Courseiva
Software Troubleshooting →hardMultiple Choice

220-1102 Software Troubleshooting Practice Question

A technician is troubleshooting a Windows 10 workstation that randomly reboots with a blue screen error: 0x0000001A (MEMORY_MANAGEMENT). The technician runs the Windows Memory Diagnostic tool, which passes without errors. All device drivers and the system BIOS have been updated to the latest versions. Which of the following should the technician do NEXT to identify the root cause?

⚠ Common exam trap

A common mix-up: candidates assume a passed memory diagnostic means the RAM is fine, but the error can stem from other memory-related components like the memory controller, page file, or driver memory leaks, making event logs the next logical step.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Check the System and Application event logs for error events

The correct next step is to check the System and Application event logs for error events. Since the Windows Memory Diagnostic tool passed and drivers/BIOS are updated, the issue may be caused by a software conflict, driver timing issue, or a hardware problem that the memory test didn't catch. Event logs can provide specific error codes, module names, or faulting processes that point to the root cause, such as a faulty storage driver or a third-party application.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Check the System and Application event logs for error events

    Why this is correct

    When a Windows 10 machine reboots after a bugcheck, the most useful evidence is already saved in the System and Application event logs. The BugCheck event (ID 1001) records the stop code and the path to the memory dump, while preceding events often identify the faulty driver or service that triggered the MEMORY_MANAGEMENT (0x1A) crash. Application log entries can show faulting modules from user-mode components. Reviewing these logs is the correct first diagnostic step because it tells you what was happening immediately before the failure, narrowing the root cause.

  • ✗

    Run the System File Checker (sfc /scannow) to repair system files

    Why it's wrong here

    While corrupted system files can cause crashes, the technician has already updated drivers and BIOS. SFC is a good step earlier but less likely to be the root cause here; event logs should be checked first.

  • ✗

    Disable automatic restart on system failure to see the blue screen error details

    Why it's wrong here

    Disabling the automatic restart on system failure changes the behavior after the crash, not the crash itself; the system will remain on the blue screen instead of rebooting, but this only reveals a stop code that you already know. Since 0x0000001A is already captured, the more pressing need is contextual evidence—which driver, service, or memory operation preceded the failure—and that information lives in event logs and the memory.dmp minidump, not on the screen. This setting may be useful if the stop code were unknown, but here it does not advance the diagnosis.

  • ✗

    Replace the power supply unit (PSU)

    Why it's wrong here

    A failing PSU can absolutely cause random reboots by dropping or spiking power rails, but it typically does not generate a MEMORY_MANAGEMENT (0x1A) bugcheck, which indicates a violation in the kernel's virtual memory manager, often tied to bad RAM, page file corruption, or a buggy driver. Replacing the power supply without checking event logs, running memory diagnostics, or analyzing the minidump is an expensive guess that violates evidence-based troubleshooting. The stop code, not the symptom, points the investigation away from power delivery and toward memory-related components.

About these practice questions

Courseiva writes every 220-1102 question from scratch — 925 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.