Courseiva

CompTIA A+ Core 2 220-1202 (220-1202) — Questions 601–675

687 questions total · 10pages · All types, answers revealed

Page 8

Page 9 of 10

Page 10
601
MCQhard

A user's MacBook Air running macOS Ventura is experiencing intermittent kernel panics. The crashes seem to occur when the laptop is connected to a specific USB-C hub. Which macOS tool should you use to analyze the crash logs and identify the faulty driver?

A.System Information
B.Console
C.Activity Monitor
D.Terminal with 'sudo dmesg' command
AnswerB

Console allows you to view kernel panic logs and filter them by date and process to identify the problematic driver.

Why this answer

The Console app is the correct tool because it provides a centralized interface for viewing all system logs, including kernel panic reports (stored in /Library/Logs/DiagnosticReports). When a kernel panic occurs, macOS generates a .panic file containing stack traces and loaded kext (kernel extension) information. By examining these logs in Console, you can identify the specific kext or driver (e.g., a USB hub driver) that triggered the panic, especially when the crash is hardware-dependent like this USB-C hub scenario.

Exam trap

CompTIA tests the misconception that System Information or Activity Monitor can retrieve historical kernel panic reports. While System Information shows hardware and software details, and Activity Monitor shows live resource usage, the Console app is the standard tool for viewing persistent kernel panic reports and system logs across reboots.

How to eliminate wrong answers

Option A is wrong because System Information provides a static snapshot of hardware and software configuration (e.g., USB device tree, kext versions) but does not display real-time or historical crash logs; it cannot show the dynamic stack traces needed to pinpoint a faulty driver. Option C is wrong because Activity Monitor shows running processes, CPU/memory usage, and system resource statistics, but it does not capture kernel panic logs or driver-level crash data. Option D is wrong because 'sudo dmesg' displays kernel ring buffer messages from the current boot session only; after a kernel panic and reboot, the dmesg buffer is cleared, so it cannot show the panic log from the previous crash.

602
MCQeasy

A system administrator is deploying a PowerShell script to 100 computers to change the local administrator password. The script must run once per computer and then exit. Which scripting technique ensures the script runs exactly once on each machine?

A.Use a for loop to run the script 100 times
B.Write a registry key after successful execution
C.Use a parameter to pass the computer name
D.Schedule the script to run daily
AnswerB

Implementing a registry key as an execution flag is a robust method to ensure a script runs only once per machine. After the script successfully completes its intended task, it can create a specific registry key (e.g., HKLM:\SOFTWARE\MyCompany\MyScript\Executed). Subsequent executions of the script would first check for the presence of this key; if found, the script would immediately terminate, preventing redundant operations and ensuring idempotence on each target system.

Why this answer

Writing a registry key after successful execution is the standard idempotency technique in PowerShell scripting. The script checks for the presence of the registry key at startup; if the key exists, the script exits without making changes, ensuring it runs exactly once per machine. This pattern is commonly used in login scripts, SCCM packages, and configuration management.

Exam trap

The trap is confusing 'run on 100 computers' with 'run 100 times,' leading candidates to pick the for loop, when the real requirement is idempotent single execution per machine.

How to eliminate wrong answers

Option A is wrong because a for loop running the script 100 times would execute it repeatedly on the same machine, not once per machine across 100 computers. Option C is wrong because passing a computer name as a parameter does not control execution frequency; it only tells the script which machine to target. Option D is wrong because scheduling the script to run daily would cause it to execute repeatedly, violating the requirement to run exactly once.

603
MCQmedium

A small business owner wants to ensure that all company laptops have their hard drives encrypted in case of theft. The laptops run Windows 10 Pro. Which technology should the technician enable to meet this requirement?

A.EFS (Encrypting File System)
B.Windows Defender Antivirus
C.BitLocker Drive Encryption
D.TPM (Trusted Platform Module)
AnswerC

BitLocker Drive Encryption is a full-disk encryption feature included with Windows Pro and Enterprise editions that encrypts an entire volume, typically the operating system drive. By encrypting all data at rest, BitLocker ensures that even if a laptop is lost or stolen, the data remains inaccessible without the correct decryption key or recovery password. This comprehensive protection is crucial for safeguarding sensitive business information against physical device compromise, directly addressing the need for data protection on lost or stolen laptops.

Why this answer

BitLocker Drive Encryption (option C) is the correct technology because it provides full-disk encryption for Windows 10 Pro, ensuring that all data on the laptop's hard drive is encrypted at rest. This protects against data exposure if the device is stolen, as the drive cannot be accessed without the decryption key (e.g., a PIN, USB key, or TPM-based authentication). BitLocker is built into Windows 10 Pro and is specifically designed for whole-drive encryption, meeting the requirement for all company laptops.

Exam trap

The trap here is that candidates often confuse EFS (file-level encryption) with full-disk encryption, or they mistakenly think TPM alone provides encryption, when in fact TPM is merely a key storage and attestation component that requires BitLocker to enable drive encryption.

How to eliminate wrong answers

Option A is wrong because EFS (Encrypting File System) encrypts individual files or folders at the file system level, not the entire hard drive, and it does not protect system files or the operating system from offline access after theft. Option B is wrong because Windows Defender Antivirus is a malware protection tool that detects and removes malicious software; it does not provide any encryption or data protection for the hard drive. Option D is wrong because TPM (Trusted Platform Module) is a hardware security chip that can store encryption keys and support BitLocker, but it is not an encryption technology itself—it must be combined with BitLocker to achieve full-disk encryption.

604
MCQeasy

A small business is deploying a new accounting application across five workstations. The IT lead creates a detailed change request that includes the purpose, scope, risk assessment, and rollback plan. Which document should the IT lead update immediately after the deployment is successfully completed?

A.The firewall configuration log
B.The change request form
C.The employee handbook
D.The backup verification checklist
AnswerB

The change request form (CRF) is a formal document used within IT service management (ITSM) frameworks, such as ITIL, to initiate, track, and approve modifications to IT infrastructure, services, or applications. It details the proposed change, its justification, impact analysis, approval signatures, implementation plan, and crucially, the actual completion date and verification of the change. Therefore, it serves as the authoritative record for confirming the successful deployment of a new accounting application.

Why this answer

The change request form is the central document that tracks the entire lifecycle of a change, including planning, approval, implementation, and post-implementation review. Once the deployment is successfully completed, the IT lead must update the change request form to mark it as 'Closed' or 'Completed,' documenting the actual outcome, any deviations, and the final status. This ensures an accurate audit trail for compliance and future troubleshooting, as required by ITIL-based change management processes.

Exam trap

CompTIA often tests the misconception that a technical log or checklist (like a backup verification checklist) is the immediate post-deployment update, but the correct answer is always the formal change management document that captures the entire change lifecycle.

How to eliminate wrong answers

Option A is wrong because the firewall configuration log is a security-specific record that would only be updated if firewall rules were modified as part of the deployment; the question describes a standard application installation with no mention of firewall changes. Option C is wrong because the employee handbook is a general HR policy document that outlines company rules and procedures, not a technical record for tracking IT changes or deployments. Option D is wrong because the backup verification checklist is used to confirm that backups were successfully created before or after a change, but it is not the primary document for recording the completion and outcome of a change request.

605
MCQeasy

A user wants to encrypt a USB flash drive so that if it is lost, the data cannot be read on another computer. The USB drive will be used on both Windows 10 and Windows 11 devices. Which Windows feature should be used?

A.EFS (Encrypting File System)
B.BitLocker To Go
C.Windows Defender Encryption
D.Secure Boot
AnswerB

BitLocker To Go is the dedicated feature within Windows Pro and Enterprise editions specifically designed for encrypting removable data drives, such as USB flash drives and external hard drives. It provides full-disk encryption, protecting all data stored on the drive with a password or smart card. This feature ensures data security even if the drive is lost or stolen, and it allows access to the encrypted content on other Windows 10/11 systems with the correct credentials.

Why this answer

BitLocker To Go is the correct choice because it provides full-disk encryption specifically designed for removable drives like USB flash drives. It encrypts the entire drive using AES encryption, and when the drive is inserted into another Windows 10 or Windows 11 computer, the user must enter the password or use a smart card/recovery key to access the data. This ensures that if the drive is lost, the data remains unreadable on any other system.

Exam trap

CompTIA often tests the distinction between EFS and BitLocker To Go, where candidates mistakenly choose EFS because they think file-level encryption is sufficient for removable media, but EFS does not protect data when the drive is moved to another computer because the encryption certificate is not present on the target system.

How to eliminate wrong answers

Option A is wrong because EFS (Encrypting File System) encrypts individual files and folders on NTFS volumes, but it is tied to the user's account and certificate on the local machine; it does not protect data when the drive is moved to another computer, and it is not designed for removable drives. Option C is wrong because Windows Defender Encryption is not a real Windows feature; the correct name is Windows Device Encryption, which is a simplified version of BitLocker for system drives on supported hardware, not for removable USB drives. Option D is wrong because Secure Boot is a UEFI firmware security feature that ensures only trusted bootloaders and drivers are loaded during startup; it does not encrypt data on a USB drive or protect data at rest.

606
MCQeasy

A customer is frustrated because every time they plug in a USB flash drive, Windows automatically opens the folder and plays any media files. They want to stop this behavior but still want the drive to be recognized. Which Control Panel item should you use?

A.File Explorer Options
B.AutoPlay
C.Device Manager
D.Sound
AnswerB

AutoPlay is a Windows feature, configurable through the Control Panel or Settings app, that allows users to define default actions for various types of media and devices when they are connected or inserted. For removable drives, such as USB flash drives, AutoPlay presents options like "Open folder to view files," "Import photos and videos," or "Take no action," directly addressing the customer's desire to control the automatic behavior upon device connection. This mechanism prevents unwanted applications from launching or specific actions from occurring without user intervention.

Why this answer

AutoPlay is the Control Panel item that controls what Windows does when media or a device is inserted — including the 'open folder to view files' and 'play media' behaviors for USB drives. Setting AutoPlay to 'Take no action' or turning off 'Use AutoPlay for all media and devices' stops the automatic folder opening and media playback while still allowing the drive to be recognized and accessed manually. This precisely matches the customer's request.

Exam trap

220-1202 often tests the confusion between AutoPlay (what happens when media is inserted) and File Explorer Options (how folders display) — candidates pick File Explorer Options because both are about file/folder behavior.

How to eliminate wrong answers

Option A is wrong because File Explorer Options (formerly Folder Options) controls how folders are displayed and whether hidden files are shown — it does not govern the automatic action taken when a USB drive is inserted. Option C is wrong because Device Manager manages hardware devices and drivers; it can disable a device but has no AutoPlay/media behavior settings and would not stop the folder from opening. Option D is wrong because the Sound Control Panel item configures audio playback and recording devices; it is unrelated to USB insertion behavior or media auto-play.

607
MCQeasy

A customer reports that their printer is not working after a recent Windows update. The technician suspects a driver issue. Which of the following is the BEST way to handle this situation while maintaining customer satisfaction?

A.Tell the customer that Windows updates often break things and they should avoid updates.
B.Ask the customer to try unplugging the printer and plugging it back in.
C.Say you will research the issue and call them back within an hour with steps.
D.Immediately remote into their computer and start checking settings without explaining.
AnswerC

This is the most professional and effective initial response. It demonstrates a commitment to resolving the problem by taking ownership, sets a clear expectation for follow-up within a defined timeframe, and allows the technician to perform necessary research (e.g., checking known issues, driver updates, or specific error codes) before attempting a fix. This approach builds customer confidence and ensures a more informed and efficient troubleshooting process, rather than guessing or attempting immediate, potentially ineffective, actions.

Why this answer

It demonstrates professional communication and sets realistic expectations. The technician acknowledges the issue, commits to researching the specific driver compatibility problem caused by the Windows update, and promises a follow-up within a defined timeframe. This approach maintains customer trust and avoids making promises or taking actions without a clear plan.

Exam trap

The trap here is that candidates may choose Option B (unplug/replug) because it is a common troubleshooting step, but the question specifically tests communication and professionalism, not basic hardware troubleshooting, so the best answer is the one that manages the customer's expectations and demonstrates a planned, researched response.

How to eliminate wrong answers

Option A is wrong because telling the customer to avoid Windows updates is unprofessional, dismissive, and fails to address the actual driver issue; updates are necessary for security and stability. Option B is wrong because asking the customer to unplug and replug the printer is a generic hardware reset step that does not resolve a driver conflict caused by a Windows update; it wastes the customer's time and shows a lack of diagnostic effort. Option D is wrong because immediately remote into the computer without explaining the action violates customer consent and transparency; it can cause confusion or alarm and does not build trust.

608
MCQmedium

A user is unable to install a new printer on their Windows 10 workstation because the 'Print Spooler' service is not running. You need to start the service and ensure it starts automatically on boot. Which tool should you use?

A.Device Manager
B.Services
C.Task Scheduler
D.System Configuration
AnswerB

The Services console (services.msc) is the definitive administrative tool for managing all background processes known as Windows services. It allows administrators to view the status of each service, start, stop, pause, or restart them, and configure their startup type (e.g., Automatic, Manual, Disabled). Printer installations frequently depend on services like the Print Spooler, and if such a service is stopped or misconfigured, this utility is the correct place to diagnose and rectify the issue, enabling successful printer setup.

Why this answer

The Print Spooler is a Windows service that manages print jobs sent to the printer. To start it and set its startup type to Automatic, you must use the Services console (services.msc), which provides direct control over service state and startup configuration. Device Manager manages hardware drivers, not service states.

Exam trap

The trap here is that candidates confuse Device Manager's ability to update or roll back printer drivers with the ability to start the underlying Print Spooler service, which is a service management task, not a device management task.

How to eliminate wrong answers

Option A is wrong because Device Manager is used to manage hardware devices and their drivers, not to start or configure Windows services like the Print Spooler. Option C is wrong because Task Scheduler is designed to schedule automated tasks or scripts at specific times or events, not to manage the runtime state or startup type of a service. Option D is wrong because System Configuration (msconfig) controls boot options, startup programs, and general system startup behavior, but it does not allow you to start a stopped service or change its startup type to Automatic.

609
MCQmedium

A technician needs to install a new hard drive in a computer that is under a strict security policy requiring all drives to be sanitized before disposal. The old drive will be replaced. What is the most secure method to ensure data cannot be recovered from the old drive?

A.Perform a quick format of the drive.
B.Use a degausser to erase the magnetic fields.
C.Run the Windows Disk Cleanup tool.
D.Delete all partitions using Disk Management.
AnswerB

Degaussing involves exposing a magnetic storage device, like a hard disk drive (HDD), to a powerful alternating magnetic field. This process randomizes the magnetic domains on the platters, effectively erasing all recorded data by rendering it unreadable. This method physically alters the magnetic properties of the storage medium, making data recovery practically impossible and satisfying the most stringent data destruction requirements for HDDs.

Why this answer

A degausser generates a powerful magnetic field that physically randomizes the magnetic domains on the platters, effectively destroying all stored data and rendering the drive unusable. This is the only method listed that meets the strict security policy requirement for sanitization, as it prevents any possible data recovery even with advanced forensic tools.

Exam trap

CompTIA often tests the misconception that a quick format or partition deletion is sufficient for data sanitization, when in reality these methods only remove pointers to the data, leaving the raw data recoverable with simple tools.

How to eliminate wrong answers

Option A is wrong because a quick format only rewrites the file system metadata (e.g., the MFT or FAT) and does not erase the actual data on the disk; data remains recoverable with tools like TestDisk or PhotoRec. Option C is wrong because the Windows Disk Cleanup tool only removes temporary files and empties the Recycle Bin; it does not touch user data or system files on the drive. Option D is wrong because deleting partitions using Disk Management only removes the partition table entries, leaving the underlying data intact and fully recoverable until overwritten.

610
MCQmedium

A technician is deploying a new accounting software package across the company. The finance manager requests that the software be installed on their personal laptop, which is not company-managed. Company policy prohibits installing unapproved software on personal devices. How should the technician respond?

A."I'm sorry, but company policy doesn't allow installing this software on personal devices. However, I can help you set up remote access to a company workstation that has it."
B."I can install it, but you'll have to sign a waiver accepting all risks."
C."That's against policy. Please use a company laptop."
D."I'll need to get approval from IT management first. Can you email the request?"
AnswerA

This response effectively balances adherence to company policy with user support. By stating that installing software on personal devices is prohibited, the technician upholds crucial security, licensing, and data integrity standards. Simultaneously, offering remote access to a company workstation provides a practical, policy-compliant alternative that enables the user to perform their job functions without compromising organizational security or compliance.

Why this answer

It upholds the company's security policy by refusing to install unapproved software on a non-managed device, while still providing a practical solution: setting up remote access (e.g., via VPN and Remote Desktop Protocol) to a company workstation that already has the accounting software. This approach ensures compliance with policy and maintains data security by keeping the software within the managed environment.

Exam trap

CompTIA often tests the candidate's ability to balance policy enforcement with customer service, and the trap here is that candidates may choose a technically correct but unhelpful response (like C or D) instead of the one that both follows policy and provides a workable solution.

How to eliminate wrong answers

Option B is wrong because having the user sign a waiver does not negate the company policy; it still results in installing unapproved software on a personal device, which exposes the company to security risks such as data leakage or malware infection, and violates compliance requirements. Option C is wrong because while it correctly states the policy, it simply tells the user to use a company laptop without offering any immediate solution or guidance, which is unhelpful and fails to address the finance manager's need for access. Option D is wrong because it unnecessarily escalates the request to IT management for approval when the policy is already clear—this wastes time and does not resolve the user's need; the technician should know the policy and provide a compliant alternative directly.

611
MCQmedium

A user reports that after installing a new third-party disk cleanup utility, Windows 11 randomly displays a blue screen with the stop code CRITICAL_PROCESS_DIED. The system boots normally in Safe Mode, and the issue does not occur there. Which of the following is the BEST first step to resolve the issue?

A.Run System File Checker (SFC) with the /scannow parameter.
B.Perform a System Restore to a point before the utility was installed.
C.Run the Windows Memory Diagnostic tool to test for faulty RAM.
D.Uninstall the third-party disk cleanup utility in Safe Mode.
AnswerD

The timeline directly links the new utility to the CRITICAL_PROCESS_DIED stop code, and the absence of crashes in Safe Mode confirms a third-party driver or service is responsible. Removing that utility in Safe Mode eliminates the faulty component and is the least invasive, most targeted first step before considering broader repairs.

Why this answer

The crash appeared only after installing a third-party cleanup tool and does not occur in Safe Mode, which strongly indicates a problematic third-party driver or service. Uninstalling that utility in Safe Mode removes the offending component directly. Broader repairs like SFC, System Restore, or memory testing are either unnecessary or address causes not supported by the evidence.

Exam trap

The trap here is assuming any blue screen requires running SFC or memory diagnostics first instead of correlating the crash with the most recent software change.

612
MCQmedium

A small business owner wants to ensure that employees cannot install browser extensions or add-ons without administrator approval. Which method should the technician use to enforce this restriction across all company computers?

A.Configure each browser's settings manually on every computer.
B.Use Group Policy to disable extension installation.
C.Install a third-party firewall to block extension downloads.
D.Set the browser to private browsing mode.
AnswerB

Group Policy centrally enforces the browser extension restriction across all domain-joined company computers, satisfying the requirement that employees cannot install extensions without administrator approval. Disabling extension installation via Computer Configuration removes users' ability to add them, unlike per-device settings that leave each machine independently configurable.

Why this answer

Group Policy (specifically the Administrative Templates for Google Chrome, Microsoft Edge, or Firefox) provides a centralized method to enforce browser settings across all domain-joined computers. By configuring the 'Block external extensions' or 'ExtensionInstallBlockList' policy, the technician can prevent users from installing extensions without administrator approval, ensuring consistent enforcement without manual intervention on each machine.

Exam trap

The trap here is that candidates often think a firewall or manual configuration is sufficient, but the A+ exam tests the understanding that Group Policy is the only centralized, scalable method for enforcing browser restrictions in a domain environment, while firewalls operate at the network layer and cannot intercept browser-internal operations.

How to eliminate wrong answers

Option A is wrong because manually configuring each browser's settings on every computer is not scalable, prone to human error, and does not provide centralized enforcement or auditing. Option C is wrong because a third-party firewall blocks network traffic (e.g., downloads from specific URLs) but cannot control the browser's internal extension installation process, which occurs via the browser's own APIs and registry. Option D is wrong because private browsing mode only prevents local history and cookie storage; it does not restrict extension installation, which remains fully functional in private mode.

613
MCQmedium

A user complains that their laptop battery drains quickly and the device gets very hot. The battery is a lithium-ion type and is three years old. What is the most environmentally responsible recommendation?

A.Replace the entire laptop with a new Energy Star model.
B.Remove the battery and run the laptop only on AC power.
C.Replace the battery with a compatible model and recycle the old battery at a certified e-waste facility.
D.Continue using the laptop until the battery fails completely.
AnswerC

Replacing the depleted battery with a new, compatible model is the most appropriate and sustainable solution. This action restores the laptop's full functionality and portability, significantly extending its useful lifespan while being more cost-effective than purchasing a new device. Concurrently, recycling the old battery at a certified e-waste facility ensures hazardous materials are handled safely, preventing environmental contamination and promoting resource recovery.

Why this answer

It directly addresses the user's complaint (battery degradation causing heat and poor runtime) while ensuring responsible disposal of the hazardous lithium-ion battery. Recycling at a certified e-waste facility prevents toxic materials from entering landfills and allows recovery of valuable metals, aligning with environmental best practices.

Exam trap

The trap here is that candidates may choose Option B (remove battery and run on AC) thinking it solves the heat issue, but they overlook that the old battery still needs proper disposal and that the laptop's heat could stem from other factors like dust or failing thermal paste.

How to eliminate wrong answers

Option A is wrong because replacing the entire laptop when only the battery is faulty is wasteful and unnecessarily increases e-waste, even if the new model is Energy Star rated. Option B is wrong because removing the battery and running solely on AC power does not solve the heat issue (the laptop may still throttle or run hot due to other components) and leaves the old battery unaddressed, which could still pose a fire risk if stored improperly. Option D is wrong because continuing to use a degraded lithium-ion battery risks thermal runaway, swelling, or leakage, and delays responsible recycling, which is environmentally harmful.

614
MCQhard

A technician is investigating a security incident where a user's virtual machine was compromised. The technician suspects that the VM was infected with malware that spread from the host. Which virtualization security best practice would have prevented this?

A.Enable snapshots for all VMs.
B.Use a Type 2 hypervisor for better isolation.
C.Keep the hypervisor and host OS updated with security patches.
D.Assign more virtual CPUs to the VM.
AnswerC

Regular updates patch vulnerabilities that could be exploited for VM escape, preventing malware from spreading between host and VM.

Why this answer

Keeping the hypervisor and host OS updated with security patches is a fundamental virtualization security best practice that prevents malware from exploiting known vulnerabilities in the hypervisor layer. In this scenario, the malware spread from the host to the VM, indicating a hypervisor-level compromise that patching would have mitigated. Regular patching closes the attack vector that allows host-to-VM infection, such as vulnerabilities in the hypervisor's management interface or device emulation code.

Exam trap

CompTIA often tests the misconception that Type 2 hypervisors provide better isolation than Type 1 hypervisors, when in fact Type 1 (bare-metal) hypervisors offer stronger security boundaries because they run directly on hardware without a host OS layer.

How to eliminate wrong answers

Option A is wrong because enabling snapshots for all VMs is a backup and recovery practice, not a security control; snapshots do not prevent malware from spreading from the host to the VM and can even increase storage overhead and performance issues. Option B is wrong because a Type 2 hypervisor (hosted hypervisor) actually provides weaker isolation than a Type 1 hypervisor, as it runs on top of a host OS, increasing the attack surface and making it easier for malware to spread from the host to VMs. Option D is wrong because assigning more virtual CPUs to a VM improves performance but does not provide any security isolation or prevent malware propagation from the host; it has no effect on hypervisor vulnerabilities or host-to-VM attack paths.

615
MCQmedium

A user reports that after installing a new third-party backup utility, their Windows 11 computer takes several minutes to reach the desktop and shows a black screen with a spinning circle. The user wants to keep the backup utility but needs faster boot times. A technician opens Task Manager and notices the backup utility has a 'High' startup impact. Which of the following should the technician do FIRST to resolve the slow boot?

A.Disable the backup utility in the Startup tab of Task Manager.
B.Perform a clean boot using msconfig and disable all non-Microsoft services.
C.Use msconfig to set the computer to Safe Boot with minimal services.
D.Run the System File Checker (sfc /scannow) to repair corrupted system files.
AnswerA

Disabling the startup entry prevents the utility from launching at boot, directly addressing the high startup impact. The application remains installed and can be launched manually when needed, so the user keeps it while boot time improves. This is the least invasive first step before considering uninstallation or more drastic measures.

Why this answer

Task Manager's Startup tab shows the impact of each startup program. When a specific application is flagged as high impact and the timing correlates with its installation, disabling that startup entry is the most direct and least disruptive fix. It preserves the application for manual use and avoids unnecessary system-wide changes.

Exam trap

The trap here is assuming that a slow boot always requires a system file repair or a clean boot, when the startup impact data already points to a specific third-party application.

616
MCQeasy

During a security audit, you discover that a Windows 10 workstation has the 'Store passwords and credentials using reversible encryption' policy enabled. What is the primary security risk associated with this setting?

A.It increases the time required to log on to the system.
B.It allows users to bypass the password complexity requirement.
C.It stores passwords in a format that can be easily decrypted, making them vulnerable if the database is compromised.
D.It prevents the use of biometric authentication methods.
AnswerC

Storing passwords using reversible encryption means the original plaintext password can be mathematically recovered from its stored form. If an attacker successfully compromises the system's password database, they can easily decrypt all stored credentials, exposing actual user passwords. This critical vulnerability allows for widespread credential stuffing attacks and unauthorized access to other services where users might reuse their passwords.

Why this answer

The 'Store passwords using reversible encryption' policy causes Windows to store passwords in a format that can be decrypted back to plaintext. This directly violates the principle of storing only hashed credentials; if the SAM database or LSASS process memory is compromised, an attacker can recover the original password, enabling lateral movement or privilege escalation.

Exam trap

The trap here is that candidates often confuse 'reversible encryption' with 'password complexity' or 'account lockout' settings, but the core risk is the ability to decrypt stored passwords, not a performance or usability issue.

How to eliminate wrong answers

Option A is wrong because enabling reversible encryption does not affect logon time; it only changes how the password is stored, not the authentication process speed. Option B is wrong because password complexity requirements are enforced independently via the 'Password must meet complexity requirements' policy; reversible encryption does not bypass or weaken those rules. Option D is wrong because biometric authentication (e.g., Windows Hello) relies on a separate credential provider and is not disabled by reversible encryption; the setting only affects password-based credentials stored for network authentication.

617
MCQmedium

An administrator receives an alert that a workstation is repeatedly making DNS queries for random-looking domain names and sending small amounts of data to external IP addresses every few minutes. The endpoint protection agent is installed and up to date, and no user is logged in. Which of the following is the MOST likely explanation for this behavior?

A.The workstation is receiving a legitimate software update from the vendor.
B.The workstation is synchronizing its clock with an external NTP server.
C.The workstation is infected with malware that uses DNS tunneling for command and control.
D.The endpoint protection agent is performing a cloud reputation lookup for each file.
AnswerC

Random-looking domains queried at regular short intervals, combined with small outbound transfers, match DNS tunneling used by malware to reach a command-and-control server. Because DNS is normally allowed through firewalls, attackers encode data in queries and responses. The absence of a logged-in user and the automated cadence point to a compromised host rather than legitimate activity.

Why this answer

Malware that has established a foothold often uses DNS tunneling to evade egress filtering, encoding command-and-control traffic in DNS queries and responses. The combination of randomized domain names, a repeating short interval, small outbound data, and no interactive user strongly indicates a compromised endpoint rather than any normal update, reputation, or time-sync process.

Exam trap

The trap here is dismissing the traffic as routine update or synchronization noise because it is small and periodic, when random domain names plus frequent small transfers are the signature of DNS tunneling.

618
MCQhard

A company is migrating from Windows 10 to Windows 11 on several workstations. You need to verify that each computer meets the minimum hardware requirements, including TPM 2.0 and Secure Boot capability, before deploying the upgrade. Which built-in tool should you run on each machine to generate a compatibility report?

A.System Information (msinfo32.exe) and manually check the System Summary for TPM and Secure Boot status.
B.Windows 11 PC Health Check app (downloaded from Microsoft).
C.Deployment Imaging and Servicing Management (DISM) with the /Get-CurrentEdition option.
D.System Restore (rstrui.exe) to revert to a previous state if the upgrade fails.
AnswerB

The Windows 11 PC Health Check app is the official and most accurate tool specifically designed by Microsoft to assess a system's compatibility with Windows 11. It performs a comprehensive scan of all hardware and software requirements, including CPU generation, RAM, storage, TPM 2.0, and Secure Boot status. The app then provides a clear, consolidated pass/fail report, detailing any specific components that do not meet the upgrade criteria.

Why this answer

The Windows 11 PC Health Check app is the official Microsoft tool designed specifically to verify compatibility with Windows 11, including TPM 2.0 and Secure Boot capability. It generates a detailed compatibility report, making it the correct built-in tool for this pre-upgrade validation task.

Exam trap

The trap here is that candidates may confuse the PC Health Check app with the older Windows 10 Upgrade Assistant or rely on manual checks via msinfo32, but the exam specifically tests knowledge of the dedicated compatibility tool introduced for Windows 11.

How to eliminate wrong answers

Option A is wrong because manually checking System Information (msinfo32.exe) for TPM and Secure Boot status is inefficient and does not generate a compatibility report; it only displays raw hardware data without assessing Windows 11 requirements. Option C is wrong because DISM with /Get-CurrentEdition is used to display the current edition of Windows (e.g., Pro, Enterprise) and is unrelated to hardware compatibility checks. Option D is wrong because System Restore (rstrui.exe) is a recovery tool for reverting system changes, not a compatibility assessment tool.

619
MCQeasy

A user reports that their Windows 10 laptop takes a very long time to boot and shows a 'Preparing Automatic Repair' message before eventually loading the desktop. They mention this started after a power outage. Which Windows tool should you use first to diagnose and attempt to fix the boot issue?

A.System Restore
B.Startup Repair
C.Reset this PC
D.System File Checker (sfc /scannow)
AnswerB

Startup Repair is a Windows Recovery Environment (WinRE) diagnostic tool that automatically scans for common boot issues, including corrupted BCD, missing system files, and faulty drivers, then applies targeted fixes. It analyzes boot and event logs to identify the root cause and can rewrite the BCD, replace bootmgr, and repair disk errors. Because it is built for boot failures, it is the correct first response to a boot loop, which is precisely the scenario described.

Why this answer

Startup Repair (option B) is the correct first tool because the user reports a boot failure with 'Preparing Automatic Repair' after a power outage, which often corrupts critical boot configuration data (BCD) or the Master Boot Record (MBR). Startup Repair is designed to automatically diagnose and fix these specific boot-related issues without affecting user files, making it the most appropriate initial step.

Exam trap

The trap here is that candidates often choose System File Checker (sfc /scannow) because they associate file corruption with boot issues, but sfc requires a running OS and cannot repair boot loader components like the BCD or MBR, which are the actual culprits after a power outage.

How to eliminate wrong answers

Option A is wrong because System Restore reverts system files and settings to a previous restore point, but it requires a working boot environment to launch and does not directly repair boot loader corruption; it is a secondary step after boot is restored. Option C is wrong because Reset this PC is a more drastic recovery option that reinstalls Windows and may remove apps or files, which is excessive when the issue is likely boot configuration corruption that can be fixed with a targeted tool. Option D is wrong because System File Checker (sfc /scannow) scans and repairs protected system files, but it runs from within a working Windows environment and cannot fix boot loader or BCD corruption that prevents the OS from loading.

620
MCQeasy

A user reports that their Windows 10 laptop is running slowly and frequently shows a 'Low Memory' warning. They have 8 GB of RAM and are not running any unusual applications. Which built-in Windows tool should you use to determine if a specific process is leaking memory?

A.Performance Monitor
B.Task Manager
C.Event Viewer
D.System Configuration (msconfig)
AnswerB

Task Manager is the most direct and accessible utility for immediately identifying processes consuming excessive memory. Its 'Processes' or 'Details' tab provides a real-time, sortable list of all running applications and background processes, clearly displaying their current memory usage. This allows a technician to quickly pinpoint which specific process is exhibiting escalating memory consumption, a hallmark sign of a memory leak.

Why this answer

Task Manager (Option B) is the correct tool because it provides a real-time view of per-process memory usage, including the 'Memory (Active Private Working Set)' column, which can identify a process that is consuming an abnormally increasing amount of RAM over time—indicative of a memory leak. Unlike other tools, Task Manager allows you to quickly sort processes by memory usage and observe growth without needing to configure counters or parse logs.

Exam trap

CompTIA often tests the misconception that Performance Monitor is the only tool for memory leak diagnosis, but Task Manager is the correct first-line tool for quickly identifying a leaking process in a user-reported scenario.

How to eliminate wrong answers

Option A is wrong because Performance Monitor requires you to manually add specific counters (e.g., Process\Private Bytes) and set up data collector sets to track memory usage over time, which is more complex and not the quickest built-in tool for identifying a leaking process on a user's laptop. Option C is wrong because Event Viewer logs system, security, and application events, but it does not display real-time per-process memory consumption or memory leak patterns; it would only show low memory warnings after the fact, not the specific process causing the leak. Option D is wrong because System Configuration (msconfig) is used to manage boot options, startup programs, and services, not to monitor or diagnose active memory usage or leaks.

621
MCQhard

A technician needs to deploy a custom security policy to all Windows 10 workstations in a small office. The policy must restrict access to the Control Panel and prevent users from changing system settings. Which administrative tool should be used to create and apply this policy locally on each machine?

A.Local Security Policy (secpol.msc)
B.User Accounts (netplwiz)
C.Local Group Policy Editor (gpedit.msc)
D.System Configuration (msconfig)
AnswerC

Local Group Policy Editor (gpedit.msc) is the appropriate tool for deploying custom security policies on a standalone Windows machine. It provides extensive administrative templates under both Computer Configuration and User Configuration, allowing technicians to configure granular settings. These settings include restricting access to the Control Panel, disabling specific system features, enforcing software restrictions, and managing user environments, making it ideal for implementing comprehensive custom security policies.

Why this answer

The Local Group Policy Editor (gpedit.msc) is the correct tool because it provides the administrative templates and policy nodes (e.g., User Configuration > Administrative Templates > Control Panel) needed to restrict access to Control Panel and prevent system setting changes. These settings are written to the local Group Policy Objects (GPOs) stored in %SystemRoot%\System32\GroupPolicy, which Windows applies at user logon. This tool is available on Windows 10 Pro, Enterprise, and Education editions, but not on Windows 10 Home.

Exam trap

A common misconception is that Local Security Policy (secpol.msc) can handle all policy restrictions, but it only covers security-specific settings, not administrative templates for UI restrictions like Control Panel access.

How to eliminate wrong answers

Option A is wrong because Local Security Policy (secpol.msc) only manages security-related policies such as account policies, audit policies, and user rights assignments; it does not include administrative templates for restricting Control Panel access or system settings. Option B is wrong because User Accounts (netplwiz) is used to manage user account properties, passwords, and automatic logon settings, not to deploy custom security policies that restrict Control Panel or system changes. Option D is wrong because System Configuration (msconfig) is a boot and startup configuration tool for troubleshooting (e.g., selective startup, boot options, services), and it cannot create or apply security policies to restrict user access to system settings.

622
MCQeasy

A company wants to secure its server room door so that only authorized personnel can enter. They need a system that can be quickly revoked if an employee leaves and that logs entry attempts. Which physical security control best meets these requirements?

A.A combination lock with a shared code.
B.A biometric fingerprint scanner.
C.An electronic key card system.
D.A physical key and lock system.
AnswerC

An electronic key card system satisfies both constraints: credentials are revoked centrally in software the moment an employee leaves, and every swipe attempt is logged with a timestamp and identity. Unlike mechanical locks, which require physical rekeying, it provides immediate revocation and an auditable entry trail.

Why this answer

An electronic key card system meets both requirements: access can be instantly revoked by deactivating the card in the central database, and each entry attempt is logged with a timestamp and card ID. This provides granular, auditable access control without the need to physically change locks or share codes.

Exam trap

CompTIA often tests the distinction between 'revocability' and 'auditability' — the trap here is assuming biometrics are always the best for security, but the question emphasizes quick revocation and logging, where electronic key cards are more practical and cost-effective than biometric systems.

How to eliminate wrong answers

Option A is wrong because a combination lock with a shared code cannot be individually revoked without changing the code for everyone, and it typically does not log entry attempts. Option B is wrong because while a biometric fingerprint scanner can log attempts and be revoked by deleting the user's template, it is less practical for quick revocation in a large organization and can suffer from false rejection or hygiene issues. Option D is wrong because a physical key and lock system requires rekeying or replacing locks to revoke access, and it provides no automated logging of entry attempts.

623
MCQhard

A security incident occurred on a Windows 10 workstation where an unauthorized user gained access. The technician needs to review detailed security events, such as logon attempts and file access, to determine the scope of the breach. Which tool should the technician use to examine these logs?

A.Event Viewer
B.Resource Monitor
C.Performance Monitor
D.Local Security Policy
AnswerA

The Event Viewer is the definitive tool for investigating past security incidents on a Windows 10 workstation. It centralizes system logs, with the 'Windows Logs > Security' section specifically detailing events like logon attempts, object access, and privilege use. Each entry includes a timestamp, user account, and an Event ID, providing crucial forensic data to reconstruct the sequence of events during a security breach.

Why this answer

Event Viewer is the correct tool because it provides a centralized, detailed log of security-related events, including logon attempts (Event ID 4624 for successful logons, 4625 for failed logons) and file access audits (Event ID 4663). These logs are essential for forensic analysis to determine the scope of a breach on a Windows 10 workstation.

Exam trap

CompTIA often tests the distinction between tools that configure security settings (Local Security Policy) versus tools that review logged events (Event Viewer), leading candidates to confuse policy configuration with log review.

How to eliminate wrong answers

Option B (Resource Monitor) is wrong because it focuses on real-time performance data such as CPU, memory, disk, and network usage, not historical security event logs. Option C (Performance Monitor) is wrong because it tracks system performance counters and creates data collector sets for performance analysis, not security event auditing. Option D (Local Security Policy) is wrong because it is used to configure security settings like password policies and audit policies, not to review existing event logs.

624
MCQeasy

A technician needs to deploy a PowerShell script to 50 Windows 10 workstations that will install a security update silently. The script must run with administrative privileges. Which method should the technician use to ensure the script executes properly without user interaction?

A.Double-click the script file on each workstation
B.Run the script via 'powershell.exe -ExecutionPolicy Bypass -File script.ps1' from an elevated command prompt
C.Use the 'Start-Process' cmdlet without elevation
D.Copy the script to the Startup folder
AnswerB

Executing the script using 'powershell.exe -ExecutionPolicy Bypass -File script.ps1' from an elevated command prompt is the most effective method for deploying a PowerShell script requiring administrative privileges. The '-ExecutionPolicy Bypass' parameter temporarily overrides the system's execution policy for the current session, allowing the script to run without restrictions. When launched from an elevated command prompt, the script inherits administrative rights, ensuring it can perform system-level changes, and the '-File' parameter specifies the script to execute directly.

Why this answer

Running 'powershell.exe -ExecutionPolicy Bypass -File script.ps1' from an elevated command prompt bypasses PowerShell's execution policy for that session and ensures the script runs with administrative privileges. This combination allows silent, unattended execution of the security update installation across multiple workstations without user interaction.

Exam trap

CompTIA often tests the misconception that double-clicking a .ps1 file executes it like a batch file, when in reality it opens in an editor, and that 'Start-Process' without elevation is sufficient for administrative tasks.

How to eliminate wrong answers

Option A is wrong because double-clicking a .ps1 file opens it in Notepad by default on Windows 10, not executing it; even if execution policy allowed it, it would require user interaction and does not guarantee elevation. Option C is wrong because 'Start-Process' without elevation (e.g., missing the '-Verb RunAs' parameter) runs the script with the current user's privileges, which may lack the administrative rights needed to install a security update. Option D is wrong because copying the script to the Startup folder runs it at user logon with the user's privileges (not elevated), and the execution policy may block it; it also requires user logon, not a silent deployment.

625
MCQeasy

A user reports that their Windows 10 PC is running slowly and they suspect a background process is consuming excessive memory. Which command-line tool should you use to identify the process by name and memory usage?

A.tasklist
B.ipconfig
C.chkdsk
D.sfc
AnswerA

tasklist enumerates running processes with their names and memory usage, directly satisfying the stem's need to identify the offending process by name and memory consumption. Task Manager offers the same data graphically, but the question specifies a command-line tool.

Why this answer

The `tasklist` command displays a list of all currently running processes on a Windows system, including their process ID (PID), session name, session number, and memory usage. By default, it shows memory consumption in kilobytes, allowing you to identify which process is consuming excessive memory by name. This makes it the correct tool for diagnosing a memory-hungry background process.

Exam trap

CompTIA often tests the distinction between system information commands (like `systeminfo` or `tasklist`) and network or disk utilities; the trap here is that candidates may confuse `ipconfig` (a network tool) or `sfc` (a system file checker) with a process management tool, or assume `chkdsk` can show memory usage because it reports disk-related resource consumption.

How to eliminate wrong answers

Option B (ipconfig) is wrong because it displays TCP/IP network configuration values (IP address, subnet mask, default gateway) and has no capability to list processes or memory usage. Option C (chkdsk) is wrong because it checks the file system integrity of a volume for logical and physical errors, not for running processes or memory consumption. Option D (sfc) is wrong because it scans and verifies the integrity of all protected system files, replacing incorrect versions with correct Microsoft versions, and does not provide any process or memory information.

626
MCQhard

A technician is setting up a virtual machine for a software developer who needs to test an application on multiple operating systems. The host runs Windows 10 Pro with 32 GB of RAM and a quad-core CPU. The developer wants the VM to have direct access to a USB security dongle. Which configuration step is essential to meet this requirement?

A.Configure the VM to use dynamic memory.
B.Enable virtualization extensions (VT-x/AMD-V) in the host BIOS.
C.Install the guest additions or integration services in the VM.
D.Enable USB controller passthrough in the VM settings.
AnswerD

USB passthrough forwards the physical USB device from host to guest, giving the VM direct access to the security dongle. Enabling USB 3.0 support or installing guest additions alone does not expose the host-attached dongle to the virtual machine.

Why this answer

USB passthrough (or USB controller passthrough) allows the virtual machine to directly access and control a physical USB device, such as a security dongle, bypassing the host operating system. This is essential for applications that require direct hardware-level communication with the dongle for licensing or authentication.

Exam trap

The trap here is that candidates often confuse VM enhancements (like shared folders and mouse smoothing) with the ability to pass through hardware devices, leading them to select Option C instead of the correct USB passthrough configuration.

How to eliminate wrong answers

Option A is wrong because dynamic memory adjusts the amount of RAM allocated to the VM based on demand, but it has no effect on USB device access or passthrough capabilities. Option B is wrong because enabling virtualization extensions (VT-x/AMD-V) in the host BIOS is necessary for running any 64-bit or hardware-assisted virtual machines, but it does not enable USB passthrough; it is a prerequisite for virtualization itself, not a specific step for USB access. Option C is wrong because guest additions or integration services improve performance, clipboard sharing, and display resolution, but they do not provide direct USB device access; USB passthrough is configured at the hypervisor level, not through guest software.

627
MCQmedium

A company’s change management policy requires that all changes be categorized as standard, emergency, or normal. During a server migration, a technician discovers a critical security patch must be applied immediately to prevent a data breach. Which type of change should the technician request?

A.Standard change
B.Emergency change
C.Normal change
D.Service request
AnswerB

An emergency change is specifically designed for situations that demand immediate action to resolve a critical incident or prevent a major service disruption, such as an active security breach or a widespread system failure. This type of change allows for an expedited approval process, often bypassing some standard review steps, to deploy critical fixes like security patches without delay. Post-implementation review and documentation are still required to ensure proper governance and learning.

Why this answer

The scenario describes a critical security patch that must be applied immediately to prevent a data breach, which aligns with the definition of an emergency change. Emergency changes are pre-approved or fast-tracked to address urgent threats or service outages, bypassing the normal change advisory board (CAB) review process. This ensures the patch can be deployed without delay to mitigate the risk.

Exam trap

CompTIA often tests the distinction between 'emergency' and 'standard' changes by presenting a time-sensitive scenario where candidates mistakenly classify a critical patch as a standard change because it is a routine security update, ignoring the 'immediate' and 'critical' context.

How to eliminate wrong answers

Option A is wrong because a standard change is a low-risk, pre-approved change that follows a documented procedure (e.g., applying routine OS updates), not an urgent security patch requiring immediate action. Option C is wrong because a normal change requires full CAB review and scheduling, which would introduce unacceptable delay for a critical security vulnerability. Option D is wrong because a service request is a user-initiated request for information, access, or a standard service (e.g., password reset), not a change to the IT infrastructure like applying a security patch.

628
MCQeasy

During a security incident, a user's files have been renamed with a '.encrypted' extension, and a ransom note demands Bitcoin to restore them. The user has no backups. What is the most appropriate immediate action?

A.Pay the ransom to regain access quickly.
B.Disconnect the computer from the network immediately.
C.Run a full antivirus scan to remove the malware.
D.Restart the computer in Safe Mode and attempt file recovery.
AnswerB

Disconnecting the computer from the network immediately is the most critical first step in containing a ransomware infection. This action prevents the malware from encrypting additional local files, stops it from accessing and encrypting shared network drives or cloud storage, and halts its potential spread to other systems or network segments. Isolating the compromised machine effectively limits the scope of the attack and preserves uninfected data, which is crucial for incident response.

Why this answer

Ransomware encrypts files, and paying the ransom does not guarantee decryption. The correct first step is to isolate the infected system to prevent the malware from spreading to network shares or other devices.

629
MCQeasy

During a software deployment, you need to ensure that all users on a Windows 10 workstation have the company logo as their desktop background. Which Control Panel applet would you use to set a mandatory desktop background?

A.Ease of Access Center
B.Personalization
C.Display
D.Folder Options
AnswerB

The Personalization section in Windows Settings is the correct location for modifying the desktop background and other visual elements of the user interface. Here, users can select a specific image, a solid color, or a slideshow as their desktop wallpaper, as well as customize accent colors, lock screen images, and apply various themes. This centralizes all aesthetic customization options, directly addressing the need to change the desktop's appearance during a software deployment or user setup.

Why this answer

The Personalization applet in Control Panel allows you to set a desktop background image. To enforce a mandatory background for all users, you would configure a Group Policy setting (via gpedit.msc) that references the Personalization category, specifically the 'Desktop Wallpaper' policy under User Configuration > Administrative Templates > Desktop > Desktop. This overrides individual user settings and locks the background.

Exam trap

CompTIA often tests the misconception that the Display applet controls desktop backgrounds because it deals with visual output, but Display strictly handles resolution and scaling, not wallpaper.

How to eliminate wrong answers

Option A is wrong because the Ease of Access Center is designed to configure accessibility features like Narrator, Magnifier, and high-contrast themes, not desktop wallpaper settings. Option C is wrong because the Display applet manages screen resolution, scaling, and multiple monitor configurations, not desktop background images. Option D is wrong because Folder Options controls file explorer behaviors such as view settings, search options, and file associations, not desktop personalization.

630
MCQmedium

During a network upgrade, a technician needs to run new Ethernet cables through a drop ceiling. The technician notices that some existing cables are resting on the ceiling tiles and are not secured. What safety concern should the technician address?

A.Leave the cables as they are and run the new cables alongside them.
B.Secure all cables to the ceiling grid using appropriate cable supports.
C.Use zip ties to attach the cables to the sprinkler pipes for stability.
D.Remove the existing cables and replace them with the new ones.
AnswerB

Securing all cables to the ceiling grid with proper supports like J-hooks or cable trays is the correct and safest practice. This method ensures compliance with building codes and TIA/EIA cabling standards, preventing cables from becoming fire hazards, interfering with other building systems, or causing ceiling tile collapse. Proper support also maintains cable integrity, reduces signal interference, and simplifies future troubleshooting and maintenance tasks.

Why this answer

Cables resting on ceiling tiles are a fire and safety hazard because they can be damaged, impede airflow, and violate fire codes. The correct action is to secure all cables to the ceiling grid or structure using appropriate cable supports (J-hooks, bridle rings, or cable trays) so they are properly supported and out of the way.

Exam trap

The trap is picking the 'convenient' answer (zip ties to sprinkler pipes or leaving cables alone) — 220-1202 tests whether you recognize fire-code and physical-safety violations in cabling work.

How to eliminate wrong answers

Option A is wrong because leaving unsecured cables in place perpetuates the hazard and adds more risk with the new cabling. Option C is wrong because attaching cables to sprinkler pipes is a serious code violation — it can damage the sprinkler system, void fire suppression integrity, and is prohibited by NFPA standards. Option D is wrong because removing existing cables is not required to address the safety concern and could disrupt live services; the issue is securing them, not replacing them.

631
MCQhard

A data center manager wants to implement a physical security control that can detect if a server chassis has been opened without authorization. Which control should they use?

A.Intrusion detection system (IDS) on the network
B.Chassis intrusion switch
C.Tamper-evident seals
D.Video surveillance
AnswerB

A chassis intrusion switch can detect when the case is opened, but it requires a connection to the motherboard and may be bypassed if the system is off; tamper-evident seals are more reliable for detection.

Why this answer

A chassis intrusion switch is a physical security control, typically a microswitch inside the server chassis, that detects when the chassis cover is opened. Upon detection, it can trigger an alert, log an event in the system's management controller (like IPMI or BMC), or prevent the system from booting. This provides an immediate and active detection mechanism for unauthorized access.

While tamper-evident seals provide visual evidence of tampering, a chassis intrusion switch offers a more direct and often automated method of detection.

Exam trap

The trap here is that candidates might consider tamper-evident seals (which provide visual evidence after the fact) but overlook the more active and often integrated electronic detection provided by a chassis intrusion switch, which is a direct physical security control designed for immediate detection of chassis opening.

How to eliminate wrong answers

Option A is wrong because an Intrusion Detection System (IDS) on the network monitors network traffic for malicious activity, not physical chassis access. Option B is wrong because a chassis intrusion switch is an electronic sensor that can detect when a chassis is opened, but it is not a physical security control that provides tamper evidence; it is an electronic detection mechanism that can be bypassed or disabled. Option D is wrong because video surveillance can monitor physical access to the server room but does not directly detect if a specific server chassis has been opened; it requires continuous monitoring and review of footage.

632
MCQmedium

A user reports that their iPad will not rotate the screen when they turn the device sideways. The rotation lock icon appears in the status bar. What is the most likely cause?

A.The accelerometer is faulty.
B.The app being used does not support rotation.
C.Rotation lock is enabled in Control Center or via the side switch.
D.The device needs a software update to fix a rotation bug.
AnswerC

The presence of the rotation lock icon directly confirms that the device's orientation lock feature has been activated. This setting, typically accessible through the Control Center by swiping down from the top-right corner, or via a physical side switch on older iPad models, intentionally prevents the screen from rotating. Disabling this software lock will restore the iPad's ability to adjust its display orientation based on accelerometer input.

Why this answer

The rotation lock icon visible in the iPad status bar is the definitive indicator that Rotation Lock is currently enabled, either through Control Center or the physical side switch (on older iPads). When Rotation Lock is active, iOS suppresses the accelerometer-driven orientation change regardless of how the device is physically turned. Disabling it via Control Center (or flipping the side switch) restores normal screen rotation behavior.

Exam trap

220-1202 often tests whether candidates recognize that a visible status-bar icon indicates a software/user setting rather than a hardware failure, so the trap is jumping to 'faulty accelerometer' when the icon itself proves the hardware is fine.

How to eliminate wrong answers

Option A is wrong because a faulty accelerometer would not display the rotation lock icon in the status bar — that icon is a software state indicator, not a hardware fault symptom, and accelerometer failure typically causes no rotation at all with no icon present. Option B is wrong because an app that does not support rotation would only affect that specific app, not produce a system-wide rotation lock icon in the status bar. Option D is wrong because a software update bug would not selectively display the rotation lock icon; that icon is only shown when the user (or side switch) has explicitly enabled the lock.

633
MCQeasy

A user reports that a PowerShell script they wrote to rename multiple files in a folder works on their desktop but fails with a 'permission denied' error when run from a network folder. The user has full control of the network folder. What is the most likely cause?

A.The script uses a cmdlet that is not available on the network drive.
B.The execution policy is set to RemoteSigned, which blocks scripts from network locations.
C.The network folder has a space in its name.
D.The user is not running PowerShell as an administrator.
AnswerB

The RemoteSigned execution policy is a security measure that mandates all PowerShell scripts originating from the internet or network shares must be digitally signed by a trusted publisher to execute. While locally created scripts can run without a signature, PowerShell classifies scripts executed directly from a network location as 'remote.' This policy prevents the execution of unsigned network scripts, often resulting in an 'Access Denied' or similar error, directly addressing the reported issue.

Why this answer

The PowerShell execution policy controls which scripts can run and from where. The RemoteSigned policy requires that scripts from the internet (including network shares) be digitally signed, and it treats network drives as an 'internet' zone. When the script is run from a network folder, the policy blocks execution unless the script is signed, resulting in a 'permission denied' error, even though the user has full NTFS permissions.

Exam trap

CompTIA often tests the misconception that 'permission denied' always relates to NTFS or share permissions, when in fact PowerShell's execution policy can block scripts from network locations even if the user has full control.

How to eliminate wrong answers

Option A is wrong because cmdlets are part of the PowerShell module and are available regardless of the drive location; a missing cmdlet would produce a 'command not found' error, not a 'permission denied' error. Option C is wrong because a space in the folder name would cause a syntax error or path resolution issue, not a 'permission denied' error, and PowerShell handles spaces correctly with quoting or escaping. Option D is wrong because running as administrator is not required for renaming files in a folder where the user already has full control; the 'permission denied' error here is due to the execution policy, not a lack of administrative rights.

634
MCQeasy

A customer reports that their Windows 10 laptop is displaying pop-up ads even when no browser is open. They suspect a malware infection. Which of the following should you do first to remediate this issue?

A.Run a full antivirus scan while the system is connected to the internet.
B.Disconnect the network cable, boot into Safe Mode, then run a full antivirus scan.
C.Perform a System Restore to a point before the pop-ups started.
D.Immediately reinstall Windows 10 to ensure complete removal.
AnswerB

This is the most effective initial remediation strategy. Disconnecting the network cable immediately isolates the infected system, preventing the malware from communicating with external servers, spreading to other devices, or receiving further instructions. Booting into Safe Mode loads only essential system services and drivers, often preventing malware from fully loading and executing, making it easier for antivirus software to detect and remove it without interference. Finally, a full antivirus scan can then thoroughly identify and eradicate the dormant or partially active threats.

Why this answer

The first step in malware remediation is to disconnect from the network to prevent further communication with command-and-control servers. Then boot into Safe Mode to prevent malicious processes from loading, and run a full antivirus scan. This isolates the threat before attempting removal.

635
MCQmedium

A user reports that their laptop frequently disconnects from the office Wi-Fi and reconnects after a few seconds. The network uses WPA2-Enterprise with PEAP-MSCHAPv2. Other users do not experience this issue. What is the most likely cause?

A.The laptop's wireless driver is outdated.
B.The RADIUS server is rejecting the laptop's certificate intermittently.
C.The office Wi-Fi channel is congested.
D.The laptop's power saving mode is turning off the Wi-Fi adapter.
AnswerA

An outdated wireless driver can cause intermittent connectivity issues, such as frequent disconnects and reconnects, on a single device.

Why this answer

The most likely cause is an outdated or incompatible wireless driver. This can cause intermittent connectivity issues on a single device. Other users are unaffected, and since the network uses WPA2-Enterprise with PEAP-MSCHAPv2, which relies on username/password authentication, the RADIUS server does not reject client certificates.

Channel congestion would affect multiple users, and power saving mode typically turns off the adapter after inactivity, not causing frequent reconnects.

Exam trap

Candidates may incorrectly attribute a single-user issue to server-side authentication problems, but in this case the RADIUS server does not use client certificates in PEAP-MSCHAPv2, so the correct cause is a local driver issue.

How to eliminate wrong answers

Option A is wrong because an outdated wireless driver would typically cause persistent connectivity issues, frequent drops without automatic reconnection, or driver crashes, not a pattern of disconnection and reconnection every few seconds that only affects one user. Option C is wrong because channel congestion would affect all users in the same area, not just one laptop, and would manifest as slow speeds or intermittent connectivity for everyone, not a specific reconnection pattern. Option D is wrong because power saving mode turning off the Wi-Fi adapter would cause the laptop to disconnect and not reconnect automatically for several seconds, and this behavior would be consistent and not intermittent; moreover, power saving features typically do not cause a reconnection after a few seconds without user intervention.

636
MCQhard

A server administrator needs to grant a junior technician the ability to reset user passwords on a Windows Server 2019 domain controller, but without giving them full administrative rights. Which administrative tool should be used to delegate this specific permission?

A.Local Security Policy to assign the 'Reset passwords' user right.
B.Active Directory Users and Computers and use the Delegation of Control Wizard.
C.Group Policy Management Console to create a policy that allows password resets.
D.Computer Management to add the technician to the 'Account Operators' group.
AnswerB

The Delegation of Control Wizard in Active Directory Users and Computers assigns granular permissions, such as Reset password, on a specific OU without granting full Domain Admin rights. This satisfies the least-privilege requirement for the junior technician.

Why this answer

The Delegation of Control Wizard in Active Directory Users and Computers is the correct tool because it allows an administrator to grant specific permissions, such as resetting user passwords, to a non-administrative user without granting full administrative rights. This wizard modifies the ACL on the selected organizational unit (OU) or container, enabling granular control over tasks like password resets while preserving security boundaries.

Exam trap

The Delegation of Control Wizard allows granular permissions, whereas built-in groups like Account Operators grant overly broad rights, violating the principle of least privilege.

How to eliminate wrong answers

Option A is wrong because Local Security Policy assigns user rights (e.g., 'Log on locally') at the local machine level, not granular Active Directory permissions like resetting passwords, and it cannot delegate AD-specific tasks. Option C is wrong because Group Policy Management Console applies computer or user configuration settings via GPOs, not delegated permissions for AD object operations like password resets; it cannot grant a user the ability to modify AD objects. Option D is wrong because adding the technician to the 'Account Operators' group grants broad permissions to manage user accounts, groups, and passwords across the domain, which exceeds the requirement of only resetting passwords and introduces unnecessary security risks.

637
MCQmedium

A user reports that their Windows 10 PC is infected with a virus that changes the desktop background to a ransom note. After removing the virus with antivirus software, the desktop background remains unchanged. What should you do to restore the original background?

A.Reinstall the graphics driver.
B.Run System File Checker (sfc /scannow).
C.Check Group Policy settings for desktop wallpaper enforcement and reset them.
D.Perform a system restore to a point before the infection.
AnswerC

Malware frequently modifies Group Policy settings to enforce its presence, restrict user actions, or maintain persistence, such as preventing users from changing their desktop wallpaper. These specific policies, often found under User Configuration > Administrative Templates > Desktop > Desktop in the Local Group Policy Editor (gpedit.msc), can enforce a specific background image or disable the ability to change it. Identifying and then disabling or setting such a policy to 'Not Configured' will restore the user's ability to customize their desktop background.

Why this answer

The virus likely modified the Group Policy setting that enforces a specific desktop wallpaper. Even after the virus is removed, the Group Policy setting persists and overrides any user attempts to change the background. Resetting the Group Policy wallpaper enforcement restores the user's ability to change the background normally.

Exam trap

The trap here is that candidates assume a virus removal or system file repair will fix all remnants of the infection, but they overlook that malware can modify persistent system policies like Group Policy, which require explicit reversal.

How to eliminate wrong answers

Option A is wrong because the graphics driver is not involved in displaying a static desktop background; the issue is a policy enforcement, not a rendering or driver problem. Option B is wrong because System File Checker (sfc /scannow) repairs corrupted system files, but the wallpaper change is due to a Group Policy setting, not file corruption. Option D is wrong because a system restore might revert the Group Policy change, but it is not the most direct or efficient fix; the problem is specifically a persistent policy setting that can be reset without affecting other system changes.

638
MCQmedium

A user on Windows 11 is trying to install a new application, but receives the error 'Windows cannot access the specified device, path, or file. You may not have the appropriate permissions to access the item.' The user is a local administrator. What is the most likely cause?

A.The file is corrupted and needs to be re-downloaded.
B.User Account Control (UAC) is blocking the installation.
C.The file has been blocked by Windows because it was downloaded from the internet.
D.The user does not have 'Read & Execute' permissions on the file.
AnswerC

Windows applies a security measure known as the 'Mark-of-the-Web' (MotW) to files downloaded from the internet, assigning them a 'Zone Identifier' alternate data stream. This security feature prevents immediate execution or access until the user explicitly 'unblocks' the file via its Properties dialog box. This restriction often manifests as a 'cannot access the specified device, path, or file' error, even for administrative users, making 'Unblock' the common resolution.

Why this answer

When a file is downloaded from the internet, Windows attaches a Zone.Identifier alternate data stream marking it as originating from the 'Internet' zone. Even as a local administrator, the user cannot execute or install it until the block is removed via the file's Properties dialog ('Unblock' checkbox) or PowerShell's Unblock-File cmdlet. The error message about permissions is misleading — it is a Mark-of-the-Web restriction, not an NTFS ACL problem.

Exam trap

The trap is taking the error message literally — 'you may not have the appropriate permissions' sounds like an NTFS or UAC issue, but the real cause is the Mark-of-the-Web, and candidates who focus on ACLs or UAC pick the wrong answer.

How to eliminate wrong answers

Option A is wrong because a corrupted download typically produces checksum or installer errors, not a permissions-style access denial, and the specific error text points to execution blocking. Option B is wrong because UAC prompts with a consent dialog or elevation failure, not a 'cannot access the specified device, path, or file' message — and a local admin would simply approve the prompt. Option D is wrong because the user is a local administrator and the file was just downloaded by that user, so they inherently have Read & Execute rights; the block is a zone-based policy, not an ACL.

639
MCQhard

A user's iOS device is running out of storage, and they want to offload unused apps without deleting documents and data. Which iOS feature should be recommended, and where is it configured?

A.Enable 'Optimize iPhone Storage' in Photos settings
B.Use 'Offload Unused Apps' in Settings > General > iPhone Storage
C.Manually delete apps from the Home Screen
D.Configure iCloud Storage to offload app data
AnswerB

'Offload Unused Apps' removes an app's executable while retaining its documents and data, directly satisfying the requirement to free storage without losing user content. It is configured under Settings > General > iPhone Storage, where iOS lists per-app sizes and offers the offload toggle. Reinstalling later restores the app with data intact.

Why this answer

The 'Offload Unused Apps' feature automatically removes app binaries when storage is low, but preserves the app's documents and data. This is configured in Settings > General > iPhone Storage, where users can also manually offload individual apps. It directly addresses the user's requirement to free up space without losing personal data.

Exam trap

CompTIA often tests the distinction between 'offloading' (preserving data) and 'deleting' (removing everything), and candidates may confuse 'Optimize iPhone Storage' with app offloading because both involve storage management.

How to eliminate wrong answers

Option A is wrong because 'Optimize iPhone Storage' in Photos settings only manages photo and video storage by replacing full-resolution originals with device-optimized versions, not app offloading. Option C is wrong because manually deleting apps from the Home Screen removes both the app and its documents/data, which contradicts the user's requirement to preserve data. Option D is wrong because iCloud Storage does not offload app data; it syncs and backs up data, but does not remove app binaries from the device to free local storage.

640
MCQmedium

A technician is tasked with upgrading the operating system on ten identical workstations. The change advisory board has approved the upgrade. After completing the first workstation, the technician notices the new OS causes a critical line-of-business application to fail. What should the technician do next?

A.Continue upgrading the remaining workstations since the change was approved.
B.Restore the first workstation to the previous OS and complete the rest without changes.
C.Report the failure to the change advisory board and pause further upgrades.
D.Research a hotfix for the application and apply it to all workstations.
AnswerC

Reporting the failure to the Change Advisory Board (CAB) and immediately pausing further upgrades is the correct and most responsible course of action. This allows the CAB, as the governing body for changes, to evaluate the identified risk, assess the impact, and collectively decide on the appropriate next steps. They can then modify the rollout plan, investigate a workaround, or halt the change entirely, preventing wider system instability.

Why this answer

When a pilot upgrade reveals a critical application failure, the change advisory board (CAB) must be informed because the approved change no longer meets its success criteria. Pausing further upgrades prevents the same failure from affecting the remaining nine workstations and allows the CAB to reassess, request a rollback plan, or approve a remediation. This follows ITIL change management principles.

Exam trap

220-1202 often tests whether candidates understand that CAB approval is not a one-time gate — a failed pilot invalidates the approval, and the technician must escalate rather than proceed or self-remediate.

How to eliminate wrong answers

Option A is wrong because continuing the rollout despite a known critical failure violates change management governance and would multiply the impact across all ten workstations. Option B is wrong because restoring the first workstation and then completing the rest without changes ignores the root cause — the remaining upgrades would likely fail identically. Option D is wrong because researching and applying a hotfix without CAB approval bypasses the change control process and may introduce untested code into production.

641
MCQeasy

A technician writes a batch script to automate software installation across multiple workstations. The script needs to wait for the installer to finish before proceeding to the next line. Which command should be used?

A.PAUSE
B.TIMEOUT
C.START /WAIT
D.CALL
AnswerC

The START /WAIT command is specifically designed to launch an external program or command and then pause the execution of the batch script until that launched program terminates. When used with a software installer, this ensures that the batch script will not proceed to subsequent commands until the installation process, including any child processes it spawns, has fully completed and exited, making it ideal for sequential automation of software deployments.

Why this answer

The START /WAIT command launches a specified program or script and pauses execution of the batch file until that process terminates. This is exactly what is needed to ensure the installer completes before the next line runs, making it the correct choice for sequential automation.

Exam trap

CompTIA often tests the distinction between PAUSE (user input wait), TIMEOUT (fixed delay), and START /WAIT (process-aware wait), trapping candidates who confuse a simple delay with true process synchronization.

How to eliminate wrong answers

Option A (PAUSE) is wrong because it simply halts the script and displays 'Press any key to continue...', waiting for user input rather than for a specific process to finish. Option B (TIMEOUT) is wrong because it introduces a fixed delay (e.g., TIMEOUT /T 30) but does not monitor the installer process; the script will resume after the timeout regardless of whether the installer has completed. Option D (CALL) is wrong because it invokes another batch file or label within the same script context and returns control after that script finishes, but it does not inherently wait for a spawned process like an installer; it is designed for subroutine-like calls, not for launching external executables with a wait requirement.

642
MCQmedium

A user calls the help desk because they cannot access a shared folder on the network. The user's account is part of the 'Sales' group, which has 'Read' permission, but the user needs to modify files. What is the most efficient way to grant the required access?

A.Assign 'Full Control' to the user's account directly
B.Add the user to a group that has 'Modify' permission
C.Change the folder's sharing settings to 'Everyone' with 'Read/Write'
D.Remove the user from the Sales group and add them to a new group with 'Read' permission
AnswerB

Adding the user to an existing or new group that possesses 'Modify' permission is the most appropriate and secure solution. 'Modify' permission allows the user to read, write, execute, and delete files and subfolders, which directly addresses the need to make changes. This method adheres to the principle of least privilege by granting only the necessary access and simplifies administration through efficient group-based security management.

Why this answer

Adding the user to a group with 'Modify' permissions is efficient because it avoids individual permission assignments and follows the principle of group-based access control. This ensures the user can edit files without overcomplicating permissions.

643
MCQmedium

A user reports that their external hard drive is no longer recognized by Windows. They suspect it might be infected with malware from a previous connection. You run a security scan and find no threats. What is the most likely cause of the drive not being recognized?

A.The drive is permanently damaged by malware.
B.The USB controller driver is corrupted or outdated.
C.The user needs to format the drive to remove malware.
D.Windows Firewall is blocking the external drive.
AnswerB

A corrupted or outdated USB controller driver is a common cause for an external hard drive not being recognized or functioning correctly. The driver acts as the essential software interface between the operating system and the USB hardware, translating commands and enabling communication. If this driver is compromised, the OS cannot properly enumerate or interact with the connected drive, leading to recognition failures that can often be resolved by updating or reinstalling the driver via Device Manager.

Why this answer

When a drive is not recognized after a suspected malware incident, the issue is often driver-related or due to a corrupted file system, not necessarily malware. Reinstalling or updating the USB controller driver in Device Manager can resolve recognition issues. The correct answer is to check Device Manager for driver issues.

644
MCQhard

A technician discovers that a user has been sharing their login credentials with coworkers to allow them to access a shared drive. The company's security policy prohibits password sharing. What is the most effective way to prevent this behavior while still allowing necessary access?

A.Disable the user's account and create a generic shared account for the drive.
B.Implement a Group Policy that forces password changes every 30 days.
C.Configure the shared drive permissions using security groups and add the coworkers to the appropriate group.
D.Send a company-wide email reminding users not to share passwords.
AnswerC

Configuring shared drive permissions using security groups is the most appropriate and secure solution. This method allows the technician to grant specific access levels (e.g., read, write) to defined groups of users, ensuring that only authorized personnel can access the drive without sharing individual credentials. It enforces the principle of least privilege, maintains individual accountability for actions, and simplifies management by centralizing access control, directly addressing the need for shared access securely.

Why this answer

Configuring the shared drive permissions using security groups and adding the coworkers to the appropriate group is the most effective solution because it grants necessary access through proper authorization rather than credential sharing. This follows the principle of least privilege and eliminates the need for users to share passwords. It also provides an auditable, manageable access control mechanism.

Exam trap

220-1202 often tests the difference between technical access controls (security groups) and policy/awareness measures (emails, password expiration), so candidates who pick awareness or password-change options miss the need for a preventive technical control.

How to eliminate wrong answers

Option A is wrong because disabling the user's account and creating a generic shared account violates accountability and non-repudiation; generic accounts are prohibited by most security policies and make auditing impossible. Option B is wrong because forcing password changes every 30 days does not prevent sharing — users can simply share the new password — and frequent changes can lead to weaker passwords or written reminders. Option D is wrong because a company-wide email is a awareness measure, not a technical control; it does not prevent the behavior and is easily ignored.

645
MCQmedium

A company uses a cloud-based file storage service. An employee reports that when they try to upload a large video file, the upload fails after several minutes of progress. The employee's internet connection is stable and other uploads of smaller files work fine. What is the most likely cause of this issue?

A.The employee's computer has insufficient RAM.
B.The cloud service's server is temporarily overloaded.
C.The file exceeds the maximum upload size allowed by the service.
D.The employee's account has been suspended.
AnswerC

Cloud storage services enforce a per-file upload ceiling, often several gigabytes. Smaller files succeed because they stay under this limit, while the large video trips it mid-transfer, producing a failure after minutes of apparent progress rather than an immediate connection error.

Why this answer

The most likely cause is that the file exceeds the maximum upload size allowed by the cloud service. Cloud storage providers enforce file size limits to manage bandwidth and storage resources, and a large video file would be rejected after the upload begins if it surpasses this threshold. The fact that smaller uploads succeed and the connection is stable points directly to a file size restriction rather than a network or account issue.

Exam trap

CompTIA A+ often tests the misconception that a stable internet connection and successful small uploads rule out file size limits, leading candidates to incorrectly blame server overload or local hardware issues instead of recognizing the service's enforced upload cap.

How to eliminate wrong answers

Option A is wrong because insufficient RAM on the employee's computer would cause system-wide slowdowns or crashes, not a specific upload failure after several minutes of progress; RAM does not directly affect the upload process once the file is read into memory. Option B is wrong because a temporarily overloaded server would typically cause slow uploads or timeouts for all users, not a consistent failure after several minutes for a single large file while smaller uploads succeed. Option D is wrong because a suspended account would prevent all uploads, not just large files, and the employee would likely receive an authentication or authorization error immediately rather than after several minutes of progress.

646
MCQhard

A technician is troubleshooting a network issue and needs to access the user's computer remotely. The user is in a different city and speaks with a heavy accent, making communication difficult. The technician has trouble understanding the user's description of the error. What is the best approach?

A.Ask the user to type the error message in a chat window to avoid miscommunication.
B.Speak slowly and loudly, repeating each question until the user understands.
C.Ask the user to transfer the call to a colleague who speaks English more clearly.
D.Proceed with remote access without further communication, assuming you can diagnose the issue visually.
AnswerA

This approach leverages written communication, which effectively bypasses potential verbal accent barriers or auditory comprehension issues, ensuring precise capture of critical information like error messages or command outputs. By asking the user to type, the technician obtains an exact record of the problem details, minimizing misinterpretation and facilitating more accurate troubleshooting. This method demonstrates resourcefulness and respect for the user's communication style, aligning with professional customer service practices.

Why this answer

When verbal communication is unreliable due to accent or language barriers, switching to a text-based channel such as chat lets the user type the exact error message, eliminating mishearing and providing a precise, copyable record of the issue. This is the most professional and effective approach.

Exam trap

220-1202 often tests professional communication and cultural sensitivity — the trap is choosing a technically plausible but unprofessional option (transfer to a clearer speaker) over the respectful, effective one (switch to chat).

How to eliminate wrong answers

Option B is wrong because speaking slowly and loudly does not address comprehension of an accent and can come across as condescending; volume does not improve intelligibility of accented speech. Option C is wrong because asking to transfer to a colleague who 'speaks English more clearly' is unprofessional and potentially discriminatory, and it delays resolution. Option D is wrong because proceeding without understanding the user's description risks misdiagnosis and may violate the principle of confirming the issue before acting.

647
MCQmedium

A technician is configuring a new server room and needs to ensure that only authorized personnel can physically access it. The company wants a solution that does not require replacement of keys or cards if one is lost. Which access control method best meets this requirement?

A.Use a combination lock
B.Implement a biometric fingerprint reader
C.Install a smart card system
D.Use a keypad with a PIN code
AnswerB

Implementing a biometric fingerprint reader provides a highly secure and personalized access control solution for a server room. This method authenticates individuals based on their unique physiological characteristics, making it inherently difficult to share or transfer credentials. Since the 'credential' is part of the individual, there are no physical tokens to be lost, stolen, or forgotten, significantly reducing administrative tasks associated with credential reissuance or recovery and enhancing overall security posture.

Why this answer

A biometric fingerprint reader authenticates based on a unique physical characteristic of the person, so there is no key, card, or token that can be lost and need replacing. If a user is removed, their biometric template is simply deleted from the system, and no physical credential reissue is required. This directly satisfies the requirement of not replacing keys or cards when one is lost.

Exam trap

220-1202 often tests the distinction between something you have (card/key), something you know (PIN/combination), and something you are (biometric); the phrase 'does not require replacement if lost' is the giveaway that points to a biometric factor.

How to eliminate wrong answers

Option A is wrong because a combination lock uses a shared code that must be changed and redistributed whenever it is compromised or a person leaves, and it does not identify individuals. Option C is wrong because a smart card system still relies on a physical card that can be lost, requiring replacement and reissuance, which is exactly what the company wants to avoid. Option D is wrong because a keypad PIN is a knowledge factor that can be shared, forgotten, or observed, and PINs must be changed and redistributed when compromised, again not eliminating the replacement problem.

648
MCQmedium

A small office user reports that their Windows 10 PC randomly freezes for 10-15 seconds, especially when opening large files. Task Manager shows high disk usage (100%) but low CPU and memory usage. Which built-in Windows tool should be used to diagnose the disk performance issue?

A.Use Resource Monitor to analyze disk activity and queue length.
B.Run the Performance Monitor with a Data Collector Set for disk.
C.Check the Event Viewer for disk-related errors.
D.Defragment the hard drive using the Optimize Drives tool.
AnswerA

Resource Monitor provides a real-time, granular view of disk I/O operations, detailing which processes are actively reading from or writing to the disk. It displays critical metrics such as total disk activity, read/write speeds, and importantly, the disk queue length, which indicates how many I/O requests are pending. This immediate insight allows an administrator to quickly identify specific applications or services causing excessive disk utilization and potential bottlenecks leading to system freezes.

Why this answer

Resource Monitor (resmon.exe) provides real-time metrics on disk activity, including disk queue length, average disk seconds per read/write, and per-process I/O. The user's symptom of 100% disk usage with low CPU/memory suggests a disk bottleneck; a consistently high queue length (above 2 per spindle) indicates the disk cannot keep up with I/O requests, which Resource Monitor can pinpoint directly.

Exam trap

CompTIA often tests the distinction between real-time diagnostic tools (Resource Monitor) and historical logging tools (Performance Monitor), leading candidates to choose Performance Monitor because it sounds more comprehensive, but it is not designed for live troubleshooting of an active bottleneck.

How to eliminate wrong answers

Option B is wrong because Performance Monitor with a Data Collector Set is a historical logging tool, not a real-time diagnostic tool for immediate analysis of current high disk usage. Option C is wrong because Event Viewer logs system errors and warnings, not granular per-process disk I/O metrics like queue length or latency. Option D is wrong because defragmentation (Optimize Drives) improves sequential read performance on HDDs but does not address the underlying cause of high disk queue length or random freezes, and is irrelevant for SSDs which do not benefit from defragmentation.

649
MCQmedium

A user reports that their Windows 10 PC is infected with a virus that keeps reappearing after removal. The technician boots into Safe Mode, runs a full antivirus scan, and removes the threat. However, after rebooting normally, the virus returns. What is the most likely reason?

A.The antivirus definitions are outdated.
B.The virus has a persistence mechanism, such as a scheduled task or registry run key.
C.The user is re-downloading the virus from the same source.
D.The virus is a polymorphic variant that changes its signature.
AnswerB

Safe Mode scans miss autostart locations that only load during a normal boot, so a scheduled task or registry Run key relaunches the payload after removal. Clearing that persistence entry alongside the antivirus scan is what stops the reinfection cycle.

Why this answer

The virus likely uses a persistence mechanism such as a scheduled task (via schtasks.exe) or a registry Run key (e.g., HKCU\Software\Microsoft\Windows\CurrentVersion\Run) to re-infect the system after boot. Safe Mode may bypass some of these mechanisms, but a normal boot re-triggers them, allowing the virus to reinstall itself even after the initial removal.

Exam trap

CompTIA often tests the distinction between detection failure (outdated definitions or polymorphism) and re-infection due to persistence mechanisms, so the trap here is assuming the antivirus failed to detect the virus rather than recognizing that the virus is being re-introduced after removal.

How to eliminate wrong answers

Option A is wrong because outdated antivirus definitions would prevent detection, not cause the virus to reappear after removal; the scan already removed the threat. Option C is wrong because the user re-downloading the virus would require active user action each time, but the problem states the virus 'keeps reappearing' automatically after reboot, indicating a persistence mechanism rather than repeated user downloads. Option D is wrong because a polymorphic virus changes its signature to evade detection, but the antivirus already detected and removed it; the issue is re-infection after reboot, not evasion of the scan.

650
MCQhard

A technician is troubleshooting a wireless network where users report intermittent connectivity. The network uses WPA2-Enterprise with a RADIUS server. The technician notices that the RADIUS server logs show frequent authentication failures from one specific access point. What is the most likely cause?

A.The access point is using a different channel than the others.
B.The RADIUS server certificate has expired.
C.The access point's RADIUS shared secret is incorrect.
D.The clients are using WPA2-PSK instead of WPA2-Enterprise.
AnswerC

The shared secret is used for authentication between the AP and RADIUS server; a mismatch causes failures.

Why this answer

The RADIUS shared secret is a pre-shared key configured on both the access point and the RADIUS server to authenticate the AP itself. If the secret on the specific AP does not match the server's configuration, the server will reject authentication requests from that AP, causing intermittent connectivity for clients associated with it. The logs showing frequent authentication failures from one AP point directly to a mismatch in this shared secret.

Exam trap

CompTIA often tests the distinction between client-side authentication failures (e.g., wrong PSK or certificate) and infrastructure-side authentication failures (e.g., RADIUS shared secret mismatch), and the trap here is that candidates may confuse a RADIUS server certificate issue with a per-AP shared secret problem, not realizing that a certificate expiry would affect all APs uniformly.

How to eliminate wrong answers

Option A is wrong because using a different channel affects RF interference and throughput, not RADIUS authentication; the RADIUS server logs would not show authentication failures due to channel differences. Option B is wrong because an expired RADIUS server certificate would cause authentication failures for all access points, not just one specific AP, and the error would typically appear as a certificate validation failure rather than a shared secret mismatch. Option D is wrong because if clients were using WPA2-PSK instead of WPA2-Enterprise, the AP would not forward authentication requests to the RADIUS server at all, so the server logs would not show authentication failures from that AP.

651
MCQeasy

A customer reports that their laptop battery is swelling and the case is cracking. They ask if it's safe to continue using it plugged in. What should the technician advise?

A.It's fine to keep using it plugged in as long as the battery is removed.
B.Continue using it but only on battery power to avoid overheating the charger.
C.Shut down the laptop immediately, disconnect the battery if safely possible, and replace the battery as soon as possible.
D.Place the laptop in a freezer to reduce swelling, then continue using it.
AnswerC

This is the correct and safest course of action. Immediately shutting down the laptop removes power from the compromised battery, mitigating further heat generation and reducing the risk of thermal runaway. Disconnecting the battery, if it can be done without force or further damage, isolates the hazard. The swollen battery must then be replaced and disposed of properly as hazardous electronic waste.

Why this answer

A swelling lithium-ion battery indicates internal chemical breakdown and gas generation, which can lead to thermal runaway, fire, or explosion. The immediate risk is physical rupture of the battery casing and potential short-circuiting. The correct action is to shut down the laptop, disconnect the battery if it can be done safely without puncturing it, and replace it as soon as possible to eliminate the hazard.

Exam trap

CompTIA often tests the misconception that a swollen battery is safe to use if kept plugged in or if the battery is removed, when in fact any continued use or physical handling of a swollen battery poses immediate fire and chemical hazard risks.

How to eliminate wrong answers

Option A is wrong because removing a swollen battery from a laptop that is still plugged in does not eliminate the risk of short circuits or fire from the damaged battery, and the act of removal itself can be dangerous if the casing is already compromised. Option B is wrong because continuing to use the laptop on battery power will further discharge and stress the already unstable battery, increasing the likelihood of thermal runaway. Option D is wrong because placing a lithium-ion battery in a freezer can cause condensation, internal short circuits, and further chemical instability, and it does not reverse the swelling or make the battery safe.

652
MCQeasy

After deploying a new Windows 11 update, several users complain that they can no longer access shared folders on the network. You verify that network discovery and file sharing are enabled. Which Windows security setting should you check first to resolve this issue?

A.Check if the users are in the 'Remote Desktop Users' group.
B.Verify that the 'Password Protected Sharing' option is turned off.
C.Review Windows Defender Firewall rules for 'File and Printer Sharing.'
D.Run Windows Update to install additional patches.
AnswerC

Reviewing Windows Defender Firewall rules for 'File and Printer Sharing' is the most appropriate first step. Major Windows updates frequently modify or reset firewall configurations, potentially blocking the necessary inbound and outbound network traffic for the Server Message Block (SMB) protocol, which underpins file and printer sharing. If the firewall rule allowing 'File and Printer Sharing' is disabled or restricted, network clients will be unable to establish connections to access shared resources, directly causing the reported issue.

Why this answer

After a Windows 11 update, the most common cause for losing access to shared folders—even when network discovery and file sharing are enabled—is that the Windows Defender Firewall rules for 'File and Printer Sharing' have been reset or disabled. This update often modifies firewall profiles (e.g., switching from Private to Public) or resets custom rules, blocking the NetBIOS, SMB, and RPC ports (TCP 139, 445; UDP 137, 138) required for file sharing. Checking and re-enabling these inbound rules restores connectivity.

Exam trap

The trap here is that candidates confuse 'Password Protected Sharing' (a sharing-level setting) with network-level blocking, or assume that enabling network discovery and file sharing in the GUI automatically opens all necessary firewall ports, when in fact the firewall rules are separate and often reset by updates.

How to eliminate wrong answers

Option A is wrong because the 'Remote Desktop Users' group controls RDP access, not file sharing over SMB; shared folders use SMB/CIFS, not Remote Desktop Protocol. Option B is wrong because 'Password Protected Sharing' affects whether users must have local accounts on the host to access shares, but it does not block network traffic; if it were the issue, users would see the share but be prompted for credentials, not unable to access it entirely. Option D is wrong because running Windows Update again would not fix a firewall rule that was already altered by the previous update; the problem is a configuration change, not missing patches.

653
MCQeasy

A user calls the help desk claiming they received an urgent email from the CEO asking them to purchase gift cards for a client and reply with the codes. The user is suspicious because the email address looks slightly off. What type of social engineering attack is this?

A.Shoulder surfing
B.Phishing
C.Tailgating
D.Dumpster diving
AnswerB

Phishing is a cybercrime that employs fraudulent electronic communications, most commonly emails, to deceive individuals into divulging sensitive information like usernames, passwords, credit card details, or performing actions such as transferring funds or purchasing gift cards. Attackers impersonate legitimate entities to gain trust, making the deceptive email the primary vector for this social engineering attack. This directly aligns with a user receiving a deceptive email.

Why this answer

This is a phishing attack because the attacker impersonates a trusted entity (the CEO) via email to trick the user into performing a fraudulent action (purchasing gift cards and sharing codes). The suspicious email address indicates a spoofed sender, a common phishing technique that exploits trust and urgency to bypass user skepticism.

Exam trap

CompTIA A+ often tests the distinction between social engineering attack types by using a scenario that involves electronic communication (email) to trick the user, leading candidates to confuse phishing with physical or observation-based attacks like shoulder surfing or tailgating.

How to eliminate wrong answers

Option A is wrong because shoulder surfing involves directly observing a user's screen or keystrokes to steal information, not sending deceptive emails. Option C is wrong because tailgating is a physical security breach where an unauthorized person follows an authorized individual into a restricted area, unrelated to email-based deception. Option D is wrong because dumpster diving involves searching through trash for discarded sensitive documents or data, not crafting fraudulent electronic communications.

654
MCQmedium

A user calls the help desk because their computer is running slowly and they see a fake antivirus program warning that their system is infected. The user cannot close the warning window. Which type of malware is this, and what is the best removal approach?

A.Ransomware; pay the fee to remove the warning.
B.Spyware; run a full scan in normal mode.
C.Rogue antivirus; boot into Safe Mode with Networking and run Malwarebytes.
D.Adware; uninstall the program from Control Panel.
AnswerC

Rogue antivirus masquerades as legitimate security software, using scareware pop-ups that resist normal window closure to pressure payment. Booting into Safe Mode with Networking prevents the rogue's startup persistence from loading, allowing Malwarebytes to quarantine the infection and its associated registry entries without interference from the running process.

Why this answer

The symptoms—a fake antivirus warning that cannot be closed—are classic indicators of rogue antivirus (scareware). This type of malware mimics legitimate security software to trick users into paying for unnecessary services. The best removal approach is to boot into Safe Mode with Networking, which loads only essential drivers and services, preventing the rogue program from auto-starting, then run Malwarebytes to detect and remove the threat.

Exam trap

CompTIA A+ often tests the distinction between ransomware and rogue antivirus, trapping candidates who confuse the 'pay to remove' demand with ransomware's file-encryption extortion, when the key difference is that rogue antivirus does not actually encrypt files.

How to eliminate wrong answers

Option A is wrong because ransomware typically encrypts files and demands payment for decryption, not a fake antivirus warning that can't be closed; paying the fee would not remove the malware and would only fund the attacker. Option B is wrong because spyware is designed to covertly collect personal information, not display fake warnings, and running a scan in normal mode may fail if the malware actively blocks security tools. Option D is wrong because adware usually displays pop-up ads but can often be closed or uninstalled normally; the inability to close the warning indicates a more aggressive rogue program that may not appear in the Control Panel's uninstall list.

655
MCQmedium

During a network equipment upgrade, a technician finds several old switches with visibly leaking capacitors on the circuit boards. What is the correct procedure for handling these switches?

A.Power them on to see if they still function before disposal.
B.Wear nitrile gloves, place the switches in a sealed bag, and label for e-waste recycling.
C.Use compressed air to blow out the leaked substance and then recycle the switches.
D.Dispose of the switches in the regular office recycling bin.
AnswerB

Wearing nitrile gloves is crucial for protecting the technician's skin from direct contact with the corrosive capacitor electrolyte. Placing the compromised switches into a sealed bag effectively contains the hazardous leakage, preventing environmental contamination and further exposure during transport. Labeling for e-waste recycling ensures that the devices are handled by certified facilities equipped to safely process hazardous materials, complying with environmental regulations.

Why this answer

Leaking capacitors often contain hazardous materials such as electrolytes or polychlorinated biphenyls (PCBs), which require special handling to prevent environmental contamination and personal injury. The correct procedure is to wear nitrile gloves (to avoid skin contact with corrosive or toxic substances), place the switches in a sealed bag to contain any leaked material, and label them for e-waste recycling, ensuring compliance with environmental regulations like the WEEE Directive or RCRA.

Exam trap

CompTIA often tests the misconception that visibly damaged equipment can be safely tested or cleaned with common tools, when in fact hazardous material protocols require containment and professional e-waste disposal without powering on or disturbing the leak.

How to eliminate wrong answers

Option A is wrong because powering on switches with leaking capacitors can cause short circuits, electrical fires, or further release of hazardous fumes, and it does not address proper disposal procedures. Option C is wrong because using compressed air can aerosolize hazardous electrolyte particles, leading to inhalation risks or spreading contamination, and it does not constitute safe handling or recycling. Option D is wrong because regular office recycling bins are not designed for hazardous e-waste; disposing of leaking capacitors in general waste violates environmental laws and can harm sanitation workers and the environment.

656
MCQmedium

During a macOS deployment, you need to create a bootable USB installer for macOS Sonoma to upgrade multiple iMacs. You have the 'Install macOS Sonoma' app in the Applications folder. Which command-line tool should you use to create the installer?

A.diskutil
B.asr
C.createinstallmedia
D.hdiutil
AnswerC

The createinstallmedia executable inside the Install macOS Sonoma app's Contents/Resources directory writes the bootable installer to a target volume, satisfying the requirement for a USB installer. It is Apple's supported tool; diskutil only formats, and asr clones volumes.

Why this answer

The `createinstallmedia` command is the official Apple tool for creating a bootable USB installer from the 'Install macOS Sonoma' app. It is located inside the app bundle at `/Applications/Install macOS Sonoma.app/Contents/Resources/createinstallmedia` and is specifically designed for this purpose, ensuring the USB drive is properly formatted and the installer is written correctly for UEFI boot.

Exam trap

CompTIA often tests the distinction between disk management tools (`diskutil`, `hdiutil`) and the specific installer creation tool (`createinstallmedia`), leading candidates to pick `diskutil` or `hdiutil` because they are familiar with formatting drives or mounting images, but they cannot create a bootable installer from the macOS app bundle.

How to eliminate wrong answers

Option A is wrong because `diskutil` is used for managing disks and partitions (e.g., formatting, mounting, unmounting) but cannot create a bootable installer from an app bundle. Option B is wrong because `asr` (Apple Software Restore) is used for restoring disk images to volumes, not for creating bootable USB installers from macOS installer apps. Option D is wrong because `hdiutil` is used for manipulating disk images (e.g., mounting, converting, resizing DMG files) and cannot directly create a bootable USB installer from the macOS installer application.

657
MCQeasy

A technician is tasked with installing a security patch on 50 company laptops. The change management process requires a full system backup before any patch installation. During the backup of the first laptop, the backup fails due to insufficient disk space. What should the technician do?

A.Skip the backup for this laptop and proceed with the patch installation.
B.Free up disk space by deleting temporary files and retry the backup.
C.Install the patch anyway and create a manual restore point.
D.Report the failure to the change manager and request an exception.
AnswerB

Insufficient disk space is a common reason for backup failures. Deleting temporary files, clearing system caches, or emptying the Recycle Bin are standard and effective initial troubleshooting steps to reclaim necessary storage. Successfully freeing up space and completing the backup ensures compliance with the change management policy, providing a critical recovery point before proceeding with the patch installation.

Why this answer

The change management process explicitly requires a full system backup before patch installation. Deleting temporary files is a standard, low-risk method to free disk space and retry the backup, ensuring compliance without violating policy. This approach maintains data integrity and follows the established procedure.

Exam trap

CompTIA often tests the candidate's understanding that change management policies are mandatory and must be followed, not circumvented, and that troubleshooting steps should be taken before escalating to management.

How to eliminate wrong answers

Option A is wrong because skipping the backup violates the mandatory change management requirement, risking data loss if the patch causes issues. Option C is wrong because installing the patch without a full backup and relying on a manual restore point does not satisfy the policy for a complete system backup, and a restore point may not capture all system state. Option D is wrong because reporting the failure and requesting an exception is premature; the technician should first attempt to resolve the disk space issue, as the process expects troubleshooting before escalation.

658
MCQmedium

A technician is troubleshooting a Windows 10 PC that shows a black screen with a movable mouse cursor after boot. The user can press Ctrl+Alt+Del and launch Task Manager. Which Control Panel or Settings tool should be used to repair the system files that may be corrupted?

A.System Properties > System Protection
B.Device Manager
C.Administrative Tools > Computer Management
D.Settings > Update & Security > Troubleshoot
AnswerA

System Protection, accessible via System Properties, is the correct choice because it enables System Restore. System Restore allows a technician to revert the operating system's critical files, registry settings, and installed programs to a previous working state, effectively undoing recent changes that might have introduced corruption or instability. This process is invaluable for resolving issues like system crashes or unbootable states caused by faulty updates or software installations, without affecting personal user data.

Why this answer

The black screen with a movable mouse cursor after boot, combined with the ability to launch Task Manager via Ctrl+Alt+Del, indicates that the Windows shell (explorer.exe) may be failing to load due to corrupted system files. System Properties > System Protection provides access to System Restore, which can revert system files and registry settings to a previous known-good state, effectively repairing corruption without affecting user data. This tool leverages Volume Shadow Copy snapshots to restore critical system files, making it the appropriate choice for this scenario.

Exam trap

The trap here is that candidates confuse 'System Restore' (accessed via System Properties > System Protection) with 'Reset this PC' or 'Troubleshoot' (found in Settings > Update & Security), leading them to choose Option D, but System Restore is the correct tool for reverting system file corruption without reinstalling Windows.

How to eliminate wrong answers

Option B (Device Manager) is wrong because it is used to manage hardware drivers and devices, not to repair corrupted system files or restore the operating system to a previous state. Option C (Administrative Tools > Computer Management) is wrong because it provides access to tools like Event Viewer, Disk Management, and Services, but does not include a direct mechanism to repair corrupted system files or perform a system restore. Option D (Settings > Update & Security > Troubleshoot) is wrong because it offers automated troubleshooters for common issues (e.g., network, audio) and includes the 'Reset this PC' option, but it does not provide System Restore functionality; System Restore is accessed via System Properties, not through the Troubleshoot page.

659
MCQhard

A company is migrating from Windows 7 to Windows 10 and needs to automate the installation of 200 workstations with identical software and settings. They have a reference computer already configured. Which Windows tool should they use to capture and deploy a custom system image?

A.Windows System Image Manager (Windows SIM)
B.System Preparation Tool (Sysprep)
C.Windows Recovery Environment (WinRE)
D.Windows Backup and Restore
AnswerB

The System Preparation Tool (Sysprep) is a critical utility for preparing a Windows installation for imaging and subsequent deployment to multiple computers. It generalizes the operating system by removing system-specific data, such as unique Security Identifiers (SIDs) and hardware-specific drivers, making the image hardware-independent. This process ensures that all deployed machines start with a unique identity and avoid conflicts on a network, making it the indispensable first step before capturing a deployable image.

Why this answer

Sysprep is the correct tool because it generalizes a Windows installation by removing unique system identifiers (such as the computer SID, computer name, and driver caches) so that the reference computer’s image can be safely captured and deployed to multiple workstations. After Sysprep runs with the /generalize option, the image is captured using a tool like DISM or ImageX, then deployed to 200 identical workstations, ensuring each machine generates its own unique SID and settings on first boot.

Exam trap

The trap here is that candidates confuse Sysprep with Windows SIM, thinking that creating an answer file is the same as capturing an image, but Sysprep is the prerequisite generalization step that makes the image safe for cloning, while Windows SIM only creates automation scripts.

How to eliminate wrong answers

Option A is wrong because Windows System Image Manager (Windows SIM) is used to create unattended answer files (Unattend.xml) that automate installation settings, not to capture or deploy a system image. Option C is wrong because Windows Recovery Environment (WinRE) is a diagnostic and recovery platform for repairing a broken OS, not a tool for capturing or deploying a custom image. Option D is wrong because Windows Backup and Restore creates file-level or system-state backups, not a hardware-independent, deployable system image suitable for cloning to multiple workstations.

660
MCQmedium

A technician is troubleshooting a Windows 10 workstation that displays a fake security alert claiming the system is infected and prompting the user to call a toll-free number. The user cannot close the alert window or open Task Manager. Which type of malware is causing this behavior, and what is the best removal approach?

A.It is a rootkit; use a rootkit removal tool from within Windows.
B.It is ransomware; pay the fee to remove the alert.
C.It is a tech support scam; boot into Safe Mode with Networking and run an anti-malware scan.
D.It is a worm; disconnect the network and reinstall the operating system.
AnswerC

This is the correct approach for a tech support scam, which typically involves browser-based pop-ups or installed scareware designed to trick users into calling fake support numbers. Booting into Safe Mode with Networking loads only essential drivers and services, preventing the scam's malicious processes from fully executing and allowing network access for anti-malware updates. Running a comprehensive anti-malware scan can then effectively identify and remove the associated files, browser extensions, and registry entries.

Why this answer

The fake security alert that cannot be closed and blocks Task Manager is a classic tech support scam, not actual malware that encrypts files or hides deep in the system. Booting into Safe Mode with Networking loads only essential drivers and services, bypassing the scam's persistence mechanism, and allows an anti-malware scan to remove the malicious files and registry entries.

Exam trap

The 220-1202 exam often tests the distinction between ransomware (which encrypts data) and tech support scams (which only display fake alerts), leading candidates to confuse the visible popup with actual file-encrypting malware.

How to eliminate wrong answers

Option A is wrong because a rootkit hides its presence by intercepting system calls at the kernel level, whereas this alert is a visible, user-mode popup that blocks Task Manager via simple registry or Group Policy changes, not kernel-level hooks. Option B is wrong because ransomware encrypts user files and demands payment for decryption, but this alert does not encrypt anything—it only displays a fraudulent message to trick the user into calling a phone number. Option D is wrong because a worm self-replicates across networks without user interaction, while this alert is a standalone scam that does not spread; reinstalling the OS is unnecessary when a targeted removal from Safe Mode suffices.

661
MCQeasy

A user reports that their workstation is running slowly and they see frequent pop-up ads even when no browser is open. They also notice a new toolbar in their system tray that they did not install. What is the most likely security issue?

A.A rootkit has hidden itself in the kernel.
B.The system has adware installed.
C.A ransomware encryption process has started.
D.The user's account has been phished and credentials stolen.
AnswerB

Adware matches the evidence precisely: pop-ups appearing without a browser open indicate a background process injecting advertisements, and the unrequested system-tray toolbar confirms bundled unwanted software. Unlike a virus, adware primarily generates revenue through forced advertising rather than self-replication, satisfying the stem's slow performance and persistent pop-up constraints.

Why this answer

Adware is a type of malware that displays unwanted advertisements, often in the form of pop-ups or browser redirects, and may install toolbars or other unwanted software without the user's consent. The presence of a new toolbar in the system tray and frequent pop-ups even when no browser is open are classic indicators of adware infection, as adware often runs background processes to generate revenue through ad impressions.

Exam trap

The distinction between adware and other malware types is a common test point in CompTIA A+. Candidates may confuse adware with a rootkit because both can be persistent, but rootkits are stealthy and do not produce visible ads or toolbars.

How to eliminate wrong answers

Option A is wrong because a rootkit is designed to hide its presence and maintain privileged access at the kernel level, not to display pop-up ads or install visible toolbars; rootkits typically avoid drawing attention. Option C is wrong because ransomware typically encrypts files and displays a ransom note, not pop-up ads or toolbars, and the system would show signs of file encryption or lock screen rather than slow performance with ads. Option D is wrong because phishing and credential theft lead to unauthorized access to accounts, not the installation of adware or the appearance of pop-up ads and toolbars on the local workstation.

662
MCQhard

A technician is deploying a new point-of-sale system in a busy retail store. The store manager insists on a specific configuration that the technician knows will cause data security vulnerabilities. Which of the following is the BEST course of action?

A.Implement the configuration as requested to keep the manager happy.
B.Refuse to do the work and walk away.
C.Explain the security risks in non-technical terms and propose a secure alternative that meets their needs.
D.Secretly implement a secure configuration and tell the manager it's what they asked for.
AnswerC

This is the most professional and effective approach, demonstrating a technician's commitment to both client satisfaction and robust security. By translating complex technical risks into understandable language, the technician empowers the manager to make informed decisions regarding their system's security posture. Proposing a secure alternative ensures the system's operational requirements are met while mitigating potential vulnerabilities, thereby protecting sensitive data and the business's reputation.

Why this answer

It aligns with the CompTIA A+ objective of balancing security with business needs. The technician must communicate the security risks of the manager's requested configuration (e.g., using default credentials or disabling encryption on the POS system) in non-technical terms, then propose a secure alternative that still meets the operational requirements, such as using WPA3 with a strong passphrase instead of an open Wi-Fi network. This approach maintains professionalism, avoids data breaches, and preserves the working relationship.

Exam trap

CompTIA often tests the trap that candidates choose Option A (compliance with authority) or Option B (rigid refusal) instead of the balanced, professional approach of explaining risks and proposing alternatives, which is the core of CompTIA's 'Communication and Professionalism' domain.

How to eliminate wrong answers

Option A is wrong because implementing an insecure configuration knowingly violates the technician's ethical and professional responsibility to protect sensitive payment card data, potentially leading to PCI DSS non-compliance and data breaches. Option B is wrong because walking away without attempting to educate the manager or offer a secure alternative is unprofessional and fails to resolve the issue, leaving the store vulnerable. Option D is wrong because secretly implementing a different configuration undermines trust and could cause operational issues if the manager discovers the change, and it does not address the root cause of the manager's misunderstanding.

663
MCQmedium

During a security audit, you find that a configuration file /etc/app/config.cfg has permissions -rwxrwxrwx. What command should you run to restrict it so only the owner can read and write, and the group can read, while others have no access?

A.chmod 640 /etc/app/config.cfg
B.chmod 750 /etc/app/config.cfg
C.chmod 644 /etc/app/config.cfg
D.chmod 600 /etc/app/config.cfg
AnswerA

The chmod 640 /etc/app/config.cfg command correctly sets the file permissions using octal notation. The '6' grants the file owner read and write access (4+2), allowing them to modify the configuration. The '4' assigns read-only access to the file's group, enabling applications running under that group to read the necessary settings. Finally, the '0' ensures that all other users have no access whatsoever, adhering to the principle of least privilege for sensitive configuration data.

Why this answer

The requirement is to set permissions so the owner can read and write (6), the group can read (4), and others have no access (0). The octal representation 640 achieves exactly this: 6 (rw-) for owner, 4 (r--) for group, and 0 (---) for others. This matches the security policy of restricting access to only the owner and group read access.

Exam trap

CompTIA often tests the distinction between 644 and 640, where candidates mistakenly choose 644 because they forget that 'others have no access' means the last digit must be 0, not 4.

How to eliminate wrong answers

Option B (750) is wrong because it grants the group execute permission (5) and others no access, but the requirement specifies group should only have read access, not execute. Option C (644) is wrong because it grants others read access (4), violating the requirement that others have no access. Option D (600) is wrong because it grants the group no access (0), but the requirement specifies the group should have read access.

664
MCQmedium

A user reports that their browser displays a warning saying 'Your connection is not private' when visiting a frequently used banking site. After checking, you see the certificate error is for a different domain. What is the most likely cause?

A.The user's system date and time are incorrect
B.The website's SSL certificate has expired
C.A malicious proxy or DNS hijacking is redirecting traffic to a fake site
D.The browser needs to be updated to the latest version
AnswerC

A malicious proxy or DNS hijacking attack can redirect a user's traffic from the legitimate website to a fraudulent, imposter site controlled by an attacker. When the browser attempts to establish an HTTPS connection with this fake site, the attacker presents an SSL certificate that either belongs to a completely different domain or is self-signed and untrusted. This mismatch between the expected domain and the domain listed on the presented certificate is a strong indicator of a man-in-the-middle attack, alerting the user to potential data interception or phishing.

Why this answer

The certificate error for a different domain indicates that the browser is being directed to a server whose SSL certificate does not match the expected banking site's domain. This is a classic sign of a man-in-the-middle attack, often caused by malicious proxy or DNS hijacking, where traffic is redirected to a fraudulent server presenting a certificate for a different domain.

Exam trap

CompTIA often tests the distinction between certificate errors caused by date/time issues versus domain mismatches, and the trap here is that candidates may confuse a 'different domain' error with a simple expired certificate or browser update issue.

How to eliminate wrong answers

Option A is wrong because an incorrect system date and time would cause a certificate validity error (e.g., 'not yet valid' or 'expired'), but the error would still reference the correct domain, not a different one. Option B is wrong because an expired SSL certificate would produce a warning about the certificate being out of date, but the domain in the certificate would still match the banking site's domain. Option D is wrong because an outdated browser might lack support for newer TLS versions or cipher suites, but it would not cause a certificate domain mismatch; the error would typically be about protocol or cipher incompatibility, not a different domain.

665
MCQmedium

A small business owner wants to replace their old wireless router because guests have been using the network to access inappropriate content. The owner wants to isolate guest traffic from the main business network and enforce content filtering. Which combination of wireless security and features should the technician recommend?

A.WPA3-Personal with MAC address filtering.
B.WPA2-PSK with a guest network enabled and content filtering via OpenDNS.
C.WPA2-Enterprise with a RADIUS server and no guest network.
D.WEP encryption with a hidden SSID.
AnswerB

WPA2-PSK secures the wireless link, while a guest network provides a separate SSID and VLAN, isolating visitor traffic from business resources. OpenDNS enforces content filtering at the DNS layer, satisfying the requirement to block inappropriate content without extra hardware.

Why this answer

WPA2-PSK with a guest network creates a separate VLAN or subnet that isolates guest traffic from the main business network, preventing guests from accessing internal resources. Content filtering via OpenDNS provides DNS-level filtering to block inappropriate content without requiring additional hardware, addressing both isolation and content control requirements.

Exam trap

The trap here is that candidates often choose WPA3-Personal or WPA2-Enterprise thinking stronger encryption equals better security, but the question specifically requires guest isolation and content filtering, which are features of a guest network and DNS-level filtering, not of the authentication protocol itself.

How to eliminate wrong answers

Option A is wrong because WPA3-Personal uses a shared passphrase and does not inherently isolate guest traffic; MAC address filtering is easily bypassed by spoofing and does not enforce content filtering. Option C is wrong because WPA2-Enterprise with a RADIUS server provides strong authentication but does not include a guest network, so guest traffic would still mix with the main network, and it lacks content filtering capabilities. Option D is wrong because WEP encryption is deprecated and easily cracked within minutes using tools like aircrack-ng; hiding the SSID only prevents casual discovery but does not isolate traffic or filter content.

666
MCQhard

A technician is installing a new UPS (Uninterruptible Power Supply) in a server rack. The UPS is heavy and must be mounted securely. What is the most important safety consideration during installation?

A.Ensure the UPS is connected to a grounded outlet before mounting.
B.Use a lifting team or mechanical lift to position the UPS.
C.Verify that the UPS batteries are charged before installation.
D.Install the UPS at the top of the rack for better airflow.
AnswerB

UPS units, especially larger models, contain heavy batteries and transformers, making them exceptionally weighty. Utilizing a lifting team of at least two individuals or a specialized mechanical lift, such as a server lift or rack lift, is crucial to prevent severe back injuries, muscle strains, or the accidental dropping and damaging of the expensive equipment. This practice adheres to fundamental workplace safety protocols for handling heavy loads.

Why this answer

The UPS is a heavy piece of equipment, and improper lifting can cause serious injury or damage. Using a lifting team or mechanical lift ensures safe handling and prevents back strain, crush injuries, or dropping the unit, which is the primary safety concern during physical installation.

Exam trap

The trap here is that candidates focus on electrical safety (grounding) or operational readiness (battery charge) instead of recognizing that the immediate physical hazard of moving a heavy object is the most critical safety consideration during installation.

How to eliminate wrong answers

Option A is wrong because grounding is an electrical safety step, but it is not the most important consideration during the physical mounting of a heavy UPS; the immediate risk of injury from lifting outweighs electrical concerns at this stage. Option C is wrong because verifying battery charge is a functional check, not a safety consideration during installation; batteries can be charged after the unit is securely mounted. Option D is wrong because installing the UPS at the top of the rack creates a top-heavy stability hazard and makes lifting more dangerous; heavy components should be mounted low in the rack for stability.

667
MCQmedium

A technician is removing malware from a Windows 10 PC and wants to ensure that no remnants remain in the registry or startup folders. After running an antivirus scan and deleting infected files, which additional step should the technician perform?

A.Run the Windows Memory Diagnostic tool.
B.Check and clean startup entries using MSConfig or Autoruns.
C.Disable System Restore to free up disk space.
D.Update all device drivers to the latest versions.
AnswerB

Checking and cleaning startup entries using utilities like MSConfig (System Configuration) or the more comprehensive Autoruns by Sysinternals is a crucial step in malware removal. Many malware strains establish persistence by adding entries to the Windows registry's Run keys, startup folders, or scheduled tasks, ensuring they automatically execute every time the system boots. Removing these malicious entries prevents the malware from reactivating after a reboot, effectively disrupting its ability to maintain control over the system.

Why this answer

Malware frequently persists via registry Run keys, startup folders, and scheduled tasks that survive file deletion. After an antivirus scan removes the payload, remnants in these autostart locations can re-download or re-execute the malware. Using MSConfig or Sysinternals Autoruns to inspect and clean startup entries ensures no persistence mechanism remains, which is the correct remediation step.

Exam trap

220-1202 often tests the misconception that an antivirus scan alone fully removes malware, when persistence mechanisms in the registry and startup folders must also be manually cleaned.

How to eliminate wrong answers

Option A is wrong because Windows Memory Diagnostic tests RAM hardware for faults — it has nothing to do with malware persistence or registry remnants. Option C is wrong because disabling System Restore only deletes restore points and frees disk space; it does not remove malware remnants and actually removes a recovery option. Option D is wrong because updating device drivers addresses hardware compatibility and stability, not malware persistence in registry or startup folders.

668
MCQeasy

A user reports that after a recent Windows update, the 'Local Users and Groups' snap-in is missing from the Computer Management console. The user needs to add a new local user account. Which administrative tool should be used to complete this task?

A.Run lusrmgr.msc from the Run dialog.
B.Open the Services console (services.msc) and restart the 'User Manager' service.
C.Use the Disk Management tool to create a new user volume.
D.Open the Registry Editor and modify the SAM registry hive.
AnswerA

Running lusrmgr.msc opens the standalone Local Users and Groups snap-in directly, bypassing the Computer Management console where the node has disappeared. This satisfies the requirement to add a new local user account, since the underlying management interface remains functional even when its parent console entry is missing after the update.

Why this answer

The 'Local Users and Groups' snap-in is a Microsoft Management Console (MMC) component that can be launched directly by running lusrmgr.msc from the Run dialog. This command opens the Local Users and Groups manager, which allows you to create, modify, and delete local user accounts and groups without needing the Computer Management console. Since the snap-in is missing from the console due to the update, using the standalone MMC command is the correct workaround.

Exam trap

The exam often tests the misconception that missing snap-ins require service restarts or registry edits, but the correct approach is to use the standalone MMC command for the specific snap-in.

How to eliminate wrong answers

Option B is wrong because there is no 'User Manager' service in Windows; the Local Users and Groups functionality is not a service that can be restarted via services.msc. Option C is wrong because Disk Management is used for managing disk partitions and volumes, not for creating user accounts. Option D is wrong because directly editing the SAM registry hive is unsupported, dangerous, and not a standard administrative tool for adding user accounts; it can corrupt the security database.

669
MCQhard

A company is migrating to a new cloud-based system and needs to dispose of old tape backup cartridges that contain years of financial data. The tapes are magnetic media. Which disposal method is most appropriate for this media type?

A.Overwrite the tapes with a bulk eraser.
B.Reformat the tapes using a tape drive.
C.Incinerate the tapes in a certified facility.
D.Delete the files from the tape catalog.
AnswerA

A bulk eraser, or degausser, generates a powerful alternating magnetic field that randomizes the magnetic domains on the tape's surface. This process effectively scrambles all recorded data, rendering it irrecoverable and ensuring complete data destruction. It is the industry-standard and most secure method for sanitizing magnetic media like tapes, as it physically alters the magnetic alignment across the entire medium.

Why this answer

A bulk eraser generates a strong magnetic field that completely demagnetizes magnetic tape media, rendering all data unrecoverable while allowing the tape to be reused. This is the standard sanitization method for magnetic media like tape cartridges. It satisfies data disposal requirements without destroying the media.

Exam trap

220-1202 often tests the difference between sanitization, destruction, and simple deletion, so the trap is choosing reformatting or catalog deletion, which do not actually remove data from magnetic media.

How to eliminate wrong answers

Option B is wrong because reformatting a tape only rewrites the file system structures; residual data remains recoverable with forensic tools, so it is not adequate sanitization. Option C is wrong because incineration destroys the media entirely, which is acceptable for destruction but not the most appropriate when the media can be safely sanitized and reused; also, not all tapes should be incinerated due to environmental regulations. Option D is wrong because deleting files from a tape catalog only removes index references, leaving the actual data intact on the tape.

670
MCQhard

A technician is troubleshooting an Android phone that cannot connect to Wi-Fi networks, even though other devices connect fine. The technician notices that the phone's MAC address is displayed as '02:00:00:00:00:00' in the Wi-Fi settings. Which feature is likely causing this, and how should it be resolved?

A.The phone is using a static IP configuration; change it to DHCP.
B.The Wi-Fi hardware is faulty; the phone needs repair.
C.The phone has a randomized MAC address enabled; disable it for the network.
D.The phone is in Airplane Mode; turn it off.
AnswerC

Android 10+ uses randomized MACs by default to enhance privacy; the address shown is a randomized one, and disabling it for that network can fix connection issues.

Why this answer

A MAC address of '02:00:00:00:00:00' is not a normal hardware MAC; it is a placeholder/zeroed address often seen when MAC randomization is enabled or when the device is masking its real MAC. Android uses MAC randomization by default for privacy, and some networks that filter or authenticate by MAC address will reject the device. Disabling randomized MAC for that specific network lets the phone use its permanent hardware MAC, which typically resolves the connection issue.

Exam trap

On the CompTIA A+ exam, MAC randomization is a privacy feature, not a hardware fault. Candidates often mistakenly choose hardware failure or static IP issues when they see an unusual MAC address.

How to eliminate wrong answers

Option A is wrong because a static IP configuration does not cause the MAC address to display as '02:00:00:00:00:00'; that address is a randomized MAC, not related to DHCP vs. static IP. Option B is wrong because a faulty Wi-Fi hardware would typically show no MAC address or an error, not a specific randomized MAC like '02:00:00:00:00:00', and other devices connect fine, ruling out a network-side issue. Option D is wrong because Airplane Mode disables all wireless radios, so the phone would not show any Wi-Fi networks or a MAC address in Wi-Fi settings; it would show 'Wi-Fi off' or similar.

671
MCQeasy

A user calls the help desk complaining that their browser homepage keeps changing to a site they did not set, and they cannot change it back. You remotely check and find no malware. What is the most likely cause?

A.The user's browser profile is corrupted.
B.A recently installed program modified the browser settings during installation.
C.The user's DNS settings are being hijacked by the ISP.
D.The browser's shortcut target is pointing to a different URL.
AnswerB

Bundled software frequently rewrites the homepage and search provider during installation, and some lock those settings via policy or registry entries, preventing the user from reverting them. Absence of malware points to a legitimate installer rather than an infection.

Why this answer

Many legitimate software installers include bundled programs or browser extensions that modify the default homepage, search provider, or new tab page as part of their installation routine. Even without malware, these changes are often made via registry keys (e.g., HKCU\Software\Microsoft\Internet Explorer\Main\Start Page) or browser policy files, and the user may not have unchecked the relevant option during setup. Since no malware was found, a recently installed program is the most likely cause of the unwanted homepage change.

Exam trap

The trap here is that candidates often assume any unwanted homepage change must be malware, but CompTIA tests the concept that legitimate software can alter browser settings during installation, and the absence of malware points to a non-malicious program as the cause.

How to eliminate wrong answers

Option A is wrong because a corrupted browser profile typically causes crashes, missing bookmarks, or sync errors, not a persistent homepage change that the user cannot revert. Option C is wrong because ISP DNS hijacking redirects all DNS queries for a domain to a different IP, which would affect navigation to any site, not just change the browser's homepage setting; the homepage is a local browser preference, not a DNS resolution issue. Option D is wrong because a modified shortcut target would only affect the homepage if the browser is launched with a command-line argument (e.g., --homepage URL), but the user would still be able to change the homepage within the browser settings; the shortcut target does not override the internal browser preference unless explicitly configured that way.

672
MCQeasy

A user reports that their Windows 10 laptop is running very slowly and the hard drive light is constantly active. The technician suspects a malware infection. Which of the following should the technician perform FIRST according to best practices?

A.Restart the laptop in Safe Mode with Networking.
B.Disconnect the laptop from the network.
C.Run a full antivirus scan on the laptop.
D.Use System Restore to revert to a previous restore point.
AnswerB

Disconnecting from the network immediately contains the potential infection, preventing malware from spreading to other systems or communicating with command-and-control servers. This is the first step in the incident response process for a suspected malware infection. It also preserves evidence for later analysis.

Why this answer

The first step in malware incident response is containment, which means disconnecting the device from the network to prevent the malware from spreading or communicating externally. Running scans, restarting in Safe Mode, or using System Restore are remediation steps that should follow containment. Isolation also preserves evidence for analysis.

Exam trap

The trap here is jumping to remediation like running a scan or using System Restore before isolating the system, which can allow malware to spread.

673
MCQmedium

A company policy requires that all workstations must have Windows Firewall enabled. You check a user's PC and find the firewall is off. Which Control Panel applet would you use to turn it back on?

A.Security and Maintenance
B.Windows Defender Firewall
C.Network and Sharing Center
D.System
AnswerB

The Windows Defender Firewall applet is the dedicated control panel for managing all aspects of the operating system's built-in firewall. It provides granular control over inbound and outbound connection rules, allowing administrators to define exceptions for specific applications, ports, and protocols. This interface is essential for configuring firewall profiles for different network types (Domain, Private, Public) to meet security policies, such as ensuring the firewall is active and properly configured on all workstations.

Why this answer

The Windows Defender Firewall applet (Option B) is the dedicated Control Panel interface for managing Windows Firewall settings, including turning the firewall on or off. Since the question specifically asks which applet to use to enable the firewall, this is the correct tool. Other applets may display firewall status but do not provide the direct toggle to enable or disable the firewall.

Exam trap

The trap here is that candidates often confuse Security and Maintenance (which shows a warning about the firewall being off) with the actual tool needed to fix the issue, leading them to select Option A instead of the correct Windows Defender Firewall applet.

How to eliminate wrong answers

Option A (Security and Maintenance) is wrong because it only reports the firewall status and provides a link to the Windows Defender Firewall applet, but does not contain the actual toggle to turn the firewall on or off. Option C (Network and Sharing Center) is wrong because it is used for managing network connections, adapters, and sharing settings, not for enabling or disabling the Windows Firewall. Option D (System) is wrong because it displays basic system information, hardware specs, and allows management of system properties like remote settings and device names, with no firewall controls.

674
MCQeasy

A user's computer is infected with adware that changes the browser homepage and displays constant pop-ups. After removing the adware with an antivirus, the homepage remains changed. What additional remediation step should you take?

A.Reinstall the operating system
B.Reset the browser settings to default
C.Run a disk cleanup utility
D.Update the antivirus definitions and scan again
AnswerB

Resetting the browser settings to their default configuration is the most effective and direct solution for adware that alters browser behavior, such as changing the homepage, default search engine, or injecting unwanted extensions. This action specifically targets and reverts all user-defined and malicious modifications within the browser's profile, restoring its original state without affecting the operating system or other applications. It efficiently eliminates the persistent symptoms of the adware infection.

Why this answer

After adware removal, the browser's homepage and settings are often stored in the browser's configuration files or registry keys that the antivirus does not reset. Resetting the browser settings to default restores the homepage, search engine, and new tab page to their original state, clearing any persistent malicious configurations left behind by the adware.

Exam trap

CompTIA often tests the misconception that a full OS reinstall is required for any persistent malware symptom, but the trap here is that the issue is a configuration change, not an active infection, so a targeted browser reset is sufficient.

How to eliminate wrong answers

Option A is wrong because reinstalling the operating system is an extreme measure that is unnecessary when the issue is isolated to the browser's settings; it would also delete user data and applications. Option C is wrong because a disk cleanup utility only removes temporary files and frees up disk space, it does not modify browser configuration settings or registry entries that control the homepage. Option D is wrong because updating antivirus definitions and scanning again would only detect and remove remaining malware files, but the adware has already been removed; the persistent homepage change is a configuration artifact, not an active infection.

675
MCQmedium

During a security audit, you discover that a user’s Windows 10 device has allowed multiple failed login attempts without locking the account. Which policy should you adjust to enforce account lockout after 5 failed attempts?

A.Password Policy – Minimum password length
B.Account Lockout Policy – Account lockout threshold
C.User Rights Assignment – Deny log on locally
D.Security Options – Interactive logon: Message text for users attempting to log on
AnswerB

The Account lockout threshold policy directly specifies the maximum number of consecutive unsuccessful login attempts permitted before a user account is automatically locked out. Once this threshold is met, the system prevents further login attempts for that account, typically for a defined duration or until an administrator intervenes. This policy is precisely designed to mitigate brute-force attacks by preventing an attacker from making unlimited login attempts.

Why this answer

The Account Lockout Policy – Account lockout threshold setting directly controls the number of failed logon attempts allowed before the account is locked. By setting this value to 5, the system will enforce a lockout after exactly five incorrect password entries, preventing further brute-force attempts until an administrator unlocks the account or the lockout duration expires.

Exam trap

The CompTIA A+ exam often tests the distinction between password policy settings (which govern password complexity and length) and account lockout policy settings (which govern failed attempt limits), leading candidates to mistakenly choose Password Policy options when the question is about lockout enforcement.

How to eliminate wrong answers

Option A is wrong because Minimum password length only enforces the number of characters required in a password, not the number of failed attempts before lockout. Option C is wrong because User Rights Assignment – Deny log on locally controls which users or groups are prohibited from logging on at the console, not the failed attempt count. Option D is wrong because Interactive logon: Message text for users attempting to log on sets a legal or informational banner displayed before logon, but does not affect account lockout behavior.

Page 8

Page 9 of 10

Page 10

All pages

Practice 220-1202 by domain

Target a specific domain to shore up weak areas.

See all domains with question counts →