addresses the specific problem without unnecessary expense or waste. Furthermore, recycling the old fuser through a certified e-waste recycler ensures that hazardous materials are handled properly and valuable components are recovered, aligning with environmental best practices and regulations.

Why this answer

The fuser unit is a consumable component that degrades over time, and replacing only the faulty fuser while recycling the old one through a certified e-waste recycler minimizes electronic waste. This approach addresses the root cause (a worn-out fuser) without discarding the entire printer, which would generate unnecessary e-waste and violate environmental best practices.

Exam trap

CompTIA often tests the misconception that a failing component always requires full device replacement, but the trap here is that candidates overlook the environmental impact of e-waste and fail to recognize that consumable parts like fusers are designed to be replaced individually.

How to eliminate wrong answers

Option A is wrong because replacing the entire printer with a new Energy Star model is unnecessarily wasteful; the printer itself is likely still functional, and only the fuser unit needs replacement. Option C is wrong because continuing to use the printer until it fails completely poses a fire hazard from the overheating fuser and may cause further damage to other components, increasing waste and repair costs. Option D is wrong because disposing of all parts in general trash violates e-waste regulations and environmental guidelines, as printer components contain hazardous materials like lead and mercury that require proper recycling.

576
MCQeasy

A user reports that their Windows 10 PC is running slowly and they see many background processes in Task Manager. You need to identify which processes are consuming the most CPU and memory resources without installing any additional software. Which built-in Windows tool should you use?

A.Performance Monitor
B.Resource Monitor
C.Task Manager
D.System Configuration (msconfig)
AnswerC

Task Manager's Processes tab lists every running process with live CPU and memory usage, letting you sort by either column to find the heaviest consumers. It ships with Windows 10, satisfying the constraint of no additional software installation.

Why this answer

Task Manager (Option C) is the correct built-in tool because it provides a real-time, sortable list of all running processes, displaying their CPU and memory usage directly on the Processes tab. This allows you to quickly identify which processes are consuming the most resources without needing to install additional software, as the user specifically requested.

Exam trap

The trap here is that candidates often confuse Resource Monitor (Option B) as the primary tool for resource monitoring, but the question asks for the tool to 'identify which processes are consuming the most CPU and memory resources' without installing software, and Task Manager is the immediate, built-in solution for that specific task.

How to eliminate wrong answers

Option A is wrong because Performance Monitor is a tool for logging and analyzing performance counters over time, not for viewing real-time per-process CPU and memory usage in a simple list. Option B is wrong because Resource Monitor offers more detailed per-process resource data (including disk and network), but it is not the primary tool for a quick, immediate identification of top resource consumers; Task Manager is the first-line tool for this task. Option D is wrong because System Configuration (msconfig) is used to manage startup programs, boot options, and services, not to monitor current CPU or memory consumption of running processes.

577
MCQhard

A technician is tasked with disposing of a failed SSD that contains encrypted financial records. The SSD is non-functional and cannot be powered on. Which method should the technician use to ensure data is destroyed?

A.Use a degausser on the SSD.
B.Perform a secure erase command via SATA interface.
C.Physically shred the SSD using an industrial shredder.
D.Overwrite the SSD with a data wiping tool on another computer.
AnswerC

Physically shredding the SSD using an industrial shredder is the most robust and reliable method for data destruction when a drive has failed and cannot be accessed electronically. This process mechanically breaks the entire device, including all individual NAND flash memory chips, into tiny, unrecognizable fragments. By pulverizing the semiconductor dies where the data is actually stored, it becomes absolutely impossible to reconstruct the original data. This ensures complete and irreversible data sanitization regardless of the drive's operational status.

Why this answer

The SSD is non-functional and cannot be powered on, so any software-based method (secure erase, overwriting) is impossible. Physical destruction via an industrial shredder is the only reliable way to ensure the encrypted financial records are unrecoverable from a dead SSD, as it physically breaks the NAND chips beyond repair.

Exam trap

The trap here is that candidates assume a degausser works on all storage devices, but SSDs are not magnetic media and degaussing has no effect on NAND flash memory.

How to eliminate wrong answers

Option A is wrong because degaussers use a strong magnetic field to erase data on magnetic media (HDDs), but SSDs store data electrically in NAND flash cells and are not affected by magnetic fields; degaussing will not destroy the data and may leave the SSD physically intact. Option B is wrong because a secure erase command requires the SSD to be powered on and functional to execute the ATA Secure Erase command via the SATA interface; a non-functional SSD cannot communicate or execute any command. Option D is wrong because overwriting with a data wiping tool requires the SSD to be connected to another computer and powered on to write new data over the existing data; a dead SSD cannot be recognized or written to.

578
MCQeasy

During a software deployment, you need to ensure that a legacy application always runs with administrative privileges, even for standard users. How can you configure this using Windows built-in tools?

A.Set the application's shortcut to 'Run as administrator' in the Compatibility tab
B.Disable User Account Control (UAC) in the Control Panel
C.Add the user to the local Administrators group
D.Use the 'Run as different user' option from the Shift+right-click menu
AnswerA

Setting the application's shortcut to 'Run as administrator' in the Compatibility tab is the most targeted and secure method for a specific application requiring elevated privileges. This configuration modifies the shortcut's properties to include a flag, instructing Windows to prompt for administrative credentials via User Account Control (UAC) each time the application is launched. This ensures the application consistently runs with the necessary elevated rights without granting the user full administrative privileges for all their activities, adhering strictly to the principle of least privilege.

Why this answer

The Compatibility tab in a shortcut's properties allows you to set the 'Run as administrator' flag, which embeds a compatibility manifest that prompts for elevation via UAC when the application is launched. This ensures the legacy application always runs with administrative privileges, even for standard users, by triggering a credential prompt for an administrator account.

Exam trap

CompTIA often tests the misconception that disabling UAC or adding users to the Administrators group is the correct way to grant admin rights to a single application, when the targeted 'Run as administrator' shortcut setting is the proper built-in method.

How to eliminate wrong answers

Option B is wrong because disabling UAC globally would remove the elevation prompt, but the application would still run with the user's limited privileges, not administrative rights, and it weakens system security. Option C is wrong because adding a standard user to the local Administrators group grants permanent administrative rights to the entire user account, which is excessive and violates the principle of least privilege; it is not a targeted solution for a single application. Option D is wrong because 'Run as different user' allows running an application under a different user account, but it does not automatically grant administrative privileges; the specified user must already have the necessary rights, and it requires manual intervention each time.

579
MCQhard

A technician is called to a user's desk for a 'printer issue.' Upon arrival, the user is on a phone call and waves dismissively at the technician. The technician waits for two minutes, but the user continues their call. What should the technician do?

A.Stand silently until the user finishes the call, even if it takes a long time.
B.Leave a note on the desk saying you were there and will return later, then check back in 15 minutes.
C.Interrupt the call to say you'll come back later.
D.Close the ticket as 'user not available' and move on to the next task.
AnswerB

This is the most professional and efficient course of action. Leaving a note respectfully acknowledges the user's current engagement without interruption, while documenting the technician's presence and intent to return. The specified 15-minute follow-up provides a reasonable timeframe for the user to conclude their call and allows the technician to manage their schedule effectively, demonstrating proactive customer service and time management.

Why this answer

It demonstrates professional respect for the user's current activity while ensuring the issue is addressed. Leaving a note and returning in 15 minutes maintains a service-level commitment without disrupting the user's call, aligning with CompTIA's best practices for customer communication and time management in a support scenario.

Exam trap

The trap here is that candidates may choose Option D (close the ticket) thinking it is efficient, but CompTIA emphasizes that closing a ticket without user consent or follow-up is unprofessional and violates the core principle of customer service.

How to eliminate wrong answers

Option A is wrong because standing silently for an indefinite period wastes technician time and does not proactively manage the support queue; it fails to balance efficiency with customer service. Option C is wrong because interrupting the user's call is unprofessional and could escalate frustration, violating the principle of respecting the user's current engagement. Option D is wrong because closing the ticket as 'user not available' without attempting to reschedule abandons the support request prematurely, which is poor practice and could lead to unresolved issues and negative user experience.

580
MCQeasy

A user calls the help desk frustrated because their laptop will not connect to the company Wi-Fi. They say they have tried restarting the laptop but it still does not work. The technician suspects the wireless adapter driver may be corrupt. What is the best first step for the technician to take?

A.Remotely reinstall the wireless adapter driver.
B.Ask the user if they see any error messages or if other devices connect to the Wi-Fi.
C.Tell the user to bring the laptop to the IT office for a physical inspection.
D.Escalate the ticket to the network team immediately.
AnswerB

Asking the user about error messages and the connectivity of other devices is a critical first step in effective troubleshooting. Error messages provide specific diagnostic clues, while checking other devices helps to quickly determine if the problem is isolated to the user's laptop (client-side issue) or if it's a broader network problem affecting multiple clients or the access point. This information gathering allows for proper problem isolation and guides subsequent troubleshooting steps efficiently.

Why this answer

The best first step is to ask the user if they see any error messages or if other devices can connect to the Wi-Fi, because this gathers critical diagnostic information before taking any action. It helps determine whether the issue is isolated to the laptop or affects the entire network, and whether there are specific error codes that point to driver, authentication, or hardware problems. This aligns with the troubleshooting methodology of identifying the problem and establishing a theory before implementing a solution.

Exam trap

220-1202 often tests the order of troubleshooting steps, causing candidates to jump to a fix (reinstall driver) instead of first gathering information, which is the correct first step in the CompTIA methodology.

How to eliminate wrong answers

Option A is wrong because remotely reinstalling the driver is a corrective action that should only be taken after confirming the driver is actually the cause; doing it first skips the diagnostic step and may waste time or disrupt the user. Option C is wrong because asking the user to bring the laptop in is premature and inconvenient when basic information gathering can be done remotely first. Option D is wrong because escalating to the network team immediately bypasses standard troubleshooting and may be unnecessary if the issue is local to the laptop.

581
MCQeasy

A technician is disposing of a stack of CDs and DVDs that contain backup data from a medical office. The media are labeled with patient information. Which method should the technician use to destroy the data?

A.Use a degausser on each disc.
B.Scratch the surface of each disc with a key.
C.Use a cross-cut shredder that accepts optical discs.
D.Place the discs in a microwave for 10 seconds.
AnswerC

A cross-cut shredder designed for optical media physically destroys the disc by cutting it into numerous small, irregular fragments. This process ensures that the data layer, where information is encoded as pits and lands, is completely obliterated across the entire surface. Reducing the disc to tiny, non-contiguous pieces makes it virtually impossible to reconstruct the original data, providing a highly secure and effective method for irreversible data destruction.

Why this answer

A cross-cut shredder that accepts optical discs physically destroys the media into small pieces, making data recovery impossible. This method is compliant with HIPAA requirements for destroying protected health information (PHI) on CDs and DVDs, as it renders the data irrecoverable through physical destruction.

Exam trap

CompTIA often tests the misconception that degaussing works on all storage media, but the trap here is that optical discs are non-magnetic, so candidates who confuse magnetic media destruction with optical media destruction will incorrectly choose Option A.

How to eliminate wrong answers

Option A is wrong because degaussers use a strong magnetic field to erase data on magnetic media (e.g., hard drives, tapes), but optical discs like CDs and DVDs store data as physical pits and lands on a reflective layer, not magnetically, so a degausser has no effect on them. Option B is wrong because scratching the surface with a key only damages a small portion of the disc; data can still be read from unscratched areas using specialized software, leaving patient information recoverable. Option D is wrong because microwaving discs for 10 seconds may cause physical damage but is unreliable and dangerous—it can create toxic fumes, fire hazards, and may not fully destroy all data layers, especially on dual-layer DVDs, leaving residual data potentially recoverable.

582
MCQmedium

A technician is writing a PowerShell script to check the status of a Windows service on multiple remote computers. The script must output the service name and status for each computer where the service is running. Which cmdlet combination should the technician use to achieve this?

A.Get-Service -ComputerName $computers | Where-Object {$_.Status -eq 'Running'}
B.Invoke-Command -ComputerName $computers -ScriptBlock {Get-Service} | Select-Object Status
C.Get-WmiObject Win32_Service -ComputerName $computers | Where-Object {$_.State -eq 'Running'}
D.Get-Service -Name * -ComputerName $computers | Format-Table -AutoSize
AnswerA

This command leverages the Get-Service cmdlet, which is the standard PowerShell method for interacting with Windows services. The -ComputerName parameter allows specifying one or more remote machines, making it suitable for checking multiple computers. Piped to Where-Object, it filters the results based on the Status property, specifically selecting only those services whose status is 'Running', directly fulfilling the requirement to identify running services.

Why this answer

Get-Service with the -ComputerName parameter can query multiple remote computers directly, and piping its output to Where-Object with the condition {$_.Status -eq 'Running'} filters only services whose Status property equals 'Running'. This meets the requirement to output the service name and status for each computer where the service is running, as Get-Service returns objects containing both Name and Status properties by default.

Exam trap

CompTIA often tests the distinction between Get-Service and Get-WmiObject Win32_Service, where candidates confuse the property names 'Status' vs 'State' and the correct filtering syntax, leading them to choose option C despite its deprecated status and incorrect property reference.

How to eliminate wrong answers

Option B is wrong because Invoke-Command -ScriptBlock {Get-Service} returns service objects from remote computers, but Select-Object Status only outputs the Status property, omitting the service name required by the task. Option C is wrong because Get-WmiObject Win32_Service uses the State property (not Status) to check if a service is running, and the condition {$_.State -eq 'Running'} is incorrect; the correct property value is 'Running' but the property name is 'State', not 'Status', and the cmdlet is deprecated in favor of Get-CimInstance. Option D is wrong because Format-Table -AutoSize only formats the output for display but does not filter for running services; it would output all services regardless of their status, failing to meet the requirement to check only where the service is running.

583
MCQeasy

A user reports that their Windows 10 laptop shows a 'Your license will expire soon' watermark on the desktop, even though they purchased a retail license key. You need to resolve the activation issue. Which Control Panel applet should you use first?

A.Device Manager
B.System
C.Programs and Features
D.User Accounts
AnswerB

The 'System' applet, accessible via Control Panel or Settings in Windows 10, is the correct location for viewing fundamental operating system information. This interface prominently displays details such as the Windows edition (e.g., Home, Pro), system type (32-bit or 64-bit), processor, and installed RAM. Crucially, it also provides the current Windows activation status, indicating whether the copy is activated and allowing users to change the product key or initiate the activation process if necessary.

Why this answer

The System applet (Control Panel > System) provides direct access to the Windows activation status and the 'Change product key' option. Since the user already has a retail license key, the first troubleshooting step is to verify the current activation state and re-enter the key via this applet, which triggers a re-activation with Microsoft's licensing servers.

Exam trap

The trap here is that candidates may confuse activation issues with driver or user account problems, leading them to Device Manager or User Accounts, when the correct first step is always to check the System applet for activation status and key entry.

How to eliminate wrong answers

Option A is wrong because Device Manager is used to manage hardware drivers and devices, not software licensing or activation. Option C is wrong because Programs and Features is for uninstalling or modifying installed applications, not for managing Windows activation or product keys. Option D is wrong because User Accounts handles user profile settings, passwords, and credentials, but does not provide any interface for Windows license activation or product key entry.

584
MCQhard

A user's iPhone is experiencing random restarts and app crashes after installing a new configuration profile for email. The technician needs to remove the profile but cannot find it in Settings. What should the technician check?

A.Check Settings > General > VPN & Device Management
B.Reset the iPhone's network settings
C.Use iTunes to restore the iPhone from a backup
D.Disable iCloud Keychain
AnswerA

Configuration profiles installed on iOS appear under Settings > General > VPN & Device Management, not in the email account list. Removing the profile there clears the email configuration causing the restarts and app crashes, which the technician could not locate elsewhere.

Why this answer

Configuration profiles are managed under Settings > General > VPN & Device Management. When a profile is installed (e.g., for email), it appears in this section, not in the main Settings list. If the profile is missing from the expected location, the technician should check here first to remove it and resolve the random restarts and app crashes.

Exam trap

CompTIA A+ often tests the misconception that configuration profiles are managed like regular app settings or can be removed via network resets or iCloud toggles, when in fact they require the dedicated VPN & Device Management path.

How to eliminate wrong answers

Option B is wrong because resetting network settings clears Wi-Fi passwords and cellular settings but does not remove installed configuration profiles, which are stored separately in the device management area. Option C is wrong because restoring from a backup would reintroduce the problematic profile if it was included in that backup, failing to resolve the issue. Option D is wrong because disabling iCloud Keychain affects password and credit card syncing, not the installation or removal of configuration profiles.

585
MCQmedium

A technician is configuring a wireless network for a new office. The network must support legacy devices that only support WPA-TKIP, but the technician also wants to maximize security for modern devices. Which configuration should the technician use?

A.Enable WPA3-SAE for all devices.
B.Use WPA2-PSK with TKIP encryption.
C.Configure the router for WPA2-PSK with AES and enable WPA-TKIP as a fallback.
D.Set up a separate SSID with WPA-TKIP for legacy devices and another SSID with WPA2-AES for modern devices.
AnswerD

WPA-TKIP and WPA2-AES use incompatible cipher suites, so a single SSID cannot serve both securely. Separate SSIDs let legacy clients associate using TKIP while modern devices negotiate AES-CCMP, satisfying the legacy support requirement without weakening modern encryption.

Why this answer

It isolates legacy WPA-TKIP devices on a separate SSID, preventing the weaker TKIP encryption from compromising the security of modern devices. Modern devices can then connect to a second SSID using WPA2-AES, which provides strong encryption (CCMP) and is not vulnerable to TKIP-specific attacks like Michael MIC exhaustion. This approach satisfies both requirements without forcing all devices onto a single, less secure configuration.

Exam trap

CompTIA often tests the misconception that a mixed-mode SSID (WPA2 with TKIP fallback) is a safe compromise, when in fact it can force all clients to use weaker encryption or cause performance degradation, making separate SSIDs the correct approach for legacy support without compromising modern security.

How to eliminate wrong answers

Option A is wrong because WPA3-SAE is not backward compatible with WPA-TKIP legacy devices; those devices would be unable to connect at all. Option B is wrong because using WPA2-PSK with TKIP encryption forces all devices to use the weaker TKIP protocol, which is deprecated and vulnerable to attacks, and does not maximize security for modern devices. Option C is wrong because configuring WPA2-PSK with AES and enabling WPA-TKIP as a fallback typically forces the router to support a mixed mode (WPA2/WPA mixed) that allows TKIP connections on the same SSID, which can downgrade security for all clients due to TKIP's known weaknesses and the potential for compatibility issues with 802.11n and higher data rates.

586
MCQeasy

During a routine security audit, you discover that several user accounts on a Windows 10 workstation have local administrator privileges when they should only be standard users. You need to quickly review and modify user account types from the command line. Which built-in tool should you use?

A.lusrmgr.msc (Local Users and Groups MMC)
B.net user
C.net localgroup
D.diskpart
AnswerC

The net localgroup command is the correct command-line utility for managing local security group memberships on a Windows system. It allows administrators to view existing local groups, create new ones, delete groups, and critically, add or remove specific user accounts from these groups. This functionality is essential for tasks like adjusting user privileges, enforcing the principle of least privilege, and rectifying unauthorized group memberships identified during a security audit.

Why this answer

The `net localgroup` command is the correct built-in tool for this task because it allows you to both view and modify group memberships from the command line. Specifically, `net localgroup Administrators` lists current members, and `net localgroup Administrators <username> /delete` removes a user from the local Administrators group, effectively demoting them to a standard user. This directly addresses the need to quickly review and change user account types without a GUI.

Exam trap

The trap here is that candidates often confuse `net user` with `net localgroup`, assuming `net user` can change group membership because it manages user accounts, but `net user` only modifies the user object itself, not its group affiliations.

How to eliminate wrong answers

Option A is wrong because `lusrmgr.msc` (Local Users and Groups MMC) is a graphical management console, not a command-line tool, and the question explicitly requires a command-line solution. Option B is wrong because `net user` manages individual user account properties (like password, account expiry) but cannot directly add or remove a user from a local group like Administrators; it lacks the `/add` or `/delete` group membership switches. Option D is wrong because `diskpart` is a disk partitioning tool used for managing disks, volumes, and partitions, and has no functionality for user account or group management.

587
MCQmedium

A technician is tasked with securely connecting a remote office to the main office over the internet. The remote office has 10 users who need access to the same resources as local users. Which of the following remote access methods provides the most secure and scalable solution?

A.Configure port forwarding on the main office router for each required service
B.Set up a site-to-site VPN between the two offices
C.Use Remote Desktop for each user to connect to a workstation at the main office
D.Implement a client-to-site VPN for each user
AnswerB

A site-to-site VPN establishes a secure, encrypted tunnel between the two office networks, effectively making them appear as one contiguous network. This allows all users in the remote office to securely access resources in the main office as if they were locally connected, without individual client configuration. It provides robust network-level security and is highly scalable for connecting entire branch offices.

Why this answer

A site-to-site VPN (often using IPsec or a secure tunnel protocol) creates an encrypted, always-on connection between the two office routers, allowing all 10 users transparent access to the main office resources as if they were on the same LAN. This method is both secure (encrypting all traffic) and scalable (handling multiple users without per-client configuration), making it the best fit for connecting entire networks over the internet.

Exam trap

CompTIA often tests the distinction between site-to-site and client-to-site VPNs, where candidates mistakenly choose client-to-site VPN (Option D) thinking it is more secure per-user, but the question emphasizes 'scalable' and 'connecting a remote office'—a site-to-site VPN is the correct enterprise solution for network-to-network connectivity.

How to eliminate wrong answers

Option A is wrong because port forwarding exposes specific services directly to the internet, creating a large attack surface and requiring manual configuration for each service, which is neither secure nor scalable for multiple users. Option C is wrong because Remote Desktop Protocol (RDP) provides only per-user, per-session access to individual workstations, which is not designed for network-level resource sharing and introduces significant management overhead for 10 users. Option D is wrong because client-to-site VPN requires each user to install and maintain a VPN client, which adds administrative burden and is less scalable than a site-to-site VPN that centralizes the connection at the network edge.

588
MCQmedium

An iOS user is concerned about a lost iPhone and wants to ensure that if the device is erased, it cannot be reactivated without their Apple ID and password. Which iOS security feature provides this protection?

A.Find My iPhone location tracking.
B.Activation Lock, enabled by Find My iPhone.
C.iCloud Keychain with two-factor authentication.
D.Lost Mode in the Find My app.
AnswerB

Activation Lock is a robust anti-theft feature automatically enabled when Find My iPhone is active on an iOS device. This security measure links the device's hardware to the owner's Apple ID, requiring that specific Apple ID and password to erase the device, turn off Find My, or reactivate it after a factory reset. It effectively renders a stolen iPhone useless to anyone but the original owner, significantly deterring theft.

Why this answer

Activation Lock is the iOS feature that binds a device to the owner's Apple ID, so after an erase the device cannot be reactivated without entering the original Apple ID credentials. It is automatically enabled when Find My iPhone is turned on, which is why the correct answer pairs the two. This directly satisfies the user's requirement that a wiped device remain unusable to a thief.

Exam trap

The trap is conflating 'find/locate' features (Find My iPhone, Lost Mode) with 'anti-reactivation' protection — only Activation Lock, enabled by Find My iPhone, prevents a wiped device from being reused.

How to eliminate wrong answers

Option A is wrong because Find My iPhone location tracking only helps locate a device — it does not prevent reactivation after an erase. Option C is wrong because iCloud Keychain with 2FA protects credential syncing, not device reactivation. Option D is wrong because Lost Mode locks and displays a message on the device but does not by itself prevent reactivation after an erase; that protection comes from Activation Lock.

589
MCQeasy

A user reports that their MacBook Pro running macOS Ventura suddenly lost all desktop icons and the menu bar is missing. They can still move the cursor and click on open applications. Which macOS feature or tool should you use to restore the desktop and menu bar?

A.Restart the MacBook by holding the power button.
B.Open Activity Monitor and force quit the WindowServer process.
C.Use Force Quit (Cmd+Option+Esc) and select Finder, then click Relaunch.
D.Run the command 'sudo killall Dock' in Terminal.
AnswerC

This is the correct method to restart the Finder process, which controls the desktop, menu bar, and file system display. It is a standard macOS troubleshooting step.

Why this answer

The Finder process manages the desktop icons and the menu bar in macOS. When the Finder becomes unresponsive or crashes, relaunching it via Force Quet (Cmd+Option+Esc) restores the desktop environment and menu bar without requiring a full system restart. This is the standard troubleshooting step for a hung Finder that still allows cursor movement and interaction with open applications.

Exam trap

Candidates often confuse the Finder and the Dock, mistakenly choosing 'sudo killall Dock' because they think the Dock is responsible for the desktop and menu bar, when in fact the Finder manages those elements.

How to eliminate wrong answers

Option A is wrong because holding the power button performs a forced shutdown, which is overly aggressive and can cause data loss or file system corruption; a normal restart via Apple menu or keyboard shortcut is preferred, but even that is unnecessary when the Finder can be relaunched. Option B is wrong because force quitting the WindowServer process would terminate the entire windowing system, causing all graphical elements (including open applications) to disappear and requiring a login window restart, which is excessive for a Finder-only issue. Option D is wrong because 'sudo killall Dock' only restarts the Dock process, which manages the application dock and not the desktop icons or menu bar; the desktop and menu bar are controlled by the Finder, not the Dock.

590
MCQhard

A security incident has occurred: an employee's workstation was used to access unauthorized websites. The manager wants to review recent web browsing history and application usage. Which administrative tool can provide a comprehensive timeline of user activity on the Windows 10 system?

A.Performance Monitor to create a trace of user actions.
B.Task Scheduler to view past task executions.
C.Event Viewer to examine Security and Application logs for user activity.
D.Local Users and Groups to check user group memberships.
AnswerC

Correct. Event Viewer logs security events (logons) and application events, which can help reconstruct user activity.

Why this answer

Event Viewer is the correct administrative tool because it consolidates Security logs (e.g., event ID 4624 for logons, 4648 for explicit logon attempts) and Application logs that record user activity such as web browsing and application launches. By filtering these logs, a manager can reconstruct a timeline of user actions on the Windows 10 system, including unauthorized website access.

Exam trap

CompTIA often tests the misconception that Performance Monitor can trace user actions because of its name, but it is strictly a performance data collector, not an activity logger.

How to eliminate wrong answers

Option A is wrong because Performance Monitor is designed to collect performance counters and system resource usage data, not to log user activity or web browsing history; it cannot provide a timeline of user actions. Option B is wrong because Task Scheduler only shows scheduled tasks and their execution history, not arbitrary user-initiated activities like web browsing or application usage. Option D is wrong because Local Users and Groups is used to manage user accounts and group memberships, not to audit or review past user activity.

591
MCQeasy

A customer needs to transfer their user profile, documents, and application settings from an old Windows 7 PC to a new Windows 10 PC. Which Windows tool is specifically designed for this purpose?

A.Windows Easy Transfer
B.File History
C.User State Migration Tool (USMT)
D.Windows Backup and Restore
AnswerC

The User State Migration Tool (USMT) is a command-line utility provided by Microsoft as part of the Windows Assessment and Deployment Kit (ADK), specifically designed for IT professionals to migrate user profiles, files, and operating system settings during large-scale Windows deployments. It captures a user's entire "state" from a source computer using `scanstate` and then restores it to a new or reinstalled Windows machine using `loadstate`, making it ideal for transferring comprehensive user profile documents and settings.

Why this answer

The User State Migration Tool (USMT) is a command-line utility designed for IT professionals to automate large-scale user state migrations, including user profiles, documents, and application settings, from one Windows OS to another. It supports migration from Windows 7 to Windows 10 and provides granular control over what is transferred via XML configuration files.

Exam trap

A common mistake is thinking Windows Easy Transfer is still available for Windows 7 to Windows 10 migrations, but it was removed after Windows 8. USMT is the correct enterprise-grade tool for this scenario, as it is included in the Windows Assessment and Deployment Kit (ADK).

How to eliminate wrong answers

Option A is wrong because Windows Easy Transfer was deprecated starting with Windows 8 and is not available for migrating from Windows 7 to Windows 10; it was a consumer tool that did not support cross-version migrations in later OS releases. Option B is wrong because File History is a backup feature that only protects personal files in libraries, not user profiles or application settings, and is not designed for migrating to a new PC. Option D is wrong because Windows Backup and Restore creates system image backups or file backups but does not specifically migrate user profiles and application settings to a new operating system version; it is intended for disaster recovery, not user state transfer.

592
MCQmedium

An employee's company-issued Android phone is suddenly displaying pop-up ads even when no browser is open. The employee claims they only downloaded apps from the official Google Play Store. Which of the following is the MOST likely cause?

A.The phone's firmware is outdated.
B.A recently installed app has been granted 'Draw over other apps' permission.
C.The phone's Wi-Fi network is infected with malware.
D.The phone's screen has a hardware defect causing ghost touches.
AnswerB

The 'Draw over other apps' permission, also known as 'Display over other apps' or 'Overlay permission,' grants an application the ability to render its content on top of any other running application or the system UI. Malicious adware frequently leverages this powerful permission to display intrusive, unsolicited advertisements that appear suddenly and cover legitimate app content, making them difficult to dismiss and often obscuring the actual source. This behavior is a hallmark of adware that aims to force ad impressions onto the user.

Why this answer

The 'Draw over other apps' permission allows an app to display content on top of other applications, including the home screen and lock screen. This is a common technique used by adware and malicious apps to serve persistent pop-up ads even when no browser is open, as the app can draw its own window outside of the normal app lifecycle. Since the employee only downloaded from Google Play, this permission abuse is the most likely cause, as even Play Store apps can be granted this permission by the user during installation or runtime.

Exam trap

CompTIA often tests the distinction between network-level threats (like DNS hijacking) and client-side permission abuse, so the trap here is that candidates may assume pop-up ads always come from browser-based malware or network injection, rather than recognizing the 'Draw over other apps' permission as the specific Android mechanism for persistent on-screen overlays.

How to eliminate wrong answers

Option A is wrong because an outdated firmware (system software) typically causes security vulnerabilities or performance issues, but it does not directly cause pop-up ads to appear; adware behavior is tied to app-level permissions, not firmware version. Option C is wrong because a Wi-Fi network infected with malware would typically intercept or redirect web traffic, not inject pop-up ads into the Android UI layer; pop-ups that appear without a browser open are a client-side overlay issue, not a network-level attack. Option D is wrong because ghost touches from a hardware defect would cause random taps and interactions, not the display of structured pop-up ads with specific content; ghost touches cannot generate ad windows with text and images.

593
MCQhard

A technician needs to configure a Windows 10 kiosk machine that runs a single full-screen application for public use. They want to prevent users from accessing the desktop, taskbar, or any other system functions. Which Settings page should they use to set up this restricted user experience?

A.Settings > Personalization > Start
B.Control Panel > User Accounts > Manage User Accounts
C.Settings > Accounts > Other users > Set up a kiosk
D.Local Group Policy Editor > Computer Configuration > Windows Settings > Security Settings
AnswerC

This is the correct and most direct path in Windows 10 for configuring a single-app kiosk. The 'Set up a kiosk' option utilizes the 'Assigned Access' feature, which creates a highly restricted user experience. It allows an administrator to designate a specific user account to run only one Universal Windows Platform (UWP) application in full-screen mode, preventing access to the desktop, Start menu, taskbar, or other system functions, thereby ensuring a true kiosk environment.

Why this answer

The 'Set up a kiosk' option under Settings > Accounts > Other users is the dedicated Windows 10 feature for configuring an assigned access kiosk. This setting restricts the user to a single full-screen Universal Windows Platform (UWP) app and blocks access to the desktop, taskbar, and other system functions, meeting the exact requirement for a public-facing kiosk.

Exam trap

The trap here is that candidates often confuse the 'Set up a kiosk' feature with Group Policy security settings or user account management, mistakenly thinking that locking down a kiosk requires complex policy edits rather than the simple, built-in Settings wizard.

How to eliminate wrong answers

Option A is wrong because Settings > Personalization > Start only controls Start menu appearance and layout, not the ability to lock down the entire user experience or prevent desktop access. Option B is wrong because Control Panel > User Accounts > Manage User Accounts is used for standard user account management (creating, deleting, changing passwords) and does not provide any kiosk or restricted shell configuration. Option D is wrong because Local Group Policy Editor > Computer Configuration > Windows Settings > Security Settings deals with security policies like password policies, audit policies, and user rights assignments, not the assigned access kiosk mode which is configured via Settings or the 'Set up a kiosk' wizard.

594
MCQhard

A user reports that a script they run daily now fails with 'Text file busy' error. The script is located on an NFS mount. Which command will show if the script is currently being used by another process?

A.fuser /path/to/script
B.ps aux | grep script
C.lsof /path/to/script
D.strace -p $(pgrep script)
AnswerC

lsof lists all open files and the associated processes; it will show if the script is in use.

Why this answer

`lsof /path/to/script` lists all processes that have the file open, including those holding it for execution. The 'Text file busy' error occurs when a process is executing the script (the text segment is mapped), and `lsof` can detect this by showing the file descriptor or memory mapping for the running process.

Exam trap

The A+ exam often tests the distinction between `lsof` and `fuser`; the trap here is that candidates assume `fuser` is sufficient, but `fuser` may not report processes that have the file mapped for execution (text segment) on NFS mounts, whereas `lsof` reliably shows all open file descriptors and memory mappings.

How to eliminate wrong answers

Option A is wrong because `fuser /path/to/script` shows the PID(s) of processes using the file, but it does not distinguish between a file being open for reading/writing and a file being executed (text segment busy), and it may not reliably detect the 'Text file busy' condition on NFS mounts. Option B is wrong because `ps aux | grep script` only shows processes whose command line contains 'script', but it does not directly confirm that the file itself is open or being executed by another process. Option D is wrong because `strace -p $(pgrep script)` attaches to a process with 'script' in its name and traces its system calls, but it does not show whether the script file is busy; it also requires the script process to be running and named exactly 'script', which may not be the case.

595
MCQhard

A technician is responding to a security incident where an employee's credentials were used to access a server without authorization. The employee claims they did not perform the action. Which of the following should the technician do first to remediate the compromised account?

A.Reset the account password and enable MFA.
B.Disable the account to prevent further access.
C.Review the server logs to determine the extent of the breach.
D.Notify the employee's manager and HR department.
AnswerB

Disabling the compromised account is the paramount first step in incident response, specifically within the containment phase. This action immediately revokes all authentication tokens and active sessions associated with the account, effectively severing the attacker's current access and preventing any further unauthorized actions or data exfiltration. It provides a critical window for the security team to investigate and remediate the breach without the attacker continuing to operate within the system.

Why this answer

The immediate step is to disable the compromised account to prevent further unauthorized access. Then the technician should force a password reset and enable multi-factor authentication (MFA) to secure the account. Logging and investigation follow containment.

596
MCQmedium

During a software deployment, a user reports that a stranger in a delivery uniform asked to use their computer to 'check a shipment status' and then quickly left. Later, the user notices unusual network activity. What should the technician investigate first?

A.Check the user's email for phishing messages.
B.Verify the delivery person's identity with the shipping company.
C.Scan the workstation for malware and review recent system changes.
D.Disable the user's network access permanently.
AnswerC

Unauthorized physical access to a workstation creates a high probability that an attacker could have installed malicious software, altered system configurations, or created backdoors for future access. Scanning for malware identifies immediate threats, while reviewing recent system changes helps pinpoint unauthorized modifications, making these crucial first steps in containment, eradication, and investigation to restore system integrity.

Why this answer

The scenario describes a classic social engineering attack where an unauthorized individual gains physical access to a workstation under a pretext. The immediate technical priority is to scan the workstation for malware and review recent system changes because the attacker may have installed a backdoor, keylogger, or remote access trojan (RAT) that explains the unusual network activity. This aligns with incident response best practices: isolate and analyze the affected system first to contain potential data exfiltration or lateral movement.

Exam trap

The CompTIA A+ exam often tests the candidate's ability to prioritize immediate technical containment over administrative or non-technical follow-ups; the trap here is that many candidates choose Option B (verifying identity) because it seems logical for a physical security breach, but the exam expects you to recognize that the workstation is already compromised and must be investigated first.

How to eliminate wrong answers

Option A is wrong because checking the user's email for phishing messages addresses a different attack vector (email-based social engineering), but the incident here involved direct physical access, not a phishing link. Option B is wrong because verifying the delivery person's identity with the shipping company is a non-technical, administrative step that does not address the immediate technical threat of malware or unauthorized system changes already present on the workstation. Option D is wrong because permanently disabling the user's network access is an overreaction and violates the principle of least disruption; a temporary network isolation (e.g., disabling the NIC or blocking the port) is appropriate, but permanent access removal is not a diagnostic or containment step.

597
MCQmedium

A technician is configuring a new Windows 10 workstation for a user who handles sensitive financial data. The company policy mandates that the screen lock after 5 minutes of inactivity and require a password on wake. Which settings should the technician configure?

A.Set the power plan to turn off the display after 5 minutes.
B.Configure the screen saver to start after 5 minutes and check 'On resume, display logon screen.'
C.Enable the 'Require password on wakeup' setting in the power plan only.
D.Set the computer to sleep after 5 minutes and require a password on wake.
AnswerB

Configuring the screen saver to activate after 5 minutes of inactivity, combined with checking the 'On resume, display logon screen' option, directly addresses the requirement. The screen saver initiates after the specified idle period, and the critical checkbox ensures that upon any user input to dismiss the screen saver, the Windows logon screen is presented. This effectively locks the user's session, requiring re-authentication and thus securing the workstation as per policy.

Why this answer

The screen saver with 'On resume, display logon screen' enforces a lock after 5 minutes of inactivity and requires a password to unlock. This directly meets the policy requirement for screen lock and password on wake. The power plan display timeout only turns off the display but does not lock the session, so it does not require a password to resume.

Exam trap

The trap is confusing display timeout or sleep with screen lock; candidates may think turning off the display or sleeping locks the session, but only the screen saver with password protection or explicit lock policy does.

How to eliminate wrong answers

Option A is wrong because turning off the display after 5 minutes does not lock the workstation; the session remains active and no password is required to resume. Option C is wrong because the 'Require password on wakeup' setting in the power plan applies to sleep/hibernate, not to screen saver lock, and it does not enforce a 5-minute inactivity lock. Option D is wrong because setting the computer to sleep after 5 minutes and requiring a password on wake does lock the session, but sleep is a power state that may disrupt user workflows and is not the standard method for screen lock policy; the screen saver method is the correct configuration for inactivity lock.

598
MCQmedium

A technician is on a support call with a user who has a strong accent and is speaking quickly. The technician is having difficulty understanding the issue. What is the most professional way to handle this?

A.Pretend to understand and hope the issue becomes clear during troubleshooting.
B.Ask the user to speak more slowly and repeat the problem, apologizing for the difficulty.
C.Transfer the call to a different technician who might understand the accent better.
D.Tell the user that their accent is hard to understand and ask them to email the problem instead.
AnswerB

This is the most professional and effective approach for a technician. By politely asking the user to slow down and repeat, the technician demonstrates active listening and a genuine commitment to understanding the issue, fostering a positive customer experience. Apologizing for the difficulty, even if it's a communication barrier, shows empathy and helps de-escalate potential frustration, paving the way for accurate problem identification and resolution.

Why this answer

It demonstrates active listening and professional courtesy by politely asking the user to slow down and repeat the issue. This approach maintains rapport, ensures accurate information gathering, and avoids misdiagnosis that could lead to wasted time or incorrect troubleshooting steps. In a support context, clear communication is essential for identifying the root cause and applying the correct fix.

Exam trap

CompTIA often tests the candidate's ability to prioritize professional communication over technical shortcuts, and the trap here is that candidates may choose Option C (transfer the call) thinking it is efficient, but it actually violates the principle of taking ownership of the customer's issue.

How to eliminate wrong answers

Option A is wrong because pretending to understand risks missing critical details about the problem, leading to ineffective or even harmful troubleshooting steps that could escalate the issue or violate service-level agreements. Option C is wrong because transferring the call without first attempting to clarify the issue is unprofessional and may not resolve the communication barrier; it also wastes time and shifts responsibility unnecessarily. Option D is wrong because telling the user their accent is hard to understand is disrespectful and unprofessional, and asking them to email the problem bypasses real-time interaction, potentially delaying resolution and frustrating the user.

599
MCQmedium

A company is decommissioning a server that contained encrypted customer financial data. The IT manager wants to ensure the data is destroyed without damaging the hard drives, as they will be reused in test environments. Which method should be used?

A.Physically shred the drives.
B.Perform a standard format and reinstall the OS.
C.Issue a cryptographic erase command to the drive's self-encrypting feature.
D.Use a degausser on the drives.
AnswerC

Issuing a cryptographic erase command to a self-encrypting drive (SED) is the most secure and efficient method for data sanitization while preserving drive functionality. This command instructs the drive's built-in encryption controller to instantly generate and apply a new, random encryption key, effectively rendering all previous data unreadable and irrecoverable with the old key. Since the data itself remains encrypted but inaccessible, the drive can be immediately reused or repurposed without physical destruction or lengthy overwriting processes.

Why this answer

The server's hard drives are self-encrypting drives (SEDs) that support the TCG Opal or IEEE 1667 standard. Issuing a cryptographic erase command (e.g., via hdparm --security-erase or a vendor tool) instantly invalidates the media encryption key, rendering all data on the drive permanently inaccessible without physically damaging the drive. This meets the requirement of destroying the encrypted customer financial data while preserving the drives for reuse in test environments.

Exam trap

A common misconception tested on the CompTIA A+ exam is that a standard format or OS reinstall is sufficient for secure data destruction. However, encrypted data on SEDs remains recoverable unless the encryption key is specifically invalidated via a cryptographic erase command.

How to eliminate wrong answers

Option A is wrong because physically shredding the drives destroys them, contradicting the requirement to reuse them in test environments. Option B is wrong because a standard format and OS reinstall only overwrites file system metadata and does not securely erase the underlying encrypted data; the original media encryption key remains intact, and data could potentially be recovered from the encrypted sectors. Option D is wrong because using a degausser applies a strong magnetic field that destroys the drive's firmware, servo tracks, and the self-encrypting capability, making the drive permanently unusable and violating the reuse requirement.

600
MCQeasy

A user reports that their browser frequently redirects to a search page they never set, and they see unfamiliar toolbars. After running a malware scan that found nothing, what should the technician do next to resolve the issue?

A.Replace the network cable.
B.Reset the browser settings to default.
C.Update the network adapter driver.
D.Reinstall the operating system.
AnswerB

Browser hijackers persist via extensions, search providers and homepage settings that malware scans often miss. Resetting settings to default removes these unwanted modifications, restoring the browser to a clean state and eliminating the redirects and toolbars the user reported.

Why this answer

The symptoms—unwanted redirects and unfamiliar toolbars—are classic signs of browser hijacking, often caused by a malicious extension or a changed proxy configuration. Since a malware scan found nothing, the next logical step is to reset the browser settings to default, which removes all extensions, restores the homepage and search engine, and clears cached data that may be enforcing the redirects. This action directly addresses the most common vector for such behavior without resorting to hardware or OS-level changes.

Exam trap

The trap here is that candidates often jump to reinstalling the OS or scanning for malware again, but CompTIA tests whether you recognize that browser-specific issues are best resolved with browser-level tools before escalating to system-wide repairs.

How to eliminate wrong answers

Option A is wrong because replacing the network cable would only fix physical connectivity issues, not software-based browser hijacking or redirects caused by extensions or proxy settings. Option C is wrong because updating the network adapter driver addresses hardware-level network communication problems, not browser-level configuration or add-on issues. Option D is wrong because reinstalling the operating system is an extreme, time-consuming measure that is unnecessary when the problem is isolated to the browser; resetting browser settings is a far more targeted and efficient first step.

Page 7

Page 8 of 10

Page 9

All pages

Practice 220-1202 by domain

Target a specific domain to shore up weak areas.

See all domains with question counts →