Courseiva

CompTIA Tech+ (FC0-U71) (FC0-U71) — Questions 76–150

988 questions total · 14pages · All types, answers revealed

Page 1

Page 2 of 14

Page 3
76
MCQmedium

A user needs to collaborate on a document with colleagues in real-time. Which type of application should they use?

A.Email client
B.File compression tool
C.Local word processor
D.Cloud-based productivity suite
AnswerD

A cloud-based productivity suite stores the document centrally and synchronises edits instantly, letting multiple users work simultaneously. This satisfies the real-time collaboration requirement, unlike locally installed office software that relies on file sharing or emailed copies.

Why this answer

A cloud-based productivity suite (e.g., Microsoft 365, Google Workspace) stores documents on remote servers and uses WebDAV or proprietary sync protocols (like Google Drive API) to enable multiple users to edit the same file simultaneously. This real-time collaboration relies on operational transformation or conflict-free replicated data types (CRDTs) to merge edits without conflicts. Local or offline tools lack the network infrastructure to synchronize changes across users in real time.

Exam trap

The trap here is that candidates confuse 'collaboration' with simply sharing files via email or local editing, overlooking that real-time sync requires a cloud-based platform with live co-authoring protocols.

How to eliminate wrong answers

Option A is wrong because an email client (e.g., Outlook, Gmail) is designed for asynchronous message exchange via SMTP/IMAP, not for real-time document editing; it cannot propagate live changes to a shared file. Option B is wrong because a file compression tool (e.g., WinZip, 7-Zip) reduces file size using algorithms like DEFLATE but provides no networking or collaboration features. Option C is wrong because a local word processor (e.g., Microsoft Word installed locally) operates on a single file system without network connectivity or multi-user sync capabilities, so it cannot support real-time co-authoring.

77
MCQmedium

Which of the following SQL statements will add a new row to the 'Products' table?

A.UPDATE Products SET name='Widget', price=10.99
B.INSERT INTO Products VALUES ('Widget', 10.99)
C.CREATE ROW IN Products ('Widget', 10.99)
D.ADD INTO Products VALUES ('Widget', 10.99)
AnswerB

INSERT INTO appends a new row to the named table, with VALUES supplying the column data in table order. This satisfies the stem's requirement to add a row, whereas UPDATE modifies existing rows, SELECT retrieves them and CREATE TABLE defines structure.

Why this answer

The SQL INSERT statement is the standard Data Manipulation Language (DML) command used to add new rows to a table. The syntax INSERT INTO Products VALUES ('Widget', 10.99) inserts a new row with the specified values into the Products table, assuming the column order matches the table definition. This is the correct and ANSI-standard way to add data.

Exam trap

FC0-U71 often tests the confusion between DML statements (INSERT, UPDATE, DELETE) and DDL statements (CREATE, ALTER, DROP), and candidates may pick UPDATE because they associate it with modifying table data.

How to eliminate wrong answers

Option A is wrong because UPDATE modifies existing rows in a table — it does not add new rows, and without a WHERE clause it would change every row's name and price. Option C is wrong because CREATE ROW is not valid SQL syntax; CREATE is used for DDL objects like tables, views, and indexes, not for inserting rows. Option D is wrong because ADD INTO is not a valid SQL statement; the correct keyword is INSERT INTO, and ADD is used in ALTER TABLE contexts (e.g., ALTER TABLE ...

ADD COLUMN).

78
MCQmedium

A sales database has a Customers table with CustomerID as the primary key and an Orders table that includes CustomerID. Which type of relationship is typically established between Customers and Orders?

A.One-to-one
B.Many-to-many
C.Unrelated
D.One-to-many
AnswerD

One customer can place many orders, while each order belongs to exactly one customer, so CustomerID in Orders acts as a foreign key referencing the Customers primary key. This cardinality defines a one-to-many relationship, not one-to-one or many-to-many.

Why this answer

A single customer can place many orders, but each order belongs to exactly one customer, which is the definition of a one-to-many relationship. The CustomerID foreign key in the Orders table references the primary key in Customers, enforcing that each order is tied to one customer while allowing a customer to have multiple orders.

Exam trap

The trap is overthinking the relationship — candidates sometimes pick many-to-many because a customer can have many orders and an order can have many items, but the question is strictly about Customers and Orders.

How to eliminate wrong answers

Option A is wrong because one-to-one would mean each customer has at most one order and each order maps to one customer — that would require a unique constraint on Orders.CustomerID, which is not the case. Option B is wrong because many-to-many would require a junction table (e.g., CustomerOrders) linking customers and orders, allowing one order to belong to multiple customers — not how sales orders work. Option C is wrong because the presence of CustomerID as a foreign key in Orders explicitly establishes a relationship between the two tables.

79
MCQhard

A developer writes a function that opens a file, reads its contents, and then returns the data. If the file does not exist, the program should display a friendly message instead of terminating abruptly. Which approach best handles this situation?

A.Wrap the file read in a try-catch block and handle the file-not-found exception
B.Add comments describing what should happen if the file is missing
C.Use a loop to retry the file read indefinitely until it succeeds
D.Declare the file path as a constant at the top of the program
AnswerA

A try-catch block lets the code attempt the file read and intercept the exception raised when the file is missing. The catch block can then display the friendly message and allow the program to continue. This is the standard structured way to handle anticipated runtime errors without crashing, directly satisfying the requirement.

Why this answer

When an operation can fail for a predictable reason such as a missing file, structured exception handling allows the program to recover gracefully. The try block contains the risky read, and the catch block intercepts the specific error and presents a friendly message. Comments, constants, and unbounded retries do not intercept the failure, so they cannot prevent the abrupt termination.

Exam trap

The trap here is believing that documenting the failure or retrying automatically is equivalent to handling it, when only catching the exception lets the program respond in a controlled way.

80
MCQmedium

A computer has 8 GB of RAM. If the operating system and applications are using 3.2 GB, how much RAM is available for other processes?

A.4.8 GB
B.11.2 GB
C.5.8 GB
D.3.2 GB
AnswerA

Subtracting the 3.2 GB consumed by the operating system and applications from the installed 8 GB leaves 4.8 GB free. This satisfies the stem's constraint of calculating remaining RAM available for other processes, since RAM is a shared finite resource.

Why this answer

Available RAM is total RAM minus RAM in use: 8 GB − 3.2 GB = 4.8 GB. This is a straightforward subtraction problem testing basic memory capacity arithmetic.

Exam trap

FC0-U71 often tests basic arithmetic under time pressure — the trap is misreading 'available' as 'used' (picking D) or performing addition instead of subtraction (picking B).

How to eliminate wrong answers

Option B is wrong because 11.2 GB results from adding 8 + 3.2 instead of subtracting, which is a nonsensical operation since used memory cannot exceed total. Option C is wrong because 5.8 GB does not correspond to any correct arithmetic operation on 8 and 3.2 (it appears to be a miscalculation). Option D is wrong because 3.2 GB is the amount currently in use, not the amount available — the question asks for available memory, which is the complement.

81
MCQmedium

An office printer frequently jams and produces poor-quality color prints. The office manager decides to replace it with a printer that is faster and more cost-effective for high-volume black-and-white text documents. Which type of printer is most appropriate?

A.Thermal printer
B.Inkjet printer
C.Dot-matrix printer
D.Laser printer
AnswerD

Laser printers use a toner-based electrophotographic process that produces sharp text at high speed with a low cost per page, matching the high-volume monochrome requirement. Their straight paper path and durable mechanisms also reduce the frequent jamming the office currently experiences.

Why this answer

A laser printer uses a laser beam and toner to produce fast, high-volume black-and-white text documents at a low cost per page, making it the best fit for an office with frequent jams and poor color output that needs faster, more cost-effective monochrome printing.

Exam trap

The trap is focusing on the 'color prints' complaint and picking inkjet — candidates miss that the requirement is high-volume black-and-white text, where laser printers dominate on speed and cost per page.

How to eliminate wrong answers

Option A is wrong because thermal printers are used for receipts, labels, and barcodes, not general office documents, and they require special thermal paper. Option B is wrong because inkjet printers are slower for high-volume text, have higher cost per page, and are prone to clogging and smearing — the opposite of what the office needs. Option C is wrong because dot-matrix printers are impact printers used for multipart forms and carbon copies, are noisy, and produce low-resolution output unsuitable for high-volume office text.

82
MCQhard

A web application needs to send user registration data to a server. Which HTTP method should be used?

A.PUT
B.DELETE
C.POST
D.GET
AnswerC

POST carries registration data in the request body, keeping credentials out of the URL and supporting larger payloads. It satisfies the stem's need to send user data to a server, unlike GET, which appends data to the query string.

Why this answer

The POST method is designed to submit data to be processed to a specified resource, such as creating a new user registration record on a server. Unlike GET, which appends data to the URL, POST sends the registration data in the request body, making it suitable for non-idempotent operations where each submission creates a new resource or triggers server-side processing.

Exam trap

Many certification exams test the misconception that PUT is the correct method for creating new resources because it is idempotent, but the trap is that PUT requires a known resource URI (e.g., /users/123), whereas POST is used when the server assigns the new resource's identifier, as in user registration.

How to eliminate wrong answers

Option A (PUT) is wrong because PUT is intended to replace or update an existing resource at a specific URI, not to create a new registration entry without a known URL; using PUT for new registrations would require the client to know the final resource identifier beforehand. Option B (DELETE) is wrong because DELETE removes a specified resource, which is the opposite of sending registration data to create a new record. Option D (GET) is wrong because GET is used to retrieve data from the server, appending parameters to the URL query string, which is insecure for sensitive registration data and violates HTTP semantics by causing side effects on the server.

83
Multi-Selecthard

A technician is explaining how data is represented and processed in a computer. Which TWO of the following statements accurately describe the relationship between bits, bytes, and storage capacities? (Choose two.)

Select 2 answers
A.A kilobyte (KB) is always equal to 1,000 bytes in all contexts.
B.A megabyte (MB) is larger than a gigabyte (GB).
C.A nibble is half a byte and can represent 16 different values.
D.A bit can store more than two states, allowing it to represent multiple characters.
E.A byte consists of 8 bits and can represent 256 different values.
AnswersC, E

A nibble is 4 bits, which is half of an 8-bit byte. With 4 bits, there are 2^4 = 16 possible combinations, so it can represent values from 0 to 15. This is often used in hexadecimal notation, where each hex digit corresponds to one nibble. This statement is accurate and useful for understanding how binary data is grouped and displayed. The technician should confirm this as a correct description.

Why this answer

A byte is 8 bits and can represent 256 values, and a nibble is 4 bits with 16 possible values. These two statements accurately describe standard data units. The other statements contain common misconceptions about decimal versus binary prefixes, unit order, and the nature of a bit.

The technician should use these correct relationships to explain data representation.

Exam trap

The trap here is assuming that kilobyte always means 1,000 bytes, when in many computing contexts it historically meant 1,024 bytes, and confusing the order of magnitude between megabytes and gigabytes.

84
MCQeasy

A mobile app needs to display weather data from an online service. The app sends HTTP requests and receives responses in JSON format. This communication is made possible by a set of rules and protocols that allow the app and the service to interact. This set of rules is called a(n):

A.Data structure
B.API
C.SDLC
D.Algorithm
AnswerB

An API is the defined set of rules and protocols governing how one piece of software requests data from another. Here it governs the app's HTTP requests and the JSON responses returned by the weather service, enabling their interaction.

Why this answer

An API (Application Programming Interface) is a set of rules and protocols that allows different software applications to communicate with each other. In this scenario, the mobile app uses HTTP requests to interact with the weather service's API, which defines the endpoints, request formats, and JSON response structures. The API abstracts the underlying service implementation, enabling standardized data exchange.

Exam trap

FC0-U71 often tests the definition of API versus other computing concepts — candidates confuse API with data structures or algorithms because they all involve 'rules' or 'organization'.

How to eliminate wrong answers

Option A is wrong because a data structure is a way to organize and store data in memory (e.g., arrays, linked lists), not a communication protocol between applications. Option C is wrong because SDLC (Software Development Life Cycle) is a process for building software, not a mechanism for app-to-service communication. Option D is wrong because an algorithm is a step-by-step procedure for solving a problem, not a set of rules for network communication.

85
MCQeasy

Which of the following is a best practice for creating a strong password?

A.Using a long passphrase that includes symbols and numbers
B.Using a password with 8 characters including letters and numbers
C.Reusing the same password across multiple sites
D.Using your pet's name as a password
AnswerA

Length defeats brute-force and dictionary attacks far more effectively than complexity alone, while mixing symbols and numbers widens the search space. A passphrase remains memorable yet resists guessing, satisfying the best-practice requirement without relying on predictable substitutions or reused credentials.

Why this answer

A long passphrase that includes symbols and numbers is considered a best practice because it increases both length and complexity, making it significantly harder for attackers to crack using brute-force or dictionary attacks. Length is the most critical factor in password strength, and adding symbols and numbers further expands the search space. This approach aligns with guidance from NIST and other security organizations, which recommend passphrases over short, complex passwords.

Exam trap

FC0-U71 often tests the misconception that complexity alone (like 8 characters with letters and numbers) is sufficient for a strong password, when in fact length and uniqueness are more critical.

How to eliminate wrong answers

Option B is wrong because an 8-character password, even with letters and numbers, is no longer considered strong; modern hardware can crack such passwords quickly, and it lacks symbols and sufficient length. Option C is wrong because reusing the same password across multiple sites means a breach on one site compromises all others, violating the principle of unique credentials per account. Option D is wrong because using a pet's name is easily guessable through social engineering or public information, and it lacks complexity and length.

86
MCQhard

A security analyst discovers that a file on a server has been modified without authorization. Which element of the CIA triad has been compromised?

A.Non-repudiation
B.Integrity
C.Availability
D.Confidentiality
AnswerB

Integrity guarantees data remains unaltered unless changed by an authorised process. Because the file was modified without authorisation, its trustworthiness is broken, directly satisfying the scenario's unauthorised-modification constraint. Confidentiality concerns disclosure and availability concerns access, neither of which the stem describes.

Why this answer

Integrity ensures that data has not been altered or tampered with in an unauthorized manner. Since the file was modified without authorization, the integrity of the data has been compromised, which is the definition of an integrity violation in the CIA triad.

Exam trap

FC0-U71 often tests the CIA triad by describing a scenario and asking which element is affected — candidates sometimes pick confidentiality for any 'unauthorized' action, but modification always maps to integrity.

How to eliminate wrong answers

Option A is wrong because non-repudiation is not part of the CIA triad — it is a separate security property ensuring a party cannot deny having performed an action, typically provided by digital signatures. Option C is wrong because availability concerns whether data or systems are accessible when needed (e.g., DoS attacks), not whether data was altered. Option D is wrong because confidentiality concerns unauthorized disclosure of data, not unauthorized modification.

87
MCQhard

A database administrator is designing a new table to store employee records. The administrator wants to ensure that no two employees can have the same employee identification number, and that the employee identification number cannot be left empty. Which constraint should be applied to the EmployeeID column to meet both requirements?

A.CHECK
B.UNIQUE
C.FOREIGN KEY
D.PRIMARY KEY
AnswerD

A PRIMARY KEY constraint enforces both uniqueness and non-null values. It ensures that each EmployeeID is unique across all rows and that no row can have a NULL EmployeeID. This directly satisfies both requirements: preventing duplicate employee identification numbers and disallowing empty values in that column.

Why this answer

The PRIMARY KEY constraint uniquely identifies each row and enforces both uniqueness and non-null values. This meets the need to prevent duplicate employee identification numbers and to disallow empty values. UNIQUE allows nulls, FOREIGN KEY enforces referential integrity, and CHECK validates conditions but does not enforce uniqueness across rows.

Exam trap

The trap here is assuming that a UNIQUE constraint also prevents null values, when in most databases it permits one or more nulls.

88
MCQhard

Which internet connection type provides symmetric upload and download speeds over a fiber-optic cable?

A.Satellite
B.Fiber
C.Cable
D.DSL
AnswerB

Fiber uses optical transmission, which provides equal upload and download bandwidth rather than the asymmetric rates typical of DSL, cable and satellite. This satisfies the stem's requirement for symmetric speeds delivered over a fibre-optic cable.

Why this answer

Fiber-optic internet (often referred to as Fiber-to-the-Home or FTTH) uses light pulses transmitted through glass strands to deliver data. Unlike DSL or cable, fiber connections are inherently symmetric, meaning they provide identical upload and download speeds because the technology does not rely on asymmetric frequency division or shared coaxial infrastructure. This makes fiber the correct answer for symmetric speeds.

Exam trap

The trap here is that candidates confuse 'fiber' as a general term for any high-speed internet, but the question specifically tests the property of symmetric speeds, which is unique to fiber-optic connections among the listed options, not just a marketing label.

How to eliminate wrong answers

Option A is wrong because satellite internet uses radio waves to communicate with orbiting satellites, which introduces high latency and typically asymmetric speeds (download faster than upload) due to the nature of the satellite link and power constraints. Option C is wrong because cable internet (DOCSIS) uses coaxial cable and shared bandwidth, with upstream channels allocated less spectrum than downstream, resulting in asymmetric speeds (e.g., 300 Mbps down / 10 Mbps up). Option D is wrong because DSL (Digital Subscriber Line) uses telephone lines and is inherently asymmetric (ADSL) or, in the case of SDSL, is rarely deployed and still limited by copper line quality and distance, not fiber-optic cable.

89
MCQmedium

What is the primary risk of using public Wi-Fi without a VPN?

A.The Wi-Fi network may be slower
B.Data transmitted can be intercepted by attackers
C.The device may overheat
D.Increased risk of malware infection from the network
AnswerB

Public Wi-Fi carries traffic unencrypted across a shared medium, letting anyone on the same network capture packets with readily available tools. A VPN defeats this by tunnelling traffic through an encrypted channel, so interception yields only ciphertext. This directly addresses the stem's constraint: exposure of transmitted data to nearby attackers.

Why this answer

Public Wi-Fi is often unencrypted, allowing attackers to intercept data transmitted over the network. A VPN encrypts traffic, protecting data in transit.

90
Multi-Selectmedium

Which TWO of the following are appropriate steps when troubleshooting a user's inability to access the internet? (Select TWO.)

Select 2 answers
A.Check the IP address configuration
B.Restart the computer
C.Ping the default gateway
D.Replace the network cable
E.Power cycle the router
AnswersA, C

Verifies if the workstation has a valid IP.

Why this answer

Checking the IP address configuration is a fundamental first step in troubleshooting network connectivity. A misconfigured IP address, such as an Automatic Private IP Addressing (APIPA) address in the 169.254.x.x range, indicates that the device failed to obtain a valid IP from a DHCP server, which would prevent internet access. Verifying the IP configuration with commands like `ipconfig` (Windows) or `ifconfig` (Linux/macOS) helps identify if the device has a proper IP, subnet mask, and default gateway.

Exam trap

The trap here is that candidates often confuse general troubleshooting steps (like restarting the computer or power cycling the router) with the specific, targeted diagnostic steps required to isolate a network connectivity issue, leading them to select broad actions instead of precise checks like verifying the IP configuration or pinging the default gateway.

91
MCQeasy

A junior developer writes a program that stores a customer's age in a variable. The program must later perform arithmetic, such as adding five years to that age. Which data type is MOST appropriate for this variable?

A.Boolean
B.Array
C.Integer
D.String
AnswerC

An integer stores whole numbers and supports arithmetic operations, so it can hold an age and allow adding five years. Ages are naturally whole values, making an integer a precise and efficient choice without unnecessary decimal precision. This matches the stated requirement to perform arithmetic on the stored value.

Why this answer

The variable must hold a whole-number age and support arithmetic such as adding five years. An integer satisfies both requirements directly, providing numeric storage and calculation. A Boolean cannot represent numbers, a string treats the value as text and concatenates instead of adding, and an array is meant for collections rather than a single scalar value.

Exam trap

The trap here is assuming any type that can display the age, such as a string, is acceptable, when the requirement is specifically to perform arithmetic on it.

92
MCQhard

A technician is troubleshooting a workstation that randomly loses its connection to a file server. The workstation's IP address is 169.254.10.25, and it cannot reach the default gateway. The switch port shows link and activity lights. Which of the following is the MOST likely cause?

A.The DNS server is unreachable.
B.The DHCP server is not responding to requests.
C.The network cable is damaged or disconnected.
D.The file server's firewall is blocking SMB traffic.
AnswerB

When a DHCP client cannot obtain a lease, Windows and many other operating systems self-assign an address in the 169.254.0.0/16 range, known as APIPA or link-local. That address has no gateway, so the workstation cannot reach the file server on another subnet. The link lights confirm the physical connection is fine, which points to a DHCP communication failure rather than a cable or switch port problem.

Why this answer

An address in the 169.254.0.0/16 range is self-assigned by the operating system when DHCP attempts fail. Because no lease is obtained, no default gateway or DNS servers are provided either, which explains why the workstation cannot reach the file server. Link lights confirm the cable and switch port are working, so the next step is to investigate the DHCP server, scope, or relay.

Exam trap

The trap here is focusing on the file server or DNS when the link-local address already proves the workstation never received a valid IP configuration.

93
MCQhard

You are a desktop support technician for a small accounting firm. The firm uses a legacy accounting application that only runs on Windows 7. The application stores data in a local SQL Server Express database. A user reports that since the IT department applied a mandatory security update last night, the accounting application fails to start and displays an error: 'Cannot connect to database server. Check that the SQL Server (MSSQLSERVER) service is running.' You verify that the SQL Server service is set to Automatic but is not running. When you attempt to start it manually, it fails with error 1069: 'The service did not start due to a logon failure.' Which of the following is the MOST likely cause and solution?

A.The security update changed the service startup type to Disabled. Set it back to Automatic.
B.The security update deleted the database file. Reinstall the application.
C.The password for the service account has expired or was changed. Update the service logon credentials.
D.The security update corrupted the database files. Restore the database from backup.
AnswerC

Error 1069 means the SQL Server service could not log on with its configured account, typically because that account's password expired or was changed by the security update. Re-entering the current credentials in the service's Log On properties restores startup.

Why this answer

Error 1069 specifically indicates a logon failure for the service account. When a mandatory security update is applied, it may enforce password expiration policies or reset the service account password, causing the SQL Server service to fail to start. Updating the service logon credentials in the Services console resolves the issue.

Exam trap

The trap here is that candidates may confuse a service startup failure (error 1069) with a database corruption or missing file issue, but the error code directly points to authentication failure for the service account, not data integrity.

How to eliminate wrong answers

Option A is wrong because the service startup type is still set to Automatic (as verified), not Disabled, and error 1069 is unrelated to startup type changes. Option B is wrong because a deleted database file would cause a different error (e.g., 'database not found'), not a logon failure for the service. Option D is wrong because corrupted database files would produce database-level errors (e.g., 'database corrupt'), not a service logon failure (error 1069).

94
MCQmedium

A technician is installing RAM in a desktop computer. The motherboard supports dual-channel memory. Which memory configuration will provide the BEST performance?

A.One 8 GB and one 4 GB DDR4 module
B.Two 8 GB DDR4 modules in matching slots for dual-channel
C.Two 8 GB DDR4 modules in the same channel
D.One 16 GB DDR4 module
AnswerB

Dual-channel mode requires matched modules in the paired slots, letting the memory controller interleave two 64-bit channels into a 128-bit aggregate path. Two identical 8 GB DDR4 modules therefore double theoretical bandwidth versus a single module, satisfying the best-performance constraint.

Why this answer

Dual-channel memory requires two identical memory modules installed in matching slots to double the memory bandwidth.

95
MCQhard

A developer is testing a piece of code that calculates discounts. The code should give 10% off for orders over $100, and 5% off for orders between $50 and $100. Which test input set would best verify boundary conditions?

A.$50, $100, $150
B.$0, $50, $100, $200
C.$50.00, $100.00
D.$49.99, $50.00, $99.99, $100.00, $100.01
AnswerD

These values sit exactly on and just outside each threshold: $50.00 and $100.00 are boundaries, while $49.99, $99.99 and $100.01 test just below and above. This exercises the 5% and 10% discount transitions, satisfying the boundary-condition requirement.

Why this answer

It tests the exact boundary values for the discount tiers: $49.99 (just below $50, no discount), $50.00 (5% threshold), $99.99 (still 5%), $100.00 (boundary between 5% and 10%), and $100.01 (10% threshold). This set validates both the lower and upper edges of each range, ensuring the code handles floating-point comparisons correctly.

Exam trap

The trap here is that candidates often pick Option A or C, thinking that testing the exact boundary values ($50, $100) is sufficient, but they miss the need to test values just outside the boundaries to catch off-by-one or floating-point comparison errors.

How to eliminate wrong answers

Option A is wrong because it only tests $50, $100, and $150, missing the critical values just below and above the boundaries (e.g., $49.99, $100.01) that could expose off-by-one errors. Option B is wrong because it includes $0 and $200, which are not boundary values for the given ranges, and omits $49.99 and $100.01, failing to test the exact edges. Option C is wrong because it only tests the exact boundary values $50.00 and $100.00, but does not test values just below or above them (e.g., $49.99, $100.01), which are necessary to catch rounding or comparison errors.

96
Multi-Selectmedium

Which TWO of the following are characteristics of a solid-state drive (SSD) compared to a hard disk drive (HDD)?

Select 2 answers
A.Higher storage capacity
B.Silent operation
C.Lower cost per gigabyte
D.Sensitive to magnetic fields
E.Faster access time
AnswersB, E

SSDs have no moving parts, so they operate silently.

Why this answer

SSDs have no moving parts; they use NAND flash memory to store data, which eliminates the mechanical noise produced by spinning platters and moving actuator arms in HDDs. This makes SSDs completely silent during operation, a key advantage in noise-sensitive environments like recording studios or quiet office spaces.

Exam trap

The trap here is that candidates often assume 'higher storage capacity' (option A) is a characteristic of SSDs because they are newer technology, but in reality, HDDs still dominate in raw capacity per dollar, and the question specifically asks for characteristics of an SSD compared to an HDD.

97
MCQmedium

A user downloads a software installer from the internet. On Windows, which file extension is most likely to be used for the installer?

A..pkg
B..deb
C..exe
D..dmg
AnswerC

Windows executables use the .exe extension, which the OS loader recognises as a Portable Executable binary it can run directly. Downloadable installers for Windows are therefore distributed as .exe files, satisfying the scenario's requirement for the most likely installer extension on that platform.

Why this answer

On Windows, the standard file extension for executable programs and software installers is .exe (executable). When a user downloads an installer for Windows, it is typically an .exe file that can be run to install the application. The other extensions are associated with different operating systems: .pkg and .dmg are used on macOS, and .deb is used on Debian-based Linux distributions.

Exam trap

FC0-U71 often tests the association of file extensions with their respective operating systems, and candidates may confuse macOS or Linux package formats with Windows executables.

How to eliminate wrong answers

Option A is wrong because .pkg is a package file format used by macOS for software installation, not Windows. Option B is wrong because .deb is a package format used by Debian and Debian-based Linux distributions like Ubuntu, not Windows. Option D is wrong because .dmg is a disk image file used on macOS for distributing software, not Windows.

98
MCQhard

An IT administrator is setting up a virtualization server to run multiple operating systems. The server will host critical business applications and requires maximum performance and reliability. Which type of hypervisor should the administrator choose?

A.Hosted hypervisor like VirtualBox
B.Type 1 hypervisor, such as VMware ESXi
C.Containerization platform like Docker
D.Type 2 hypervisor, such as VMware Workstation
AnswerB

A Type 1 hypervisor runs directly on the host hardware, so guest operating systems bypass an underlying OS and gain lower latency plus fewer failure points. That bare-metal architecture satisfies the maximum performance and reliability demanded by critical business applications.

Why this answer

A Type 1 (bare-metal) hypervisor like VMware ESXi runs directly on the host hardware without an underlying OS, giving it direct access to CPU, memory, and I/O resources. This architecture delivers the lowest virtualization overhead, highest performance, and best reliability — critical for hosting business-critical applications. Type 1 hypervisors also offer advanced features like vMotion, HA, and resource pools that enterprises rely on.

Exam trap

FC0-U71 often tests whether candidates can distinguish Type 1 vs Type 2 hypervisors and whether they mistakenly treat containerization (Docker) as a hypervisor — picking Docker for 'multiple operating systems' is the classic error.

How to eliminate wrong answers

Option A is wrong because a hosted (Type 2) hypervisor like VirtualBox runs on top of a general-purpose OS, adding overhead and reducing performance and reliability — unsuitable for critical production workloads. Option C is wrong because Docker is a containerization platform, not a hypervisor; containers share the host OS kernel and provide process isolation rather than full VM isolation, so they cannot run multiple different OS kernels and lack the hardware-level isolation a hypervisor provides. Option D is wrong because VMware Workstation is a Type 2 hypervisor that requires a host OS (Windows/Linux), introducing overhead and making it inappropriate for a dedicated high-performance virtualization server.

99
MCQeasy

A developer writes a script to calculate the average of a list of numbers. The script uses a loop to sum the numbers and then divides by the count. Which programming concept does this represent?

A.Iteration
B.Selection
C.Recursion
D.Sequence
AnswerA

The loop repeatedly executes the summation step for each element in the list, which is iteration: repeating a block of statements over a collection. Dividing afterwards is arithmetic, but the loop-driven repetition is the concept being demonstrated.

Why this answer

The script uses a loop to repeatedly access each number in the list and add it to a running total. This repeated execution of a block of code (the loop body) is the defining characteristic of iteration. Iteration is the correct programming concept because the average calculation depends on cycling through a sequence of elements, which is exactly what a loop provides.

Exam trap

The trap here is that candidates may confuse 'sequence' (the general order of steps) with 'iteration' (the repeated execution of a block), especially since the script does follow a sequence of steps, but the key distinguishing concept is the loop that repeats the summing operation.

How to eliminate wrong answers

Option B (Selection) is wrong because selection involves making a decision based on a condition (e.g., if-else statements), not repeatedly executing a block of code. Option C (Recursion) is wrong because recursion involves a function calling itself to solve a problem by breaking it into smaller subproblems, whereas this script uses an explicit loop to process the list. Option D (Sequence) is wrong because sequence refers to the order in which statements are executed one after another, but the core mechanism here is the repeated execution of the summing operation, not just the linear order of steps.

100
Multi-Selectmedium

A network administrator is documenting the physical topology of a new office. The design uses a central switch with a dedicated cable to every desk, and the administrator wants to describe the strengths of this layout. Which TWO characteristics accurately describe this topology? (Choose two.)

Select 2 answers
A.Adding a new workstation requires breaking the existing cable path
B.All devices share a single common backbone cable
C.Data travels in one direction around a closed loop
D.A single cable failure affects only the device connected to that cable
E.The central switch is a single point of failure for the network
AnswersD, E

In a star topology, each endpoint has its own dedicated link to the central switch. If one cable is cut or a connector fails, only that workstation loses connectivity while all other devices continue communicating normally. This fault isolation is a key advantage of the star layout in office environments.

Why this answer

A star topology connects every device to a central switch through its own dedicated cable. This design isolates faults to individual links, so one damaged cable affects only that workstation. The trade-off is that the central switch becomes a single point of failure for the whole network.

Shared backbones, cable-path interruptions, and looped traffic describe bus and ring topologies instead.

Exam trap

The trap here is confusing the star's per-device fault isolation with the bus topology's shared-cable vulnerability.

101
MCQeasy

What is the primary purpose of a password manager?

A.To store passwords in the cloud for easy access
B.To encrypt all network traffic
C.To share passwords securely with team members
D.To generate and store strong, unique passwords
AnswerD

A password manager generates high-entropy, unique credentials per site and stores them in an encrypted vault unlocked by one master passphrase. This directly counters credential reuse and weak passwords, the primary purpose the question asks for.

Why this answer

A password manager's core function is to create high-entropy, unique passwords for every account and store them in an encrypted vault, eliminating password reuse and weak credentials. It uses a master password and strong encryption (e.g., AES-256) to protect the vault, and can auto-fill credentials, reducing human error. While some managers offer cloud sync or sharing, those are secondary features, not the primary purpose.

Exam trap

The trap here is confusing a password manager's primary purpose with its secondary features like cloud storage or sharing, which are often highlighted in marketing but are not the core function.

How to eliminate wrong answers

Option A is wrong because storing passwords in the cloud is an optional feature for synchronization, not the primary purpose; many password managers are local-only, and cloud storage alone without encryption and generation is insecure. Option B is wrong because encrypting all network traffic is the role of a VPN or TLS, not a password manager. Option C is wrong because secure password sharing is a convenience feature in some team-oriented managers, but it is not the core purpose; the primary goal is individual credential security.

102
MCQmedium

A small business wants employees to use a cloud-based office suite so that multiple people can edit the same document at the same time and see each other's changes immediately. Which characteristic of the cloud-based suite makes this possible?

A.The suite is installed locally on each employee's computer.
B.The suite saves the document only when the user manually clicks Save.
C.The suite stores documents on a central server and supports real-time co-authoring.
D.The suite requires each employee to email the document to the next editor.
AnswerC

A cloud-based suite keeps documents on a central service and uses real-time co-authoring so each participant's edits appear for others almost instantly. The service merges changes and tracks who is editing. This directly enables multiple employees to work in the same document at the same time and see each other's updates without exchanging files manually.

Why this answer

Real-time collaboration in a cloud-based office suite depends on central document storage plus continuous synchronization between participants. That combination lets several employees edit one shared document and see each other's changes as they happen. Local installation, email handoffs, and manual saving do not provide that simultaneous shared editing experience.

Exam trap

The trap here is confusing any online file storage with true real-time co-authoring, which requires live synchronization rather than just a shared folder.

103
MCQmedium

A developer needs to store several related values for one record, such as a product's name, price, and quantity, and pass them around as a single unit. The values have different data types. Which data structure is MOST appropriate?

A.An array of integers
B.A record or struct with named fields
C.A single string containing all values separated by commas
D.A Boolean flag
AnswerB

A record or struct groups related values under one name, with each field having its own type. This lets the product name, price, and quantity travel together as a single unit while preserving type safety. It directly matches the need to treat several differently typed, related values as one logical entity.

Why this answer

The product record combines a text name, a numeric price, and a numeric quantity that belong together. A record or struct with named fields stores these related, differently typed values as one unit and keeps each field's type intact. A delimited string loses typing, a Boolean is too limited, and an integer array cannot hold the text name or provide meaningful field names.

Exam trap

The trap here is choosing a string because it can technically hold everything, ignoring that it discards data types and requires reparsing.

104
MCQeasy

Which component of the CIA triad ensures that data cannot be modified by unauthorized users?

A.Integrity
B.Authentication
C.Availability
D.Confidentiality
AnswerA

Integrity guarantees data remains accurate and unaltered unless changed by an authorised party, directly matching the requirement that unauthorised users cannot modify it. Confidentiality restricts who can read data, and availability ensures timely access, so neither addresses modification.

Why this answer

Integrity, the 'I' in the CIA triad, specifically ensures that data remains accurate, complete, and unaltered unless modified by authorized parties. It protects against unauthorized modification, deletion, or corruption, whether the data is at rest, in transit, or in use. Authentication verifies identity, availability ensures access, and confidentiality prevents unauthorized disclosure—none of these directly address modification prevention.

Exam trap

The trap here is confusing authentication with integrity, as candidates often think that verifying a user's identity (authentication) also ensures data cannot be modified, but authentication only controls access, not the modification itself.

How to eliminate wrong answers

Option B is wrong because authentication is not a component of the CIA triad; it is a separate security principle that verifies the identity of a user or system, often serving as a prerequisite for access control but not ensuring data integrity. Option C is wrong because availability ensures that data and systems are accessible to authorized users when needed, focusing on uptime and resilience rather than preventing unauthorized modification. Option D is wrong because confidentiality ensures that data is not disclosed to unauthorized individuals, typically through encryption or access controls, but it does not prevent authorized users from modifying data or address unauthorized changes.

105
MCQeasy

A programmer needs to store a customer's name in a variable. Which data type is most appropriate?

A.String
B.Float
C.Integer
D.Boolean
AnswerA

A customer name is textual data, so String stores the sequence of characters directly. Numeric types such as int or double cannot hold letters, and char holds only a single character, making String the appropriate choice.

Why this answer

A customer's name is a sequence of characters (letters, spaces, possibly punctuation), which is best represented as a String data type. In most programming languages, strings are used to store text and are enclosed in quotes (e.g., "John Doe"). This aligns with the fundamental concept that names are not numeric or logical values.

Exam trap

The trap here is that candidates might confuse a customer's name with a numeric identifier (like an ID) and incorrectly choose Integer, but names are inherently textual and require a string data type.

How to eliminate wrong answers

Option B (Float) is wrong because a float is a data type for storing decimal numbers (e.g., 3.14), not textual data like a name. Option C (Integer) is wrong because an integer stores whole numbers (e.g., 42) and cannot hold alphabetic characters. Option D (Boolean) is wrong because a boolean stores only true or false values, which cannot represent a customer's name.

106
MCQeasy

A technician is setting up a new wireless router for a home office. The user wants to ensure that devices can connect using the latest standard for better speed and reduced interference. Which wireless standard should the technician configure the router to use?

A.802.11n
B.802.11g
C.802.11ac
D.802.11ax
AnswerD

802.11ax, also known as Wi-Fi 6, is the latest widely adopted wireless standard. It offers higher speeds, better performance in crowded areas, and improved efficiency through technologies like OFDMA and MU-MIMO. Configuring the router to use 802.11ax provides the best current balance of speed and reduced interference.

Why this answer

802.11ax, or Wi-Fi 6, is the latest mainstream wireless standard, offering improved speed, efficiency, and reduced interference compared to older standards. It is designed for environments with many devices and provides better performance. Configuring the router to use 802.11ax ensures the home office benefits from current wireless technology.

Exam trap

The trap here is selecting a familiar but older standard like 802.11ac instead of the latest 802.11ax when the goal is current performance.

107
MCQhard

A user's web browser warns that the connection to an online store is not private because the site's certificate cannot be validated. The user ignores the warning and enters payment card details anyway. Which type of attack is the user MOST at risk of in this situation?

A.SQL injection against the store's product database.
B.Denial-of-service attack flooding the store's web server.
C.Cross-site scripting running in the store's checkout page.
D.On-path attack intercepting the unverified connection.
AnswerD

A certificate validation failure often means the browser cannot confirm it is talking to the real store, which is exactly the condition an on-path attacker creates by inserting themselves between the user and the site. Continuing past the warning can send card details through the attacker's system. Trusting an unvalidated certificate defeats the protection TLS is meant to provide.

Why this answer

When a browser cannot validate a site's certificate, the identity of the server is in doubt, which is the hallmark of an on-path attack redirecting traffic to an imposter endpoint. Entering payment details in that state can hand them directly to the attacker. The other listed attacks target availability or server-side application flaws and are not signaled by a certificate validation warning.

Exam trap

The trap here is treating a certificate warning as a harmless glitch, when it actually undermines the identity check that protects against an on-path attacker.

108
MCQmedium

A company issues smartphones to employees and needs to enforce security policies such as remote wipe and mandatory encryption. Which technology should the IT department implement?

A.Antivirus software
B.VPN
C.MDM
D.Firewall
AnswerC

MDM centrally enforces device policies such as mandatory encryption and remote wipe across enrolled smartphones. It satisfies the requirement to apply security controls to company-issued devices, unlike standalone antivirus or VPN tools that do not manage device configuration.

Why this answer

Mobile Device Management (MDM) is the correct technology because it provides centralized policy enforcement for smartphones, including remote wipe, mandatory encryption, passcode requirements, and app management. MDM agents on the device check in with the MDM server (e.g., Intune, Jamf, Workspace ONE) and apply configuration profiles that enforce these controls. This directly matches the stated requirements.

Exam trap

FC0-U71 often tests the confusion between MDM and VPN/antivirus, tricking candidates into picking a security tool that only addresses one aspect (malware or transit) instead of centralized device policy management.

How to eliminate wrong answers

Option A is wrong because antivirus software only detects and remediates malware; it cannot enforce encryption, remote wipe, or device-wide security policies. Option B is wrong because a VPN only secures data in transit between the device and a private network; it does not manage device configuration or enable remote wipe. Option D is wrong because a firewall filters network traffic at a boundary or host level and has no capability to enforce endpoint security policies or perform remote wipe.

109
MCQmedium

A user is concerned about connecting to a public Wi-Fi network at a coffee shop. Which security measure can best protect their data?

A.Use HTTPS websites only
B.Use a firewall
C.Disable antivirus
D.Use a VPN
AnswerD

A VPN encrypts all traffic between the user's device and the VPN server, creating a protected tunnel that prevents attackers on the public Wi-Fi network from intercepting credentials, messages, or browsing data. This directly satisfies the coffee-shop scenario's constraint: untrusted network traffic requiring confidentiality against local eavesdropping.

Why this answer

A VPN encrypts traffic between the user's device and the VPN server, protecting data on public networks.

110
MCQhard

A technician is installing a legacy application on Windows 10 and receives an error log indicating 'Access Denied'. Which of the following should the technician do FIRST?

A.Install MSXML6.
B.Run the installer as Administrator.
C.Install .NET Framework 3.5.
D.Upgrade the application to a newer version.
AnswerB

'Access Denied' during installation indicates the process lacks rights to write to protected locations such as Program Files or the registry. Running the installer as Administrator elevates the token, granting the permissions needed to complete installation.

Why this answer

Legacy applications often require elevated privileges to install on Windows 10 because they may attempt to write to system directories or registry keys that are protected by User Account Control (UAC). Running the installer as Administrator is the simplest and most common first troubleshooting step to resolve permission-related issues before considering other solutions like missing dependencies or application upgrades.

Exam trap

The trap here is that candidates see a legacy application and immediately assume a missing dependency (like MSXML or .NET) is the cause, overlooking the simple permission issue that is the most common first step in troubleshooting installation failures.

How to eliminate wrong answers

Option A is wrong because MSXML6 is a specific XML parser that would only be relevant if the log explicitly cited a missing MSXML component, not a general permission error. Option C is wrong because .NET Framework 3.5 is a runtime dependency that would produce a different error (e.g., 'Framework not found'), not an access-denied message. Option D is wrong because upgrading the application is a long-term solution that bypasses the root cause; the technician should first attempt to install with elevated privileges, which is simpler and preserves legacy compatibility.

111
MCQmedium

A home user reports that a web page loads slowly and intermittently fails to open, but other users on the same network reach the same site without trouble, and the site is reachable from a mobile phone on cellular data. The technician suspects the browser is holding outdated cached data for that site. Which action should the technician take first?

A.Change the DNS server addresses on the router
B.Reboot the internet service provider modem
C.Clear the browser cache and cookies
D.Replace the network interface card
AnswerC

A browser cache stores copies of pages, scripts, and images so they load faster on repeat visits. When those copies become stale or corrupt, the browser can render an outdated version or stall while requesting resources. Clearing the cache and cookies forces the browser to fetch fresh content from the web server, which directly addresses the suspected cause and is non-destructive to the rest of the system.

Why this answer

The symptom is isolated to one browser on one machine while other devices reach the same site, which points to locally stored browser data rather than network hardware, the shared internet link, or DNS. Clearing the cache and cookies forces a fresh fetch from the server and directly resolves stale or corrupt cached content.

Exam trap

The trap here is escalating to network hardware or shared services when the evidence shows the problem is confined to a single browser on a single device.

112
Multi-Selectmedium

A user is setting up a new wireless router for a home office and wants to secure the wireless network. Which TWO of the following should the user configure to help prevent unauthorized access? (Choose two.)

Select 2 answers
A.Enable DHCP on the router
B.Change the default administrator password
C.Enable WPA3 encryption
D.Disable SSID broadcast
E.Place the router near a window
AnswersB, C

Default administrator credentials are publicly known and are a common entry point for attackers to reconfigure the router. Changing the default password to a strong, unique one prevents unauthorized users from accessing the router's management interface and altering security settings. This is a fundamental step in securing any network device and directly reduces the risk of unauthorized access, making it a correct choice.

Why this answer

To secure a home wireless network, the user should enable strong encryption such as WPA3 and change the router's default administrator password. WPA3 protects data in transit and controls who can join, while changing the default admin password prevents unauthorized reconfiguration. The other options either provide minimal protection, are unrelated to security, or can increase exposure.

Exam trap

The trap here is believing that disabling SSID broadcast or enabling DHCP improves security, when these either provide only obscurity or are convenience features that do not prevent unauthorized access.

113
MCQhard

A user reports that a desktop application crashes every time it tries to save a file to a network drive. Other applications work fine. Which is the MOST likely cause?

A.Outdated network driver
B.Insufficient local disk space
C.Corrupted application installation
D.Insufficient permissions on the network share
AnswerD

A network share enforces NTFS and share-level access controls, so a user lacking write permission can save locally while the application fails only when writing to that mapped drive. Other applications working fine points to share-specific permissions rather than a general network fault.

Why this answer

The most likely cause is insufficient permissions on the network share (D). When a desktop application crashes specifically during a save operation to a network drive, but other applications work fine, it often indicates that the application lacks the necessary write permissions to the target folder or file. This can trigger an unhandled exception in the application's save routine, leading to a crash, whereas other applications may handle the permission denial gracefully or use different access methods.

Exam trap

The trap here is that candidates often assume a network-related issue (like a driver problem) because the symptom involves a network drive, but the key clue is that other applications work fine, isolating the problem to the specific application's permissions or handling of the save operation.

How to eliminate wrong answers

Option A is wrong because an outdated network driver would typically affect all network operations, not just saves from a single application, and would likely cause broader connectivity issues or slower performance. Option B is wrong because insufficient local disk space would affect saves to the local drive, not to a network share, and would usually produce a clear 'disk full' error rather than a crash. Option C is wrong because a corrupted application installation would likely cause crashes during multiple operations (e.g., opening, editing, or saving locally), not exclusively when saving to a network drive, and other applications working fine suggests the issue is environment-specific.

114
MCQhard

A small business wants to use a CRM system. They need to access it from mobile devices and desktops without installing software. Which deployment model fits?

A.Platform as a Service (PaaS)
B.Software as a Service (SaaS)
C.On-premises
D.Infrastructure as a Service (IaaS)
AnswerB

SaaS delivers the CRM over the internet via a browser, so no local installation is needed on mobiles or desktops. This directly satisfies the stem's requirement for software-free access across both device types, with the provider handling hosting, patching and availability.

Why this answer

Software as a Service (SaaS) delivers the CRM application over the internet, allowing users to access it from any device with a web browser without installing software. This model matches the requirement for mobile and desktop access with zero local installation, as the provider hosts and manages the entire application stack.

Exam trap

The trap here is that candidates confuse PaaS with SaaS, thinking a platform is sufficient for a ready-to-use application, but PaaS requires development effort to create the CRM software, whereas SaaS delivers it as a finished service.

How to eliminate wrong answers

Option A (PaaS) is wrong because it provides a platform for developing and deploying custom applications, not a ready-to-use CRM application; the business would still need to build or install the CRM software. Option C (On-premises) is wrong because it requires installing and running the CRM software on the business's own servers, contradicting the 'without installing software' requirement. Option D (IaaS) is wrong because it offers virtualized computing resources (e.g., VMs, storage) but not a pre-built CRM application; the business would have to install and manage the CRM software on those resources.

115
MCQmedium

Which of the following is the primary purpose of hashing a password before storing it in a database?

A.To make the password longer and more secure
B.To verify the password without storing it in plaintext
C.To compress the password to save storage space
D.To encrypt the password so it can be decrypted later
AnswerB

Hashing is a one-way transformation, so the stored digest cannot be reversed to recover the original password. At login the system hashes the supplied password and compares digests, verifying authenticity without retaining plaintext. This satisfies the stem's requirement of verification without plaintext storage.

Why this answer

Hashing is a one-way function that converts a password into a fixed-length string. It is used to securely store passwords so that even if the database is breached, the actual passwords are not easily recoverable.

116
MCQhard

A gaming enthusiast is building a new PC. They want to install a dedicated graphics card, a network interface card, and a sound card. Which type of expansion slot on the motherboard should these cards be inserted into?

A.SATA
B.M.2
C.PCI
D.PCIe
AnswerD

PCIe provides the high-bandwidth serial lanes these add-in cards require, and is the modern expansion standard found on current motherboards. Legacy PCI or AGP slots cannot match its throughput or availability, so PCIe satisfies the need for dedicated graphics, network and sound card installation.

Why this answer

PCIe (Peripheral Component Interconnect Express) is the modern standard expansion slot for high-performance add-in cards like graphics cards, network interface cards, and sound cards. It provides high bandwidth and is backward compatible with PCI. Thus, D is correct.

Exam trap

FC0-U71 often tests the confusion between PCI and PCIe; candidates may choose PCI because it's a known expansion slot, but PCIe is the correct modern standard.

How to eliminate wrong answers

Option A is wrong because SATA is a storage interface for connecting hard drives and SSDs, not an expansion slot for add-in cards. Option B is wrong because M.2 is a form factor for SSDs and other small devices, not for full-sized expansion cards. Option C is wrong because PCI is an older standard, slower than PCIe, and not typically used for modern graphics cards; while some older cards may fit, PCIe is the current standard.

117
MCQeasy

Which of the following is a characteristic of open-source software?

A.The source code is available for modification.
B.Users must pay for a license.
C.It requires a subscription.
D.It can only be used on one device.
AnswerA

Open-source software publishes its human-readable source code under a licence permitting inspection, modification and redistribution, so the availability for modification is inherent to the definition. This satisfies the stem's request for a defining characteristic, distinguishing it from proprietary software, whose compiled binaries cannot legally be altered or redistributed by users.

Why this answer

Open-source software is defined by its license, which grants users the right to view, modify, and distribute the source code. This characteristic is the core principle of open-source, as codified by the Open Source Initiative (OSI). The ability to modify the source code allows for customization, auditing, and community-driven improvements.

Exam trap

The trap here is that candidates often confuse 'free of charge' with 'open-source,' but open-source is about freedom to modify the source code, not necessarily zero cost, and some open-source software may have paid support or enterprise versions.

How to eliminate wrong answers

Option B is wrong because open-source software does not require payment for a license; while some open-source projects may charge for support or distribution, the software itself is freely licensed. Option C is wrong because open-source software does not inherently require a subscription; subscriptions are a business model, not a technical or licensing requirement of open-source. Option D is wrong because open-source software can typically be installed and used on any number of devices, as the license usually permits unlimited use; restrictions on device count are more common in proprietary or commercial licenses.

118
MCQeasy

A user is editing a document in a word processor and wants to save a copy in a format that preserves the exact layout and is universally viewable without requiring the original editing software. Which file format should the user choose?

A.TXT
B.DOCX
C.RTF
D.PDF
AnswerD

PDF (Portable Document Format) preserves the layout, fonts, and images exactly as intended and can be viewed on almost any device with a free reader. It is the standard for sharing final documents that should not be easily altered. This matches the user's need for universal viewability without the original software.

Why this answer

PDF is designed to preserve the visual appearance of a document exactly as created, including fonts, images, and layout, and it can be opened on virtually any platform with a free reader. This makes it ideal for sharing final versions where the layout must remain intact and the recipient may not have the original editing software.

Exam trap

The trap here is assuming that any widely used format like DOCX or RTF will look the same everywhere, when only PDF guarantees layout fidelity across platforms.

119
MCQhard

A developer is writing a program that processes whole numbers only. Which data type should be used?

A.Float
B.String
C.Boolean
D.Integer
AnswerD

The Integer data type stores whole numbers without fractional components, matching the requirement to process whole numbers only. Floating-point types such as Float or Double would permit decimal values, so Integer is the precise choice for this constraint.

Why this answer

(Integer) because the program processes whole numbers only, and the integer data type is specifically designed to store non-fractional numeric values without decimal points. In most programming languages, integers are stored as 32-bit or 64-bit binary values, making them efficient for arithmetic operations on whole numbers.

Exam trap

The trap here is that candidates often confuse 'whole numbers' with 'numbers that might have decimals' and choose Float, not realizing that integer types are the correct and efficient choice for non-fractional data.

How to eliminate wrong answers

Option A (Float) is wrong because the float data type stores numbers with decimal points (floating-point representation), which is unnecessary and can introduce rounding errors when only whole numbers are needed. Option B (String) is wrong because strings store sequences of characters, not numeric values, and using a string would require conversion for arithmetic operations, violating the requirement to process numbers. Option C (Boolean) is wrong because the Boolean data type only stores true/false values (typically 1 or 0), which cannot represent the full range of whole numbers required for processing.

120
MCQmedium

In a relational database, which constraint ensures that a foreign key value matches an existing primary key value in the referenced table?

A.Foreign key constraint
B.Primary key constraint
C.Check constraint
D.Unique constraint
AnswerA

A foreign key constraint enforces referential integrity by rejecting any insert or update whose foreign key value lacks a matching primary key in the referenced table. This directly satisfies the stem's requirement that every foreign key value correspond to an existing primary key, preventing orphaned rows.

Why this answer

A foreign key constraint enforces referential integrity by requiring that any value in the foreign key column(s) must either match a primary key or unique key value in the referenced table, or be NULL. This ensures that relationships between tables remain consistent and prevents orphaned records. The constraint is defined on the child table and references the parent table's primary key (or a unique key).

Exam trap

The trap here is confusing the roles of primary key and foreign key constraints: candidates often think the primary key enforces referential integrity, but it only ensures uniqueness within its own table; the foreign key is the one that references the primary key in another table.

How to eliminate wrong answers

Option B is wrong because a primary key constraint uniquely identifies each row in its own table and does not enforce referential integrity across tables. Option C is wrong because a check constraint validates that column values meet a specific condition (e.g., a range or pattern) and does not reference other tables. Option D is wrong because a unique constraint ensures that all values in a column or set of columns are distinct within the same table, but it does not enforce that those values exist in another table.

121
MCQeasy

Which of the following is an example of system software?

A.Linux operating system
B.Spreadsheet
C.Web browser
D.Word processor
AnswerA

System software manages hardware and provides the platform on which applications run. A Linux operating system is system software because it controls resources, schedules processes and offers core services, unlike application software such as browsers or office suites.

Why this answer

System software includes the operating system and utilities that manage hardware. Linux is an operating system, hence system software. Word processor, web browser, and spreadsheet are application software.

122
MCQeasy

Which of the following best describes the role of an operating system?

A.It manages hardware resources and provides a platform for applications.
B.It runs only one application at a time.
C.It is responsible for data backup and recovery.
D.It connects the computer to the internet.
AnswerA

Managing hardware resources and providing an application platform is precisely the operating system's core function: it allocates CPU time, memory and I/O among processes, and exposes abstractions such as file systems and device drivers so applications need not address hardware directly. This satisfies the stem's requirement for the broadest, most accurate description.

Why this answer

The operating system (OS) is the core software layer that sits between hardware and applications. It allocates CPU time, memory, storage, and I/O devices to processes, and exposes system calls and APIs that applications use to run without directly manipulating hardware. This resource management and abstraction role is the defining function of an OS, making option A the correct description.

Exam trap

FC0-U71 often tests the misconception that the OS is solely responsible for specific tasks like internet connectivity or backups, when its fundamental role is resource management and providing an execution environment for applications.

How to eliminate wrong answers

Option B is wrong because modern operating systems are multitasking — they use schedulers (e.g., preemptive scheduling in Windows/Linux) to run many processes concurrently, not just one application at a time. Option C is wrong because backup and recovery are functions of utility software or built-in tools (e.g., Windows Backup, rsync), not the core role of the OS itself. Option D is wrong because internet connectivity is provided by network interface hardware and protocol stacks (TCP/IP) managed through drivers; while the OS includes networking support, connecting to the internet is not its primary role.

123
MCQmedium

An IT technician is configuring a new employee's laptop. The employee will handle payroll data and must access the payroll application from home. The company requires that the connection be encrypted and that the employee's device prove its identity before access is granted. Which technology BEST meets these requirements?

A.A secure web portal that requires a username and password
B.File synchronization to a cloud storage folder shared with the payroll team
C.Remote Desktop Protocol to an office workstation over the internet
D.A VPN connection using IPsec or TLS with certificate-based authentication
AnswerD

A VPN creates an encrypted tunnel between the laptop and the corporate network, protecting payroll data in transit. Certificate-based authentication requires the device to present a valid digital certificate, satisfying the requirement that the device prove its identity before access. Together, encryption and mutual authentication meet both stated conditions, unlike simpler remote-access methods.

Why this answer

The scenario requires two things: encryption of the connection and proof of the device's identity. A VPN with IPsec or TLS supplies the encrypted tunnel, while certificate-based authentication forces the laptop to present a valid digital certificate before the tunnel is established. Remote desktop, password-only web portals, and cloud sync either lack device authentication or fail to provide a private encrypted path to the payroll application.

Exam trap

The trap here is accepting any encrypted connection, such as HTTPS, while overlooking that the requirement also demands the device itself prove its identity.

124
MCQeasy

A software developer needs to track changes to source code over time. Which type of software should they use?

A.Project management
B.Graphic design
C.Version control
D.Database management
AnswerC

Version control systems record every change to source files, storing revisions in a repository so developers can review history, compare versions and revert. This directly satisfies the requirement to track source code changes over time.

Why this answer

Version control software (e.g., Git) is specifically designed to track changes to source code over time, allowing developers to manage revisions, collaborate, and revert to previous states. Graphic design software, project management tools, and database management systems do not provide the necessary functionality for source code versioning.

Exam trap

Candidates may incorrectly assume that graphic design software's version history feature can track code changes, but version control systems are purpose-built for this task and offer features like branching, merging, and commit histories.

How to eliminate wrong answers

Option A is wrong because project management software (e.g., Jira, Trello) is used for planning, tracking tasks, and managing workflows, not for tracking source code changes. Option C is wrong because graphic design software (e.g., Adobe Photoshop, GIMP) is used for creating and editing visual content, not for version tracking of code. Option D is wrong because database management software (e.g., MySQL, Oracle) is used for storing, querying, and managing structured data, not for tracking code revisions.

125
Multi-Selectmedium

A user wants to upgrade their computer's RAM for better performance. Which of the following are characteristics of DDR4 and DDR5 RAM? (Select THREE).

Select 3 answers
A.DDR5 operates at a lower voltage than DDR4
B.Dual channel configuration can improve memory performance
C.DDR4 and DDR5 use the same physical slot
D.DDR5 has higher data transfer rates than DDR4
E.DDR4 is backward compatible with DDR3 slots
AnswersA, B, D

DDR5 runs at 1.1 V versus DDR4's 1.2 V, satisfying the stem's request for a genuine generational characteristic. This reduced voltage, combined with DDR5's on-module power management IC, lowers overall power draw — a defining architectural difference from DDR4, not merely a speed increase.

Why this answer

Option A is correct because DDR5 runs at a lower nominal voltage (1.1 V) than DDR4 (1.2 V), reducing power consumption. Option B is correct because installing memory in matched pairs across two channels (dual channel) increases the effective memory bus width and improves bandwidth and overall performance. Option D is correct because DDR5 delivers higher data transfer rates than DDR4, with DDR5 starting around 4800 MT/s versus DDR4's typical 2133–3200 MT/s.

Option C is incorrect because DDR4 and DDR5 have different keying/notch positions and are not physically interchangeable. Option E is incorrect because DDR4 is not backward compatible with DDR3 slots; the modules are keyed differently and use incompatible signaling and voltages.

Exam trap

FC0-U71 often tests whether candidates incorrectly assume newer RAM is backward compatible with older slots — the trap is picking 'DDR4 is backward compatible with DDR3' or 'DDR4 and DDR5 share slots,' when in fact each generation has a unique notch and voltage.

126
Multi-Selectmedium

Which TWO of the following are types of system software? (Select two.)

Select 2 answers
A.Database management system
B.Operating system
C.Web browser
D.Device driver
E.Word processor
AnswersB, D

An operating system is system software: it manages hardware, memory, processes and file systems, providing the platform on which application software runs. This satisfies the question's system-software category, distinguishing it from application software such as browsers or word processors.

Why this answer

The operating system (B) is the core system software that manages hardware resources, provides services for application programs, and acts as an intermediary between the user and the computer hardware. Device drivers (D) are system software that allow the operating system to communicate with and control specific hardware devices, such as a graphics card or network adapter.

Exam trap

The trap here is that candidates often confuse application software (like a DBMS or web browser) with system software because they are essential for productivity, but the exam specifically tests the distinction that system software manages hardware and provides a platform for applications, not the applications themselves.

127
Multi-Selectmedium

A database administrator is designing a normalized database. Which TWO are benefits of normalization?

Select 2 answers
A.Reduces data redundancy
B.Eliminates update anomalies
C.Improves query performance
D.Increases data redundancy
E.Requires fewer tables
AnswersA, B

Normalisation splits data into related tables so each fact is stored once, eliminating duplicate columns and repeated values across rows. This directly reduces data redundancy, one of the two benefits the question asks for, by removing the repeated storage of identical information.

Why this answer

Normalization is the process of organizing data into related tables to minimize duplication, so option A (Reduces data redundancy) is correct because each fact is stored in only one place rather than repeated across multiple rows or tables. Option B (Eliminates update anomalies) is also correct because, with redundant data removed, a single change to a fact only needs to be made in one location, preventing insertion, update, and deletion anomalies. Option C (Improves query performance) is not a guaranteed benefit; normalization often requires more joins, which can actually slow read queries, so it is not a defining benefit here.

Option D (Increases data redundancy) is the opposite of what normalization does, and option E (Requires fewer tables) is incorrect because normalization typically decomposes data into more tables, not fewer.

Exam trap

FC0-U71 often tests the misconception that normalization improves performance — in reality it usually trades query speed for data integrity, and denormalization is the performance-oriented opposite.

128
MCQmedium

A technician is comparing storage technologies for a new workstation that will run a database with frequent random reads and writes. The technician needs a storage device with no moving parts, low latency, and high durability. Which of the following should the technician choose?

A.Tape drive
B.Solid-state drive (SSD)
C.Optical disc drive (ODD)
D.Magnetic hard disk drive (HDD)
AnswerB

An SSD stores data in flash memory with no moving parts, offering very low latency and high resistance to physical shock. It excels at random read and write operations, which are common in database workloads. In this scenario, the technician needs a device that is fast, durable, and silent, all of which describe an SSD. While SSDs have a finite number of write cycles, modern drives are robust enough for most workstation database tasks.

Why this answer

An SSD meets all the stated requirements: it has no moving parts, provides low latency, and is durable against shock. It is specifically designed for fast random access, making it ideal for database workloads. The other options involve mechanical components and are better suited for bulk storage or backup rather than performance-critical random I/O.

Exam trap

The trap here is focusing only on capacity or cost per gigabyte and overlooking that random access performance and durability are the primary needs for a database workstation.

129
MCQhard

An administrator reviews a server's audit log and finds a long series of failed login attempts against many different usernames, all originating from a single external address within a few minutes. No attempt succeeded. Which term BEST describes this activity?

A.A denial-of-service attack
B.A brute-force attack against one account
C.A man-in-the-middle attack
D.A password spraying attack
AnswerD

Password spraying tries a small number of common passwords against a large set of usernames, hoping to find one account with a weak password while avoiding lockout thresholds tied to a single account. The log's signature, many usernames tried in a short time from one source with no successes yet, matches this technique exactly. It is a low-and-slow credential attack aimed at breadth rather than depth.

Why this answer

The distinguishing feature in the log is breadth: many different usernames targeted from one source in a short window. That pattern matches password spraying, where an attacker tests a few common passwords across a large user list to stay under per-account lockout thresholds. Brute force would hammer one account, a denial-of-service attack would aim at availability, and a man-in-the-middle attack would involve interception rather than direct login attempts.

Exam trap

The trap here is labeling any burst of failed logins as brute force, when the spread across many accounts is what identifies password spraying.

130
MCQeasy

A small office wants to prevent unauthorized individuals from connecting to its wireless network. The office manager enables WPA3-Personal and configures a pre-shared key. Which additional step BEST reduces the risk of unauthorized access?

A.Set the pre-shared key to the office street address for easy recall.
B.Change the default administrator credentials on the wireless access point.
C.Configure the access point to use WEP encryption for backward compatibility.
D.Enable SSID broadcast so devices can find the network easily.
AnswerB

Default administrator credentials are publicly documented and are a common way attackers gain control of an access point, then alter its configuration or add rogue access. Changing them to a unique, strong passphrase protects the management interface. WPA3-Personal secures the wireless link, but it does not protect the device's administrative login, so this step directly reduces the risk of unauthorized access to the network.

Why this answer

WPA3-Personal protects the wireless traffic, but the access point's management interface remains a separate attack surface. If default administrator credentials are left in place, an attacker on the local network or with physical access could log in and change settings, create a backdoor, or disable security. Replacing those defaults with a unique strong passphrase closes that path while preserving the encryption already configured.

Exam trap

The trap here is assuming that enabling strong wireless encryption alone fully secures the network, when the device's default administrative login is an independent and commonly exploited weakness.

131
MCQhard

A company's backup strategy requires three copies of data, on two different media types, with one copy offsite. Which backup rule does this follow?

A.3-2-1 rule
B.Incremental backup
C.Differential backup
D.Full backup
AnswerA

The 3-2-1 rule specifies exactly three copies of data, stored on two distinct media types, with one copy held offsite. That maps precisely onto the company's stated requirements, whereas other schemes such as 3-2-1-1-0 add offline or verified-restore conditions the stem never mentions.

Why this answer

The 3-2-1 backup rule: three copies, two different media types, one offsite.

132
Multi-Selectmedium

Which TWO of the following are valid SQL functions used to aggregate data?

Select 2 answers
A.COUNT
B.SORT
C.SUM
D.LENGTH
E.APPEND
AnswersA, C

COUNT is an aggregate function that returns the number of rows or non-NULL values in a set, collapsing many rows into a single summary figure. It is used with GROUP BY or over an entire result set to produce totals.

Why this answer

COUNT (option A) is a valid SQL aggregate function that returns the number of rows or non-NULL values in a column, commonly used with GROUP BY to summarize data. SUM (option C) is also a valid SQL aggregate function that returns the total sum of a numeric column, making it a standard tool for data aggregation. The other options are not aggregate functions: SORT (option B) is not a SQL function (ordering is done with ORDER BY), LENGTH (option D) is a scalar string function that returns the character length of a value, and APPEND (option E) is not a standard SQL function at all.

Exam trap

The trap here is that candidates often confuse SQL clauses (like ORDER BY for sorting) or scalar functions (like LENGTH) with aggregate functions, because they see them used in queries but fail to recognize the fundamental difference between row-level operations and set-level summarization.

133
Multi-Selecthard

A company is developing a security policy. Which THREE of the following are examples of physical security controls?

Select 3 answers
A.Employing security guards to monitor entrances
B.Requiring employees to use strong passwords
C.Using a firewall to filter network traffic
D.Installing badge readers on doors
E.Locking server rooms with biometric locks
AnswersA, D, E

Security guards monitoring entrances are a physical control: they restrict and observe direct human access to the facility, deterring intrusion and tailgating. This satisfies the requirement by protecting the tangible premises rather than logical systems, data or user behaviour.

Why this answer

Option A is correct because security guards monitoring entrances are a classic physical security control, providing deterrence and access control at the facility perimeter. Option D is correct because badge readers on doors are physical access control mechanisms that restrict entry to authorized personnel using credentials such as RFID or smart cards. Option E is correct because biometric locks on server rooms are physical controls that authenticate individuals via fingerprints, iris scans, or similar traits before granting access to sensitive areas.

Option B is not a physical control; strong passwords are a logical/technical authentication control. Option C is not a physical control; firewalls are network security devices that filter traffic at the logical layer.

Exam trap

The trap here is confusing logical/technical controls (passwords, firewalls) with physical controls; candidates often pick password policies because they 'secure' the company, but the exam requires recognizing that physical controls must restrict tangible access.

134
MCQmedium

A software company uses a development model where work is divided into 2-week sprints. Each sprint begins with a planning meeting, includes daily standups, and ends with a review and retrospective. A product owner prioritizes features, and a scrum master facilitates the process. Which methodology is being used?

A.Kanban
B.Scrum
C.Waterfall
D.Extreme Programming (XP)
AnswerB

Scrum prescribes exactly these time-boxed ceremonies: sprint planning, daily standups, sprint review and retrospective, with a product owner prioritising the backlog and a scrum master facilitating. The stem's fixed two-week sprints and defined role separation satisfy Scrum's empirical, iterative structure rather than Kanban's continuous flow.

Why this answer

Scrum is an agile framework that uses sprints, daily standups, sprint reviews, and specific roles (product owner, scrum master, development team).

135
MCQmedium

A database administrator is designing a table to store employee records. She needs to ensure that no two employees can have the same employee number, and that the employee number is never left blank. Which combination of constraints should she apply to the employee number column?

A.INDEX and AUTO_INCREMENT
B.UNIQUE and NOT NULL
C.PRIMARY KEY and FOREIGN KEY
D.CHECK and DEFAULT
AnswerB

The UNIQUE constraint prevents duplicate employee numbers, and the NOT NULL constraint ensures the column cannot be left empty. Together they satisfy both requirements: every employee has an employee number, and no two employees share the same one. This is a standard way to enforce a candidate key when the column is not the table's primary key.

Why this answer

To require that every employee has a unique employee number, the column needs both a uniqueness rule and a non-null rule. UNIQUE prevents duplicates, and NOT NULL prevents blanks. A primary key would also work, but the question asks for a combination of constraints; UNIQUE and NOT NULL are the specific constraints that meet both conditions.

Exam trap

The trap here is thinking that an index or AUTO_INCREMENT automatically enforces uniqueness and non-null values, when only explicit constraints guarantee those rules.

136
MCQeasy

A user reports that when they try to open a PDF file attached to an email, nothing happens. Which of the following is the most likely cause?

A.The file permissions are set to read-only.
B.The antivirus software has quarantined the file.
C.There is no software installed that can open PDF files.
D.The network connection is down.
AnswerC

A PDF file has no default handler registered, so the double-click produces no visible action. Without an installed application capable of opening PDF files, the operating system cannot launch anything, which matches the reported symptom exactly.

Why this answer

If no software is installed that can handle PDF files, the operating system has no default handler to open the file. When a user clicks on a PDF attachment in an email client, the system attempts to launch the associated application (e.g., Adobe Acrobat Reader, a web browser with PDF support). If no such application is present, nothing happens—the file simply does not open, and no error message may appear depending on the email client's configuration.

Exam trap

The trap here is that candidates may confuse 'nothing happens' with a network issue or antivirus blocking, but the key is that the file is already present locally and the problem is the lack of an application to interpret the file format.

How to eliminate wrong answers

Option A is wrong because read-only file permissions do not prevent a file from opening; they only prevent modifications to the file. Option B is wrong because if antivirus software quarantines the file, the user would typically see a notification or the file would be missing from its location, not a scenario where 'nothing happens' when trying to open it. Option D is wrong because the network connection being down would affect the ability to download the email or attachment, but once the email is already displayed with the attachment, the network is not required to open a locally stored PDF file.

137
MCQeasy

Which file extension typically indicates a compressed archive in Windows?

A..docx
B..jpg
C..mp4
D..zip
AnswerD

The .zip extension denotes a compressed archive container in Windows, holding one or more files in compressed form. Executable extensions such as .exe or document extensions such as .docx do not indicate compression, making .zip the extension that typically signals a compressed archive.

Why this answer

.zip is the standard compressed archive format on Windows, bundling one or more files into a single compressed container. Windows Explorer natively supports creating and extracting .zip files without third-party tools, making it the default archive extension.

Exam trap

FC0-U71 often tests basic file-extension recognition, and the trap is that .docx is technically a ZIP container internally — candidates who know this may overthink and pick it instead of the obvious general-purpose archive extension.

How to eliminate wrong answers

Option A is wrong because .docx is a Microsoft Word document format (an Office Open XML file), not a general-purpose compressed archive, even though it is internally a ZIP container. Option B is wrong because .jpg is a compressed image format using lossy JPEG compression, not an archive of multiple files. Option C is wrong because .mp4 is a multimedia container format for video and audio, not a file archive.

138
MCQmedium

A user is selecting a software license for a new application. The user wants to use the software for any purpose, modify it, and redistribute modified versions, but also wants to ensure that any redistributed modified versions remain under the same license. Which type of license best fits these requirements?

A.Public domain dedication
B.Permissive open-source license such as MIT
C.Copyleft license such as GNU GPL
D.Proprietary license
AnswerC

A copyleft license like the GNU GPL grants freedom to use, modify, and redistribute the software, but requires that derivative works be distributed under the same license. This ensures modified versions remain open and under identical terms, exactly matching the user's stated requirement for reciprocity.

Why this answer

The user wants freedom to use, modify, and redistribute, plus a requirement that modified versions stay under the same license. That reciprocal condition is the defining feature of a copyleft license such as the GNU GPL. Permissive licenses and public domain allow modification and redistribution but do not enforce the same-license requirement, while proprietary licenses forbid these freedoms altogether.

Exam trap

The trap here is assuming that any open-source license automatically requires derivative works to use the same license, when only copyleft licenses impose that condition.

139
MCQhard

A developer is troubleshooting an issue where a user can list the files in a shared folder but cannot download any of them. Based on the exhibit, what is the most likely cause?

A.The user lacks permissions to list the folder.
B.The Allow statement on list also allows downloads.
C.The Deny statement on read explicitly denies file retrieval.
D.The policy is malformed and causes an error.
AnswerC

The Deny statement overrides any Allow, so although list permissions remain effective, the explicit deny on read blocks file retrieval. This matches the symptom precisely: directory enumeration succeeds while downloads fail, because listing and reading are separate actions and the deny targets only the read action.

Why this answer

The exhibit shows an explicit Deny statement for read access, which overrides any Allow statements due to access control evaluation logic. Even if the user has list permission, the Deny on read prevents downloading files. This is the most likely cause because Deny statements are absolute and cannot be overridden by Allow statements.

Exam trap

The trap here is that candidates often assume that having list permission implies full read access, but access control separates listing from reading file data, and an explicit deny on read overrides any allow.

How to eliminate wrong answers

Option A is wrong because the user can list objects, which requires s3:ListBucket permission, so they clearly have that permission. Option B is wrong because s3:ListBucket only grants permission to list objects, not to download them; downloading requires s3:GetObject, which is a separate action. Option D is wrong because if the policy were malformed, AWS would return a policy validation error and the bucket operations would likely fail entirely, but the user can still list objects, indicating the policy is syntactically valid.

140
MCQmedium

Which of the following BEST describes the primary function of an operating system?

A.Secure network traffic
B.Manage hardware resources
C.Create documents
D.Provide internet access
AnswerB

The operating system allocates CPU, memory, storage and I/O among processes, and provides the abstraction layer applications use to reach that hardware. Managing hardware resources is its core function, distinct from user applications or utilities.

Why this answer

The primary function of an operating system is to manage hardware resources, including the CPU, memory, storage, and input/output devices, by abstracting them into a usable interface for applications. Without an OS, software cannot directly coordinate hardware access, as the OS handles scheduling, memory allocation, and device drivers. This resource management is fundamental to all other OS roles, such as file system management and process control.

Exam trap

The trap here is that candidates confuse the OS's role as a resource manager with specific application functions (like document creation or internet access), leading them to pick options that describe user-facing tasks rather than the underlying system management.

How to eliminate wrong answers

Option A is wrong because securing network traffic is a function of firewalls, VPNs, or security software, not the primary purpose of an operating system; the OS can provide basic security features (e.g., user permissions), but it is not its core function. Option C is wrong because creating documents is an application-level task performed by word processors (e.g., Microsoft Word), not by the operating system itself. Option D is wrong because providing internet access is the role of network hardware (e.g., routers, modems) and network configuration, not the OS; the OS manages network interfaces but does not supply connectivity.

141
MCQeasy

A user reports that their desktop computer takes a long time to start up and frequently freezes. A technician suspects the storage drive is failing. Which of the following steps should the technician take FIRST to diagnose the issue?

A.Replace the hard drive with a solid-state drive.
B.Check the computer's RAM usage in Task Manager.
C.Run the manufacturer's diagnostic utility to check the drive's health.
D.Reinstall the operating system.
AnswerC

Running the manufacturer's diagnostic utility provides definitive information about the drive's condition, such as SMART status and error rates. This is a non-destructive first step that helps confirm whether the drive is the root cause. If the tool reports failures, the technician can proceed with replacement; if not, other causes must be investigated.

Why this answer

Running the manufacturer's diagnostic utility is the correct first step because it directly tests the suspected failing component without making changes. It provides actionable data about the drive's health, allowing the technician to make an informed decision. Other options either skip diagnosis or address different components, which could lead to unnecessary work.

Exam trap

The trap here is assuming that slow performance always means the drive must be replaced immediately, rather than confirming the failure with diagnostics first.

142
Multi-Selectmedium

A user's workstation has become slow and shows unexpected pop-up windows even when no browser is open. A technician suspects malware and wants to reduce the risk of further compromise while investigating. Which TWO actions should the technician take FIRST? (Choose two.)

Select 2 answers
A.Run a full antivirus scan while leaving the machine connected.
B.Share the user's login credentials with the security team by email.
C.Document the observed symptoms and note the time they began.
D.Immediately reinstall the operating system without further checks.
E.Disconnect the workstation from the network.
AnswersC, E

Recording symptoms, timestamps, and the state of the machine preserves evidence and supports later analysis of how the infection occurred and what it affected. This documentation is valuable whether the machine is later reimaged or cleaned, and it helps identify other potentially compromised systems. Capturing this information early, before remediation changes the system, is a core incident-handling practice.

Why this answer

Containment and evidence preservation come before remediation. Disconnecting the workstation stops active communication with external infrastructure and prevents lateral spread, while documenting symptoms and timestamps preserves information needed for analysis. Scanning, reimaging, or sharing credentials either allows the threat to continue operating or destroys evidence, so those actions belong later in the response process.

Exam trap

The trap here is jumping straight to remediation such as scanning or reimaging, which can let active malware keep communicating or destroy the evidence needed to understand the scope of the incident.

143
MCQhard

A developer writes a Python script that processes user input. During execution, the script prompts for an age and stores it in a variable. Which data type is most appropriate for the variable that stores the age?

A.Float
B.Boolean
C.String
D.Integer
AnswerD

An integer stores whole-number values without fractional components, matching an age expressed in completed years. It satisfies the stem's constraint that the script processes numeric input into an appropriate variable type, avoiding the precision and comparison issues that arise when ages are held as strings or floating-point values.

Why this answer

An age is a whole number of years, so the Integer type is the natural fit. Python's int type stores whole numbers without a fractional component and supports arithmetic operations directly. Using Integer avoids unnecessary type conversions and preserves numeric semantics for comparisons and calculations.

Exam trap

The trap here is that input() returns a string, so candidates may pick String, forgetting that the question asks for the most appropriate data type for storing an age, which is numeric.

How to eliminate wrong answers

Option A is wrong because Float is used for numbers with decimal fractions (e.g., 3.14), and an age is not typically expressed with decimals. Option B is wrong because Boolean only holds True/False values and cannot represent numeric ages. Option C is wrong because String stores text; while input() returns a string, the age should be converted to an integer for numeric processing, making String the less appropriate final data type.

144
MCQmedium

A mobile app developer wants to integrate weather data into an app. The developer uses an HTTP request to a web service that returns JSON data. The web service requires an API key in the request header for authentication. What is this web service an example of?

A.GraphQL API
B.WebSocket
C.REST API
D.SOAP API
AnswerC

The service exposes HTTP endpoints returning JSON and authenticates via an API key header, which is characteristic of a REST API. This satisfies the stem's description of stateless HTTP requests with header-based authentication, distinguishing it from SOAP or GraphQL services.

Why this answer

This web service is a REST API because it uses HTTP requests to access and manipulate resources, returns data in JSON format, and requires an API key in the request header for authentication. REST APIs are stateless and rely on standard HTTP methods (GET, POST, etc.), making them ideal for integrating external data like weather information into mobile apps.

Exam trap

CompTIA often tests the distinction between REST and SOAP by focusing on data format (JSON vs. XML) and authentication simplicity (API keys vs. WS-Security), leading candidates to confuse REST with GraphQL due to both using JSON, but GraphQL is a query language, not a service architecture.

How to eliminate wrong answers

Option A is wrong because GraphQL API is a query language that allows clients to request specific data fields, but it does not inherently require an API key in the header for authentication; authentication is an additional layer, not a defining characteristic. Option B is wrong because WebSocket is a full-duplex communication protocol over a single TCP connection, used for real-time bidirectional data streams, not for standard HTTP request-response interactions like fetching weather data. Option D is wrong because SOAP API uses XML-based messaging and often relies on WS-Security or other complex protocols for authentication, not simple API keys in HTTP headers, and it is not typically associated with lightweight JSON responses.

145
MCQeasy

What is the primary purpose of a network firewall?

A.To prevent malware infections by scanning files
B.To encrypt data transmitted over the network
C.To block unauthorized network traffic based on rules
D.To provide wireless network access
AnswerC

A firewall inspects packets against configured rule sets, permitting or denying traffic by source, destination, port and protocol. This directly fulfils the stem's requirement of blocking unauthorised network traffic, since each rule defines precisely which connections may pass the boundary between trusted and untrusted networks.

Why this answer

A network firewall's primary purpose is to control incoming and outgoing network traffic by comparing packets against a set of predefined security rules. It acts as a barrier between trusted internal networks and untrusted external networks (like the internet), allowing or denying traffic based on criteria such as IP addresses, ports, and protocols. This rule-based filtering is the core function that distinguishes a firewall from other security tools.

Exam trap

FC0-U71 often tests the distinction between firewall functions and those of other security or networking devices, so candidates may confuse firewalls with antivirus, encryption tools, or wireless access points.

How to eliminate wrong answers

Option A is wrong because scanning files for malware is the function of antivirus or anti-malware software, not a firewall; firewalls operate at the network layer and do not inspect file contents for malicious code. Option B is wrong because encryption of transmitted data is handled by protocols like TLS/SSL, VPNs, or IPsec, not by a firewall; firewalls may allow or block encrypted traffic but do not perform the encryption themselves. Option D is wrong because providing wireless network access is the role of a wireless access point (WAP) or wireless router, not a firewall; while some home routers combine both functions, the firewall component does not enable wireless connectivity.

146
MCQeasy

Which of the following software categories includes applications like Microsoft Teams and Slack?

A.Productivity software
B.Collaboration software
C.Security software
D.Development tools
AnswerB

Collaboration software directly satisfies the category constraint by providing shared workspaces, persistent chat channels, file exchange and integrated voice or video meetings. Microsoft Teams and Slack both centre on real-time team communication rather than content creation or system maintenance, which is precisely the defining function this question tests.

Why this answer

Microsoft Teams and Slack are team communication and collaboration platforms, so they fall under Collaboration software. These tools provide chat, video conferencing, file sharing, and integration with other work apps. Collaboration software is specifically designed to help groups work together, which matches the described applications.

Exam trap

The trap is confusing productivity software with collaboration software because both are office-related; candidates may pick Productivity simply because Teams and Slack are used at work.

How to eliminate wrong answers

Option A is wrong because Productivity software refers to individual task-oriented tools like Microsoft Word, Excel, or Google Docs, not team communication platforms. Option C is wrong because Security software includes antivirus, firewalls, and encryption tools, which Teams and Slack are not. Option D is wrong because Development tools are used for coding, debugging, and deployment (e.g., IDEs, compilers), not for team collaboration.

147
MCQmedium

Based on the exhibit, which of the following is the purpose of the DNS server address?

A.To convert domain names to IP addresses
B.To encrypt network traffic
C.To route packets to the internet
D.To assign IP addresses to clients
AnswerA

DNS resolves human-readable domain names into routable IP addresses, letting clients locate servers without hard-coded numeric endpoints. This satisfies the exhibit's requirement that name queries reach the correct host, since DNS is the service responsible for forward lookups within the network's name resolution chain.

Why this answer

The DNS server address is used to resolve human-readable domain names (like www.example.com) into machine-readable IP addresses. This is the fundamental purpose of the Domain Name System, which translates names to IPs so that network devices can locate and communicate with each other.

Exam trap

The trap here is that candidates often confuse the DNS server's role with that of a DHCP server or a router, especially when the exhibit shows network configuration fields where both DNS and gateway addresses are listed.

How to eliminate wrong answers

Option B is wrong because encryption of network traffic is handled by protocols like TLS/SSL or IPsec, not by a DNS server. Option C is wrong because routing packets to the internet is the function of a default gateway or router, not a DNS server. Option D is wrong because assigning IP addresses to clients is the role of a DHCP server, not a DNS server.

148
MCQmedium

A technician is reviewing how a computer processes a single machine instruction. The instruction cycle begins when the CPU fetches an instruction from memory whose address is held in a specific register. The technician must identify the register that stores the memory address of the next instruction to be executed. Which of the following is that register?

A.Program counter
B.Memory address register
C.Instruction register
D.Accumulator
AnswerA

This is correct because the program counter holds the memory address of the next instruction to fetch. After each fetch, it increments or is updated by a jump so the CPU knows where to continue. It is central to the fetch-decode-execute cycle, directly matching the scenario's requirement to identify the register that tracks the next instruction's location.

Why this answer

The program counter stores the address of the next instruction to be fetched, making it the register that drives sequential execution. Each cycle, its value is used to access memory, then advanced or redirected by branches. Other registers such as the accumulator, memory address register, and instruction register serve different roles in processing data or the current instruction.

Exam trap

The trap here is conflating the register that holds the address of the next instruction with the register that holds the instruction currently being executed or the address being accessed right now.

149
MCQmedium

A user wants to upgrade their desktop's storage from a traditional hard drive to a faster drive that connects directly to the motherboard without cables. Which storage interface should they choose?

A.External USB drive
B.SATA SSD
C.SATA hard drive
D.NVMe M.2
AnswerD

NVMe M.2 drives slot directly into a motherboard M.2 connector, drawing power and data over the PCIe bus with no cabling. SATA drives need separate data and power cables, so NVMe M.2 satisfies the cable-free, faster-storage requirement.

Why this answer

NVMe M.2 drives plug directly into an M.2 slot on the motherboard, requiring no data or power cables, and use the PCIe bus for far higher throughput than SATA. This matches the user's requirement of a fast drive that connects directly to the motherboard without cables. M.2 NVMe is the standard choice for modern desktop storage upgrades where cable-free installation and maximum speed are priorities.

Exam trap

The trap here is conflating the M.2 form factor with the NVMe protocol — candidates may pick 'SATA SSD' thinking any SSD is fast, or assume M.2 always means NVMe, when the question specifically rewards the cable-free, motherboard-mounted NVMe option.

How to eliminate wrong answers

Option A is wrong because an external USB drive connects via a cable to an external port and is typically slower than internal drives, directly contradicting the 'no cables' requirement. Option B is wrong because a SATA SSD still requires both a SATA data cable and a power cable from the PSU, so it does not meet the cable-free criterion. Option C is wrong because a SATA hard drive is a traditional spinning disk that is slower than SSDs and also requires SATA data and power cables.

150
Multi-Selectmedium

A developer is debugging a program that unexpectedly crashes. Which TWO tools or techniques are commonly used to identify the cause of the crash? (Select the two correct answers.)

Select 2 answers
A.Code compilation
B.Refactoring
C.Breakpoints
D.Logging
E.Code review
AnswersC, D

Breakpoints pause execution at a chosen line, letting the developer inspect variables, call stack and memory state immediately before the crash occurs. This satisfies the scenario by catching the fault at its source rather than inferring it afterwards from logs alone.

Why this answer

Breakpoints (C) are correct because they let a developer pause program execution at a specific line or condition, inspect variables, call stack, and memory state at the moment before the crash, which directly reveals the faulty logic or invalid value causing the failure. Logging (D) is correct because strategically placed log statements (or a logging framework) record runtime events, error messages, and stack traces leading up to the crash, allowing post-mortem analysis of the sequence of operations that triggered it. Code compilation (A) only translates source into executable code and would surface syntax or type errors at build time, not the runtime cause of a crash.

Refactoring (B) restructures existing code to improve readability or design without diagnosing the crash, and code review (E) is a static, human inspection of source that may catch defects but does not observe the program's actual runtime behavior during the crash.

Exam trap

FC0-U71 often tests the difference between static techniques (code review, compilation) and dynamic techniques (breakpoints, logging) — candidates incorrectly include code review as a crash diagnosis tool, but it does not observe runtime behavior.

Page 1

Page 2 of 14

Page 3