220-1102 Operating Systems Practice Question
A technician is supporting a service-desk jump box. The immediate goal is to view listening ports and active connections. Which tool, control, or procedure is the best fit?
⚠ Common exam trap
Many exam-takers confuse Event Viewer's ability to log network events (like firewall blocks) with the real-time display of active connections and listening ports, leading them to incorrectly select Event Viewer instead of the dedicated network statistics tools.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
netstat or ss
B is correct because both `netstat` (Windows) and `ss` (Linux) are command-line tools specifically designed to display listening ports, active connections, routing tables, and protocol statistics. The technician's goal is to view listening ports and active connections, which is exactly what these utilities provide by default (e.g., `netstat -an` or `ss -tuln`).
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Event Viewer
Why it's wrong here
Event Viewer aggregates Windows event logs, which record historical system, security, and application events. However, it provides no real-time view of current TCP/UDP connections or active remote sessions, which is the immediate need on a jump box. While logs may reveal past login attempts or service failures, they cannot display the live network state required for this scenario.
- ✓
netstat or ss
Why this is correct
The netstat command (or its Linux counterpart ss) displays the active network connections, listening ports, and protocol statistics in real time. On a jump box, running netstat -ano shows each established connection with its owning process ID, while ss -tulpn provides comparable detail on Linux. This directly fulfills the goal of viewing live connections for troubleshooting, security auditing, or verifying remote access sessions.
- ✗
Local Users and Groups
Why it's wrong here
Local Users and Groups (lusrmgr.msc) manages local accounts, group memberships, and password policies. It is a security configuration tool used for access control, not for inspecting network activity or active connections. Viewing who is connected to the jump box over the network requires a network-centric utility like netstat, not an account management console.
- ✗
System Restore
Why it's wrong here
System Restore reverts the Windows system files, registry, and installed applications to an earlier restore point, primarily for undoing problematic changes. It does not offer any diagnostic visibility into current network connections or real-time system operations. Since the immediate goal is to view live connection data, System Restore is irrelevant and could even disrupt the current session if invoked.
Go deeper
Related to this question
Learn chapter
Remote Desktop Protocol (RDP)
Key term
Linux
Linux is an open-source operating system that manages computer hardware and software, widely used in servers, desktops, and embedded systems.
Key term
Windows
Windows is a family of operating systems developed by Microsoft that manages computer hardware and software, providing a graphical user interface for users to interact with their devices.
About these practice questions
One of 925 original 220-1102 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.