Courseiva
Back to CompTIA A+ Core 2 220-1202 questions

Scenario-based practice

Hard Difficulty Questions

Practise CompTIA A+ Core 2 220-1202 practice questions — original exam-style scenarios covering every exam domain, with detailed explanations, wrong-answer analysis, and common exam traps.

20
scenario questions
220-1202
exam code
CompTIA
vendor

Scenario guide

How to approach hard difficulty questions

These are the questions most candidates get wrong. They require connecting multiple concepts, reading tricky output, or knowing edge-case behaviour that isn't on most study cards. Practising them trains you to operate under uncertainty — a necessary skill on the real exam.

Quick answer

Hard Difficulty Questions questions test whether you can apply the concept in context, not just recognise a definition.

How the topic appears in realistic exam-style scenarios.

Which detail in the question changes the correct answer.

How to eliminate plausible but wrong options.

How to connect the question back to the wider exam objective.

Related practice questions

Related 220-1202 topic practice pages

Scenario questions usually connect to one or more exam topics. Use these links to review the underlying concepts behind the scenario.

Practice set

Practice scenarios

Question 1hardmultiple choice
Full question →

A technician needs to deploy a script to 100 Windows 10 computers that will change the local administrator password. The script must run with elevated privileges and not leave the password visible in the script file. Which approach is most secure?

Question 2hardmultiple choice
Full question →

A company is decommissioning a data center and must destroy 1000 HDDs and 200 SSDs. The policy mandates that all data be destroyed on-site and that the drives be rendered physically unusable. Which combination of methods is most efficient?

Question 3hardmultiple choice
Full question →

An organization experiences a data breach when an attacker physically removes hard drives from a decommissioned server that was placed in a storage area without being properly sanitized. What physical security control should have been implemented?

Question 4hardmultiple choice
Full question →

A technician is performing a routine software update on a finance department server. The change management documentation specifies that the update must be applied during a maintenance window from 2:00 AM to 4:00 AM. At 3:30 AM, the update fails with an error. The technician has no rollback plan documented. What should the technician do?

Question 5hardmultiple choice
Full question →

A user's Windows 10 laptop is experiencing random restarts, especially under heavy load like gaming or video rendering. The Event Viewer shows multiple 'Kernel-Power 41' critical errors. The CPU temperature is normal, and the power supply is functioning. Which component is most likely causing the issue?

Question 6hardmultiple choice
Full question →

A company uses a private cloud for its internal applications. The IT team wants to ensure that if one physical host fails, the virtual machines running on it can be automatically restarted on another host with minimal downtime. Which feature should they implement?

Question 7hardmultiple choice
Full question →

During a security audit, a technician discovers that a company Android device has an app that can read SMS messages and access contacts without the user's knowledge. The app was sideloaded. What built-in Android security feature could have prevented this?

Question 8hardmultiple choice
Review the full routing breakdown →

A technician is troubleshooting a network issue for a remote employee. The employee's internet connection is unstable, and the technician suspects the home router. The employee is not technical and becomes defensive when the technician asks about their router setup. Which approach is MOST effective?

Question 9hardmultiple choice
Full question →

A user reports that a script they run daily now fails with 'Text file busy' error. The script is located on an NFS mount. Which command will show if the script is currently being used by another process?

Question 10hardmultiple choice
Full question →

A user reports that their Windows 10 PC is infected with malware that keeps reinstalling after removal. You need to boot into a minimal environment to run antivirus scans without malware interference. Which advanced startup option should you use?

Question 11hardmultiple choice
Full question →

A security audit reveals that a user's Windows 10 workstation has remote desktop enabled, which violates company policy. You need to disable Remote Desktop and ensure it cannot be easily re-enabled by the user. Which Control Panel tool should you use?

Question 12hardmultiple choice
Read the full VPN explanation →

A security analyst discovers that an attacker has been using a compromised VPN account to access the corporate network. The account belongs to a former employee who was terminated two weeks ago. Which of the following should the analyst do immediately to prevent further unauthorized access?

Question 13hardmultiple choice
Review the full subnetting walkthrough →

A technician needs to configure a Windows 10 computer to use a static IP address of 192.168.1.100 with subnet mask 255.255.255.0 and default gateway 192.168.1.1. Which command-line tool and syntax should be used?

Question 14hardmultiple choice
Full question →

During a routine check, a technician finds that a user's Windows 10 computer has an outdated antivirus that hasn't updated in 3 months. The user claims they never saw any update prompts. What is the most likely reason and the appropriate remediation?

Question 15hardmultiple choice
Full question →

An IT manager wants to implement a data destruction policy that meets the U.S. Department of Defense (DoD) 5220.22-M standard for top-secret data. The drives are HDDs and will be reused within the organization. Which method is required?

Question 16hardmultiple choice
Full question →

During a forensic investigation, a technician needs to recover files that a user deleted from their Mac's internal SSD several days ago. The Trash has been emptied. Which macOS feature or tool should be attempted first to recover these files?

Question 17hardmultiple choice
Full question →

A technician is investigating a privilege escalation vulnerability. They need to list all files in /usr/bin that have the SUID or SGID bit set and are owned by root. Which single command will achieve this?

Question 18hardmultiple choice
Full question →

A user's MacBook Air running macOS Ventura is experiencing intermittent kernel panics. The crashes seem to occur when the laptop is connected to a specific USB-C hub. Which macOS tool should you use to analyze the crash logs and identify the faulty driver?

Question 19hardmultiple choice
Full question →

A system administrator needs to change the group ownership of a directory /srv/data and all its contents to 'datagroup'. Which command will accomplish this recursively?

Question 20hardmultiple choice
Full question →

During a forensic investigation, an analyst needs to list all files in a directory that have been modified in the last 24 hours, including hidden files, and display the results with full path and timestamp. Which command should they use?

These 220-1202 practice questions are part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style 220-1202 questions with detailed explanations, topic-based practice, mock exams, readiness tracking, and study analytics.