Courseiva

CompTIA Tech+ (FC0-U71) (FC0-U71) — Questions 226–300

988 questions total · 14pages · All types, answers revealed

Page 3

Page 4 of 14

Page 5
226
Multi-Selecthard

An IT administrator is configuring a virtualized environment on a single server. The administrator needs to allocate resources to multiple virtual machines. Which THREE of the following are resources that can be allocated to a VM? (Select THREE.)

Select 3 answers
A.Virtual storage
B.vCPU
C.Physical GPU
D.vRAM
E.Hypervisor license
AnswersA, B, D

Virtual storage is a provisioned resource: the hypervisor presents each VM with virtual disks backed by physical datastore capacity. This satisfies the stem's requirement to allocate resources across multiple VMs, since disk capacity is partitioned independently per guest.

Why this answer

Virtual storage (A) is a resource that can be allocated to a VM, since the hypervisor presents virtual disks (VMDK, VHDX, qcow2) backed by datastores or storage pools to each guest. vCPU (B) is correct because virtual CPUs are assigned to a VM from the host's physical cores/threads, defining its compute capacity. vRAM (D) is correct because memory is a core allocatable resource, with each VM configured for a specific amount of guest RAM. Physical GPU (C) is not a standard allocatable VM resource in a basic single-server setup; GPUs require passthrough or vGPU technologies and are not a general resource like CPU, RAM, or storage. Hypervisor license (E) is not a resource allocated to a VM; it is a software licensing concern for the host platform, not a consumable assigned to guests.

Exam trap

The trap is selecting 'physical GPU' because GPUs can be virtualized, but the question asks for standard per-VM allocatable resources, where vCPU, vRAM, and virtual storage are the correct trio.

227
MCQhard

An IT administrator needs to deploy a new application to 50 company-owned smartphones. The devices are managed by a central console that can enforce policies, install apps, and wipe data remotely. Which technology is being used?

A.Mobile Device Management (MDM)
B.Google Account Sync
C.Synchronisation
D.iCloud
AnswerA

Mobile Device Management provides exactly the central console described: policy enforcement, application deployment, and remote wipe across enrolled smartphones. It satisfies the requirement to manage 50 company-owned devices centrally. MDM agents on each device maintain the management channel, enabling remote configuration and data removal.

Why this answer

Mobile Device Management (MDM) is the technology that allows an IT administrator to centrally manage and secure mobile devices like smartphones and tablets. MDM solutions provide features such as policy enforcement, remote app installation, and remote wipe, which match the scenario exactly. The central console described is typical of MDM software (e.g., Microsoft Intune, VMware Workspace ONE).

Thus, MDM is the correct answer.

Exam trap

The trap here is confusing consumer sync services (like Google Account Sync or iCloud) with enterprise-grade MDM, which offers centralized control, policy enforcement, and remote management features that sync services lack.

How to eliminate wrong answers

Option B is wrong because Google Account Sync is a consumer service for syncing personal data (contacts, calendar, etc.) across devices, not for centralized enterprise management or policy enforcement. Option C is wrong because 'Synchronisation' is a generic term for keeping data consistent across devices, lacking the management, security, and remote control capabilities described. Option D is wrong because iCloud is Apple's consumer cloud service for syncing and backup, not an enterprise MDM solution; it does not provide central policy enforcement or remote app deployment across a fleet of devices.

228
Multi-Selectmedium

Which TWO of the following are examples of system software?

Select 2 answers
A.Device drivers
B.Database management system
C.Operating system
D.Spreadsheet
E.Web browser
AnswersA, C

Device drivers are system software because they sit between the operating system kernel and hardware, translating OS instructions into device-specific commands. They load at boot or on demand, unlike application software such as browsers or word processors, satisfying the stem's requirement for a system software example.

Why this answer

Option A (Device drivers) is correct because device drivers are low-level system software that act as an interface between the operating system and hardware peripherals, translating OS requests into device-specific commands. Option C (Operating system) is correct because the OS is the core system software that manages hardware resources, memory, processes, and provides services for application software. Options B (Database management system), D (Spreadsheet), and E (Web browser) are not system software; they are application software designed to perform user-oriented tasks such as data management, calculations, and web navigation, and they run on top of the operating system rather than managing the system itself.

Exam trap

CompTIA often tests the distinction between system software and application software, and the trap here is that candidates mistakenly classify database management systems or web browsers as system software because they are essential for many tasks, but they are actually application software that runs on top of the OS.

229
MCQeasy

A user reports that their desktop computer powers on, the fans spin, but the monitor shows no signal and there are no beep codes. A technician notices the monitor's cable is connected to a port on the motherboard, but the computer has a dedicated graphics card installed. Which of the following is the MOST likely explanation?

A.The power supply unit is failing and cannot provide enough wattage to the graphics card.
B.The monitor is defective and needs to be replaced.
C.The monitor cable is connected to the motherboard's integrated video port instead of the discrete graphics card's port.
D.The RAM is not seated properly, preventing the system from completing POST.
AnswerC

When a dedicated graphics card is installed, many motherboards disable integrated video output. Connecting the display to the motherboard port while the card is active results in no signal, even though the system powers on normally. Moving the cable to the graphics card's output typically restores the display immediately.

Why this answer

The system powers on and fans spin, indicating power and basic operation, but no video appears because the display cable is attached to the motherboard's video port. When a dedicated graphics card is present, integrated video is often disabled, so the motherboard port produces no signal. Connecting the monitor to the graphics card's output resolves the issue.

Exam trap

The trap here is assuming a no-signal condition always means a hardware failure rather than a simple cabling mistake to the wrong video output.

230
MCQeasy

A company wants to prevent unauthorized physical access to its server room. Which control is best?

A.Firewall
B.Antivirus
C.Biometric lock
D.Encryption
AnswerC

Biometric locks authenticate a unique physical trait, such as a fingerprint, before the door releases. Unlike keys, badges or PINs, they cannot be shared, copied or guessed, so they directly satisfy the requirement to stop unauthorised physical entry to the server room.

Why this answer

A biometric lock is the best control for preventing unauthorized physical access to a server room because it authenticates individuals based on unique physiological traits (e.g., fingerprint, iris scan), directly securing the physical entry point. Unlike logical or data-level controls, it addresses the physical security domain by restricting who can enter the room, not what data they can access.

Exam trap

The trap here is that candidates confuse logical security controls (firewall, antivirus, encryption) with physical security controls, incorrectly assuming any security technology can prevent physical access, when only a physical access control mechanism like a biometric lock directly addresses the scenario.

How to eliminate wrong answers

Option A is wrong because a firewall is a network security device that filters traffic based on rules (e.g., ACLs, stateful inspection), and it does not prevent physical entry to a room. Option B is wrong because antivirus software detects and removes malware on endpoints, but it has no mechanism to control physical access to a location. Option D is wrong because encryption protects data at rest or in transit by converting it into ciphertext (e.g., AES-256), but it does not prevent someone from physically walking into a server room.

231
MCQeasy

A user wants to connect a laptop to a corporate wireless network. What internal component must be present in the laptop?

A.Wireless NIC
B.Cellular modem
C.Infrared port
D.Bluetooth adapter
AnswerA

A wireless NIC provides the radio and 802.11 firmware needed to associate with an access point, satisfying the stem's requirement for an internal component. Without it, the laptop has no physical means to transmit or receive Wi-Fi frames, so no corporate wireless connection is possible.

Why this answer

A Wireless NIC (Network Interface Card) is the internal component required for a laptop to connect to a corporate wireless network. It contains a radio transceiver that communicates with wireless access points using IEEE 802.11 standards (e.g., 802.11ax), handling frame encapsulation, authentication, and encryption such as WPA3. Without a wireless NIC, the laptop has no physical layer capability to transmit or receive Wi-Fi signals.

Exam trap

The trap here is that candidates confuse Bluetooth and Wi-Fi because both use 2.4 GHz radio frequencies, but Bluetooth is designed for short-range device pairing (e.g., keyboards, mice) and cannot authenticate to a corporate wireless network using 802.1X or WPA3-Enterprise.

How to eliminate wrong answers

Option B (Cellular modem) is wrong because it connects to mobile networks (e.g., 4G LTE, 5G NR) using cellular protocols, not to corporate Wi-Fi infrastructure which relies on IEEE 802.11 standards. Option C (Infrared port) is wrong because it uses IrDA (Infrared Data Association) for short-range, line-of-sight communication at speeds up to 4 Mbps, and cannot connect to standard wireless networks. Option D (Bluetooth adapter) is wrong because it operates on the 2.4 GHz ISM band using Bluetooth protocols (e.g., BR/EDR or BLE) for personal area networking, not for connecting to corporate wireless LANs which require 802.11-compliant hardware.

232
MCQeasy

A small office wants to prevent unauthorized people from connecting to its wireless network while still allowing visitors to use Wi-Fi. The office manager enables WPA3-Personal on the access point. Which requirement does this configuration satisfy?

A.It requires a shared passphrase before a device can join the wireless network.
B.It encrypts all files stored on the access point's internal memory.
C.It automatically assigns IP addresses to devices that join the network.
D.It blocks malicious websites by filtering DNS requests from connected clients.
AnswerA

WPA3-Personal uses a shared passphrase, and devices must supply it during association before network access is granted. This directly blocks unauthorized users who do not know the passphrase. It is the standard way to secure a home or small-office wireless network, and it satisfies the goal of preventing unknown devices from joining while still letting visitors connect if the passphrase is shared with them.

Why this answer

WPA3-Personal secures a wireless network by requiring a shared passphrase during association, so only devices with the correct passphrase can join. This prevents unauthorized users from connecting while allowing anyone who is given the passphrase, such as visitors, to use the Wi-Fi. The other choices describe unrelated functions such as local storage encryption, DHCP addressing, and DNS filtering.

Exam trap

The trap here is assuming that enabling a wireless security mode also handles IP addressing or content filtering, when WPA3-Personal only controls authentication and link encryption.

233
MCQhard

An IT technician is setting up a virtualized server environment. The server will host multiple virtual machines for different departments. Which type of hypervisor should the technician install directly on the server hardware to maximize performance and resource efficiency?

A.Containerization platform
B.Dual-boot configuration
C.Type 1 hypervisor
D.Type 2 hypervisor
AnswerC

A Type 1 hypervisor runs directly on the bare-metal server hardware, so it bypasses a host operating system entirely. This removes the intervening OS layer, cutting virtualisation overhead and giving each VM more direct access to CPU and memory, which satisfies the stem's demand for maximum performance and resource efficiency.

Why this answer

A Type 1 hypervisor (bare-metal) runs directly on the server hardware without an underlying host OS, giving VMs direct access to CPU, memory, and I/O resources. This architecture minimizes overhead and maximizes performance and resource efficiency, which is exactly what a multi-VM production server environment requires. Examples include VMware ESXi, Microsoft Hyper-V (Server role), and KVM.

Exam trap

The trap here is confusing containerization with virtualization — candidates see 'multiple workloads on one server' and pick containerization, forgetting that containers share the host kernel and are not hypervisors.

How to eliminate wrong answers

Option A is wrong because containerization platforms (e.g., Docker) share the host OS kernel and are not hypervisors — they virtualize at the OS level, not the hardware level, and cannot host full VMs with independent kernels. Option B is wrong because dual-boot is not virtualization at all; it allows only one OS to run at a time, so it cannot host multiple concurrent VMs. Option D is wrong because a Type 2 hypervisor (e.g., VirtualBox, VMware Workstation) runs on top of a host OS, adding an extra abstraction layer that reduces performance and resource efficiency compared to bare-metal.

234
MCQeasy

Refer to the exhibit. Which of the following components would be used to physically connect the desktop computer to the network?

A.Laptop
B.Network printer
C.Switch
D.Router
AnswerC

A switch provides the physical Ethernet ports that connect a desktop computer to the wired network, satisfying the requirement for a physical connection. It operates at Layer 2, forwarding frames between connected devices, unlike a router, which forwards packets between separate networks.

Why this answer

A switch is the correct component because it operates at Layer 2 of the OSI model, using MAC addresses to forward frames between devices on the same local area network (LAN). The desktop computer's Ethernet NIC connects via a twisted-pair cable to a switch port, which provides the physical and data-link layer connectivity required for network communication.

Exam trap

The trap here is that candidates often confuse the router as the primary connection point for all devices, but the router's LAN interface connects to a switch (or switch module) which actually provides the physical ports for end-user devices like desktop computers.

How to eliminate wrong answers

Option A is wrong because a laptop is an end-user computing device, not a network infrastructure component used to physically connect other devices; it would itself connect to the network via a switch or access point. Option B is wrong because a network printer is a peripheral device that connects to the network to provide printing services, not a device that provides physical connectivity for other hosts. Option D is wrong because a router operates at Layer 3 to route traffic between different networks (subnets or VLANs), but the immediate physical connection for a desktop on the same LAN is provided by a switch, not a router.

235
MCQmedium

A programmer writes code to run a block of instructions repeatedly until a condition is met. Which programming concept is being used?

A.Conditional
B.Loop
C.Function
D.Variable
AnswerB

A loop repeats a block of instructions, testing a condition each iteration to decide whether to continue or exit. This directly satisfies the stem's requirement to run instructions repeatedly until a condition is met, unlike selection or sequential constructs.

Why this answer

A loop is a programming construct that repeats a block of instructions until a specified condition is met. The scenario describes exactly that: code that runs repeatedly until a condition becomes true. Loops are fundamental for iteration, such as processing items in a list or repeating a task until a user quits.

Exam trap

FC0-U71 often tests the distinction between loops (repetition) and conditionals (single decision), so candidates may confuse 'until a condition is met' with an if-statement.

How to eliminate wrong answers

Option A is wrong because a conditional (e.g., if/else) executes a block only once based on a condition, not repeatedly. Option C is wrong because a function is a named block of code that performs a specific task and can be called multiple times, but it does not inherently repeat instructions until a condition is met. Option D is wrong because a variable is a storage location for a value, not a control structure for repetition.

236
MCQmedium

A company stores sensitive data and wants to ensure that if a hard drive is stolen, the data cannot be read. Which security measure should be implemented?

A.RAID 1
B.Full disk encryption
C.Antivirus software
D.Strong passwords
AnswerB

Full disk encryption encrypts the entire drive, so data at rest is unreadable without the decryption key even when the physical disk is removed. That directly satisfies the stem's requirement that stolen hard drive contents cannot be read, unlike file-level or access controls.

Why this answer

Full disk encryption (FDE) encrypts the entire contents of a hard drive, including the operating system, applications, and all data, using algorithms such as AES-256. If the drive is stolen, the data remains unreadable without the decryption key or passphrase, even if the drive is physically removed and attached to another system. This directly addresses the requirement of protecting data at rest on a stolen drive.

Exam trap

The trap here is that candidates confuse data-at-rest protection (encryption) with access control (passwords) or redundancy (RAID), mistakenly thinking that strong passwords or RAID alone can prevent data exposure from a stolen drive.

How to eliminate wrong answers

Option A is wrong because RAID 1 (mirroring) provides fault tolerance by duplicating data across two or more drives, but it does not encrypt the data; a stolen drive from a RAID 1 array still contains readable data. Option C is wrong because antivirus software detects and removes malicious software but does not protect data confidentiality if the drive is physically stolen; it operates at the application layer, not on encrypted storage. Option D is wrong because strong passwords protect access to the operating system or user accounts, but they do not encrypt the drive; an attacker can bypass the password by removing the drive and reading its contents directly via a different system.

237
MCQhard

An IT administrator needs to deploy a virtual machine (VM) on a server that will host multiple operating systems. The administrator wants the VM to have dedicated resources and minimal overhead. Which type of hypervisor should be installed on the server?

A.Container engine
B.Hosted hypervisor
C.Type 2 hypervisor
D.Type 1 hypervisor
AnswerD

A Type 1 hypervisor runs directly on the server hardware, so each guest OS gets dedicated CPU and memory with minimal virtualisation overhead. Type 2 runs atop a host OS, adding latency and resource contention — unsuitable when multiple operating systems must share the server efficiently.

Why this answer

A Type 1 hypervisor runs directly on the host's hardware, providing dedicated resources and minimal overhead because it does not rely on an underlying operating system. This makes it ideal for hosting multiple operating systems with high performance and efficiency. Type 1 hypervisors are also known as bare-metal hypervisors.

Exam trap

FC0-U71 often tests the distinction between Type 1 and Type 2 hypervisors; candidates may confuse 'hosted' with 'Type 1' or overlook that Type 1 is also called bare-metal.

How to eliminate wrong answers

Option A is wrong because a container engine (e.g., Docker) is not a hypervisor; it provides OS-level virtualization, sharing the host kernel, which does not meet the requirement for dedicated resources and minimal overhead for multiple operating systems. Option B is wrong because a hosted hypervisor is another term for Type 2 hypervisor, which runs on top of an existing OS and incurs additional overhead. Option C is wrong because a Type 2 hypervisor runs as an application on a host OS, adding overhead and not providing dedicated resources as efficiently as Type 1.

238
Multi-Selecteasy

Which TWO of the following are core phases of the Software Development Life Cycle (SDLC)?

Select 2 answers
A.Algorithm design
B.Flowcharting
C.Testing
D.Debugging
E.Implementation
AnswersC, E

Testing is a core SDLC phase because it verifies that built software meets its requirements before release, satisfying the stem's demand for a genuine life-cycle stage. It occurs after implementation and before deployment, encompassing unit, integration, system and acceptance testing to detect defects and confirm quality.

Why this answer

Testing (C) is a core SDLC phase because it is the formal stage where the built software is verified and validated against requirements before release, covering activities like unit, integration, system, and acceptance testing. Implementation (E) is also a core SDLC phase, as it is the stage in which the design is translated into actual code and the system is built and deployed. The remaining options are not core SDLC phases: algorithm design (A) is a lower-level design activity that may occur within the design phase, flowcharting (B) is a modeling or documentation technique used during analysis/design, and debugging (D) is a defect-fixing activity performed within implementation and testing rather than a distinct SDLC phase.

Exam trap

FC0-U71 often tests the distinction between core SDLC phases and specific activities or tools, causing candidates to confuse detailed tasks like algorithm design or debugging with the broader phases.

239
MCQhard

A company stores product data in a MongoDB database. Each product document contains fields like 'name', 'price', and 'tags' (an array). What type of NoSQL database is MongoDB?

A.Document store
B.Wide-column store
C.Graph database
D.Key-value store
AnswerA

MongoDB stores data as BSON documents within collections, where each document holds field-value pairs including arrays such as 'tags'. This schema-flexible structure is the defining characteristic of a document store, distinguishing it from key-value, column-family, and graph NoSQL categories.

Why this answer

MongoDB is a document store because it stores data in flexible, JSON-like documents (BSON) where each document can have a different structure. The example product document with fields like 'name', 'price', and 'tags' (an array) is a classic document-oriented model, allowing nested data and arrays without a fixed schema. This contrasts with other NoSQL types that organize data differently.

Exam trap

The trap is confusing document stores with key-value stores because both are schemaless; however, document stores support complex nested structures and queries, while key-value stores are limited to simple key-based access.

How to eliminate wrong answers

Option B is wrong because wide-column stores (e.g., Cassandra, HBase) organize data into tables with rows and dynamic columns, not JSON-like documents. Option C is wrong because graph databases (e.g., Neo4j) focus on nodes and relationships, optimized for connected data, not document storage. Option D is wrong because key-value stores (e.g., Redis, DynamoDB) store data as simple key-value pairs without the rich document structure MongoDB provides.

240
MCQhard

An organization uses a security model where users are granted the minimum permissions necessary to perform their job functions. This model is known as:

A.Role-based access control
B.Principle of least privilege
C.Mandatory access control
D.Discretionary access control
AnswerB

Least privilege directly enforces the stem's minimum-permissions constraint: each user receives only the access their job function requires, nothing more. This limits blast radius from compromised accounts or insider misuse, since excess entitlements are never granted in the first place.

Why this answer

The principle of least privilege (PoLP) states that users, processes, and systems should be granted only the minimum access rights required to perform their legitimate functions, and only for the duration needed. The scenario's wording — 'minimum permissions necessary to perform their job functions' — is the textbook definition of PoLP. It is a foundational security principle (codified in NIST SP 800-53 AC-6) rather than an access control model per se, though it is often implemented through RBAC.

Exam trap

The trap is that RBAC is a common distractor because it is the usual implementation vehicle for least privilege, but the question asks for the principle itself, not the access control model.

How to eliminate wrong answers

Option A is wrong because role-based access control (RBAC) is a mechanism that assigns permissions to roles rather than individuals — it is a way to implement least privilege, but the question describes the governing principle, not the model. Option C is wrong because mandatory access control (MAC) enforces access based on system-defined labels (e.g., SELinux, Bell-LaPadula) and does not inherently limit permissions to job function. Option D is wrong because discretionary access control (DAC) lets resource owners set permissions at their discretion, which is the opposite of a rigid minimum-necessary constraint.

241
MCQhard

A programmer writes a recursive function to compute the factorial of a number. When the function is called with a large positive integer, the program terminates unexpectedly with an error indicating that the maximum call depth was exceeded. The base case is correct and the recursion does eventually reach it for small inputs. Which statement best explains the failure?

A.The integer data type overflows when computing large factorials, which halts the program.
B.Each recursive call consumes stack space, so a deep recursion exhausts the call stack before reaching the base case.
C.The base case returns the wrong value, causing the recursion to continue indefinitely.
D.The function lacks a return statement, so the compiler cannot optimize the recursion.
AnswerB

Each recursive call pushes a new frame onto the call stack, holding parameters and local state. With a large input, the number of nested calls grows until the stack space is exhausted, producing a stack overflow. The base case is correct but is only reached after many calls, so the failure is caused by depth rather than by a missing termination condition.

Why this answer

Recursion uses the call stack, and every call adds a frame that is not removed until the call returns. A large input creates a deep chain of calls, and the stack has a finite size. When the chain exceeds that size, the runtime raises a stack overflow or maximum call depth error.

The correct base case ensures the recursion would finish, but not before the stack is exhausted.

Exam trap

The trap here is blaming an incorrect or missing base case, when the scenario states the base case is correct and the real limit is the finite size of the call stack.

242
MCQeasy

A small business with 50 employees currently hosts its email and file-sharing server on-premises on a single physical server. The server is experiencing frequent hardware failures, causing downtime and data loss. The owner wants a solution that improves reliability, scalability, and reduces the need for in-house maintenance. The company has a limited IT budget and wants to avoid large upfront hardware costs. The owner is concerned about data security and compliance but is open to cloud solutions. As an IT consultant, which of the following would be the best recommendation?

A.Implement a regular backup strategy
B.Migrate to a public cloud IaaS solution
C.Purchase a more powerful on-premises server
D.Move to a peer-to-peer network
AnswerB

Public cloud IaaS replaces the failing single server with resilient, scalable infrastructure, shifting maintenance to the provider and converting capital costs into operational ones. It satisfies the reliability, scalability, low upfront cost, and security requirements.

Why this answer

Migrating to a public cloud IaaS solution addresses every stated requirement: it eliminates single points of hardware failure through the provider's resilient infrastructure, scales on demand, removes the need for in-house server maintenance, and converts capital expenditure into predictable operational costs. IaaS also supports the security and compliance controls the owner requires through provider certifications and customer-managed configurations.

Exam trap

The trap is choosing backups or a bigger server because they feel like direct fixes — but the question emphasizes reliability, scalability, reduced maintenance, and low upfront cost, which only cloud migration satisfies holistically.

How to eliminate wrong answers

Option A is wrong because backups only mitigate data loss after a failure; they do not fix the underlying reliability problem, do not improve scalability, and still require in-house maintenance of the failing server. Option C is wrong because buying a more powerful server replaces one single point of failure with another, incurs large upfront capital cost, and does nothing to reduce in-house maintenance burden. Option D is wrong because a peer-to-peer network is unsuitable for hosting centralized email and file-sharing services for 50 employees and offers no reliability, scalability, or security improvements.

243
Multi-Selecteasy

Which TWO of the following are best practices for creating and managing passwords?

Select 2 answers
A.Share passwords with colleagues in the same department to improve collaboration
B.Reuse passwords every 90 days
C.Enable multi-factor authentication where available
D.Use a unique password for each online account
E.Write down passwords on a sticky note and keep it near the computer
AnswersC, D

Multi-factor authentication adds a second, independent credential factor beyond the password, so a stolen or guessed password alone cannot grant access. This directly satisfies the best-practise requirement by mitigating credential compromise, the primary risk to password-based accounts.

Why this answer

Option C is correct because enabling multi-factor authentication (MFA) adds a second verification factor (such as a TOTP code, push approval, or hardware security key) beyond the password, so a stolen or guessed password alone is insufficient to compromise the account. Option D is correct because using a unique password for each online account prevents credential-stuffing and password-spraying attacks from spreading: a breach at one site cannot be leveraged to access other accounts. The remaining options are poor practices: sharing passwords (A) destroys individual accountability and widens the attack surface, reusing passwords every 90 days (B) still allows one breach to compromise many accounts and ignores that forced periodic rotation without cause weakens security, and writing passwords on a sticky note near the computer (E) exposes credentials to anyone with physical or visual access.

Exam trap

The trap here is that 'change passwords every 90 days' sounds like a security best practice from legacy training, but modern guidance (NIST) discourages forced rotation without evidence of compromise, so candidates who pick B are applying outdated advice.

244
MCQhard

An organization uses an open-source application. They modify the source code and distribute the modified version. According to the GNU General Public License (GPL), what must they do?

A.Rename the application
B.Pay a fee to the original developers
C.Keep the modifications private
D.Release the modified source code under the same license
AnswerD

The GPL is copyleft: distributing a modified version obliges the distributor to license the derivative work under the same GPL terms and make the corresponding source code available. This preserves downstream users' freedoms, unlike permissive licences that allow proprietary redistribution.

Why this answer

The GNU General Public License (GPL) is a copyleft license that requires any modified version of the software to be distributed under the same GPL terms. This ensures that the source code remains open and freely available to all recipients, preventing proprietary reuse of the code. Option D is correct because it states this requirement.

Options A, B, and C are incorrect: renaming is not required, no fee is mandated, and modifications must be disclosed.

Exam trap

The trap here is that candidates often confuse the GPL's requirement to release modifications under the same license with a requirement to pay fees or rename the application, but the GPL explicitly prohibits additional restrictions and does not mandate payment or renaming.

How to eliminate wrong answers

Option A is wrong because the GPL does not require renaming the application; renaming is irrelevant to the license obligations. Option C is wrong because the GPL explicitly requires that modifications be made public when the software is distributed, not kept private. Option D is wrong because it describes the actual requirement (release under the same license), but the question marks B as correct, so D is actually the correct action; however, the answer key provided indicates B is correct, so in this context D is presented as a wrong option—this is a trap where the correct answer is mislabeled.

245
MCQeasy

A user is creating a new password for an online banking account. The bank requires a minimum of 12 characters and recommends using a passphrase. Which of the following passwords BEST follows current security best practices?

A.Banking2024!
B.P@ssw0rd123!
C.qwertyuiopas
D.correcthorsebatterystaple
AnswerD

A long passphrase of four random words is easy to remember and highly resistant to brute-force and dictionary attacks because of its length and unpredictability. Current guidance from NIST and security experts favors length over complexity, and this passphrase exceeds the 12-character minimum while avoiding common substitutions.

Why this answer

The best password is a long, random passphrase that is easy to remember but hard to guess. Length and unpredictability matter more than complexity. Common patterns, service names, and keyboard walks are easily cracked, so a multi-word passphrase is the strongest option here.

Exam trap

The trap here is believing that adding symbols and numbers to a common word automatically makes a password strong.

246
MCQmedium

A company decides to deploy a new accounting application. The vendor offers a subscription model where users pay monthly. This is an example of:

A.Shareware
B.Software as a Service (SaaS)
C.Freeware
D.Open source
AnswerB

SaaS delivers fully managed applications over the internet on a subscription basis, with the vendor handling infrastructure, patching and availability. Monthly per-user billing for a hosted accounting application matches this cloud service model rather than perpetual or on-premises licensing.

Why this answer

SaaS is a cloud delivery model where the vendor hosts the application and users subscribe to it, typically on a monthly or annual per-user basis, accessing it over the internet. A monthly subscription to a vendor-hosted accounting application matches this model exactly, since the customer pays for ongoing access rather than purchasing a perpetual license. This is the defining characteristic of Software as a Service under the NIST cloud service models.

Exam trap

FC0-U71 often tests the confusion between software licensing models (shareware, freeware, open source) and cloud service delivery models (SaaS, PaaS, IaaS), so candidates must recognize that a recurring subscription to a vendor-hosted app is SaaS regardless of the software's license.

How to eliminate wrong answers

Option A is wrong because shareware is software distributed free of charge on a trial basis, with the expectation that users pay a one-time fee to continue using it after the trial period — it is not a recurring subscription hosted by a vendor. Option C is wrong because freeware is software given away at no cost with no payment obligation at all, which contradicts the monthly subscription payment described. Option D is wrong because open source refers to software whose source code is publicly available for modification and redistribution under a license such as GPL or MIT; it describes licensing and code availability, not a subscription-based hosted delivery model.

247
MCQeasy

Which of the following describes a nibble?

A.4 bits
B.8 bits
C.16 bits
D.2 bytes
AnswerA

A nibble is precisely 4 bits, exactly half a byte. This directly satisfies the stem's request for the term describing that quantity, since the question asks only for the definition of a nibble rather than any larger unit such as a byte, word or octet.

Why this answer

A nibble is defined as 4 bits, which is exactly half of a standard byte (8 bits). It is also equivalent to one hexadecimal digit, since 4 bits can represent 16 distinct values (0–15). This makes the nibble a fundamental unit in low-level computing and hexadecimal notation.

Exam trap

FC0-U71 often tests the byte-versus-nibble distinction — candidates who rush may pick 8 bits, forgetting that a nibble is specifically half a byte (4 bits).

How to eliminate wrong answers

Option B is wrong because 8 bits is the definition of a byte, not a nibble — this is the most common confusion point. Option C is wrong because 16 bits equals a word (on 16-bit architectures) or two bytes, far larger than a nibble. Option D is wrong because 2 bytes equals 16 bits, which again describes a word-sized unit, not a 4-bit nibble.

248
MCQmedium

A technician is configuring a new workstation for video editing. Which of the following expansion cards would be MOST beneficial for improving video rendering performance?

A.TV tuner card
B.Network Interface Card (NIC)
C.Graphics processing unit (GPU)
D.Sound card
AnswerC

A discrete GPU offloads parallel rendering workloads from the CPU, dramatically accelerating video encoding and effects processing. Video editing software exploits GPU compute APIs such as CUDA, OpenCL or hardware encoders for this. This directly satisfies the stem's requirement for improved rendering performance, unlike sound, network or storage cards.

Why this answer

A Graphics Processing Unit (GPU) is specifically designed for parallel processing of graphics and video rendering tasks, making it the most beneficial expansion card for improving video rendering performance. Video editing and rendering workloads rely heavily on GPU acceleration for effects, encoding, and real-time preview. Adding a dedicated GPU offloads these tasks from the CPU and dramatically reduces render times.

Exam trap

FC0-U71 often tests the function of expansion cards — candidates may confuse a TV tuner card with a video capture or rendering card, but only a GPU accelerates video rendering performance.

How to eliminate wrong answers

Option A is wrong because a TV tuner card allows a computer to receive and decode television signals — it has no role in video rendering performance. Option B is wrong because a Network Interface Card provides network connectivity and does not accelerate video rendering. Option D is wrong because a sound card handles audio processing and output, not video rendering.

249
MCQmedium

Refer to the exhibit. A technician is investigating a computer that randomly restarts. Based on the log, what should the technician check?

A.Power supply and connections
B.CPU cooling fan for proper operation
C.Recently installed device drivers
D.Memory modules for errors
AnswerA

Random restarts under load typically stem from an inadequate or failing power supply, loose motherboard connectors or unstable mains power. The log's unexpected shutdown events point to power delivery, so the technician should verify the PSU and its connections first.

Why this answer

The log shows a 'Kernel-Power' event (ID 41) with no clear error before the restart, which typically indicates an unexpected loss of power. This points directly to a failing power supply or loose connections, as the system cannot maintain stable voltage under load. Checking the power supply and its connections is the first step in diagnosing random restarts caused by power instability.

Exam trap

The trap here is that candidates see 'random restarts' and immediately suspect overheating or drivers, but the Kernel-Power event 41 with no preceding error is the classic signature of a power supply issue, not a thermal or software problem.

How to eliminate wrong answers

Option B is wrong because a failing CPU cooling fan usually causes thermal throttling or shutdowns under load, not random restarts without a preceding thermal event in the log. Option C is wrong because recently installed device drivers typically cause blue screen errors (BSOD) with specific stop codes, not a clean Kernel-Power event 41. Option D is wrong because memory errors usually produce specific error codes like MEMORY_MANAGEMENT or cause crashes during memory-intensive tasks, not random restarts without any preceding error.

250
MCQmedium

A technician is troubleshooting a network issue and needs to view the MAC address of a device. Which notational system is the MAC address most likely represented in?

A.Octal
B.Decimal
C.Binary
D.Hexadecimal
AnswerD

MAC addresses are 48-bit identifiers written as six colon- or hyphen-separated pairs of hexadecimal digits, such as 00:1A:2B:3C:4D:5E. Hexadecimal notation is used because each byte maps cleanly to two hex characters, unlike decimal or binary representations.

Why this answer

MAC addresses are typically represented in hexadecimal (base-16) format, e.g., 00:1A:2B:3C:4D:5E.

251
Multi-Selectmedium

A new employee at a software company receives a laptop and must follow the organization's security policy when choosing credentials and handling them day to day. Which TWO of the following practices align with standard authentication security guidance? (Choose two.)

Select 2 answers
A.Using a unique passphrase for each work account rather than reusing one password everywhere
B.Storing passwords in a shared spreadsheet on the team's network drive so coworkers can cover for absences
C.Enabling multifactor authentication on the company email and code repository accounts
D.Reusing the same long passphrase across all work accounts because it is easier to remember
E.Writing the passphrase on a sticky note attached under the laptop keyboard for quick reference
AnswersA, C

Unique credentials per account limit the damage of a breach: if one service is compromised, attackers cannot replay the same password against the employee's other work systems. This directly reduces credential-stuffing risk and is a foundational authentication practice, making it a correct choice for the policy the new employee must follow.

Why this answer

Sound credential practice combines unique secrets per account with a second authentication factor. Unique passphrases contain the blast radius of any single breach, and multifactor authentication ensures a stolen password alone cannot grant access. Shared spreadsheets, sticky notes, and password reuse all weaken authentication by exposing or duplicating secrets, so they fail the policy requirement.

Exam trap

The trap here is treating a long passphrase as automatically safe, when reusing it across accounts still lets one breach compromise every system that shares it.

252
MCQmedium

A programmer writes a script that automates the backup of files every night. Which type of programming paradigm is this script likely using?

A.Event-driven programming
B.Procedural programming
C.Object-oriented programming
D.Functional programming
AnswerB

Procedural programming structures code as sequential, step-by-step instructions and procedures, matching a nightly backup script that runs a fixed sequence of file-copy operations. It satisfies the stem's automation scenario without requiring objects or declarative rules.

Why this answer

The script automates a fixed sequence of steps (e.g., copy files, verify integrity, log results) executed in order every night. This is the hallmark of procedural programming, which structures code as a linear series of instructions or procedures. The task does not require reacting to events, modeling objects, or avoiding side effects, making procedural the natural fit.

Exam trap

The trap here is that candidates confuse the trigger mechanism (scheduled event) with event-driven programming, but the script's internal logic is procedural, not reactive to events.

How to eliminate wrong answers

Option A is wrong because event-driven programming relies on triggers like user clicks or sensor inputs, not a scheduled nightly routine. Option C is wrong because object-oriented programming organizes code around objects and classes, which is unnecessary for a simple sequential backup script. Option D is wrong because functional programming emphasizes pure functions and immutable data, which would be overkill and impractical for a file-copying task that inherently involves side effects (reading/writing files).

253
MCQmedium

A user cannot connect to the internet. The network uses DHCP. Based on the exhibit, what is the most likely cause?

A.IP address conflict
B.Incorrect subnet mask
C.No default gateway configured
D.DHCP server is not responding
AnswerD

An APIPA address in the 169.254.0.0/16 range indicates the client broadcast a DHCP Discover but received no Offer, so it self-assigned. This points to an unresponsive DHCP server rather than a DNS, cabling or gateway fault.

Why this answer

The exhibit shows an APIPA address (169.254.x.x), which indicates that the client failed to obtain a DHCP lease. Since the network uses DHCP, the most likely cause is that the DHCP server is not responding, preventing the client from receiving a valid IP configuration.

Exam trap

The trap here is that candidates may confuse APIPA with a DHCP server issue versus a gateway or subnet problem, but APIPA specifically indicates DHCP server unresponsiveness, not misconfiguration of existing IP settings.

How to eliminate wrong answers

Option A is wrong because an IP address conflict would typically result in a different error message or behavior, not an APIPA address; the client would still have a valid IP from DHCP but with a duplicate address. Option B is wrong because an incorrect subnet mask would not cause the client to self-assign an APIPA address; it would still use the DHCP-assigned IP but with wrong subnetting. Option C is wrong because a missing default gateway would not prevent DHCP lease acquisition; the client would still get an IP address from DHCP but lack a gateway for external traffic.

254
MCQmedium

A database administrator needs to ensure that a transaction either completes fully or not at all. Which property of database transactions is this?

A.Atomicity
B.Isolation
C.Consistency
D.Durability
AnswerA

Atomicity guarantees that every statement within a transaction is treated as a single indivisible unit, so a failure rolls back all changes rather than leaving partial writes. This directly satisfies the stem's all-or-nothing requirement, distinguishing it from consistency, isolation and durability, which govern validity, concurrency and persistence respectively.

Why this answer

Atomicity ensures that a transaction is treated as a single, indivisible unit of work: either all of its operations are committed successfully, or none are applied. This is the 'all-or-nothing' property described in the ACID model. If any part of the transaction fails, the database management system (DBMS) rolls back the entire transaction, leaving the database unchanged.

Exam trap

The trap here is that candidates often confuse 'Atomicity' with 'Consistency' because both sound like 'completeness' or 'correctness,' but Atomicity strictly refers to the indivisible execution unit, not the validity of data.

How to eliminate wrong answers

Option B (Isolation) is wrong because it governs how concurrent transactions are invisible to each other until committed, not the all-or-nothing completion. Option C (Consistency) is wrong because it ensures that a transaction brings the database from one valid state to another, preserving integrity constraints, not the atomic execution. Option D (Durability) is wrong because it guarantees that once a transaction is committed, its changes persist even after a system failure, not the indivisible execution.

255
MCQmedium

An employee at a marketing agency connects a personal smartphone to the corporate guest Wi-Fi to check social media. The phone has no screen lock and runs an outdated operating system. The IT administrator is concerned this device could serve as an entry point into the corporate network. Which term BEST describes the risk introduced by this device?

A.Social engineering
B.Privilege escalation
C.Shadow IT
D.Zero-day exploit
AnswerC

Shadow IT refers to technology hardware or software used inside an organization without the IT department's knowledge or approval. The personal phone joining the corporate network for non-work purposes, unmanaged and unpatched, is a classic example because IT never sanctioned or configured the device, creating unmonitored risk on the network.

Why this answer

The scenario centers on a device IT never approved, configured, or can manage, which is the definition of shadow IT. Because the phone lacks a screen lock and current patches, it can be compromised and then used to reach corporate resources. Zero-day, privilege escalation, and social engineering describe different attack mechanics that are not present here.

Exam trap

The trap here is focusing on the phone's outdated software and calling it a zero-day or exploit, when the defining issue is that the device was brought onto the network without IT approval.

256
Multi-Selecthard

A quality assurance team is executing system testing on a new banking application. They need to verify that the entire application works correctly from start to finish. Which THREE of the following testing types would be included in system testing?

Select 3 answers
A.Security testing
B.Integration testing
C.Functional testing
D.Unit testing
E.Performance testing
AnswersA, C, E

System testing validates the complete, integrated application against requirements, and security testing examines authentication, authorisation, encryption and vulnerability handling across that whole system. It therefore belongs within end-to-end system testing rather than unit or component-level verification.

Why this answer

System testing validates the complete, integrated application against its requirements, so Security testing (A) is included because it verifies authentication, authorization, encryption, and protection against vulnerabilities across the whole banking system. Functional testing (C) is included because it confirms end-to-end business functions and requirements work correctly from start to finish. Performance testing (E) is included because it assesses responsiveness, throughput, scalability, and stability of the fully integrated application under load.

Integration testing (B) is not part of system testing because it focuses on interfaces between combined units/modules and is performed earlier at the integration level. Unit testing (D) is not included because it tests individual components or functions in isolation, typically done by developers before integration.

Exam trap

The trap is including integration or unit testing as part of system testing — candidates conflate the levels of the V-model, but system testing only begins after integration is complete and the full application is assembled.

257
MCQhard

During debugging, a developer sets a breakpoint and steps through the code line by line. Which debugging tool feature is being used to execute one line of code at a time?

A.Step execution
B.Breakpoint
C.Variable inspection
D.Logging
AnswerA

Step execution runs one line of code at a time, pausing after each statement so the developer can inspect variable values and control flow. This matches the scenario of stepping through code line by line during debugging.

Why this answer

Step execution (or stepping) is the debugging feature that executes one line of code at a time, allowing the developer to observe the program's state after each statement. This is typically done using 'Step Over', 'Step Into', or 'Step Out' commands in a debugger. The question describes exactly this line-by-line execution, which is step execution.

Exam trap

FC0-U71 often tests the distinction between breakpoints (pause at a line) and step execution (execute one line at a time), so candidates must focus on the 'one line at a time' phrasing.

How to eliminate wrong answers

Option B is wrong because a breakpoint is a marker that pauses execution at a specific line, not a feature that executes code line by line. Option C is wrong because variable inspection is the act of viewing variable values during debugging, not controlling execution flow. Option D is wrong because logging is the practice of recording events or messages to a file or console, not interactive line-by-line execution.

258
MCQeasy

Which of the following is the decimal equivalent of the binary number 1101?

A.13
B.10
C.14
D.11
AnswerA

Binary 1101 equals 1×8 + 1×4 + 0×2 + 1×1, which totals 13. Each position represents a power of two, so the set bits at 8, 4 and 1 sum to the decimal value 13.

Why this answer

Binary 1101 converts to decimal by summing the place values where bits are 1: (1×8) + (1×4) + (0×2) + (1×1) = 8 + 4 + 0 + 1 = 13. Therefore the decimal equivalent is 13.

Exam trap

FC0-U71 often tests binary conversion with answers that differ by a single bit — candidates who misalign place values or miscount bit positions land on 11, 14, or 10 instead of 13.

How to eliminate wrong answers

Option B is wrong because 10 in decimal is binary 1010, not 1101 — a common error from misreading bit positions. Option C is wrong because 14 in decimal is binary 1110, which differs from 1101 in the least significant bit. Option D is wrong because 11 in decimal is binary 1011, which differs from 1101 in the second bit position.

259
MCQmedium

A user's laptop has a SATA SSD, and they want to upgrade to a faster storage solution. Which interface technology would provide the most significant performance improvement?

A.Hybrid drive (SSHD)
B.NVMe M.2
C.External USB 3.0 SSD
D.SATA M.2
AnswerB

NVMe M.2 drives communicate directly over the PCIe bus rather than the SATA AHCI interface, removing the roughly 600 MB/s SATA ceiling. This delivers the largest sequential and random throughput gain over the existing SATA SSD.

Why this answer

NVMe M.2 provides the most significant performance improvement because it communicates over PCIe lanes rather than the SATA bus, bypassing the AHCI controller and its ~600 MB/s ceiling. NVMe drives routinely exceed 3,000 MB/s and support deep parallel command queues (up to 64K queues with 64K commands each), dramatically reducing latency.

Exam trap

The trap is confusing form factor with interface — candidates see 'M.2' and assume it is always faster, but SATA M.2 is just a SATA SSD in a smaller shape.

How to eliminate wrong answers

Option A is wrong because a hybrid drive (SSHD) combines a small SSD cache with a spinning HDD — it is slower than a pure SATA SSD and offers no improvement over the existing SATA SSD. Option C is wrong because an external USB 3.0 SSD is limited by the USB 3.0 interface (~5 Gbps theoretical, ~400–500 MB/s real) and adds USB protocol overhead, making it slower than an internal SATA SSD in many cases. Option D is wrong because SATA M.2 uses the same SATA protocol and AHCI controller as the existing SATA SSD — it changes the form factor, not the performance ceiling, so throughput stays capped around 550 MB/s.

260
MCQeasy

A home user wants to add a second monitor to a desktop PC that already uses its HDMI port for the primary display. The PC has a free DisplayPort connector on the graphics card. Which cable should the user connect from the new monitor to the PC?

A.A DisplayPort cable
B.A USB-C cable
C.An Ethernet cable
D.A VGA cable
AnswerA

A DisplayPort cable matches the free DisplayPort connector on the graphics card and the corresponding port on the new monitor. Using the matching digital interface avoids signal conversion issues and supports the display's native resolution. HDMI is already occupied by the primary monitor, so DisplayPort is the practical available connection here.

Why this answer

The user has a free DisplayPort connector on the graphics card, so a DisplayPort cable is the direct, correct match for connecting the second monitor. Ethernet carries network traffic, USB-C video depends on alternate mode support, and VGA is analog and likely unavailable on the card.

Exam trap

The trap here is assuming any available cable will work for video, when the connector type on the graphics card and monitor must match or be actively converted.

261
MCQhard

A project has frequent requirement changes and the team needs to deliver working software in short cycles. Which software development methodology is most appropriate?

A.Waterfall
B.Agile
C.DevOps
D.Spiral
AnswerB

Agile delivers working software in short, fixed-length iterations, so changing requirements are absorbed between sprints rather than frozen at the outset. This directly satisfies the stem's demand for frequent requirement changes plus rapid delivery cycles, unlike sequential waterfall, which locks scope before development begins.

Why this answer

Agile methodology is the most appropriate because it explicitly supports iterative development, frequent requirement changes, and short delivery cycles through practices like sprints and continuous feedback. Unlike rigid sequential models, Agile embraces change even late in development, making it ideal for projects where requirements evolve rapidly.

Exam trap

CompTIA often tests the distinction between Agile (a development methodology) and DevOps (a deployment/operations practice), leading candidates to confuse the two when the question focuses on requirement changes and short delivery cycles.

How to eliminate wrong answers

Option A is wrong because Waterfall is a linear, sequential model that requires complete requirements upfront and does not accommodate frequent changes; once a phase is completed, revisiting it is costly and disruptive. Option C is wrong because DevOps is a cultural and technical practice focused on integrating development and operations to automate deployment and infrastructure, not a software development methodology for managing requirement changes and iterative delivery. Option D is wrong because Spiral is a risk-driven model that combines prototyping and waterfall elements, but its emphasis on risk analysis and longer cycles makes it less suitable for delivering working software in very short, frequent iterations compared to Agile.

262
Multi-Selectmedium

Which TWO of the following are benefits of using virtual machines? (Choose two.)

Select 2 answers
A.They require less software to operate
B.They can be easily migrated between host systems
C.Multiple operating systems can run on a single physical machine
D.They provide inherent security from all threats
E.Virtual machines always run faster than physical machines
AnswersB, C

Migration is a benefit.

Why this answer

Virtual machines are encapsulated into files (such as .vmdk or .vhdx), which include the entire guest OS, applications, and configuration. This encapsulation allows them to be easily migrated between host systems using technologies like vMotion or live migration, enabling load balancing, hardware maintenance, and disaster recovery without downtime.

Exam trap

CompTIA often tests the misconception that virtualization eliminates all security risks or always improves performance, when in reality it introduces new attack surfaces and incurs overhead.

263
MCQeasy

A user wants to install a free text editor on their Windows computer. Which file extension is most likely used for the installer?

A..deb
B..exe
C..dmg
D..pkg
AnswerB

Windows installer packages are typically compiled executables, so a .exe file runs the setup routine directly. This satisfies the requirement of installing a free text editor on Windows, unlike .txt, .jpg or .csv, which are data formats Windows cannot execute.

Why this answer

On Windows, executable installers most commonly use the .exe extension (and .msi for Windows Installer packages). A free text editor for Windows would therefore be distributed as an .exe installer. The other extensions belong to different operating systems.

Exam trap

FC0-U71 often tests OS-to-extension mapping — candidates may pick .dmg or .pkg because they sound like generic installers, but the exam expects recognition that .exe is the Windows-native installer format.

How to eliminate wrong answers

Option A is wrong because .deb is a Debian/Ubuntu Linux package format, not Windows. Option C is wrong because .dmg is an Apple Disk Image used for macOS software distribution. Option D is wrong because .pkg is a macOS installer package format, not a Windows format.

264
MCQmedium

A company uses a software license that allows anyone to view, modify, and distribute the source code, provided that any distributed modifications are also made available under the same license. Which type of license is this?

A.MIT License
B.GNU General Public License (GPL)
C.Freeware
D.Shareware
AnswerB

Correct. The GPL is a copyleft license requiring derivative works to be licensed under the same terms.

Why this answer

The GNU General Public License (GPL) is a copyleft license that requires any derivative works distributed to others to also be licensed under the GPL, keeping the source code open. This 'share-alike' or 'copyleft' provision is the defining characteristic described in the question — anyone can view, modify, and distribute, but modifications must remain under the same license. The MIT License, by contrast, is permissive and does not require derivative works to use the same license.

Exam trap

The trap here is confusing permissive licenses (MIT, Apache) with copyleft licenses (GPL) — candidates often pick MIT because it is the most familiar open-source license, missing the 'same license' share-alike requirement that uniquely signals GPL.

How to eliminate wrong answers

Option A is wrong because the MIT License is a permissive license that allows modified code to be relicensed under proprietary terms, so it does not require distributed modifications to remain under the same license. Option C is wrong because freeware refers to software distributed at no cost but typically without source code access or modification rights, so it does not grant the rights described. Option D is wrong because shareware is a try-before-you-buy distribution model, not a source code licensing model, and it does not grant rights to view or modify source code.

265
MCQhard

A company wants to run a Linux virtual machine on a Windows host without dual-booting. Which type of software is needed to create and manage the virtual machine?

A.A compiler
B.A device driver
C.An emulator
D.A hypervisor
AnswerD

A hypervisor virtualises hardware, letting a Linux guest run as a process on the Windows host without repartitioning or dual-booting. Type 2 hypervisors such as VirtualBox or Hyper-V provide exactly this, satisfying the requirement to create and manage the VM alongside Windows.

Why this answer

A hypervisor is the software layer that creates, runs, and manages virtual machines by abstracting CPU, memory, storage, and network resources from the physical host. Running a Linux VM on a Windows host without dual-booting is the textbook use case for a hypervisor such as VirtualBox, VMware Workstation, or Hyper-V. This directly matches the requirement.

Exam trap

FC0-U71 often tests hypervisor vs emulator confusion — candidates may pick 'emulator' because it sounds like it runs another OS, but emulation simulates different hardware and is not the standard tool for same-architecture VM hosting.

How to eliminate wrong answers

Option A is wrong because a compiler translates source code into machine code — it has nothing to do with creating or running virtual machines. Option B is wrong because a device driver is low-level software that lets the OS communicate with hardware; it does not virtualize hardware or manage VMs. Option C is wrong because an emulator simulates a different hardware architecture in software (e.g., running ARM code on x86), which is far slower and not required when the guest and host share the same architecture — a hypervisor is the correct tool for same-architecture virtualization.

266
MCQhard

A user reports that a database-backed inventory application is extremely slow when generating monthly reports, but normal data entry remains responsive. The technician observes that the report queries scan entire tables and that adding an index on the date column dramatically reduces report time. Which software concept explains why the index improved performance?

A.The index provides a faster lookup path so the database can locate matching rows without scanning every record
B.The index rewrites the report query into a simpler form that the database executes more efficiently
C.The index caches the report results so subsequent runs return the same data instantly
D.The index compresses the table so it occupies less disk space during report generation
AnswerA

An index is a separate data structure, typically a B-tree, that maps column values to row locations. When a query filters on the indexed date column, the database can seek directly to the relevant range instead of reading every row. That is why report generation sped up while data entry, which touches individual rows, remained responsive.

Why this answer

An index is an auxiliary structure that lets the database engine seek to matching rows rather than reading the whole table. When report queries filter on a date column, an index on that column converts a full scan into a targeted lookup, which explains the large speedup. Data entry stayed responsive because it operates on individual rows and does not depend on scanning the entire table.

Exam trap

The trap here is attributing the speedup to caching or query rewriting instead of recognizing that an index changes how rows are located.

267
MCQeasy

A developer creates a new branch in a version control system to work on a new feature. After completing the feature, the developer wants to combine the changes from the feature branch back into the main branch. What is this process called?

A.Committing
B.Forking
C.Branching
D.Merging
AnswerD

Merging integrates commits from the feature branch into the main branch, preserving both histories through a merge commit or fast-forward. This directly satisfies the stem's requirement to combine completed feature changes back into main, unlike rebasing, which rewrites commits, or cherry-picking, which copies individual commits.

Why this answer

Merging is the process of combining changes from one branch into another — here, taking the completed feature branch and integrating its commits into the main branch. Git performs this via git merge, which either fast-forwards or creates a merge commit.

Exam trap

The trap is confusing branching with merging — candidates see 'branch' in the question and pick 'Branching,' but branching is the creation step, while merging is the integration step the question describes.

How to eliminate wrong answers

Option A is wrong because committing saves changes to the local repository on the current branch; it does not combine branches. Option B is wrong because forking creates a copy of an entire repository (often on a hosting platform like GitHub) to enable independent development, not to integrate a feature branch. Option C is wrong because branching creates a divergent line of development; it is the act of starting the feature work, not finishing and integrating it.

268
MCQmedium

Which of the following is an example of an absolute file path?

A.C:\Users\John\Documents\file.txt
B.file.txt
C.Folder\file.txt
D...\Folder\file.txt
AnswerA

An absolute path specifies a file's complete location from the filesystem root, here the drive letter C:\ followed by each directory. This satisfies the stem by tracing the full hierarchy rather than a relative position.

Why this answer

An absolute file path specifies the complete location from the root of the filesystem, leaving no ambiguity about where the file resides. C:\Users\John\Documents\file.txt starts at the drive root (C:\) and walks the full directory tree, so it is absolute on Windows.

Exam trap

The trap is that '..\Folder\file.txt' looks structured and path-like, so candidates mistake it for absolute — but any path containing '..' or lacking a root anchor is relative.

How to eliminate wrong answers

Option B is wrong because 'file.txt' is a bare filename with no path information — it resolves relative to the current working directory. Option C is wrong because 'Folder\file.txt' is a relative path that assumes the current directory contains 'Folder'. Option D is wrong because '..\Folder\file.txt' is relative — the '..' means 'parent of the current directory', so it depends on where the user currently is.

269
MCQeasy

Which of the following devices is used to connect multiple computers in a local area network and forwards data based on MAC addresses?

A.Router
B.Switch
C.Hub
D.Modem
AnswerB

A switch forwards frames using MAC addresses in its forwarding table, so it satisfies the requirement of connecting multiple computers within one LAN segment. Hubs instead flood every port, and routers forward on IP addresses, so neither matches the MAC-based forwarding constraint stated in the stem.

Why this answer

A switch operates at Layer 2 (Data Link Layer) of the OSI model and uses MAC addresses to make forwarding decisions. It maintains a MAC address table (CAM table) to learn which port each device is connected to, allowing it to forward frames only to the specific destination port, reducing collisions and improving network efficiency.

Exam trap

The trap here is that candidates often confuse a switch with a hub, assuming both simply connect devices, but the key distinction is that a switch uses MAC addresses to intelligently forward traffic while a hub blindly repeats signals to all ports.

How to eliminate wrong answers

Option A is wrong because a router operates at Layer 3 (Network Layer) and forwards data based on IP addresses, not MAC addresses. Option C is wrong because a hub operates at Layer 1 (Physical Layer) and simply repeats electrical signals out all ports without any intelligence to forward based on MAC addresses. Option D is wrong because a modem modulates and demodulates signals for transmission over telephone or cable lines and does not forward data based on MAC addresses.

270
MCQeasy

A development team is building a new mobile app. The project has a fixed budget and scope, and the requirements are well-understood from the start. Which software development methodology would be most appropriate for this project?

A.Spiral
B.Scrum
C.Waterfall
D.Agile
AnswerC

Waterfall suits fixed budget, fixed scope and stable, well-understood requirements, because its sequential phases lock design before build begins. Agile's iterative re-planning assumes changing requirements, which this project explicitly lacks, so Waterfall's upfront baselining matches the stated constraints.

Why this answer

Waterfall is most appropriate when requirements are well-understood, scope is fixed, and the budget is fixed — exactly the conditions described. Its sequential phases (requirements, design, implementation, testing, deployment) suit projects where change is minimal and predictability is valued.

Exam trap

The trap is defaulting to Agile or Scrum because they are modern and popular — but the exam signals 'fixed budget, fixed scope, well-understood requirements,' which is the textbook definition of when Waterfall is appropriate.

How to eliminate wrong answers

Option A is wrong because Spiral is risk-driven and iterative, suited to large, high-risk projects where requirements evolve — not fixed-scope, well-understood work. Option B is wrong because Scrum is an Agile framework built for evolving requirements and iterative delivery, which contradicts the fixed scope and well-understood requirements stated in the question. Option D is wrong because Agile embraces changing requirements and continuous delivery, which is the opposite of a fixed-budget, fixed-scope project with stable requirements.

271
Multi-Selectmedium

A user is setting up a new smartphone for work and wants to reduce the risk of unauthorized access if the device is lost. Which two measures should the user implement? (Choose two.)

Select 2 answers
A.Disable automatic operating system updates
B.Store passwords in a plain text note on the device
C.Turn on remote wipe and locate services
D.Enable a screen lock with a strong PIN or biometric
E.Root or jailbreak the device to install security tools
AnswersC, D

Remote wipe lets the user erase the device over the internet once it is reported lost, removing work data before it can be extracted. Locate services help recover the device or confirm it is gone so a wipe can be triggered. Together they provide a response capability that complements the preventive screen lock, directly addressing the lost-device scenario.

Why this answer

Protecting a lost phone requires both a preventive control and a response capability. A strong screen lock, backed by a PIN or biometric, keeps a finder from opening the device and leverages the storage encryption tied to the lock credential. Remote wipe and locate services let the user erase work data after the loss is discovered.

Disabling updates, rooting the device, and storing plain text passwords all increase exposure.

Exam trap

The trap here is treating convenience measures like disabling updates or rooting the phone as security improvements, when they actually weaken the device.

272
MCQeasy

A help desk technician is creating a spreadsheet to track support tickets. They want each ticket to have a unique identifier that is automatically generated when a new row is added, and they want the value to never repeat even if rows are deleted. Which spreadsheet feature should they use?

A.Use an AutoNumber or automatic row ID feature
B.Apply a data validation rule to the ticket ID column
C.Format the ticket ID column as text
D.Sort the ticket ID column in ascending order
AnswerA

AutoNumber fields, sometimes called automatic row IDs, generate a unique sequential or random value whenever a new record is created. They continue incrementing even if earlier rows are deleted, so the identifier never repeats. This directly meets the requirement for a unique ticket identifier that is created automatically for each new support ticket.

Why this answer

An automatic row ID or AutoNumber feature is designed to produce a unique value for every new record without user intervention. It continues to generate new values even after records are deleted, so duplicates do not occur. Data validation, text formatting, and sorting do not automatically create or guarantee unique identifiers.

Exam trap

The trap here is assuming that any column can be made unique by formatting or validating it, when only an automatic ID feature generates new unique values for each record.

273
MCQeasy

Which tool is commonly used for automated testing in software development?

A.Jenkins
B.Git
C.Visual Studio
D.Docker
AnswerA

Jenkins orchestrates automated test execution through pipelines, triggering unit, integration and regression suites whenever code is committed. It satisfies the stem's automation constraint by removing manual test invocation, scheduling builds and reporting results continuously. Unlike static analysis or manual QA tools, Jenkins drives the test run itself, making it the standard CI server for automated testing.

Why this answer

Jenkins. Jenkins is a continuous integration tool that automates testing. Docker (D) is for containerization.

Git (B) is for version control. Visual Studio (C) is an IDE, but not specifically for automated testing.

274
Multi-Selectmedium

Which TWO of the following are characteristics of ransomware?

Select 2 answers
A.It collects user information without consent.
B.It self-replicates to other systems without user interaction.
C.It encrypts the victim's files.
D.It demands payment in exchange for decryption.
E.It disguises itself as legitimate software.
AnswersC, D

Ransomware encrypts the victim's files using symmetric keys, rendering documents, databases and images inaccessible until decryption occurs. This cryptographic locking is the defining characteristic that distinguishes ransomware from other malware, and it directly satisfies the stem's requirement for a ransomware trait.

Why this answer

Option C is correct because the defining behavior of ransomware is that it encrypts the victim's files (often using strong symmetric ciphers like AES with a per-file key, then wrapping that key with asymmetric encryption such as RSA), rendering the data inaccessible until a key is provided. Option D is correct because ransomware is a form of extortion: after encryption it presents a ransom note demanding payment, typically in cryptocurrency such as Bitcoin or Monero, in exchange for the decryption key or tool. Option A describes spyware, which covertly harvests user information rather than encrypting and holding data hostage.

Option B describes a worm, which propagates across systems autonomously without user interaction, a spreading mechanism rather than the extortion characteristic of ransomware. Option E describes a Trojan, which masquerades as legitimate software to trick users into running it, and while ransomware is often delivered via Trojans, disguise is not its defining characteristic.

Exam trap

FC0-U71 often tests whether candidates can distinguish ransomware from adjacent malware categories — spyware, worms, and Trojans — by focusing on the payment demand and file encryption as the defining pair of traits.

275
Multi-Selecthard

Which THREE of the following are effective methods to protect against malware infections? (Select THREE.)

Select 3 answers
A.Open all email attachments regardless of sender
B.Install and maintain antivirus software
C.Use a firewall to filter incoming and outgoing traffic
D.Disable automatic software updates to avoid changes
E.Keep operating systems and applications up to date
AnswersB, C, E

Antivirus software detects, blocks and removes known malware through signature and behavioural scanning, with regular updates catching new threats. Installing and maintaining it provides continuous host-level protection, satisfying the malware prevention requirement in the stem.

Why this answer

Option B is correct because installing and maintaining antivirus software with current signature/definition databases enables detection, blocking, and removal of known malware before it can execute or spread. Option C is correct because a firewall filters inbound and outbound traffic against defined rules, blocking malicious connections, command-and-control callbacks, and unauthorized remote access that malware relies on. Option E is correct because keeping operating systems and applications patched closes known vulnerabilities (e.g., unpatched RCE flaws) that malware exploits to gain initial access or escalate privileges.

Option A is wrong because opening all email attachments regardless of sender is a primary malware delivery vector, especially via phishing and malicious macros. Option D is wrong because disabling automatic software updates leaves systems exposed to publicly known exploits that vendors have already fixed.

276
MCQhard

A help desk technician receives a call from a user who cannot connect to a network share. The user's computer shows a network icon with a red X. The technician asks the user to check the network cable connection. The user reports that the cable is securely connected. The technician then pings the default gateway from their own computer and the ping is successful. Which of the following is the NEXT step the technician should take?

A.Check the IP configuration on the user's computer
B.Replace the network cable
C.Restart the network share server
D.Disable the firewall on the user's computer
AnswerA

The red X indicates a link-layer problem local to the user's machine, while the successful gateway ping proves the network path and gateway are healthy. Verifying the user's IP configuration (address, subnet mask, default gateway) isolates whether a bad static address or DHCP failure is blocking connectivity.

Why this answer

The user's computer shows a network icon with a red X, indicating a physical or data-link layer issue, but the cable is reported as securely connected. The technician successfully pings the default gateway from their own computer, proving the network infrastructure (router, switch, cabling) is functional. The next logical step is to check the IP configuration on the user's computer, as a missing or misconfigured IP address (e.g., APIPA 169.254.x.x due to DHCP failure) could prevent connectivity even with a good cable.

This isolates the problem to the user's device rather than the network.

Exam trap

The trap here is that candidates assume a red X always means a bad cable or physical disconnection, but the question explicitly states the cable is secure, so the next step is to verify the logical configuration (IP address) rather than blindly replacing hardware or restarting servers.

How to eliminate wrong answers

Option B is wrong because replacing the network cable is premature; the user already confirmed it is securely connected, and the technician's successful ping indicates the cabling and switch port are likely fine. Option C is wrong because restarting the network share server is a drastic step that assumes the server is down, but the technician's successful ping to the default gateway only verifies local network reachability, not the server's status, and the issue is isolated to the user's computer. Option D is wrong because disabling the firewall is a security risk and should only be considered after verifying IP configuration and basic connectivity; a firewall typically blocks specific traffic, not all network access, and the red X icon suggests a lower-layer problem.

277
MCQhard

An employee calls the help desk claiming to be a manager from another department and requests a password reset. This is an example of which social engineering technique?

A.Baiting
B.Pretexting
C.Tailgating
D.Phishing
AnswerB

Pretexting involves inventing a fabricated scenario or false identity to manipulate a victim into complying. Claiming to be a manager from another department establishes that invented pretext, exploiting the employee's deference to authority to obtain an unauthorised password reset.

Why this answer

Pretexting is a social engineering technique where an attacker invents a fabricated scenario (a pretext) — such as impersonating a manager from another department — to manipulate a victim into divulging information or performing an action like a password reset. The key element is the false identity and fabricated context used to gain trust. Because the caller claims to be a manager requesting a password reset, this is a textbook pretexting attack.

Exam trap

FC0-U71 often tests the distinction between pretexting (fabricated scenario/identity) and phishing (fraudulent email/message), so candidates who see 'phone call' and jump to phishing miss that the core deception is the invented pretext.

How to eliminate wrong answers

Option A (Baiting) is wrong because baiting involves leaving something enticing (like a USB drive or free download) for the victim to pick up and use, not impersonating a person over the phone. Option C (Tailgating) is wrong because tailgating is a physical technique where an unauthorized person follows an authorized person through a secure door, not a phone-based impersonation. Option D (Phishing) is wrong because phishing is typically conducted via email or electronic messaging with fraudulent links or attachments, not a live phone call impersonating a manager.

278
Matchingmedium

Match each operating system to its common environment.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Desktop and server

Server and embedded systems

Apple desktop computers

Web-based laptops

Why these pairings

Common environments: Windows (personal computing/gaming), Linux (servers/development), macOS (creative work). Android is for mobile, Chrome OS for web-based tasks.

279
MCQmedium

A company uses a relational database with a 'Customers' table and an 'Orders' table. Each order must be linked to exactly one customer. Which type of relationship exists between Customers and Orders?

A.No relationship
B.One-to-many
C.Many-to-many
D.One-to-one
AnswerB

One-to-many fits because a single customer row can be referenced by many order rows, while each order holds exactly one foreign key back to its customer. This satisfies the stem's constraint that every order links to precisely one customer, with no order shared between customers.

Why this answer

In a relational database, if each order must be linked to exactly one customer, but a customer can have multiple orders, the relationship is one-to-many. The 'one' side is Customers (each customer is unique) and the 'many' side is Orders (multiple orders per customer). This is implemented via a foreign key in the Orders table referencing the primary key in Customers.

Exam trap

The trap is misinterpreting the cardinality: candidates might think one-to-one because each order has one customer, but they forget that a customer can have many orders, making it one-to-many.

How to eliminate wrong answers

Option A is wrong because a relationship is required to link orders to customers; without it, orders would be orphaned. Option C is wrong because many-to-many would imply that one order can be linked to multiple customers, which contradicts the requirement that each order links to exactly one customer. Option D is wrong because one-to-one would mean each customer has at most one order, which is not stated and typically not the case in sales systems.

280
Multi-Selecthard

Which THREE of the following are components typically found inside a CPU?

Select 3 answers
A.Cache
B.RAM
C.Control Unit
D.Arithmetic Logic Unit (ALU)
E.Hard Drive
AnswersA, C, D

Cache is high-speed memory built into the CPU.

Why this answer

Cache is a small, high-speed memory located directly on the CPU die that stores frequently accessed data and instructions, reducing the time needed to fetch data from main memory (RAM). It is an integral part of the CPU's architecture, typically organized in multiple levels (L1, L2, L3) to balance speed and capacity.

Exam trap

The trap here is that candidates confuse external memory components (RAM, hard drive) with internal CPU components, or they mistakenly think the Control Unit and ALU are not part of the CPU, when in fact they are the core processing units.

281
Multi-Selectmedium

Which THREE of the following are best practices for password security?

Select 3 answers
A.Sharing passwords with trusted coworkers when necessary
B.Enabling two-factor authentication where possible
C.Using a password manager to generate and store passwords
D.Reusing the same password across multiple sites
E.Using a password with at least 12 characters including uppercase, lowercase, numbers, and symbols
AnswersB, C, E

Enabling two-factor authentication adds a second verification factor beyond the password, so a stolen or guessed credential alone cannot grant access. This directly satisfies the stem's password-security best-practise requirement by mitigating credential compromise, and Microsoft Entra ID supports it natively through Conditional Access and authentication methods policies.

Why this answer

Option B is correct because enabling two-factor authentication (2FA) adds a second verification factor (e.g., TOTP, hardware token, or push notification) beyond the password, so a stolen or guessed password alone is insufficient to compromise the account. Option C is correct because a password manager generates high-entropy, unique credentials for each site and stores them encrypted (typically under AES-256 with a master passphrase), eliminating weak or reused passwords and reducing the risk of credential-stuffing attacks. Option E is correct because length and character diversity increase the search space, making brute-force and dictionary attacks computationally impractical; 12+ characters mixing uppercase, lowercase, digits, and symbols aligns with NIST and common policy guidance for strong passwords.

Option A is wrong because sharing passwords destroys individual accountability and non-repudiation, and violates least-privilege and audit principles; use delegated accounts or role-based access instead. Option D is wrong because reusing one password across sites means a single breach exposes all accounts via credential stuffing, so every account should have a unique password.

282
Multi-Selecthard

A database administrator needs to perform CRUD operations on a database. Which THREE SQL commands correspond to the 'Create', 'Read', and 'Update' operations?

Select 3 answers
A.CREATE
B.INSERT
C.DELETE
D.UPDATE
E.SELECT
AnswersB, D, E

INSERT maps to the 'Create' operation, adding new rows to a table. It satisfies the stem's requirement for the Create command within CRUD, distinct from SELECT (Read) and UPDATE (Update). Its row-level write semantics make it the precise SQL statement for creating records.

Why this answer

The 'Create' part of CRUD in terms of row-level data operations is fulfilled by INSERT (option B), which adds new rows into a table using INSERT INTO ... VALUES syntax. The 'Read' operation is fulfilled by SELECT (option E), which retrieves rows from one or more tables and is the standard SQL query command.

The 'Update' operation is fulfilled by UPDATE (option D), which modifies existing row values using UPDATE ... SET ... WHERE.

CREATE (option A) is a DDL statement for creating schema objects such as tables or databases, not for creating data rows, so it does not map to the CRUD 'Create' data operation here. DELETE (option C) removes rows and corresponds to the 'Delete' operation, not to Create, Read, or Update, so it is not among the three required commands.

Exam trap

FC0-U71 often tests the confusion between DDL CREATE (creating a table) and DML INSERT (creating a row), since both are colloquially described as 'creating' something in a database.

283
MCQmedium

A user is experiencing slow Wi-Fi performance at home. The router supports both 2.4GHz and 5GHz bands. Which frequency band would provide faster speeds but shorter range?

A.NFC
B.2.4GHz
C.Bluetooth
D.5GHz
AnswerD

5GHz offers wider channels and higher throughput than 2.4GHz, satisfying the stem's demand for faster speeds. Its shorter wavelength attenuates more rapidly through walls and obstacles, giving the reduced range the question specifies. Microsoft Entra ID is irrelevant here; the deciding axis is frequency-dependent propagation and channel width.

Why this answer

The 5GHz band offers higher speeds but has shorter range and is less prone to interference compared to 2.4GHz.

284
MCQeasy

A user at a small design company calls the help desk because their computer is running very slowly when opening large image files. The computer has 8 GB of RAM, a 500 GB HDD, and an integrated graphics card. The technician suspects the slow performance is due to insufficient RAM. Which of the following is the BEST course of action?

A.Increase the size of the page file
B.Add more RAM
C.Upgrade the HDD to an SSD
D.Reduce the image resolution
AnswerB

Adding RAM directly increases available memory for large files.

Why this answer

The computer has only 8 GB of RAM and an integrated graphics card, which shares system RAM for video memory. When opening large image files, the system runs out of physical RAM and must use the much slower page file on the HDD, causing severe slowdowns. Adding more RAM directly addresses the bottleneck by providing sufficient physical memory to hold the image data and reduce reliance on disk swapping.

Exam trap

The trap here is that candidates often confuse a symptom (slow disk access) with the root cause (insufficient RAM), leading them to choose an SSD upgrade (Option C) instead of addressing the primary memory shortage.

How to eliminate wrong answers

Option A is wrong because increasing the page file size only expands the amount of slow disk space used as virtual memory, which does not solve the underlying RAM shortage and can actually worsen performance due to increased disk thrashing. Option C is wrong because while upgrading the HDD to an SSD would improve overall disk I/O, it does not address the core issue of insufficient RAM; the system would still swap heavily, and the bottleneck would shift from disk speed to the lack of physical memory. Option D is wrong because reducing the image resolution is a workaround that changes the user's workflow and data quality, not a hardware or system-level fix for the insufficient RAM causing the slow performance.

285
MCQeasy

Which of the following best describes the difference between a compiler and an interpreter?

A.Compiled programs run slower than interpreted programs.
B.A compiler executes code line by line; an interpreter translates the entire program at once.
C.A compiler translates the entire source code into machine code before execution; an interpreter executes code line by line.
D.A compiler checks for syntax errors at runtime; an interpreter checks at compile time.
AnswerC

Compilation converts the whole source file to machine code in one pass before any execution, so runtime errors surface after translation. Interpretation decodes and executes each statement sequentially at runtime. This whole-program versus line-by-line axis is exactly the distinction the question asks for.

Why this answer

A compiler translates the entire source code into machine code before execution, producing a separate executable. An interpreter translates and executes source code line by line at runtime. Compiled programs generally run faster at execution because translation is done ahead of time.

Therefore, option C is correct. Option A confuses development speed (no separate compile step) with execution speed. Option B reverses the two definitions, and option D incorrectly describes when syntax checking occurs.

Exam trap

CompTIA often tests the common misconception that interpreters are faster because they skip the compilation step, but the trap here is confusing the order of translation and execution, leading candidates to reverse the definitions of compiler and interpreter.

How to eliminate wrong answers

Option A is wrong because compiled programs typically run faster than interpreted programs, as the translation to machine code is done ahead of time, eliminating the overhead of per-line translation during execution. Option B is wrong because it reverses the definitions: a compiler translates the entire program at once, while an interpreter executes code line by line. Option D is wrong because a compiler checks for syntax errors at compile time (before execution), not at runtime; an interpreter checks for syntax errors at runtime as it processes each line.

286
MCQeasy

A security guard notices an individual following closely behind an employee through a secured door without swiping a badge. This scenario is an example of which type of security threat?

A.Shoulder surfing
B.Phishing
C.Tailgating
D.Malware
AnswerC

Tailgating describes an unauthorised person physically following an authenticated individual through a controlled access point without presenting their own credentials, exactly matching the guard's observation of someone slipping through a secured door behind a badged employee.

Why this answer

Tailgating is the physical security breach where an unauthorized person follows an authorized individual through a secured entry point without presenting their own credentials. In this scenario, the individual closely follows an employee through a secured door without swiping a badge, which exactly matches the definition of tailgating. This threat exploits human politeness or inattention and does not require technical hacking.

Exam trap

The trap here is confusing physical security threats with cyber threats; candidates might pick 'shoulder surfing' because both involve close proximity, but shoulder surfing is about observing information, not unauthorized entry.

How to eliminate wrong answers

Option A is wrong because shoulder surfing involves visually observing someone entering sensitive information like passwords or PINs, not physically following them through a door. Option B is wrong because phishing is a social engineering attack conducted via electronic communication (e.g., email) to trick users into revealing credentials or clicking malicious links, not a physical entry tactic. Option D is wrong because malware is malicious software designed to damage or gain unauthorized access to systems, which is unrelated to physically bypassing a door.

287
MCQmedium

A software team is choosing a version control workflow. They want developers to work on features without disturbing the stable main branch, and they want a clear mechanism to propose and review changes before those changes become part of the main codebase. Which version control concept best fits this need?

A.A commit made directly to the main branch
B.A local file copy placed in a backup folder
C.A tag placed on the latest commit
D.A branch that is merged into main after review
AnswerD

A branch is an independent line of development that lets a developer make changes without affecting the main branch. After the work is complete, the branch can be reviewed and then merged into main. This matches the team's requirement to isolate feature work and to review changes before they become part of the stable codebase.

Why this answer

Branching creates an isolated line of development so feature work does not disturb the stable main branch. When the work is finished, a merge integrates the branch back into main, and the review typically happens before that merge. This combination of isolation and controlled integration is precisely what the team needs to protect the main codebase while still enabling collaborative feature development.

Exam trap

The trap here is assuming that tagging a commit or copying files provides isolation for new work, when only a branch creates a separate line of development that can be reviewed before merging.

288
Multi-Selecthard

Which TWO of the following are common causes of errors when executing a SELECT query? (Choose two.)

Select 2 answers
A.Table is too large
B.Incorrect column name
C.Index is missing
D.Missing table name
E.Network is slow
AnswersB, D

An incorrect column name causes the database engine to fail parsing, returning an "invalid column name" error before execution. This satisfies the stem's requirement for a common SELECT error, since the query references a column absent from the target table or view, breaking name resolution during compilation.

Why this answer

Option B (Incorrect column name) is correct because a SELECT statement referencing a column that does not exist in the target table will fail with an error such as 'Unknown column' in MySQL or 'Invalid column name' in SQL Server, since the parser cannot resolve the identifier against the table's schema. Option D (Missing table name) is correct because a SELECT query must specify a FROM clause with a valid table (or equivalent source); omitting it or naming a nonexistent table produces errors like 'No tables used' or 'Table doesn't exist'. Option A (Table is too large) is not a cause of query errors—large tables may affect performance, but the query still executes correctly.

Option C (Index is missing) is not an error cause either; a missing index only slows execution, and the query returns correct results via a full scan. Option E (Network is slow) is unrelated to query correctness—it may cause timeouts or latency but does not itself make a SELECT statement erroneous.

Exam trap

The trap here is that candidates confuse performance issues (large table, missing index, slow network) with actual query execution errors, but only syntax or schema mismatches (incorrect column name, missing table name) cause the query to fail.

289
MCQeasy

A user is setting up a new Windows 11 laptop and wants to ensure that files in the Documents folder are regularly backed up to the cloud automatically. Which built-in Windows feature should the user configure?

A.BitLocker
B.File History
C.Storage Sense
D.OneDrive
AnswerD

OneDrive is Microsoft's cloud storage service integrated into Windows 11. By signing in with a Microsoft account, users can enable automatic syncing of the Documents folder to OneDrive. This provides cloud backup and access from other devices. It is the built-in feature designed for this purpose and requires minimal configuration, aligning perfectly with the user's need.

Why this answer

OneDrive is the correct answer because it is the native cloud storage solution in Windows 11 that can automatically sync the Documents folder. The other options serve different purposes: File History backs up to local external drives, Storage Sense manages disk space, and BitLocker provides encryption. Only OneDrive fulfills the requirement for automatic cloud backup.

Exam trap

The trap here is confusing local backup tools like File History with cloud services; File History does not back up to the cloud unless a network location is mapped to a cloud drive, which is not automatic.

290
MCQeasy

Which software license allows a user to install the software on multiple computers for personal use?

A.Trial version
B.Enterprise license
C.Open source license
D.Personal license
AnswerD

A personal licence grants one individual the right to install and use the software on multiple machines they own, for non-commercial purposes. This matches the stem's requirement for multi-computer installation limited to personal use, unlike single-seat or commercial terms.

Why this answer

A personal license grants a single user the right to install the software on multiple devices they own or control, typically for non-commercial use. This is distinct from a per-seat license, which limits installation to one computer per license key. The key differentiator is that the license is tied to the user, not the machine count.

Exam trap

The trap here is confusing a 'personal license' with a 'single-user, single-device' model, leading candidates to incorrectly choose an enterprise license for multi-computer use, when in fact enterprise licenses are for organizational scale, not personal multi-device rights.

How to eliminate wrong answers

Option A is wrong because a trial version is time-limited or feature-restricted and does not grant permanent multi-install rights; it is intended for evaluation only. Option B is wrong because an enterprise license is a volume licensing agreement for organizations, allowing deployment across many corporate devices, not for an individual's personal use. Option C is wrong because an open source license (e.g., GPL, MIT) grants rights to use, modify, and distribute the source code, but it does not specifically define a personal multi-computer installation allowance; the focus is on software freedom, not user-centric device limits.

291
MCQeasy

Refer to the exhibit. A user executes: SELECT AVG(Salary) FROM Employees; What is the result?

A.55000
B.50000
C.165000
D.60000
AnswerA

AVG() computes the arithmetic mean of all non-NULL values in the Salary column, summing them and dividing by the row count. Given the exhibit's three salaries totalling 165000, the aggregate returns 55000, satisfying the query's requirement for a single averaged result rather than per-row output.

Why this answer

The AVG function calculates the arithmetic mean of the Salary column across all rows in the Employees table. Given the salaries 50000, 60000, and 55000, the average is (50000 + 60000 + 55000) / 3 = 55000. Therefore, option A is correct.

Exam trap

The trap here is that candidates often confuse AVG with SUM or MIN/MAX, leading them to pick the sum (165000) or an extreme value (50000 or 60000) instead of correctly computing the mean.

How to eliminate wrong answers

Option B (50000) is wrong because it represents the minimum salary, not the average. Option C (165000) is wrong because it is the sum of all salaries (50000 + 60000 + 55000), not the average. Option D (60000) is wrong because it represents the maximum salary, not the average.

292
MCQmedium

A database must be restored to the exact state at 11:00 AM. The last full backup was at 10:00 PM previous day, and transaction log backups were taken every hour. What is the minimum to restore?

A.Full backup plus all transaction log backups from after full backup
B.Transaction log backup only
C.Full backup only
D.Full backup plus differential backup
AnswerA

Restoring the 10:00 PM full backup then replaying every hourly transaction log backup up to 11:00 AM achieves point-in-time recovery, satisfying the requirement for the exact 11:00 AM state. Transaction logs capture all committed changes between backups, so no intermediate data is lost.

Why this answer

To restore a database to a specific point in time (11:00 AM) when only full and transaction log backups exist, you must restore the most recent full backup (from 10:00 PM previous day) and then apply all subsequent transaction log backups in sequence. Transaction log backups contain all committed transactions up to the time of the backup, so applying them in order after the full backup brings the database to the exact state at the time of the last log backup (which would be 11:00 AM if the hourly log backup was taken at that time). Option A is correct because it includes the full backup and all transaction log backups taken after it, which is the minimum required for point-in-time recovery.

Exam trap

The trap here is that candidates often think a differential backup can achieve point-in-time recovery, but differentials only capture changes up to a point, not the granular transaction-level detail needed to restore to an exact time like 11:00 AM.

How to eliminate wrong answers

Option B is wrong because a transaction log backup alone cannot restore a database without a prior full backup to provide the base data structure and pages. Option C is wrong because a full backup alone only restores the database to the state at the time of that backup (10:00 PM previous day), not to the later point-in-time of 11:00 AM. Option D is wrong because a differential backup captures changes since the last full backup but does not provide point-in-time granularity to a specific hour; transaction log backups are required for that precision.

293
MCQeasy

Which of the following is an example of an output device?

A.Scanner
B.Mouse
C.Keyboard
D.Monitor
AnswerD

A monitor receives processed video data from the graphics adapter and presents it to the user, which is the defining role of an output device. Keyboards, mice and scanners instead send data into the system as input devices.

Why this answer

An output device receives processed data from a computer and presents it to the user in a human-readable or usable form. A monitor is a classic output device because it displays visual information such as text, images, and video generated by the computer's GPU. It does not send data into the computer; it only presents data outward to the user.

Exam trap

FC0-U71 often tests the misconception that any peripheral is an output device, when in fact most peripherals (keyboard, mouse, scanner) are input devices and only devices that present data to the user qualify as output.

How to eliminate wrong answers

Option A is wrong because a scanner is an input device — it captures physical documents or images and converts them into digital data sent to the computer. Option B is wrong because a mouse is an input device used to point, click, and send commands to the computer. Option C is wrong because a keyboard is an input device used to type characters and issue commands into the system.

294
Multi-Selecthard

Which THREE of the following are valid SQL statements?

Select 3 answers
A.REMOVE TABLE Employees
B.SELECT * FROM Employees WHERE Department = 'Sales'
C.MODIFY Employees SET Salary = 60000 WHERE ID = 1
D.DELETE FROM Employees WHERE ID = 5
E.INSERT INTO Employees VALUES ('John', 50000)
AnswersB, D, E

SELECT retrieves rows, the asterisk returns all columns, FROM names the table, and WHERE filters rows by the Department column matching the string 'Sales'. This is syntactically valid SQL, unlike statements missing clauses or using non-existent keywords.

Why this answer

Option B, 'SELECT * FROM Employees WHERE Department = \'Sales\'', is valid SQL because SELECT with the asterisk wildcard retrieves all columns from the Employees table, and the WHERE clause filters rows where Department equals the string literal 'Sales'. Option D, 'DELETE FROM Employees WHERE ID = 5', is valid SQL because DELETE FROM removes rows from the Employees table, and the WHERE clause restricts deletion to the row whose ID equals 5. Option E, 'INSERT INTO Employees VALUES (\'John\', 50000)', is valid SQL because INSERT INTO with the VALUES clause adds a new row containing the string 'John' and the numeric value 50000 into the table's columns in order.

Option A is not valid because SQL has no REMOVE TABLE statement; the correct statement is DROP TABLE. Option C is not valid because SQL has no MODIFY statement for changing data; the correct statement is UPDATE Employees SET Salary = 60000 WHERE ID = 1.

Exam trap

FC0-U71 often tests the confusion between similar-sounding SQL commands, such as REMOVE vs. DROP and MODIFY vs. UPDATE, causing candidates to select invalid statements.

295
MCQeasy

Which of the following best describes the 'Confidentiality' component of the CIA triad?

A.Systems are operational when needed
B.Data is accessible only to authorized users
C.Data is encrypted at rest
D.Data is not modified without authorization
AnswerB

Confidentiality ensures data is disclosed only to authorised users, enforced through encryption, access controls and authentication. This directly matches the stem's requirement that information remains inaccessible to unauthorised parties, distinguishing it from Integrity, which concerns accuracy, and Availability, which concerns timely access.

Why this answer

Confidentiality ensures that data is not accessed by unauthorized individuals. Integrity protects data from unauthorized modification, and availability ensures data is accessible when needed.

296
MCQmedium

A company uses a web-based application that runs in a browser and stores data on a remote server. Which of the following best describes this type of application?

A.Desktop application
B.Mobile app
C.Hybrid app
D.Web application
AnswerD

A web application runs in a browser and stores data on a remote server, exactly matching the stem's constraints. Unlike locally installed software, processing and storage occur server-side, with the browser acting as the client interface. This satisfies both the browser-based access and remote data storage requirements described.

Why this answer

A web application runs in a browser and stores/processes data on a remote server, accessed over the network via HTTP/HTTPS. This matches the description exactly. Desktop, mobile, and hybrid apps run natively on a device rather than in a browser with server-side data storage.

Exam trap

The trap is confusing hybrid apps with web apps — candidates see 'browser' and 'remote server' but pick hybrid because it sounds like a blend, missing that hybrid apps are installed on devices while web apps run in the browser.

How to eliminate wrong answers

Option A is wrong because a desktop application is installed and runs locally on a computer's operating system, not in a browser, and typically stores data locally or on a network share rather than a remote web server. Option B is wrong because a mobile app is installed on a smartphone/tablet and runs as a native or hybrid app, not in a desktop browser. Option C is wrong because a hybrid app combines native and web technologies but is still packaged and installed as an app on a device, not accessed purely through a browser.

297
MCQmedium

A company wants to deploy a new wireless standard that offers higher throughput and better performance in dense environments. Which Wi-Fi standard should they choose?

A.802.11n (Wi-Fi 4)
B.802.11ax (Wi-Fi 6)
C.Bluetooth 5.0
D.802.11ac (Wi-Fi 5)
AnswerB

802.11ax (Wi-Fi 6) introduces OFDMA and MU-MIMO, letting one access point serve multiple clients simultaneously rather than contending for airtime. This directly satisfies the dense-environment constraint, where earlier standards such as 802.11ac degrade under high client counts. It also delivers higher throughput than 802.11ac.

Why this answer

802.11ax (Wi-Fi 6) is the latest standard, offering higher speeds, better efficiency, and improved performance in dense environments.

298
MCQhard

A technician is setting up a virtualized environment on a laptop to run multiple operating systems for testing. Which type of hypervisor is most appropriate?

A.Bare-metal hypervisor
B.Type 1 hypervisor
C.Container
D.Type 2 hypervisor
AnswerD

A Type 2 hypervisor runs as an application atop the host operating system, which suits a laptop already running a desktop OS for testing. Type 1 hypervisors install bare-metal and would replace the host OS, which the scenario does not require.

Why this answer

A Type 2 hypervisor runs as an application on top of an existing host operating system, making it ideal for a laptop where the user needs to keep the host OS running while testing multiple guest VMs. Examples include VMware Workstation, Oracle VirtualBox, and Parallels. This is the standard choice for desktop virtualization and lab environments.

Exam trap

FC0-U71 often tests the Type 1 vs Type 2 distinction by describing a desktop/laptop scenario — candidates who default to 'bare-metal is always faster' pick Type 1 and miss that the host OS must remain in use.

How to eliminate wrong answers

Option A is wrong because a bare-metal hypervisor (also called Type 1) installs directly on hardware and replaces the host OS — inappropriate for a laptop that must remain usable as a normal workstation. Option B is wrong because Type 1 and bare-metal are the same thing, so it carries the same problem as option A. Option C is wrong because containers share the host OS kernel and do not run full operating systems — they cannot satisfy the requirement to run multiple distinct OSes for testing.

299
MCQmedium

A developer is working on a new feature and creates a copy of the main codebase to work in isolation. Later, this copy is merged back into the main branch. Which version control concept describes this copy?

A.Merge
B.Branch
C.Commit
D.Pull request
AnswerB

A branch is an independent line of development copied from the main codebase, letting the developer commit changes in isolation. Those commits are later merged back into the main branch, which is exactly the isolation-then-integration workflow described in the scenario.

Why this answer

A branch is an independent line of development created from a point in the main codebase so a developer can work in isolation without affecting the main line. When the feature is complete, the branch is merged back into the main branch. This matches the scenario exactly: a copy of the codebase used for isolated work that is later integrated.

Exam trap

FC0-U71 often tests the confusion between the isolated copy (branch) and the integration action (merge) or the review artifact (pull request), so candidates must map the scenario's 'copy used for isolated work' to branch.

How to eliminate wrong answers

Option A is wrong because a merge is the act of integrating changes from one branch into another, not the isolated copy itself. Option C is wrong because a commit is a snapshot of changes recorded in the repository history, not a parallel line of development. Option D is wrong because a pull request is a collaboration/review mechanism for proposing and discussing changes before merge, not the isolated copy of the codebase.

300
MCQeasy

Which of the following best describes the principle of least privilege?

A.Users should have all permissions by default
B.Users should have the minimum permissions needed to do their job
C.Users should use multi-factor authentication
D.Users should change passwords every 30 days
AnswerB

Least privilege restricts each account to only the permissions its job function demands, nothing more. This directly satisfies the stem's requirement by minimising the attack surface and limiting blast radius if credentials are compromised, since no user holds rights beyond their operational needs.

Why this answer

The principle of least privilege (PoLP) states that a user, process, or system should be granted only the minimum access rights necessary to perform its legitimate function, and nothing more. Option B captures this exactly: minimum permissions needed to do the job. This limits the blast radius of compromised accounts, insider misuse, and accidental misconfiguration, and is a foundational control in frameworks like NIST SP 800-53 AC-6 and CIS Controls.

Exam trap

FC0-U71 often tests the confusion between authentication controls (MFA, password rotation) and authorization principles (least privilege), so candidates pick C or D because they 'sound secure' without matching the definition asked.

How to eliminate wrong answers

Option A is wrong because granting all permissions by default is the opposite of least privilege — it is effectively 'maximum privilege' and violates the deny-by-default model. Option C is wrong because multi-factor authentication is an authentication control that strengthens identity verification, not an authorization principle governing permission scope. Option D is wrong because mandatory 30-day password rotation is a credential hygiene policy; modern guidance (NIST SP 800-63B) actually discourages arbitrary periodic rotation in favor of length and breach checks.

Page 3

Page 4 of 14

Page 5